Monday, January 4, 2010

This may be your last Windows upgrade, you better enjoy it!

Cloud Computing promises to move all functionality into the cloud. At the same time the consumerisation trend is driving the use of consumer electronics such as of the shelf laptops, iPhones, MacBooks and home entertainment centers as access devices. Typically these devices will be cool, flat, inexpensive and it’s doubtful they will have a physical keyboard. But more interestingly – at least from a service management perspective – is that it will no longer matter how these devices are configured and even whether they run Windows, Chrome, Linux or some kind of mobile derivative. Many organizations are planning their upcoming transition to Windows 7 as the first step towards such a new consumerised, cloud centric future. Through this approach they aim to achieve short term efficiencies while at the same time reaping some of the future benefits already.


Putting the words consumerisation and benefits in one sentence is not something that comes natural for a lot of IT departments. For a long time IT felt “microcomputers require micromanagement”. An idea that may be soon be just as dated as the word “microcomputer” itself. Let’s have a quick look at some of the things that are happening already.


More and more organizations offer webmail as a way to access their email systems. This enable employees to access their mail from their home PC, from an internet cafĂ© while on vacation or from customer sites where our employees cannot plug in their laptop’s but do have access to browsers. At the same time we see that the API of this webmail is used to set up access from personal phones and PDA’s. With the introduction of intranets and sharepoints many of the received mails however link back to content on the corporate network. So more advanced organizations are already offering instant intranet access, either via the standard VPN protocols supported by modern devices or by offering an “on the fly” VPN, where the VPN client software is installed via the browser during the first connection. A related trend we see is the use of multiple devices by one person. Not many corporations hand out multiple laptops, netbooks and desktops to the same person, but several executives are taken to the idea of an ultralight tablet for short trips and a solid laptop for longer stays, and I guess many of you reading this also have both a laptop and a desktop and maybe even a netbook or MacBook for on the side? If it was not so much work to have the right data on the right machine, we would swap devices much more often, wouldn’t we?

But also on the application side we see several related developments. Traditionally enterprise applications required a specifically configured client (think client/server) and access was only offered to devices inside the corporation’s network. Most modern applications offer access from a browser. Originally the browser interface supported a subset of the functionality but more and more the full scope of the application functionality is available to browser based clients. This reduces the need for client specific configuration but more importantly it allows organizations to offer non-employees, who use non-company provided devices, access to these applications. These can be contractors, temp workers, employees subcontractors etc. And as a result companies have taken to offering access to these applications over the internet. Of course governing and enforcing who is allowed to have access and who is not, is still required. But access itself is no longer depending on physical availability of a specific configuration or specific client device. Offering access to applications irrespective of time or place is cloud computing as original defined by Ramnath K. Chellappa :“a computing paradigm where the boundaries of computing will be determined by economic rationale rather than technical limits.[1]“


The described consumerisation and cloud computing developments basically impact our move to Windows 7 in three ways. First, we may use multiple devices - sometimes on and sometimes off the corporate network. Secondly, most application logic will execute on servers in the cloud (not on our desktop) and thirdly, ideally our data and settings travel with us like a virtual desktop, instead of being confined to one physical device. However there is also a fourth thing to be considered, and – as always in IT - that is legacy. The above approach can be implemented in a green pasture environment, but what about the apps we bought 5 or 10 years ago and we still use every day. For those we will need a “transition strategy”.

With some companies already moved over, how would you go about setting up such a strategy? One of our European colleagues created a simple seven step approach which starts with a small questionnaire to assess where you are with regard to each of these steps. The first step is to define your vision for your “next generation workspace”. This section includes questions on new possibilities such as virtual desktop infrastructures, support for roaming profiles and devices, virtual application streaming etc.

Next step is sketching out a transition strategy in a Project Plan. Part of this project plan are the following areas: Compliance: do your current contracts and licenses allow you to take the planned approach; Training: what new skills (apart from Windows 7 skills) do you need to acquire; Financial: what will be the cost impact of this transition on your services and how will you charge for these services; Hardware & Software: What do you already have and what would need to be changed, bought, upgraded. And the final items are Management & Support of the transition and of the new situation going forward. Especially the changes in the area of support are quit profound. With user-owned “off the shelf” devices and applications predominantly running in the cloud, support will include even more self service and will require more collaboration with your (cloud) service providers and seamless access to the support environments of the device providers.

Like mentioned, this may be the last desktop environment you provide. My kids already take their own personalized laptops and phones to school and fully expect to do the same when they join the workforce. The only thing they find cool about my company supplied equipment is the fact that access fees and subscription cost are covered. Now if we could only find a way to “consumerise” those too (starting at home).


PS If interested in the described step by step plan, leave me a note twitter.com@leanitmanager

Monday, December 21, 2009

Service Portfolio Management or How Cloud Computing puts an end to bottoms up Service Management

This blog features both under our Service Management and Portfolio Management sections and revolves around a video we created earlier this year.

In the video a demand manager tries to convince an operations manager of the benefits of a portfolio approach. The operations manager is not easy to convince as he feels his approach of monitoring his hardware and software gives him good insight into what is going on.


Such a bottoms up approach, starting from the technical components we are running in our datacenter, is a common approach when implementing traditional service management (if we do not run it ourselves, it can’t be very important so we don’t need to support it, let alone document it). Cloud Computing puts a spanner into this logic. Starting from the components we run ourselves will give an increasingly incomplete picture.

Does that make the video less applicable? On the contrary! A top down portfolio approach now becomes even more essential. So suggest you have a quick look, if only for the undeniable entertainment value.

BTW If you’re interested to see how Service Management, Portfolio Management and Cloud Computing are also coming together in terms of popularity have a look at my Cloudy Xmas trends blog.

Sunday, December 20, 2009

Cloudy Xmas cards and new year’s predictions

At the end of the year - and in this case the end of a decade - I thought it made sense to look back at what has been and try and predict what may be. Many already have named 2010 the year of Cloud Computing, so I decided to call on Google Trends to put this into a little perspective.

Below you see the results, I expect you may be as (pleasantly) surprised as I was.



As I personally spend the last decade dabbling in Service Oriented Architectures (SOA), Service Management (ITIL) and Project and Portfolio Management (PPM) I used these as anchor points for this perspective. In addition I decided to include Cloud Computing's slightly more mature nephew (SaaS) also in to the fold.  The epiphany for me personally was that it explained why I had found it so hard to choose between SOA, PPM and ITIL (design, build and run). But enough about me.

The rise of Cloud Computing’s from zero to hero in just 2 years is amazing. And with regard to news volume, shown in the bottom graph, it actually has already surpassed the others. But even more amazing is the geographic areas in which each term has the highest relative interest. For me it reinforced where the true competition of the future will be coming from, and it is not from the traditional countries. Sure, Australia is big on ITIL and the UK is big on SaaS. For Ireland, the only other European county in the top 10, the data was inconclusive on whether their current deep economic crisis makes them more eager or the Irish weather stimulates queries on clouds. The outlier for SOA in Dutch is unfortunately a fluke. It is not because we are all striving to be brilliant OO programmers here, I am afraid it is because SOA is a Dutch acronym for something complety different (which I was directed not to mention here).  




So are we done for 2011? All that needs to be said about cloud computing has been googled? Not yet.

As you can see Cloud Computing has surpassed Saas (Score 5.3) and is closing in on SOA (score 8.8), ITIL (score 8.4) and PPM (score 7.6). But any comparison with IT terms like Linux, Mac and Windows is quit sobering. Cloud Computing is not a household name yet.

But 2010 is still young, so I am sure we can propel it some more.

PS want to have some fun yourself, here is the URL of this Cloud Application: http://www.google.com/trends?q=cloud+computing%2C+saas%2C+itil%2C+ppm+%2C+soa&ctab=0&geo=all&date=all&sort=1

Thursday, December 17, 2009

Cloud Computing becomes Cool Computing?

Last month InformationWeek’s Bob Evans started a contest asking their readership to come up with a better name for “Cloud Computing”. Reason was that the CEO’s of both HP and IBM recently expressed some discontent with the current name. Something about “Cloudy not being clear enough”. Not clear enough for what, for justifying really large invoices? And then we are not even mentioning Oracle’s CEO, who has been on a contra-Cloud quest for ages.

The overwhelming majority of the 500 names the contestants submitted were acronyms, which make you wonder whether IT is truly beyond salvation. No amount of Cloud can save people that speak mnemonics, especially now IT's role is changing so significantly. Bob’s personal favorites for a new name were Cloud 9, Univac, the Matrix, and Rain. I secretly suspect some of these are acronyms in disguise.

Personally I was very surprised that nobody took the opportunity to
repeat the IT scam of the century. About twenty years ago someone called one type of computing OPEN, thus instantly making all other types of computing “closed” and therefore bad.

So what would the equivalent of OPEN be for Cloud?

Cloud Computing becomes Easy Computing - not believable enough?
Cloud Computing becomes Clear Computing - not compelling enough?
Cloud Computing becomes Open Computing - too early?
(some of the original open folks are still alive)
Cloud Computing becomes Cool Computing - Yes, even sounds familiar!

So we have a winner! Cool Computing

Now we just need to change the name of this blog.
Good thing that name changes are truly a core competency around here.

Friday, December 4, 2009

Re: Top 5 causes of IT project failures - an insurer's view

Tony Cox of Computer Weekly described the Top 5 causes of IT project failures by analyzing the records of project insurer Hiscox.

Comment: Funny how all five normally occur before most people think the project has even started.
BTW I hope that somewhere during my career there will be a time when there won’t be a monthly blog or article about constant project failures. I have some hope, new research we are publishing soon (at twitter.com/@leanitmanager) does seem to indicate in that direction.

Sunday, November 15, 2009

Service or Application? -Same difference! - Let’s Speak Value - - - - streams

On this blog a lively debate has been going on about whether using the term applications instead of services is an acceptable service management practice. Many may say we have reached the “How many angels can dance on the head of a pin?” stage here. But if service management is about managing services, would it not make sense to have some common understanding what these services are?


Reality is that neither Service nor Application are very well defined concepts. Most people agree they are related and often refer to the same thing. Development will call what they build an application while operations calls the same thing a service when they run it. But what is this “thing”?

The first question we face is granularity: Is Office the application or is Excel? And is the shared spell checker part of the application or not. And if we use the translation function, is that part of the application? ( while in reality it is a service running at either Microsoft’s or Google’s website?). And is the online training part of the application or is that only part of the service? Same for support, automatic patches and updates?

But more important than the answers to the above, is the fact that in reality nobody cares! Unless we are still trying to write down (defend) what we do, it makes no difference to anyone.

Is there an alternative that will make people care? I think there is.

It is the concept of value streams. Based on the concept of Value Chain as first described by Michael Porter in his 1985 best-seller, Competitive Advantage: Creating and Sustaining Superior Performance (now we are talking), a value stream is an end-to-end business process which delivers a product or service to a customer or consumer.

Value Stream Mapping is a lean manufacturing technique used to analyze the flow of materials and information currently required to bring a product or service to a consumer. At Toyota, where the technique originated, it is known as "material and information flow mapping". Wikipedia details the concept of Value Streams in an IT context further under Lean IT.





So what is the big difference between using service/application versus Value Stream?

Well, I for one would be very hesitant to sit down with a user and ask him to 'define' the applications/services he uses in more detail. I would however be more than happy to sit down and together with him map out the value stream he uses to service his customers and figure out where IT adds or can add value and where we see waste that can be eliminated by, through or from IT. But the conversation will likely be 80% around what our company does for its customers and only 20% about IT (and I for one believe that would be a good thing).

Saturday, November 14, 2009

Will IT in 2010 be seen as Cost or Investment?

Under the above title we started a discussion at the LinkedIn group that Gartner is hosting for attendees of the recent Gartner ITxpo’s in Orlando and Cannes. The discussion is getting quite lively, so thought it may be a good idea to invite a wider audience here.
To protect the innocent I won’t repeat all responses or the names of the senders here, but a particularly interesting response to "IT, cost or investment?" came in today and included the following observation:

“IT can help to optimize processes and therefore to reduce cost. So, you invest to reduce
the cost in any function, IT is not different to Finance, HR, Sales, etc. The question you should
ask is why does your C-Levels see IT as a cost at all. Do they see Marketing as a cost ?”

Being guilty of spending my days in a marketing role myself this reminded me of one my favorite marketing quotes (allegedly from the world’s largest advertisers):

“I’m positive we waste half the [marketing] money we spend, I just don’t know which half".

What do you think: Is IT better or worse off than marketing? 50% sounds outrages, but how many IT organizations can link 50% of their total budget (not just their project budget) back to increased profit, growth, increased marketshare.

In marketing this is no problem, we just call the part we cannot allocate directly “awareness building” or even better “strategic spend” or “corporate imaging”. I believe we need a similar bucket in IT. I am not kidding, bear with me.

In every business there is always some cost that cannot be allocated directly to results (no direct ROI), but still everyone agrees they are needed. Examples are providing a (desk) phone to every employee, having a corporate wide area network (soon to be called Cloud), providing an email system (well that last one probably has a demonstrable negative ROI given the time it consumes of our employees). No departmental manager with a P&L responsibility will agree to fund such infrastructure projects.

Yet in IT we tend to make no difference in how we treat these. Sure we distinguish between “keeping the lights on” and “new projects”. But keeping the lights on includes cost we probably could attribute directly to results, and some new projects (like migrating to IP6 or Windows7) can not.

Guess I am asking for cost categories comparable to “Demand Generation” and “Awareness Building” for IT. In marketing the first is treated as a cost (50 dollars per lead) and can be directly be linked back to increased revenue. The latter (awareness) is treated as an investment and cannot be linked back directly.

Interested in your all comments and thoughts.

Friday, October 23, 2009

Conclusion: Cloud Computing and the New Role of the IT manager

Read Part 1 and Part 2 (IaaS) and Part 3 (SaaS) here.

In the previous entries we discussed the possible impact of IaaS (Infrastructure as a Service), SaaS (Software a as a Service) and even briefly PaaS (Platform as a Service) on the role of our Cloud IT Manager separately.

It is, however, important to realize these three models are not happening separately; they are all happening at the same time and as result are influencing each other. As all three models are delivered "as a service", vendors are preparing themselves to play their role in 1, 2 or even all 3 of these markets. Will our Cloud IT Manager only be a consumer of services provided by these vendors or will he retain other responsibilities as well? Sourcing services will certainly be a core activity, not only for end user services (like CRM) but also for IT services like Infrastructure, security and support as a service.  Before reaching a preliminary conclusion about our IT manager's future role, one of the questions I'd like to ask is:


Will a Cloud IT Manager be a more Lean IT manager?
Connecting Cloud Computing and Lean IT may at first glance seem farfetched, but both Cloud Computing and Lean IT are leveraging the concept that mass produced is almost always cheaper than custom made. Cloud Computing offers mass produced standardized services to millions of users, and as a result monthly amounts per user can be relatively low. The proverbial Ford Model T was all about using standardization to drive cost down - any color as long as it is black! Toyota perfected Lean manufacturing to be able to offer choice at affordable cost. They did so by using highly standardized components and combining these into unique, desirable automobiles, by using standardized processes in the last phases of their manufacturing process.

More on the relationship between Cost and Cloud at a later date, but at minimum, what our Cloud IT manager can do today is use the Lean IT mantra of Maximizing Value (only do what adds value to the end customer) and Minimizing Waste (eliminating steps that do not add value) to guide his  current decisions on Cloud Computing. Just take any cloud proposal and evaluate it against these two criteria.  More long term I'd like to think that a Lean IT approach will help our Cloud IT Manager to combine standardized low-cost cloud services, into unique desirable and differentiating - customer relevant - services.

This last sentence sounds a bit too much like brochure talk, so let's explore this a bit further: Imagine a sporting goods manufacturer that traditionally ran a planning application to manage its logistical operations. This manufacturer outsourced most of its manufacturing to third parties. It may however still offer this planning application to help this "Extended Enterprise" go to market more efficiently than its competitors. Or one could think of an electronics manufacturer that differentiates itself with "unmatched customer service". This manufacturer runs a return-and-repair management system even though 90% of the repairs and returns are handled by third parties.  The traditional idea that internal applications are intended primarily for internal staff is increasingly no longer sustainable. A number of forward thinking companies therefore no longer provide their business applications (exclusively) on their own network. They take their applications and offer these on the Internet as a service. In some sense they have become cloud service providers, like a bank offering home banking or a travel agent offering online booking to its business customers. In some organizations the synergy between the original activities and providing the service makes them more competitive, others may at some point spin off this new activity as a new venture, while for some running the service is all they will be doing (having outsourced manufacturing, logistics, design, etc.). Our Cloud IT Manager is no longer just aligned or even integrated with the business, he is becoming the business.

Reaching conclusions on Cloud Computing is not easy. To some the whole cloud thing may be a bit overwhelming, providing yet more acronyms and complexity; to others it may seem the best idea since sliced bread. IT magazines continue to talk almost exclusively about Cloud Computing, as if there is nothing else left to invest in. For larger organizations Gartner disagrees with that and recently predicted that through 2012, IT will invest more in private than public cloud providers. Last month the US government announced a major many billion dollar large cloud computing initiative, while at the same time in Europe the Dutch Government basically forbids any use of the Cloud by government.

So when and where should your organization start?  Several organizations have started building Private Clouds. Not as a pilot, but as a first real project. Disentangling existing applications is way too expensive and labor intensive to just have a look; you need to build a business case. Others have started with SaaS for some less business critical applications (somehow CRM and sales force automation still seem to classify as such).  If you are serious about engaging with the business I would encourage you to investigate some PaaS platforms (like Force.com) and some technology for connecting Cloud and non Cloud applications (like Dutch based "Cloud Orchestrator" Cordys).

But no matter what you decide to do first; deployment will be more successful if you have a relative high level of maturity in your existing processes. Cloud Computing offers more options, more flexibility, more opportunities for efficiency and automation. But just like in the past: automating chaos will only give you one thing: automated chaos. If this four part blog only gave you one insight, I hope that it is that frameworks like ITIL and COBIT with their best practices for service portfolio management, security and risk management, configuration and asset management. etc.  are crucial to our Cloud IT Manager's chances of success, now maybe more than ever.

Thursday, October 22, 2009

Part 3: SaaS and the New Role of the IT Manager

Read Part 1 and Part 2 here.

Cloud purists would argue that a true Cloud IT organization exclusively uses services (SaaS) and owns no software, let alone platforms or infrastructure. And if these purists started a brand new organization today, they might have a point, at least until their first takeover or merger. This not having an installed base, allegedly enabled God to create the world in six days, but just for the sake of argument, let's examine what the responsibilities of our Cloud IT Manager would be in such a green pasture, pure SaaS environment.

First thing that comes to mind is the service or application portfolio. Our Cloud IT Manager will need to be involved with selecting which applications and services the organization will use. Not because he feels users need to ask him (he may feel that way, but the users most likely won't) but simply because he will be held responsible for any associated risks. What if the vendor goes belly up? What if the vendor's data center burns down? What if the vendor uses his market power to increase his prices beyond what is reasonable? Vendor Lock-in has plagued us for too long; let's make sure we prevent Cloud lock-in while we still can. So if nothing else our Cloud IT manager will need to provide a disaster recovery and exit strategy for each application. Portfolio Management suddenly becomes his core business.

Now our Cloud IT Manager monitors the portfolio, he is also the best person to offer a catalog of available approved Cloud Applications (one recent and highly visible example of this approach is apps.gov). And of course our Cloud IT Manager will be involved with rolling out (implementing) new services throughout the organization. His portfolio perspective will help him oversee the project and program management of these organizational change efforts. Having a view of both the pipeline of new services and the catalog of available services enables him to calculate, manage and monitor the integral cost of these services. All is supported by ITIL processes like Service Portfolio and Catalog Management, that were further defined in the most recent incarnation of ITIL, but were basically already foreseen in earlier versions.

The next topic to discuss has been the core part of ITIL for years: Support. If our Cloud IT Manager's organization uses ten different SaaS applications from five different vendors, does he want his users to go to each individual vendor for support, entering their issues in many different places. Apple reportedly offered 10.000 Macbooks to a corporate client with as recommended support procedure: "users visiting the Apple Store and lining up to talk to an Apple Guru on duty". Would your organization be ready for that? Or do we keep first line support under one roof, either in-house or via a SaaS Service Desk.

But our Cloud IT Manager responsibilities do not stop here. If his organization uses CRM from one vendor and ERP from another vendor, our Cloud IT manager would be expected to connect or integrate these two. In fact: "connectability" may need to be the prime criteria for selecting these vendors in the first place. Balancing the need for integration with the risk of vendor lock-in becomes a core capability of our Cloud IT Manager. Connecting business processes across different (cloud and none-cloud) applications becomes essential (more about this later).

Aren't we forgetting something? Yes, Security! Security (or Risk) is the most cited reason organizations are not going with the public cloud yet (one reason our upcoming Cloud Academy starts off with a session called: Security First!). Good old COBIT is very suited to be used as guidance here. Security should be seen in a broad sense, from defining users to data protection and disaster recovery. In many cases the specific solutions to address these concerns can itself again be cloud services. For example an identity service provider can offer a cloud service to define users and offer a single sign-on experience. Single Sign on across cloud services is something our Cloud IT Manager probably wants to provide, if only to prevent users from putting sticky notes with all their different passwords at the bottom of their keyboards.

Cloud Security also includes protecting the organizations data. A common concern is Data Loss Protection/Prevention (DLP). So far most known data loss incidents were caused by memory sticks or laptops going astray, not by Cloud providers being hacked, but better to be safe than sorry. But also good old backup and recovery need renewed focus in a cloud environment.

Talking about Security and Risk management brings us to something like "cloud escrow". With traditional IT we get a compiled working copy of the software. In case the vendor goes out of business we can get a copy of the sources via escrow. This way we can still make changes to his software, for example for a new upcoming version of the underlying database or operating system. The typical timeframe between start and finish of such a procedure here is months.

How different for SaaS. If the vendor goes out of business today, the application stops working today. And even if the vendor has a service provider hosting the software, the curator (the new "owner" of the IP) may tell the hosting company to discontinue the service immediately in order to reduce cost or liability. May seem farfetched but there are examples of exactly that happening. To address this some SaaS vendors offer a copy off their working code and a regular backup of the customer's data. That is all fine and good, but our Cloud IT manager better be able to recover the service in a reasonable time frame. Reasonable can vary from a couple of days to a couple of minutes.

It will be clear that our Cloud IT manager can only accommodate this if he has automated this procedure and tested it regularly! So do we still need a hibernating datacenter in the basement? Better not, as this would eliminate most of the cost savings from going cloud. We could cater for this recovery again by using the Cloud, for example by mandating that the cloud provider regularly delivers a set of tested images that can be automatically deployed on Amazon or another IaaS provider within an hour. The early adopter will need to negotiate this himself, while late adopters will have the benefit of this being offered as standard feature by the service vendor or by a third party. Having a good understanding of the portfolio (risks, cost, benefits, and criticality) will help our Cloud IT Manager to make the right decisions and set the right priorities.

So even with 100% SaaS our Cloud IT Manager still has an important role to play. But did we not say in the earlier part of this blog that with SaaS our Cloud IT Manager may not even be aware of which cloud applications the users are deploying? How can he monitor, manage and secure a portfolio he does not even see. There is no simple answer here. One aspect he could monitor however is his network. Appropriate network and security tooling could tell our Cloud IT Manager - by interpreting the network traffic - what URLs (applications) are visited or even what typical response times are.

In the distant future, however, it becomes more unlikely that users will be accessing all their applications via a corporate network as on the one hand application to application communication happens directly between virtual machines (bypassing the network) while users maybe no longer accessing their applications primarily via corporate network but more and more directly through public networks such as their home fiber connection or free wireless at their office campus or local starbucks or from the back of a commercial airliner. Would we require them to VPN first to the corporate network and then visit these applications from there? Not likely as this may significantly decrease speed and increase cost, especially with rich content like video and 3D. Or can we put something on their access device to monitor their behavior. Also not likely as these devices may be of the shelf iPhones or netbooks, with preconfigured and prepaid 3G access build in. Welcome to the wonderful world of consumerisation, a trend going hand in hand with Cloud Computing. More on this in a later blog.

In general one could say our Cloud IT manager may need to learn to use the carrot more than the stick. Simply blocking a service will less and less become an (accepted or viable) option. Off course our Cloud IT Manager can still set procedures and policies that users are asked to adhere to, like the US Army is contemplating with regard to "personal" and/or "off-duty" use of facebook and twitter. Or more forensically he could "follow the money" by asking accounting to monitor (credit card) payments to unapproved cloud service providers. A more positive approach is to make the use of approved services significantly easier, for example by offering a catalog of prepaid services, all under single sign-on. Also he can agree with any cloud providers he has contracts with to give (real time) insight into usage and service levels using standardized reports and reporting API's.

In my next blog post: Conclusions on the role of the IT Manager: is a Cloud IT Manager also a more Lean IT Manager?

Sunday, October 18, 2009

Part 2: IaaS and the New Role of the IT manager

Read Part 1 here.

How does Infrastructure as a Service (IaaS) impact the role of our Cloud IT Manager? Well, first of all, he will need to learn some new skills, the first one being virtualization management. Second, to have any chance of deploying his current intertwined spaghetti of applications into the cloud he needs to find a method to disentangle these applications. Deploying virtualization on an in house infrastructure (an internal cloud) can be a very workable catalyst here. Also he needs to find a way to offer his applications just as cost effective and scalable as "competing" SaaS providers. Again virtualization may be the way to do so.  Does this mean virtualization is all that matters? No, but without it, any "cloud" attempts are the same as plain old outsourcing, hosting or time sharing.

This virtualization needs to go hand in hand with Automation, together they form the building blocks of any cloud. A cloud environment implies dynamically scaling up and down capacity, based on demand. This is not possible fast enough if we create and configure our virtual machines manually.  That is where automation comes in. Doing automation without virtualization would not work, as the complexity of the provisioning tasks to be automated would be just too high.  This is not the only reason for deploying automation, apart from cost savings we want our Cloud IT manager to spend more time on business and less on technology, or if you like more time with users and less with plumbing,  as this is a crucial cloud benefit. 

Probably just as important as virtualization and automation for a successful cloud strategy is a reliable infrastructure for accessing the cloud (a.k.a. the network). Unlike with traditional PC applications, users of cloud applications are very unforgiving for any network outages or delays. A provider of SaaS bookkeeping applications in the Amsterdam area lost a significant number of his SME customers after a two-day outage of the major local Internet provider. Our Cloud IT manager is likely to lose his job if he allows for similar mishap in an enterprise environment. Together with Security this is one of the reasons why companies are starting today with an "Internal Cloud", even if their long term strategy is to leverage the public cloud (see question 4 in this Wall Street Journal Cloud pop quiz).

Another important thing to realize is that in the majority of cases "the Cloud", internal or external, will initially be an additional set of infrastructure. In most organizations the introduction of Mini's did not replace the Mainframe and neither did the WinTel space heaters replace all Unix Servers. Anyone who believes "the Cloud" will replace all in house systems, may also believe we can fix the climate problem by everybody driving electric cars by 2015. In addition companies will not have "one cloud". They will source cloud resources from multiple vendors, to optimize cost and balance risk. This means that, instead of reducing complexity, any cloud effort may initially increase complexity.

If you felt having good change processes and reliable configuration data was important in today's relatively stable datacenters, guess how crucial this will be is in a dynamic "provision to order" cloud environment, where virtualization enables a certain process to use different (virtual) resources every day, hour or even minute.  We all know the stories about IT departments that are afraid to switch off a certain server, because they have no idea what it does. Imagine this being a virtual server that we are paying for by the minute. We better understand which (business) processes this server is supporting, so we can decide whether it is safe to switch it off or not.

Helping understand and manage all this complexity if of course exactly where frameworks like ITIL and COBIT come in.  Ideally they help us to build an understanding of goals, risk, cost, configurations and especially interdependencies to offer a transparent view, also across these various infrastructure platforms.  But we need more than just a view. Ideally we want to be able to dynamically move applications to the (cloud) platform that is the most cost or energy efficient. This demands an integrated view across platforms, and although frameworks like ITIL and COBIT are infrastructure agnostic, most of us unfortunately deployed these frameworks with platform or department specific procedures and processes. Some integration of these procedures will need to be done. Let's make sure we do not create yet another set of cloud procedures to be filed next to our mainframe and windows procedures, especially as virtualization enables us to eventually move applications - more or less freely - across these platforms.

Last item to mention here separately is Risk. Last week the Times online addition spoke about Stormy times for cloud computing in the context of Microsoft and T-Mobile's Sidekick data loss mishap.  Dismissing cloud because of risk would be throwing out the baby with the bathwater. I know of no companies that build their own hard disks, because they do not trust hard disk vendors. They do take precautions:  they don't buy the cheapest, keep a backup, and have a recovery plan. That is why any cloud IT investments, not just IaaS, should go through the proper (IT) channels. So they can be screened for risk, security and cost issues. Risk management and Cloud Deployment have to go hand in hand and COBIT is a good way to connect them.

In my next blog post: SaaS and the role of our Cloud  IT Manager.