One can't help be see in the news these days all the uncertain weather, terrorist threats, and potential interrupted utilities. Just look at what happened in Chicago with traffic control for the airlines. No working DR plan there.
Contrary to popular belief, most companies and organizations categorize business continuity planning as risk aversion or an insurance policy. Although similar, business continuity planning comprises the steps, policies and procedures that are activated once a disaster has occurred. The object is to recover as quickly as possible so you can minimize downtime. Having a plan in place saves time, money, and possibly your entire company. So why so few have one? Test it? Interesting...........
Here are some favorite questions we get asked all the time:
What type of disasters could impact my business?
Last year, New England suffered through a tornado, hurricane and earthquake over a short period of time. Imagine those events ripping through your company. Beyond those obvious disasters, there are things like computer outages, fires, floods, cyber-attacks, viruses, and a whole host of situations that could affect your organization. Bottom line: Be prepared for the worst-case scenario: a loss of your entire organization, including the physical structure and personnel. Organizations always forget about the staff. Plan on your local staff not being available in your plan.
So if I have a major disaster, how does a business continuity plan help?
A business continuity plan will not prevent the earthquake, flood or most other types of disasters from happening. What a tested business continuity plan could do is potentially save you thousands, if not millions, of dollars in production losses, your reputation as a business, and your customers and clients. Here's one example. A large manufacturing client in Central Massachusetts says it cannot afford to be down for any length of time. They sometimes have two or three shifts working. It's estimated that if the company was shut down for just one week, it would lose $5 million in production. A clear, concise business continuity plan with policies and procedures could cut that downtime to two or three days. Also, if your competition and your clients find you've suffered a disaster and you cannot respond in a timely manner, your business begins to erode and your clients move to other companies. Once you lose the confidence of your clients, it's extremely difficult to recapture them. Engage the entire organization in the planning and testing. Their input is very important.
The business continuity plan is an organizational plan, and every employee has a stake in the planning, up keep and ownership. When the time comes to utilize that plan, it will take the entire team to ensure success.
Arnett Group not only can help you plan, but test, communicate, train and design your response to any situation.
Keep it positive!
Scott Arnett
scott@arnettservicesgroup.com
www.arnettservicesgroup.com
About Me
- Scott Arnett
- Scott Arnett is an Information Technology & Security Professional Executive with over 30 years experience in IT. Scott has worked in various industries such as health care, insurance, manufacturing, broadcast, printing, and consulting and in enterprises ranging in size from $50M to $20B in revenue. Scott’s experience encompasses the following areas of specialization: Leadership, Strategy, Architecture, Business Partnership & Acumen, Process Management, Infrastructure and Security. With his broad understanding of technology and his ability to communicate successfully with both Executives and Technical Specialists, Scott has been consistently recognized as someone who not only can "Connect the Dots", but who can also create a workable solution. Scott is equally comfortable playing technical, project management/leadership and organizational leadership roles through experience gained throughout his career. Scott has previously acted in the role of CIO, CTO, and VP of IT, successfully built 9 data centers across the country, and is expert in understanding ITIL, PCI Compliance, SOX, HIPAA, FERPA, FRCP and COBIT.
Wednesday, October 1, 2014
Tuesday, September 30, 2014
New Website
Change is always a good thing. This is a positive change for Arnett Group.
Please check out our new website.
www.arnettservicesgroup.com
Please check out our new website.
www.arnettservicesgroup.com
Thursday, February 6, 2014
Video Conference - Corporate Tool or Toy?
There are many advantages to having a Video Conference Solution - big or small organization. Even with more and more home based staff, the tool is essential. Communication, collaboration and effective meetings.
Video conferencing has long been thought of as the technology for the big guys, the ones handling mergers and acquisitions and the like - not something the average business could afford or make use of. In the last few years, the advancement in technology, bandwidth affordability, and the business capability drive has changed a few notions around this tool. Video conferencing is not only a viable technology for business of any size but a necessity.
The technology of many video solutions today will interface with other solutions, making it a more open use, and not just a closed or proprietary toolset. That opens the door to many more applications of use and leverage - more than just meetings.
We always hear many customers say that video conference solutions are to complicated, to expensive, and not worth the investment. We always say, stop, take a moment to see how far these solutions have come, how more user friendly they are, the simplicity and quality. Plus the cost has come down - there are more solutions on the market today.
Check out http://www.arnettservicesgroup.com/video-conferencing.html
In my opinion, this technology has gone from corporate toy to a real business tool. SMB can really benefit from the many new video solutions on the market today. Let's us not only show you, but build some process and organizational function around the tool to get your ROI.
Keep it positive!
Scott Arnett
www.arnettservicesgroup.com
Video conferencing has long been thought of as the technology for the big guys, the ones handling mergers and acquisitions and the like - not something the average business could afford or make use of. In the last few years, the advancement in technology, bandwidth affordability, and the business capability drive has changed a few notions around this tool. Video conferencing is not only a viable technology for business of any size but a necessity.
The technology of many video solutions today will interface with other solutions, making it a more open use, and not just a closed or proprietary toolset. That opens the door to many more applications of use and leverage - more than just meetings.
We always hear many customers say that video conference solutions are to complicated, to expensive, and not worth the investment. We always say, stop, take a moment to see how far these solutions have come, how more user friendly they are, the simplicity and quality. Plus the cost has come down - there are more solutions on the market today.
Check out http://www.arnettservicesgroup.com/video-conferencing.html
In my opinion, this technology has gone from corporate toy to a real business tool. SMB can really benefit from the many new video solutions on the market today. Let's us not only show you, but build some process and organizational function around the tool to get your ROI.
Keep it positive!
Scott Arnett
www.arnettservicesgroup.com
Friday, January 10, 2014
Your Bucket List
Start of another year, and reflection of the past year or years is always a good thing. Perhaps it will help you develop new resolutions for the upcoming year.
Most of us have seen the movie Bucket List, and if not, you should. It should not take getting sick to realize life has slipped by and you have not done all you want to do, but many times that is reality. We get busy in careers, chasing titles, financial goals, or even keeping up with the Jones and wake up one day, look in the mirror and say how did I get here. How did I get so old, when did the kids leave, why don't I have fun anymore, why am I working so hard, what is going to happen to me?
So what is on your Bucket List? Travel? NASCAR Event? Meeting someone? If we had a list we kept current and take the time to do something for ourselves each week, perhaps life will be more fulfilling. Working on your priority list each day should have something on there I would call "life" - lunch with a friend, dinner with your wife, golf or a child's event. If your entire list is nothing but work related - time to adjust.
We ask ourselves many times why did God allow me to get ill, or in an accident, why did this happen to me? Maybe he wants to slow you down so you take time to find what is important in life again. Perhaps, reset priority and find what truly is important in life.
Life truly does go by very fast, and each day brings something new, we don't know what, each new day is a true surprise. So make the best of it, keep it positive, and do something special for someone. When your time comes, be able to say I had a great life, and made a difference for others, and had great experiences.
Keep it positive!
Scott Arnett
scott@arnettservicesgroup.com
www.arnettservicesgroup.com
Most of us have seen the movie Bucket List, and if not, you should. It should not take getting sick to realize life has slipped by and you have not done all you want to do, but many times that is reality. We get busy in careers, chasing titles, financial goals, or even keeping up with the Jones and wake up one day, look in the mirror and say how did I get here. How did I get so old, when did the kids leave, why don't I have fun anymore, why am I working so hard, what is going to happen to me?
So what is on your Bucket List? Travel? NASCAR Event? Meeting someone? If we had a list we kept current and take the time to do something for ourselves each week, perhaps life will be more fulfilling. Working on your priority list each day should have something on there I would call "life" - lunch with a friend, dinner with your wife, golf or a child's event. If your entire list is nothing but work related - time to adjust.
We ask ourselves many times why did God allow me to get ill, or in an accident, why did this happen to me? Maybe he wants to slow you down so you take time to find what is important in life again. Perhaps, reset priority and find what truly is important in life.
Life truly does go by very fast, and each day brings something new, we don't know what, each new day is a true surprise. So make the best of it, keep it positive, and do something special for someone. When your time comes, be able to say I had a great life, and made a difference for others, and had great experiences.
Keep it positive!
Scott Arnett
scott@arnettservicesgroup.com
www.arnettservicesgroup.com
Monday, January 6, 2014
Cloud Computing Contracts and Cloud Outages
Happy New Year! I'm Bob Lankey, still filling in for Scott. I want to continue our series on Cloud Computing legal challenges and awareness. Today we are talking about Cloud Computing Contracts and Cloud Outages. Oh - those outages can have an impact on your operations, and potential financial portfolio.
The past few years have provided numerous examples of significant service interruptions at major providers. Amazon AWS service was down for 12 to 30 hours, affecting many companies that rely on Amazon services, including Foursquare, Hootsuite, Quora and Reddit. We saw the Sony PlayStation service was interrupted, being the victim of a massive hack attack. Most recently, there were outages with Microsoft’s Business Productivity Online Services, and Google’s Blogger service.
When a cloud service goes down, users lose access to their data; they may also be deprived from the processing capabilities that are provided as part of the cloud offering. In turn, they may be unable to provide services to their own customers, and be exposed to significant liability for failure to provide these services. When is a cloud user compensated for the loss of service, and to what extent? Let’s examine some cloud computing contracts and their provisions for cloud outages.
Service providers will disclaim their liability in their “Terms of Service,” or “Terms and Conditions.” This is usually achieved through Disclaimer of Warranty and Limitation of Liability provisions. Some contracts also include a limitation of damage provision.
The Disclaimer of Warranty states that the company makes no warranty with respect to the service, including, no warranty that the service will be available, or will not lose the data. Many times no warranty stated or implied around security.
For example, many entities -- including businesses -- have come to rely on YouTube to publish information in video format. The YouTube service is provided free of charge, and is funded through the advertising revenues that are generated from displaying ads related to the content being viewed.
The YouTube Terms of Service Disclaimer of Warranty provision (section 9) states:
YOU AGREE THAT YOUR USE OF THE SERVICES SHALL BE AT YOUR SOLE RISK. …. YOUTUBE …. DISCLAIM [S] ALL WARRANTIES, EXPRESS OR IMPLIED, IN CONNECTION WITH THE SERVICES …. YOUTUBE …. ASSUMES NO LIABILITY OR RESPONSIBILITY FOR …. (IV) ANY INTERRUPTION OR CESSATION OF TRANSMISSION TO OR FROM OUR SERVICES, (IV) ANY BUGS, VIRUSES, TROJAN HORSES, OR THE LIKE WHICH MAY BE TRANSMITTED TO OR THROUGH OUR SERVICES BY ANY THIRD PARTY ….
Limitation of Liability provisions are intended to limit the scope of liability in terms of the nature of the liability, such as liability for direct or consequential damages, or liability for negligence. Limitation of Damages provisions limit the dollar amount for any liability, and state the maximum amount of damages for which the provider might be responsible. For example, the YouTube Terms of Service Limitation of Liability provision (section 10) states in part:
IN NO EVENT SHALL YOUTUBE …. BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL ….. DAMAGES …. RESULTING FROM …. (IV) ANY INTERRUPTION OR CESSATION OF TRANSMISSION TO OR FROM OUR SERVICES, (IV) ANY BUGS, VIRUSES, TROJAN HORSES, OR THE LIKE, WHICH MAY BE TRANSMITTED TO OR THROUGH OUR SERVICES BY ANY THIRD PARTY ….
In other words, whether you have uploaded a clip of last Sunday’s picnic, or the installation instructions for a sophisticated piece of equipment that your business sells, YouTube will not compensate you if its network goes down or is attacked. There will be no compensation for loss of service or for loss or corruption of the data. And no compensation for the loss of business if your customers return their purchases because they could not access the installation instructions and were unable to install the products they purchased from you.
Thus, while using a free service is financially attractive, this is true only to the extent that the service operates without problems. If there is any loss of connection, processing capability or data -- there may be significant consequences for the users of these services. The service provider will not compensate for any of these losses. As the saying goes, “There is no such thing as a free lunch.”
In addition, if a virus passed through by use of this service and impacts your operations or your customers operation, the cloud provider is not responsible as stated in the contract. Worth the risk?
In order to find out what terms a cloud service provider offers to address a service interruption, you should look at the contract for these services, which may be found in several documents. First, look at the Services Agreement. This is usually the main agreement that defines the terms and conditions for access to the service. There, you may find a provision that describes the cloud provider’s commitment to provide continuous -- or almost continuous -- service.
For example, the Salesforce.com Master Services Agreement describes the company’s commitment to provide services 24 hours a day (see Section 4.1), except for planned downtime and a number of specific circumstances out of the company’s control, such as denial-of-service attacks. The company also makes a commitment to protect the security, confidentiality and integrity of the user’s data (see Section 4.2). This is key statement in regards to the commitment to security.
Some companies supplement their general terms and conditions with a separate Service Level Agreement (SLA) For example, in addition to its service agreement, Rackspace Cloud Terms of Service, Rackspace uses several SLAs.. The Rackspace Cloud Servers SLA provides:
Network
We guaranty our data center network will be available 100% of the time in any given monthly billing period, excluding scheduled maintenance. Make sure you understand their BCP/DR architecture and process/plan.
The document defines “scheduled maintenance” as “maintenance that is announced at least ten business days in advance, and that does not exceed sixty minutes in any calendar month.” There is no explanation of what happens if “scheduled maintenance” needs to take more than sixty minutes in a calendar month. Since this does not fit under the definition of “scheduled maintenance,” what is it?
The basic result is the same in both contract structures (i.e., single services agreement or services agreement combined with an SLA). If the service were interrupted, one or several of these clauses -- in the Services Agreement or in the SLA -- would be the basis for defining the bargain between the two parties.
Some contracts are very specific about the way the cloud provider will compensate the client for the damages resulting from a service interruption. For example, the Rackspace Cloud Servers SLA provides:
Credits
If we fail to meet a guaranty stated above, you will be eligible for a credit. Credits will be calculated as a percentage of the fees for the Cloud Servers™ adversely affected by the failure for the current monthly billing period during which the failure occurred (to be applied at the end of the billing cycle), as follows:
Network: Five percent (5%) of the fees for each 30 minutes of network downtime, up to 100% of the fees. …
Limitations
…. This Service Level Guaranty is your sole and exclusive remedy for Cloud Servers™ unavailability. So make sure you understand that. You should consult with your legal staff on this important part of the agreement.
Note that the compensation will only be for the loss of service, and will amount only to a percentage of your monthly service fee. There is no compensation for the loss of data, business, reputation or other loss. These terms are consistent with what is generally offered in the industry, but does not mean you should just accept it for your business. Do your homework, and find what risks the business is willing to take.
Read slowly and carefully. Most of these clauses provide some compensation for the unavailability of the services, typically as a percentage of the monthly fee, but not much else.
Ensure the method of calculation is clearly defined. For example, what constitutes “downtime”? How is the duration of service interruption computed? Do intermittent failures count as “downtime”? For example, if the service is up for one minute, down for one minute, and again, up and down for one minute at a time, is the interruption computed as the total of the periods when the system is down? Or is it the entire time when the service is so unreliable that processing is stalled or interrupted?
And, there are more complex questions. For example, is a cloud outage caused by a hacking circumstance out of the control of the service provider, and should therefore result in no liability? Or was the hacking possible due to gross negligence, and failure to install commonly known safeguards? This brings up my security essentials - and make sure your clearly define your expectations around security, safeguards and data protection.
You should also understand that, unless there has been a negotiated contract with clear and specific commitments, there will be no compensation for the loss of data or the loss of business. The cloud provider is furnishing only a specific service, such as hosting and computing. It has no way to know whether the data in its custody are critical company secrets or sensitive personal data. In addition, the cloud services are usually not priced to address the nature of the data being hosted or processed. If the agreement pertains to a certain volume of data, all that counts is just that: the volume of data stored or processed. There is no room for distinguishing between “regular data” and “highly sensitive data.”
Thus, if your data matter to your business, are critical to your operations or are the lifeline to your activities, make sure you understand the risks of cloud computing. Consider redundant systems, local storage and other technical or physical means to ensure business continuity, even when the cloud is out of service. This again brings up the fact that Business Continuity, Disaster Recovery and Security is still your responsibility. You have to ensure you have a plan, your contract covers what you need it to cover and that the business understands all the risks.
There is no perfect, infallible cloud service. Interruptions and downtime are bound to happen, whether they are caused by a natural event (e.g., an equipment break-down) or by a man-made one (e.g., a breach of security or a denial-of-service attack). Users and cloud service providers need to be clear on what happens when there is an interruption in the service. Any uncertainty in the terms for compensating the customer for service interruptions and downtime will only cause problems when such cloud outages occur. Clarity will save time, money and aggravation to both parties if these terms are adequately defined in the contract for these services. Don't accept the standard contract, make sure the contract fits your business needs, and risk acceptance.
At the end of the day, any outage with a cloud service provider can have significant impacts to your business, and working with a 3rd party can be frustrating. Make sure the contract clearly states all the expectations, commitments, deliverables, and compensation. The contract should cover "normal" operations as well as those unexpected incidents. Take it serious - it is your data.
Best regards
Bob
bob.lankey@arnettservicesgroup.biz
www.arnettservicesgroup.com
The past few years have provided numerous examples of significant service interruptions at major providers. Amazon AWS service was down for 12 to 30 hours, affecting many companies that rely on Amazon services, including Foursquare, Hootsuite, Quora and Reddit. We saw the Sony PlayStation service was interrupted, being the victim of a massive hack attack. Most recently, there were outages with Microsoft’s Business Productivity Online Services, and Google’s Blogger service.
When a cloud service goes down, users lose access to their data; they may also be deprived from the processing capabilities that are provided as part of the cloud offering. In turn, they may be unable to provide services to their own customers, and be exposed to significant liability for failure to provide these services. When is a cloud user compensated for the loss of service, and to what extent? Let’s examine some cloud computing contracts and their provisions for cloud outages.
Free cloud computing contracts
If a service provided at no cost goes down, is interrupted or is not available for any reason, usually users do not receive any compensation for the loss of availability, loss of data or other loss. The business rationale is if the service is provided for no fee, there is no financial loss for the user.Service providers will disclaim their liability in their “Terms of Service,” or “Terms and Conditions.” This is usually achieved through Disclaimer of Warranty and Limitation of Liability provisions. Some contracts also include a limitation of damage provision.
The Disclaimer of Warranty states that the company makes no warranty with respect to the service, including, no warranty that the service will be available, or will not lose the data. Many times no warranty stated or implied around security.
For example, many entities -- including businesses -- have come to rely on YouTube to publish information in video format. The YouTube service is provided free of charge, and is funded through the advertising revenues that are generated from displaying ads related to the content being viewed.
The YouTube Terms of Service Disclaimer of Warranty provision (section 9) states:
YOU AGREE THAT YOUR USE OF THE SERVICES SHALL BE AT YOUR SOLE RISK. …. YOUTUBE …. DISCLAIM [S] ALL WARRANTIES, EXPRESS OR IMPLIED, IN CONNECTION WITH THE SERVICES …. YOUTUBE …. ASSUMES NO LIABILITY OR RESPONSIBILITY FOR …. (IV) ANY INTERRUPTION OR CESSATION OF TRANSMISSION TO OR FROM OUR SERVICES, (IV) ANY BUGS, VIRUSES, TROJAN HORSES, OR THE LIKE WHICH MAY BE TRANSMITTED TO OR THROUGH OUR SERVICES BY ANY THIRD PARTY ….
Limitation of Liability provisions are intended to limit the scope of liability in terms of the nature of the liability, such as liability for direct or consequential damages, or liability for negligence. Limitation of Damages provisions limit the dollar amount for any liability, and state the maximum amount of damages for which the provider might be responsible. For example, the YouTube Terms of Service Limitation of Liability provision (section 10) states in part:
IN NO EVENT SHALL YOUTUBE …. BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL ….. DAMAGES …. RESULTING FROM …. (IV) ANY INTERRUPTION OR CESSATION OF TRANSMISSION TO OR FROM OUR SERVICES, (IV) ANY BUGS, VIRUSES, TROJAN HORSES, OR THE LIKE, WHICH MAY BE TRANSMITTED TO OR THROUGH OUR SERVICES BY ANY THIRD PARTY ….
In other words, whether you have uploaded a clip of last Sunday’s picnic, or the installation instructions for a sophisticated piece of equipment that your business sells, YouTube will not compensate you if its network goes down or is attacked. There will be no compensation for loss of service or for loss or corruption of the data. And no compensation for the loss of business if your customers return their purchases because they could not access the installation instructions and were unable to install the products they purchased from you.
Thus, while using a free service is financially attractive, this is true only to the extent that the service operates without problems. If there is any loss of connection, processing capability or data -- there may be significant consequences for the users of these services. The service provider will not compensate for any of these losses. As the saying goes, “There is no such thing as a free lunch.”
In addition, if a virus passed through by use of this service and impacts your operations or your customers operation, the cloud provider is not responsible as stated in the contract. Worth the risk?
Paid cloud computing contracts
If the service is provided for a fee, the terms of use of the service will usually include provisions similar to those discussed above. However, this time, these provisions will usually include some commitment from the service provider, and some form of compensation if there are deficiencies in the services, such as an interruption. In most cases, however, this compensation is strictly limited. Do not count on being compensated for the loss of business resulting from service interruption.In order to find out what terms a cloud service provider offers to address a service interruption, you should look at the contract for these services, which may be found in several documents. First, look at the Services Agreement. This is usually the main agreement that defines the terms and conditions for access to the service. There, you may find a provision that describes the cloud provider’s commitment to provide continuous -- or almost continuous -- service.
For example, the Salesforce.com Master Services Agreement describes the company’s commitment to provide services 24 hours a day (see Section 4.1), except for planned downtime and a number of specific circumstances out of the company’s control, such as denial-of-service attacks. The company also makes a commitment to protect the security, confidentiality and integrity of the user’s data (see Section 4.2). This is key statement in regards to the commitment to security.
Some companies supplement their general terms and conditions with a separate Service Level Agreement (SLA) For example, in addition to its service agreement, Rackspace Cloud Terms of Service, Rackspace uses several SLAs.. The Rackspace Cloud Servers SLA provides:
Network
We guaranty our data center network will be available 100% of the time in any given monthly billing period, excluding scheduled maintenance. Make sure you understand their BCP/DR architecture and process/plan.
The document defines “scheduled maintenance” as “maintenance that is announced at least ten business days in advance, and that does not exceed sixty minutes in any calendar month.” There is no explanation of what happens if “scheduled maintenance” needs to take more than sixty minutes in a calendar month. Since this does not fit under the definition of “scheduled maintenance,” what is it?
The basic result is the same in both contract structures (i.e., single services agreement or services agreement combined with an SLA). If the service were interrupted, one or several of these clauses -- in the Services Agreement or in the SLA -- would be the basis for defining the bargain between the two parties.
Some contracts are very specific about the way the cloud provider will compensate the client for the damages resulting from a service interruption. For example, the Rackspace Cloud Servers SLA provides:
Credits
If we fail to meet a guaranty stated above, you will be eligible for a credit. Credits will be calculated as a percentage of the fees for the Cloud Servers™ adversely affected by the failure for the current monthly billing period during which the failure occurred (to be applied at the end of the billing cycle), as follows:
Network: Five percent (5%) of the fees for each 30 minutes of network downtime, up to 100% of the fees. …
Limitations
…. This Service Level Guaranty is your sole and exclusive remedy for Cloud Servers™ unavailability. So make sure you understand that. You should consult with your legal staff on this important part of the agreement.
Note that the compensation will only be for the loss of service, and will amount only to a percentage of your monthly service fee. There is no compensation for the loss of data, business, reputation or other loss. These terms are consistent with what is generally offered in the industry, but does not mean you should just accept it for your business. Do your homework, and find what risks the business is willing to take.
Tips for navigating cloud contract clauses
Before entering into a contract for cloud computing or similar services, review carefully its clauses. They will be essential if the service is interrupted, and the user looks for compensation for the harm or losses resulting from the interruption.Read slowly and carefully. Most of these clauses provide some compensation for the unavailability of the services, typically as a percentage of the monthly fee, but not much else.
Ensure the method of calculation is clearly defined. For example, what constitutes “downtime”? How is the duration of service interruption computed? Do intermittent failures count as “downtime”? For example, if the service is up for one minute, down for one minute, and again, up and down for one minute at a time, is the interruption computed as the total of the periods when the system is down? Or is it the entire time when the service is so unreliable that processing is stalled or interrupted?
And, there are more complex questions. For example, is a cloud outage caused by a hacking circumstance out of the control of the service provider, and should therefore result in no liability? Or was the hacking possible due to gross negligence, and failure to install commonly known safeguards? This brings up my security essentials - and make sure your clearly define your expectations around security, safeguards and data protection.
You should also understand that, unless there has been a negotiated contract with clear and specific commitments, there will be no compensation for the loss of data or the loss of business. The cloud provider is furnishing only a specific service, such as hosting and computing. It has no way to know whether the data in its custody are critical company secrets or sensitive personal data. In addition, the cloud services are usually not priced to address the nature of the data being hosted or processed. If the agreement pertains to a certain volume of data, all that counts is just that: the volume of data stored or processed. There is no room for distinguishing between “regular data” and “highly sensitive data.”
Thus, if your data matter to your business, are critical to your operations or are the lifeline to your activities, make sure you understand the risks of cloud computing. Consider redundant systems, local storage and other technical or physical means to ensure business continuity, even when the cloud is out of service. This again brings up the fact that Business Continuity, Disaster Recovery and Security is still your responsibility. You have to ensure you have a plan, your contract covers what you need it to cover and that the business understands all the risks.
There is no perfect, infallible cloud service. Interruptions and downtime are bound to happen, whether they are caused by a natural event (e.g., an equipment break-down) or by a man-made one (e.g., a breach of security or a denial-of-service attack). Users and cloud service providers need to be clear on what happens when there is an interruption in the service. Any uncertainty in the terms for compensating the customer for service interruptions and downtime will only cause problems when such cloud outages occur. Clarity will save time, money and aggravation to both parties if these terms are adequately defined in the contract for these services. Don't accept the standard contract, make sure the contract fits your business needs, and risk acceptance.
At the end of the day, any outage with a cloud service provider can have significant impacts to your business, and working with a 3rd party can be frustrating. Make sure the contract clearly states all the expectations, commitments, deliverables, and compensation. The contract should cover "normal" operations as well as those unexpected incidents. Take it serious - it is your data.
Best regards
Bob
bob.lankey@arnettservicesgroup.biz
www.arnettservicesgroup.com
Friday, December 20, 2013
Cloud Computing Legal Issues: Data Location
Welcome back to our series on Cloud Computing Legal Issues. I am fascinated on the speed that certain businesses want to move key business systems, data, and functions to the cloud without doing a risk assessment and legal review. It concerns me that it appears some business leaders are just following a hype trend and not doing their homework.
This post is about data location. You have a signed contract now with a cloud service provider, do you know where your data will be hosted? In a cloud computing environment, data and applications are hosted "in the cloud.” What that cloud is made of, and where its components are located, matters. However, ask a cloud service vendor where your data will be stored or processed, the typical answers will likely range from "well… hum ... in the cloud" to "we have servers everywhere, data moves around constantly" or "we cannot tell you for security reasons." Really? You better demand knowing in the contract. I sat in on a meeting a few weeks ago and heard a salesman from a top "cloud provider" say - you don't have to worry about that anymore, that is the beauty of the cloud. I choked on my coffee, and more so when the business leaders said, oh, ok.
As the custodian of confidential and valuable data -- personal or company information -- you need to know where data will be located at all times. In the cloud environment, location matters, especially from a legal standpoint. In the legal world, location is most frequently associated with jurisdiction. The concept of “jurisdiction” is associated with the power of a judge or government entity to assert authority over the persons or things involved in an action, and to make a decision about a specific issue or sets of facts.
Jurisdiction is not necessarily exclusive. Several countries or courts may have concurrent jurisdiction over a matter. Indeed, litigants frequently argue about who has jurisdiction over their dispute. In the cloud environment, where a piece of equipment is located may have significant consequences on the ability of a court or other government authority to assert jurisdiction over that piece of equipment, and, in the case of a server, over the data contained in that server.
If the cloud that hosts your data has servers in a foreign country, the laws of that foreign country may govern your data when stored in that server. As a result, many important foreign laws may govern your data (in addition to those of the United States). This even applies to your code that is being developed in a foreign country - proceed with caution and complete awareness.
Cloud computing legal issues: Data protection laws
Assume that Cloud X Service provides hosting, email and collaboration solutions to Arnett, a U.S. company with no operations abroad. Assume also that the Cloud X network includes servers located in a data center in the United Kingdom. Thus, Arnett as Cloud X’s customer ends up using data or servers that are in the U.K.
The Data Protection Act (1998) governs the protection of personal information that is processed in the U.K. Of course, the Data Protection Act applies to companies that do business in the U.K. However, that is not the extent of its reach. Under Section 5(1)(b) of the act,, the law also applies to a data controller that is not established in the U.K. or in any other European Economic Area state (EEA includes the European Union plus Lichtenstein, Norway, Iceland) but that “uses equipment in the United Kingdom for processing the data otherwise than for the purposes of transit through the United Kingdom.”
This means that if a foreign company uses equipment that is located in the U.K. to process personal data, the processing of the data must comply with the U.K. Data Protection Law, even if the company is not established, or does not do business in the U.K.. The same provision can be found in the data protection laws of the 30 EEA member states and other countries.
When a cloud service provider elects to install servers in the EEA or other countries with a similar data protection law, all data that is processed, stored or maintained on these servers are subject to the data protection laws of the country where the servers are located. These laws have extensive requirements, restrictions and prohibitions on what may or may not be done with personal data. They may require registrations with the country’s Data Protection Supervisory Authority; they may prohibit certain transfers of these data, and much more. Failure to comply may have serious consequences. It is your obligation to be aware, you can't outsource your responsibility - ignorance to the law is no defense.
Cloud computing legal issues: Government surveillance
In addition to foreign data protection laws, consider the possibility that a third party or a foreign government might want to have access to a cloud service server that holds your data. In principle, access by a third party, even a government, is restricted, and even the police or secret service may not have access to premises or equipment without appropriate authorization -- in the form of a search warrant or court order -- before being allowed to search a computer.
However, this is not the case everywhere. For example, if your data is stored on a server that is located in India, the server will be subject to the laws of India. India’s Information Technology Act of 2000 (as amended in 2009) governs many aspects of the protection and use of computers, networks, etc. Section 69 of India’s IT Act allows the Central Government to issue directions for the interception, monitoring and decryption of messages from any computer and other communication device for security reasons, for public order, to prevent the commission of any cognizable offense or to investigate any offense. Section 69B(1) grants the Central Government the power to authorize any agency of the government to monitor and collect traffic data or information generated, transmitted, received or stored on any computer. In both cases, there is no requirement for a court order or other permission, and no limitation to these powers. Plus I may add, it is not limited to just communications, things like data transfers such as proprietary code could be intercepted.
What information may be retained and preserved may also be dictated by the Indian government. Section 67C of the Information Technology Act requires companies to preserve and retain such information as may be specified, and for such duration, and in such manner and format as the central government may prescribe.
Thus, while the cloud may take advantage of the friendly business environment in a country, it may also subject equipment and data stored in this equipment to the monitoring and surveillance of the government in that country. The political influences may add additional risk to your company sensitive data. What is your risk as an organization?
Contracting tip
When negotiating your contract for cloud services, decide if knowing where your data is located is important to you. If it is, then try to limit the geographic area where your data will be stored or processed. The City of Los Angeles was able to obtain some restrictions in its contract with Computer Sciences Corp. and Google Inc. for email and other services. Some of the data will be stored only in the continental U.S.. See, Appendix J.1, Section 1.7 of the Professional Services Contract between Google and the City of Los Angeles, which provides:
1.7 Data Transfer. Google agrees to store and process Customer's email and Google Message Discovery (GMD) data only in the continental United States. As soon as it shall become commercially feasible, Google shall store and process all other Customer Data, from any other Google Apps applications, only in the continental United States. Google shall make commercially reasonable efforts to advise Customer when such data storage capability is made available. Notwithstanding the foregoing, Google may store and process Login Data in any country in which Google or its agents maintain facilities.
Cloud service providers want the freedom to move data to different servers for load balancing or to take advantage of the lower cost of utilities or personnel in different geographies. However, by doing so, they may inadvertently expose their customers’ data to the laws of countries other than those where the customer opted to operate. Plus, it is your data, you are responsible for the protection thereof, you can't outsource that responsibility, so take control and set the expectations and contractual requirements.
It may be that, in the future, countries that wish to attract foreign investments and data centers will carve out a niche from their data protection laws. However, currently, the black letter law in many countries may subject cloud users to the data protection requirements and other laws of the country where the servers are located.
One more note on data location - always include a disaster recovery section in all your contracts. Business Continuity and Disaster Recovery is very important part of many regulatory requirements. Location will play a part in those plans.
Happy Holidays!
Bob Lankey
bob.lankey@arnettservicesgroup.biz
www.arnettservicesgroup.com
This post is about data location. You have a signed contract now with a cloud service provider, do you know where your data will be hosted? In a cloud computing environment, data and applications are hosted "in the cloud.” What that cloud is made of, and where its components are located, matters. However, ask a cloud service vendor where your data will be stored or processed, the typical answers will likely range from "well… hum ... in the cloud" to "we have servers everywhere, data moves around constantly" or "we cannot tell you for security reasons." Really? You better demand knowing in the contract. I sat in on a meeting a few weeks ago and heard a salesman from a top "cloud provider" say - you don't have to worry about that anymore, that is the beauty of the cloud. I choked on my coffee, and more so when the business leaders said, oh, ok.
As the custodian of confidential and valuable data -- personal or company information -- you need to know where data will be located at all times. In the cloud environment, location matters, especially from a legal standpoint. In the legal world, location is most frequently associated with jurisdiction. The concept of “jurisdiction” is associated with the power of a judge or government entity to assert authority over the persons or things involved in an action, and to make a decision about a specific issue or sets of facts.
Jurisdiction is not necessarily exclusive. Several countries or courts may have concurrent jurisdiction over a matter. Indeed, litigants frequently argue about who has jurisdiction over their dispute. In the cloud environment, where a piece of equipment is located may have significant consequences on the ability of a court or other government authority to assert jurisdiction over that piece of equipment, and, in the case of a server, over the data contained in that server.
If the cloud that hosts your data has servers in a foreign country, the laws of that foreign country may govern your data when stored in that server. As a result, many important foreign laws may govern your data (in addition to those of the United States). This even applies to your code that is being developed in a foreign country - proceed with caution and complete awareness.
Cloud computing legal issues: Data protection laws
Assume that Cloud X Service provides hosting, email and collaboration solutions to Arnett, a U.S. company with no operations abroad. Assume also that the Cloud X network includes servers located in a data center in the United Kingdom. Thus, Arnett as Cloud X’s customer ends up using data or servers that are in the U.K.
The Data Protection Act (1998) governs the protection of personal information that is processed in the U.K. Of course, the Data Protection Act applies to companies that do business in the U.K. However, that is not the extent of its reach. Under Section 5(1)(b) of the act,, the law also applies to a data controller that is not established in the U.K. or in any other European Economic Area state (EEA includes the European Union plus Lichtenstein, Norway, Iceland) but that “uses equipment in the United Kingdom for processing the data otherwise than for the purposes of transit through the United Kingdom.”
This means that if a foreign company uses equipment that is located in the U.K. to process personal data, the processing of the data must comply with the U.K. Data Protection Law, even if the company is not established, or does not do business in the U.K.. The same provision can be found in the data protection laws of the 30 EEA member states and other countries.
When a cloud service provider elects to install servers in the EEA or other countries with a similar data protection law, all data that is processed, stored or maintained on these servers are subject to the data protection laws of the country where the servers are located. These laws have extensive requirements, restrictions and prohibitions on what may or may not be done with personal data. They may require registrations with the country’s Data Protection Supervisory Authority; they may prohibit certain transfers of these data, and much more. Failure to comply may have serious consequences. It is your obligation to be aware, you can't outsource your responsibility - ignorance to the law is no defense.
Cloud computing legal issues: Government surveillance
In addition to foreign data protection laws, consider the possibility that a third party or a foreign government might want to have access to a cloud service server that holds your data. In principle, access by a third party, even a government, is restricted, and even the police or secret service may not have access to premises or equipment without appropriate authorization -- in the form of a search warrant or court order -- before being allowed to search a computer.
However, this is not the case everywhere. For example, if your data is stored on a server that is located in India, the server will be subject to the laws of India. India’s Information Technology Act of 2000 (as amended in 2009) governs many aspects of the protection and use of computers, networks, etc. Section 69 of India’s IT Act allows the Central Government to issue directions for the interception, monitoring and decryption of messages from any computer and other communication device for security reasons, for public order, to prevent the commission of any cognizable offense or to investigate any offense. Section 69B(1) grants the Central Government the power to authorize any agency of the government to monitor and collect traffic data or information generated, transmitted, received or stored on any computer. In both cases, there is no requirement for a court order or other permission, and no limitation to these powers. Plus I may add, it is not limited to just communications, things like data transfers such as proprietary code could be intercepted.
What information may be retained and preserved may also be dictated by the Indian government. Section 67C of the Information Technology Act requires companies to preserve and retain such information as may be specified, and for such duration, and in such manner and format as the central government may prescribe.
Thus, while the cloud may take advantage of the friendly business environment in a country, it may also subject equipment and data stored in this equipment to the monitoring and surveillance of the government in that country. The political influences may add additional risk to your company sensitive data. What is your risk as an organization?
Contracting tip
When negotiating your contract for cloud services, decide if knowing where your data is located is important to you. If it is, then try to limit the geographic area where your data will be stored or processed. The City of Los Angeles was able to obtain some restrictions in its contract with Computer Sciences Corp. and Google Inc. for email and other services. Some of the data will be stored only in the continental U.S.. See, Appendix J.1, Section 1.7 of the Professional Services Contract between Google and the City of Los Angeles, which provides:
1.7 Data Transfer. Google agrees to store and process Customer's email and Google Message Discovery (GMD) data only in the continental United States. As soon as it shall become commercially feasible, Google shall store and process all other Customer Data, from any other Google Apps applications, only in the continental United States. Google shall make commercially reasonable efforts to advise Customer when such data storage capability is made available. Notwithstanding the foregoing, Google may store and process Login Data in any country in which Google or its agents maintain facilities.
Cloud service providers want the freedom to move data to different servers for load balancing or to take advantage of the lower cost of utilities or personnel in different geographies. However, by doing so, they may inadvertently expose their customers’ data to the laws of countries other than those where the customer opted to operate. Plus, it is your data, you are responsible for the protection thereof, you can't outsource that responsibility, so take control and set the expectations and contractual requirements.
It may be that, in the future, countries that wish to attract foreign investments and data centers will carve out a niche from their data protection laws. However, currently, the black letter law in many countries may subject cloud users to the data protection requirements and other laws of the country where the servers are located.
One more note on data location - always include a disaster recovery section in all your contracts. Business Continuity and Disaster Recovery is very important part of many regulatory requirements. Location will play a part in those plans.
Happy Holidays!
Bob Lankey
bob.lankey@arnettservicesgroup.biz
www.arnettservicesgroup.com
Thursday, December 19, 2013
Cloud Computing: Legal Issues
Many organizations are quickly running to the cloud, but who is taking the time to evaluate and review the legal issues that comes with this new technology offerings. I have spoken with several organizational legal teams to find out they are brought in after there is a problem, breach of contract or a change of heart. Perhaps, the legal review needs to be done up front.
Let's take a few minutes to talk about some of the key issues. The characteristics of cloud computing -- on demand self-service, elasticity, metered service or ubiquitous access -- make it look like a simple and casual operation, but cloud computing services present many legal issues. Organizations need to tread carefully and perform due diligence, this means bring the corporate attorney into the loop.
Cloud computing legal issues: data location
Organizations need to know where the data they’re responsible for – both personal customer data and corporate information -- will be located at all times. In the cloud environment, location matters, especially from a legal standpoint. I would also demand all your data is encrypted while at rest in the cloud.
Cloud computing legal issues result from where a cloud provider keeps data, including application of foreign data protection laws and surveillance. In my next post, learn about cloud computing legal issues stemming from data location, and how to avoid them.
Cloud computing contracts and cloud outages
When a cloud service goes down, users lose access to their data and therefore may be unable to provide services to their customers. When is a cloud user compensated for the loss of service, and to what extent? Users need to examine how cloud computing contracts account for cloud outages.
In a future post, learn how a cloud outage could negatively affect business and examines some cloud computing contracts and their provisions for cloud outages. You are still responsible for your Business Continuity Plan and Disaster Recovery Plan - you can not outsource that.
Cloud computing contracts: Tread carefully
Organizations must be careful with cloud computing contracts, according to a panel of lawyers at the RSA Conference 2011. Cloud computing contracts should include many data protection provisions, but cloud computing service providers may not agree to them.
In a future post, learn some advice on negotiating with cloud computing service providers and on legal considerations for organizations entering cloud service provider contracts, including data security provisions. I have found many service providers will push back on encryption demands, or even backup requirements. Make sure the contract and services agreement meet all YOUR business requirements, not theirs.
Ten key provisions in cloud computing contracts
When entering into a relationship with a cloud computing service provider, companies should pay attention to contract terms, security requirements and several other key provisions when negotiating cloud computing contracts.
In a future post, I will discuss cloud computing contracts and the ten key provisions that companies should address when negotiating contracts with cloud computing service providers. Have it in writing, including performance metrics, data ownership, and most important, the right to audit their facility and operations.
Developing cloud computing contracts
Cloud service relationships can be complicated. The use of cloud services could sacrifice an entity’s ability to comply with several laws and regulations and could put sensitive data at risk. Consequently, it’s essential for those using cloud computing services to understand the scope and limitations of the services they receive, and the terms under which these services will be provided.
In this series of posts, I will explain the critical considerations for cloud computing contracts in order to protect your organization as well as reviewing the critical steps and best practices for developing, maintaining and terminating cloud computing contracts. I will also give you advice on the terms and length of such contracts, and what your options are if you need to make a change due to performance.
In summary, not all Cloud Service providers are equal, and not all have your best interest in mind. After all, they are in this to make money, your money. Move to the cloud with caution, an open mind, and your legal affairs in order.
Happy Holidays
Bob Lankey
bob@arnettservicesgroup.biz
www.arnettservicesgroup.com
Let's take a few minutes to talk about some of the key issues. The characteristics of cloud computing -- on demand self-service, elasticity, metered service or ubiquitous access -- make it look like a simple and casual operation, but cloud computing services present many legal issues. Organizations need to tread carefully and perform due diligence, this means bring the corporate attorney into the loop.
Cloud computing legal issues: data location
Organizations need to know where the data they’re responsible for – both personal customer data and corporate information -- will be located at all times. In the cloud environment, location matters, especially from a legal standpoint. I would also demand all your data is encrypted while at rest in the cloud.
Cloud computing legal issues result from where a cloud provider keeps data, including application of foreign data protection laws and surveillance. In my next post, learn about cloud computing legal issues stemming from data location, and how to avoid them.
Cloud computing contracts and cloud outages
When a cloud service goes down, users lose access to their data and therefore may be unable to provide services to their customers. When is a cloud user compensated for the loss of service, and to what extent? Users need to examine how cloud computing contracts account for cloud outages.
In a future post, learn how a cloud outage could negatively affect business and examines some cloud computing contracts and their provisions for cloud outages. You are still responsible for your Business Continuity Plan and Disaster Recovery Plan - you can not outsource that.
Cloud computing contracts: Tread carefully
Organizations must be careful with cloud computing contracts, according to a panel of lawyers at the RSA Conference 2011. Cloud computing contracts should include many data protection provisions, but cloud computing service providers may not agree to them.
In a future post, learn some advice on negotiating with cloud computing service providers and on legal considerations for organizations entering cloud service provider contracts, including data security provisions. I have found many service providers will push back on encryption demands, or even backup requirements. Make sure the contract and services agreement meet all YOUR business requirements, not theirs.
Ten key provisions in cloud computing contracts
When entering into a relationship with a cloud computing service provider, companies should pay attention to contract terms, security requirements and several other key provisions when negotiating cloud computing contracts.
In a future post, I will discuss cloud computing contracts and the ten key provisions that companies should address when negotiating contracts with cloud computing service providers. Have it in writing, including performance metrics, data ownership, and most important, the right to audit their facility and operations.
Developing cloud computing contracts
Cloud service relationships can be complicated. The use of cloud services could sacrifice an entity’s ability to comply with several laws and regulations and could put sensitive data at risk. Consequently, it’s essential for those using cloud computing services to understand the scope and limitations of the services they receive, and the terms under which these services will be provided.
In this series of posts, I will explain the critical considerations for cloud computing contracts in order to protect your organization as well as reviewing the critical steps and best practices for developing, maintaining and terminating cloud computing contracts. I will also give you advice on the terms and length of such contracts, and what your options are if you need to make a change due to performance.
In summary, not all Cloud Service providers are equal, and not all have your best interest in mind. After all, they are in this to make money, your money. Move to the cloud with caution, an open mind, and your legal affairs in order.
Happy Holidays
Bob Lankey
bob@arnettservicesgroup.biz
www.arnettservicesgroup.com
Tuesday, December 10, 2013
U.S. Tech Companies Ask Governments to Reform Surveillance Practices
U.S. Tech Companies Ask Governments to Reform Surveillance Practices - by now I think most of us have heard the news. Plus we have all heard of the many examples of US Surveillance Practices as it pertains to cell phones, emails, and the long list of actions.
Eight top tech companies in the U.S. have asked governments around the world to reform surveillance laws and practices, and asked the U.S. to take the lead. Should the US take the lead, or as being the largest surveillance organization have the lead?
AOL, Apple, Facebook, Google, LinkedIn, Twitter, Yahoo and Microsoft said Monday that they understand that governments need to take action to protect their citizens' safety and security, but "strongly believe that current laws and practices need to be reformed." Internet companies have been at the focus of disclosures through newspapers from June by former U.S. National Security Agency contractor, Edward Snowden, which suggested that the agency had real-time access to content on the servers of some Internet companies and was also tapping into the communications links between the data centers of Yahoo and Google.
The companies deny complicity in the NSA's dragnet surveillance, and some have asked permission from the U.S. Foreign Intelligence Surveillance Court to disclose aggregate information on security requests for user data under the Foreign Intelligence Surveillance Act.
The latest move appears to be one of a number by the Internet companies to highlight that they are on the side of the user, and to bring pressure on governments, particularly of the U.S. Facebook, AOL, Apple, Google, Microsoft and Yahoo wrote in October to the chairman and members of a U.S. Committee on the Judiciary, demanding that the surveillance practices of the U.S. should be reformed to enhance privacy protections and provide "appropriate oversight and accountability mechanisms."
Then these tech companies are working on ways to encrypt traffic between data centers, users, and applications. So as the security and technology borders continue to shift, are we taking steps to make it more difficult for government agencies to protect us, and giving safe haven to terrorists? Where do you draw the line of balance between privacy, security, and national best interest.
I agree that the world has changed, and threats everyday have changed at both a national level and a personal level. Each of us has threats against us each day, credit card fraud, identity theft, email malware and the list goes on. We do risk management each day and may not realize it. So it is a very real topic for all of us to discuss and get involved with. Appropriate for these tech companies to get involved? Should there be an independent advisor board to influence Washington on this topic - perhaps independent IT experts?
I think we need to take our time, look at the right approach and proceed with caution. We are quickly loosing our freedoms, and that is a worry.
Keep it positive!
Scott Arnett
scott@arnettservicesgroup.com
www.arnettservicesgoup.com
Eight top tech companies in the U.S. have asked governments around the world to reform surveillance laws and practices, and asked the U.S. to take the lead. Should the US take the lead, or as being the largest surveillance organization have the lead?
AOL, Apple, Facebook, Google, LinkedIn, Twitter, Yahoo and Microsoft said Monday that they understand that governments need to take action to protect their citizens' safety and security, but "strongly believe that current laws and practices need to be reformed." Internet companies have been at the focus of disclosures through newspapers from June by former U.S. National Security Agency contractor, Edward Snowden, which suggested that the agency had real-time access to content on the servers of some Internet companies and was also tapping into the communications links between the data centers of Yahoo and Google.
The companies deny complicity in the NSA's dragnet surveillance, and some have asked permission from the U.S. Foreign Intelligence Surveillance Court to disclose aggregate information on security requests for user data under the Foreign Intelligence Surveillance Act.
The latest move appears to be one of a number by the Internet companies to highlight that they are on the side of the user, and to bring pressure on governments, particularly of the U.S. Facebook, AOL, Apple, Google, Microsoft and Yahoo wrote in October to the chairman and members of a U.S. Committee on the Judiciary, demanding that the surveillance practices of the U.S. should be reformed to enhance privacy protections and provide "appropriate oversight and accountability mechanisms."
Then these tech companies are working on ways to encrypt traffic between data centers, users, and applications. So as the security and technology borders continue to shift, are we taking steps to make it more difficult for government agencies to protect us, and giving safe haven to terrorists? Where do you draw the line of balance between privacy, security, and national best interest.
I agree that the world has changed, and threats everyday have changed at both a national level and a personal level. Each of us has threats against us each day, credit card fraud, identity theft, email malware and the list goes on. We do risk management each day and may not realize it. So it is a very real topic for all of us to discuss and get involved with. Appropriate for these tech companies to get involved? Should there be an independent advisor board to influence Washington on this topic - perhaps independent IT experts?
I think we need to take our time, look at the right approach and proceed with caution. We are quickly loosing our freedoms, and that is a worry.
Keep it positive!
Scott Arnett
scott@arnettservicesgroup.com
www.arnettservicesgoup.com
Monday, December 9, 2013
IOS: Designing the Information Advantage
Arnett Group has a partnership with IOS, and the teamwork between the two organizations has been fantastic. Imaging Office Systems (IOS) is a company that has had a single focus since 1973: document management. To IOS document management means scanning documents, installing and configuring imaging systems, offering professional services and consulting as well as a modern approach to off –site storage. As you see it does not mean copiers as IOS is about reducing paper not multiplying it.
Scanning…IOS is one of the largest scanning companies in the United States with four separate conversion centers all operating identically under the FDA’s Quality System 21-CFR-Part 820 converting over 5,000,000 images per month. We also offer business process scanning.
Imaging Systems…IOS has installed over 500 multi-user systems throughout the United States. IOS represents several imaging software products such as OnBase, FileBound and EMC. IOS performs the system design, implementation, customization, training and on-going support.
Professional Services…this group of programmers, developers and certified Project Managers has developed a national reputation for being able to handle difficult system conversions from older imaging systems, as well as creating unique workflows and integrations to host systems. Utilizing Arnett Group to provide systems, network and security services, it is a professional team for the customer.
Record Center Storage…putting a modern twist on box storage, IOS delivers back the requested files through secure on-line portals so the boxes never have to leave the record center both greatly reducing the cost of storage as well as improving the security of client information.
IOS has experience in multiple markets such as pharmaceuticals, manufacturing, medical, and financials, to name a few. Some of our clients with imaging systems and scanning solutions are names you may recognize: such as Eli Lilly, GE Engine Service, Northwestern Memorial Hospital, and Baxter Credit Union.
Reach out to Arnett Group and let us work with you on a secure and complete document management solution. We are very proud to be working with IOS!
Keep it positive!
Scott Arnett
scott@arnettservicesgroup.com
www.arnettservicesgroup.com
Scanning…IOS is one of the largest scanning companies in the United States with four separate conversion centers all operating identically under the FDA’s Quality System 21-CFR-Part 820 converting over 5,000,000 images per month. We also offer business process scanning.
Imaging Systems…IOS has installed over 500 multi-user systems throughout the United States. IOS represents several imaging software products such as OnBase, FileBound and EMC. IOS performs the system design, implementation, customization, training and on-going support.
Professional Services…this group of programmers, developers and certified Project Managers has developed a national reputation for being able to handle difficult system conversions from older imaging systems, as well as creating unique workflows and integrations to host systems. Utilizing Arnett Group to provide systems, network and security services, it is a professional team for the customer.
Record Center Storage…putting a modern twist on box storage, IOS delivers back the requested files through secure on-line portals so the boxes never have to leave the record center both greatly reducing the cost of storage as well as improving the security of client information.
IOS has experience in multiple markets such as pharmaceuticals, manufacturing, medical, and financials, to name a few. Some of our clients with imaging systems and scanning solutions are names you may recognize: such as Eli Lilly, GE Engine Service, Northwestern Memorial Hospital, and Baxter Credit Union.
Reach out to Arnett Group and let us work with you on a secure and complete document management solution. We are very proud to be working with IOS!
Keep it positive!
Scott Arnett
scott@arnettservicesgroup.com
www.arnettservicesgroup.com
Tuesday, December 3, 2013
VCE VBLOCK Systems
I had the opportunity to be involved in a side by side compare of the VCE VBLOCK System and a comparable solution from HP. While I like the VBLOCK solution, I have a hard time with the TCO of the solution.
The benefits of the VBLOCK solution is the all in one rack design and it is built together, tested, and delivered to the customer as a 1 rack solution. That has many benefits to many organizations, more so today with small IT teams in organizations. Plus the solution is made up of the leaders in the industry, EMC, VMware, Cisco and Intel. I also like the management tools that come with the solution, so overall, I give it a C+.
There are other solutions out there that offer same if not better all in one model, with great management tools, and support. More important with a better TCO over the life of the solution. I had a CIO ask me the other day about my thoughts on Cisco and where they are going. Still a leader in network hardware? While I think they are still a leader, they are no longer the only game in town, and there are some great network switches and equipment available from other manufactures. For the overall cost, I still like the HP pro curve for edge switches, small offices and such. I have a hard time to justify to a customer why spend all that money with Cisco to purchase and then year after year SmartNet costs. This applies to the VBLOCK solution.
Cisco has a great marketing machine, and while they make many claims regarding speed, performance, reliability, there is nothing here the other guys don't have. My recommendation is to do your homework, look at the cost, and look at what it is you are trying to solve and the capability you need to deliver.
Keep it positive!
Scott Arnett
www.arnettservicesgroup.com
The benefits of the VBLOCK solution is the all in one rack design and it is built together, tested, and delivered to the customer as a 1 rack solution. That has many benefits to many organizations, more so today with small IT teams in organizations. Plus the solution is made up of the leaders in the industry, EMC, VMware, Cisco and Intel. I also like the management tools that come with the solution, so overall, I give it a C+.
There are other solutions out there that offer same if not better all in one model, with great management tools, and support. More important with a better TCO over the life of the solution. I had a CIO ask me the other day about my thoughts on Cisco and where they are going. Still a leader in network hardware? While I think they are still a leader, they are no longer the only game in town, and there are some great network switches and equipment available from other manufactures. For the overall cost, I still like the HP pro curve for edge switches, small offices and such. I have a hard time to justify to a customer why spend all that money with Cisco to purchase and then year after year SmartNet costs. This applies to the VBLOCK solution.
Cisco has a great marketing machine, and while they make many claims regarding speed, performance, reliability, there is nothing here the other guys don't have. My recommendation is to do your homework, look at the cost, and look at what it is you are trying to solve and the capability you need to deliver.
Keep it positive!
Scott Arnett
www.arnettservicesgroup.com
Wednesday, November 27, 2013
WebHost XTC Has Grown!
Happy Thanksgiving Friends -
Let me also tell you about Arnett Services Group new focus on Mobile Application development. The new team is second to none. Top notch. Call today or go to: www.arnettservicesgroup.com.
Keep it Positive!
Scott Arnett
WebHost XTC is expanding! Customers are asking for creative
services, to be a full service creative digital firm to support their businesses,
big or small. Therefore, they have
created a new division called 1724 Designs.
1724 Designs is setup as the creative division of WebHost XTC. WebHost XTC
started as a custom ecommerce hosting company, and needed to expand into a full
creative digital firm. 1724 provides
full creative and marketing support for clients across the US. Their services include website design,
creative design, website development, ecommerce development and online
marketing services.
It is their goal to be responsive to customers’ needs and be a resource
for your online business activities. They want to be your web service
partner. Please check out their new
website:
www.1724designs.com
Let me also tell you about Arnett Services Group new focus on Mobile Application development. The new team is second to none. Top notch. Call today or go to: www.arnettservicesgroup.com.
Keep it Positive!
Scott Arnett
Thursday, September 26, 2013
Human Beings First
Following the news these days makes one frustrated with all the behaviors. Why do some people get so passionate about politics that they lose all human decency?... That story next….Last week, in the heat of the fight over defunding Obamacare, the communications chairman for the Democratic Party of Sacramento tweeted to an aide to Sen. Ted Cruz that he hoped her children “die from debilitating, painful and incurable diseases.” There were other, unrepeatable tweets, before the state party intervened and he took it back. But some people are immune to shame. After the Navy Yard shootings, an associate professor of journalism at the University of Kansas tweeted that he wished the children of NRA members would die in a mass shooting. It’s fine to hold strong opinions, but when you become so inflamed that you wish death on the children of anyone who disagrees with you, it’s hard to take your claim that you’re the enlightened one seriously.
By the way, that professor adamantly refused to take back his hateful comments, and University of Kansas officials stood behind him. That’s because colleges are defenders of free speech. Unless of course, it’s hate speech. That’s defined as advocating violence against any group that liberal professors LIKE. Make you sick?
How about in the technology field, do you get the sense that a former colleague or a direct report has strong opinions on something of the past that they wish you failure and will do what they can to facilitate failure? Are we not human beings first and should we not have the motto of "for the success of others?"
I encourage everyone to be engaged in the issues of today, and that includes technology. That engagement should be positive, constructive and respectful. Debate your views and opinion but do it in a manner that keeps you part of the solution. Like grandma said, think before you speak, words of wisdom we can all live with.
Keep it positive!
Scott Arnett
www.arnettservicesgroup.com
By the way, that professor adamantly refused to take back his hateful comments, and University of Kansas officials stood behind him. That’s because colleges are defenders of free speech. Unless of course, it’s hate speech. That’s defined as advocating violence against any group that liberal professors LIKE. Make you sick?
How about in the technology field, do you get the sense that a former colleague or a direct report has strong opinions on something of the past that they wish you failure and will do what they can to facilitate failure? Are we not human beings first and should we not have the motto of "for the success of others?"
I encourage everyone to be engaged in the issues of today, and that includes technology. That engagement should be positive, constructive and respectful. Debate your views and opinion but do it in a manner that keeps you part of the solution. Like grandma said, think before you speak, words of wisdom we can all live with.
Keep it positive!
Scott Arnett
www.arnettservicesgroup.com
Wednesday, September 25, 2013
BCP Plan Ready?
There are a few questions I get asked at every engagement with customers, is our Business Continuity Plan ready for any event? The first thing to discuss is when was the last time it was reviewed, updated and tested? The BCP Plan is not one thing you do, put on the shelf and it is ready to go whenever we need it. Organizations change throughout the year, technology changes, staff changes, and threats change. So you have to work on it throughout the year.
The one thing I like to do it is an audit of the plan. Take an audit questionnaire or template and walk through it with the management team, and based on those results, determine some focus areas. Ensure the plan is ready when needed, and that the plan is offsite as well.
One more recommendation, and that is staff training. You need to take the time to train your staff on the plan, what to do in the event of a crisis. Once the training is complete, test the plan and ensure everyone knows what to do. If you can not come to the office, you call this message hot line for instructions, you VPN into the office to work from home, you report in hourly, whatever the instructions need to be. Staff need to know, understand and be able to act as needed.
Senior Management needs to take this issue serious, and ensure their organization is ready for any event coming their way. Plan, Prepare and Test will make sure you are ready to execute as needed.
If you need help with your plan, reach out.
Keep it positive!
Scott Arnett
www.arnettservicesgroup.com
The one thing I like to do it is an audit of the plan. Take an audit questionnaire or template and walk through it with the management team, and based on those results, determine some focus areas. Ensure the plan is ready when needed, and that the plan is offsite as well.
One more recommendation, and that is staff training. You need to take the time to train your staff on the plan, what to do in the event of a crisis. Once the training is complete, test the plan and ensure everyone knows what to do. If you can not come to the office, you call this message hot line for instructions, you VPN into the office to work from home, you report in hourly, whatever the instructions need to be. Staff need to know, understand and be able to act as needed.
Senior Management needs to take this issue serious, and ensure their organization is ready for any event coming their way. Plan, Prepare and Test will make sure you are ready to execute as needed.
If you need help with your plan, reach out.
Keep it positive!
Scott Arnett
www.arnettservicesgroup.com
Friday, September 20, 2013
Cloud Services - Still A Good Deal?
Everyone is still talking about Cloud Services, and many organizations are making decisions on whether to put systems and data into the cloud or leave it in their own data center.
Let me tell you a little story. Ever have an internet connection from an ISP, which came with an email address from them? I think we all have and many still do, and nothing wrong with that. At some point though, some of these ISP companies passed all the management of these email addresses to Yahoo, where they became standard, free (advertising-supported) Yahoo webmail addresses in all but name – run on Yahoo servers, with the Yahoo front end. When the ISP Internet contract ended, the ISP email service carried on at Yahoo.
All this was fine until the ISP informed many customers that it would close the account and delete all the mail, contacts, etc. from a certain date unless they started to pay them money per month for a premium mail service - which they don't want.
So the question comes up who owns that data? Can they keep your data for ransom to get more fees from you? How hard will it be to move all your data to another service? Email is just one example of many scenarios. How about another potential - the cloud service provider goes out of business. Where is all your data now, and is it business critical data?
IT is the steward of the company data, but the business still owns that data. The business has to understand and assume some of the risk. My suggestion always is that IT still owns the backup of that data, even in the cloud. There are solutions out there that would pull down some of that data to your data center for safe keeping. You can't outsource your regulatory responsibility of the security of the data and availability.
Proceed with caution. Understand your new cloud partner, ensure your have all your questions answered and you clearly understand ownership of the data, backup of the data, and availability. Do the due diligence necessary to ensure you have a positive experience and get the results you are looking for.
Perhaps, your core systems and critical data is better left right in your own data center or private cloud. Develop a strategy that includes cloud, but where appropriate and at the right risk level.
Keep it Positive!
Scott Arnett
www.arnettservicesgroup.com
Let me tell you a little story. Ever have an internet connection from an ISP, which came with an email address from them? I think we all have and many still do, and nothing wrong with that. At some point though, some of these ISP companies passed all the management of these email addresses to Yahoo, where they became standard, free (advertising-supported) Yahoo webmail addresses in all but name – run on Yahoo servers, with the Yahoo front end. When the ISP Internet contract ended, the ISP email service carried on at Yahoo.
All this was fine until the ISP informed many customers that it would close the account and delete all the mail, contacts, etc. from a certain date unless they started to pay them money per month for a premium mail service - which they don't want.
So the question comes up who owns that data? Can they keep your data for ransom to get more fees from you? How hard will it be to move all your data to another service? Email is just one example of many scenarios. How about another potential - the cloud service provider goes out of business. Where is all your data now, and is it business critical data?
IT is the steward of the company data, but the business still owns that data. The business has to understand and assume some of the risk. My suggestion always is that IT still owns the backup of that data, even in the cloud. There are solutions out there that would pull down some of that data to your data center for safe keeping. You can't outsource your regulatory responsibility of the security of the data and availability.
Proceed with caution. Understand your new cloud partner, ensure your have all your questions answered and you clearly understand ownership of the data, backup of the data, and availability. Do the due diligence necessary to ensure you have a positive experience and get the results you are looking for.
Perhaps, your core systems and critical data is better left right in your own data center or private cloud. Develop a strategy that includes cloud, but where appropriate and at the right risk level.
Keep it Positive!
Scott Arnett
www.arnettservicesgroup.com
Thursday, September 12, 2013
New Phone System Challenges
It was with great pleasure to get invited to a breakfast meeting with a customer the other day. The pancakes sure hit the spot, but so did the conversation on technology.
Customer is frustrated with an old on premise phone system that no longer meets all the business needs. The CEO is tired of hearing all the complaints, and frustrations from the staff, and looks at me to say, what do we do? We need some call center features, some wireless phone features, and a better voice mail system. I hear and read all these options out there, but none of them make sense to me.
So I took out a piece of paper to start listing all the business requirements he could think of. My feedback to him was don't worry about budget yet or technology, but let's just list out all the capabilities you are looking for or your staff is asking for. Then we took that list and start to prioritize the list so we can match technology solutions to the wish list.
This quickly brings up the discussion of on premise solutions or cloud solutions. What are the benefits of both and challenges. For the SMB clients, the cloud voice solutions sure give them a lot of capability, and you can quickly have a voice solution for home based employees, ACD and other options that would otherwise be a great deal of hardware on premise.
I assured this CEO we can get them to where they need to be with the right technology solution. My point to him was to be open minded and look at all options. There are a lot of opinions out there, and confusion. Let's spend the time to work through the strategy and then approach the tactical with the right solution. Letting the voice experts sift through all the industry options and bring forward only that which matters will save the client time and money.
There are many great solutions on the market today, let us help you find the right solution for you at the right price.
Keep it positive!
Scott Arnett
scott@arnettservicesgroup.com
www.arnettservicesgroup.com
Customer is frustrated with an old on premise phone system that no longer meets all the business needs. The CEO is tired of hearing all the complaints, and frustrations from the staff, and looks at me to say, what do we do? We need some call center features, some wireless phone features, and a better voice mail system. I hear and read all these options out there, but none of them make sense to me.
So I took out a piece of paper to start listing all the business requirements he could think of. My feedback to him was don't worry about budget yet or technology, but let's just list out all the capabilities you are looking for or your staff is asking for. Then we took that list and start to prioritize the list so we can match technology solutions to the wish list.
This quickly brings up the discussion of on premise solutions or cloud solutions. What are the benefits of both and challenges. For the SMB clients, the cloud voice solutions sure give them a lot of capability, and you can quickly have a voice solution for home based employees, ACD and other options that would otherwise be a great deal of hardware on premise.
I assured this CEO we can get them to where they need to be with the right technology solution. My point to him was to be open minded and look at all options. There are a lot of opinions out there, and confusion. Let's spend the time to work through the strategy and then approach the tactical with the right solution. Letting the voice experts sift through all the industry options and bring forward only that which matters will save the client time and money.
There are many great solutions on the market today, let us help you find the right solution for you at the right price.
Keep it positive!
Scott Arnett
scott@arnettservicesgroup.com
www.arnettservicesgroup.com
Tuesday, September 10, 2013
Business Continuity - A GREAT Place to Start
I was recently asked to participate in a strategy session with a client on their IT infrastructure strategy. The CIO called and asked if I would come spend the day, and the driving question is, where should we go with infrastructure. So during the first hour of the session, I asked all the questions, and the big question is, what do you have for a BCP or DR plan? No one answered for the first few minutes, everyone had that blank look on their face. Not that uncommon I assured them, and said, that is a great place to start.
During the BCP definition stage, your infrastructure requirements start to take shape on the white board. If your business leaders and application owners are asking for high availability, no data loss, low recovery point goals, then you now have some requirements to define your infrastructure design. Plus, start looking at other business capability objectives, like mobility, customer portals, and the list will go on, now you can align infrastructure to the business. Take all your notes from the white board now, and start to build your 2014 design, goals, objectives and technology solutions. Keeping BCP and DR right in the mix, and when you are done, your plans are defined right along with your infrastructure efforts.
The best way to do Business Continuity Plans is to make them part of your day to day operational tasks, architecture tasks, and a line item in all IT projects. Then it is not a burden project anymore, but something that maintains itself as part of all staff daily tasks. Now don't get me wrong, someone still needs to own it, maintain it, and train new staff on it. I propose to all my customers that BCP and DR plans is woven into the fabric of all IT functions.
Keep it positive!
Scott Arnett
www.arnettservicesgroup.com
During the BCP definition stage, your infrastructure requirements start to take shape on the white board. If your business leaders and application owners are asking for high availability, no data loss, low recovery point goals, then you now have some requirements to define your infrastructure design. Plus, start looking at other business capability objectives, like mobility, customer portals, and the list will go on, now you can align infrastructure to the business. Take all your notes from the white board now, and start to build your 2014 design, goals, objectives and technology solutions. Keeping BCP and DR right in the mix, and when you are done, your plans are defined right along with your infrastructure efforts.
The best way to do Business Continuity Plans is to make them part of your day to day operational tasks, architecture tasks, and a line item in all IT projects. Then it is not a burden project anymore, but something that maintains itself as part of all staff daily tasks. Now don't get me wrong, someone still needs to own it, maintain it, and train new staff on it. I propose to all my customers that BCP and DR plans is woven into the fabric of all IT functions.
Keep it positive!
Scott Arnett
www.arnettservicesgroup.com
Sunday, September 1, 2013
Mobile Applications
Good afternoon everyone!
I am proud to say that the Arnett Group has really taken a leadership role in mobile application development. There are many organizations out there wanting a mobile application developed for internal consumption or an external application for their customers. We even offer it a step farther and do machine to machine mobile applications. Controlling equipment, lighting, or special vehicles, we can develop that mobile application for you.
This month we are focused on an application for customer to help their sales staff become more efficient. More information and workflow at their fingertips, in the field, on demand. How can we take all the information for several different backend systems, and present it on a mobile device to help the sales staff quickly respond to customer requests, or complete the sales process. Fun project!
So how can we help your organization utilize the technology your employees walk in the door with everyday? How can you take that smartphone and turn it into a leading edge tool for your organization. Give us a call, and let us help you look at some mobile application solutions to drive your business.
Keep it positive!
Scott Arnett
scott.arnett@charter.net
www.arnettservicesgroup.com
I am proud to say that the Arnett Group has really taken a leadership role in mobile application development. There are many organizations out there wanting a mobile application developed for internal consumption or an external application for their customers. We even offer it a step farther and do machine to machine mobile applications. Controlling equipment, lighting, or special vehicles, we can develop that mobile application for you.
This month we are focused on an application for customer to help their sales staff become more efficient. More information and workflow at their fingertips, in the field, on demand. How can we take all the information for several different backend systems, and present it on a mobile device to help the sales staff quickly respond to customer requests, or complete the sales process. Fun project!
So how can we help your organization utilize the technology your employees walk in the door with everyday? How can you take that smartphone and turn it into a leading edge tool for your organization. Give us a call, and let us help you look at some mobile application solutions to drive your business.
Keep it positive!
Scott Arnett
scott.arnett@charter.net
www.arnettservicesgroup.com
Sunday, August 25, 2013
Welcome Back!
Welcome back to my blog, and I am excited to share some of the new things happening. This has been an interesting year for sure, but as much as there are disappointments, there are blessings as well.
This blog will compliment our new website, so check it out at www.arnettservicesgroup.com. I look forward to announcing new things on this blog, talk about technology, and solutions.
The next few days I will take the time to announce our services and focus, and how we can help many organizations. There are many IT Professionals in the sunset of their career not ready to call it quits yet. So they have joined Arnett Group as a resource to our many customers.
I look forward to the next chapter - and glad you will be with me.
Talk soon
Keep it positive!
Scott Arnett
scott.arnett@charter.net
This blog will compliment our new website, so check it out at www.arnettservicesgroup.com. I look forward to announcing new things on this blog, talk about technology, and solutions.
The next few days I will take the time to announce our services and focus, and how we can help many organizations. There are many IT Professionals in the sunset of their career not ready to call it quits yet. So they have joined Arnett Group as a resource to our many customers.
I look forward to the next chapter - and glad you will be with me.
Talk soon
Keep it positive!
Scott Arnett
scott.arnett@charter.net
Thursday, April 11, 2013
Coming Back Soon!
Thank you for all the wonderful emails, voice mail and cards. I will be back to this blog soon!
Life is full of challenges, surprises, happiness and disappointments. Part of the journey!
Keep it positive!
Scott Arnett
Life is full of challenges, surprises, happiness and disappointments. Part of the journey!
Keep it positive!
Scott Arnett
Wednesday, October 24, 2012
2013 Trends - What Do You Think?
Wonder what is coming in 2013? What does Gartner have to say these days?
Below are the top 10 technology trends for 2013 per Gartner. To make this list all ten items have the following attributes: They will have a major impact on enterprises. The technology will drive significant change or disruption. Tipping points are occurring now or over the next couple years that makes the technology strategic or applicable to a wider market.
1) Mobile Device Battles - BYOD and BYOA increases. Cloud and mobility are mutually reinforcing trends. No platform, form factor, or technology dominates.
2) Mobile Applications and HTML5 - New expectations for usability, appearance, and behavior. The experience flows to where you are and working in context. Development challenges: new design skills, cloud/client architecture, complex apps may not work, native apps vs. HTML5.
3) Personal Cloud - replaces the PC, a collection of services and representation of your personal life. The cloud is where users center their digital lives, they are in control. Contextually aware and operationally obvious apps. So what about security? Worried? I am........
4) Internet of Things - Over 50 percent of Internet connections are things. Cameras, microphones, remote sensing of objects, wi-fi. Operational IT and traditional information technology are converging. Traditional supply chain transitions to Digital supply chain.
5) Hybrid IT and Cloud Computing - Strategic models for cloud service consumption. Adopt cloud techniques. Secure, manage and govern hybrid cloud and hybrid IT. Adopt new application design. Make externally facing services cloud services. Big outstanding question: Who will be responsible for delivery of cloud services? Architecture and Engineering is key. IT will be broker. Does that mean Business is the buyer?
6) Strategic Big Data - Hadoop and NoSQL gain momentum. Big data is a transformational architecture vs. isolated project. Centralized model replaced with distributed "logical" model. Homogenous RDBMS model replaced with heterogenous model.
7) Actionable Analytics - Cloud, packaged analytics, and big data accelerates in 2013-2014. Systems shift from computing and aggregation to reasoning, learning, and acting. Search and analytics become more intertwined. Convergence of analytic trends drives new values. Usage emphasizes decision management optimization.
8) Mainstream-In-Memory-Computing - Changes expectations, design, and architecture. Boost performance and efficiencies.
9) Integrated Eco-systems - Simplification, optimization, and security. Appliances become more popular due to integrated hardware, software, and services to address workload. No one appliance does it all. Marketplaces and brokerages. Facilitate purchases, consumption, and/or services or apps. Changes the landscape doesn't it?
10) Enterprise App Stores - Enterprise app stores are strategic for governing cloud and mobile use in a consumer driven world. Mainstream enterprise App Store with packaged and apps and portal options is key.
So what do you think? The 10 listed here by Gartner on track? Missing the mark? What are you seeing out there?
Keep it positive!
Scott Arnett
scott.arnett@charter.net
Subscribe to:
Posts (Atom)