About Me

My photo
Scott Arnett is an Information Technology & Security Professional Executive with over 30 years experience in IT. Scott has worked in various industries such as health care, insurance, manufacturing, broadcast, printing, and consulting and in enterprises ranging in size from $50M to $20B in revenue. Scott’s experience encompasses the following areas of specialization: Leadership, Strategy, Architecture, Business Partnership & Acumen, Process Management, Infrastructure and Security. With his broad understanding of technology and his ability to communicate successfully with both Executives and Technical Specialists, Scott has been consistently recognized as someone who not only can "Connect the Dots", but who can also create a workable solution. Scott is equally comfortable playing technical, project management/leadership and organizational leadership roles through experience gained throughout his career. Scott has previously acted in the role of CIO, CTO, and VP of IT, successfully built 9 data centers across the country, and is expert in understanding ITIL, PCI Compliance, SOX, HIPAA, FERPA, FRCP and COBIT.

Tuesday, December 13, 2011

Recovery as a Service

What? Another cloud acronym? RaaS? Sure looks like it, Recovery as a Service. Remember the Sunguard and IBM contracts you haggle over each year? Well now you can buy that recovery service in the cloud. So is that a good thing?

There are many reasons you engage a recovery partner, and many options you may need in the event of a disaster. How can a cloud service provide a temp physical location? Will they help setup a temporary internet connection for you? What should I worry about you may ask…..

Keep in mind that cloud services are a multi tenancy solution, that is oversubscribed and at the mercy of your available bandwidth. In addition, there currently is no option to bridge between multiple cloud providers. There is also a challenge when it comes to testing / scheduling access to your virtual hardware.

One more important point to make is around regulatory compliance, regardless if that is PCI, SOX or HIPAA. You are still responsible for maintaining your security, DR plans, and compliance. You cannot pass your obligations off to your cloud provider. I would recommend putting into your contract that ability for your auditors to audit the cloud provider. Do not rely on just a SAS 70 Type II audit document given to you by the provider. It is helpful information but not sufficient enough. Your auditor needs to test the environment, controls, and so forth.

RaaS truly is for small environments, and not a solution for large enterprises. It can be used for test or development environments, but in limited capacity. The key to utilizing a Recovery as a Service solution is getting an internet connection restored and your users access to that data or applications. If you have limited bandwidth now, it will be 30 to 45 days for new circuits to address the bandwidth constraint to make RaaS a viable solution.

Keep it positive!

Scott Arnett

Monday, December 12, 2011

Build, Rent, or Cloud Services?

I had a colleague call me a few weeks ago and was seeking advice on a data center strategy. Their data center is 25 years old, the environmental controls need replacement, they need space – do I think they should remodel and expand. We talked for a few hours to get more information on the current state, desired state and future state. During the conversation it became very clear that there is confusion between co-location options, Cloud Services (SaaS, IaaS, etc) and internal options.

My colleague said that there is confusion out there and I should put this out on my blog as others may be asking the same questions. I was more than happy to oblige, with one condition – that they read some of my cloud posts. So we have a deal, and here we go.

My first recommendation to my colleague was to perform an assessment of what they have today. This assessment should include the facilities, but also, networks, servers, storage, tools, applications, access options, capacity, and disaster recovery. Once we have that completed assessment, a picture of what we have in place today, let’s identify today’s pain points. This quickly revealed that it truly is a facility issue that is putting constraints on the operations, and the ability to deliver capability to the business.

To remodel a production data center online is almost impossible. I have done it once in my career, but it comes with high risk, and many challenges. In addition, to make that investment of building a new data center and make the TCO financially sustainable, you have a great deal of homework ahead of you.

So to make sure we are all on the same page, my definition of a co-location is taking your operations and renting space from Joe’s Data Center and putting it on their floor. You pay to rent the floor space that includes power, cooling, and network / internet connectivity. It is your servers, storage, equipment. You still maintain your process(s), procedure, operations, monitoring and break/fix. A hosted solution is just moving your application(s) and data to their data center on their servers/storage and you maintain the application, they maintain the infrastructure. Cloud based services is renting an application or called Software as a Service (SaaS) or renting some storage for DR or called Infrastructure as a Service.

There are benefits to each scenario and you have to look at the cost(s), risk(s) and operations. In addition, your disaster recovery plan. Going to an option that takes your mission critical infrastructure and applications off premise comes with risk. You have to take into account carrier performance, geographic risks, power grids, and so forth. If your corporate office or key production facility just lost internet connection, they no longer have access to applications or infrastructure – what impact does that have on the business? Do you have redundant circuits between different carriers? Are the different carriers all renting space on the same fiber that was just cut? Do you have redundant power grid supply lines – from different substations? You now have all these factors to consider as your data center is miles away from all your users and many things out of your control. Here is a diagram I found in some of my archives:

 This diagram shows connectivity to the primary data center from multiple facilities with point to point connections. There is new technology out there to utilize and investigate, such as MPLS. You can also push down to the client to determine which data center to connect to. There are some great load balance solutions out there now. One I greatly recommend is from A10 networks. Check them out, there are some real advantages to their solutions. One more comment on the MPLS network option is that you can push your security to the MPLS cloud and have your firewalls, IDS, DLP all sitting in that cloud to protect the entire private MPLS cloud you installed. I would keep your data center to data center sync line direct Point to Point. Just my preference. The main point here is don’t forget the DR portion of your planning. Very key!

The other question was, should I just push everything to the cloud now and be done with it? So given the information they shared, I don’t think you can push your entire data center to the cloud. Things like email, and even your voice services can go to the cloud. But your mission critical systems – can you really get them into a Cloud offering and deliver at or above your current operation? Probably not. What about your corporate data, is the organization comfortable with that data sitting in a multi tenancy environment out of your control? Probably not. So look for the quick wins and easy decisions to make to get some of that out of your data center today. This will help take the load off your aging environmental components while you determine your course of action.

Some of the feedback I get is to just say “if it was you, what would you do….”. I have tried to not do that, but I know folks are interested in my opinion. Given what I know from my colleague, I would build a new data center on premise, that is much smaller than what you have today, and that brings much needed automation, and process improvement. I would place your MDF in that new data center, your key infrastructure components, and mission critical applications. I would turn your email, video conference, voice services, and SharePoint into SaaS solutions. I would also drive virtualization – nothing moves from old data center to new data center without a new plan. New virtualization plans for server, storage, and desktop. I would develop a hybrid cloud solution and look for some appliance solutions for the integration to your external cloud solution. I would look for a storage IaaS solution for your archive data – encrypted of course. I would also build your MPLS WAN for all site connections and put your security in the cloud as a service. Let the security experts do that for you.

This accomplishes a few things, 1) you remove the risk of a facility failure, 2) you take the load off your limited staff and let them focus on mission critical components, 3) you start the cloud journey small and grow into it as it makes sense, 4) you are now in a position to deliver a more successful DR plan to the organization, 5) you will drive down cost(s) with your new facility with the new technology and new approach.

I am not opposed to co-location solutions, I just have found the TCO for that solution hard to sell. You add up all your cost(s), risk(s), risk avoidance, and operational changes, and you can no longer afford it.

Keep it positive!



Scott Arnett
scott.arnett@charter.net

Wednesday, November 30, 2011

Wi-Fi Security or Best Practice

How did we live without Wi-Fi?  I can go to McDonald's or a coffee shop and get Wi-Fi and do my work, access my email or even do online banking.  Ever worry about the security of that capability?  Wi-Fi is inherently susceptible to hacking and eavesdropping, but it can be secure if you use some basic principles.  I would not recommend online banking or sensitive transactions from a public Wi-Fi though. 

Here are some tips to keep in mind:

  Don't use WEP.    WEP (wired equivalent privacy) security is long dead.  Its underlying encryption can be broken quickly and there are tools to download off the Internet to help you hack it.  I would recommend WPA2.

  Don't use WPA/WPA2-PSK.  PSK = pre-shared key.  This mode of WPA and WPA2 security isn't secure for the enterprise.  The entry of this key into the client would need to be changed each time an employee leaves or the client is lost or stolen.  This is a management challenge, and many times goes overlooked or forgotten.  Not a good option.

 Do implement 802.11i. The EAP protocol of WPA and WPA2 security uses 802.1x authentication instead of PSKs, providing the ability to offer each users or client their own login credentials:  user name and password or a digital certificate.  The encryption keys are regularly changed and exchanged silently in the background.  Look into NPS of Windows Server 2008.  There are also some great RSA products to help with security.

 Do Secure 802.1x Client Settings:  The EAP mode of WPA/WPA2 is still vulnerable to man-in-the-middle attacks.  You need to secure the settings of the client to prevent these attacks.  An example would be to in the EAP settings of Windows you can enable server certificate validation by selecting the CA certificate, specify the server address, and disable it from prompting users to trust new servers or CA certificates.  Utilize Group Policy if you can. 

  Use a wireless intrusion prevention system:  When it comes to Wi-Fi security there is more than combating those directly trying to gain access to the network.  Hackers can setup rogue access points, or perform DOS attacks.  An intrusion prevention system for wireless (WIPS) can alert you to rogue APs or malicious activity.  Think of security in layers.  One more tool and protection layer to keep you safe.

 NAP:  Should you consider deploying a Network Access Protection (NAP)?  It could provide additional control over network access, and policy based protection.  Windows 2008 comes with some of these features, give it some consideration.  There are some great third party options as well. 

There are several other things you can do, like hiding your SSID, don't leave default passwords on your systems, and disable feature/functions you don't need.  Bottom like is that using wireless comes with additional security awareness and steps needed to be taken.  I would also recommend a firewall on that laptop you are using at your favorite Wi-Fi hot spot.  Security is everyone's responsibility. 

Keep it positive!

Scott Arnett
scott.arnett@charter.net

Friday, November 18, 2011

What does Private Cloud Drive?

Had to chuckle the other day, I was talking with a colleague in Atlanta, and he said Private Cloud is driving him to drink. I thought IT in general did that, not just Private Cloud.  But that got me to think, what is Private Cloud really driving - how about virtualization. 

Private clouds promise an agile data center, where workloads can be moved around to different physical servers, storage, and networking gear to meet challenging demand.  And you can't have a private cloud without virtualization, since the private cloud architecture requires breaking free from physical network and infrastructure constraints.  There are several organizations moving down the path of virtualization with great success, but how many are ready for that next step to Private Cloud?

IT vendors are introducing products aimed at private clouds like never before, expanding the virtual value.  I see this innovation in interconnects, such as the PCI-SIG's Single Root IOV protocol for linking virtualized devices; in processors, with Intel VI-x and AMD-V, in storage, with hybrid cache mechanisms; in storage controllers with robust software APIs; in applications, with cloud delivery mechanisms, distributed processing, and encapsulation; in networking, with Virtual Private LAN Service and Cisco's Overlay Transport Virtualization.  Now does that excite you? 

How about the otherside of that coin?  While the vendors are solving one problem of implementing private cloud, no one offers a good way to run this larger infrastructure.  There is no enterprise wide management tool worth the cost that delivers what is needed.  So without this management, how are you going to show your ROI?  You increased capability, sure, but at what cost? 

I am not discouraging anyone from driving towards private cloud, on the contrary.  With some good planning, some holistic view, you can find a place to start.  The standards, tools, and ROI will come along, but it is not there yet today.  Keep focused on virtualization of your servers, storage, I/O and applications, but don't forget desktops,.  Have a strategy around cloud, and how you will manage the technology, the process, and the people. 

Keep it positive!

Scott Arnett
scott.arnett@charter.net

Thursday, November 10, 2011

Wicker Basket for iPhone?

Take a moment and sit in your favorite chair at home, turn the TV off, iPhone, radio and all other technology of today.  Hear that?  Silence, calm, just the moment of the day.  I wonder what happened to the picnic down at the lake with just your sweetheart, or the quiet ride in the car through the country.  When was the last time you played a board game with the kids, and had popcorn and no TV?

You hear folks talk about the good ole' days, then you hear others say that today is so much better that just 30 years ago.  Really?  Is our lives that much better?  Has iPhones really made today so wonderful?  How about social networking - the wonderful Facebook?  Can you have that picnic on facebook?  Can you take that walk?  How about a gentleman's handshake?  Technology can't replace many of these things.  Has technology improved our lives so much that the simple things of days gone by should be left in the history books? 

I propose to you that we need some balance.  Technology in the medical field has made significant improvements, and the list goes on.  I would also say, we need some technology free activities as well.  Nothing wrong with writing a letter or card to put in the mail.  Nothing wrong with many things our parents did before computers, iPhones, social websites, and texting.  We have become so overwhelmed with technology, immediate communications, instant news, instant now - that we loose touch with reality at times.  To have a balance in our life and to keep things in perspective - turn it off and take a step aside and look around.  Have some yard time, have some game time, or even go to the park.  When was the last time you went to the library to read a book or magazines? 

I wonder the quality of life impact technology has had on us.  It has made things in life easier, made information available at our fingertips, but has it not made us lazy?  Dependent?  Impatient and at times out of perspective?  Technology become invasive?  All good questions, with many of the answers coming in the future.  I think technology has had a negative impact on parts of our lives, but it is our life and we are in control.  Use the power button from time to time.

Keep it positive!

Scott Arnett
scott.arnett@charter.net

Wednesday, November 2, 2011

Next Generation Virtualized Data Center - Part 1

Journey to the Private Cloud will be difficult with today's technology and standards.  I find some of the motivation to take this journey interesting, as some CIO's are just simply following the crowd.  Is the motivation cost savings?  Agility?  Technology? 

Let's not spend time debating whether fully virtualized data centers will become standard or the norm. They will, and sooner than most may think. There are bigger challenges than how soon you can get 50% or more of your servers virtualized.  Things like network, tools, management and the list goes on. 

When I say Private Cloud, I mean an internal network that combines compute, storage, and other data center resources with high virtualization, hardware integration, automation, monitoring, and orchestration.  Things like self service, are key items to this definition.  Getting to this definition, with today's technology will be tough.  Let's look at the range of problems IT faces, such as multivendor environments, limited automation, and still-emerging technology and standards.

Standards are scarce indeed, making every purchasing decision dicey. The CTO must understand how every component interacts with every other component, but since extensive server virtualization has increased operational complexity, this can be an extraordinarly difficult thing to get your arms around. IT teams looking to conventinoal network and system management products for help are finding that these expensive tools are inadequate to the task at hand.  I would also say, don't look to just the normal vendors you have for years, like Cisco.  There are some real up and coming champions to watch.

I also tell my colleagues the only savings realized from virtualization is fewer physical servers.  Costs have increased via more expensive servers with bigger I/O and more memory, added cost of the hypervisor, and a much more difficult time to resolve problems when they occur. 

VMWare is still the go to vendor when IT organizations talk enterprise class server virtualization.  Many of my colleagues set this as a standard but have started to look at XEN and Microsoft, driven by cost(s).  Citrix and Microsoft are closing the gap to VMWare on technology, and feature/function.

It seems IT organizational leaders are all over the place when it comes rating the importance of virtualization features.  I feel high availability is a priority one, followed by price.  Both Microsoft Hyper-V R2 and Citrix XenServer offer high-availability features with a reasonable price tag. VMWare also offers high availability in its entry-level packages, except that it doesn't bundle features like Distributed Resource Scheduler, for machine load balancing, with its low-cost VSphere Essentials, making it an incomplete offering.  I also question the support cost(s) of the VMWare solutions.

Other features I find highly valued included live virtual machine migration, fault tolerance, load balancing, and virtual switching/networking. Citrix and Microsoft recently cozied up to Marathon Technologies to provide fault tolerance for their platforms.   There are features that VMWare offer that others do not, like storage DRS, which load balances data store I/O, and Storage vMotion.  Why I don't like and seek alternatives is cost.  VMWare's decision this year to increase its price beyond a certain virtual memory allocation.  VMWare later raised the limit, but that move only delays a price increase that could drive IT organizations to look at these alternatives.  If its bells and whistles like Storage DRS and Storage vMotion that VMWare expects to justify higher licensing costs, I am not buying it.  I see steady improvements to Hyper-V and Xen, and Oracle's integration of Virtual Iron into their VM product, there are lots of alternatives to consider. 

The challenge is mixing production hypervisors, that will not give your a unified, automated disaster recovery scheme.  Plus it will require some deep expertise if you want one policy to govern all of your systems, a good goal.  Make sure you take a holistic view of the environment, production, test, DR, and management. 

I will have a future discussion on "Master Disaster Recovery for Virtual".  Till then - keep your investigation and study on Private Clouds - don't be quick to jump on the bandwagon and put it in production. 

Keep it positive!

Scott Arnett
scott.arnett@charter.net

Monday, October 31, 2011

Pressure Cooker - Fall Cooking?

IT professionals at all levels are facing unprecedented stress in their jobs these days. Ever ask yourself why? How are you dealing with your stress? 

Stress has a negative impact on your health, not to mention your family and inner circle.  The impact of stress on our health is well documented. Among the problems created by chronic stress: It makes us more susceptible to getting sick because it attacks our immune system; it causes high blood pressure and arteriosclerosis (hardening of the arteries)—both of which increase our risk of heart attack; and it can also leads to ulcers. According to the American Institute of Stress, 90 percent of all illnesses are stress-related.

So where is all the stress coming from?  Where do you want to start?  Economic, job security, over worked, out of alignment expectations, constant communications, and the list goes on.  Technology is making difficult for you to leave work, always working, always online, checking email, sending emails, and so forth.  Ever feel like you could explode?

I talked with a now retired CIO who went to Florida for sun and golf, and no iPhone, no technology.  He said the stress, tension and uneasy left when he unplugged.  Took him awhile, but he said looking back, his mistake was not taking time that was rightfully his.  He should have punched out and turn the electronics off to have dinner with the family, the soccer games he missed, the baseball games.  He is now in his late 60's and it is to late for him to do those things with his kids, they have grown to fast and he never had time.  Just one more upgrade, one more late night meeting, one more trip, one more ERP system, and 40 years later - he never made that game, that dinner or play.  His advice to anyone coming up in IT is to keep it in check.  If you are working over 45 hours every week, you better evaluate your priorities and push back or move on.  Jobs come and go, but family is forever, and you only get one trip on this earth.

I propose to you  that a good leader knows what his staff is working, and will help ensure there is work/life balance.  In tune with your staff is to make sure they make those life events, to ensure they have personal time, and that there is a culture that has expections to demands.  There are staff shortages in IT, and the demands are ever increasing.  Communication with your manager, or staff are essential, and upstream as well as downstream communications. 

Make sure you have a hobby, or punch out and take a walk, play Wii with the kids - do something that is not work related.  Have some downtime, good for your health, and good for your employer.  If you are healthy, you are a happy productive employee. 

One more comment if I may, I find it concerning that there is quickly becoming a negative tone towards IT in the business community.  IT says they need more staff, more time, more money - but just push down on them, work them harder with less, we need to save money.  Technology will make your company successful, and your IT staff is essential to that goal. If IT doesn't like it, just go to the cloud.  Be careful with that attitude and direction, you have unqualified business people making  techology decisions.  40% of companies go out of business after a significant disaster - you cooking one up? 

Keep it positive!

Scott Arnett
scott.arnett@charter.net