Welcome!

Microservices Expo Authors: Pat Romanski, Liz McMillan, Elizabeth White, Mamoon Yunus, Jason Bloomberg

Related Topics: Microsoft Cloud, Microservices Expo, Machine Learning , Silverlight, Cloud Security

Microsoft Cloud: Article

SharePoint Gone Wild: When Governance Lacks Accountability

Help your organization understand what "could happen"

In a webinar entitled ‘Business Drivers and Checklists for Successful SharePoint Governance', Randy Williams, SharePoint MVP and AvePoint Enterprise Trainer & Evangelist, and I discussed the business drivers that come from individuals outside the IT department for SharePoint as a service within an organization. These drivers often result in policies being defined to set the expectation with the business and to focus alignment with the IT department.

Over a series of posts, I will focus on horror stories, from some of our 8,000+ customers we have here at AvePoint, which provided the genesis for these business drivers. The intention of this series is to proactively help your organization understand what "could happen" and what the business drivers are to help you structure your organization's governance system. I'm fortunate enough to get to meet a lot of our customers in person to discuss their SharePoint pain points, and enjoy referring them to resources all over the Internet to help them to cure these pains. I often feel like a SharePoint therapist of sorts, and selfishly enjoy hearing the pains as it triggers new ideas for products and articles we can share more broadly.

I'm a big fan of mind mapping, and over time, I've collected these pains and sorted them into some distinct business drivers, influenced by the other SharePoint governance experts in the field I discussed in one of my previous posts. Here are the main business drivers (for more explanation of each of these, check out Randy's recent post on the topic here):

To refer back to the policy areas defined in the governance system that the 21 Apps team came up with (IT Governance; Project Governance; Information Governance; Business & IT Alignment; and Continuous Improvement), there is overlap between the drivers and the policies - not a one to one mapping. This would make for a tidier diagram, but you can't have everything I guess!

To start this journey through the business drivers, I will start with one of the pain points that I have heard at every single customer, small or large, this past year - accountability.

The definition of accountability - "the state of being accountable, liable, or answerable" - really does sum it up well with respect to SharePoint content. When I state SharePoint content, I really mean being accountable at a document, library, sub site, site collection, web app or farm level. There are obviously other forms of SharePoint content outside this stack, such as in service applications including the managed metadata term store, user profiles, and business connectivity services external content types.

Typically, in an organization the IT department has the accountability of the farm level from an operational and maintenance level.

From a web application level, these are typically the workloads such as a collaboration system, document management system, intranet, internet, business intelligence system and so on. Within an organization, these cross-business workloads are often owned by either the IT department or a specific business unit such as human resources, communications, information management, or marketing. For business-specific workloads like internet sites and business intelligence systems, they are typically owned by the departments who requested them and are charged for them by the IT department.

Accountability starts to get a little hazy at the site collection level and below. The main reason for this is that content at this level, especially in cross business workloads such as collaboration systems and document management systems, typically start to separate at this level. For instance, in a document management system, each department may have its own site collection or, even further, a project management office may have a site collection per project. There are so many varieties of information architecture at the site collection and sub site level that accountability is not often the business owner of a department. This would also be the case for a project site collection where the accountable person would be the project owner.

The major pain point within organizations I talk to is how to track accountability at each of these levels. At a farm level, this can be done easily with the farm administrators group. At the web application level, this can be done with the web application policy settings. This can be accomplished on site collections with site collection administrator level. At the sub site level, this can be achieved via the owners group level. The biggest problem with assigning users to these settings is that it not only is an easy way to track accountability, but it also gives heightened permission levels to them. The main challenge here is that often these accountable people are not trained in SharePoint and don't require ‘god mode' of the container against which they have been tracked.

The other side of the accountability is not only tracking it on provisioning of these containers, but for the entire lifecycle of the containers. A common issue among customers is that the original people held accountable have transferred roles or left the organization entirely. Typically, containers require archiving for legal reasons and storage constraints. Or, IT just needs to reach out to the accountable person to notify them of a change request. Without having an up to the minute accountable person, these decisions are harder to make and can cause rifts between IT and the business.

More Stories By Jeremy Thake

Jeremy Thake is AvePoint's Chief Architect. Jeremy’s 10-plus years of experience in the software development industry, along with his expertise in Microsoft technologies, earned him the label of “expert” in the global SharePoint community. He was named a Microsoft SharePoint MVP in 2009, and continues to work directly with enterprise customers and AvePoint’s research & development team to develop solutions that will set the standard for the next generation of collaboration platforms, including Microsoft SharePoint 2013.

Jeremy was one of only eight Microsoft MVPs from Australia, where he lived for seven years, who was recognized by the SharePoint Product Team in 2010 for his extensive contributions to the global SharePoint community. He also played an instrumental role in organizing the Perth SharePoint User Group during his time living there.

@MicroservicesExpo Stories
Did you know that you can develop for mainframes in Java? Or that the testing and deployment can be automated across mobile to mainframe? In his session and demo at @DevOpsSummit at 21st Cloud Expo, Dana Boudreau, a Senior Director at CA Technologies, will discuss how increasingly teams are developing with agile methodologies, using modern development environments, and automating testing and deployments, mobile to mainframe.
As DevOps methodologies expand their reach across the enterprise, organizations face the daunting challenge of adapting related cloud strategies to ensure optimal alignment, from managing complexity to ensuring proper governance. How can culture, automation, legacy apps and even budget be reexamined to enable this ongoing shift within the modern software factory?
While some vendors scramble to create and sell you a fancy solution for monitoring your spanking new Amazon Lambdas, hear how you can do it on the cheap using just built-in Java APIs yourself. By exploiting a little-known fact that Lambdas aren’t exactly single-threaded, you can effectively identify hot spots in your serverless code. In his session at @DevOpsSummit at 21st Cloud Expo, Dave Martin, Product owner at CA Technologies, will give a live demonstration and code walkthrough, showing how ...
API Security is complex! Vendors like Forum Systems, IBM, CA and Axway have invested almost 2 decades of engineering effort and significant capital in building API Security stacks to lockdown APIs. The API Security stack diagram shown below is a building block for rapidly locking down APIs. The four fundamental pillars of API Security - SSL, Identity, Content Validation and deployment architecture - are discussed in detail below.
@DevOpsSummit at Cloud Expo taking place Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center, Santa Clara, CA, is co-located with the 21st International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is ...
We define Hybrid IT as a management approach in which organizations create a workload-centric and value-driven integrated technology stack that may include legacy infrastructure, web-scale architectures, private cloud implementations along with public cloud platforms ranging from Infrastructure-as-a-Service to Software-as-a-Service.
There are several reasons why businesses migrate their operations to the cloud. Scalability and price are among the most important factors determining this transition. Unlike legacy systems, cloud based businesses can scale on demand. The database and applications in the cloud are not rendered simply from one server located in your headquarters, but is instead distributed across several servers across the world. Such CDNs also bring about greater control in times of uncertainty. A database hack ...
In his session at 20th Cloud Expo, Scott Davis, CTO of Embotics, discussed how automation can provide the dynamic management required to cost-effectively deliver microservices and container solutions at scale. He also discussed how flexible automation is the key to effectively bridging and seamlessly coordinating both IT and developer needs for component orchestration across disparate clouds – an increasingly important requirement at today’s multi-cloud enterprise.
Docker is on a roll. In the last few years, this container management service has become immensely popular in development, especially given the great fit with agile-based projects and continuous delivery. In this article, I want to take a brief look at how you can use Docker to accelerate and streamline the software development lifecycle (SDLC) process.
In his session at 20th Cloud Expo, Chris Carter, CEO of Approyo, discussed the basic set up and solution for an SAP solution in the cloud and what it means to the viability of your company. Chris Carter is CEO of Approyo. He works with business around the globe, to assist them in their journey to the usage of Big Data in the forms of Hadoop (Cloudera and Hortonwork's) and SAP HANA. At Approyo, we support firms who are looking for knowledge to grow through current business process, where even 1%...
With Cloud Foundry you can easily deploy and use apps utilizing websocket technology, but not everybody realizes that scaling them out is not that trivial. In his session at 21st Cloud Expo, Roman Swoszowski, CTO and VP, Cloud Foundry Services, at Grape Up, will show you an example of how to deal with this issue. He will demonstrate a cloud-native Spring Boot app running in Cloud Foundry and communicating with clients over websocket protocol that can be easily scaled horizontally and coordinate...
IT organizations are moving to the cloud in hopes to approve efficiency, increase agility and save money. Migrating workloads might seem like a simple task, but what many businesses don’t realize is that application migration criteria differs across organizations, making it difficult for architects to arrive at an accurate TCO number. In his session at 21st Cloud Expo, Joe Kinsella, CTO of CloudHealth Technologies, will offer a systematic approach to understanding the TCO of a cloud application...
DevOps at Cloud Expo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 21st Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to w...
API Security has finally entered our security zeitgeist. OWASP Top 10 2017 - RC1 recognized API Security as a first class citizen by adding it as number 10, or A-10 on its list of web application vulnerabilities. We believe this is just the start. The attack surface area offered by API is orders or magnitude larger than any other attack surface area. Consider the fact the APIs expose cloud services, internal databases, application and even legacy mainframes over the internet. What could go wrong...
Cloud adoption is often driven by a desire to increase efficiency, boost agility and save money. All too often, however, the reality involves unpredictable cost spikes and lack of oversight due to resource limitations. In his session at 20th Cloud Expo, Joe Kinsella, CTO and Founder of CloudHealth Technologies, tackled the question: “How do you build a fully optimized cloud?” He will examine: Why TCO is critical to achieving cloud success – and why attendees should be thinking holistically ab...
The goal of Continuous Testing is to shift testing left to find defects earlier and release software faster. This can be achieved by integrating a set of open source functional and performance testing tools in the early stages of your software delivery lifecycle. There is one process that binds all application delivery stages together into one well-orchestrated machine: Continuous Testing. Continuous Testing is the conveyer belt between the Software Factory and production stages. Artifacts are m...
Web services have taken the development world by storm, especially in recent years as they've become more and more widely adopted. There are naturally many reasons for this, but first, let's understand what exactly a web service is. The World Wide Web Consortium (W3C) defines "web of services" as "message-based design frequently found on the Web and in enterprise software". Basically, a web service is a method of sending a message between two devices through a network. In practical terms, this ...
In his session at @DevOpsSummit at 20th Cloud Expo, Kelly Looney, director of DevOps consulting for Skytap, showed how an incremental approach to introducing containers into complex, distributed applications results in modernization with less risk and more reward. He also shared the story of how Skytap used Docker to get out of the business of managing infrastructure, and into the business of delivering innovation and business value. Attendees learned how up-front planning allows for a clean sep...
In IT, we sometimes coin terms for things before we know exactly what they are and how they’ll be used. The resulting terms may capture a common set of aspirations and goals – as “cloud” did broadly for on-demand, self-service, and flexible computing. But such a term can also lump together diverse and even competing practices, technologies, and priorities to the point where important distinctions are glossed over and lost.
"At the keynote this morning we spoke about the value proposition of Nutanix, of having a DevOps culture and a mindset, and the business outcomes of achieving agility and scale, which everybody here is trying to accomplish," noted Mark Lavi, DevOps Solution Architect at Nutanix, in this SYS-CON.tv interview at @DevOpsSummit at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.