|By Roger Oberg||
|August 9, 2006 01:00 PM EDT||
Why the recent surge of interest in regulatory and standards compliance? With the health and welfare of their citizens and local businesses in mind, global governments are requiring more accountability from organizations that do business within or across their borders. Since 1999, new legislation has passed in the United States that subjects business, IT, and even the software development process itself to audits. Some of the better known legislative acts, such as Sarbanes-Oxley, Basel II and the Health Insurance Portability & Accountability Act (HIPAA), have placed financial services and health care providers directly in the spotlight. These industries are spending money on ensuring compliance, but with mixed results so far. In the United States, for example, an estimated $2.5 billion will be spent annually by Fortune 1000 companies on compliance-related projects.
It doesn’t help that compliance requirements are often a puzzle in and of themselves. They are mandatory, but the steps to achieve compliance are not always outlined. In section 404 of the Sarbanes-Oxley act, for example, it says a company must have “good controls,” but it doesn’t clearly state what they are or how to achieve that. Regulatory requirements are also ever-changing, yet businesses are required to constantly demonstrate compliance. So for many businesses, well intended compliance requirements involve risk without clear guidelines for managing that risk.
Complying with regulations and standards is all about encapsulating business processes. It’s about clarifying and formalizing the way you do business – everything from taking an order to preparing goods for shipment, shipping and taking payment, and then allowing for scenarios like credit returns, faulty products or discounting – and appropriately recording that information.
Many companies have automated these processes by buying off-the-shelf IT packages and customizing them or, in many cases, by building their own custom-made applications. In either case, the modifications or new applications introduce yet another dimension to the puzzle: new pieces that must be shown to fit. This is the stage where compliance can become an even greater challenge.
In custom systems there can be a lot of people working on the development of the applications and errors can creep in, things can change. To withstand an audit – whether internal or external – a business has to be able to prove that the software system it has said it was going to build is the one it actually built, and that the software it built is the one it ultimately deployed – two separate processes. In essence, to achieve true compliance, businesses must be able to demonstrate the reliability and accuracy of any business process and show transparency throughout their development process.
It’s possible to demonstrate business process reliability and accuracy and have a transparent development process by manually compiling information at the time of an audit, but as you might imagine there is a high degree of overhead and risk associated with this reactive approach. There is a direct cost as well as the staff distraction and lost opportunity costs.
Establishing an effective governance framework for software delivery, what IBM Rational Software calls “Business Driven Development,” is a better choice. IBM Rational’s Software Development Platform provides guidance to customers with regard to best practices in developing software. Rational’s portfolio, requirements, testing, and software configuration management products provide a wide range of tools that capture information about what’s going on and what changes were made, what tests were done, what the design documents were and so on. It’s an ongoing process, so businesses can continuously capture information and maintain compliance. Using Rational’s automated workflow system for software delivery, a number of people in various locations can sign off on changes and allocate work. Instead of one hour per day spent on compliance issues, an hour-long conference call per week may be all that is required.
As an example, various companies in the financial services industry have chosen to work with IBM Rational to strengthen their testing and requirements practices to improve traceability and compliance with regulations like Sarbanes-Oxley. One such customer, a leading provider of data processing and information management services solutions, replaced a competitive testing solution with tools from Rational to improve its application testing processes, resulting in streamlined IT governance and regulatory compliance capabilities.
Aside from the assurance that comes from knowing the business is compliant, organizations can benefit from reduced risk and lowered costs in the long-term, improved infrastructure and project ownership, as well as better governance and understanding of business processes. With the right software delivery governance framework in place, the regulatory and standards compliance puzzle will look a lot more solvable.
|JDJ News Desk 08/09/06 12:29:42 PM EDT|
Imagine trying to solve a puzzle without being certain what the end result should look like, much less how the pieces fit together. Now imagine trying to build the puzzle pieces themselves. Bit of a challenge? To say the least! But this is exactly the situation facing many business and IT executives when it comes to complying with the increasing number of standards and regulations in their industries today.
As the race for the presidency heats up, IT leaders would do well to recall the famous catchphrase from Bill Clinton’s successful 1992 campaign against George H. W. Bush: “It’s the economy, stupid.” That catchphrase is important, because IT economics are important. Especially when it comes to cloud. Application performance management (APM) for the cloud may turn out to be as much about those economics as it is about customer experience.
Jan. 20, 2017 02:45 PM EST Reads: 4,713
When you focus on a journey from up-close, you look at your own technical and cultural history and how you changed it for the benefit of the customer. This was our starting point: too many integration issues, 13 SWP days and very long cycles. It was evident that in this fast-paced industry we could no longer afford this reality. We needed something that would take us beyond reducing the development lifecycles, CI and Agile methodologies. We made a fundamental difference, even changed our culture...
Jan. 20, 2017 02:30 PM EST Reads: 1,100
The 20th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held June 6-8, 2017, at the Javits Center in New York City, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Containers, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal ...
Jan. 20, 2017 01:30 PM EST Reads: 5,222
@DevOpsSummit taking place June 6-8, 2017 at Javits Center, New York City, is co-located with the 20th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. @DevOpsSummit at Cloud Expo New York Call for Papers is now open.
Jan. 20, 2017 01:30 PM EST Reads: 3,584
SYS-CON Events announced today that Dataloop.IO, an innovator in cloud IT-monitoring whose products help organizations save time and money, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Dataloop.IO is an emerging software company on the cutting edge of major IT-infrastructure trends including cloud computing and microservices. The company, founded in the UK but now based in San Fran...
Jan. 20, 2017 01:00 PM EST Reads: 2,568
SYS-CON Events announced today that Super Micro Computer, Inc., a global leader in Embedded and IoT solutions, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 7-9, 2017, at the Javits Center in New York City, NY. Supermicro (NASDAQ: SMCI), the leading innovator in high-performance, high-efficiency server technology, is a premier provider of advanced server Building Block Solutions® for Data Center, Cloud Computing, Enterprise IT, Hadoop/Big Data, HPC and E...
Jan. 20, 2017 12:15 PM EST Reads: 5,828
Thanks to Docker, it becomes very easy to leverage containers to build, ship, and run any Linux application on any kind of infrastructure. Docker is particularly helpful for microservice architectures because their successful implementation relies on a fast, efficient deployment mechanism – which is precisely one of the features of Docker. Microservice architectures are therefore becoming more popular, and are increasingly seen as an interesting option even for smaller projects, instead of being...
Jan. 20, 2017 11:45 AM EST Reads: 2,476
Hardware virtualization and cloud computing allowed us to increase resource utilization and increase our flexibility to respond to business demand. Docker Containers are the next quantum leap - Are they?! Databases always represented an additional set of challenges unique to running workloads requiring a maximum of I/O, network, CPU resources combined with data locality.
Jan. 20, 2017 11:30 AM EST Reads: 746
Internet of @ThingsExpo, taking place June 6-8, 2017 at the Javits Center in New York City, New York, is co-located with the 20th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. @ThingsExpo New York Call for Papers is now open.
Jan. 20, 2017 10:45 AM EST Reads: 3,698
2016 has been an amazing year for Docker and the container industry. We had 3 major releases of Docker engine this year , and tremendous increase in usage. The community has been following along and contributing amazing Docker resources to help you learn and get hands-on experience. Here’s some of the top read and viewed content for the year. Of course releases are always really popular, particularly when they fit requests we had from the community.
Jan. 20, 2017 10:30 AM EST Reads: 1,127
DevOps is being widely accepted (if not fully adopted) as essential in enterprise IT. But as Enterprise DevOps gains maturity, expands scope, and increases velocity, the need for data-driven decisions across teams becomes more acute. DevOps teams in any modern business must wrangle the ‘digital exhaust’ from the delivery toolchain, "pervasive" and "cognitive" computing, APIs and services, mobile devices and applications, the Internet of Things, and now even blockchain. In this power panel at @...
Jan. 20, 2017 09:45 AM EST Reads: 2,925
SYS-CON Events announced today that Catchpoint Systems, Inc., a provider of innovative web and infrastructure monitoring solutions, has been named “Silver Sponsor” of SYS-CON's DevOps Summit at 18th Cloud Expo New York, which will take place June 7-9, 2016, at the Javits Center in New York City, NY. Catchpoint is a leading Digital Performance Analytics company that provides unparalleled insight into customer-critical services to help consistently deliver an amazing customer experience. Designed ...
Jan. 20, 2017 09:15 AM EST Reads: 6,387
Here’s a novel, but controversial statement, “it’s time for the CEO, COO, CIO to start to take joint responsibility for application platform decisions.” For too many years now technical meritocracy has led the decision-making for the business with regard to platform selection. This includes, but is not limited to, servers, operating systems, virtualization, cloud and application platforms. In many of these cases the decision has not worked in favor of the business with regard to agility and cost...
Jan. 20, 2017 09:00 AM EST Reads: 353
Buzzword alert: Microservices and IoT at a DevOps conference? What could possibly go wrong? In this Power Panel at DevOps Summit, moderated by Jason Bloomberg, the leading expert on architecting agility for the enterprise and president of Intellyx, panelists peeled away the buzz and discuss the important architectural principles behind implementing IoT solutions for the enterprise. As remote IoT devices and sensors become increasingly intelligent, they become part of our distributed cloud enviro...
Jan. 20, 2017 08:15 AM EST Reads: 4,943
Containers have changed the mind of IT in DevOps. They enable developers to work with dev, test, stage and production environments identically. Containers provide the right abstraction for microservices and many cloud platforms have integrated them into deployment pipelines. DevOps and containers together help companies achieve their business goals faster and more effectively. In his session at DevOps Summit, Ruslan Synytsky, CEO and Co-founder of Jelastic, reviewed the current landscape of Dev...
Jan. 20, 2017 08:00 AM EST Reads: 4,296
DevOps tends to focus on the relationship between Dev and Ops, putting an emphasis on the ops and application infrastructure. But that’s changing with microservices architectures. In her session at DevOps Summit, Lori MacVittie, Evangelist for F5 Networks, will focus on how microservices are changing the underlying architectures needed to scale, secure and deliver applications based on highly distributed (micro) services and why that means an expansion into “the network” for DevOps.
Jan. 20, 2017 06:15 AM EST Reads: 5,521
"Plutora provides release and testing environment capabilities to the enterprise," explained Dalibor Siroky, Director and Co-founder of Plutora, in this SYS-CON.tv interview at @DevOpsSummit, held June 9-11, 2015, at the Javits Center in New York City.
Jan. 20, 2017 06:15 AM EST Reads: 3,655
Adding public cloud resources to an existing application can be a daunting process. The tools that you currently use to manage the software and hardware outside the cloud aren’t always the best tools to efficiently grow into the cloud. All of the major configuration management tools have cloud orchestration plugins that can be leveraged, but there are also cloud-native tools that can dramatically improve the efficiency of managing your application lifecycle. In his session at 18th Cloud Expo, ...
Jan. 20, 2017 02:15 AM EST Reads: 6,061
In his session at @DevOpsSummit at 19th Cloud Expo, Robert Doyle, lead architect at eCube Systems, will examine the issues and need for an agile infrastructure and show the advantages of capturing developer knowledge in an exportable file for migration into production. He will introduce the use of NXTmonitor, a next-generation DevOps tool that captures application environments, dependencies and start/stop procedures in a portable configuration file with an easy-to-use GUI. In addition to captur...
Jan. 20, 2017 12:45 AM EST Reads: 2,887
Docker containers have brought great opportunities to shorten the deployment process through continuous integration and the delivery of applications and microservices. This applies equally to enterprise data centers as well as the cloud. In his session at 20th Cloud Expo, Jari Kolehmainen, founder and CTO of Kontena, will discuss solutions and benefits of a deeply integrated deployment pipeline using technologies such as container management platforms, Docker containers, and the drone.io Cl tool...
Jan. 20, 2017 12:00 AM EST Reads: 1,040