Welcome!

Microservices Journal Authors: Liz McMillan, Pat Romanski, Carmen Gonzalez, Roger Strukhoff, Elizabeth White

Related Topics: Java, Microservices Journal

Java: Article

Compliance Issues Represent Pieces of a Puzzle

IBM's Rational Focuses on Business-Driven Development

Imagine trying to solve a puzzle without being certain what the end result should look like, much less how the pieces fit together. Now imagine trying to build the puzzle pieces themselves. Bit of a challenge? To say the least! But this is exactly the situation facing many business and IT executives when it comes to complying with the increasing number of standards and regulations in their industries today.

Why the recent surge of interest in regulatory and standards compliance? With the health and welfare of their citizens and local businesses in mind, global governments are requiring more accountability from organizations that do business within or across their borders. Since 1999, new legislation has passed in the United States that subjects business, IT, and even the software development process itself to audits. Some of the better known legislative acts, such as Sarbanes-Oxley, Basel II and the Health Insurance Portability & Accountability Act (HIPAA), have placed financial services and health care providers directly in the spotlight. These industries are spending money on ensuring compliance, but with mixed results so far. In the United States, for example, an estimated $2.5 billion will be spent annually by Fortune 1000 companies on compliance-related projects.

It doesn’t help that compliance requirements are often a puzzle in and of themselves. They are mandatory, but the steps to achieve compliance are not always outlined. In section 404 of the Sarbanes-Oxley act, for example, it says a company must have “good controls,” but it doesn’t clearly state what they are or how to achieve that. Regulatory requirements are also ever-changing, yet businesses are required to constantly demonstrate compliance. So for many businesses, well intended compliance requirements involve risk without clear guidelines for managing that risk.

Complying with regulations and standards is all about encapsulating business processes. It’s about clarifying and formalizing the way you do business – everything from taking an order to preparing goods for shipment, shipping and taking payment, and then allowing for scenarios like credit returns, faulty products or discounting – and appropriately recording that information.

Many companies have automated these processes by buying off-the-shelf IT packages and customizing them or, in many cases, by building their own custom-made applications. In either case, the modifications or new applications introduce yet another dimension to the puzzle: new pieces that must be shown to fit. This is the stage where compliance can become an even greater challenge.

In custom systems there can be a lot of people working on the development of the applications and errors can creep in, things can change. To withstand an audit – whether internal or external – a business has to be able to prove that the software system it has said it was going to build is the one it actually built, and that the software it built is the one it ultimately deployed – two separate processes. In essence, to achieve true compliance, businesses must be able to demonstrate the reliability and accuracy of any business process and show transparency throughout their development process.

It’s possible to demonstrate business process reliability and accuracy and have a transparent development process by manually compiling information at the time of an audit, but as you might imagine there is a high degree of overhead and risk associated with this reactive approach. There is a direct cost as well as the staff distraction and lost opportunity costs.

Establishing an effective governance framework for software delivery, what IBM Rational Software calls “Business Driven Development,” is a better choice. IBM Rational’s Software Development Platform provides guidance to customers with regard to best practices in developing software. Rational’s portfolio, requirements, testing, and software configuration management products provide a wide range of tools that capture information about what’s going on and what changes were made, what tests were done, what the design documents were and so on. It’s an ongoing process, so businesses can continuously capture information and maintain compliance. Using Rational’s automated workflow system for software delivery, a number of people in various locations can sign off on changes and allocate work.  Instead of one hour per day spent on compliance issues, an hour-long conference call per week may be all that is required.

As an example, various companies in the financial services industry have chosen to work with IBM Rational to strengthen their testing and requirements practices to improve traceability and compliance with regulations like Sarbanes-Oxley. One such customer, a leading provider of data processing and information management services solutions, replaced a competitive testing solution with tools from Rational to improve its application testing processes, resulting in streamlined IT governance and regulatory compliance capabilities.   

Aside from the assurance that comes from knowing the business is compliant, organizations can benefit from reduced risk and lowered costs in the long-term, improved infrastructure and project ownership, as well as better governance and understanding of business processes. With the right software delivery governance framework in place, the regulatory and standards compliance puzzle will look a lot more solvable.  

More Stories By Roger Oberg

Roger Oberg leads IBM Rational’s marketing team, including Rational’s strategy and planning, product and solution marketing, technical marketing, marketing programs, marketing operations and business partner marketing efforts.

Prior to joining IBM as director of market management in February 2003, when IBM acquired Rational Software, Roger was Rational's vice president of product marketing. He was vice president and general manager, visual modeling products from 1999 until 2002 and vice president and general manager, requirements management products from 1997 to 1999, overseeing 100%+ growth in both businesses. Roger joined Rational when Requisite Software was acquired in 1997, where he was vice president, marketing and sales. He was executive director for AIN at USWest, held vice president of engineering and marketing positions at XVT Software before that and spent nearly 10 years in sales, sales training, sales management and marketing positions for NBI, an office automation software and systems company. He has also served on the boards of two start-up software companies.

Comments (1) View Comments

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


Most Recent Comments
JDJ News Desk 08/09/06 12:29:42 PM EDT

Imagine trying to solve a puzzle without being certain what the end result should look like, much less how the pieces fit together. Now imagine trying to build the puzzle pieces themselves. Bit of a challenge? To say the least! But this is exactly the situation facing many business and IT executives when it comes to complying with the increasing number of standards and regulations in their industries today.

@MicroservicesExpo Stories
SYS-CON Events announced today that B2Cloud, a provider of enterprise resource planning software, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. B2cloud develops the software you need. They have the ideal tools to help you work with your clients. B2Cloud’s main solutions include AGIS – ERP, CLOHC, AGIS – Invoice, and IZUM
SYS-CON Events announced today Isomorphic Software, the global leader in high-end, web-based business applications, will exhibit at SYS-CON's DevOps Summit 2015 New York, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Isomorphic Software is the global leader in high-end, web-based business applications. We develop, market, and support the SmartClient & Smart GWT HTML5/Ajax platform, combining the productivity and performance of traditional desktop software ...
There is no doubt that Big Data is here and getting bigger every day. Building a Big Data infrastructure today is no easy task. There are an enormous number of choices for database engines and technologies. To make things even more challenging, requirements are getting more sophisticated, and the standard paradigm of supporting historical analytics queries is often just one facet of what is needed. As Big Data growth continues, organizations are demanding real-time access to data, allowing immed...
Containers and microservices have become topics of intense interest throughout the cloud developer and enterprise IT communities. Accordingly, attendees at the upcoming 16th Cloud Expo at the Javits Center in New York June 9-11 will find fresh new content in a new track called PaaS | Containers & Microservices Containers are not being considered for the first time by the cloud community, but a current era of re-consideration has pushed them to the top of the cloud agenda. With the launch ...
The world's leading Cloud event, Cloud Expo has launched Microservices Journal on the SYS-CON.com portal, featuring over 19,000 original articles, news stories, features, and blog entries. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. Microservices Journal offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. Follow new article posts on T...
SYS-CON Events announced today that MangoApps will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY., and the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. MangoApps provides private all-in-one social intranets allowing workers to securely collaborate from anywhere in the world and from any device. Social, mobile, and eas...
There are 182 billion emails sent every day, generating a lot of data about how recipients and ISPs respond. Many marketers take a more-is-better approach to stats, preferring to have the ability to slice and dice their email lists based numerous arbitrary stats. However, fundamentally what really matters is whether or not sending an email to a particular recipient will generate value. Data Scientists can design high-level insights such as engagement prediction models and content clusters that a...
The cloud has transformed how we think about software quality. Instead of preventing failures, we must focus on automatic recovery from failure. In other words, resilience trumps traditional quality measures. Continuous delivery models further squeeze traditional notions of quality. Remember the venerable project management Iron Triangle? Among time, scope, and cost, you can only fix two or quality will suffer. Only in today's DevOps world, continuous testing, integration, and deployment upend...
Chuck Piluso will present a study of cloud adoption trends and the power and flexibility of IBM Power and Pureflex cloud solutions. Speaker Bio: Prior to Data Storage Corporation (DSC), Mr. Piluso founded North American Telecommunication Corporation, a facilities-based Competitive Local Exchange Carrier licensed by the Public Service Commission in 10 states, serving as the company's chairman and president from 1997 to 2000. Between 1990 and 1997, Mr. Piluso served as chairman & founder of ...
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo in Silicon Valley. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place Nov 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 17th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading in...
It was just two years ago, in March of 2013, that the PaaS company dotCloud decided to open-source its container technology under the name "Docker." Docker quickly became a hit, with Docker Meetups spawning weekly worldwide and downloads occurring at record-breaking rates. The dotCloud team quickly changed direction, renamed the company "Docker," and brought in new CEO Ben Golub in July 2013 to lead the new business model. At the time, Docker was about a twenty-person company. Fast-forward to to...
To manage complex web services with lots of calls to the cloud, many businesses have invested in Application Performance Management (APM) and Network Performance Management (NPM) tools. Together APM and NPM tools are essential aids in improving a business's infrastructure required to support an effective web experience... but they are missing a critical component - Internet visibility. Internet connectivity has always played a role in customer access to web presence, but in the past few years u...
Working with Big Data is challenging, especially when decision makers depend on market insights and intelligence from your data but don't have quick access to it or find it unusable. In their session at 6th Big Data Expo, Ian Khan, Global Strategic Positioning & Brand Manager at Solgenia; Zel Bianco, President, CEO and Co-Founder of Interactive Edge of Solgenia; and Ermanno Bonifazi, CEO & Founder at Solgenia, discussed how a revolutionary cloud-based BI along with mobile analytics is already c...
2015 is the 10th birthday of Ruby on Rails (or simply called Rails), the popular open source web application framework that uses the Ruby programming language. Ever since Rails burst on the scene a decade ago it has continued to scale up as an elegant way to build dynamic websites quickly and efficiently. Rails has garnered a strong following, especially among tech startups. In fact, some of the best known firms out there are using the framework to build their sites. Examples of elegant sites bu...
We just finished the first O’Reilly Software Architecture Conference and the overwhelming most popular topic was microservices. Why all the hype about an architectural style? Microservices are the first post-DevOps revolution architecture. The DevOps revolution highlighted how much inadvertent friction an outdated operations mindset can cause, starting the move towards automating away manual tasks.
We’re living in exciting but demanding technological times. Big Data, Internet of Things, Apple Watch, ubiquitous computing, smart machines, robotics, and home automation . . . things that were the talk of science fiction only a few short years ago are on every CIOs wish list today. But to the point, the revolution in technology has led to major shifts in how organizations today ideate, plan, develop, and deploy software solutions. It used to be that software release cycles would take upwards of...
“This win means a great deal to us because it is decided by the readers – the people who understand how use of our technology enables new insights that drive the business,” said Matt Davies, senior director, EMEA marketing, Splunk. “Splunk Enterprise enables organizations to improve service levels, reduce operations costs, mitigate security risks, enhance DevOps collaboration, create new product and service offerings and obtain deeper insight into customer behavior. Being named Best Business App...
Software is eating the world. Companies that were not previously in the technology space now find themselves competing with Google and Amazon on speed of innovation. As the innovation cycle accelerates, companies must embrace rapid and constant change to both applications and their infrastructure, and find a way to deliver speed and agility of development without sacrificing reliability or efficiency of operations. In her Day 2 Keynote DevOps Summit, Victoria Livschitz, CEO of Qubell, discussed...
“Oh, dev is dev and ops is ops, and never the twain shall meet.” With apoloies to Rudyard Kipling and all of his fans, this describes the early state of the two sides of DevOps. Yet the DevOps approach is demanded by cloud computing, as the speed, flexibility, and scalability in today's so-called “Third Platform” must not be hindered by the traditional limitations of software development and deployment. A recent report by Gartner, for example, says that 25% of Global 2000 companies will b...
What exactly is a cognitive application? In her session at 16th Cloud Expo, Ashley Hathaway, Product Manager at IBM Watson, will look at the services being offered by the IBM Watson Developer Cloud and what that means for developers and Big Data. She'll explore how IBM Watson and its partnerships will continue to grow and help define what it means to be a cognitive service, as well as take a look at the offerings on Bluemix. She will also check out how Watson and the Alchemy API team up to off...