nl There is also a DUTCH VERSION of this site


My book on IT infrastructure architecture





More articles

01 Oct - 31 Oct 2011
01 Sep - 30 Sep 2011
01 Jul - 31 Jul 2011
01 Jun - 30 Jun 2011
01 May - 31 May 2011
01 Apr - 30 Apr 2011
01 Mar - 31 Mar 2011
01 Feb - 28 Feb 2011
01 Jan - 31 Jan 2011
01 Dec - 31 Dec 2010
01 Nov - 30 Nov 2010
01 Oct - 31 Oct 2010
01 Sep - 30 Sep 2010
01 Aug - 31 Aug 2010
01 Jul - 31 Jul 2010
01 Jun - 30 Jun 2010
01 May - 31 May 2010
01 Apr - 30 Apr 2010
01 Mar - 31 Mar 2010
01 Feb - 28 Feb 2010
01 Jan - 31 Jan 2010
01 Dec - 31 Dec 2009
01 Oct - 31 Oct 2009
01 Sep - 30 Sep 2009
01 Aug - 31 Aug 2009
01 Jun - 30 Jun 2009
01 Apr - 30 Apr 2009
01 Mar - 31 Mar 2009
01 Jan - 31 Jan 2009
01 Dec - 31 Dec 2008
01 Oct - 31 Oct 2008
01 Sep - 30 Sep 2008
01 Aug - 31 Aug 2008
01 Jul - 31 Jul 2008
01 Jun - 30 Jun 2008
01 May - 31 May 2008
01 Apr - 30 Apr 2008
01 Mar - 31 Mar 2008
01 Feb - 28 Feb 2008
01 Jan - 31 Jan 2008
01 Dec - 31 Dec 2007
01 Nov - 30 Nov 2007
01 Oct - 31 Oct 2007
01 Sep - 30 Sep 2007
01 Aug - 31 Aug 2007
01 Jul - 31 Jul 2007
01 Jun - 30 Jun 2007
01 May - 31 May 2007
01 Apr - 30 Apr 2007
01 Mar - 31 Mar 2007
01 Feb - 28 Feb 2007
01 Jan - 31 Jan 2007
01 Dec - 31 Dec 2006
01 Nov - 30 Nov 2006
01 Oct - 31 Oct 2006
01 Sep - 30 Sep 2006
01 Aug - 31 Aug 2006

Links

Recommended
Ruth Malan
Bredemeyer Consulting
Gaudi site
Byelex
XR Magazine
Esther Barthel's site on virtualization



Misc

Powered by Pivot - 1.40.1: 'Dreadwind' 
XML: RSS Feed 
XML: Atom Feed 


Studying TOGAF

25 April 10 - 00:00
Area: default - Link to this article

During most of 2009 a group of cllegues from Logica studied theThe Open Group Architecture Framework (TOGAF). The main reason for thiswas to gain more knowledge of TOGAF, but many of them also wanted toget ready for TOGAF certification. Together with two collegues I wasthe manager of the process.   

Studying the TOGAF book was no easy task. The book contains 778 pageswith a high information density. It is no easy read. We agreed to studyTOGAF book chapter-by-chapter from cover to cover. In 10 eveningsessions we would discuss any unclarities and questions we had on thematerial. In the process we learned a few lessons I want to share withyou:

  • It is not practical to read the book cover to cover. In the early chapters terminology is used that is explained much later in the book.
  • The best way is to start reading part III (ADM Guidelines and Techniques) and part IV (Architecture Content Framework) and then read the actual ADM phases (part II).
  • The book (or the online version of TOGAF for that matter) is not perfect, it contains some errors and creates some confusion of terminology. For instance: what exactly is a "building block" according to TOGAF? I took us hours of discussion to reach a consensus (which I verified with one of the authors of TOGAF when I visited the Open Group): a building block is everything. The same unclarity we had on the term "Enterprise Continuum" (read chapter 39 in the book). The same goes for the difference between artifacts and deliverables.
  • Not all parts of TOGAF are of equal maturity. The ADM is quite extensive (although most details are in the technical architecture part), but for instance the chapters on security architecture, SOA and architecture maturity models are very thin

Apart from the points above (and some extra issues I forgot) TOGAF isstill a very rich source of Enterprise Architecture information,containing many insights, checklists and models that can be used inpractice.

It just needs a little bit more maturing.

Is your data safe in the cloud?

11 April 10 - 00:00
Area: default - Link to this article

The use of cloud services is slowly becoming commonplace. Especially for non-mission critical applications like email the use of cloud services could be interesting. But what about the security of your data in these cloud email services?    

Almost all email infrastructures in business are similar. Email is not distinctive and are therefore often regarded as a commodity. But an email infrastructure is not as simple as it seems. End users want to read and edit their email in many ways and places. Processing email is often not only done from the workplace, but also from home, at customers or through a mobile phone. Email should therefore be accessible through various channels, and outside office hours. Companies must implement their email infrastructure accordingly. Another email phenomenon is spam. More than 90% of all email in the world is spam. Email administrators must implement adequate measures to prevent spam. Scanning email for viruses is also a system manager's task. All in all a lot of work for an email service that can be seen as a commodity.

An alternative is to us an email service from the cloud. The costs of using cloud services is generally much lower than maintaining an email infrastructure in-house. The reliability is high and management is taken care of. Especially for small businesses and start-ups using cloud based applications can be very attractive.

There are several providers of cloud based email services. Well known are Google's Gmail, Microsoft (Hotmail), but there are also many smaller providers active in this market. Google offers Gmail services for end users but also email services for businesses. There are 400,000 businesses using Gmail already.

It is important for companies to verify how security of data stored in the cloud (such as business-critical information in emails) is implemented. Before doing business with a cloud provider the contractual conditions should be checked. Some points to observe are:

  • How does the cloud provider guarantee that data is securely stored and that no other persons or parties can access your data (do not forget to include the physical security of the data centers, is this audited by a third party?)
  • How is it ensured that no data is lost, destroyed, etc. Is it possible that you - or an external party assigned by you - perform an audit at the cloud provider?
  • What happens to your data when the cloud provider goes bankrupt, gets acquired or if the service is no longer offered?
  • Where is your data physically stored? On U.S. servers? Is the data under U.S. law (such as the Patriot Act and SOX)?
  • What is the exit strategy if you decide to move your data from one cloud provider to another? Is this allowed?
  • In what format will you get your data back in such a case? Is the data in the cloud provider to actually destroyed? Can this be checked?

All valid points I think. But the big question is: Who really asks these questions to the cloud providers? I expect most companies that use cloud services (often for financial reasons) do not address all points above.

Or did I miss something?


More articles: See left pane.
Twitter LinkedIn Facebook RSS


About Sjaak Laan

Sjaak Laan

I am 46 years old and married with Angelina. We have 3 children of 13, 8 and 6 years old. We live in The Netherlands, in a place called Drachten

I work for Logica as Principal IT Architect. I have 20 years IT experience.

I own the following certificates:

ITAC Master Certified IT Architect

CISSP_logo CISSP (Certified Information Systems Security Professional)


TOGAF8_Certified_web TOGAF Certified Architect



I am a member of the:


I manage my business contacts using Linkedin.


I can be reached through sjaak.laan [ a t ] gmail [dot] com.

This site states my opinion only, and not nessecarily the opinion of my employer or of the clients I work for.