2007/05/15

Microsoft Troubles - III

Microsoft threatens to Sue The Free World.

Groklaw comments on MSFT threatening to sue "Patent Violations".

CNN/Fortune Original article (probably)

ZDnet (Mary Jo Follet)

2007/05/06

Driving Disks into the future

Robin Harris of ZDnet "Storage mojo" has written a series of posts on factors affecting the future of Disk Storage. These are my reactions to these quotes and trends, especially in flash memory.



Flash getting "70% cheaper every year" - hence more attractive:



"Every storage form factor migration has occurred when the smaller size reached a capacity point that enabled the application, even though it cost more per megabyte."

"With flash prices dropping 70% a year and disks 45%, the trend is inexorable: flash will just get more attractive every year."




The problems with RAID and Big Drives:



"There are three general problems with RAID: Economic, Managerial, Architectural"

  • RAID costs too much
  • Management is based on a broken concept [LUN's]
  • Parity RAID is architecturally doomed
"The big problem with parity RAID is that I/O rates are flat as capacity rises. 20 years ago a 500 MB drive could do 50 I/O per second (IOPS), or 1 IOPS for every 10 megabytes of capacity. Today, a 150 GB, 15k drive, the ne plus ultra of disk technology, is at 1 IOPS for every 750 MB of capacity. Big SATA drives are at 1 IOPS per several gigabytes. And the trend is down."






What a "Web Business" wants from Storage Vendors:



What a Web Business wants [Don MacAskill of 'smugmug']:

  • External DAS for the database servers .. and dual-controller arrays [simplified recovery after server death]
  • Spindle love. Typical array has 14.
  • No parity RAID. RAID 1+0.
  • 15k drive love. Speed is good.
  • Love drive enclosures with odd numbers of drives. Makes keeping one hot spare easy.
  • Love big battery-backed up write caches in write-back mode. Because super-fast writes are “. . . easily the hardest thing in a DB to scale.”
  • Disable array read caching: array caches are small compared to the 32 GB of RAM in the servers. reserve all array cache for writes.
  • Disable array pre-fetching: the database knows better than the array.
  • Love configurable stripe and chunk sizes. 1 MB+ is good.


"Don should be the ideal array customer: fanatical about protection; lots of data; heavy workload, not afraid to spend money. Yet he isn’t completely satisfied, let alone delighted, by what’s out there. A lot of the engineering that goes into arrays is wasted on him, so he’s paying for a lot of stuff he’ll never use, like parity RAID, pre-fetch and read caching."




And 'the future of Storage'



The future of storage:

"The dominant storage workload of the 21st century. Large file sizes, bandwidth intensive, sequential reads and writes."



"(OLTP) Not going away. The industry is well supplied with kit for OLTP. It will simply be a steadily shrinking piece of the entire storage industry. OLTP will keep growing, just not as fast as big file apps."



"Disk drives: rapidly growing capacity; slowly growing IOPS. Small I/0s are costly. Big sequential I/0s are cheap. Databases have long used techniques to turn small I/Os into larger ones. With big files, you don’t have to."



"The combination of pervasive high-resolution media, consumer-driven storage needs, expensive random I/0s and cheap bandwidth point to a new style of I/O and storage. The late Jim Gray noted that everything in storage today will be in main memory in ten years. A likely corollary is that everything analog that is stored today will be digital in 10 years."

2007/05/04

Response to Cognitive Work Load - Huh?

Another related question I've been trying to even discover the correct name for over the last 10 years.
I can't believe something so fundamental to I.T. and the knowledge economy could go unstudied.

I frame it as "Human cognitive response to workload".

There is a whole bunch of data on "human physiological response to workload" - like the US Navy and how long stokers can work at various temperatures (and humidity?).

This goes to the heart of computing/programming - being able to solve difficult problems, and managing/reducing defects/errors. In my career, I got very tired of bosses attempting to get more work done by "forced marches". 80 hour weeks aren't more productive - they just insure a very high defect rate and amazing amounts of rework.

The best I have been able to find is Dr Lisanne Bainbridge and her work on "mental load".

What I wanted to discover is:
  • that for each individual there is an optimal number of 'brain work' hours per week
  • the effect of physical & mental fatigue and sleep deprivation on 'brain work' output, degree of difficulty tasks and error rate.
  • the recovery time for strenuous (mental) effort - working 50, 75 and 100 hours / week requires recovery, but how much?


If you, gentle reader, have any leads/pointers on this I really appreciate it :-)

Even if someone knows what the field is called or refer me to the peoplethat do know.

Teams - Where's the proof?

Addition 24-May-2007
Johanna Rotham author and consultant answered an e-mail from me.
Johanna is involved in the Jerry Weinberg and Friends AYE - Amplifying Your Effectiveness - conference. Johanna's book "Behind Closed Doors" is on this blog and highly recommended for I.T. Technical Managers. Another interest of Johanna's: Hiring the Best People.

Johanna's thoughtful response:
Part of the problem is I can't do two of the same project where one is set up as an integrated team and the other is a bunch of people who don't have integrated deliverables. I can tell you that the projects where the people are set up with committed handoffs to each other (Lewis' idea that one person can't work without the rest of them), have better project throughput (more projects per time period) than the groups of people who do not have committed handoffs to each other. But that's empirical evidence, not academic research.

2007/05/02

Defining I.T. Service Management

Objectives (The What)


Having begun around 1950, the world of Commercial I.T. is now mature in many ways. "Fields of Work" and professional taxonomies are starting to become standardised. Professional "Best Practices" are being documented and international standards agreed in some areas.

For the first time, audits of one of the most pragmatic I.T. disciplines, "Service Management", are possible with ISO 20,000. Business managers can now get an independent , objective opinion on the state of their I.T. operations - or of their outsourcers.

Being "documented common sense", ITIL and the related ISO 20,000 are good professional guides, but not underpinned by theory. Are there any gaps in the standard? How does Service Management interface with other IT Fields of Work? and What changes in those other disciplines are necessary to support the new audited practice?

Analysis of the full impact of I.T. Service Management, creation of a full taxonomy and definitions of "I.T. Maturity" are beyond the scope of a small "single researcher" project.

Approach (The How)

ITIL Version 2 and 3 and ISO 20,000, as published documents, form the basis of the project.
Prior work in the field has yet to be identified. Secondary research will be the first step.

Each of the models will be codified and uniformly described, then a 3-way comparison performed. A Gap Analysis done of the 3 models, and a formal model built describing "I.T. Service Management" and its interfaces built and each of the existing approaches mapped to it.

Importance/Value (The Why)

The global economy, especially businesses in the "Western Industrialised World" are increasingly dependent on I.S./I.T. and their continued efficient operation. Corporate failures partially due to I.S./I.T. failure have occurred. Improving delivery of I.T. Services and the business management and use of them is important to reduce those failures in the future.

The advent of ubiquitous and universal computing requires concomitant development of business management.

There assertions are considered axioms in this context:
  • Organisations these days are dependent on their I.T. Operations.
  • I.T. cuts across all segments of current organisations.
  • I.T. defines the business processes and hence productivity of the whole organisation.
  • What you don't measure you can't manage and improve.
  • Improving the effectiveness of I.T. Operations requires auditable processes.
  • Common I.T. Audit and Reporting Standards, like the Accounting Standards, are necessary to contrast and compare the efficiency and effectiveness of I.T. Operations across different organisations or different units within a single organisation.
I.T. is a cognitive amplifier, it delivers "cheaper, better, faster, more, all-the-same", through the embedding of finely detailed business processes into electronic (computing) systems.

For simple, repetitive cognitive tasks, computers are 1-5,000 times cheaper than people in western countries.

From this amplification effect, computers still provide the greatest single point of leverage for organisations. The underpin the requirement to "do more with the same", improving productivity and increasing profitability.

The few studies of "IT Efficiency" that are available show that IT effectiveness is highly variable and unrelated to expenditure.

The value-add to business of a complete I.T. Service Management model is two-fold:
  • manage down the input costs of the I.T. infrastructure and Operations and,
  • audit assurance for the board and management of the continued good performance of I.T. Operations.


[A 1990 HBS or MIT study into "White Collar Productivity" - reported a decrease in the first decade of PC's]

Previous Work (What else)

There is much opinion in the area, without substantive evidence: e.g. Nick Carr and "Does IT Matter?" The McKinsey report/book on European Manufacturers and their I.T. expenditure versus financial performance shows there is no co-relation between effort (expenditure) and effect (financial performance).

"Commonsense" IT Practitioner approaches, SOX, ITIL and COBIT and others, do not address the measuring and managing of I.T. outputs and interfaces and their business effects, utiliation and effectiveness.

Jerrry Landsbaum's 1992 work included examples of their regular business reports - quantifiable and repeatable metrics of I.T. Operations phrased in business terms.

Hope to find (The Wherefore)


  • Create a formal model for I.T. Operations and its performance within and across similar organisations.
  • From the model, generate a standard set of I.T. performance metrics.
  • Generate a set of useful I.T. Operations Business Impact metrics.


Report Outline


  • Coded process models of ITIL version 2, 3 and ISO 20,000.
  • 3-way comparison of ITIL version 2, 3 and ISO 20,000.
  • Gap Analysis of ITIL version 2, 3 and ISO 20,000 models.
  • Formal I.T. Service Management model.
  • Common I.T. Service Management internal metrics and Business Impact
    metrics flowing from the model.
  • Interfaces to other I.T. and business areas and changes necessary to support audits of I.T. Service Management.
  • Further Work and Research Questions


Execution Phases

  • Learn ITIL Version 2 - Service Managers Certificate course [complete]
  • Learn ISO 20,000 - IT Consultants training [in process]
  • Acquire and learn ITIL Version 3 [depends on OGC availability. mid/late 2007]
  • Create/identify process codification.
  • Codify ITIL version 2, 3 and ISO 20,000
  • Compare and contrast coded descriptions. Report.
  • Create/adapt process description calculus for formal model.
  • Create formal I.T. Service Management model.
  • Derive interfaces to business and other I.T. processes
  • Derive internal metrics, role KPI's and business impact metrics
  • Finalise report.

2007/05/01

Bookshelf I

These are books on my bookshelf I'd recommend. Notes on them later.
Pick and choose as you need.

Personal Organisation


Personal Efficiency Program - Kerry Gleeson [older]
Getting Things Done - David Allen [newer]

Teams, People, Performance


Practice What you Preach - David H Maister [Numerical model relating Profitability to Staff Morale/Treatment]
How to be a Star at Work - Robert E Kelley
Team Management Systems - Margerison & McCann

Maimum Success: Breaking the 12 Bad Business Habits before they break you - Waldroop & Butler
[rereleased as] The 12 Bad Habits that hold Good People bBack

No Asshole Rule - Robert Sutton

Execution - the art of Getting things done (in big business)


Who says Elephants can't Dance - Louis V Gerstner [on Execution and 'Management is Hard']
Execution - Bossidy & Charan
Confronting Reality - Bossidy & Charan

Gallup Research


First, Break all the Rules - Buckingham & ??
Now, Discover your Strengths - Buckingham & Clifton [old]
StrengthsFinder 2.0 - Tom Rath [current]
12: The Elements of Great Managing - Wagner & Harter
The One thing you need to know - Buckingham

Off the Wall - Different ideas on Management and Leadership


Contrarian's Guide to Leadership - Steven B Sample
Simplicity - Jensen

Intelligent Leadership - Alistair Mant [old]
Maverick - Ricardo Semler. [old]
The 7-day Weekend - Ricardo Semler [new]

Wear Clean Underwear - Rhonda Abrams
Management of the Absurd - Richard Fearson
Charisma Effect - Guilfoyle

Computing Management


Measuring and Motivating Maintenance Programms - Jerry Landsbaum
any of the 50 books by Robert L. (Bob) Glass

Why Information Systems Fail - Chris Sauer
Software Failure : Management Failure - Flowers

Jerry Weinberg Prolific author - Quality, People, Teams, Inspections & Reviews, technical, ...
Quality Software Management - 4 book series
Becoming a Technical Leader
Weinberg on Writing - the Fieldstone Method
Secrets of Consulting
Psychology of Computer Programming
-- and another 40 or so --

Peopleware - DeMarco & Lister from Dorset House Publishing specialising in why people matter.

Project Retrospectives - Norm Kerth
Programming on Purpose - PJ Plauger

Mythical Man Month - Fredrick Brooks [I don't have a copy]

"IT Doesn't Matter" - Nicholas G Carr [read a synopsis, don't buy]

2007/04/20

The End of the Internet, or the Microsoft Users Net-Meltdown?

The 2005 Australian Computer Crime and Security Survey(PDF) reports that at the end of 2004 "the hackers turned pro". The 2006 ACCSS indexACCSS index may be easier for downloads. [In 2016, the ACCSS was replaced by "the BDO and Australian Cybercrime Survey".]

For 2-3 years now, most malware has satisfied the definition of Organised Crime:
it's theft, it's purposeful, it's co-ordinated.

In an August 2006 post, I reported the ACCSS comments and new comments from SANS .

ZDNet now report that Rootkits becoming increasingly complex and operate by stealth. They say:

Rootkits -- malicious software that operates in a stealth fashion by hiding its files, processes and registry keys--have grown over the past five years from 27 components to 2,400, according to McAfee's Rootkits Part 2: A Technical Primer (PDF).
If you use a Microsoft system and connect to the Internet without extensive protection, you should be afraid, very afraid. And even large organisations who do everything right, are still open to targetted "zero day" attacks. The first Windows Vista security problems are being reported. It's better than their previous efforts, but still contains significant security flaws. The Whitehouse mandated a minimum security configuration for all US Federal Government Vista destops.


2007/04/10

Microsoft troubles - II

Follow up to a previous post on MSFT hitting a 'financial pot hole' by 2010. The numbers look very, very bad to me. The seeming lack of management response and apparent leadership would deeply disturb me as a shareholder...
The Paul Graham piece Microsoft is Dead and the follow-up were a prompt for this post.

2007/04/09

Startups: selecting and nuturing.

A comment on Paul Grahams post Why to Not Not Start a Startup.

Paul along with Robert T Morris (author of the 1988 Morris Worm, now MIT assoc. professor) run a Venture Capital firm.
They run Startup School as well. An exceptional idea.

At the end of this is a list of Paul's 16 points.

2007/04/08

Web 2.1 - Meta-tags by default

Why do we need fine products like Content Keeper, when the problem is one that should be solved at source?

[11-Apr-2007 Addition]
The "Kathy Sierra" affair caused Chris Locke, co-author of Cluetrain Manifeso to post his version/take. My take from reading about the affair.
This whole affair unfolded because "Web 2.0" not just allows, but
enforces, anonymity. Provable Identities don't exist.

In an hour's scrolling through posts, I never saw this point [or anything like it] made.
How far would this thing have gone if the police could've tracked the posters quickly and unequivocally?
Presumably within a day or so the perpetrators would've been identifiedand action initiated, legal jurisdictions allowing.

There are good reasons to allow & support anonymity on the Web -"Freedom of Speech" is part of it, along with denying Political suppression and enabling 'whistleblowing'.

But the ugly human stuff of stalking, intimidation and control-by-fear need effective checks and consequences.

[End Addition]

Knowing the type of content you are downloading is a basic right - the same way that we don't go into newsagencies, bookshops and libraries and get surprised by the content. The same way that various TV stations will broadcast 'social content' warnings before some programs (violence, 'disturbing or graphic images', 'images of deceased people' and even 'images of surgery'). Our society has very well developed methods of flagging content that some audiences may wish to avoid - right up to full TV, movie & print "classification" and censorship. Plus we have blanket bans, enshrined in legislation, on things like "kiddie porn" and "snuf movies".

Simple minded banning of pages based on keywords or URL makes a priori judgements of what will and won't offend the audience - or under high-control regimes, what is or is not banned/seditious material. Then it becomes a simple "arms race" - two camps competing against one another (attack and defense), and by definition the reactive side can only respond once a new exploit/mechanism is noticed and identified. Yep, it's effective against people obeying the rules, but at the price of massive collateral damage and never being sure you're not compromised.

Generally, the USA is particularly sensitive to sexual matters, but not to violence. Sweden mostly has very different mores...
Filtering all pages that mention 'breast' or it's (English language) derivatives and colloquialisms fails in many ways, especially for medical & pregnancy issues ('false positives') and is easily circumvented by mistyping, obfuscation or using images ('false negatives') and is completely irrelevant for non-English language pages.

In the world of IT Security, this is why we now have Firewalls andIntrusion Detection Systems [and now systems that actively seek to confuse/entrap/counter attackers.] Funny - just like in the real world.

I'm thinking the web-server is the place to insert consistent meta-tags into content.
And that requires a minimum additional two publication stages - author, reviewer, editor/publisher - [as described by Peter Miller in his Aegis Documentation piece (82Kb PDF ) Aegis Is Only For Software, Isn't It?].

Nothing publicly published should go untagged - and that needs independent review and an enforced process to
[OK, so where does that leave the wonderful world of 'blogs'?]

We live in interconnected communities, now global in Cyberspace. All of us have sensitivities that should be respected and the publishing world evolved over many centuries a tradition of "no surprises". It's a convention that has served us well before Cyberspace, it would serve us there as well or better - with everyone "just one click away" from your content.

Free Speech is only a Right in some countries.
Censorship is a given and necessity, even in the most "enlightened" countries - where it might be called 'national security' :-)
And there are globally shared mores/values/injunctions against such things as child pornography and worse.

It's not an even playing field, and will never, can never, be.

My opinion is that laws like the DMCA [USA - Digital Millennium Copyright Act] and the Australian "anti-spam and pornography" laws [no refs] are wrong-headed and irrelevant at best - and counter-productive at worst.

With the Global Net and One Shared Cyberspace, and many cultures, beliefs, religions, etc etc, "Web 2.0" needs to add:
mandatory content tagging.

Then we can adibe by our tired-and-true convention "no surprises" and respect all our differences and sensitivities.

2007/04/03

Selling Good Goverance - I.T. Services Audits

IBM got to be bigger, by turnover, than everyone else combined for nearly two decades, accounting for up to 60% of IT sales. One of the chief factors was they were good salesmen - they knew their audience: who to target and what things they wanted (and only sell to people that can sign the cheque!)

IBM didn't sell to "techos" - but managers, the more senior the better. They talked their language (cheaper, better, faster) and gave solid "Dollars and Cents" Costs and Benefits. They got to come back because they generally made good on those promises.

Selling I.T. Services Audits, Security and Continuity


These functions are Goverance related and should be contolled and reported directly to Board Level - not even senior management or CEO.

Board Pitch


Can your Business run without Accounting??
  • No!

Can it run without it's I.T. services?
  • No!

What part of your business isn't affected by I.T.?
  • None!

Why do you have Accounting Audits?
  • "Have to" - regulatory requirement.
  • "credibility enhancer" - investors and owners can trust the figures claimed.
  • Integral to Good Goverance. The things the Board want done, are being done.

Why don't you do I.T. Services, Security and Continuity Audits?
  • Ummmmm?


If you're entrusted with husbanding other peoples money, not assuring and insuring the I.T. Services of the business isn't sound practice.

Major failures/events in anyone of these functions is high impact: They are "Bet the whole company".
The sort of decision that the owners need to make, and make consciously.

Supporting Facts


From a Sarbanes Oxley site:
Fifty percent of companies that lose their data go out of business immediately and ninety percent don't survive more than two years, according to research firm Baroudi Bloor International. ...
Only three percent of all data loss is caused by fire, flood and other such disastrous events. The most common causes are hardware or system malfunction (44 percent), human error (32 percent), software corruption (14 percent) or viruses (7 percent). ...
And remember, without your business's data, there's no business at all.


In a brief report on a fire in a British Telecom hub in Manchester affecting 136,000 phone lines:
  • 86 percent of firms affected found the fire was disruptive and it had an impact on voice communications in 60 percent of those polled....

  • Just 34 percent had a disaster recovery or business continuity plan in place ....

  • Those polled showed low awareness of solutions, nor did most appreciate the need for business continuity planning. 71 percent saw little value in automatic call diverts in emergency situations and 70 percent of those polled were unaware that banks expect businesses applying for loans to have a proven disaster recovery plan in place.


In 10 Steps to surviving a disaster(PDF)
According to the Association of Records Managers and Administrators, about 60 percent of businesses that experience a major disaster such as a fire close within two years. According to Labor Department Statistics, over 40 percent of all companies that experience a disaster never reopen and more than 25 percent of those that do reopen close within two years.


And from Glen Abbot, Scotland’s leading supplier of Business Continuity Services.

Business Failure

A business failure is defined as:
"An occurrence, and/or perception, that threatens the operations, staff, shareholder value, stakeholders, brand, reputation, trust and/or strategic/business goals of an organisation."

In a five-year period, twenty percent of companies within the UK will suffer some kind of serious disruption to their operations. This may be as a result of an IT failure, emergencies such as fire or flood, or some other unplanned disruption. Eighty percent of those companies who suffer a serious disruption suffer severe losses or fail to survive in business during the following eighteen months (National Audit Office).


And yet more in the Reader Comments section of this piece on 'Continuity Central'.

2007/04/02

Three Metrics to change our business

In a previous post, Research Outline,3 sets of metrics were proposed that, if applied consistently across large organisations, would change the face of our industry (IT&T), perhaps even support the transition to a Profession.

"IT is done for a Business Benefit"


After 50+ years of doing it, we are looking at the end of the Silicon Revolution by 2010. Already we've passed the end of Moore's Law for CPU speed [Q1-2003]. But more than that - Business & Government are getting hard-nosed about IT&T delivering 'value'.

The IT recession we're just coming out of was a direct reaction against the perceived needless waste of Y2K. The other in 1991 was the marker that all the 'easy wins' in IT had been achieved and IT itself could be cut.

Big Business and Government account for over 60% of the Australian GDP. Around 45% of GDP is influenced directly by IT&T - with an investment rate of around 10% - $45Bn/year for 'the majors'. Globally, multiply this by 50-60 times. [Source: ABS surveys]

Compare this to the ~$50Bn earnings by all companies listed on the ASX. Leveraging IT&T whilst containing costs is a central concern of all good business execs - and becoming more so. Shaving 1% off IT&T inputs goes directly to the bottom line and allows good companies to easily outperform their competitors.

My belief is that the first people to adequately address these questions in quantifiable terms will dominate the market . And what better way than to charge than a percentage of the realised savings? For a consulting firm, that's putting it's money where it's mouth is...

Metrics


The three sets of figures I'd like to produce are linked to this central question:
Doing More with Less.

  • What's the leverage IT&T gives us? [Virtual Employees]
    • Year on Year reporting from a consistent base.
  • Where do our IT&T costs go? [Standard reporting in Business Inputs andOutputs]
    • Are we getting a good deal from our IT&T?
    • Comparing to what?
  • How effective are our IT&T processes? [Benchmarked KPI's]
    • If ITIL is the answer, how well are our folks doing it?
    • How much more room for improvement is there?


And the worst thing that could happen is:
You find out your IT&T people do a good job.

2007/03/23

Future Forecasting for I.T. - how close to 'mature' is the market?

Jonathon Schwartz of SUN Microsystems posted an article on SUN and Intel Alliance. SUN may be coming back from the brink - with the 'opening' of Solaris, they could have realised again they're a hardware company (and do great servers).

There was a line that gave me pause:
To be clear, this isn't about displacing one another's competitors, it's about getting as big a piece of the future as possible. The market's not shrinking, after all.


I was struck by The market's not shrinking, after all.

In 2000, the personal-use PC's were 'desktops' - now laptop sales are at least equal or higher...
The world is changing - the I.T. market is very close to maturation - near 'topping out' perhaps.

Take for instance the Gartner predictions for desktop/laptop sales in next 12 months (can't remember the link).
They forecast a 10.6% growth in sales volume (to 255+M units) but only 4.x% increase in sales dollars.

SUN have announced their "DataCentre in a Container". Think that through - these are effectively very nicely packaged *mainframes* of MIMD(non-homogeneous) design versus the classic MIMD (SMP) design. You get a 'volume discount' by buying excess capacity - and it comes prebuilt. Your techs should not ever be opening the doors. It really will be "everything in software". And the box could be anywhere within a few milliseconds down the network.

Some organisations will resell capacity, not like the old Processing Bureaus and lately (web hosting), but fractional amounts of a 'box'. Just like leasing office, storage or wharehouse space.

The big change will be corporations adopting the same scale-up/scale-out architectures as the large internet companies - the Internet Data Centre rather than the usual Enterprise Data Centre...

Moore's Law on CPU speed broke in Q1-2003 - but those pesky engineers are still building smaller devices and putting more transistor on a chip - that means more bang for your CPU buck for maybe another 10 years [definitely 2010, but why not 2015].

Scenario:
Organisation buys a DC box. Keeps it for it's economic life (dominated probably by disk size/failures), then replaces it.
The new box *will* have more CPU power, or cost less per processing 'unit', modulo disk pricing.

All of a sudden servers (the things that SUN sells) will be bought in large quanta, kept and replaced in the same large quanta.
And each quanta will feature better "bang per buck". What we've seen in desktops and servers, is that unit price can't be maintained - the price of the low-end units will keep drifting down.

The West's economy is getting close to being saturated with corporate compute power...
Real growth might occur in the developing world - that's a complex equation that includes social and cultural variables.

So will the market for server CPU's keep expanding? I think we are close to maturation of the I.T. industry, within 30-50% of the maximum CPU demand... Which means very close to total sales dollars.

Modulo brand new applications of course :-)
Artificial Intelligence, Knowledge Management or Data Mining/Business Intelligence could actually deliver something useful oneday.

2007/03/22

I.T. in context

Here are Questions, not Answers...
Things that I'd like to explore and have better answers on.

Most of these questions probably don't have permanent 'answers' - each generation, each culture, each industry has to define and redefine them for their mix of technology, political structure and workplace organisation I suspect.

2007/03/20

Quantifying the Business Benefits of I.T. Operations

Objectives (The What)


That "I.T. is done for a Business Benefit" seems axiomatic.

But where's the evidence after 50-60 years of computing? It's not coming out our ears - just the reverse.

Businesses understand the importance of hard data and it's through analysis for marketing, but don't apply the same techniques or management principles to their I.T. Operations.

I'd like to model and quantify the Business Benefits of I.T. Operations across multiple organisations to provide baselines, benchmarks and trend analysis. The impact of all aspects of I.T. is beyond the scope of a single researcher project.

Approach (The How)



Data is fundamental input for analyses. Leveraging what's available means the outputs can be commercially reproduced and aer within the project budget (zero cost).

Three separate data streams will be mined:
  • Historic "ITSM" tool data from multiple organisations.
  • Detailed I.T. accounting information from selected organisations.
  • Primary research in one organisation to collect and report "FTE equivalents provided" by I.T.


[FTE = Full Time Employee. Otherwise, "virtual employees". What head count and cost would be needed to provide similar services with 1965 technology.]

Importance/Value (The Why)



There propositions are to be tested:
  • I.T. is done for a Business Benefit.
  • Business Benefits, tangible or intangible, should be measurable.
  • Organisations these days are dependent on their I.T. Operations.
  • I.T. cuts acros all segments of current organisations.
  • I.T. defines the business processes and hence productivity of the whole organisation.
  • What you don't measure you can't manage and improvve.
  • Improving the effectiveness of I.T. Operations requires reliable metrics.
  • Commin I.T. Reporting Standards, like the Accounting Standards, are necessary to contrast and compare the efficiency and effectiveness of I.T. Operations across different organisations or different units within a single organisation.


I.T. is a cognitive amplifier, it delivers "cheaper, better, faster, more, all-the-same", through the embedding of finely detailed business processes into electronic (computing) systems.

For simple, repetitive cognitive tasks, computers are 1-5,000 times cheaper than people in western countries.

From this ampflication effect, computers still provide the greatest single point of leverage for organisations. The underpin the requirement to "do more with the same", improving productivity and increasing profitability.

Subtle shifts in this whole-organisation amplification ratio (e.g. from 100:1 to 95:1 or 105:1) are impossible for isolated individuals to detect unaided. But they make very large differences to the 'global' organisation output and productivity.

In retail businesse, the gross margin is often around 2.5%. Reducing whole company productivity by 5% will destroy it's profitability, and without any metrics, will be impossible for any management team to identify and resolve.

The few studies of "IT Efficiency" that are available show that IT effectiveness is highly variable and unrelated to expenditure.
My proposition is that "intuitive management" of IT is stretched well beyond it's useful limits and needs to be replaced by evidence-based management.

The value-add to business is two-fold:
  • manage downt he input costs of the I.t. infrastructure and,
  • quantify the "cognitive amplifier" effects across the whole organisation to make informed decisions on optimum 'global' investment/expenditure on I.T. Operations.


[There's the 1990 HBS or MIT study into "White Collar Productivity" - reporting a decrease in the first decade of PC's]

Previous Work (What else)


There is a dearth of published material/research in this area.
The "State-of-Practice" is "NEVER DONE".
There is much opnion in the area, without substantive evidence: e.g. Nick Carr and "Does IT Matter?"

"Commonsense" IT Practitioner approaches, ITIL and COBIT (others?), do not address the measuring and managing of I.T. outputs and their business effects, ultilisation and effectiveness.

The McKinsey report/book on European Manufacturers and their I.T. expenditure versus financial performance shows there is no co-relation between effort (expenditure) and effect (financial peformance).

Jerrry Landsbaum's 1992 work included examples of their regular business reports - quantifiable and repeatable metrics of I.T. Operations phrased in business terms. This work seems entirely disregarded.


Hope to find (The Wherefore)


  • Model I.T. Operations performance within and across similar organisations.
  • generate tools usable within organisations to collect/report their own metrics.
  • Define a set of useful I.T. Operations performance and Business Impact metrics.
  • Model inputs to Business and Business Utilisation/Outcomes.


Report Outline


  • Analyse ITSM tool data. Derive KPI's, Internal Baselines/Trends, Cross-section Benchmarks
  • Annual I.T. Operations Report
  • FTE Employee equivalents - Count and Cost
  • Why IT Matters to the Business.
  • Gaps in Service Management models - ITIL and COBIT
  • Adding I.T. Operations to Management Theories.
  • Advancing I.T. as a Profession
  • Further Work and Research Questions


Execution Phases

Force Multipliers - Tools as Physical and Cognitive Amplifiers

The industrial revolution was about using Tools as Physical Amplifiers.

Prior to the steam engine, the oxen/bullock/horse/donkey/elephant was the dominat non-human power-source.

Humans can work at about 125-250W continuously (1/8 to 1/4 of a kilowatt, or 1/6 to 1/3 Horsepower). Elite athletes can produce 500W or more for short periods.

All biological systems have a short and medium term "duty-cycle" - our muscles get tired, non-linearly, and need short-term recovery and longer-term rest and recuperation. Sleep and recreation are about the nervous system/mind/brain.

From chapters of Taylor's book Scientific Management here's proof you get more out of people by making them rest! He improved average output from 12 tons/day to 47 tons/day through careful (psychological) selection and enforcing rest periods. Counter-intuitive, but well-researched.
For example, when pig iron is being handled (each pig weighing 92 pounds), a first-class workman can only be under load 43 per cent of the day.
He must be entirely free from load during 57 per cent of the day.
And as the load becomes lighter, the percentage of the day under which the man can remain under load increases.
So that, if the workman is handling a half-pig, weighing 46 pounds, he can then be under load 58 per cent of the day, and only has to rest during 42 per cent.
As the weight grows lighter the man can remain under load during a larger and larger percentage of the day, until finally a load is reached which he can carry in his hands all day long without being tired out.


For an 8-hour day at 125W, a total of 1KwHr (kilowatt hour) useful work is done, ignoring rest breaks.
Animals are heat engines as well. We 'burn' fuel with oxygen, releasing Carbon Dioxide and some useful work. For that 8-hour day, the energy input is probably 10,000KJ (kilo joules) [or 2500 (kilo)'calories']

Electricity sells for ~20c/KwHr in the western world. The minimum wage in Australia is ~$100/day now.
The raw "Physical Amplification" on a cost basis is ~500:1

A 500 HP bulldozer is controlled by one operator. There's a 3000:1 amplification. But machines are under 50% effective at converting their output to 'work done' compared to people.
On a cost-basis, the bulldozer might costs $150/hour to operate (40-50L of fuel, Wages, Maintenance, Depreciation).
Or 10c/hour/person-equivalent. Probably 400:1 ratio based on the operator wages.

Cognitive Amplifiers


The same comparison calculations as with Physical Tools and Machines can be done for humans and computers.

The human brain runs at ~50 watts - with around a 4MJ total energy input (1000 'calories') per day.
Like muscles, it has a "duty cycle' and requires rest and recuperation, as well as sleep and longer-term "recreation" and holidays. There appear to be no studies of "Human Response to Cognitive Workload". [Looking for the wrong thing?]

Directly comparing the human brain's I/O bandwidth, processing and storage capacity with electronic computers is difficult because they are organised so differently and probably complementary. The are best at different tasks.

45 years of "Aritifical Intelligence" research tells us that we don't understand in fine detail our brain processes and capabilities or the fully appreciate the complexity of "ordinary tasks". To recognise, not understand, human speech takes around a 1.5Ghz CPU and 256Mb of RAM - plus a very large, complex training dataset. Recognising speech, without understanding it is the equivalent of talking gibberish.

For repetitive cognitive processes that humans do poorly - computers with their methodical exactness, excel.

A $5,000 computer system that costs $10,000 over a 5-year life (excluding software) can run an accounting systems that processes 25,000 transactions/hour and is able to store, summarise and report on perhaps a decades' worth of data.

The equivalent human processing using mechanical 'tabulators', themselve 5-10 times faster than pen-and-journal, would take 250 operators just for data-entry. Consolidating and reporting the accounts requires another largish group (25?).

The yearly wages bill for the operators would be ~$4M. On-costs, leave, recruitment and training - say $25M for 5 years.
A 2500:1 amplification on a cost basis.

Cognitive Amplifiers


I.T. Systems benefits are "cheaper, better, faster, more, all-the-same".

I.T. systems embed the business processes used and their interfaces, performance and reliability define the productivity possible across the whole organisation.

Perfect I.T. Project Management - They're Research Projects!

My last post took me most of a day to produce. Not a great words/minute rate.
I'd expected to spend no more than an hour - it's work that I first did around 2000, so I'm familiar with it.

A friend jibed that "You should've used your I.T. project management methodology".

I do have stong views on managing I.T. projects, especially large one, and they are backed up by the solid research data from Standish Group. They do apply to exactly this task of writing. Unfortunately they offer no useful guidance.

  • All new programs are research projects
  • If you haven't got working code, you don't know how long it can take. If it's a complex task, then beforehand you cannotknow where the 'beartraps' are.
  • At any point in a project, you can only see in detail a couple of weeks ahead.
  • 'Scale' is everthing [Alan Kay's argument]. Don't take on any project more than 30% larger than one you've completed successfully.
  • Everyone is an efficient, effective Project Manager - it's just the Domain and Scale that change.
  • Production of new Software is Pure Research. It relies on Creativity, it will take unanticipated twists and turns, you can't order "breakthroughs" to schedule, seemingly simple things can be 'too hard' and it's only Done when it's Done (The Golden Rule of Open Source). And when you're done, you probably want or need to redo it - completely - and several times.


The Standish Group's rule is: Maximum of six people for six months.
That's a summary of 50,000 detailed case studies. I think it's worth taking on board.

So I feel happy about my little project taking as long as it did.

2007/03/19

The Triple Whammy - the true cost of I.T. Waste

Background

There's a report around at the moment that says spending on I.T. is 3-4 times more effective than anything else. [Link to come]

In the first couple of decades of commercial computing, all the "low hanging fruit" - the best returns - for I.T. were exploited. That's when 'the books', financial information and large internal databases (assets, employees, stockholders, vendors, customers, ...) were computerised.

1991 - the first IT recession - marked the end of this era. For the first time, IT staff were laid off in an economic downturn. Previously other staff could be displaced by automating their jobs with I.T.

The 2000 I.T. recession - which we are only just starting to recover from - was industry backlash (and rightfully so) to "Y2K" and the "Dotcom Bust"). The general I.T. justification before then was: "We need this, trust us". After 2000, business needed to be convinced...

Controlling Waste in Government I.T. - An Immodest Proposal

The Standish Group has researched and released the CHAOS report since 1994. What's special about Yet Another Expensive Industry Report?

The fact that nobody else does it, they have 50,000 detailed case studies of I.T. projects, and their results are consistent year to year (but they would make it that way, wouldn't they?).

Do we believe their claims the US spends $250Bn/year on IT applications development? That $81Bn of that is on cancelled projects and anothe $59Bn on over-runs? Or that only 16.2% of projects finish on time and within 130% of budget? That "For every 100 projects that start, there are 94 restarts"?

To scale that back to Australia, about one fifteenth the size, there'd be A$21Bn/year on just applications development. Which doesn't gel with estimates from the ABS that the I.T. sector here is about A$20Bn in total. (The ABS only reports accurately the ICT sector - grossly inflated by 'Communications' i.e. phone et al.) If the Australian I.T. sector is 5% of GDP, it would be around $50Bn and employ 500,000 people. Not unbelievable.

Either the US does a lot more AppDev that us, they pay a lot more, the survey is wrong - or the ABS survery figures are out.
To cut through the questions, all that's needed is a 'scale factor' - to convert the numbers from Standish into believable figures for Australia. Taking the ABS survey figure as a lower bound and guessing that half I.T. budgets go on AppsDev, or $10Bn, then that's a scale factor of 25:1.

So the Waste in Australia on cancelled AppDev projects is at least $3.25Bn/yr. The ABS also state that 40% of I.T. expenditure is by Government - half by the Federal Govt. The Government is wasting $1.5Bn - $3Bn of public monies yearly.

The only reliable figure for 'waste' is cancelled projects. Standish do say 52.7% of projects will cost 189% of their original estimates. But that could just be deliberate low estimates, optimisum or ineptitude of the IT areas - which after 50+ years of commercial I.T. you'd have thought management might have recognised and addressed.

It's over 10 years since Standish started their CHAOS reports - so why hasn't any section of the Australian Government looked at the problem here? Some possibilities:
  • There is no problem here. [Nope, glorious failures like ADCNET abound]

  • We don't have figures, so nothing could be wrong.

  • It's too trivial a figure

  • Nobody here knows the Standish work. [That's either negligence or incompetence.]

  • It's nobody's job? How about:

    • Australian Audit Office?

    • Senate Estimates Committee and Expenditure Review Board?

    • AGIMO, NOIE, GOI, ...

    • FMA Act & Finance - "Efficient, Effective, Ethical expenditure of public monies"

    • Department Heads [see FMAA]

    • I.T. Heads

There is a tried, proven model for controlling 'waste' - and the government knows it well:
Aviation.

Two independent bodies are needed: An investigator and an enforcement/compliance agency.
In Aviation, they are "BASI (Bureau of Air Safety Investigation)" and "CASA (Civil Aviation Safety Authority)".
CASA creates real 'consequences' for people and organisations - negligence and incompetence are cause for temporary or permanent disbarment from the industry.

BASI looks to find the causes of 'incidents', how to avoid them in future and promulgates the information to everyone that should know.

For about $30M/year, roughly the budget of the ANAO, the Federal Government could start to define and address the problem of I.T. waste. This is an area where the Government can lead the Private Sector - the same companies and people contract for the public and private sector. The Government can be seen to be impartial and transparent, and their is no legal impediment for a government "right to practice" list.

Spending $30M to save $3,250M - that sound like a good deal to me. Why not to the Government?

Going Backwards - losing what we know

The people who worked with the computer pioneer John von Neuman all practiced and valued 'code reviews'. This definitely was passed on - Jerry Weinberg, the Software Qualtiy supremo, is proof. In the 1970's, as an academic, he even proved reviews and a focus on 'quality' were the cheapest, most effective way to produce good programs, quickly.

There must be hundreds of other Good Practices that have fallen by the way, that were once 'standard practice' somewhere and exceedingly useful.

So why aren't all or some of the Good Practices taught routinely - both at University and in the work place? After all, we're talking about things that work, that address the software fundaments: cheaper, better, faster, more, that push up the tradeoff point for "pick two of 'fast, good, cheap'", make the production of software more reliable and predictable - and ultimately cheaper.

Theodore Dalrymple (Anthony Daniels) a British doctor and psychiatrist in Life At The Bottom says:

"When a man tells me, in explanation of his anti-social behaviour, that he is easily led, I ask him whether he was ever easily led to study mathematics or the subjunctives of French verbs."..


That's what we seem to have in I.T., people are Easily Led Astray. Somehow we know what will and won't lead to better work - and systematically chose against "Good Practices".

I've never seen more than one person at a site spontaenously improve their practices. But have been at effect more than once of management directives to "remove the gold plating" - to give away Good Practices.