IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 

 


Thu, Jun 28, 2007 10:31 EDT

Overcoming Blind Spots that Curb CIO Accountability

Topic: IT Organization Management

Current Rating: 5 Comments: 5

Simple IT Blind Spots Can Derail Even the Most Strategic IT Department

As IT departments evolve into larger, more sophisticated, and more strategically relevant divisions within organizations, expectations of business alignment and accountability for every IT dollar and decision swell within management ranks. However, this breakneck pace of change can cause even the most savvy CIO to lose sight of the very fundamentals of accountability that enable strategic-level success in the first place.

Consider this litmus test: Your CFO requests answers to several questions; can you deliver answers in 30 minutes or less?

• Is all of our software legally licensed? If audited by a software vendor, would we be at risk of prosecution?
• Are employees running applications that represent security threats?
• How many of those expensive CRM licenses purchased last year are actually being used?
• Will a migration to Vista require major new investments in hardware?
• If a business unit were wiped out by a flood, how would we know what hardware or software assets were lost?

If you can’t confidently answer questions of this nature, your organization is at risk either legally or financially. This is where bad things suddenly happen to good IT people – people who have the strategic interests of the enterprise at heart, but lack the comprehensive insight into the network assets and utilization needed to eliminate critical blind spots and avoid catastrophe.

As with driving an automobile, eliminating the blind spots means adjusting the mirrors and looking at things from a different angle to see what is not ordinarily apparent. CIOs must secure resources for IT asset management (ITAM) processes and auto-discovery tools that will provide much-needed visibility—and therefore control—over the inventory and usage of IT assets. With such tools in place, not only can IT departments more effectively avoid nasty surprises, but they can also free up costly overhead associated with routine manual processes and unnecessary fire drills—devoting more time to mission-critical operations and other strategic projects.

Here are some of the blind spots you can overcome and avoid by achieving a deeper understanding of the desktop environment:

1) Corporate software piracy
According to the Business Software Alliance (BSA), more than 20 percent of installed software in the U.S. is non-compliant. The ramifications of corporate software piracy can be enormous: copyright infringement penalties of up to $150,000 per infringed-upon title (not including legal fees), business disruption associated with protracted

You do not have flash or javascript support.
Average (2 votes)
5
 
 
Sat, Jul 7, 2007 3:24 EDT
Posted by: asengupta
Rating:

Very useful article, thank you. However, doing remote audits of all applications being run by employees smacks too much of big-brother to me. In our company many people work remotely and some use their personal computers to do office work. How can we balance their expectations of privacy with the necessity of securing the enterprise? I realize that legally we may be able to run such audits, but what is the impact on morale if the employees feel like they are being monitored?

 
Mon, Jul 9, 2007 4:08 EDT
Posted by: GeoffW
Rating:

There are two points to consider here, 1. You should have a company handbook or policy that states that the company / organisation audits computers for software. 2. Communicating with the staff why you are doing something.

If you supply home working staff software for their own computer then you are entitled to provide a service to ensure it is up to date.

The "usage" is virtually immaterial if you read License Agreements it is based on "INSTALLED" software not "USED" software.

 
Sat, Aug 25, 2007 13:57 EDT
Anonymous user
Posted by: Cary King
Rating:

When using company assets employees should have no expectation of privacy. If they are using personal computers to do office work, then the organization is mixing and matching their licensing issues. The risk to the organization of security breaches and software licensing violations is considerable. Each violation can cost the the company lots of money - consult the BSA and RIIA fine structures for yourself - and, you'll still have to "true up" with the software publisher anyway.

Plus, IT asset management data is fundamental to understanding and controlling IT costs so that your IT organization can demonstrate alignment with business services objectives.

IT Asset Management is one of those fundamental "run the business" activities that is poorly done because it's not sexy - yet, according to Gartner, "customers that commit a minimum of 3 percent of their annual operating budgets to ITAM programs and tools can expect a 25 percent reduction in their total cost of ownership."

A high risk of not doing ITAM, and a big payoff for doing it well. The first step is to get some help understanding what the possibilities are. The failure rate can be high for those that don't fully understand the commitment needed to achieve a proactive solution.

 
Thu, Aug 30, 2007 1:30 EDT
Anonymous user
Posted by: Bill K
Rating:

The focus on using the network only to inventory assets ignores the machines that are disconnected. It also ignores the logistical processes of moving IT equipment into a building, to its deployment location, and then back out of the enterprise (for retirement/disposition). Also, there are a lot of stored assets such as spare parts and still-in-box equipment that network discovery tools can't see. Network discovery is a great, low-overhead first step--- with IT environments growing so quickly a CIO probably cannot afford to overlook all the infrastructure and items not on the network.

 
Wed, Dec 5, 2007 14:34 EST
Posted by: Kris Barker
Rating:

Good point - tracking disconnected equipment can be a real headache, and there's no perfect solution. The choices are to perform a manual inventory, use a remote inventory client (an agent run on a disconnected computer from a floppy, CD or other media), use a network client to collect data when machines reconnect to the network, or use RFID/barcode tagging. Of course, these methods each have their own pitfalls... Manual inventories are incredibly time-consuming, error-prone and non-dynamic; remote inventory clients need to be run manually and don’t address the issue of “missing” devices; network clients only work when machines reconnect to the network and therefore don't take into account systems sitting in storage closets or on loading docks; and RFID tagging tracks movement of machines but does not transmit critical software inventory or hardware information for individual PCs (plus, it's expensive and requires manual work to tag the equipment in the first place).

At the end of the day, companies need to develop IT asset management processes by which equipment details and locations are documented and maintained "from cradle to grave". This might include, for example, a "discovery" tool that tracks current inventories of all networked hardware and software, as well as processes that are kicked off when new equipment is purchased, retired, and/or moved, notifying the people that need to track this information. IT asset management tools can help, but they will never supplant robust, carefully-planned documentation processes.

Start a Conversation
Click to post

Got something to say? We want to hear it! Click the Post button to get started. GO»

EXPERT ADVICE
See our roster of experts.

Advice & Opinion from more than 90 of IT's most insightful thinkers.

advertisement

TOP USERS
UserPoints
1. laith al jazi12550
2. Akshay Upadhye7650
3. Chris Moore6750
4. abdhiraj6175
5. remi5525
UserPoints
6. Mark Cummuta4675
7. Brian Flora4575
8. Al Sacco4200
9. asengupta3750
10. reCareered3700
  PARTNERS       PODCASTS       WEBCASTS    
 

Enterprise Content Management: From Strategy to Solution

Enterprise content management (ECM) has become an important competence and infrastructural technology, particularly for large and medium-sized organizations. Hear about industry trends for ECM and why standardizing your ECM platform is so critical to your success during this roundtable discussion.

Sponsored by IBM  View This Webcast »

 

The CIO's Guide to Wireless in the Enterprise

This guide provides a basic overview and worksheet of mobile computing for those who are interested in evaluating a wireless enterprise solution.

Sponsored by Blackberry
  Read This White Paper »

 

The Universal Wireless Client

Learn how replacing multiple wireless clients with one Universal Wireless Client can cut support and help desk costs, increase end user satisfaction, improve security, and help implement Network Access Control.

Sponsored by Fiberlink  Read this White Paper »

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

NAC launch from HP Procurve Podcast with Lippis Report, Part 1

ProCurve Networking by HP joins the Lippis Report to announce major product and organizational additions to their ProActive Defense strategy.  Read More »

 

Accenture's View on Web 2.0 and its impact on business

Publisher at CIO magazine, Bob Melk, talks to Accenture's Blair Jones about the emergence of Web 2.0...  Read More »

 

A Best-Practice Framework for Virtualization

This podcast offers insights and perspective on the various issues that relate to virtualization...  Read More »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

Forrester builds a case for the next generation information workplace.

As businesses seek new ways to enhance collaboration and improve productivity, the information workplace continues to evolve...  Read More »

 

Find out what Forrester says about mobile endpoint security and its management.

Mobility raises productivity. But IT departments are hard-pressed to protect mobile data and to manage security software, wireless clients and regulatory compliance for mobile workers...   Read More »

 

Get Forrester's take on simplifying mobility with the universal wireless client.

Mobile workers want to use all types of wireless networks: WiFi, 3G cellular networks, corporate WLANs and home wireless networks. But how can IT support...  Read More »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

 
NEWSLETTER

Sign-up for the Advice & Opinion Newsletter

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Reducing Data Center Costs with Data Deduplication: A TCO Analysis

TDWI Research report clears confusion about automating data governance

Learn about the software-based VoIP solution from Microsoft

Microsoft System Center - Designed For Big

Storage Efficiency: The Key to Green Storage Operation

Fuel the Responsive Enterprise Through Oracle Fusion Middleware

Balance Your Innovation and Efficiency Platforms for Competitive Advantage and Responsiveness

Oracle Real Application Testing with Oracle Database 11g

InfoWorld Test Center on Oracle Active Data Guard

Master Data Management: The Approach Determines the Results

The Power of Pervasive Business Intelligence

Reap the Benefits of Unified Communications

Controlling High Fraud Risk of International Transactions

Renowned Engineering Institution Chooses AMD Processor-Based Servers

How to Manage the Mobile Work Environment

Extending PCI Compliance to the Mobile Workforce

Solving Online Credit Fraud Using Device Reputation

Process Integration and Traceability through Requirements Management

Virtual Support Technology Delivers Quantifiable Gains in Productivity and Performance

Building Competitive Advantage with Next-Generation Wireless Infrastructure

Building an Online Customer Experience Competency

Skechers, an IBM Customer Case Study

What Is Innovation and What Role Do CIOs Have In It?

Configuration Assessment: Choosing the Right Solution

They Can't Steal What You Don't Have: Smart Security Choices for Mobile Workers

Speed, agility, flexibility - The HP BladeSystem c-Class

Cost-Effective Data Center 1U Server Solutions

Secure your virtual and physical environments with the same software

GET YOUR VoIP ONTM! Win 2 Years of Hosted VoIP from Cypress. $100,000 retail value. Enter today!

Standalone Server vs. Open Source Toolkits

Drive More Effective Business Processes with SOA

Oracle Database 11g: Real Application Testing & Manageability

InfoWorld Test Center on Oracle Real Application Testing

Oracle Database 11g: Advances in Compression, Real Application Testing and Data Guard

Getting Off on the Right Foot: Avoiding Common Master Data Management False Starts

Conquering Information Management Challenges

The Challenge of Network Access Control -- Is a Managed Service the Answer?

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

The Universal Wireless Client: Simplify mobility and reduce the cost of supporting mobile workers

Strategic IT Financial Management - Achieve Higher Organizational Performance

Strategies for Asia-Pacific Expansion

Unified Communications: "More Than Just Talk"

Accelerating ITIL at the Service Desk

New research validates telepresence solutions.

The Gartner Magic Quadrant

How to Choose the Right ECM Platform

Optimizing Infrastructure Control

Effective Security with a Continuous Approach to ISO 27001 Compliance

Best Practices for Providing Secure and Cost-Effective Remote Access