<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itskeptic.org"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The IT Skeptic - Comments for &quot;Whining about the IT department&quot;</title>
 <link>http://www.itskeptic.org/whining-about-it-department</link>
 <description>Comments for &quot;Whining about the IT department&quot;</description>
 <language>en</language>
<item>
 <title>Stand firm</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9173</link>
 <description>&lt;p&gt;As I said in the post we&lt;br /&gt;
&lt;blockquote&gt;don&#039;t know if this is excessive lockdown or not. We can&#039;t know without seeing the governance directives given to that IT department by their Board in terms of risk appetite... If IT&#039;s reaction is excessive in the context of that organisation, this is not entirely a failure of IT. It takes two to tango. This is at least equally a failure of the organisation&#039;s corporate governance of IT to provide proper direction, monitoring and evaluation. &lt;/blockquote&gt;&lt;/p&gt;
&lt;p&gt;The same applies to every organisation.  Such blocking is not automatically wrong.  And a wide open, loving, sharing, sunny IT policy is not automatically right. People aren&#039;t all stupid.&lt;/p&gt;
</description>
 <pubDate>Thu, 15 Mar 2012 19:48:47 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 9173 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Re:  Enterprise Security and other things</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9172</link>
 <description>&lt;p&gt;Let me state that I work for a Forbes 500 company, as an IT person.  I&#039;m not a contractor, I&#039;m actually an employee of that company, and so I see the IT situation from the inside.  Having said that, the company does a lot of the actions that the Forbes article lists, and a few others that they don&#039;t.  For example, iPhones are no longer being considered as a standard for company use.  iPads are allowed for company business, but the can&#039;t be hooked into the company network.  Personal equipment is not to be used on the network, nor is personal equipment to be used form home for company work.  The list goes on for a little while here, you get the gist.&lt;/p&gt;
&lt;p&gt;But at the same time, you have to consider that we maintain company data, but government data (many governments, to be honest), along with in some cases competitor data.  You can&#039;t be lax about this stuff, and there&#039;s always an active push to protect the data.  This of course, flies in the face of the Avenade survey, as the company I work for would never move in those directions suggested.&lt;/p&gt;
&lt;p&gt;Admittedly, the company I work for may be more of an outlier here, but it wouldn&#039;t be the first time.&lt;/p&gt;
</description>
 <pubDate>Thu, 15 Mar 2012 15:56:14 +0000</pubDate>
 <dc:creator>Visitor</dc:creator>
 <guid isPermaLink="false">comment 9172 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Over their heads</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9028</link>
 <description>&lt;p&gt;Financial models can help, but charging policy is only one way of managing such demand, of course.  In the specific example I wonder if there was a technical solution to prevent streaming services that might have been deployed, for example.  But back to charging, even a by-usage charging policy might not change perceptions of IT - they just become an expensive necessary evil rather than one the company used to pay for. It might influence some decisions, but it might make IT&#039;s life all the harder and more costly.  We&#039;re back to strategy alignment and governance really. &lt;/p&gt;
&lt;p&gt;In truth, even if the Exec was charged he&#039;s an overhead as well, it&#039;s wooden dollars and would he care?  I suspect not. &lt;/p&gt;
&lt;p&gt;Of course it doesn&#039;t help when the business leaders don&#039;t lead by example.  At a former client, the MD refused to be treated any differently to anyone else - went through the IT processes, waited for lead times;  this made it all the easier to help him when he needed something unusual, because it was exceptional and IT recognised that fact.  More importantly it gave the mandate to IT to manage their support services properly, which led to better service quality, response times, etc. If only all were like this. &lt;/p&gt;
&lt;p&gt;People like Dave will never get it because they blur the lines between business and personal enablement too far. Everything IT does that isn&#039;t personally convenient makes IT the devil. So quotaing of his email or storage would be wrong because &#039;disks are cheap&#039;, restrictions on international data roaming would damage his ability to get the football scores, etc etc. &lt;/p&gt;
&lt;p&gt;But Dave isn&#039;t the guy who needs convincing - he&#039;s an end user with a chip on his shoulder.  C-level people will be convinced only by the cost-effective delivery of their strategy, and where IT enables that IT needs to make sure it&#039;s visible.  That is to say, ultimately it&#039;s a question of visible value. &lt;/p&gt;
&lt;p&gt;Rich Pemberton&lt;/p&gt;
</description>
 <pubDate>Mon, 20 Feb 2012 12:22:42 +0000</pubDate>
 <dc:creator>RichPem</dc:creator>
 <guid isPermaLink="false">comment 9028 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Budget or Billing - I know which I prefer!</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9027</link>
 <description>&lt;p&gt;But if IT was in a position to bill that exec for his usage - where is the problem then? That is the place IT should be going to - like Cary has mentioned, Away from being an overhead. &lt;/p&gt;
&lt;p&gt;(IT) Budgets create limitations while the business is requiring more flexibility. Going back to basics - if you demand more of something you should pay for it. That exec demanded a new toy and used it a lot (he was responsible for its use as long as he had it) and should have been charged for the usage or his department charged. Until then the business will demand this of IT and expect IT to pay from their budgets. &lt;/p&gt;
&lt;p&gt;What happened here, dealing with business demand IT has now made an enemy. That is what happens but until change of behaviours cone - what else can be expected?&lt;/p&gt;
</description>
 <pubDate>Mon, 20 Feb 2012 09:53:21 +0000</pubDate>
 <dc:creator>Mark O&#039;Loughlin</dc:creator>
 <guid isPermaLink="false">comment 9027 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>front lines</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9026</link>
 <description>&lt;p&gt;Thanks for dispatches from the front lines.&lt;br /&gt;
There are real reasons why IT have evolved the controls we have.&lt;/p&gt;
</description>
 <pubDate>Mon, 20 Feb 2012 07:28:28 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 9026 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>But get this from the trenches</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9025</link>
 <description>&lt;p&gt;We had a business exec demand that they take their shiny new iPAD roaming with them on an o/s vacation so they could &quot;keep in touch&quot;.  (given out because the exec was envy when they attended a board meeting and was the only one who didn&#039;t have one) &lt;/p&gt;
&lt;p&gt;They ran up $25,000 in telco bills whilst away within just a couple of weeks.  That&#039;s real dollars - Aussie ones.  This person was given a laminated cheat-sheet to keep consumption down (log in, send/receive your email then disconnect and work away).&lt;/p&gt;
&lt;p&gt;Then had the gall to blame IT for not locking down the device - it turns out that their snot-nosed teenage spawn was a big NBA &amp;amp; NFL fan and was streaming game after game.  No, we hadn&#039;t blacklisted any non-work sites, as our definition of keeping in touch was based on common sense.&lt;/p&gt;
&lt;p&gt;Initially refused to pay the bill and this got escalated up high enough for IT to have a new enemy.&lt;/p&gt;
</description>
 <pubDate>Sun, 19 Feb 2012 23:21:46 +0000</pubDate>
 <dc:creator>Ripleys situation</dc:creator>
 <guid isPermaLink="false">comment 9025 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Well-timed rebuttal</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9023</link>
 <description>&lt;p&gt;Consumerization: The view from IT you may not like but need to hear &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.infoworld.com/d/consumerization-of-it/consumerization-the-view-it-you-may-not-need-hear-183809-0&quot; title=&quot;http://www.infoworld.com/d/consumerization-of-it/consumerization-the-view-it-you-may-not-need-hear-183809-0&quot; rel=&quot;nofollow&quot;&gt;http://www.infoworld.com/d/consumerization-of-it/consumerization-the-vie...&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I came across this article shortly after finding the insane Forbes article. It&#039;s the perfect antidote.&lt;/p&gt;
</description>
 <pubDate>Sat, 18 Feb 2012 18:54:06 +0000</pubDate>
 <dc:creator>hazyitsm</dc:creator>
 <guid isPermaLink="false">comment 9023 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>decisions</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9021</link>
 <description>&lt;p&gt;I worked in a hospital long ago where the management (read: administration department) decided they couldn&#039;t pay the outsourced (but wholy owned)  IT service provider for 24x7 support.  so the service desk staff were on an unpaid roster to provide emergency support out of business hours.&lt;br /&gt;
Even the head of clinical services didn&#039;t know this until I told her.  Heck she didnt even know we weren&#039;t there 24x7.  I was with her to explain why non-critical things weren&#039;t being fixed until next day.  When I told her that she and her staff were in fact calling us at home in the middle of the night she was horrified.  Initially she was abusing me because she thought it was the service provider&#039;s idea not to have anyone there at night.&lt;/p&gt;
&lt;p&gt;So your point about governors and executive communicating and visibly supporting decisions is a key one.&lt;/p&gt;
</description>
 <pubDate>Fri, 17 Feb 2012 19:03:35 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 9021 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Poor old Dave, IT just</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9020</link>
 <description>&lt;p&gt;Poor old Dave, IT just aren&#039;t giving him what he wants (for his is a protestation on personal constraints not business risk).  &lt;/p&gt;
&lt;p&gt;If that list is true in its entirety I think it&#039;s fair to say the business - in partnership with IT - recognises data and information as critical to their business.  Port 25 was clamped down upon in my last client organisation by the anti-virus solution, to help prevent the malware bring SMTP servers into effect throughout the organisation. An earlier client had no external devices - USB, DVD, etc - permitted whatsoever.  Another regularly told IT to &#039;throw disk space at the capacity problem because storage is cheap&#039; - well it might be, but the cost [to IT and the business] of managing storage in that way...&lt;/p&gt;
&lt;p&gt;It&#039;s growing pains though.  IT is beginning to mature in its management of risk, and now more regularly defers to the board&#039;s risk appetite in its plans rather than take the &#039;computer says no&#039; stance. I wonder how clearly the board are communicating that it&#039;s a business decision rather than an IT decision to restrict USB access?&lt;/p&gt;
&lt;p&gt;I use USB access specifically because very recently I was involved in an information security project where this became a very hot topic indeed. What made sure it happened was that the management board visibly owned the decision, they communicated it to all through a board-appointed Infosec Officer and supported it with a clear statement on how circumvention would be handled. &lt;/p&gt;
&lt;p&gt;I think the prime key to its success though was that a solution was offered, in that pre-prepared [by IT] secure USBs were made freely available to anyone who asked. Thus IT were positioned - and communicated - to be providing a solution, not just the constraint. &lt;/p&gt;
&lt;p&gt;Dave Gardner doesn&#039;t mention what alternative solutions were available, but I&#039;ve experienced them in every one of his bullet points. Quick examples:&lt;br /&gt;
 - Facebook/Skype/home email: availability of unrestricted internet PCs in communal areas&lt;br /&gt;
 - BYOD: guest internet access to web-published services&lt;br /&gt;
 - No chat:  Lync, Cisco WebEx connect are increasingly provided.&lt;/p&gt;
&lt;p&gt;I think Dave&#039;s lost sight of the fact that as a consultant he might have a greater personal business need to access services outside of his client - but this isn&#039;t his client&#039;s responsibility, it&#039;s that of his own business.  Conversely if he spots a need in his client, such as responding to the email-centric nature of a business by equipping employees with Blackberries, he can influence or make a proposal - perhaps it&#039;s not as cheap to run as he thinks from the outside.&lt;/p&gt;
&lt;p&gt;It&#039;s gusto from someone so ill-informed and self-involved as to make it almost irrelevant.  It will stoke those who think grown-up business will enable its departments to do their own thing rather than come in line with the business and IT strategies, of course, but I dunno - sounds to me like someone&#039;s taken the jam out of Dave&#039;s doughnut very recently.  Anyone who&#039;s had to deal with a security breach with real business impact won&#039;t give him the time of day. &lt;/p&gt;
&lt;p&gt;Rich Pemberton&lt;/p&gt;
</description>
 <pubDate>Fri, 17 Feb 2012 11:26:31 +0000</pubDate>
 <dc:creator>RichPem</dc:creator>
 <guid isPermaLink="false">comment 9020 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Stop turning the blame and responsibility back onto IT</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9019</link>
 <description>&lt;p&gt;Cary, &lt;/p&gt;
&lt;p&gt;I think you&#039;ve been on the frontline too long :)  Victims of violence can end up blaming themselves for it.  Stop turning the blame and responsibility back onto IT.  How about the Boards that have never taken the time to understand their obligations and accountability with regards to IT?  How about the Executives who have found it convenient to let IT take the rap for their own failure to understand that aspect of their business, or to resource it properly?  How about all the staff who think that because they can plug in a router and install antivirus, IT must be easy?  All the people who think they should be able to have anything they want regardless of the broader implications for their employer?&lt;/p&gt;
&lt;p&gt;This isn&#039;t IT&#039;s fault.  Oh sure we have to accept a component of the blame.  But I&#039;m sick of being told to take all of it.  I&#039;m proud of what we achieve as an industry, and those who want to see us all as &lt;a href=&quot;http://en.wikipedia.org/wiki/The_IT_Crowd&quot; target=&quot;_blank&quot;&gt;The IT Crowd&lt;/a&gt; can go mono-procreate.  It&#039;s time we redirected some of the crap back.&lt;/p&gt;
</description>
 <pubDate>Fri, 17 Feb 2012 07:10:48 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 9019 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Champagne Dreams on a beer budget</title>
 <link>http://www.itskeptic.org/whining-about-it-department#comment-9018</link>
 <description>&lt;p&gt;I conceive that as long as IT is an overhead department for which the company gives x (5%) of the total revenue to receive unlimited services (or to many that&#039;s the perception) and IT remains the &quot;bad guy&quot; gatekeepers, this is going to continue.&lt;/p&gt;
&lt;p&gt;When IT decides that they want to build investment-based budgets, collect costs for services, make those costs tranparent to business management, base those costs upon business-describable levels of service - then this unfortunate cycle of unlimited expectations and budget constraints will continue.&lt;/p&gt;
&lt;p&gt;IT can build trust with the &quot;rest of the business&quot; by making the services and their costs transparent - or not.&lt;/p&gt;
&lt;p&gt;IT can have regular discussions about business risks, IT capabilities to respond to them, and the costs involved - or not.&lt;/p&gt;
&lt;p&gt;IT can shift the management of the budget to the &quot;rest of the business&quot; to get their collaboration with controlling costs - or not.&lt;/p&gt;
&lt;p&gt;As I see it now, IT&#039;s customers (the rest of the business) is being marketed to by all sorts of &quot;Cloud&quot; and outsourcing providers - the biggest disintermediation play in history.  IT can either step up and start acting like a Prime Contractor that provides services and demonstrates value - or the can watch as pieces of their portfolio are picked up by suppliers and their influence wanes.  Soon IT will be left with the legacy app dogs.&lt;/p&gt;
&lt;p&gt;IT can act as trusted advisor and expert management of services, or it can act as the overhead IT department.  &lt;/p&gt;
&lt;p&gt;IT Management and Business Management can openly discuss the risks (pros and cons) of thes different technologies only when IT gains the trust of business to have these discussions and can do so by combining the price of choices into the discussion.  Few IT organizations can do that.&lt;/p&gt;
</description>
 <pubDate>Fri, 17 Feb 2012 01:33:36 +0000</pubDate>
 <dc:creator>CaryKing</dc:creator>
 <guid isPermaLink="false">comment 9018 at http://www.itskeptic.org</guid>
</item>
</channel>
</rss>
