You’re probably familiar with the service management joke, and it’s a fairly weak joke at best, but it does contain within it a horrible grain of truth. Anyway, here goes: Why is it called ITIL? Because at so many meetings when service management is discussed the conclusion is always, it’ll have to wait!
Hardly worthy of a quiet groan, but like I say there has been a tendency in the past to put off adopting best practice until you have more time, and continue with what is, perhaps, little better fire-fighting problems as they occur.
So what is ITIL? Well the IT Infrastructure Library provides a framework of best practice guidance for IT service managers. The actual ITIL publications cover areas such as service strategy, service design, service transition, service operation, and continual service improvement.
The IT Service Management Forum (itSMF) has just produced a 58 page book, which describes itself as “An Introductory Overview of ITIL® V3”. This is available as a PDF from http://www.itsmf.com/upload/bookstore/itSMF_ITILV3_Intro_Overview.pdf. They are clearly expecting people to print it because, apart from the cover page, it is all in black and white – or perhaps that’s a hidden metaphor.
The publication offers the following definition of service management: “[it] is a set of specialized organizational capabilities for providing value to customers in the form of services”. And to clarify, it says that a service is: “a means of delivering value to customers by facilitating outcomes customers want to achieve without the ownership of specific costs and risks”.
The book also suggests benefits from the use of ITIL, which include: increased user and customer satisfaction with IT services; improved service availability, directly leading to increased business profits and revenue; financial savings from reduced rework, lost time, improved resource management and usage; improved time to market for new products and services; and improved decision making and optimized risk.
Definitely worth reading through for anyone involved in IT and any kind of service management.
On a completely different topic... The Arcati Mainframe Yearbook 2008 will shortly be conducting its annual survey. It’s been available since 2005, and as well as the annual user survey, it contains a directory of vendors and consultants, a media guide, a strategy section with papers on mainframe trends and directions, a glossary of terminology, and a technical specification section. The survey is at www.arcati.com/usersurvey08.html. The Arcati Mainframe Yearbook 2008 itself will be available in January 2008.
Monday, 26 November 2007
Monday, 19 November 2007
Rational mainframes
Who says mainframes are hard to use and integrate with other systems? Well, it seems just about everyone who hasn’t spent long periods of time working on them. Experienced mainframers, of course, always stress the reliability and security of mainframes compared to any other system.
Anyway, it seems that IBM has taken the “hard to use” criticism on board and has done something about it. So last October, it initiated a $100 million mainframe simplification project with promises of management and development tools that would be incredibly powerful, but very easy to use. And a couple of weeks ago it started delivering the stuff.
These Rational development tools included retooled compilers for COBOL and DL/I on z/OS, a turn-key COBOL or Java code generation tool called the Rational Business Developer Extension, and an RCD (Rapid Component Development) tool that can scan existing COBOL code and identify useful jobs or processes, which it then componentizes. This product is called Rational Transformation Workbench.
The thinking behind the new products is that organizations have high-quality code that is supporting the business and already up and running. What’s needed is a simple way to expose that code – rather than writing what could very well be less efficient or bug-ridden code. So rather than the mainframe being a box that sits quietly somewhere within an organization and gets on with its work without bothering anybody, it now becomes a major player in the development of a business. Which, as you’ll appreciate, is a position IBM prefers mainframes to occupy.
The compilers are Version 4.1 of Enterprise COBOL for z/OS and Version 3.7 of Enterprise PL/I for z/OS. These are designed to integrate mainframe applications with Web-oriented business processes.
Version 7 of Rational Business Developer Extension uses code written in IBM’s EGL (Enterprise Generation Language) to generate COBOL or Java. EGL is similar to COBOL in construction and helps “modernize” code by allowing users to work in an SOA (Service-Oriented Architecture) environment.
IBM also announced Version 7.1 of Rational Developer for System z. This is claimed to be a simplified development environment for programming mainframe applications. Although described as new product, in many it is a repackaging of existing IBM technologies.
I’d also like to mention (again) the Virtual IMS User Group at www.virtualims.com. It’s first virtual presentation is on the 4 December at 10:30 CST. One of NEON Enterprise Software’s IMS experts will give the first presentation. Following the presentation, Virtual IMS Connection members will be able to ask any questions they have and share their own experiences. It’s all free.
Anyway, it seems that IBM has taken the “hard to use” criticism on board and has done something about it. So last October, it initiated a $100 million mainframe simplification project with promises of management and development tools that would be incredibly powerful, but very easy to use. And a couple of weeks ago it started delivering the stuff.
These Rational development tools included retooled compilers for COBOL and DL/I on z/OS, a turn-key COBOL or Java code generation tool called the Rational Business Developer Extension, and an RCD (Rapid Component Development) tool that can scan existing COBOL code and identify useful jobs or processes, which it then componentizes. This product is called Rational Transformation Workbench.
The thinking behind the new products is that organizations have high-quality code that is supporting the business and already up and running. What’s needed is a simple way to expose that code – rather than writing what could very well be less efficient or bug-ridden code. So rather than the mainframe being a box that sits quietly somewhere within an organization and gets on with its work without bothering anybody, it now becomes a major player in the development of a business. Which, as you’ll appreciate, is a position IBM prefers mainframes to occupy.
The compilers are Version 4.1 of Enterprise COBOL for z/OS and Version 3.7 of Enterprise PL/I for z/OS. These are designed to integrate mainframe applications with Web-oriented business processes.
Version 7 of Rational Business Developer Extension uses code written in IBM’s EGL (Enterprise Generation Language) to generate COBOL or Java. EGL is similar to COBOL in construction and helps “modernize” code by allowing users to work in an SOA (Service-Oriented Architecture) environment.
IBM also announced Version 7.1 of Rational Developer for System z. This is claimed to be a simplified development environment for programming mainframe applications. Although described as new product, in many it is a repackaging of existing IBM technologies.
I’d also like to mention (again) the Virtual IMS User Group at www.virtualims.com. It’s first virtual presentation is on the 4 December at 10:30 CST. One of NEON Enterprise Software’s IMS experts will give the first presentation. Following the presentation, Virtual IMS Connection members will be able to ask any questions they have and share their own experiences. It’s all free.
Monday, 12 November 2007
The War of the Web
Back in 1978 Jeff Wayne released his musical version of H G Wells’ 1898 classic The War of the Worlds – and I’d like you to be humming the well-known theme from that album while you read the rest of this blog, which I’ve called “The War of the Web”.Now we’ve all installed firewalls, antivirus software, and anti-spyware, and we’ve probably got something to check for rootkits and any other nasties, but now even that isn’t enough. It appears that gone are days of the sad little nerd trying to claim fame in his sad little nerd community by launching a virus on the rest of us that basically says, “I am here, look at me”. I’m sure there are still people like that passing their time in this particular way, but they are not the problem.
The next level of attack on ordinary people, like you and I, came from organized crime. Every time we inadvertently found ourself trying to download something free off the Internet we also downloaded a piece of software that exposed our files to outsiders – the growth of broadband helped criminals no end. Not only could they see the existence of our files labelled secret_passwords.doc and home_accounts.xls, they could download their contents and steal our identity at the bank as they withdrew all our hard-earned cash. Next they turned our computers into zombies that sent out millions of spam e-mails over our broadband connection when we left it for a few minutes.
But now we have reached a new level of sophisticated attack and from the unlikeliest of bedfellows. I’m talking about legitimate governments and terrorists! Now I’m sure that your government and mine can’t possibly be involved – it’s always the others! For example, there has been wide reporting in the press that the Chinese plan to have electronic supremacy by 2050. Apparently, hackers within the Chinese People’s Liberation Army have revealed China’s plan to control other countries’ military networks and disable their financial and communications capabilities. It seems that superiority in any future war lies in successful cyber assaults, and, what’s worse, globally there are an awful lot of vulnerable systems. It also seems that the Chinese have produced a blueprint for Cyber warfare.
Obviously, a successful cyber attack could destabilize a country – which is probably why those hackers who can’t get a job for a legitimate government are being recruited to help terrorists. Although it doesn’t appear to have happened, 11 November was meant to see a denial of service by al-Qaeda. This was the date set for a cyber jihad against non-Moslem targets. The attack was meant to work by allowing sympathizers to download a tool that when coordinated with thousands of other like-minded people would cause the denial of service attack.
Now I know the Internet is full of paranoid ravings and conspiracy Web sites, but it does seem like an extra problem to worry about – maybe the Internet won’t be there tomorrow morning when I try to log on. The only good inference you can draw from this is that if these cyber attacks are well known, there must be a lot of people in white hats preventing such attacks from happening. But, perhaps equally worryingly, they must be thinking about ways to wage cyber war on whoever they think of as wearing black hats. Let’s hope the War of the Web never gets passed the planning stage – take it away Jeff!
Thursday, 1 November 2007
IMS community virtual user group Web site
I was blogging about IMS a couple of weeks ago and at the time I was thinking that there wasn’t a lot of Web-based resources available for IMS sites. So now I’d like to announce the launch of Virtual IMS Connection, the IMS community Web site at www.virtualims.com.
You would have thought that with IMS installed at 95% of the Fortune 1000 companies that the Web would be awash with sites discussing its use, how to improve performance with various hints and tips, and perhaps even a section for people looking for work and companies looking for experience people. Strangely, there seems to be very little out there. But, as I said above, not any longer.
The new Web site at www.virtualims.com is intended to be a meeting place for all IMS people. It’s a virtual user group. I’m planning to run virtual meetings and hopefully produce a Web-based newsletter for IMS folk. In fact, I plan to have the first session in early December this year.
Now you’re asking how much is this going to cost to join? The answer is nothing at all. You just sign up and then you can take part in the first and all future virtual meetings. And you can join in the discussions.
The Web site will tell you about virtual meetings – the topics and date and time. There’s a section pointing to useful IMS articles that have been published recently, a section for IMS-related resources, and section for IMS events. There is also an IMS news section.
In addition, there is a forum area where IMS experts can share their experiences and useful hints and tips, and ask their peers questions about any aspect of IMS. Lastly, there is a job bank, where people looking for jobs and people needing staff can post their information.
The whole thing depends on user involvement, and the topics for the virtual meetings and the content of the Web site will depend very much on input from the users. I’m hoping that the Virtual IMS Connection Web site will become a major IMS resources and a lively and informative site for IMS people to visit. Please register your interest now – it really is all free.
You would have thought that with IMS installed at 95% of the Fortune 1000 companies that the Web would be awash with sites discussing its use, how to improve performance with various hints and tips, and perhaps even a section for people looking for work and companies looking for experience people. Strangely, there seems to be very little out there. But, as I said above, not any longer.
The new Web site at www.virtualims.com is intended to be a meeting place for all IMS people. It’s a virtual user group. I’m planning to run virtual meetings and hopefully produce a Web-based newsletter for IMS folk. In fact, I plan to have the first session in early December this year.
Now you’re asking how much is this going to cost to join? The answer is nothing at all. You just sign up and then you can take part in the first and all future virtual meetings. And you can join in the discussions.
The Web site will tell you about virtual meetings – the topics and date and time. There’s a section pointing to useful IMS articles that have been published recently, a section for IMS-related resources, and section for IMS events. There is also an IMS news section.
In addition, there is a forum area where IMS experts can share their experiences and useful hints and tips, and ask their peers questions about any aspect of IMS. Lastly, there is a job bank, where people looking for jobs and people needing staff can post their information.
The whole thing depends on user involvement, and the topics for the virtual meetings and the content of the Web site will depend very much on input from the users. I’m hoping that the Virtual IMS Connection Web site will become a major IMS resources and a lively and informative site for IMS people to visit. Please register your interest now – it really is all free.
Monday, 29 October 2007
Database auditing
Finding out how your database is performing and what activities took place has traditionally been an historical activity. By that I mean actions against the database have been recorded in the logs and then later – perhaps the following day – these logs have been examined to find out exactly what happened. The advantage of this is that you have a fairly good record of all activities that occurred and it doesn’t use up too many valuable MIPS. The downside is that you never know what is happening currently and you may not be getting enough detail about what happened recorded in your log.
The alternative is to run trace utilities – and for DB2, for example, there are a number of traces that can be run. The good thing about traces is that they can help to identify where a performance problem is occurring. However, they also have a high CPU overhead. Not that you would, but if you run DB2’s global trace with all the audit classes started, IBM reckons this will add 100% CPU overhead. Even running just all the audit trace classes adds and estimated 5% CPU overhead.
So why are we worried about auditing what’s going on in our database? It’s the growth in regulations. In the USA there’s the Sarbanes-Oxley Act (SOX) and also the Payment Card Industry Data Security Standard (PCI-DSS). Both of these can affect what a company needs to audit. An audit is meant to identify whether procedures are in place, whether they are functioning as required, and whether they are being updated as necessary. In the event that one of these is not happening, the audit should be able to make recommendations for improvement.
It’s also important, with database auditing software, that it doesn’t have to be used by the DBA or anyone else who maintains the database. Pretty obviously, if the DBA was making changes to the data or browsing records he wasn’t authorized to look at, when he ran the auditing software, he could remove all information about those activities and no-one would be any the wiser.
So, to summarize, a successful database auditing tool would have to work in real-time and not historically. It would not have to impact on performance. It would have to comply with the latest regulations. And it would have to be able to audit the actions of the DBA and other super users.
There’s one other characteristic that would be useful. Having identified in real-time actions that violated corporate policies (like changing the payroll data!) it should then respond with a policy-based action – like an alert.
The alternative is to run trace utilities – and for DB2, for example, there are a number of traces that can be run. The good thing about traces is that they can help to identify where a performance problem is occurring. However, they also have a high CPU overhead. Not that you would, but if you run DB2’s global trace with all the audit classes started, IBM reckons this will add 100% CPU overhead. Even running just all the audit trace classes adds and estimated 5% CPU overhead.
So why are we worried about auditing what’s going on in our database? It’s the growth in regulations. In the USA there’s the Sarbanes-Oxley Act (SOX) and also the Payment Card Industry Data Security Standard (PCI-DSS). Both of these can affect what a company needs to audit. An audit is meant to identify whether procedures are in place, whether they are functioning as required, and whether they are being updated as necessary. In the event that one of these is not happening, the audit should be able to make recommendations for improvement.
It’s also important, with database auditing software, that it doesn’t have to be used by the DBA or anyone else who maintains the database. Pretty obviously, if the DBA was making changes to the data or browsing records he wasn’t authorized to look at, when he ran the auditing software, he could remove all information about those activities and no-one would be any the wiser.
So, to summarize, a successful database auditing tool would have to work in real-time and not historically. It would not have to impact on performance. It would have to comply with the latest regulations. And it would have to be able to audit the actions of the DBA and other super users.
There’s one other characteristic that would be useful. Having identified in real-time actions that violated corporate policies (like changing the payroll data!) it should then respond with a policy-based action – like an alert.
Monday, 22 October 2007
IMS at 40
With the recent announcement of Version 10 of IMS, I thought it would be quite interesting to take look at what IMS actually is, before seeing what’s in the new version.
Information Management System, to give it its full name, is a combination of database and transaction processing system. I’m not sure whether it’s 40th birthday was last year or next year because work started on it back in 1966, but it was 1968 when it was first running anywhere.
There are three databases associated with IMS DB. These are called “full function”, “fast path”, and High-Availability Large Databases (HALDBs). With full function databases – the original database type – data is stored in VSAM or OSAM files and can be accessed using HDAM, HIDAM, HSAM, HISAM, and SHISAM access methods. Full-function databases are derived from DL/I databases that were around at the time (1966). There are two types of fast path database – Data Entry DataBases (DEDBs) and Main Storage DataBases (MSDBs). These databases do not have indexes and are stored in VSAM files. HALDBs are the newest (since V7). They are like souped-up very big full-function databases.
IMS TM (sometimes written as IMS DC – Data Communications) provides a way for users to run transactions to get information from the database. It is perhaps most like CICS in the way it allows users to work. IMS stores transactions in message queues and then schedules them to run. Like CICS there is a lot of work going on internally to maintain the integrity of the data and the transaction.
Highlights of the V10 announcement include enhanced IMS/XML database support, enhanced XML and Web services capabilities, more autonomic computing, and improved performance in database utilities. Of course, full details are on the IBM Web site at http://www-306.ibm.com/software/data/ims/v10/.
IMS is reckoned to be installed in 95 percent of Fortune 1000 companies, which makes it an important piece of software. It might have been around for quite a while, but by embracing SOA and Web services it has ensured that it will be with us for a long time yet.
Information Management System, to give it its full name, is a combination of database and transaction processing system. I’m not sure whether it’s 40th birthday was last year or next year because work started on it back in 1966, but it was 1968 when it was first running anywhere.
There are three databases associated with IMS DB. These are called “full function”, “fast path”, and High-Availability Large Databases (HALDBs). With full function databases – the original database type – data is stored in VSAM or OSAM files and can be accessed using HDAM, HIDAM, HSAM, HISAM, and SHISAM access methods. Full-function databases are derived from DL/I databases that were around at the time (1966). There are two types of fast path database – Data Entry DataBases (DEDBs) and Main Storage DataBases (MSDBs). These databases do not have indexes and are stored in VSAM files. HALDBs are the newest (since V7). They are like souped-up very big full-function databases.
IMS TM (sometimes written as IMS DC – Data Communications) provides a way for users to run transactions to get information from the database. It is perhaps most like CICS in the way it allows users to work. IMS stores transactions in message queues and then schedules them to run. Like CICS there is a lot of work going on internally to maintain the integrity of the data and the transaction.
Highlights of the V10 announcement include enhanced IMS/XML database support, enhanced XML and Web services capabilities, more autonomic computing, and improved performance in database utilities. Of course, full details are on the IBM Web site at http://www-306.ibm.com/software/data/ims/v10/.
IMS is reckoned to be installed in 95 percent of Fortune 1000 companies, which makes it an important piece of software. It might have been around for quite a while, but by embracing SOA and Web services it has ensured that it will be with us for a long time yet.
Monday, 15 October 2007
Back-ups and archives
So what is the difference between a back-up and an archive? Don’t both copy data somewhere so it can be restored at a later time if necessary? The answer to the second question is sort-of “yes”, and the answer to the first question is what this blog is about.
Back-ups of data can be stored at the same location as the original or offsite. If the main site suffers a catastrophe, the data can be restored somewhere else using the offsite back-up and work can continue. Back-ups used to be performed to tapes and the tapes would be overwritten after a week or some other fairly short period of time. The data in a back-up was the same as the data left on the mainframe.
An archive is something completely different. Gartner has suggested that the amount of data in a database is typically growing by 125%. For performance reasons, no one can afford to leave unused data in a database. Unused data is data that isn’t needed operationally and won’t be referenced. It won’t be needed by a transaction. This data can be moved out of the database to an archive. The database will then be smaller, so reorgs and back-ups will take place more quickly. Using the database will require less CPU, so everything else will perform better. In addition to improved performance, organizations will enjoy reduced costs. So archiving gives a huge return on investment.
The big problem with archived data is that it needs to hang around for a long time. In fact, with new laws and regulations this could be up to 30 years! A lot can change in 30 years. Your schema on the database may change, in fact, because of takeovers, mergers, and other reasons, your brand of database may change. And there’s even a chance that you won’t have a mainframe! What you need is a future-proof storage mechanism. You also need to be able to access the data that you have in your archive. Many countries are now allowing electronic records to be used in court and those archived records need to be able to be accessed. It’s no good in 20 years time hoping that you can restore some back-ups because, even if you have the same database, you probably won’t use the same schema. You need to be able to access the data, you need to be able to retrieve the data, and you need to be able to produce reports about the data.
As well as being able to run e-discovery tools against your archive (when it comes to litigation both sides need to know what you’ve got!), you need to ensure that it is incorruptible. It’s no good finding that five years ago someone accessed the archive and hid the tracks of their previous ten years of misdeeds. The archived data has to be read-only.
And, of course, when the time comes, you have to be able to delete the data that has come to end of both its business life and its compliance life.
So archiving has much more to it than simple back-ups. It’s quite a big difference.
Back-ups of data can be stored at the same location as the original or offsite. If the main site suffers a catastrophe, the data can be restored somewhere else using the offsite back-up and work can continue. Back-ups used to be performed to tapes and the tapes would be overwritten after a week or some other fairly short period of time. The data in a back-up was the same as the data left on the mainframe.
An archive is something completely different. Gartner has suggested that the amount of data in a database is typically growing by 125%. For performance reasons, no one can afford to leave unused data in a database. Unused data is data that isn’t needed operationally and won’t be referenced. It won’t be needed by a transaction. This data can be moved out of the database to an archive. The database will then be smaller, so reorgs and back-ups will take place more quickly. Using the database will require less CPU, so everything else will perform better. In addition to improved performance, organizations will enjoy reduced costs. So archiving gives a huge return on investment.
The big problem with archived data is that it needs to hang around for a long time. In fact, with new laws and regulations this could be up to 30 years! A lot can change in 30 years. Your schema on the database may change, in fact, because of takeovers, mergers, and other reasons, your brand of database may change. And there’s even a chance that you won’t have a mainframe! What you need is a future-proof storage mechanism. You also need to be able to access the data that you have in your archive. Many countries are now allowing electronic records to be used in court and those archived records need to be able to be accessed. It’s no good in 20 years time hoping that you can restore some back-ups because, even if you have the same database, you probably won’t use the same schema. You need to be able to access the data, you need to be able to retrieve the data, and you need to be able to produce reports about the data.
As well as being able to run e-discovery tools against your archive (when it comes to litigation both sides need to know what you’ve got!), you need to ensure that it is incorruptible. It’s no good finding that five years ago someone accessed the archive and hid the tracks of their previous ten years of misdeeds. The archived data has to be read-only.
And, of course, when the time comes, you have to be able to delete the data that has come to end of both its business life and its compliance life.
So archiving has much more to it than simple back-ups. It’s quite a big difference.
Subscribe to:
Posts (Atom)