Transformation Innovation

NPR on Cloud Computing

By G C Network | August 29, 2008

You know it’s important when NPR covers it !! On the “All Things Consider” radio show, NPR took a look into cloud computing. I’m not sure if Computing In The…

Sun Federal Cloud Computing eBook

By G C Network | August 28, 2008

Sun Federal now has it’s ebook on cloud computing available for all. The website doesn’t really offer any new information, but it does highlight how Sun Federal is targeting the…

Amazon Elastic Block Store

By G C Network | August 27, 2008

Last week, with their announcement of Elastic Block Store, Amazon has made enterprise class storage in the cloud a reality. According to Dion Hinchcliffe of Ziff Davis,”Elastic Block Store finally…

HP CTO On the Future

By G C Network | August 26, 2008

In a recent Web Guild article, Shane Robinson, Chief Strategy & Technology Office for HP outilined his belief that we are in the early stages of a major shift. As…

Google serves as first line of defense during Russia’s invasion of Georgia (A plug for the cloud)

By G C Network | August 25, 2008

As reported by the Christian Science Monitor, “As Georgian troops retreated to defend their capital from Russian attack, the websites of their government, also under fire, retreated to Google. In…

Apptis and Servervault announce Fedcloud

By G C Network | August 22, 2008

On August 18th, Apptis announced a partnership with ServerVault to offer a trusted cloud computing environment to federal agencies. Called Fedcloud they are offering a federally compliant, on-demand infrastructure that…

SOA-R Educational Series Schedule Changes

By G C Network | August 21, 2008

Since launching the SOA-R series back in July, cloud computing has become a hot topic among national security professionals. Evidence of this high level of interest is obvious from the…

Comments from Mr. Robert Carey, DON CIO and Army COS General George W. Casey, Jr

By G C Network | August 20, 2008

Over the last couple of weeks, I’ve had the distinct pleasure to listen to both Mr. Robert Carey, CIO, Department of the Navy, and General George W. Casey, Jr., Chief…

Akamai at SOA-R Session

By G C Network | August 19, 2008

Had another very enlightening SOA-R session last week. Of particular note to me was Akamai’s vision of cloud computing. As presented by Fran Trently, Sr. Director Public Sector, Akamai is…

Six Benefits of Cloud Computing

By G C Network | August 18, 2008

A Public CIO magazine article, to be published later this fall, will highlight six main benefits of cloud computing. Reduced Cost Increased Storage Highly Automated Flexibility More Mobility Allows IT…

4 Factors Driving Digital Transformation ROI

The critical assessment factors for cloud ROI risk probability are the following:     

  • Infrastructure utilization
  • Speed of migration to cloud
  • Ability to scale business/mission processes
  • Quality delivered by the new cloud-based process 

These four factors directly drive digital transformation ROI because they affect revenue, cost, and the time required to realize any investment return. Differences between actual and projected values in these metrics indicate a likely failure to achieve the desired goals.

Although business alignment is always a primary digital transformation drive, ROI remains a key decision component. This metric should, however, be addressed from multiple vantage points to include cloud workload utilization, workload size versus memory/processor distribution and the virtual hardware instance to physical asset ratio. 

Value delivered through innovation should also be part of the business value calculation. Value can be delivered through operational cost reductions, optimization of resource capacity, and a reduced total cost of ownership. Business process time reductions, product quality improvements and customer experience enhancements are also useful outcomes.

Security Controls

Business/mission model changes can also introduce operational risk. Acceptance of these risk are based on executive risk tolerance. Their risk mitigation decisions result in the implementation of security controls. A control will restrict a list of possible actions down to what is allowed or permitted by the organization. Encryption, for example, can be used to restrict the unauthorized use of data.

The security control continuum extends over three categories:         

  • Management (administrative) controls: policies, standards, processes, procedures, and guidelines set by corporate administrative entities (i.e., executive to mid-level management)         
  • Operational (and physical) controls: operational security (execution of policies, standards and process, education, and awareness) and physical security (facility or infrastructure protection)
  • Technical (logical) controls: Access controls, identification and authentication, authorization, confidentiality, integrity, availability, and non-repudiation 

They also encompass the following types:

  • Directive controls: often referred to as administrative controls, advise employees of the behavior expected of them during their interfaces with or use of information systems
  • Preventive controls: include physical, administrative, and technical measures that preclude actions that violate policy or increase the risk to system resources
  • Deterrent controls: use warnings and a description of related consequences to prevent security violations
  • Compensating controls: Also called an alternative control, a mechanism that is put in place to address security requirements deemed impractical to implement
  • Detective controls: Refer to the use of practices, processes, and tools that identify and possibly react to security violations
  • Corrective controls: involves physical, administrative, and technical measures designed to react to a security-related incident in order to minimize the opportunity for an unwanted event to reoccur
  • Recovery controls: restore the system or operation to a normal operating state once integrity or availability is compromised 

The costs associated with the implementation of any security control should be weighed against the value gained from digital transformation business/mission process improvements.

Would you like to learn more about digital transformation innovation? Pick up a copy of my new book, Click to Transform! 

A book about business and technology
Posted in

pwsadmin