STORAGE MANAGEMENT/ EXECUTIVE: ITIL® and Other Best Practices Frameworks Jim Damoulakis CTO, GlassHouse Technologies jimd@glasshouse.com Sept. 21, 2004.

Slides:



Advertisements
Similar presentations
STORAGE MANAGEMENT/ GETTING STARTED: Storage Management 101 Everything you always wanted to know about Storage Management (but were afraid to ask) Stephen.
Advertisements

Alignment of COBIT to Botswana IT Audit Methodology
Service Delivery – your ticket to play
Chapter 10 Accounting Information Systems and Internal Controls
ITIL: Service Transition
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
Yale University Information Technology Services Administrative Systems Art Hunt 3/22/04 Software Service Level Agreement with Finance, Procurement and.
TI BISNIS ITG using COBIT &
Chapter © 2009 Pearson Education, Inc. Publishing as Prentice Hall.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
The Transforming Power of the ITIL Framework for the Project Manager Patrick von Schlag Deep Creek Center November 10, 2010.
ITIL A Team GALIP Presentation A. Silverman, N. Elovitz, L. Johnson, M. Saxena, W. Zhao.
Effort in hours Duration Over Weeks Or Months Inception Launch Web Lifecycle Methodology Maintenance Phases Copyright Wonderlane Studios.
ITIL: Why Your IT Organization Should Care Service Support
Defining Services for Your IT Service Catalog
Demonstrating IT Relevance to Business Aligning IT and Business Goals with On Demand Automation Solutions Robert LeBlanc General Manager Tivoli Software.
© 2010 Plexent – All rights reserved. 1 Change –The addition, modification or removal of approved, supported or baselined CIs Request for Change –Record.
Explosive Data Growth – How to Handle the Risks and Opportunities David Bregman Director November 7, 2006.
Optimize ITIL ® Implementations With processes automation ITIL is a Registered Trademark by the OGC Dimitri Mizernik
The Evergreen, Background, Methodology and IT Service Management Model
Continual Service Improvement Process
Collin County’s Doing More with Less How Collin County’s ITIL Framework has worked to do more with less.
Security Baseline. Definition A preliminary assessment of a newly implemented system Serves as a starting point to measure changes in configurations and.
1 Process Engineering A Systems Approach to Process Improvement Jeffrey L. Dutton Jacobs Sverdrup Advanced Systems Group Engineering Performance Improvement.
STORAGE MANAGEMENT/ EXECUTIVE: Managing a Compliant Infrastructure Processes and Procedures Mike Casey Principal Analyst Contoural Inc.
Roles and Responsibilities
Deakin Richard Tan Head, Information Technology Services Division DEAKIN UNIVERSITY 14 th October 2003.
Module N° 8 – SSP implementation plan. SSP – A structured approach Module 2 Basic safety management concepts Module 2 Basic safety management concepts.
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
ISO17799 Maturity. Confidentiality Confidentiality relates to the protection of sensitive data from unauthorized use and distribution. Examples include:
Roadmap to Maturity FISMA and ISO 2700x. Technical Controls Data IntegritySDLC & Change Management Operations Management Authentication, Authorization.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
Committee of Sponsoring Organizations of The Treadway Commission Formed in 1985 to sponsor the National Commission on Fraudulent Financial Reporting “Internal.
Building Capability.  In order to successfully operate an architecture function within an enterprise, it is necessary to put in place appropriate organization.
STORAGE MANAGEMENT/MASTER: The Storage Control Center SRM, Performance Monitoring and Operations Jenney Fields Senior Consultant GlassHouse Technologies,
SAM for Virtualizatio n Presenter Name. Virtualization: a key priority for business decision makers Technavio forecasts that the global virtualization.
ITIL Overview 1 Configuration Management Working Group February 8, 2011.
IT Governance: COBIT, ISO17799 & ITIL. Introduction COBIT ITIL ISO17799Others.
ITIL Drivers for Government Scott Spencer Vice President, Program Management, GTSI.
Introduction to the Continual Service Improvement Toolkit Welcome.
Version 3.3 ITIL – IT Service Management An overview program for IT Service Management good practices.
Example Incident Mgmt Initiation No recording of Incidents Users can approach different departments Solutions of previous incidents are not available.
Cloud Computing Use Case Draft v2.
Information Technology Services Strategic Directions Approach and Proposal “Charting Our Course”
ITIL Awareness UC JDCMG Discussion 4/26/2017.
ITIL VS COBIT 06 PLM - Group 9
State of Georgia Release Management Training
CSI - Introduction ITIL v3.
Introduction to ITIL and ITIS. CONFIDENTIAL Agenda ITIL Introduction  What is ITIL?  ITIL History  ITIL Phases  ITIL Certification Introduction to.
CLOUD-BASED VIDS A CIO’S PERSPECTIVE Stephen Alford, CIO WEP, Inc.
#325 - CobiT and Service Delivery Debra Mallette, CISA, CSSBB Kaiser Permanente IT.
Driving Value from IT Services using ITIL and COBIT 5 July 24, 2013 Gary Hardy ITWinners.
Practical IT Research that Drives Measurable Results 1Info-Tech Research Group Get Moving with Server Virtualization.
ITIL and Remedy ITSM Implementation Overview
COBIT. The Control Objectives for Information and related Technology (COBIT) A set of best practices (framework) for information technology (IT) management.
1 Using CobiT to Enhance IT Security Governance LHS © John Mitchell John Mitchell PhD, MBA, CEng, CITP, FBCS, MBCS, FIIA, CIA, CISA, QiCA, CFE LHS Business.
ISACA Willamette Valley Chapter Luncheon Thursday, March 20, 2008 Practical Auditors Guide for CobiT Steve Balough, CISA.
Introduction to ITIL IT Service Management Collin Smith
Identification of Business Needs Visualizing the Service Offering
BIL 424 NETWORK ARCHITECTURE AND SERVICE PROVIDING.
Establishing Strategic Process Roadmaps
The Process Owner is the Secret Agent!
Establish Process Governance
ITIL: Why Your IT Organization Should Care Service Support
ITIL: Why Your IT Organization Should Care Service Support
Alignment of COBIT to Botswana IT Audit Methodology
ITIL: Why Your IT Organization Should Care Service Support
Presentation transcript:

STORAGE MANAGEMENT/ EXECUTIVE: ITIL® and Other Best Practices Frameworks Jim Damoulakis CTO, GlassHouse Technologies jimd@glasshouse.com Sept. 21, 2004

Outline Best practices frameworks ITIL® Other “standards” Drivers Benefits ITIL® What is it? Who owns it? How do you use it? Other “standards” CMM COBIT COSO ITIL® is a registered trade mark of OGC

Outline (2) How does this fit with storage? GH SML Improving storage management – need more than tools Managing increasing complexity and controlling cost Realization that you can’t take advantage of new technology without fixing the process Better services at lower cost GH SML What is it? How does it fit with the frameworks? Usage examples

Best practices frameworks Process rediscovered? Increased accountability – compliance Aligning IT with business – more than lip service Growth is too difficult to manage Reduce risk Improve effectiveness Improve cost

ITIL: What? IT Infrastructure Library (ITIL) “ITIL is the most widely accepted approach to IT service management in the world.” A best practices approach for IT service management A framework to structure new and existing methods and activities De facto standard (Real standard is BS15000) Quality focus

ITIL: Who? UK Office of Government Commerce (OGC) Holder of copyright Also oversees PRINCE2 itSMF: IT Service Management Forum Drives much of the ITIL definition and qualification criteria Publications Training Certifications (people, not organizations)

ITIL framework publications Source: Pink Elephant

Service delivery Service level management Financial management for IT services Capacity management IT services continuity management Availability management

Service support Incident management Problem management Configuration management Change management Release management

Capability maturity model: Carnegie Mellon SEI Level Name Description 1 Initial Ad-hoc, reactive, “firefighting” 2 Repeatable Proactive, trained people 3 Defined Documented, standardized products and procedures 4 Managed Metrics for deliverables and processes 5 Optimizing Continuous improvement with feedback

Control OBjectives for Information and related Technology (COBIT® ) Controlled by the IT Governance Institute (ITGI) and Information Systems Audit and Control Association (ISACA) Framework for governance of IT “Developed as a generally applicable and accepted standard for good Information Technology (IT) security and control practices that provides a reference framework for management, users, and IS audit, control and security practitioners”

CobiT domains: Planning & organization Acquisition & implementation Delivery & support Monitoring

Compliance auditing COSO internal control – Integrated framework Committee of Sponsoring Organizations of the Treadway Commission Blessed by SEC and PCAOB as approved IT governance framework Five components: Control environment Risk assessment Control activities Information and communication Monitoring

How does this apply to storage? ITIL, COBIT, COSO do not discuss storage specifically Goals of effectiveness and efficiency are the same across IT Storage adds the problem of persistence Need for a storage-specific framework

The GlassHouse Storage Management Lifecycle™ A framework of best practice for the planning, management and operation of the storage environment A guide to the steps needed to align, plan, design and purchase the storage infrastructure A road map for the development of policies and standard operating procedures needed for efficient and compliant storage management Supportive of international standards on compliance

Storage Management Lifecycle Phase 1 Planning Phase 2 Provisioning Phase 3 Maintenance Phase 4 Customer Care Source: GlassHouse Technologies Inc. 2004 Storage Management Lifecycle

Phase 1: Planning 1.1 Strategy 1.2 Policies 1.3 Discovery Phase 1.4 Requirements Source: GlassHouse Technologies Inc. 2004

Phase 2: Provisioning 2.1 Purchasing 2.2 Change Control 2.3 Activation Service Acceptance Source: GlassHouse Technologies Inc. 2004

Phase 3: Maintenance 3.1 Service Delivery 3.2 Infrastructure Management 3.3 Support Phase 3.4 Compliance Source: GlassHouse Technologies Inc. 2004

Phase 4: Customer Care 4.1 Service Ordering 4.2 Fulfillment 4.3 Quality Source: GlassHouse Technologies Inc. 2004 4.4 Alignment Check

Operations & Maintenance 21 51 Domain Activities Tasks Focus Areas Planning 4 28 89 Provisioning 25 56 Operations & Maintenance 21 51 Client Care (end user) 3 16 Technical Requirements Reference Architecture Primary Environment

Planning Strategy Policies Discovery of environment Example: Breakout of planning phase and tiered, detailed activities and tasks Phase Activity Tasks Business Drivers, Service Levels required, Financial criteria Strategy Demarcation lines, storage group roles, data classification, expense request, capacity planning, security, technology directions, communications Policies Planning Primary environment, server environment, storage network environment, data identification, backup environment, DR environment, archiving environment, policies, procedure, tools environment, organization structure, application environment Discovery of environment Group service levels, define COS attributes, develop reference architecture, establish financial parameters, establish standard operating procedures Technical requirements

Mapping the ITIL framework to the SML (SS) Service Support Service desk √ Incident management √ Problem management √ Configuration management √ Change management √ Release management √ (BP) Business Perspective Business continuity √ Partnerships and outsourcing Surviving change Transformation of business practice Application Management (SD) Service Delivery Capacity management √ Financial management √ Availability management √ Service level management √ Service continuity management √ (IM) Infrastructure Management Network service management √ Operations management √ Management of local processors √ Computer installation and acceptance √ Systems management √ √ indicates match to GH SML activity

Engagement objectives - Capability maturity model

Key findings: Fragile storage utility model Business unit concerns – Availability Single tier of service – Cost & need mismatch No service level agreements – Need & value mismatch Cost model constraints – Not tiers, no penalties, no BU$ Virtual storage team – Authority & accountability mismatch Mature management practices – Under development One level data protection – Cost & need mismatch No lab environment – Cost & risk mismatch

Overall maturity level

Prioritization of process development plan by: Impact Level of effort

Storage management road map 3 Months 6 months 9 months 9+ Months Foundation Optimize Compliance Architecture Desired State: Improved staff productivity Continuous reduction in unit TCO of storage Reduced risk to critical apps Costs aligned with data criticality Improved service levels to business units Expansion and growth part of a planned strategy Compliant with regulation, legislation and mandate Pragmatic and usable Disaster Recovery plan Key Metrics Develop and Implement Key Performance Indicators and Key Risk Indicators Cost Model Simulation Develop model to include BU, Arch, DR and Dev costs Base SOP’s Develop key Standard operating procedures with compliance, completion and quality artifacts SLA Development Simulation Develop & Publish draft SLA’s Backup Compression Model BU Strategies for closing window of opportunity Automation Tools selection Cost Reduction Consolidation of Storage Data Identification Application, Server, Storage, Business cross ref and inter dependency Critical Priorities Identify & Implement immediate compliance requirements ILM Strategies Develop ILM strategies for DB information, and email ILM Implementation Implement ILM strategies for DB and email Audit Capability Develop & implement internal audit capability Archiving Develop archiving compliance needs, refresh, recovery needs & priorities Strategic Storage Architecture - Business needs, Policies, Service Levels, Backup, Archiving, DR, Reference Architecture, RFI/RFP, Acquisition, Implementation, Metrics, Tools, SOP’s, Operation,

Sample Tools – Provisioning

Summary – Why a best practices framework? Promotes alignment of business needs with IT storage directions Optimizes storage investment effectiveness and reduces operational costs. Ability to cost, migrate and manage data appropriate to its value. Provides speedy development of policy and procedure Reduces risk and promotes manageability and predictability. Creates a solid basis for identification and selection of appropriate automation tools. Supports compliance process validation.

Useful links Official ITIL home page – www.ogc.gov.uk/index.asp?id=2261 itSMF – www.itsmf.com CobiT – www.isaca.org COSO – www.coso.org CMM – www.sei.cmu.edu/cmm/ GlassHouse SML – www.glasshouse.com