Friday, December 31, 2010

Predictions for the next decade (2011 – 20)

1. Android (and its derivatives) will be omnipresent in embedded, mobile and hand held devices.
2. In laptops/desktops, windows or some flavor of it will be preferred operating system.
3. SAAS and PAAS will prevail for small and big enterprise.
4. IAAS will thrive in enterprise data centers.
5. Fragmentation and Alternatives of Java and Enterprise Java (like Apache harmony, and Spring) will emerge stronger and official java from Oracle will loose its sheen due to lust for its monetization by Oracle.
6. Laptop, mobile and tablet will merge into one.
7. Indian IT workforce will shift from permanent job to contractual jobs like in USA.
8. 3G and 4G (BWA) will bring internet book in India over smart phone and tablets.
9. Developing countries will swept by telecom revelation like India in previous decade.
10. Gamification will engulf almost all experiences especially of social media.
11. Outsoucing will change from India focused to 2I + 1 (2 location in India and one elsewhere)
12. Apple will loose its grip on smart mobile phone market.
13. Application will be pervasive in devices and appliances like phones (mobile and fixed line), TVs, automobiles, refrigerators, disk (CD/DVD/BlueRay) players, and any computing device.

Thursday, December 30, 2010

What questions (non financial) should I ask to a Cloud provide?

1. Number of years in service?
2. Number of subscribers?
3. Number of users?
4. Min number of users per subscriber?
5. Max number of users per subscriber?
6. Average number of users per subscriber?
7. Geographic spread of subscribers?
8. Mode by which Cloud can be accessed ( Browser, hand held device – mobile phone – which one, etc)
9. Does app has offline client?
10. Browser compatibility
11. List of business processes affected
12. Severity of affect to each business process (just touch, requires change, need complete change)
13. How to integrate with existing business systems – batch/real, synchronous/asynchronous, technology/platform?
14. Do employees need training?
15. Does Cloud affect master data?
16. How to integrate with Single Sign On (SSO)?
17. Does proposed cloud will capture any sensitive information (trade secret, patent, customer data, etc)?
18. What are the bandwidth requirements of proposed Cloud?
19. Does proposed Cloud have SSL support?
20. Does Cloud provider share with you external penetration tests and internal network security audits periodically?
21. Does provider have a documented policy for "hardening" the OS under Web and other servers?
22. Does provider have a documented set of controls to separate data and security information among customer applications?
23. Does provider perform background checks on personnel with administrative access to servers and applications?
24. Does provider has documented process for security alerts from IT partners?
25. What are the procedures for business continuity and disaster recovery?
26. Does provider certify the security of scripts and integration code; documented procedures for installing security patches
27. Does provider offer application- or transaction-based intrusion- detection services?
28. Does provider has documented identity management and help desk procedures?
29. What percentage of security staff has security industry certification?
30. What is the average experience of provider's security staff in information and network security?
31. What is the provider’s operational model: a. Self Hosting b. Co-location c. Managed Hosting d. Cloud Computing?
32. Is the provider's data center N + 1 for power?
33. Provider's Data facility: 1. Tier III 2. Tier IV
34. Is the provider's data center certified SAS 70 Type II or Type 1?
35. How many data centers does the provider have?
36. Which data centers will be used to server the application?
37. Is there a DR plan if a data center becomes unavailable?
38. Does the provider use at least 3 ISPs? Who are they?
39. Can a private connection to my enterprise WAN be provided?
40. Does the provider have network redundancy? How is this achieved?
41. How is network latency mitigated?
42. Can the provider provide location specific SLA's measured by a third party benchmarking service?
43. What are the hardware and software components provided by the provider?
44. Are provider servers dedicated or shared? If shared, by what method?
45. Is infrastructure redundant? If so, how is this accomplished?
46. What is Backup and retention schedule?
47. What monitoring is done as well as the interval, and reports that are available to review?
48. Is there staff 24/7? If not, what hours is staff available?
49. What is the provider's change management, patch management and upgrade policies and procedures?
50. What are the downtime notification policies (i.e. is advance notification given? How much?)?
51. Will a staging server/staging sand box be available for testing prior to production deployment?
52. Does provider has sand box for development?
53. How is security alerts handled? What are the security policies?
54. Do you have clear Service Level Agreements (SLAs) established with the service provider?
55. What kind of System Monitoring provided by the service provider?
56. What kind of help-desk support is available?
57. What are the change management processes available from the service provider?
58. Does the service provider provide you a staging environment to test changes before they are promoted to production?
59. Will the service provider support for full data and rule customization recovery on contract termination?
60. What API’s are exposed by service provider to develop application over cloud?
61. What API’s are exposed by service provider to deploy application over cloud?
62. Does my enterprise need new licensees of app servers/database or any other applications to be deployed over cloud?
63. How much time is needed to set up a proof of concept or trial demo?
64. How can offering being customized?
65. Industry references
66. Historical records of service availability?

Tuesday, December 28, 2010

Legal Challenges in cloud computing: Software Architect Perspective

Though Cloud gaining currency across the globe and across the industry. But if one carefully observe, he will find slow adoption of cloud in big enterprises. From a Software Architect perspective one should be aware of the legal challenges while evaluating cloud platforms for a solution.

1. Intellectual Property Rights
a. Is application and data protected under intellectual property rights?
b. If cloud provider gives access to your application, data, log etc to third party then what legal responsibility cloud provider assumes?
2. Trade Secrets
a. How secure are the trade secrets?
b. How far cloud provider can go to protect data, log, etc. in case of court summons and/or quasi legal requests/pressure?
c. How long cloud provider keeps application data and logs even after application is deleted from cloud and/or log deleted from cloud?
3. Privacy
a. What responsibility cloud provider assumes to protect Application Owner’s privacy?
b. What responsibility cloud provider assumes to protect Application users’ privacy?
c. Is there any liability coverage for privacy breach?
d. How behavioral tracking is maintained?
4. Data Centre
a. What legal responsibility does cloud provider assume in case of disaster?
b. What legal responsibility does cloud provider assume in case of hacking?
5. Jurisdiction
a. In case of any legal dispute which law apples – location of application provider, location of end user, location of cloud provider, location of server farm or any other?
b. In case of data breach who will send the notice of data breach – application provider or cloud provider?
c. How trans-border laws will be handled?
d. How do reputational risks covered?
e. How long data will be retained for legal and taxation purpose?
f. What is damage policy (say total dames are capped by amount of fee)?
g. Does the flow of data meet the regulatory requirements of each jurisdiction it flows through?
h. Does the cloud provider provides solutions for de-identifying data for transboarder data flow?
i. Where will the data and processes be stored? Can a commitment be obtained?
j. Are there multiple cloud platforms/parties involved?
k. Can the movement of data be controlled?
l. Should/can the data be encrypted?
6. Service Level Agreement
a. What are the SLA’s for cloud provider?
b. What matrices will be used to measure performance of cloud provider?
c. In case of dishonoring of SLA, what are the penalties and they will be enforced?
7. Licensing
a. Do libraries, components, services, servers, etc used in application creation, deployment, etc have cloud compatible licenses?
b. Do libraries, components, services, servers, etc used in application creation, deployment, etc licenses cover upgrade and maintenance as well?
c. How application’s license is structured for end users?
8. Physical Location of Data and processes
a. What is the location of data?
b. What is the location of processes?
c. Is any point of time, location of data and process be ascertained?
9. E-discovery
a. What are the evidentiary issues when client data is in cloud?
b. What are the SLA’s of e-discovery?
c. Who is responsible for e-discovery?
10. Termination
a. In case of contract termination, how data will be moved from cloud to in agreed upon format?
b. Who is responsible to move data?
c. If cloud provider goes out of business then how termination will be handled?
d. If application provider goes out of business then how termination will be handled – data, intellectual property.
e. Is there any lock in?
11. Change in Terms and conditions
a. How change in terms and conditions to be handled?
b. Does cloud provider change terms and condition by inserting URL?
12. Audit
a. Can application provider do audit of facilities and processes/procedures and how extensive are these audits?
b. Can application provider do audit of logs and how extensive are these audits?
13. Miscellaneous
a. What insurance cover cloud provider has?
b. In case of emergencies how data be accesses and who will be responsible?
c. Use of application provider’s name and logo for publicity by cloud provider?
d. Use of cloud provider’s name and logo for publicity by application provider?
e. How service renewal will be handled?

Monday, December 20, 2010

Sunday, December 19, 2010

A Small Step for Service Governance

While talking about SOA Governance, one visualizes big fat software and tools which costs millions of dollars and a platoon of support staff to “govern” SOA Governance platform.
In my experience, I noticed that small baby steps always more helpful and governance should be embedded in architecture and design. Instead of SOA Governance, I like it to be service governance first.
Recently, talking to one of my counterpart at my client place, I encountered a classic case of mis governance in services space. Once service is created and deployed, its contract ( wsdl in case of web service) is freely available across enterprise which makes unknowns its customer (sic) without any controlling authority. This uncontrolled distribution and usage of contract leads to nightmares and fights when service performance decreases or new version of service need to be releases and older version to be retired.

How to avoid such dogfight!

Simply create a registry (not UDDI) of service and make sure that this registry contains the information that who is calling whom and authentication has to pass through this registry. I understand this suggestion violets purist form of SOA but in this world nothing is perfect.

Saturday, December 18, 2010

Convention over Configuration

Now a days every software using or claiming to use convention over configuration.

Is anybody paying any attention on negatives of this paradigm?

1. To utilize a piece of software which is based on Convention over Configuration paradigm, one requires deep familiarity of software.
2. Refactoring becoming difficult and specifically if at any point of time, need arise to change convention, developers have night mares.
3. Bloated code is very normal because of binding the logic with convention. This pain can be reduced if conventions are made configurable.
4. This paradigm makes software very restrictive in view of “ only one way” of doing the things.

Few of the well known examples of softwares using Convention over Configuration paradigm are:
1. Java Bean
2. XDocLet
3. EJB
4. Spring
5. Hibernate
6. Grails
7. Ruby on Rails
8. Apache Camel
9. Struts
10. Maven
11. Apache Wicket

Reference:
1. http://softwareengineering.vazexqi.com/files/pattern.html
2. http://msdn.microsoft.com/en-us/magazine/dd419655.aspx
3. http://elegantcode.com/2009/11/28/convention-over-configuration/
4. http://en.wikipedia.org/wiki/Convention_over_configuration
5. http://marekblotny.blogspot.com/2009/04/convention-over-configuration.html
6. http://codebetter.com/jeremymiller/2009/01/24/convention-over-configuration-in-msdn-magazine/
7. http://www.javalobby.org/java/forums/t65305.html
8. http://www.sonatype.com/books/mvnref-book/reference/installation-sect-conventionConfiguration.html
9. http://weblogs.asp.net/sfeldman/archive/2009/07/20/convention-over-configuration.aspx