Wednesday, November 14, 2007

A five-step model for configuration management

There are two meanings for the project management process of configuration management.

1. It can be used for the process of identifying, tracking, and managing of all the physical assets of a project. The items that you track under configuration management are called “configuration items” in the Capability Maturity Model (CMMI).

2. It can also refer to the process of identifying, tracking and managing of all the characteristics of the assets of a project. These characteristics can also be referred to as product “metadata.” This is closer to the definition of configuration management in the Project Management Body of Knowledge (PMBOK®) from the Project Management Institute.

The following model describes the five major aspects of configuration management.

Planning. You need to plan ahead to create the processes, procedures, tools, files, and databases for managing the project assets or the metadata. You also may need to gain an agreement on exactly what assets are important, how you will define them, how they will be categorized, classified, numbered, reported, etc. The results of this up-front planning are documented in a Configuration Management Plan.

Part of your planning process should be to assign configuration tracking numbers to each type of configuration item.

Tracking. It’s important to understand the baseline for all configuration items. In other words, for each configuration item, you need to understand what you have at the beginning of the project. In many cases, you may have nothing to start with. In other cases, like physical assets, you may have some assets to begin with. The purpose of your tracking processes is to ensure that you can track all changes to a configuration item throughout the project.

You need processes and systems designed to identify when assets are assigned to your project, where they go, what becomes of them, who is responsible for them and how they’re disposed of. Since a project has a beginning and end, ultimately all the assets need to go somewhere. This could be in a final deliverable, into the operations/support area, scrapped, etc. You should be able to dissect each major deliverable of the project and show where all the pieces and parts came from, and where they reside after the project ends.

Managing. Managing assets means ensuring that they’re secure, protected, and used for the right purposes. For example, it doesn’t do any good to track purchased assets that your project doesn’t need in the first place. Also, your tracking system may show expensive components sitting in an unsecured storage room, but is that really the proper place for them? Managing assets has to do with acquiring what you need and only what you need. You also have to make sure you have the right assets at the right place at the right time.

Reporting. You need to be able to report on the project assets, usually in terms of what you have and where they are, as well as financial reporting that can show cost, budget, depreciation, etc.

Auditing. Auditing involves validating that the actual configuration elements (whatever they are) at any given time are the same as what you expect. Many projects get in trouble when they start to lose track of physical assets (for instance, material, supplies, code or other configuration items) or if the physical characteristics (metadata) of your deliverables is different that what you expect.

The auditing process is used to validate that the configuration elements match up with your expectations. These expectations are based on the original baseline, plus any change requests that you have processed up to the current time.



10 services to turn off in MS Windows XP

As I pointed out on 19 October, in point number four of the article 10 security tips for all general-purposes OSes, an important step in the process of securing your system is to shut down unnecessary services. As long as Microsoft Windows has been a network capable operating system, it has come with quite a few services turned on by default, and it is a good idea for the security conscious user of Microsoft’s flagship product to shut down any of these that he or she isn’t using.

Each version of MS Windows provides different services, of course, so any list of services to disable for security purposes will be at least somewhat particular to a given version of Microsoft Windows. As such, a list like this one needs to be identified with a specific Microsoft Windows version, though it can still serve as a guide for the knowledgeable MS Windows user to check out the running services on other versions as well.

If you are running Microsoft Windows XP on your desktop system, consider turning off the following services. You may be surprised by what is running without your knowledge.

  • IIS – Microsoft’s Internet Information Services provide the capabilities of a Webserver for your computer.
  • NetMeeting Remote Desktop Sharing — NetMeeting is primarily a VoIP and videoconferencing client for Microsoft Windows, but this service in particular is necessary to remote desktop access.

  • Remote Desktop Help Session Manager – This service is used by the Remote Assistance feature that you can use to allow others remote access to the system to help you troubleshoot problems.
  • Remote Registry – The capabilities provided by the Remote Registry service are frightening to consider from a security perspective. They allow remote users (in theory, only under controlled circumstances) to edit the Windows Registry.
  • Routing and Remote Access – This service bundles a number of capabilities together, capabilities that most system administrators would probably agree should be provided separately. It is rare that any of them should be necessary for a typical desktop system such as Microsoft Windows XP, however, so they can all conveniently be turned off as a single service. Routing and Remote Access provides the ability to use the system as a router and NAT device, as a dialup access gateway, and a VPN server.
  • Simple File Sharing – When a computer is not a part of a Microsoft Windows Domain, it is assumed by the default settings that any and all filesystem shares are meant to be universally accessible. In the real world, however, we should only want to provide shares to very specific, authorized users. As such, Simple File Sharing, which only provides blanket access to shares without exceptions, is not what we want to use for sharing filesystem resources. It is active by default on both MS Windows XP Professional and MS Windows XP Home editions. Unfortunately, this cannot be disabled on MS Windows XP Home. On MS Windows XP Professional, however, you can disable it by opening My Computer -> Tools -> Folder Options, clicking the View tab, and unchecking the Use simple file sharing (Recommended) checkbox in the Advanced settings: pane.
  • SSDP Discovery Service – This service is used to discover UPnP devices on your network, and is required for the Universal Plug and Play Device Host service (see below) to operate.

  • Telnet – The Telnet service is a very old mechanism for providing remote access to a computer, most commonly known from its use in the bad ol’ days of security for remote command shell access on Unix servers. These days, using Telnet to remotely manage a Unix system may be grounds for firing, where an encrypted protocol such as SSH should be used instead.
  • Universal Plug and Play Device Host – Once you have your “Plug and Play” devices installed on your system, it is often the case that you will not need this service again.
  • Windows Messenger Service – Listed in the Services window under the name Messenger, the Windows Messenger Service provides “net send” and “Alerter” functionality. It is unrelated to the Windows Messenger instant messaging client, and is not necessary to use the Windows Messenger IM network.

On your system, these services may not all be turned on, or even installed. Whether a given service is installed and running may depend on whether you installed the system yourself, whether you are using XP Home or XP Professional, and from which vendor you got your computer if MS Windows XP was installed by a vendor.

With the exception of Simple File Sharing, all of the above listed services can be disabled from the same place. Simply click on the Start button, then navigate to Settings -> Control Panel, open Administrative Tools, and from there open the Services window. To disable any service in the list, double-click on its entry in that window and change the Startup type: setting. In general, you should change services you are turning off for security purposes to a “Disabled” state. When in doubt about whether a given service is necessary for other services, check the Dependencies tab in the service’s settings dialog.

Obviously, this is not a comprehensive list of everything running on your computer that you may want to turn off. It is merely a list of ten items that you most likely do not need to have running, and constitute a security vulnerability if left running. Most users will never have need of any of the services in this list, once the computer is up and running. Other services may be disabled without ill effect as well, though you should research each item in the complete services list before you disable it to ensure that you actually do not need it running. Some of them are quite critical to the normal operation of your system, such as the Remote Procedure Call (RPC) service.

Every running — but unused — service on your machine is an unnecessary security vulnerability. If a service is not important at all for authorized users and basic system functionality, turn it off.





Taking a look at IBM Lotus Symphony Presentations

Continuing with my first-look series covering the IBM Lotus Symphony office suite, I’ve created a gallery covering the slideshow application, Symphony Presentations. (I covered Symphony Documents in the first gallery and Symphony Spreadsheets in the second gallery.)

As you’ll discover, while Symphony Presentations contains everything you will need to create effective slideshows, it lacks many of the bells and whistles you’ll find in Microsoft PowerPoint and, surprisingly, even its cousin, OpenOffice Impress.

You can download the Lotus Symphony suite and try Presentations yourself.

Keep in mind that Lotus Symphony is listed as Beta 1. However, since the suite has essentially been extracted from the final version of Lotus Notes 8, it’s actually pretty solid. That’s not to say that I didn’t encounter any snags — but they were fairly minor.





You can download it from here also

Convert Word graphics to AutoShapes to type text directly on your images

While you can use a text box to add a word or two to your Word document pictures, it is easier to position text typed directly onto the picture itself. While Word does not let you type directly onto a pasted picture, it does let you add text to AutoShapes. By turning your picture into an AutoShape, you can type directly on it. Follow these steps:

  1. Right-click any toolbar.
  2. Click Drawing.
  3. Click AutoShapes on the Drawing toolbar.
  4. Point to Basic Shapes and click Rectangle.
  5. Click and drag in your document where you want to position the rectangle.
  6. Click the Fill Color button’s drop-down arrow in the Drawing toolbar.
  7. Click Fill Effects and then click the Picture tab.
  8. Click the Select Picture button.
  9. Navigate to the picture and click Insert. Click OK.
  10. With the shape still selected, right-click the shape and select Add Text.
  11. Type the text you want at the prompt.
  12. Select and right-click the text.
  13. Click Font.
  14. Choose the desired font, font size, color, etc. from the Font dialog box and then click OK.

You can position the text within the shape by adding blank lines, spacing, indents, or any other paragraph formatting you wish.




Let Excel e-mail your weekly reports

If you have to send the same worksheet to a number of people every week, it probably takes you quite awhile to prepare the e-mail. If you have to do this for a number of reports, it can take even longer. Follow these steps to have Excel e-mail the reports for you:

1. Open the workbook containing the report you want to send.
2. Press [Alt][F11].
3. In the Project-VBA Project pane, double-click ThisWorkbook.
4. Go to Insert | Procedure.
5. Click in the Name text box and enter WeeklyReportEmail. Click OK.
6. At the prompt, enter the following code:
Dim DistList As Variant
DistList = Array("name1@company.com", "name2@company.com", "name3@company.com")
ActiveWorkbook.Sendmail Recipients: = DistList
7. Press [Alt]Q.
8. Press [Alt][F8].
9. Click WeeklyReportEmail in the Macro list.
10. Click the Options button.
11. In the Ctrl+ box, enter m. Click OK.


Now when you need to send a report to everyone on your distribution list just open the workbook and press [Ctrl]M.

10 tips for meeting IT project deadlines

Overview: Erratic and poorly estimated timelines, scope creep, unexpected staff illnesses, and supplier failures are just a few of the things that could go wrong with your project. And because time is today the most common metric to measure efficiency, the schedule delays caused by these events can end up costing you a fair amount of money. These tips will help you plan your next project and ensure that it comes in on time, under budget, and at a high quality level.

Erratic and poorly estimated timelines, scope creep, unexpected staff illnesses, and supplier failures are just a few of the things that could (and probably will) go wrong with your project. And because time is today the most common metric to measure efficiency, the schedule delays caused by these events can end up costing you a fair amount of money (in addition to a possible damaged reputation). Here are some tips to help you plan your next project and ensure that it comes in on time, under budget, and at a high quality level.

Analyze the requirements in detail
Understand exactly what the project involves, down to the smallest details. Ask questions to clarify ambiguous areas. Finally, hire professionals to clearly document the business requirements, the functional specification, and the design requirements. Watch out for scope creep; it can single-handedly destroy all the work you've done. If the need arises, take aggressive steps to reduce the scope of the project or to avoid adding unplanned new features that require significant integration time.

Map available resources
Map available resources with requirements to ensure that there are enough personnel on site to complete the job. Identify all relevant infrastructure—hardware, software, human resources, tools, documents—required to execute the project well before the project development starts.
Perform training and knowledge transfer
Include training, if any, as part of the project timeline. Don't treat training as something team members do on their own time, but account for it in the project schedule and budget.

Identify risks
Identify the potential risks and create contingency plans to deal with them. Develop a backup plan to meet the project deadline in case of unexpected process or personnel failures. This "plan B" acts are your support system when things don't go as expected.

Estimate and allocate
Assign roles and responsibilities to team members and ensure that each task has a clear owner. Use project management tools and Gantt charts to record who does what and identify start and end dates for each activity. Failure to assign clear responsibilities for each task can lead to overlapping responsibilities, duplication of efforts, excessive time spent on activities, and inferior product quality.

Modularize work
Break down main activities into sub-activities, until each activity is complete on its own and independent of other activities. Arrange them in logical order and then start executing the smallest activity in the order of occurrence.

Avoid too many meetings
Plan meetings to discuss the status of the project or on an as-needed basis to address immediate problems. Long, unending meetings with no clear agenda and hence no clear outcome only waste time.

Write things down
Document the failures and successes of the project. This is important; it acts as historical information for similar activities in other projects. Use a project dashboard to obtain a visual, high-level overview of the project and to measure the progress of project activities. Take stock of the project at each milestone and update the project dashboard each time.

Beware of follow-the-sun development
If there is a follow-the-sun development model (a continuous engineering environment with development happening 24/7 across the globe), ensure clear communications to avoid misunderstanding between co-located or cross-country-located team members. Coordinate well and regularly so that nothing falls through the cracks.

Escalate issues
Escalate issues to management as they occur and brainstorm on solutions to problems. Trying to remedy problems after they've deteriorated beyond recovery is the last thing you need.


Don't let Windows XP startup problems leave you dead in the water

Overview: When everything works the way it should, we take Windows startup for granted. But if something fails, it's important to be able to diagnose the problem and effect a solution. This chapter from It's Never Done That Before! A Guide to Troubleshooting Windows XP starts by explaining what normally happens during startup. Then, it looks at various issues you may encounter if a process fails and discusses techniques and tools you can use to troubleshoot problems.

The Book Name is "IT’S NE VER DONE THAT BEFORE! --A Guide to Troubleshooting Windows XP" By John Ross

You can get this book from here

10 types of programmers you'll encounter in the field

Overview: Programmers enjoy a reputation for being peculiar people. In fact, even within the development community, there are certain programmer archetypes that other programmers find strange. Justin James put together this list of some of the weirder types of programmers you're likely to run across.
Programmers enjoy a reputation for being peculiar people. In fact, even within the development community, there are certain programmer archetypes that other programmers find strange. Here are 10 types of programmers you are likely to encounter. Can you think of any more?

1. Gandalf
This programmer type looks like a short-list candidate to play Gandalf in The Lord of the Rings. He (or even she!) has a beard halfway to his knees, a goofy looking hat, and may wear a cape or a cloak in the winter. Luckily for the team, this person is just as adept at working magic as Gandalf. Unluckily for the team, they will need to endure hours of stories from Gandalf about how he or she to walk uphill both ways in the snow to drop off the punch cards at the computer room. The Gandalf type is your heaviest hitter, but you try to leave them in the rear and call them up only in times of desperation.

2. The Martyr
In any other profession, The Martyr is simply a "workaholic." But in the development field, The Martyr goes beyond that and into another dimension. Workaholics at least go home to shower and sleep. The Martyr takes pride in sleeping at the desk amidst empty pizza boxes. The problem is, no one ever asked The Martyr to work like this. And he or she tries to guilt-trip the rest of the team with phrases like, "Yeah, go home and enjoy dinner. I’ll finish up the next three week’s worth of code tonight."

3. Fanboy
Watch out for Fanboy. If he or she corners you, you're in for a three-hour lecture about the superiority of Dragonball Z compared to Gundam Wing, or why the Playstation 3 is better than the XB 360. Fanboy's workspace is filled with posters, action figures, and other knick-knacks related to some obsession, most likely imported from Japan. Not only are Fanboys obnoxious to deal with, they often put so much time into the obsession (both in and out of the office) that they have no clue when it comes to doing what they were hired to do.

4. Vince Neil
This 40-something is a throwback to 1984 in all of the wrong ways. Sporting big hair, ripped stonewashed jeans, and a bandana here or there, Vince sits in the office humming Bon Jovi and Def Leppard tunes throughout the workday. This would not be so bad if "Pour Some Sugar on Me" was not so darned infectious. Vince is generally a fun person to work with, and actually has a ton of experience, but just never grew up. But Vince becomes a hassle when he or she tries living the rock ‘n roll lifestyle to go with the hair and hi-tops. It's fairly hard to work with someone who carries a hangover to work every day.

5. The Ninja
The Ninja is your team’s MVP, and no one knows it. Like the legendary assassins, you do not know that The Ninja is even in the building or working, but you discover the evidence in the morning. You fire up the source control system and see that at 4 AM, The Ninja checked in code that addresses the problem you planned to spend all week working on, and you did not even know that The Ninja was aware of the project!
See, while you were in Yet Another Meeting, The Ninja was working. Ninjas are so stealthy, you might not even know their name, but you know that every project they're on seems to go much more smoothly. Tread carefully, though. The Ninja is a lone warrior; don’t try to force him or her to work with rank and file.

6. The Theoretician
The Theoretician knows everything there is to know about programming. He or she can spend four hours lecturing about the history of an obscure programming language or providing a proof of how the code you wrote is less than perfectly optimal and may take an extra three nanoseconds to run. The problem is, The Theoretician does not know a thing about software development. When The Theoretician writes code, it is so "elegant" that mere mortals cannot make sense of it. His or her favorite technique is recursion, and every block of code is tweaked to the max, at the expense of timelines and readability.
The Theoretician is also easily distracted. A simple task that should take an hour takes Theoreticians three months, since they decide that the existing tools are not sufficient and they must build new tools to build new libraries to build a whole new system that meets their high standards. The Theoretician can be turned into one of your best players, if you can get him or her to play within the boundaries of the project itself and stop spending time working on The Ultimate Sorting Algorithm.

7. The Code Cowboy
The Code Cowboy is a force of nature that cannot be stopped. He or she is almost always a great programmer and can do work two or three times faster than anyone else. The problem is, at least half of that speed comes by cutting corners. The Code Cowboy feels that checking code into source control takes too long, storing configuration data outside of the code itself takes too long, communicating with anyone else takes too long... you get the idea.
The Code Cowboy’s code is a spaghetti code mess, because he or she was working so quickly that the needed refactoring never happened. Chances are, seven pages' worth of core functionality looks like the "don’t do this" example of a programming textbook, but it magically works. The Code Cowboy definitely does not play well with others. And if you put two Code Cowboys on the same project, it is guaranteed to fail, as they trample on each other’s changes and shoot each other in the foot.
Put a Code Cowboy on a project where hitting the deadline is more important than doing it right, and the code will be done just before deadline every time. The Code Cowboy is really just a loud, boisterous version of The Ninja. While The Ninja executes with surgical precision, The Code Cowboy is a raging bull and will gore anything that gets in the way.

8. The Paratrooper
You know those movies where a sole commando is air-dropped deep behind enemy lines and comes out with the secret battle plans? That person in a software development shop is The Paratrooper. The Paratrooper is the last resort programmer you send in to save a dying project. Paratroopers lack the patience to work on a long-term assignment, but their best asset is an uncanny ability to learn an unfamiliar codebase and work within it. Other programmers might take weeks or months to learn enough about a project to effectively work on it; The Paratrooper takes hours or days. Paratroopers might not learn enough to work on the core of the code, but the lack of ramp-up time means that they can succeed where an entire team might fail.

9. Mediocre Man
"Good enough" is the best you will ever get from Mediocre Man. Don’t let the name fool you; there are female varieties of Mediocre Man too. And he or she always takes longer to produce worse code than anyone else on the team. "Slow and steady barely finishes the race" could describe Mediocre Man's projects. But Mediocre Man is always just "good enough" to remain employed.
When you interview this type, they can tell you a lot about the projects they've been involved with but not much about their actual involvement. Filtering out the Mediocre Man type is fairly easy: Ask for actual details of the work they've done, and they suddenly get a case of amnesia. Let them into your organization, though, and it might take years to get rid of them.

10. The Evangelist
No matter what kind of environment you have, The Evangelist insists that it can be improved by throwing away all of your tools and processes and replacing them with something else. The Evangelist is actually the opposite of The Theoretician. The Evangelist is outspoken, knows an awful lot about software development, but performs very little actual programming. The Evangelist is secretly a project manager or department manager at heart but lacks the knowledge or experience to make the jump. So until The Evangelist is able to get into a purely managerial role, everyone else needs to put up with his or her attempts to revolutionize the workplace.

courtesy @TechRepublic

We're still struggling with security, admits Microsoft

Microsoft is still experiencing pain as it struggles to bring its own security products and service up to speed.

Microsoft released Windows Live OneCare for consumers in May 2006 and its Forefront Client Security for enterprises earlier this year. Both products entered a saturated security market populated by experienced security-specialist companies such as Symantec, McAfee and Trend Micro.

When Microsoft began investing in the security field around 2003, the company didn't have "the ability to speak AV," said Vinny Gullotto, general manager of the company's Malware Protection Centre. Now, that ability is much more developed, said Gullotto, who spoke early this week on the sidelines of IT Forum in Barcelona, the company's largest customer event in Europe.

At least initially, Windows Live OneCare didn't fare well in malware detection tests, but Microsoft is improving its performance, Gullotto said.

Between September 2006 and September this year, Microsoft has improved its malware detection rate by about 20 points, Gullotto said. Now, Microsoft's detection rate is usually between 91 percent to 95 percent, depending on the testing plan, he said.

At least as recently as May, Microsoft's OneCare and Forefront products, which share the same set of malware detection signatures, only had a 76 percent detection rate, according to AV-Test, a German anti-virus testing organisation that often performs tests on commission for technology magazines.

One way to improve detection rates is to increase the number of signatures, Gullotto said. Many testing organisations test anti-virus software against a batch of malicious software samples and rank those products according to how well the samples are flagged.

But generating more signatures demands more analysts and research capacity. Microsoft is investing heavily in both of those areas, although Gullotto declined to say how much.

Microsoft used to only have one malware research lab, based in Washington . This year, Microsoft has opened new labs in Tokyo, Dublin and Melbourne to allow it to respond to customers 24 hours a day worldwide.

Last year, it took Microsoft three days to respond to a query from one of its customers regarding security, Gullotto said. Now, that response time is down to between six to eight hours, but Gullotto said they'd like it to be around a maximum of six hours.

To meet that goal, Microsoft is hiring experts for all three new labs, Gullotto said, but "I'm not satisfied with it. We want to hire more experienced people." Over the last few years, Microsoft has had success in recruiting experienced security analysts from companies such as F-Secure, Trend Micro and McAfee.

The growth in the number of malicious software samples circulating on the Internet is "just immense at this particular point in time," Gullotto said. Microsoft is also trying to build more tools that can automatically analyse malware, he said.

In another improvement, Microsoft plans to update spyware signatures in its OneCare, ForeFront and Defender products once a day rather than twice a week as is done now, Gullotto said. Spyware is the term for an unwanted program that records and transmits information about a person's PC, often without the user's consent or knowledge.

courtesy @TechWorld.com


U.S. Government Joins Microsoft Against States

The 2002 consent decree that partially governs Microsoft's actions about its monopolistic business practices was originally supposed to expire today. But Redmond is currently locked in a battle with a coalition of states that want to see federal oversight extended for another half-decade.

On Friday, Microsoft picked up an ally -- the very same government. The U.S. Department of Justice joined Microsoft in its attempt to persuade U.S. District Court Judge Colleen Kollar-Kotelly that the consent decree has done its job and should expire this month.

At issue is the antitrust settlement that followed the Court's original finding that Microsoft had unfairly stifled competition through its Windows monopoly. Among other things, the decree stipulates that Windows development is supervised by a technical committee, and ensures that rivals have an even playing field. The current deadline was moved from today until Jan. 31 of next year.

The DOJ's brief argues that the states' rationale for extending the decree are illogical and even contradict their own past claims. The group of 17 states are led, as they have been throughout, by California and New York (called "Movants" in the brief). "The California and New York Movants advance inadequate and mutually inconsistent arguments to justify extension of the Final Judgments; both state groups argue theories, moreover, that are directly contravened by the states' own past statements and actions," the document states.

The brief argues a number of points, but the main argument it asserts is that the original consent decree was properly adhered to by Microsoft. In fact, the DOJ asserts, even some of the contesting states have said as much. "As the New York Group informed the Court two months ago, the Final Judgments "have achieved [their] goals" and "are enabling the competition they are designed to protect." The California Movants do not provide any evidence that the goals of the expiring provisions of the Final Judgments have not been achieved, when those goals are properly considered in light of the Court of Appeals decision and this Court's ruling. Accordingly, there is no legal basis upon which to seek such an extension," it reads.

The states have until Friday to respond to Microsoft and the DOJ's latest briefs.

courtesy @reddevnews.com