Enterprise Information Security

On June 2, 2010, in Activities, by PPj
Upon the success of Information Security for Business 2010 training at Bangkok and on the eve of second training on Information Security for Business on August 2010 at Bangkok, Thailand and third training on  October 2010 at Dhaka, Bangladesh,  I would like to share my findings on Enterprise Information Security.
`
With ever increasing concerns on privacy and information security, the essence of enterprise level information security is also being felt by many organizations, locally and globally.  Integration of information security measures and practices along with business processes must result into seamless security integration and be affordable.
Security concerns have become umbrella concept for various business processes including procurement, human resource mobilization, outsourcing/insourcing, managed services, information value chain, and  business partner integration along with core business processes.
`
The primary concerns for CXOs before incorporating information security measures into an enterprise are on investment planning, return on investment, resistance to change (motivation), and business continuity. Our research also found that the implementation of information security measures in an enterprise lacked proper initial planning, security balancing, standard configuration, and training. Many enterprises also face business threats due to contemporary business models that makes extensive use of information for strategies such as; business intelligence outsourcing, cloud computing, and managed IT services.
`
Sambad Technologies (and Shristi Technologies as consultant on Information Security) organized Information Security for Business training on May 12-14, 2010 at Eastin Hotel, Bangkok, Thailand.  The training addressed latest enterprise information security risks and contemporary approaches to reduce the risk level.  The event also provided a common platform for executives, managers, and professionals from various enterprises for human networking, experience sharing, and prospective business expansion.
`
View the event profile through photos in Facebook.
Have a look at profile of the organizer, Sambad Technologies Pvt. Ltd.
Shristi Technologies is consultant of Sambad Technologies for education and consultancy services on Information Security.
`
To address increasing demand on training on Information Security for Business, we have scheduled second international training on Information Security for Business to be held on August 2010 at Bangkok, Thailand and on July, 2010 at Dhaka, Bangladesh.  Visit Sambad Technologies website for more details.
`
Quick links;

Windows Core Workshop 2010

On May 20, 2010, in Activities, by PPj
The ecosystem of learning-and-teaching is eventually transforming towards learning-and-sharing.  Participation of right stakeholders in learning-and-sharing is very essential for knowledge discovery and sharing.
The ecosystem
While learning and sharing about technology, the learners need to be aware about the driving factors that lead to the invention of technology.  Dreams, philosophy, tales, societal trends etc. make up needs and conceptual applications in people’s mind.  Science theorizes these abstract concepts into more formal structures.  Engineering builds logical as well as physical realization of the theories and suggests optimal design for different usage scenario.  And finally, technology defines daily use of the solutions built to make better quality of human life.
Operating system ecosystem
While talking about Operating System (OS), the ecosystem through which OSs emerge need also be understood well.  Dreams, expectations, and user experiences are the primary driving forces for better and convenient computer architectures.  OSs exploit the functionalities provided by computer architecture so that developers can build applications with better user experiences.
Theories vs. experiences
When learners and practitioners try to understand the OS ecosystem, most of them face the problem of synchronizing their theories with experiences with OS design.
Current issues
Operating system designers need to exploit the underlying features provided by computer architecture for greater user (end user as well as developers) experiences.  While the fundamental debate on the role of OS as resource manager vs. abstract layers still persists, advancements in technology has raised issues such as;
  • optimal utilization of multi-cores
  • parallel processing
  • synchronization of user threads and kernel threads
  • security in virtualization
  • energy efficiency consideration
in the design of operating systems.
Pre-requisites
Learners of operating systems need to have a good knowledge of computer architecture, access to good set of tools, and contemporary learning contents.  Good set of tools help foster learning activities, enable hands on practices and simulations, and comply with latest contents.
The educators, as an experience sharer, need to project the importance of computer architecture features into OS design, elaborate on importance of user experiences out of all features provided at different levels of abstraction, and design a good curriculum.
Microsoft’s offering
Considering the difficulties faced by academia in conducting Operating System course in under-graduate and graduate studies, Microsoft offers a good set of learning resources that enables learners to explore features of most popular operating system kernel.
Windows Curriculum Resource Kit is a collection of instructional materials that follows the ACM/IEEE-CS Operating System Body of Knowledge and illustrates operating system (OS) concepts using Windows XP as  a case study.
Windows Research Kernel packages core Windows XP/Server 2003 SP1 kernel sources with build and test environment.
ProjectOZ provides an experimental environment on top of native NT API providing alternative UNIX simulator.
Windows Core Workshop 2010
The Windows Core Workshop, Beijing, 2010 was centered on use of WRK in academics.  WRK is a core kernel with no GUI, no drivers, and enables learners to play with kernel behaviors in user space, I/O stack, I/O filtering etc.  The technical sessions covered by Dave Probert, the kernel architect at Microsoft, were fabulous.  Faculties from various countries also shared their experiences of using WRK into OS curriculum.
To use the WRK, two systems with Windows XP 64 / Server 2003 are required.  The systems can be real machine or virtual machine.  One machine is used for development where as another machine for debugging.
The bundles
Microsoft Research provides resource kits for faculties and students.  The Windows Core materials are same in both kits.  Faculty resource kit contains additional supplement materials for faculties.
Here are some useful links if you are willing to use WRK for better learning experience of Operating Systems.
The event
Windows Core Wrokshop 2010
April 15-16, 2010
Four Points by Sheraton, Haidian, Beijing, China
Hasso Plattner Institute (HPI), University of Potsdam, Germany
Configuring WRK virtual machines in Mac OS :-)
Installing WRK in virtual machine manually
Pohang University of Science and Technology (POSTECH) Korea
An example oriented API documentation system
Photos in Facebook
Tagged with:  

Innovation and Intellectual Properties

On March 24, 2010, in Activities, by PPj

World economy emerged from commodity exchange and had come to experience economy.  There has been lots of innovation in product design and service delivery, and now the market demands authenticity in experience.  After its invention, extensive use of information technology in business processes has resulted into requirement of more specialized attention to different fields of IT.  The convergence of technologies enabled work to flow from place to place and a new culture of doing business, namely out-sourcing, emerged.  The original idea behind outsourcing was to harness productivity from the regions where labor cost is low, and to compress the time of project completion as the work was dispatched to a different time-zone.

Companies taking out-sourced development and service delivery tasks performed very well for couple of years.  But as the living standards of human resources went up by time, employees in the out-sourcing companies started demanding more benefits.  Companies from developed world found it less charming to out-source their business processes to developing world where labor cost was considered to be cheaper before.

Dependency on service based economy only turns out very fast.  The physical products also turn out after some time.  However, intellectual properties can be enhanced regularly so that their usability can be maximized throughout time.  Nepalese IT industries has been focusing a lot in IT enabled services for quick return but less attention has been given to develop intellectual properties like software, systems, pattents etc.

Nepalese software industries need to understand which particular track of economy they would like to follow; IT enabled services or intellectual properties?  IT enabled services are really important but heavily relying on services only can be disastrous.  Rather the software industries need to developed their own core intellectual properties and then only provide services required to enhance the quality and usability of their products in future.

Information Security for Business

On December 26, 2009, in Activities, by PPj
In the context where the global communication infrastructure, information, and services are under the threat of Information Security breach, Nepalese organizations are also not far apart.
Followings are the synopsis that are the motivation factors for serious concern over Information Security in Nepalese market.
Barack Obama’s concern in cyber security highlights importance of Information Security in current world.
http://www.nytimes.com/2009/12/22/technology/internet/22cyber.html?_r=1&ref=technology
BBC News broadcasts that online fraud went up by 185%
http://www.bbc.co.uk/london/content/articles/2008/10/04/bexley_phishing_feature.shtml
Iranian Cyber army diverting requests to Twitter to malicious website
http://news.bbc.co.uk/2/hi/technology/8420233.stm
Students bypassing school Internet security
http://news.bbc.co.uk/newsbeat/hi/technology/newsid_10000000/newsid_10003500/10003579.stm
A single man in US stole 138m credit card numbers from super-market chains like WalMart and Seven-Eleven
http://news.bbc.co.uk/2/hi/business/8206305.stm
Lower configuration of web-platform went slow after Jackson’s death
http://news.bbc.co.uk/2/hi/technology/8120324.stm
People, being the key factor for any organizational structure, are the most responsible entities for maintaining Information Security.  Therefore, the investment in motivation, top-level management comittment, and business process re-engineering is required that fosters seamless integration of Information Security solutions with business processes maintaining the productivity and better confidence.
The investment in motivation, top-level management comittment, policies development, implementation framework, procedures, and code of practices play important role.  Tools cover the last 1% of the solution for information security threats.  The training was highly successful in delivering this message to all the participants.
The problems we’ve seen in Nepal includes;
- the role of NDA plays very insignificant role in case of Information Security breach as most of the security breach occur due to human instincts,
- preparedness for disaster recovery plan and policies are completely missing,
- general acceptable use policy missing even in large organizations,
- people are very keen in personal information security (spyware, keyloggers, SSL enabled protocols) but unaware about the behavior of technology that would aggregate into an Information Security catastrophe,
- business model threats such as; SaaS security models, sub-system vendor lock-in etc. are not analyzed, and
- as a whole, an Information Security implementation framework, policies, procedures, code of conduct, awareness of social engineering etc. are missing.
The training on Information Security for Business organized by Sambad Technologies (consultant: Shristi Technologies, business partner: Datum Systems) was highly successful to deliver the current Information Security scenario to the participants and the measures that can be taken to protect businesses from Information Security threats.
Photos here @ Facebook.
Media coverages;
-
-
-
-
In the context where the global communication infrastructure, information, and services are under the threat of Information Security breach, Nepalese organizations are also not far apart. Followings are the synopsis that are the motivation factors for serious concern over Information Security in Nepalese market.
People, being the key factor for any organizational structure, are the most responsible entities for maintaining Information Security.  Therefore, the investment in motivation, top-level management comittment, and business process re-engineering is required that fosters seamless integration of Information Security solutions with business processes maintaining the productivity and better confidence.
The investment in motivation, top-level management comittment, policies development, implementation framework, procedures, and code of practices play important role.  Tools cover the last 1% of the solution for information security threats.  The training was highly successful in delivering this message to all the participants.
The problems we’ve seen in Nepal includes;
  • the role of NDA plays very insignificant role in case of Information Security breach as most of the security breach occur due to human instincts,
  • preparedness for disaster recovery plan and policies are completely missing,
  • general acceptable use policy missing even in large organizations,
  • people are very keen in personal information security (spyware, keyloggers, SSL enabled protocols) but unaware about the behavior of technology that would aggregate into an Information Security catastrophe,
  • business model threats such as; SaaS security models, sub-system vendor lock-in etc. are not analyzed, and
  • as a whole, an Information Security implementation framework, policies, procedures, code of conduct, awareness of social engineering etc. are missing.
The training on Information Security for Business organized by Sambad Technologies (consultant: Shristi Technologies, business partner: Datum Systems) was highly successful to deliver the current Information Security scenario to the participants and the measures that can be taken to protect businesses from Information Security threats.

Media coverages;

Tagged with:  
(three first photos on right aligned,  + more if required)
Knowledge Management, being a set of management practices and supplemented by tools, is highly applicable in all development projects.  Sustainability of development projects does ensure the sustainable development of nation.  All the stakeholders need to be aware about the influencing factors and enhance their positive effects in the development projects.  The role of management culture, knowledge creation and collaboration, and efficient and effective tools has been well understood by the professional society.  All we need is to develop an efficient framework that supports knowledge integration from different fields of expertise and conduct sustainable projects.
My presentation covers the research on how Micro-Servers can be used at different levels of governance, automation for service delivery, and decision making and planning by government as well as public/private organizations.  A complete solution framework is developed and presented.  The queries about the product and implementation framework were very effective.  (Photos here)
Followings are the summaries of some of the influential presentations I witnessed.
Experiences of Hydro-Powers
Rather than investing money in real-state sector, why not invest in more productive project such as hydro-powers – experience of Prakash Sharan Mahat, Minister of Energy.  Tranmission highway project for electricity, (what about transportation, and information??) for increased accessibility are essential components of hydro-power projects.  Multi-purpose projects, are we ready for them yet?
Energy and climate change  (the economics behind that)
The major concern, CDM and Carbon market has enabled very un-fair business of carbon emission quota. The ambitious growth of developing country impedes the efforts of developed countries to minimize the emission of CO2.
ICIMOD shared experience of;
glaciers are becoming shorter and shorter.  Too many landslides.  Lack of GHG mitigation plans.  Livelihood and poverty problems. Imja lake.  Some success stories from Bangladesh, Nepal, and India.
AIT President shared his vision for knowledge economy regarding contextualization of knowledge assets, knowledge being not value-free or consequence-free, knowledge being essential for proper tie up of sponsors with projects, and in overall the role of knowledge creating academies in addressing knowledge requirement of the society.
Dr. Pahari from Nepal Development Research Institute presented very important concept on why spatial information management is required in current context of Nepal for effective planning of development projects.  Most of the reports generated contain summaries of attributes but lack geo-statistical information related to them.  This presentation convinced the need of some tools that can capture spatial information which served as an open platform for my solution framework!!  I thanked him for it.
One of the interesting presentation with a radical context but very effective one was on disaster preparedness by the use of Nepalese proverbs!  The implicit knowledge in traditional knowledge, stories, proverbs in Nepalese culture can be externalized and shared with communities for disaster preparedness.
Panel discussion on Knowledge Management for Mountain Development at the end emphasized on success factors for knowledge management (from ICIMOD), implications of knowledge management for conservation planning by looking into bio-diversity, mitigation of information asymmetry in food production (from Helvetas), use of legacy communication systems for information dissemination, and use of water informatory for water capacity management in regional level (from ICIMOD).

Knowledge Management, being a set of management practices and supplemented by tools, is highly applicable in all development projects.  Sustainability of development projects does ensure the sustainable development of nation.  All the stakeholders need to be aware about the influencing factors and enhance their positive effects in the development projects. The role of management culture, knowledge creation and collaboration, and

efficient and effective tools has been well understood by the professional society.  All we need is to develop an efficient framework that supports knowledge integration from different fields of expertise and conduct sustainable projects.

Visit KMSD Conference 2009 – website here.

My presentation covers the research on how Micro-Servers can be used at different levels of governance, automation for service delivery, and decision making and planning by government as well as public/private organizations.  A complete solution framework is developed and presented.  The queries about the product and implementation framework were very effective.  (Photos here)

Followings are the summaries of some of the influential presentations I witnessed.

Experiences from Hydro-Powers - Rather than investing money in real-state sector, why not invest in more productive project such as hydro-powers – experience of Prakash Sharan Mahat, Minister of Energy.  Tranmission highway project for electricity, (what about transportation, and information??) for increased accessibility are essential components of hydro-power projects.  Multi-purpose projects, are we ready for them yet?

Energy and climate change  (the economics behind that) - The major concern, CDM and Carbon market has enabled very un-fair business of carbon emission quota. The ambitious growth of developing country impedes the efforts of developed countries to minimize the emission of CO2.

ICIMOD shared experience of; glaciers are becoming shorter and shorter.  Too many landslides.  Lack of GHG mitigation plans.  Livelihood and poverty problems. Imja lake.  Some success stories from Bangladesh, Nepal, and India.

AIT President shared his vision for knowledge economy regarding contextualization of knowledge assets, knowledge being not value-free or consequence-free, knowledge being essential for proper tie up of sponsors with projects, and in overall the role of knowledge creating academies in addressing knowledge requirement of the society.

Dr. Pahari from Nepal Development Research Institute presented very important concept on why spatial information management is required in current context of Nepal for effective planning of development projects.  Most of the reports generated contain summaries of attributes but lack geo-statistical information related to them.  This presentation convinced the need of some tools that can capture spatial information which served as an open platform for my solution framework!!  I thanked him for it.

One of the interesting presentation with a radical context but very effective one was on disaster preparedness by the use of Nepalese proverbs!  The implicit knowledge in traditional knowledge, stories, proverbs in Nepalese culture can be externalized and shared with communities for disaster preparedness.

Panel discussion on Knowledge Management for Mountain Development at the end emphasized on success factors for knowledge management (from ICIMOD), implications of knowledge management for conservation planning by looking into bio-diversity, mitigation of information asymmetry in food production (from Helvetas), use of legacy communication systems for information dissemination, and use of water informatory for water capacity management in regional level (from ICIMOD).

The businesses are becoming aware of information security threats in Nepal.  However due to lack of implementation framework, proper management of enterprise level security, human firewall and motivation, the readiness for Information Security in businesses can’t be assured.  A concrete framework which is ‘applicable’ in Nepalese business scenario is essential.
Information Security for Business trainings conducted in Butwal and Pokhara reflected the need of such framework and cost effective solutions.  Shristi Technologies and Sambad Technologies are jointly conducting the training to supplement the need.  The next training is going to be conducted on December 19-20 will harness all the experiences and knowledge collected from previous 7 such trainings.

The businesses are becoming aware of information security threats in Nepal.  However due to lack of implementation framework, proper management of enterprise level security, and human firewall and motivation, the readiness for Information Security in businesses can’t be assured.  A concrete framework which is ‘applicable’ in Nepalese business scenario is essential.

Information Security for Business trainings conducted in Butwal (photos here) and Pokhara (photos here) reflected the need of such framework and cost effective solutions.  Shristi TechnologiesSambad Technologies, and Datum Systems are jointly conducting the training to supplement the need.  The next training is going to be conducted on December 19-20 at Kathmandu will harness all the experiences and knowledge collected from previous 7 such trainings.

Tagged with:  

First IEEE AH-ICI Conference

On November 5, 2009, in Activities, by PPj

It is great to have IEEE AH-ICI Conference on Internet organized in Nepal.  The blend of emerging technologies and their applications when shared in mass creates a huge impact in Nepalese society.  Papers presented in 21 different tracks are very fascinating and informative.

Use of ‘unicore’ for e-Science platform, 8051 implementation of elliptical curve encryption, host information protocol, mutual authentication in 3G networks, security concerns in WiMAX were very interesting presentations during the conference.

Glimpse of the conference are here.

Tagged with:  

Latest technologies

On November 4, 2009, in Presentations, by PPj

Technology is derived from science and engineering subsequently.  Use of scientific findings and engineering designs for better quality of human life and work culture is called technology.  Traditionally, four pillars of technology are defined such as; data, hardware, software, and communication technologies.  These four pillars are driven by human factor.  To get best out of technology, it must be integrated with business processes, work culture, and daily life activities which results into a form of integrated-services.  The blend of technology and management culture enables good productivity and effectiveness and hence good quality of human life.

Click here to download a short presentation.

Feel free to write your comments.

Tagged with:  

Expedition

On September 24, 2009, in Activities, by PPj

Insights are reflections of ambiance.  There need not be any reasons for traveling, emotions and feelings we have.  Aren’t in search of any treasure nor any goal.  The experiences that we collect add values to life.  Wherever I go, I know the emotions will never stop flowing, nothing gonna be certain, but I always become certain that I want it more and more.

Photos of 6-day Mustang Trek:  Day-1, Day-2, Day-3, Day-4, Day-5, and Day-6.

We need to promote internal tourism as well.  Many Nepalese visit Mustang for regilious tour.  Hospitality and quality of service will definitely add values for the internal tourists and hence promotion for internal tourism.

Nikon D90 performed great during the expedition.  The RAW pictures taken when VR enabled were stunning.  Still need to explore more functions in it.  Some of the selected shots are here.

Experience the joy of trekking through these videos.

Tagged with:  

ICT for Human Resource Management

On September 17, 2009, in Activities, by PPj

Discussion going onMany of Nepalese organizations, including Nepal Government, are not able to manage human resouces properly and hence aren’t able to harness productivity from the resource pool.

Throughout many ages of human civilization, the society’s main concern has been to boost productivity in terms of efficiency and effectiveness.  Information and Communication Technology not only enhances productivity but also quality of human life.

At operational level of HRM, personnel records, benefits, schedules, compensation, training, and skills need to be recorded in an inventory.  At tactical level, the organizations can control relocation cost, contract cost, evaluate performance, appraise, and manage work-flow.  Whereas in strategic level long term personnel planning, rewarding, employee development and career planning, knowledge management, rentention strategies, and succession planning can be done with efficiency and effectiveness by the use of ICT.