<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CIO Agenda &#187; Paul Appleton</title>
	<atom:link href="http://blog.atos.net/uk/author/paul-appleton/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.atos.net/uk</link>
	<description>Atos CIO Agenda</description>
	<lastBuildDate>Tue, 07 May 2013 16:54:05 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Security, Pedantry and Parking Tickets</title>
		<link>http://blog.atos.net/uk/2012/05/23/security-pedantry-and-parking-tickets/</link>
		<comments>http://blog.atos.net/uk/2012/05/23/security-pedantry-and-parking-tickets/#comments</comments>
		<pubDate>Wed, 23 May 2012 05:54:01 +0000</pubDate>
		<dc:creator>Paul Appleton</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Protection Inspectors]]></category>

		<guid isPermaLink="false">http://blog.atos.net/uk/?p=402</guid>
		<description><![CDATA[<p>&#8220;There&#8217;s another name for traffic wardens. Revenue Protection Inspectors is one.&#8221; Some crevices of civilisation attract the traffic warden personality. We see them lurking in children&#8217;s sporting competitions, in business communities, in our social lives where they slip just under the anti-bullying-bar. In popular culture we know them as Jobsworths, popularised by television (That’s Life) <a  class="more-link" href="http://blog.atos.net/uk/2012/05/23/security-pedantry-and-parking-tickets/"><span class="post_goto aGoTO">read more</span></a> </p><p>The post <a href="http://blog.atos.net/uk/2012/05/23/security-pedantry-and-parking-tickets/">Security, Pedantry and Parking Tickets</a> appeared first on <a href="http://blog.atos.net/uk">CIO Agenda</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>&#8220;There&#8217;s another name for traffic wardens. Revenue Protection Inspectors is one.&#8221;</p>
<p>Some crevices of civilisation attract the traffic warden personality. We see them lurking in children&#8217;s sporting competitions, in business communities, in our social lives where they slip just under the anti-bullying-bar. In popular culture we know them as Jobsworths, popularised by television (That’s Life) and in film (Beatles’ Help).</p>
<p>One particular organisational Petri-dish for this is the Business Risk discipline. Particularly when dealing with regulated systems security.</p>
<p>The information systems security advisor, ossified into making a business decision reacts by reducing personal risk, without regard for the contingent business implications. Imagine that there is a business imperative to post a letter. The post box is on the street corner; the street corner has double yellow lines.</p>
<blockquote><p>The security advisor&#8217;s solution: &#8220;The Road Traffic Act says one can&#8217;t park on double yellow lines. You must park in the town-centre car park and catch a bus to the post box. I&#8217;m not making a decision, but I can document the risks and ask someone else to break the law&#8221;.</p></blockquote>
<p>The risk opinion goes up the tree, no one wants to challenge perfectly reasonable logic until the business unit who wants to post the letter realises the additional costs and then does their own analysis:</p>
<blockquote><p>The pragmatic business: &#8220;We could be purists, at huge cost, or we could park up and take a chance. But what I think we&#8217;ll do is drive with a colleague, park up, I&#8217;ll jump out why my colleague keeps watch and drives round the block if anyone comes.&#8221;</p></blockquote>
<p>The answer to this behaviour lies in the interstices of security and risk. The security purist says &#8220;no&#8221;, the risk manager says &#8220;no but&#8221;. Unlearning behaviour is hard, the information security trade tends to attract a certain personality type who is personally risk averse, prone to pedantry and tends to think in the language of protection, defence, doing less and stopping things happening. Turning our security teams into business teams is a start, followed by extracting security from IT and reporting into the business, or at least the business risk function.</p>
<p>Making a decision is scary, but extracting value from the risk teams means empowering and enforcing decision-making behaviour, viewing security as a tool to enable business imperatives, changing the language we use to reflect that security can help an organisation grow as well as defend. There are many examples of this: from the trivial of bringing your own iPad through to enabling secure financial transactions and using security as a selling point.</p>
<p>If we don’t do this, we risk the security trade being relegated to the organisational cul-de-sacs where their deontological minds will ensure they are perceived as an Immanuel Kant and called Traffic Warden behind their backs.</p>
<a href="http://twitter.com/share?url=http://blog.atos.net/uk/2012/05/23/security-pedantry-and-parking-tickets/&via=&text=Security, Pedantry and Parking Tickets&related=:&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><p>The post <a href="http://blog.atos.net/uk/2012/05/23/security-pedantry-and-parking-tickets/">Security, Pedantry and Parking Tickets</a> appeared first on <a href="http://blog.atos.net/uk">CIO Agenda</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.atos.net/uk/2012/05/23/security-pedantry-and-parking-tickets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password Book Of Death</title>
		<link>http://blog.atos.net/uk/2012/05/22/password-book-of-death/</link>
		<comments>http://blog.atos.net/uk/2012/05/22/password-book-of-death/#comments</comments>
		<pubDate>Tue, 22 May 2012 05:56:30 +0000</pubDate>
		<dc:creator>Paul Appleton</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[PIN]]></category>

		<guid isPermaLink="false">http://blog.atos.net/uk/?p=407</guid>
		<description><![CDATA[<p>I don&#8217;t know which demonic spirit invented passwords, but if the intent was to burden us with a hopeless cause I think that the demons are still batting and we need to retire from the game. &#160; How many passwords do you have to manage? By passwords, include your card PINs, your on-line banking details, <a  class="more-link" href="http://blog.atos.net/uk/2012/05/22/password-book-of-death/"><span class="post_goto aGoTO">read more</span></a> </p><p>The post <a href="http://blog.atos.net/uk/2012/05/22/password-book-of-death/">Password Book Of Death</a> appeared first on <a href="http://blog.atos.net/uk">CIO Agenda</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>I don&#8217;t know which demonic spirit invented passwords, but if the intent was to burden us with a hopeless cause I think that the demons are still batting and we need to retire from the game.</p>
<p>&nbsp;</p>
<p>How many passwords do you have to manage? By passwords, include your card PINs, your on-line banking details, the proliferation of &#8220;secret questions&#8221; and your mother&#8217;s maiden name(s). I have more than sixty. If I count only those that I really care about, that is those that can do me financial harm such there are at least forty. And I&#8217;m a simple soul, I have a handful of cards, bank accounts, mortgages and deal online mainly with Amazon.</p>
<p>&nbsp;</p>
<p>The curse gets bigger when I include the mandatory sign-up screens for temporary web sites and spreads again when I include my work passwords.</p>
<p>&nbsp;</p>
<p>I even need a password to open the door to my office! Four more digits (I use 1234).</p>
<p>&nbsp;</p>
<p>Why do we put up with this? How do we manage it? In part, we put up with it because we have to. If one wants an account, one needs to play by their rules. One solution is to avoid the accounts. One solution is a digital password safe. One solution is to write your passwords down.</p>
<p>&nbsp;</p>
<p>I have a password book and I have a File of Death. The File of Death is the file to go to when I die, where all my credentials are located. Given how easy it is to check in to the digital world, but how hard it is to check out (even when one checks out of the real world) it&#8217;s imperative to have a mechanism to close down FaceTwit in lieu of those organisations actually taking their user&#8217;s privacy seriously enough. Before I die, there&#8217;s my password book. The only way to effectively manage all my passwords is to write them down and to have a sensible pattern. Possibly obfuscated, certainly re-used.</p>
<p>&nbsp;</p>
<p>I like bananas. I used to like apples but about five years ago web sites started imposing password lengths and apple was just too short. Now I&#8217;m up to banana216% which seems to satisfy all the current complexity requirements.</p>
<p>&nbsp;</p>
<p>Of course, I&#8217;m not completely stupid. I don&#8217;t use banana for all my accounts, only the ones that don&#8217;t personally do me harm (like work and those peculiar themed websites we all deny using). I have &#8220;fishcake&#8221; for the really high risk systems.</p>
<p>&nbsp;</p>
<p>So, what&#8217;s the solution?</p>
<p>&nbsp;</p>
<p>Reducing the proliferation of passwords can make our online life more secure. There&#8217;s no reason why forums and other socially social sites can&#8217;t just rely on oAuth and accept FaceTwitOogle credentials: indeed some are doing this already, but not enough. I can&#8217;t say I like the idea of authenticating to my bank account through Twitter, but I&#8217;d accept it for those sites that can&#8217;t directly do me harm.</p>
<p>&nbsp;</p>
<p>Incorporating a FaceTwitOogle credential reduces complexity for the site (no access control lists to manage), it improves the user experience (simple sign on), it&#8217;s socially-webby (so it must be good in a 2.0 way) and it&#8217;s an amulet against the password proliferation. If the site absolutely must have an email address, then they can ask for it: and we can use Mailinator if we wish.</p>
<p>&nbsp;</p>
<p>But in the absence of common sense and the system owners thinking through why they want a password, what risk the password mitigates and the unintended consequences, I&#8217;ll continue to use the only useable alternative.</p>
<p>&nbsp;</p>
<p>My password book of death.</p>
<a href="http://twitter.com/share?url=http://blog.atos.net/uk/2012/05/22/password-book-of-death/&via=&text=Password Book Of Death&related=:&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><p>The post <a href="http://blog.atos.net/uk/2012/05/22/password-book-of-death/">Password Book Of Death</a> appeared first on <a href="http://blog.atos.net/uk">CIO Agenda</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.atos.net/uk/2012/05/22/password-book-of-death/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>There&#8217;s no business in snow business</title>
		<link>http://blog.atos.net/uk/2010/12/13/theres-no-business-in-snow-business-2/</link>
		<comments>http://blog.atos.net/uk/2010/12/13/theres-no-business-in-snow-business-2/#comments</comments>
		<pubDate>Mon, 13 Dec 2010 06:00:28 +0000</pubDate>
		<dc:creator>Paul Appleton</dc:creator>
				<category><![CDATA[CIO Agenda]]></category>
		<category><![CDATA[Strategy & Innovation]]></category>
		<category><![CDATA[Working in IT]]></category>

		<guid isPermaLink="false">http://blog.atos.net/uk/?p=410</guid>
		<description><![CDATA[<p>Snow. Don’tcha just love it? A licence to slack, for sport, for making snow angels and snow men. It’s what, ahem, “working from home” is all about. You can’t trust your employees. They are basically children with money. You can’t trust ‘em if you can’t see ‘em. If you can see ‘em then they must <a  class="more-link" href="http://blog.atos.net/uk/2010/12/13/theres-no-business-in-snow-business-2/"><span class="post_goto aGoTO">read more</span></a> </p><p>The post <a href="http://blog.atos.net/uk/2010/12/13/theres-no-business-in-snow-business-2/">There&#8217;s no business in snow business</a> appeared first on <a href="http://blog.atos.net/uk">CIO Agenda</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Snow. Don’tcha just love it? A licence to slack, for sport, for making snow angels and snow men. It’s what, ahem, “working from home” is all about.</p>
<p>You can’t trust your employees. They are basically children with money. You can’t trust ‘em if you can’t see ‘em. If you can see ‘em then they must be working. Hard.</p>
<p>The recent and ongoing debacle with the white stuff shows that organisations need to take a consistent line on remote working: either provide the tin or don’t come to the party. Either trust or judge by presenteeism. If you trust then it is essential that the necessary support services are in place, but that’s more than merely the technology. Any organisation can invest in collaboration tools, laptops with video, remote meetings, agile telephony and virtual team. Indeed, any organisation that does not have these tools is rightly judged to be a laggard with skewed priorities. If you don’t trust, then make it clear: your staff’s value is the warmth they give to their chair.</p>
<p><span id="more-410"></span></p>
<p>For business continuity, these tools are essential. When the snow falls and staff stay home, the organisation can continue to function by taking advantage of new technologies. Having a clear policy that supports such measures is essential, but so too is the culture that is required to ensure that staff know their responsibilities and duties. Behind this, strong systems are needed that enable remote working which in turn requires investment and clarity on investment priorities.</p>
<p>Once an organisation untethers its staff it can release expensive buildings and start to push support costs back onto the individual, where the individual is given the freedom to choose their technology and the responsibility to manage that choice.</p>
<p>The choice is simple: we play our games as adult-adult, or we play our games as adult-child. When the snow falls, do we infantalise ourselves. And when it clears do we mature.</p>
<p>Or are staff inherently unreliable wasters who need to be corralled into submission?</p>
<a href="http://twitter.com/share?url=http://blog.atos.net/uk/2010/12/13/theres-no-business-in-snow-business-2/&via=&text=There's no business in snow business&related=:&lang=en&count=horizontal" class="twitter-share-button">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><p>The post <a href="http://blog.atos.net/uk/2010/12/13/theres-no-business-in-snow-business-2/">There&#8217;s no business in snow business</a> appeared first on <a href="http://blog.atos.net/uk">CIO Agenda</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.atos.net/uk/2010/12/13/theres-no-business-in-snow-business-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
