Creation of a strategy for the consumption and management of Cloud Services in the TOGAF Preliminary Phase

In a previous article I described the need to define a strategy as an additional step in the TOGAF 9 Preliminary Phase. This article describes in more details what could be the content of such a document, what are the governance activities related to the Consumption and Management of Cloud Services.

image

Before deciding to switch over to Cloud Computing, companies should first fully understand the concepts and implications of an internal IT investment or buying this as a service. There are different approaches which may have to be considered from an enterprise level when Cloud computing is considered: Public Cloud vs Private Clouds vs Hybrid Clouds. Despite the fact that many people already know what the differences are, below some summary of the various models

· A public Cloud is one in which the consumer of Cloud services and the provider of cloud services exist in separate enterprises. The ownership of the assets used to deliver cloud services remains with the provider

· A private Cloud is one in which both the consumer of Cloud services and the provider of those services exist within the same enterprise. The ownership of the Cloud assets resides within the same enterprise providing and consuming cloud services. It is really a description of a highly virtualized, on-premise data center that is behaving as if it were that of a public cloud provider

· A hybrid Cloud combines multiple elements of public and private cloud, including any combination of providers and consumers

image

Once the major Business stakeholders understand the concepts, some initial decisions may have to be documented and included in that document. The same may also apply to the various Cloud Computing categorisations such as diagrammed below:

image

The categories the enterprise may be interested in related to existing problems can already be included as a section in that document.

Quality Management

There is need of a system for evaluating performance, whether in the delivery of Cloud services or the quality of products provided to consumers, or customers. This may include:

· A test planning and a test asset management from Business requirements to defects

· A Project governance and release decisions based on some standards such as Prince 2/PMI and ITIL

· A Data quality control (all data uploaded to a Cloud computing service provider must ensure it fits the requirements of the provider). This should be detailed and provided by the provider

· Detailed and documented Business Processes as defined in ISO 9001:

o Systematically defining the activities necessary to obtain a desired result

o Establishing clear responsibility and accountability for managing key activities

o Analyzing and measuring of the capability of key activities

o Identifying the interfaces of key activities within and between the functions of the organization

o Focusing on the factors such as resources, methods, and materials that will improve key activities of the organization

o Evaluating risks, consequences and impacts of activities on customers, suppliers and other interested parties

Security Management

This would address and document specific topics such as:

· Eliminating the need to constantly reconfigure static security infrastructure for a dynamic computing environment

· Define how services are able to securely connect and reliably communicate with internal IT services and other public services

· Penetration security checks

· How a Security Management/System Management/Network Management teams monitor that security and the availability

Semantic Management

The amount of unstructured electronic information in enterprise environments is growing rapidly. Business people have to collaboratively realise the reconciliation of their heterogeneous metadata and consequently the application of the derived business semantic patterns to establish alignment between the underlying data structures. The way this will be handled may also be included.

IT Service Management (ITIL)

IT Service Management or IT Operations teams will have to address many new challenges due to the Cloud. This will need to be addressed for some specific processes such as:

· Incident Management

o The Cloud provider must ensure that all outages or exceptions to normal operations are resolved as quickly as possible while capturing all of the details for the actions that were taken and are communicated to the customer.

· Change Management

o Strict change management practices must be adhered to and all changes implemented during approved maintenance windows must be tracked, monitored, and validated.

· Configuration Management (Service Asset and…)

o Companies who have a CMDB must provide this to the Cloud providers with detailed descriptions of the relationships between configuration items (CI)

o CI relationships empowers change and incident managers need to determine that a modification to one service may impact several other related services and the components of those services

o This provides more visibility into the Cloud environment, allowing consumers and providers to make more informed decisions not only when preparing for a change but also when diagnosing incidents and problems

· Problem Management

o The Cloud provider needs to identify the root cause analysis in case or problems

image

· Service Level Management

o Service Level Agreements (or Underpinning contracts) must be transparent and accessible to the end users. The business representatives should be negotiating these agreements. They will need to effectively negotiate commercial, technical, and legal terms. It will be important to establish these concrete, measurable Service Level Agreements (SLAs) without these and an effective means for verifying compliance, the damage from poor service levels will only be exacerbated

· Vendors Management

o Relationship between a vendor and their customers changes

o Contractual arrangements

· Capacity Management and Availability Management

o Reporting on performance

Other activities must be documented such as:

Monitoring

· Monitoring will be a very important activity and should be described in the Strategy document. The assets and infrastructure that make up the Cloud service is not within the enterprise. They are owned by the Cloud providers, which will most likely have a focus on maximizing their revenue, not necessarily optimizing the performance and availability of the enterprise’s services. Establishing sound monitoring practices for the cloud services from the outset will bring significant benefits in the long term. Outsourcing delivery of service does not necessarily imply that we can outsource the monitoring of that service. Besides, today very few cloud providers are offering any form of service level monitoring to their customers. Quite often, they are providing the Cloud service but not proving that they are providing that service.

· The resource usage and consumption must be monitored and managed in order to support strategic decision making

· Whenever possible, the Cloud providers should furnish the relevant tools for management and reporting and take away the onerous tasks of patch management, version upgrades, high availability, disaster recovery and the like. This obviously will impact IT Service Continuity for the enterprise.

· Service Measurement, Service Reporting and Service Improvement processes must be considered.

Consumption and costs

· Service usage (when and how) to determine the intrinsic value that the service is providing to the Business, and IT can also use this information to compute the Return On Investment for their Cloud computing initiatives and related services. This would be related to the process IT Financial Management.

image

Risk Management

The TOGAF 9 risk management method should be considered to address the various risks associated such as:

· Ownership, Cost, Scope, Provider relationship, Complexity, Contractual, Client acceptance, etc

· Other risks should also be considered such as : Usability, Security (obviously…) and Interoperability

Asset Management and License Management

When various cloud approaches are considered (services on-premise via the Cloud), hardware and software license management to be defined to ensure companies can meet their governance and contractual requirements

Transactions

Ensuring the safety of confidential data is a mission critical aspect of the business. Cloud computing gives them concerns over the lack of control that they will have over company data, and does not enable them to monitor the processes used to organize the information.

Being able to manage the transactions in the Cloud is vital and Business transaction safety should be considered (recording, tracking, alerts, electronic signatures, etc…).

There may be other aspects which should be integrated in this Strategy document that may vary according to the level of maturity of the enterprise or existing best practices in use.

When considering Cloud computing, the Preliminary phase will include in the definition of the Architecture Governance Framework most of the touch points with other processes as described above. At completion, touch-points and impacts should be clearly understood and agreed by all relevant stakeholders.

Observations on Capability Driven Management

I’m finalizing my presentation for Business Ecology Initiative’s Optimization for Innovation conference slated for March 22nd in Washington DC.  Initially, I was approaching it as a humorous rejoinder on how to cope with taking the reigns of an or…

Stories That Move Mountains

In mid-2010 I held a series of training courses to cover many of the key techniques I’ve previously discussed on this blog. One attendee, Nick Malik, was in for his second time, the first being three years earlier. Another, Mark West, had been working with me as a contractor on a project. After the sessions Nick and I talked for a while and he suggested that I should write a book about the way I put the techniques together.

I’ve known various people over the years that have written books and it seemed like a lot of hard work, which with a day job I was not sure I wanted to take on. Move forward a month, Nick and Mark are now co-authors and we sat down to a few weekends of planning.

By October we had a plan, a chapter structure, even a name. By February we are well behind in the writing. Don’t let anyone tell you that writing a book is easy.

We have moved a long way though and I can certainly see we will be able to pull it all together. To help with the final miles of this marathon we have developed a web site where we can make a lot of the content available and also get feedback.

http://storiesthatmovemountains.com

All of the relevant blog posts from this site have been moved over and a lot more will now start to appear. This blog will now just focus on Enterprise Architect and IT topics.

Enterprise Architecture’s Obsession with Efficiency

Jeff Scott recently wrote a great blog "Is the current EA paradigm right for business architecture?"

http://blogs.forrester.com/jeff_scott/11-01-25-is_the_current_ea_paradigm_right_for_business_architecture

The comments section was full of erudite responses from several of the leading thinkers in EA. I’d like to pick up on two of the comments:

Tom Graves

"Most people seem to be obsessed by

Enterprise Architecture is Misplaced and Other News from MIT Research

Several interesting points that deserve their own blog posts, so this is just a conversation starter:- EA should not be inside of IT, and it’s usual placement hampers both IT and its effectiveness. – EA maturity is directly related to organizational pe…

Business Capability Naming and Content

Bruce Silver, BPMN luminary, has recently posted a piece on BPMN and Business Architecture where, he says, “In the past year the ‘architects’ seem to have discovered BPMN.”  WIth his usual meticulous style he dissects the difference between a process and other notions such as capabilities and functions, terms that architects like to throw around in their paperwork.

He clearly distinguishes process as the “how,” which is what we, at SenseAgility, have been saying as well. Process diagrams, and BPMN diagrams in particular, are the proof behind a particular type of capability, namely the Business Capability. In our work we’ve found that there are specific types of acceptable proofs behind different types of capabilities.

Here’s a statement Bruce makes about typing or perhaps it is even about granularity by implication, “If you’re sorting things into boxes, it doesn’t matter so much if some boxes hold square pegs and others round holes. But when you want to assemble those boxes into a coherent unit, it would be easier if the pegs and holes all had the same shape.” To us this principle is exactly the same one we employ when naming capabilities. As mentioned above, capabilities are different types. You can tell they are different types by looking at the proof behind the capability. That is, what makes the capability a capability in the first place? Business Capabilities have processes behind them, maybe more than one, but at least one.

So what I’m saying here is that if you want to give a name to a capability you need to have something in mind besides appropriate wording. Just getting people to agree on words doesn’t cut it. Why? Because ultimately you need to be talking about something of value. If capabilities can’t be linked to something of value then you might be imagining capabilities in a vacuum.

Anyway, subscribe to Bruce’s excellent blog when you get a chance.

Sample Set: Enterprise Architect Interview Questions

I’m interviewing an enterprise architecture candidate today. His CV suggests that he is an enterprise IT solution architect so I am going to probe a bit and see if he understands architecture of the enterprise. Here’s some questions I have jotted down as a framework for my own thinking. I’m sharing it in case it is useful to anyone else out the in the #entarch community.

What does "enterprise

Operational Capability Risk: Executive Rotation

As announced last year, I will  be presenting at the OMG Business Ecology Initiative’s inaugural “Optimization for Innovation” Conference on 3/22/11 on how an executive can quickly and efficiently analyze operations of a business unit. &nbsp…

Business Architecture and Business Ecology

This is a response to a very thought-provoking discussion that’s been going on at the Business Ecology Initiative LinkedIn Group on the topic of whether Business Architecture is synonymous with Business Ecology.  I suppose the answer depends on wh…

Architectural Control as a Managerial Paradox

In recent years, IS academia has argued that EA is increasingly becoming a strategic management tool or a high-level business function for long term planning and execution. It has been a healthy evolution for EA to question its IT heritage and adopt a broader perspective of how commercial enterprises navigate and gravitate in their respective marketplaces. This healthy evolution has particularly been articulated by Turner, Gotze, and Bernus (2010) in their paper Architecting the Firm: Coherency and Consistency in Managing the Enterprise, which argues the key role of architecture in executive management. Architected organisations are said to achieve better, more consistent results since the strategy is aligned and architected against operations, processes, and the technology portfolio.

As I have previously argued in my writings on strategic management, the assumed reality of strategic long term planning has to a large extent ignored the socio-political side of human and organisational behaviour. Planning is volatile and subject to rapid change in turbulent environments. As Rittel & Webber (1973) argue in their 1973 article on government policy and planning, assuming that any problem can be solved by rational planning will ultimately lead to confusion and failure. In their view, assumed rationality leads to unexpected ambiguity. Here, it is crucial to ask the question: if EA really is such a strategic discipline driven by the need for informed decision making, how can the first and always at-the-top-of-the-framework-pyramid component called strategy rely on such a naïve view of how human planning works in practice? This discussion is by no means new; already in the late 90ies, Mintzberg (2002) argued the need for an organic, emergent view of strategy by elaborating on Simon’s (1997) concept of bounded, contextual rationality. 


Let us for a short moment forget about strategy as an applied, deliberate package of human reason and rather think of strategy as inherently equivocal. Management concepts, as they often arrive straight out of the business scholar’s first year text book on business strategy, are, in fact, paradoxical and ambiguous despite the strive for precision and forecasting. This is explained in the following:
  1. The first paradox concerns the relationship between assumption of control vs. human and environmental ambiguity. The more one attempts to control and superimpose predictability onto reality, the more imprecise and irregular reality, in fact, becomes. This classic paradox of the manager as an assumed homo oeconomicus is discussed in depth by Kallinikos (2004).
  2. The second paradox is three-sided: the short, very generic nature of corporate vision and mission statements vs. the corporate search for control and manageability vs. the complexity of the business ecology surrounding the enterprise. The first facet is short and simple, where the second facet strives for precision, detail, and consistency, both which in turn neglect the ecological complexity and institutional pressure (the third facet) of the organisation’s environment.
  3. The third, most noticeable paradox is the fact that the implicit equivoque of high-level mission/vision statements fosters organisational resilience. The more loosely or ill-defined the strategy, the better will the official policy document fit into the actions and immediate strategies (what Weick (2001) denotes just in time strategies) deployed by employees to fulfil or achieve certain goals and expectations (Astley & Zammuto, 1992). The more ambiguous the official strategy or policy articulation, the more free hands for the individual employee to appropriately navigate the socio-political problems of the business environment. Despite the intended precision of a strategy document, the more possible interpretations of a strategic policy or plan, the more organisational resilience and responsiveness (Weick, 2001).

However, it is too simplistic to assume that corporate ambiguity per se triggers organisational resilience and flexibility. In that case, any old plan would do.The paradoxical nature of precision and ambiguity is better understood as a second order systems theoretical concept (Luhmann, 1995 & Luhmann, 2000), in which any system, be it social or biological/ecological, applies certain reductionisms in order to reduce the outside complexity the environment. In Luhmann’s theory of symbolically generalised media within social systems, phenomena such as scientific truth, politics, sex, and power are applied by different institutional systems in order to reduce the complexity and ambiguity of modern society. Similarly, organisations as social systems deliberately deploy equivocal mission statements and simplistic strategies in order to interpret and cope with a hyper-complex, fast-paced business environment. Despite the claim of predictability, strategic long term plans are thus put in place in order to reduce societal complexity and constraints to static architectural maps and prescriptive policies. The reduced conception of reality is by no means successful or comprehensive enough to account for all important details simultaneously, but it makes reality manageable until the actions taken and plans made are reasonable enough (see  reasonableness as a criterion for strategic success in (Weick, 2001)). 
As Teubner (2000) writes, strategic planning fosters productive misunderstandings: business strategies have to be misunderstood (compared to what was originally intended by e.g. senior management) and reinterpreted in the particular reality and bounded rationality of the individual. The final, synthesised (mis-)understanding of strategy, mission, and vision serves to build and sustain resilience and organisational responsiveness—but only with reference to the organisation itself. As Luhmann’s sociology tells us, the end result would never achieve the same results in the outside reality. This also explains why replicating or adopting existing patterns of strategy will most likely lead to a bad result without adopting, contextualising, and productively misunderstanding the presumed strategic rationality. Good strategies are misunderstood, self-referential and contextual whilst fostering resilience and adaptability.

It is my conception that EA must adopt such view of strategic thinking as a self-referential, ambiguity-producing human practice in order to successfully navigate the needs and requirements of tomorrow’ adaptive and flexible virtual enterprises.

References

Astley, W. G. & Zammuto, R. F. (1992), `Organization Science, Managers, and Language Games’, Organization Science 3(4), 443{460.
Kallinikos, J. (2004), `Deconstructing Information Packages: Organizational and Behavioural Implications of ERP Systems’, Information Technology & People 17(1), 8-30.
Luhmann, N. (1995), Social Systems, Writing Science, Stanford University Press, Stanford, California.

Luhmann, N. (2000), The Reality of the Mass Media, Stanford University Press, Stanford, California.

Mintzberg, H., Ahlstrand, B., & Lampel, J. (2002). Strategy safari (2nd ed.). LT Prentice Hall. 
Rittel, H. & Webber, M. (1973), `Dilemmas in a General Theory of Planning’, Policy Sciences 4.

Simon, H. A. (1997), Models of Bounded Rationality, Massachusetts Institute of Technology, MA.
Teubner, G. (2000), `Contracting worlds: Invoking discourse rights in private governance regimes’, Social and Legal Studies 9, 399-417.,

Turner, P., Gøtze, J., Bernus, P. (2010) Architecting the Firm: Coherency and Consistency in Managing the Enterprise. In Bernus et al (2010) Enterprise Architecture, Integration and Interoperability: IFIP TC 5 International Conference, EAI2N 2010, Held as Part of WCC 2010, Brisbane, Australia, September 20-23, 2010, Proceedings. 

Weick, K. E. (2001), Making Sense of the Organization, Blackwell Publishing.

What’s Next: The Gamification of Everything

Gamification is set to become a important trend, impacting many areas of business and society.  Gamification can be described as the application of game mechanics to non-game environments.  The gamification of social networking and location based services as exemplified by Foursquare, Gowalla and SCVNGR are probably the most recognizable with badges, mayorships and rewards offered […]

The post What’s Next: The Gamification of Everything appeared first on Brian Burke.