Wednesday, January 13, 2010

Test Drive your Architectures for effective evaluations

Are you one of those sitting in ivory towers of Enterprise Architecture Group, tasked with responsibility of evaluating project architectures and ensuring IT Governance? If you have done few reviews before, you would know that it is highly subjective process that depends largely on the evaluators’ technical skills, functional/environmental knowledge, authority structure, and other political forces. The evaluators who are parachuted into the project group for reviews are especially handicapped due to lack of knowledge of functional requirements, and often only concentrate on ‘technology’ implementation reviews. Hence, most of the reviews remain superficial and only partially beneficial.

So how exactly should you evaluate the architectures? 
I would say do what you do when you buy a car. Test Drive! You will only know the car’s performance when you actually drive it and feel it, and not just by reading specifications or by asking questions. Similarly, to evaluate the architecture, apply it to the specific functional scenarios and measure the quality attributes.
Carnegie Mellon Institute (SEI) has developed the architecture evaluation methodologies on the same principle. The most known methods are –


This methodology analyzes how well the software architecture satisfies the quality attributes (e.g. scalability, modifiability, performance etc), by applying the architecture to short-listed functional scenarios. It prescribes developing a quality attribute utility tree, and analyzing it for each scenario and alternative architecture approaches. For each scenario, the method prescribes identifying the following –
a)    Sensitivity points – a collection of components that are critical for achieving a quality attribute,
b)    Trade-off points – a sensitivity point that affects multiple quality attributes, typically trades one off for the other,
c)    Risks – something that inhibits the system from achieving its quality goal (this also includes the decisions that are not taken),
d)    Non-risks – something that is done right (and should not be changed)



CBAM begins where ATAM leaves off. It prescribes analyzing the cost, benefits and schedule implications as well for architectural approaches before making the final decisions.


This is more of a design review than architecture review, but uses the same principle of applying design to scenarios, and even writing a pseudo code to evaluate different parts of design.

The SEI has documented a very formal step by step process for all these methods. One way that may be counter productive as people tend to focus on activities, rather than the principles behind these methods. There is a great scope to tailor these methods to suit your organization, and conduct such evaluation in agile way.

More on this topic later…

Share/Bookmark

- Amit Unde

Tuesday, January 12, 2010

Clouds of Insecurity

Today, Google disclosed sophisticated attacks on its infrastructure from China and its response to it. While Google's response is a welcome move, it raises doubts in my mind about the safely of the cloud. This is not isolated instance. Recently, another public Cloud vendor, Salesforce.com, was crashed down for considerable time and raised many questions about cloud's credibility.

What makes these 'Public' clouds more insecure?
Not its infrastructure as much as its popularity ! My organization's infrastructure is not likely to be secure as Google's, however, it is not likely to be on radar of hackers either. The hackers may spend days and nights to bring google down, will they pay same attention to my organization? Probably not.
The 'Cloud' may bring-in efficiency, but it will be a trade off with the increased risk of data loss and security, at least in the near future. The benefits of cloud should be carefully weighed against the risks before committing to the cloud. Recently, Gartner published a report for Assessing the Security Risks of Cloud Computing. Click here to read seven of the specific security issues Gartner says customers should raise with vendors before selecting a cloud vendor.

Share/Bookmark

Saturday, January 9, 2010

Business Architecture – Is it IT’s intrusion into Business?

OMG’s SOA Consortium working group recently published a paper on their perspective of Business Architecture.  The paper is clearly by the IT Practitioners.  The way they define Business Architecture is as follows –
We define business architecture as the formal representation and active management of business design. Expanding this definition, business architecture is a formalized collection of practices, information and tools for business professionals to assess and implement business design and business change.
The paper advocates the active management of business design, with the same focus as that of IT.  Though it sounds good on paper, is it really practical? -  Especially when the fact is Enterprise Architecture is driven by IT. Will the social and power structure present in Today’s organization allow this?


 No doubt that we need a clear understanding and formal representation of business design, however, the comprehensiveness should be limited to suit the need, which is typically an input to IT (and not management of business).  Also, the involvement of business in driving the IT solution is critical, however, the involvement should be periodic, although frequent, and every attempt should be made to keep the overhead on business  as minimum as possible.  Attempting active management of business may be considered as unnecessary intrusion of IT into business and often, it is counter-productive. Instead, a process for periodic review of business models and refresh should be institutionalized.  The EA-IT team should, however, do the active management of IT portfolio and ensure alignment of IT investments with business goals through active governance structure.

Having said this, the paper does provide some useful information and examples of artifacts. It will be good if OMG standardizes the business architecture models and encourage tool vendors to support it. The Enterprise Business Motivation Model (EBMM) will be a great start.


Share/Bookmark

Monday, January 4, 2010

A fresh look at 2010

One of my colleagues (David Roy), sent me a list of questions related to my previous post, that can guide 2009 Review and 2010 Goal settings. He got these questions from the Newsletter by David Allen (Author of Getting Things Done).

Completing and remembering 2009


Review the list of all completed projects

What was your biggest triumph in 2009?

What was the smartest decision you made in 2009?

What one word best sums up and describes your 2009 experience?

What was the greatest lesson you learned in 2009?

What was the most loving service you performed in 2009?

What is your biggest piece of unfinished business in 2009?

What are you most happy about completing in 2009?

Who were the three people that had the greatest impact on your life in 2009?

What was the biggest risk you took in 2009?

What was the biggest surprise in 2009?

What important relationship improved the most in 2009?

What compliment would you liked to have received in 2009?

What compliment would you liked to have given in 2009?

What else do you need to do or say to be complete with 2009?

Creating the new year

What would you like to be your biggest triumph in 2010?

What advice would you like to give yourself in 2010?

What is the major effort you are planning to improve your financial results in 2010?

What would you be most happy about completing in 2010?

What major indulgence are you willing to experience in 2010?

What would you most like to change about yourself in 2010?

What are you looking forward to learning in 2010?

What do you think your biggest risk will be in 2010?

What about your work, are you most committed to changing and improving in 2010?

What is one as yet undeveloped talent you are willing to explore in 2010?

What brings you the most joy and how are you going to do or have more of that in 2010?

Who or what, other than yourself, are you most committed to loving and serving in 2010?

What one word would you like to have as your theme in 2010?

For more on this subject, visit David Allen's web site - http://www.davidco.com/

Share/Bookmark

Wednesday, December 30, 2009

Wish you a Very Happy New You for this New Year!

What will you do on New Year eve? – Fire Yourself !
If you are wondering what I mean, read Ron Ashkenas’ blog at HBR.
Ron highlights how GM Management team could not break out of their routine and do anything different, even when they were witnessing imminent demise.  Somebody else had to fire them, because they could not do it to themselves.

It is similar to UnThink principle I highlighted in my last blog entry. It is so important to stop and think about what you are doing, what you are NOT doing and what you should do. You may rediscover yourself - professionally and personally.
Easier said than done!  I have read about this stuff many time before, but never really acted on it until recently, when I was all alone on a business trip. I found myself thinking about my career and my family, and I started analyzing behind a napkin paper. I spent more than 2 hours – just thinking. I believe, I know myself better now and I am quite sure what I want to do in my life.
I guess the act of recognizing this need of self-analysis is important. Rest your sub-conscious will take care of.

Wish you a Very Happy New You for this New Year!

- Amit Unde


Share/Bookmark

Tuesday, December 22, 2009

What Insurers need to ‘UnThink’


KFC created quite a buzz with the launch of its "Unthink" campaign. By 'unthinking' their fried fast food, KFC is aligning to the choices of new generation, which is far more health conscious and even cost conscious (at least in these days). Keeping aside the recent marketing blunder (with free chicken and Oprah), I liked their ‘UnThink’ principal.

Should not every business do this? We are so used to our usual ways of doing business that we never really 'Unthink'. Although, we constantly strive to achieve efficiencies, and excellence in what we are doing, we actually never stop and question - is this a right thing to do?

Here are my thoughts on what (most of the) Insurers can 'Unthink' -

1) Online presence –
Most insurers do business through independent agents. The bulk of the business comes from agents, so the insurers tend to ignore the direct channel completely. Is this sustainable strategy? The value of Agent’s counseling can not be denied, however, there is a growing population who prefer to research, learn, connect and buy online. Their online world is now not just limited to computers and internet, it has expanded to mobile phones, and 3GS as well. You need online presence and strong channel partnerships not just for providing direct access for sale and servicing, but also for connecting consumers to your agents.

2) Risk Management –
The one thing the recession has taught us is importance of Risk Management. This year really distinguished the insurance companies who do risk management well from those who do not. Are your risk management techniques, actuarial models and financial tools modern enough to manage the risks effectively?

3) Innovation Strategy –
Do you ask for the Business case for every program or project? Well, UnThink. You might be just killing the innovation in your company.

3.95) Customer intelligence –
How much do you know about your customers? Do you know why they are with you and why will they stay with you? Do you know what you can cross-sell to them or to somebody in their household?
Your legacy systems and acquired systems might be holding you back by not providing a single view of customers and enough intelligence about them. It’s time to UnThink and challenge the status quo.

What’s with 3.95? Well, I like this number :)

- Amit Unde

Share/Bookmark

Friday, December 18, 2009

Cloud computing or not – Should you really care?


I was reading a debate between Private and Public cloud computing installations on David Tweedy’s article on Business Insurance . It seems that every vendor is now replacing ‘ASP’ by ‘Cloud’ and jumping on the bandwagon. ( Not that it is completely wrong in every case.) Another interesting aspect is that the public cloud computing infrastructure such as Amazon, SalesForce is enabling relatively smaller vendors to provide a reliable, specialized and cheaper services to their customers.
It is all good, but I have a problem with the marketing hype and jargons surrounding all these offerings. The words like Cloud, SaaS, ASP confuses the hell out of you without realizing the exact benefits of the offered service. Really, should the business care if the hosted service is a perfect ‘Cloud computing’ or not?

I would say - yes, however, rather than going by the word, they should look deep for the meaning of the word. So, what makes a perfect Cloud computing environment for hosted applications? and what does it mean in business terms?

Here are some thoughts -
1) Hosting Model - When you choose a Cloud based application, you should not be worried about Technology infrastructure beneath the application, in fact, and you have no control over it. All you should worry about is the Service levels. This is same as the most of the traditional hosted ASP models.
2) Scalable, reliable Infrastructure - The application should be highly reliable, available 24 X 7 and should perform at the optimum level. In other words, the infrastructure supporting the application should be equipped to support your growing business needs and also those of all your fellow businesses, using the same hosted application.
You should ask your vendors questions to clarify how they are planning to scale their infrastructure, especially when they add more and more customers. A virtualized environment is typically deployed to dynamically scale the infrastructure.
3) Customizability (or in terms of jargon ‘Multi-tenancy) - It should be quicker and inexpensive to implement the customization that you need and it should not degrade the performance. In other words, the application should be built in such a way that the customization is considered in the basic architecture. For example, every time you ask for new variable, the vendor should not add a new table or column in their database. Such a design becomes unwieldy as you add more customizations or vendor adds new customers. A new paradigm of architecture called ‘Multi-tenant’ architecture is often used in Cloud computing environment to address these issues.
4) Security - Your business data should be secure from errors, hackers and disasters. Ask vendors about the database and data structure – whether the data is logically and physically separated, user access control, transportation security, storage security ( encryption mechanism) etc.

So, unless your vendor provides minimum of above 4 points, don’t let them claim their application as ‘Cloud’ based application. In my experience, many vendors do not satisfy 2, 3 and 4. If they are offering hosted service, they tend to call it ‘Cloud’ based service.

- Amit Unde

Share/Bookmark