On mySimon: Toothbrush Sanitizer
BNET Business Network:
BNET
TechRepublic
ZDNet

April 27th, 2006

Using SOX to devalue computing

Posted by Paul Murphy @ 3:17 am

Categories: Enterprise Policy, General

Tags:

It’s long been possible to use a Sun box in place of a mainframe: running traditional CICS style jobs faster and at a much lower cost. Sun, in fact, has a whole bunch of people dedicated to selling this kind of thing.

But there’s a problem: the data processing certainties that lead people to buy and use the mainframe are antithetical to the user centric nature of Unix. This doesn’t mean you can’t use Solaris to do data processing; you can, but it’s a bad idea. More precisely, if you change your core toolset from a data processing focus to a computing focus, changing the box is the trivial part of the process - and changing the box without changing your thinking gets you a snake directing a mongoose: it may work for a while but sooner or later one will destroy the other.

Unfortunately, however, this is what I’m seeing SOX compliance auditors do: forcing data processing controls and thinking on computing environments and, in that process, destroying the same corporate value they’re supposed to be protecting.

In a pure Unix scenario, for example, you do not have a service level agreement because the users are fundamentally in charge, and they’d be imposing a constraining agreement between themselves and themselves not to hurt themselves. As I usually put it, the SLA is a peace treaty between Data Processing and users in a long running war over resources - and in the Unix world that war hasn’t happened: meaning that the peace treaty introduces conflicts that weren’t there before.

The SOX legislation doesn’t actually mandate any of this stuff: the problem is that the only adequate controls the auditors understand are the controls that evolved in data processing. Thus the the CoBit Standard has worldwide acceptance in data processing and there’s nothing remotely like it for computing.

As a result I’m seeing clients who know perfectly well how to run trustworthy computing environments being presured to do stupid and counterproductive things. Many, for example, are being told to restrict key systems employees capable of contributing value in a half dozen functional areas to only one of those areas -leaving them bored and idle most of the time while forcing IT to hire people with lower skills and less commitment to do the other jobs.

It’s absurd, it’s counter-productive, and it’s getting out of hand.

Paul MurphyPaul Murphy (a pseudonym) is an IT consultant specializing in Unix and related technologies. See his full profile and disclosure of his industry affiliations.


Email Paul Murphy

Subscribe to Managing L'unix via Email alerts or RSS.

  • Talkback
  • Most Recent of 12 Talkback(s)
Answer to SOX
I'm not a SOX expert but it is my understanding that you can opt out of SOX. YES, there will be a backlash from Wall Street but in the end it comes down to: Are you viable? Are you producing dividen... (Read the rest)
Posted by: stuck_in Posted on: 05/01/06 You are currently: a Guest | | Terms of Use
Not just IT that's suffering  Chris Rijk | 04/27/06
Not in my experience  dukeinlondon | 04/27/06
Sure, lots of people do Unix wrong  murph_zZDNet Moderator | 04/27/06
That's why I'm no longer a sys admin  Roger Ramjet | 04/27/06
Not to mention the cost of SOX compliance audit  CMKRNL | 04/27/06
I cannot help but wonder  jorwell | 04/27/06
It's there - check the page refered to  murph_zZDNet Moderator | 04/27/06
"User centric" is far more expensive and complex  jorwell | 04/28/06
Yes, but  murph_zZDNet Moderator | 04/28/06
User Centric vs Business Centric  Erik Engbrecht | 04/28/06
sometimes that's true, but there's a better way  murph_zZDNet Moderator | 04/29/06
Answer to SOX  stuck_in | 05/01/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here