Monday, August 17, 2015

Cloud Computing Maturity




Due to its exponential growth in recent years, cloud computing is still considered an emerging technology. As Cloud computing cannot yet be considered a mature and stable technology / platform. Cloud computing comes with both the benefits and the drawbacks of innovation. To better understand the complexity of cloud computing,
Let’s discuss this on this four pillars
1.      Cloud use and satisfaction level,
2.      Expected growth,
3.      Cloud-adoption drivers,
4.      Limitations to cloud adoption.
Various studies determined that the increased rate of cloud adoption is the result of perceived market maturity and the number of available services to implement, integrate and manage cloud services. Cloud adoption is no longer thought of as just an IT decision; it’s a business decision. Cloud has become a critical part of a company’s landscape and a cost effective way to create more agile IT resources and support the growth of a company’s core business.
Cloud Computing Maturity Stage
Cloud computing is still in a growing phase. This growth stage is characterized by the significant adoption, rapid growth and innovation of products offered and used, clear definitions of cloud computing, the integration of cloud into core business activities, a clear ROI and examples of successful usage. With roles and responsibilities still somewhat unclear, especially in the areas of data ownership and security and compliance requirements, cloud computing has yet to reach its market growth peak.
Cloud Adoption and Growth
How does cloud computing continue to mature? Security and privacy continue to be the main inhibitors of cloud adoption because of insufficient transparency into cloud-provider security. Cloud providers do not supply cloud users with information about the security that is implemented to protect cloud-user assets. Cloud users need to trust the operations and understand any risk. Providing transparency into the system of internal controls gives users this much needed trust.
Companies are experimenting with cloud computing and trying to determine how cloud fits into their business strategy. For some, it is clear that cloud can provide new process models that can transform the business and add to their competitive advantage. By adopting cloud-based applications to support the business, Software as a Service (SaaS) adoption is enabling organizations to channel resources into the development of their core competencies.
Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) adoptions enable businesses to experiment with new technologies and new services that require resources that would be expensive if they were completed through in-house implementation. IaaS and PaaS also allow companies to adapt to the rapid changes in market demand, because they create a completely new, faster and cheaper offering.
User Satisfaction
According to respondents, the level of satisfaction with cloud services is on the rise. Cloud services are now commonly being used to meet business as usual (BAU) and strategic goals, with the expectation that they will be more important for BAU than strategic plans in the future.
It’s not perfect yet, but the level of satisfaction with cloud services and deployment models is expected to increase as the market matures and vendors define standards to minimize the complexity around cloud adoption and management. The increase of cloud service brokers and integrator is helping businesses to integrate applications, data and shared storage in a more efficient way, making ongoing maintenance much easier.
Moving Past the Challenges
Study found that the most significant cloud concerns involve security and international data privacy requirements, data custodianship, legal and contractual issues, provider control over information, and regulatory compliance. Both cloud providers and cloud users have a role is moving past cloud concerns. Cloud providers need to demonstrate their capabilities to deliver services in a secure and reliable manner. Companies must understand their own accountability for security and compliance and their responsibility for implementing the necessary controls to protect their assets.
Gaining Maturity
The decision to invest in cloud products and services needs to be a strategic decision. Top management and business leaders need to be involved throughout a cloud product’s life cycle. Any cloud-specific risk should be treated as a business risk, requiring management to understand cloud benefits and challenges to be able to address cloud-specific risk. The need remains for better explanations of the benefits that cloud can bring to an organization and how cloud computing can fit into the overall core strategy of a business.
Effective access Control
As the threat landscape has evolved to include adversaries with deep pockets, immense resources and plenty of time to compromise their intended target, security professionals have been struggling to stave off data breaches. This is not a matter of if your network will be compromised, but when.
Since many companies have built up their perimeter defenses to massive levels, attackers have doubled down on social engineering. Phishing and malware-laden spam are designed to fool company employees into divulging login information or compromising their machine.  Since threat actors have become so good at circumventing traditional defenses, we cannot afford to have only a single point of failure. Without proper internal security, attackers are given free reign of the network as soon as they gain access to it.

Instead, attackers should encounter significant obstacles between the point of compromise and the sensitive data they are after. One way to accomplish this is with network segmentation.
Keep your hands to yourself : In an open network without segmentation, everyone can touch everything. There is nothing separating Sales from Legal, or Marketing from Engineering. Even third-party vendors may get in on the action.
The problem with this scenario is that it leaves the data door wide open for anyone with access credentials. In a few hours, a malicious insider could survey the network, collect everything of value and make off with the goods before security personnel get wind of anything out of the ordinary.
What makes this problem even more frustrating is that there is no reason everyone on the network should be able to touch every resource. Engineers don’t need financial records to perform their job, and accountants don’t need proprietary product specifications to do theirs.
By simply cordoning off user groups and only allowing access to necessary resources, you can drastically reduce the potential damage an attacker could inflict on the organization. Instead of nabbing the crown jewels, the thief will have to settle for something from the souvenir shop. Additionally, the more time the attacker spends trying to navigate and survey your network, the more time you have to find them and throw them out, preventing even the slightest loss of data in the process.
How it works: It is best to think of a segmented network as a collection of zones. Groups of users and groups of resources are defined and categorized, and users are only able to “see” the zones appropriate to their role. In practice, this is usually accomplished by crafting access policies and using switches, virtual local area networks (VLANs) and access control lists to enforce them.
While this is all well and good, segmentation can quickly become a headache in large corporate environments. Network expansion, users numbering in the thousands and the introduction of the cloud can disrupt existing segmentation policies and make it difficult to maintain efficacy. Each point of enforcement could contain hundreds of individual policies. As the network grows in users and assets, segmentation policies can quickly become outdated and ineffective.
Retaining segmentation integrity is an important security function in today’s world of advanced threats and high-profile data breaches. To properly protect themselves, organizations need to constantly maintain segmentation, adding new policies and adjusting existing ones as network needs change.
One way to tackle the challenges of traditional access control is with software-defined segmentation, which abstracts policies away from IP addresses and instead bases them on user identity or role. This allows for much more effective and manageable segmentation that can easily adapt to changes in the network topology.
Active segmentation for effective access control: When you couple software-defined segmentation with an intelligent planning and implementation methodology, you get active segmentation. This approach to segmentation allows network operators to effectively cordon off critical network assets and limit access appropriately with minimal disruption to normal business functions.
When implemented correctly, active segmentation is a cyclical process of:
1.      Identifying and classifying all network assets based on role or function
2.      Understanding user behavior and interactions on the network
3.      Logically designing access policies
4.      Enforcing those policies
5.      Continuously evaluating policy effectiveness
6.      Adjusting policies where necessary

Thursday, June 11, 2015

Designing Server Virtualization

Designing your server virtualization infrastructure requires a lot of planning before it's built, as well as plans for if something ever happens. Virtualization helps eliminate hardware issues inside a data center and allows virtual machines to be easily moved. In terms of speed, virtualization can create space in a matter of moments.
It's important to take into consideration the amount of resources you'll need, especially in terms of capacity and power consumption. Just because your environment seems secure doesn't mean it's bulletproof to a disaster. Disasters can come in multiple forms and are nearly impossible to avoid. However, having a disaster recovery plan in place is key in designing a server virtualization infrastructure.
Finally, private cloud always seems to creep into plans. There's a difference between private cloud and regular virtualization, and it's important to distinguish the disparities in order to make a logical decision.
 
Resource provisioning and capacity planning :Provisioning resources and planning capacity seems like it is a simple task, but it's certainly one that can't be overlooked. Virtual machines that end up without the necessary resources will suffer performance issues. On the other hand, overprovisioning resources to a VM could be a waste. It's important to have a proper capacity plan in place to ensure your resources will be ready to handle any and all workloads and keep your environment running smoothly.
Building a successful virtual server farm: When it comes to designing a virtual server farm, there is no "one size fits all." Although that's the case, it doesn't mean that there aren't any simple guidelines to follow to create a reliable environment. Understanding your applications and knowing the quantity of hosts you're looking for are two small ways of building a scalable server virtualization infrastructure.
 
Sizing hosts for a virtual server farm :Your job isn't done once you determine how many servers you'll need for your environment. Next up, you have to figure out the size of each server, including how much memory and CPU resources each host should contain
 
The problem with overprovisioning VMs : This is a very important aspect lets discuss this in detail.  It might seem like more is better when figuring out resources for a virtual machine, but too many resources can cause hardware issues. Overprovisioning VMs can prevent slow performance, but it could have a negative long-term affect.  Appropriately sizing virtual machines can be a difficult process with many unknowns. Allocating too few resources can starve a VM and lead to poor performance. Administrators wary of this potential problem may take the safer approach and allocate more resources than a VM needs. However, this overprovisioning wastes resources that other VMs could use.
 
Capacity planning tools can help organizations identify consolidation opportunities, allowing them to scale back overprovisioned VMs and save money.
 
Overprovisioning is a huge and very pervasive problem, and I think it's because it is one of the only ways people have to manage risk in their IT environment. If you have an unknown -- you don't know what your application is going to do or you don't know exactly what you'll need -- overprovisioning is the traditional way to go about it. In virtual and cloud environments, it just keeps on propagating. In virtual environments if you have a performance problem, you can just throw more hardware at it and that's the default way around rather than digging deeper. In clouds, people buy cloud instances because they don't know what they need. Sometimes it's the most prudent way to go for someone, but we're getting to the point that this isn't something we should tolerate. There are ways to fix it that don't cost a whole lot of money. In the past, maybe it was necessary but now it's not.

We like to use an analogy to a game of Tetris. Workloads come in different shapes and sizes and when you add them together, it starts to jumble up to the point where servers look like they're full. But, when you play Tetris more cleverly and move those blocks around, you can defrag capacity and get a lot more out of it. Sometimes people are doing all the right things with the tools they have at their disposal, but they can't fight this because they don't have anything that can help them play Tetris better. I wouldn't characterize 

Overprovisioning as people doing anything wrong, it's just that they don't have the analytics at their disposal to fix it. So, we see a lot of people buying more hardware before they really need to. If you analyze things more carefully you can go farther with what you have and not increase risk, just by sorting things out so they don't collide.
 
 If I'm running a critical production environment, I might want two servers totally empty for failover purposes. I might want a bunch of capacity sitting idle for disaster recovery purposes. I might not want my servers going about half capacity for safety reasons. The way you approach that is to define your operational parameters, including safety margins and dependencies, and that defines when capacity is full -- not whether CPU use is at 100%. It really comes down to properly capturing operational policies, which means defining what spare capacity you want to have. Then, everything beyond that is a waste.
 
If you have a line of business that is running applications on central IT infrastructure and they aren't paying with some type of chargeback model, they might be hard pressed to give up some of those resources because they're not paying for them. If IT is footing the bill, they care about the density. If you're a cloud or chargeback customer, you care about what you're paying. So, it's a discussion that would go differently depending on who's footing the bill.
 
We see organizations where IT is footing the bill and still getting lines of business to tighten things up a bit. The way they do that is to address new deployments. If I'm IT, when you ask for new capacity, I'm not going to give it to you if you're wasting the capacity you have. Of course, it's not always quite that simple, but that's the type of leverage IT has.
 
Optimizing performance and power : Contrary to overprovisioning, proper resource utilization can optimize performance. Not only will you get strong performance from provisioning the right amount of resources, you could maximize efficiency and savings as well.
Reclaim swap file space, reduce storage costs : Although swap files can enable features such as memory overcommit, companies are finding out that large swap files are wasting expensive storage space. Solid-state drives are mostly measured in gigabytes instead of terabytes, which makes it critical to use that space efficiently.





Monday, May 25, 2015

Cloud deployment IaaS

Let me put my experience & views on design and implementation of a system used for automatically deploying distributed applications on infrastructure clouds. I am big fan of open systems so the efforts driven in that direction. The system interfaces with several different cloud resource providers to provision virtual machines, coordinates the configuration and initiation of services to support distributed applications, and monitors applications over time.

Infrastructure as a Service (IaaS) clouds are becoming an important platform for distributed applications. These clouds allow users to provision computational, storage and networking resources from commercial and academic resource providers. Unlike other distributed resource sharing solutions, such as grids, users of infrastructure clouds are given full control of the entire software environment in which their applications run. The benefits of this approach include support
for legacy applications and the ability to customize the environment to suit the application. The drawbacks include increased complexity and additional effort required to setup and deploy the application.
Current infrastructure clouds provide interfaces for allocating individual virtual machines (VMs) with a desired configuration of CPU, memory, disk space, etc. However, these interfaces typically do not provide any features to help users deploy and configure their application once resources have been provisioned. In order to make use of infrastructure clouds, developers need software tools that can be used to configure dynamic execution environments in the cloud.
The execution environments required by distributed scientific applications, such as workflows and parallel programs, typically require a distributed storage system for sharing data between application tasks running on different nodes, and a resource manager for scheduling tasks onto nodes. Fortunately, many such services have been developed for use in traditional HPC environments, such as clusters and grids. The challenge is how to deploy these services in the cloud given the dynamic nature of cloud environments. Unlike clouds, clusters and grids are static environments. A system
administrator can setup the required services on a cluster and, with some maintenance, the cluster will be ready to run applications at any time. Clouds, on the other hand, are highly dynamic. Virtual machines provisioned from the cloud may be used to run applications for only a few hours at a time. In order to make efficient use of such an environment, tools are needed to automatically install, configure, and run distributed services in a repeatable way.
Deploying such applications is not a trivial task. It is usually not sufficient to simply develop a virtual machine (VM) image that runs the appropriate services when the virtual machine starts up, and then just deploy the image on several VMs in the cloud. Often the configuration of distributed services requires information about the nodes in the deployment that is not available until after nodes are
provisioned (such as IP addresses, host names, etc.) as well as parameters specified by the user. In addition, nodes often form a complex hierarchy of interdependent services that must be configured in the correct order. Although users can manually configure such complex deployments, doing so is time consuming and error prone, especially for deployments with a large number of nodes. Instead, we advocate an approach where the user is able to specify the layout of their application declaratively, and use a service to automatically provision, configure, and monitor the application deployment. The service should allow for the dynamic configuration of the deployment, so that a variety services can be deployed based on the needs of the user. It should also be resilient to failures
that occur during the provisioning process and allow for the dynamic addition and removal of nodes.
For this blog we have considered a system called Wrangler that implements this functionality. Wrangler allows users to send a simple XML description of the desired deployment to a web service that manages the provisioning of virtual machines and the installation and configuration of software and services. It is capable of interfacing with many different resource providers in order to deploy applications  across clouds, supports plugins that enable users to define custom behaviors for their application, and allows dependencies to be specified between nodes. Complex deployments can be created by composing several plugins that set up services, install and configure application software,
download data, and monitor services, on several interdependent nodes.

We have been using Wrangler since mid 2010 to provision virtual clusters for scientific workflow applications on Amazon EC2, the Magellan cloud at NERSC, the Sierra and India clouds on the FutureGrid, and the Skynet cloud at ISI. We have used these virtual clusters to run several hundred
workflows for applications in astronomy, bioinformatics and earth science.
So far we have found that Wrangler makes deploying complex, distributed applications in the cloud easy, but we have encountered some issues in using it that we plan to address in the future. Currently, Wrangler assumes that users can respond to failures manually. In practice this has been a
problem because users often leave virtual clusters running unattended for long periods. In the future we plan to investigate solutions for automatically handling failures by re-provisioning failed nodes, and by implementing mechanisms to fail gracefully or provide degraded service when re-provisioning is not possible. We also plan to develop techniques for re-configuring deployments, and for dynamically scaling deployments in response to application demand.

This is just the initial steps writing the completed scenario in next blog. Do write to me at ravindrapande@gmail.com

Wednesday, May 13, 2015

New Modern Performance Management Software

If any of these emotions describe the process your company uses to administer performance reviews, there’s a good chance those same emotions are found in both the reviewer and the reviewee. Recent research found that 53 percent of employees say performance reviews don’t motivate them to work harder, and 63 of employees felt their reviews weren’t true indicators of their performance. So we also need to analyze that is this process helping us or damaging? This is a real-time exercise we need to perform

And employees aren’t the only ones who question the validity of these standard appraisals. Only 8 percent of companies report their performance management process drives high levels of value, while 58 percent say it is not an effective use of time.

That’s right: nearly 60 percent of organizations don’t see reviewing the performance of their employees as a worthwhile use of resources.  Employees don’t trust them. Managers don’t respect them. In other words: performance reviews are broken.

How to Fix the Performance Review Process :Most companies are guilty of treating performance management as a yearly event, despite research showing that organizations that use continual performance management processes have better business results. Companies where employees revise or review their goals at least quarterly are:
  45 percent more likely to have above-average financial performances
  64 percent more likely to be effective at holding costs at or below the levels of their competitors.

Performance management shouldn’t end once a performance appraisal is over. It should be an ongoing process that helps create developmental plans to support an employee’s goals, career interests, and potential, as well as your organization’s business and talent needs.

Modern performance management should be dynamic, agile, and transparent.

Companies must update their performance management processes before they can leverage technology to make smarter decisions about their workforces. Draping new software on top of a flawed process won’t fix the problem.

New Processes, New Technology :Employees want to learn. They want to be good at their jobs, and they want immediate feedback on how to improve. Performance management has evolved into a series of continuous events that include goal-setting and -revising, mentoring and coaching, and development planning.

Thankfully, human resources technology has evolved, too.

But not all systems are created equal. When you compare HR software, there are significant differences between systems. Many still support the traditional performance appraisal process, but more and more are disrupting the industry to bring the benefits of modern performance management into the workplace.

Let’s understand benefits:

1. Agility in Feedback and Learning  :Facilitating a culture of continuous feedback means everyone knows where they stand on a regular basis. If ongoing feedback seems like overkill, consider how the alternative affects poor Sally:

Menu’s annual review rolls around, during which she discovers her manager was disappointed by something she did several months ago. Rather than discussing the situation and coaching her on the fly, the behavior went unchecked, and was relegated to the annual performance meeting. Not only is Menu blindsided, but she was unable to make adjustments as time went by.

Annual or semiannual feedback is not frequent enough, and it provides very little in the way of transparency or actual direction. Underperformers will assume their performance is fine and not try to improve,  great performers who desire frequent feedback will become uncertain and disengaged. Additionally, employees who see reviews as inaccurate are twice as likely to seek new jobs.

Outdated modes of providing feedback hurt businesses. Performance management software provides transparency into employee performance. Since managers can see the status of goals in real time, it’s easy to address issues as they arise and eliminate those unwelcome end-of-year surprises.

2. Dynamic Goal Setting : Business moves fast, and annual goal-setting can’t keep pace with the modern world. A goal that was created in January may not be relevant six or even three months later, so individual goals must change to stay in sync with larger strategic goals. If employees hit personal targets that aren’t aligned with the overarching aspirations of the company, then at least some of the moving parts of your business are moving in separate directions.

The right software can simplify the goal-setting process and keep everyone working on the right objectives. Software allows companies to set overarching goals and then attach manager, team, and individual employee expectations to them. Cascading goals align everyone across the organization and provide greater transparency between and inside departments.

As business priorities evolve, performance management software can create a domino effect that keeps everybody on the same page.

3. Relevant Career Development :After salary, career growth is the No. 1 reason candidates accept job offers. This is good news for businesses, because employees content with stagnation aren’t ideal teammates. Top talent is hungry for career development, and companies should do everything they can to provide it. Performance meetings are a time to discuss employee growth, development, and long-term career aspirations, then make training plans that will bridge employees’ skill gaps and help them reach new levels.

Companies that provide detailed development planning and coaching to their employees have a third less voluntary turnover and generate twice the revenue per employee of their peers. Performance management software helps employees gain insight into their career opportunities. Not only can such software match career goals with corresponding e-learning material or classes, but it can also alert employees to internal hiring opportunities in other departments or offices. Employees that want to learn and improve are valuable assets, so invest in them.

Companies must look closely at how they manage and measure employee performance, as well as the technology they use to do so. Modern performance management methods and tools help identify competencies, aspirations, and skill gaps, and then create strong, effective employee performance programs.

If employees feel that they can get the tools they need to succeed from another company, then that’s exactly what they’ll do: they’ll leave, taking their knowledge and value to competitors. Don’t let old performance management methods and technology fuel the turnover fire.

Monday, September 1, 2014

Ten Coding Pillers


Coding conventions are a set of guidelines for a specific programming language that recommend programming style, practices and methods for each aspect of a piece program written in this language. These conventions usually cover file organization, indentation, comments, declarations, statements, white space, naming conventions, programming practices, programming principles, programming rules of thumb, architectural best practices, etc. These are guidelines for software structural quality. Software programmers are highly recommended to follow these guidelines to help improve the readability of their source code and make software maintenance easier. Coding conventions are only applicable to the human maintainers and peer reviewers of a software project. Conventions may be formalized in a documented set of rules that an entire team or company follows, or may be as informal as the habitual coding practices of an individual. Coding conventions are not enforced by compilers. As a result, not following some or all of the rules has no impact on the executable programs created from the source code.
 
But in the blog I would like to put 10 best  coding pillars / rules for best coding practices above any particular technology / platform .

First and the foremost rule is that your code should only implement what’s required, no more no less. Primary focus of your implementation should be to cover the requirements, and tasks like creating reusable components, additional features like offline mode support etc should be included only if additional time and resources are available. As an extension to this rule, you should also make sure that only the required libraries, frameworks and resources are included in your project, this will reduce the overall size of your app binary and will avoid confusion.

Second, your code should implement the required task in the simplest way possible. If you find something that is getting complex, take sometime to simplify it. It is always faster and cheaper to replace complex code earlier, before you waste a lot more time on it. A simple design always takes less time to finish than a complex one, so always do the simplest thing that could possibly work. Consider an example: you multiply by 100 to turn a fraction into percentage and you also multiply by 100 to turn meters into centimeters. Should you have a single function that multiplies by 100 calledconvertToPercentOrMeters(x)? NO! Not even if it would remove some duplication. You want two methods; converToPercent(aFraction), andconvertMetersToCentimeters(aLength). You want two because they tell you different things. Not just that you will multiply by 100 but also why you will multiply by 100 and what kinds of numbers are valid inputs.

Third, your code should meet the basic performance requirements interns to time and memory efficiency of the applied algorithm, so that the user experience is not compromised. Algorithms must be analyzed to determine their resource usage. For maximum efficiency we wish to minimize resource usage. However, the various resources i.e. time, space cannot be compared directly, so which of two algorithms is to be more efficient often depends on which measure of efficiency is being considered as the most important, e.g, is the requirement for high speed, or for minimum memory usage, or for some other measure?

Fourth, your code should have proper error handling, it should be able to recover from the error without blocking users and should produce comprehensive error messages. Error handling refers to the anticipation, detection and resolution of application errors. Syntax errors are easy to find and fix, with the help of compliers. Logic errors, also called bugs, occur when executed code does not produce the expected result. These are best handling with the help of debugging tools, this can be an ongoing process that involves, in addition to the traditional debugging routine, beta testing prior to official release and customer feedback after official release.

Fifth, your code and design should avoid repetition at all levels possible, this include right from declaring variable with similar purpose, writing comments, writing functions, declaring classes to designing high level modules. In software engineering we have a principle, don’t repeat yourself (DRY), its aimed at reducing repetition of information of all kinds. It states as “Every piece of knowledge must have a single, unambiguous, authoritative representation within a system. When the DRY principle is applied successfully, a modification of any single element of a system does not require a change in other logically unrelated elements. Violation of DRY are typically referred to as WET solutions, which is commonly taken to stand for either “write everything twice” or “we enjoy typing”.

Sixth, your code should have comments which are accurate, clear, concise and only at the required places. To know where to add comments in code is always a subjective matter, one way to get around with this is by adding comments on all the places in code where you would have given an explanation while explaining your code to some other developer, probably a developer with lesser experience and expertise. Always remember that code tells you how, comment tell you why.

Seventh, your code should adhere to coding standards. Coding standards specify a common format for the source code and comments. This allows developers to share code, and the ideas expressed within the code and comments, between each other. If also specifies how comments (internal documentation) should be handled. More importantly, a well designed standard will also detail how certain code should be written, not just how it looks on screen.

Eighth, your code should have symbolic constants for hard-coded values. Its not always possible to completely eliminate hard-coded values from the code, but you can always replace them with more meaningful symbolic constants this will make your code more readable. A benefit of symbolic constants over variables is they are evaluated by the PRE-processor, i.e. they are re-written as literal values, not as variables. Thus run-time access to symbolic constants is significantly faster than access to variables.

Ninth, your code should use data structures and algorithms available in the language or its libraries. As software industry is getting matured, languages and libraries in all areas are getting equipped with rich set of data structures and algorithms. If you dig deep enough, you’ll find the required data structures and algorithms for the task in your native language or its libraries. Few advantages of using native data structures and algorithms are, the lesser code you write the lesser code you have to test and maintain, language and its libraries are throughly tested and stable, results in avoiding third party libraries thus reducing the overall resources in the app and they are commonly share and understood by the developers hence easy to communicate.

 Tenth, last but not the least your code should be thoroughly tested. The importance of testing and its impact on software cannot be underestimated. Software testing is a fundamental component of software quality assurance and represents a review of specification, design and coding. Testing can provide objective, independent information about the quality of software and risk of its failure to developers.

A software is a large complex system which is built as a combination of intermediate stable forms of small simple units, we can define these units in as smaller form as functions or as larger as software modules. Hence these points must be applied from the smallest units of a software like functions to the larger units like software modules, because the only way to maintain an overall quality of your software is by maintaining it right from it’s smallest unit to the software as a whole.

Hopefully the information shared in this blog was useful, and perhaps you have been inspired to implement these in your code more rigorously. Please share your views and feedback in the comments – we would like to hear from you.

Monday, August 11, 2014

Working from Home challanges


Many people want to work from home. Very few know how to actually make it work or do it religiously. Working from home isn’t glorified playtime. It isn’t a chance to goof off. For the successful, it’s an opportunity to do what you love and reap the benefits of being at home. 

Unfortunately, there are a lot of misconceptions floating around social media and the web in general. In fact, when you see a flashing banner advertisement with the phrase “work from home,” your natural inclination is to avoid it like the plague. I don’t blame you. 

1. “Only big company employee can work from home.” About a decade ago, this may have been true. In fact, I used to know a guy who worked for IBM, and sure enough he was one of the privileged few at the time who worked from home. Obviously, the tech landscape has changed drastically in the last five years, causing an explosion in the work-from-home movement. 

2. “You can’t make real money.” When I tell people that I work from home, I often detect skepticism in their reactions. With the development of Elance.com and oDesk.com, the future of freelancing has never been brighter. Jobs from design and marketing to accounting and strategy are all online waiting. In fact, since oDesk’s founding in 2005, freelancers have earned over $1 billion online. Sounds like “real money” to me.

3. “It’s a scam.” Sure, there are a lot of work-from-home scams out there. In fact, before I stumbled onto oDesk, I had heard the same spammy radio ads that you’ve heard. Luckily, I never fell for any of them and instead spent my time building my oDesk reputation. Dozens of happy clients later, I’m busier than ever and proud to say that I never spent a dime on any gimmicks.

4. “I would never be able to stay focused on work.” Most commonly, people wonder how I can resist the call from -- well, anything that seems more enjoyable than work. The incomplete honey-do list.  The dripping faucet.  The fridge. Staying focused on work is all about boundaries. In all honesty, is your current cubicle all that effective at keeping your attention?

5. “My kids would never leave me alone.” Your home office should ideally be separated by a physical boundary. If having a room set apart isn’t feasible, consider partitioning off a section of your room with a wall divider.

Beyond that, it is important to set clear expectations with your family. During work hours, you’re “at work” -- even though you’re technically still at home. Get buy-in from your spouse and ask for his or her help to keep these boundaries.

6. “Clients won’t take me seriously if I work from home.” As long as you provide value, clients don’t care where you work. Most of my clients use freelancers from every corner of the globe. Once they hire a freelancer, location and office configuration is seldom ever discussed. The only exception to the rule is if the freelancer’s Internet or cellular connection is undesirable, which can create friction for the client.

7. “I’d feel weird working in sweatpants.” That’s your problem. Personally, I can’t relate. You may want to talk to a psychologist about why you have such a deep attachment to wearing slacks.

8. “Need to think of benefits for both sides.” Working from home can be convenient to employees and help companies save money, but it’s not the right fit for every worker. Distractions are plentiful when you are home, and often it’s only the most disciplined who can remain productive and efficient.

“Working from home should be considered dangerous and could be a disaster when you consider the potential impact on your quality of life,” warns Grant Cardone, author of If You're Not First, You're Last. “The level of discipline it takes to work from home and generate solid results is intense and most people fail at home because of this one fact.”

If your idea of working from home involves wearing pajamas and juggling personal and work responsibilities at the same time, it’s time to reshape your priorities. Follow these five tips to effectively manage work and life as a remote worker.

9. “Need to office feel even working at home” Just because you don’t have to go into an office and sit behind a desk everyday doesn’t mean you can stay in bed or in front of the TV with your laptop trying to complete your work.

Career experts recommend setting up a specific office area in the home so you can “go to work” and not be distracted by dirty dishes, a crying child or a favorite TV show.

“Where your workspace is makes a big difference,” says Sara Sutton Fell, CEO of FlexJobs and a at-home worker for nearly 10 years. “When my second son was born, I realized it was really important for me to get more separation, so I moved my office to a space above our detached garage rather than in the house.”

10 “Set Clear Boundaries” Having a dedicated work space is half the battle, but you also need to set rules about who and what can enter your office.

“Create very strict boundaries where there are no dogs, kids or spouses allowed,” says Cardone. “The door needs to remain shut with only those that have top clearance allowed access.”

The work space should also be void of distractions. For instance, forgo putting a TV in your office or checking Facebook five times a day.

12” Keep Regular Work Hours and Prepare” Maintaining normal office hours can help maintain productivity.

 “Your family and friends need to pretend you simply aren't there, unless it's a dire emergency,”. “Remind your family of these hours and let them know you expect them to respect your work time so that you won’t have to work when you should be spending with them.”  In addition to setting the hours, career experts say it’s a good idea not to work all day in your pajamas. Keep your normal preparation routine, take a shower and get dressed, even if your commute is just down the hall.  

Thursday, July 10, 2014

Organizational Data Breach an Analysis



Businesses store vast amounts of information. A security breach occurs when an intruder, employee or outsider gets past an organization's security measures and policies to access the data. This sort of security breach could compromise the data and harm people. There are various state laws that require companies to notify people who could be affected by security breaches.

A data breach is the intentional or unintentional release of secure information to an untrusted environment. Other terms for this phenomenon include unintentional information disclosure, data leak and also data spill. Incidents range from concerted attack by black hats with the backing of organized crime or national governments to careless disposal of used computer equipment or data storage media.

Just to mention I would like to mention on the notion of a trusted environment is somewhat fluid. The departure of a trusted staff member with access to sensitive information can become a data breach if the staff member retains access to the data subsequent to termination of the trust relationship. In distributed systems, this can also occur with a breakdown in a web of trust.

Uncovering a security breach depends primarily on the method of discovery, as some methods inherently take longer than others. This also depends on the maturity of a security program implemented in an organization that directly reflects the ability of an organization to detect and respond to threats. It is important to remember that speed is not the only critical factor in incident response as execution of a well-conceived plan is equally critical while detecting and responding to breaches. Acting fast just for the sake of speed increases the risk of making mistakes, resulting in higher costs or needlessly extending the time necessary for full incident mitigation. Unfortunately, third parties discover data breaches much more frequently than victim organizations themselves.

Physical Security Breach
One form of breach is a physical security breach, wherein the intruder steals physical data, such as files or equipment that contains the data. Intruders could steal computers, particularly laptops, for this purpose. Businesses should monitor access to their property to cut down on such incidents and require employees to lock away their laptops when not in use.


Electronic Security Breach : Another form of breach is an electronic security breach, wherein the intruder gets into a business' systems to access sensitive data. The intruder gains such access by taking advantage of any weaknesses in the systems, such as inadequate firewall protection. This could also happen if the organization does not have adequate password protection for sensitive data. This sort of security breach is one reason businesses should perform constant security updates.
Data Capture Security Breach : Data capture, or skimming, is a practice whereby the intruder captures and records the data on a magnetic card stripe, such as on a credit card. This form of security breach helps the intruder produce copies of credit and debit cards. The intruder could either be an employee of a merchant who handles the customer's card, or it could be an external intruder. An external intruder could attach a device to card readers or ATM machines to skim information.
Business Response : Businesses should be wary of security breaches. Best practices for businesses to follow include having a policy in place to deal with any incidents of security breaches. They should identify what information has been compromised and decide who are the appropriate regulatory authorities to which they should report. Affected customers should also be notified.


Security and data breaches don’t favor one organization or industry over another and are taking place every day. Companies should consider the “how” of a breach as opposed to the “who” to evaluate their exposure to a similar event.

Retail operations remain a target to hackers due to the volume of information in their systems, including credit card information, confidential information for loyalty programs, and employee data. The victims of these attacks are an organization’s most valued assets: their employees and customers.

Until recently, many thought data risk was trivial compared to other threats such as theft, slip and falls, and workplace violence. But with data compromise occurring at much greater frequency, it’s one risk you don’t want to underestimate. Reputational harm stemming from a poorly managed data breach can be catastrophic.

Five myths you can’t afford to believe
1. Data theft is not a problem for me — my company is too small. Data privacy is a concern for organizations of any size. Rogue employees, data thieves, and unscrupulous business associates are looking for opportunities to take advantage of any weakness or mistake. Additionally, human error by negligent or careless staff account for a surprising number of data breaches around the country.
2. We can afford to self-insure the risk. As the economy continues to recover, companies are still closely watching discretionary spending, including certain lines of insurance coverage.
Many organizations wrongly believe that if something happens to their data, they can afford to cover the costs. According to a recent Ponemon Institute study, the average cost for a small breach of 1,000 records could easily exceed $200,000 — a sum that many companies cannot easily absorb.
Remember, the majority of funds to respond to a breach need to be liquid. Breach vendors typically look for payment before or at the time service is rendered, and payment for postage is required when the letter is mailed, not 30 days later.
3. Coverage is expensive and hard to get. This perception was true five years ago but is not true today. Competition, claims experience and a larger pool of buyers have made network security and privacy liability coverage more cost-effective and easier to obtain.
Even with the recent proliferation of retail breaches, the market remains relatively stable. Some carriers, however, are more cautious when reviewing risks with a large volume of credit card data.
4. Our general liability policy will cover us. General-liability insurance covers bodily injury and property damage as well as advertising injury and personal injury. The courts have consistently stated that data are not property because they are intangible. The perils associated with advertising injury and personal injury are very specific.
While a properly worded lawsuit could trigger coverage, the main expenses from a data-privacy event are the breach response- and notification-related costs. There is little chance of these costs being covered under a general-liability policy.
5. We have vendors who handle our sensitive information and credit card transactions; if they have a breach, it’s their problem not ours. This is not generally true. The data owner — the person or entity collecting the data — is ultimately responsible for what happens to that data.
Thus, a breach at a trusted business vendor could still lead to your obligation to provide notification and a decision whether to offer credit monitoring. Your contracts may require indemnification by your vendor, but if the breach is large enough, indemnification might not be enough to cover the costs or your vendor could file for bankruptcy.
More importantly, do you want critical correspondence to customers and/or employees handled by someone other than you?

A few steps toward peace of mind

It is essential for organizations to adopt policies and procedures addressing information security, along with a concrete, comprehensive plan for incident response. Consider these questions to create “peace of mind”:
  • Plan — What will you do if a potential issue is identified?
  • Educate — Have you adequately educated your employees about their responsibility to protect private information?
  • Access –Have you implemented standard procedures for access to and use of private data? Is access to data limited to a “need-to-know” basis?
  • Contracts — Do you have procedures for managing your contracts with third parties? Do they address indemnification and insurance?
  • Encrypt — Do you follow encryption standards? Do you restrict and/or encrypt data that is stored on mobile devices, including thumb drives and backup tapes? What about data at rest?
  • Online Do you have a written policy regarding the dissemination of personal information on public and social media sites?
  • Financial impact — Do you have adequate reserves or an appropriate insurance policy to manage the financial impact of a breach?
  • Monitor — How often do you monitor networks, websites and databases to detect potential issues?
Readiness is the crucial step. Organizations can’t afford to figure things out after a breach occurs. It’s much more cost-effective to have a ready-to-use incident-response plan, an on-call forensics expert and a privacy attorney on retainer. Then, when a potential issue is identified, your organization can act to mitigate the effects of a breach, deter any potential litigation and respond to inquiries from regulators.
Employers should also look for insurance partners who can help them identify financial risks and develop customized solutions to better protect their organization.
As larger organizations adopt security awareness campaigns due to requirements of various compliance regimes, training is often conducted only once a year. Organizations will be able to learn about potential security incidents faster only if their employees are well-equipped to recognize that something is amiss and react accordingly. And this will only be possible if, apart from stringent security policies, regular updates and refresher courses are in place.