So Wired, Forbes and well everyone is talking about this article. Basically A guy applied for a job as a VP at a large marketing firm and got passed over because his Klout score was a 34. They hired someone with a 67.
Well that's how the story spins it, but the piece everyone seems to be forgetting is when they asked about his klout score, the guy had no idea what klout was. Now clearly not everyone follows the social media space that closely and there are a lot of sites that measure your social media influence, klout.com, peerindex.com, kred.com and those are the ones that are top of mind for me. If I looked I bet I could find another dozen easily.
Klout though is the biggest one and for a VP of marketing to not be aware of it, seems like a big miss. Maybe he has 15 years of experience, but if it was traditional print marketing and they are looking for a social marketing expert, I can see why they passed. He didn't sound like a good fit.
Now I'm not in marketing, I'm an IT guy, but if I was asked the klout question, my answer would be different.
"Well my klout score is currently 42, and while that's not as high a score as I think I deserve, the reason it is lower than I think is because klout currently only ranks, facebook, twitter and google plus. I spend a lot of time on linkedin which I think has more business relevance than facebook. In fact according to a recent study by hubspot linkedin is 4X more effective than twitter and 7x more effective than facebook on visit to lead conversions. I think when linkedin.com influence is included I would be more comparable to a mid 50"
That shows I understand how klout works, what it is, and can speak intelligently on why I like it and don't like it. Now maybe they still want someone who is a social medial rockstar with a score to match, or maybe they disagree that linkedin.com is a valid way to do business, or maybe they just want someone who tweets way more than I do.
Either way I think that's a better answer than "I don't know what klout is". Even if I didn't know what klout was, I would have asked a lot of questions on why they think it is relevant and how it compared to other scoring systems.
In summary I think the reason the guy wasn't hired was his lack of knowledge on social media and now really the fact that his klout score was lower. My opinion of course since I wasn't there...
Monday, April 30, 2012
Monday, April 23, 2012
Network spring cleaning...
Well Spring is finally here, at least in Boston. Spring is that time to look around and do some of those cleanup tasks that always get skipped. So here is my top 5 spring IT tasks.
5. Check for zombie devices. You know which ones I mean right? The server that should have been retired 3 years ago but never seems to actually get turned off. Everyone has some of these devices. I’ve got apache web servers that we “retired” years ago, but they are still online. Some of them are so old and shaky we have to restart the service every 5 minutes to “keep it working”. Clearly they should just go away. My goal is to review all the devices in my network and see what should go away.
4. Review usage reports. Do you have WAN links or uplinks that are constantly running at 90%. Probably need to upgrade them. Or do you have a few ports that constantly generate errors. Maybe not enough to cause an alarm, but enough that you should fix them. It could be as easy as a bad patch cable and help solve some of those weird issues that pop up every few months. I’m also a fan of walking through the data center and closets looking for red lights. Sometimes people miss the alert that goes out and the next thing you know the second drive in the RAID set went bad and you just lost data.
3. Update and test your DR plan. If you have a DR plan that hasn’t been tested, it won’t work. They never work the first time you try it. Never. Run a test and figure out what isn’t going to work before you need it. Along with this, check the business continuity type things, like redundant power supplies actually going to different circuits. If they both plug into the same power strip they aren’t done right.
2. Check backups. Not just to see if they have errors, actually compare it to the list of servers that are online and make sure that you are backing up, or at least aware of, anything that is online. Some systems may be online but not need to get backed up. Some active directory servers for example, or NIS slave servers and be rebuilt faster than restored anyway and they don’t store data. Not all AD servers are like this. If you aren’t sure back it up.
1. Check firmware and upgrade if needed. There are two schools of thought on this. “If it aint broke don’t fix it” and “Newer is better”. In my opinion, newer has better features which generally make life better, but be smart and make sure you understand and test the better features to make sure you are ready for them.
I’m sure everyone has their own list of maintenance that they want to do as well. If you want to add ideas, I’d love to hear them.
5. Check for zombie devices. You know which ones I mean right? The server that should have been retired 3 years ago but never seems to actually get turned off. Everyone has some of these devices. I’ve got apache web servers that we “retired” years ago, but they are still online. Some of them are so old and shaky we have to restart the service every 5 minutes to “keep it working”. Clearly they should just go away. My goal is to review all the devices in my network and see what should go away.
4. Review usage reports. Do you have WAN links or uplinks that are constantly running at 90%. Probably need to upgrade them. Or do you have a few ports that constantly generate errors. Maybe not enough to cause an alarm, but enough that you should fix them. It could be as easy as a bad patch cable and help solve some of those weird issues that pop up every few months. I’m also a fan of walking through the data center and closets looking for red lights. Sometimes people miss the alert that goes out and the next thing you know the second drive in the RAID set went bad and you just lost data.
3. Update and test your DR plan. If you have a DR plan that hasn’t been tested, it won’t work. They never work the first time you try it. Never. Run a test and figure out what isn’t going to work before you need it. Along with this, check the business continuity type things, like redundant power supplies actually going to different circuits. If they both plug into the same power strip they aren’t done right.
2. Check backups. Not just to see if they have errors, actually compare it to the list of servers that are online and make sure that you are backing up, or at least aware of, anything that is online. Some systems may be online but not need to get backed up. Some active directory servers for example, or NIS slave servers and be rebuilt faster than restored anyway and they don’t store data. Not all AD servers are like this. If you aren’t sure back it up.
1. Check firmware and upgrade if needed. There are two schools of thought on this. “If it aint broke don’t fix it” and “Newer is better”. In my opinion, newer has better features which generally make life better, but be smart and make sure you understand and test the better features to make sure you are ready for them.
I’m sure everyone has their own list of maintenance that they want to do as well. If you want to add ideas, I’d love to hear them.
Friday, March 2, 2012
Please no more cloud FUD
Even before I read about the Azure outage I knew some where someone had a cloud outage. I could tell because there seemed to be an uptick in the number of "I told you cloud wouldn't work" articles, tweets and blog posts. Please no more...
Now I don't work at Microsoft and don't have any secret knowledge about what happened, but reading the public posts, it sort of sounds like a leap year bug caused "service management to go down". I suspect during the fixing of this, some other issues were caused that impacted performance and caused intermittent stability.
Now I don't use Azure but "Service management" sort of sounds to me like any existing service would continue to work, but new ones can't be brought up. If that's the case that's not a real big deal. Admittedly it would stink if I was planning to launch my new hot startup on 3/1 and couldn't bring production online, but I've got to think that's pretty rare.
It's hard to disagree that a leap year bug shouldn't have been missed, but hey I've let some stuff slip through that in hindsight should have been caught. I mean who hasn't done "reboot" or worse "shutdown" hit enter and then said "Damn wrong window". Mistakes happen.
Mistakes happen in our own data centers too folks. Anyone that honestly has never had an outage either runs a "data center" consisting of an Xbox, Wii and Pentium PC in their parents basement, or makes so few changes that they are still running Sunos 4.1.3 because they aren't done testing that new Solaris stuff.
OK maybe there are a few folks that have been really lucky, but in today's environment we need to move fast. That means mistakes are going to happen.
Last year, or maybe two years ago now, we actually took quite a few servers down in our data center because of power. We actually have complete power redundancy and this should never have happened. Dual feeds, dual switch gear, generators, UPS, etc. The power even takes a different path through most of the building. Each cabinet has 2 (or 4) PDU's.
So what did we do? Well an administrator plugged in his servers and plugged them into 2 PDU's, one in the front, and one in the back. Unfortunately the redundancy is left and right. So even though it was in two PDU's they were both on A power.
We had to take one of the UPSes offline for maintenance and since we know we have redundant power we did this at noon. Looking back, not a great call. But it also wasn't the end of the world. We learned from it, corrected our mistakes and moved on.
No one said "See I told you we shouldn't have hired Rich". Well not that I heard anyway. My point is we all have outages, we all make mistakes, let's just stop with the silly "See cloud isn't reliable" every time someone has an outage.
Now I don't work at Microsoft and don't have any secret knowledge about what happened, but reading the public posts, it sort of sounds like a leap year bug caused "service management to go down". I suspect during the fixing of this, some other issues were caused that impacted performance and caused intermittent stability.
Now I don't use Azure but "Service management" sort of sounds to me like any existing service would continue to work, but new ones can't be brought up. If that's the case that's not a real big deal. Admittedly it would stink if I was planning to launch my new hot startup on 3/1 and couldn't bring production online, but I've got to think that's pretty rare.
It's hard to disagree that a leap year bug shouldn't have been missed, but hey I've let some stuff slip through that in hindsight should have been caught. I mean who hasn't done "reboot" or worse "shutdown" hit enter and then said "Damn wrong window". Mistakes happen.
Mistakes happen in our own data centers too folks. Anyone that honestly has never had an outage either runs a "data center" consisting of an Xbox, Wii and Pentium PC in their parents basement, or makes so few changes that they are still running Sunos 4.1.3 because they aren't done testing that new Solaris stuff.
OK maybe there are a few folks that have been really lucky, but in today's environment we need to move fast. That means mistakes are going to happen.
Last year, or maybe two years ago now, we actually took quite a few servers down in our data center because of power. We actually have complete power redundancy and this should never have happened. Dual feeds, dual switch gear, generators, UPS, etc. The power even takes a different path through most of the building. Each cabinet has 2 (or 4) PDU's.
So what did we do? Well an administrator plugged in his servers and plugged them into 2 PDU's, one in the front, and one in the back. Unfortunately the redundancy is left and right. So even though it was in two PDU's they were both on A power.
We had to take one of the UPSes offline for maintenance and since we know we have redundant power we did this at noon. Looking back, not a great call. But it also wasn't the end of the world. We learned from it, corrected our mistakes and moved on.
No one said "See I told you we shouldn't have hired Rich". Well not that I heard anyway. My point is we all have outages, we all make mistakes, let's just stop with the silly "See cloud isn't reliable" every time someone has an outage.
Wednesday, February 15, 2012
Thinking about going cloud? Have you asked these questions.
We use a lot of cloud applications and recently started asking a lot of questions. Frankly not all cloud applications or vendors are created equally and spending some time understanding what they really do can help avoid a disaster later.
This is the list of questions we ask. We send this list out and then do an hour or so phone call to review the answers with the vendors. We then use these answers to rank them in a weighted spreadsheet to help us make our decision. We also add in things like company relationship, user testing etc, but those aren't really things we ask the vendors about.
Anyway here is the list. I'd love feedback on what others ask.
Disaster Recovery and Business Continuity
Do you have redundant sites designed for auto-failover?
How long does it take for the redundant site to take over.
Does this include the time to decide to fail over?
What kind of RTO/RPO are in place and are they actually tested against?
Do you have geographic redundancy?
Can you restore accidentally deleted or corrupted data? How far back can you restore from?
What impact does a failed HD, server, cabinet, switch, data center have?
E-discovery
Is it possible?
Can we do legal holds by user, file, keyword?
Can we get access to “access logs” in the event we need to?
If so how far back can we get?
What does it show us?
Can we see who our users are sharing with?
If so can we easily remove access from an enterprise level?
Stability
Do you have a site like trust.salesforce.com for transparent operations?
Is it automatically updated with outages or performance alers?
Is code/data in escrow? If so how often does it get updated?
What is the migrate out plan like?
Can we request a backup of our data including any customizations?
Company financials
Are you private or publicly owned?
Are you cash flow positive? If not what is the cash burn rate and reserve?
Are you adding new customers? How many?
Do you track your NPS (Net Promoter Score)?
Authentication
Do you support automatic provisioning and de-provisioning of user accounts?
Do you support LDAP.RADIUS or even better SAML authentication and authorization back to us?
Do you use encryption? If so is it for data in flight, at rest or both? What kind of encryption is it?
Compliance and Privacy
Do we get notified of an investigation?
Can our data be seized as part of another companies investigation?
Is our data recoverable by your organization?
Do you have an SSAE16 or ISAE3402?
Are we allowed to have our third party auditors (or internal auditors) to audit your organization?
Contract
Please attach a copy of our master services agreement, terms and conditions or other contracts that we are using.
If you get bought by a competitor can I get my data out and go?
Are there financial penalties for service level agreement failure.
Are maximum increases baked in?
How much notice do you need to give us to terminate?
How much notice do we need to give them if we want to leave? I
Does the contract auto-renew? If so what are the terms?
Performance
Are you globally load balanced? If so explain.
Do you use Akamai or other CDN for better performance?
Who do you use for WAN connectivity?
Do you offer “offline” ability? If so it is automatic, or does the user need to know that they will be offline and plan accordingly?
Development
Do you offer built in integration tools to existing systems like SAP, salesforce.com, etc.
If not, how hard is it to build them?
What toolset is used for “custom development”
Support
Are you staffed 24/7?
Can we proactively request assistance if we are doing something off hours?
Is it onsite, email, phone, web or all?
What sort of response time is available?
What is the average tenure of the tier1 staff?
Is there a public knowledgebase available? Is it the same as the internal one or is it filtered?
Can anyone from Enterasys call, or do we only get a certain amount of “authorized users”?
Architecture
How quickly do new features show up?
Do we need to do anything or do we “magically” get them?
How much notice do we get for training users?
Is the system a true multitenant system?
Do you support multiple clients, like iphone, android, blackberry as well as tablets?
Is it strictly HTML5/browser based? If so which browsers and versions are supported?
Administration
Does the system support delegated administration?
How easy is it to automate tasks?
Can we apply roles to groups?
Do we get visibility into what is shared outside of the company, or what access has been granted to third party applications?
Can we enforce enterprise wide restrictions?
This is the list of questions we ask. We send this list out and then do an hour or so phone call to review the answers with the vendors. We then use these answers to rank them in a weighted spreadsheet to help us make our decision. We also add in things like company relationship, user testing etc, but those aren't really things we ask the vendors about.
Anyway here is the list. I'd love feedback on what others ask.
Disaster Recovery and Business Continuity
Do you have redundant sites designed for auto-failover?
How long does it take for the redundant site to take over.
Does this include the time to decide to fail over?
What kind of RTO/RPO are in place and are they actually tested against?
Do you have geographic redundancy?
Can you restore accidentally deleted or corrupted data? How far back can you restore from?
What impact does a failed HD, server, cabinet, switch, data center have?
E-discovery
Is it possible?
Can we do legal holds by user, file, keyword?
Can we get access to “access logs” in the event we need to?
If so how far back can we get?
What does it show us?
Can we see who our users are sharing with?
If so can we easily remove access from an enterprise level?
Stability
Do you have a site like trust.salesforce.com for transparent operations?
Is it automatically updated with outages or performance alers?
Is code/data in escrow? If so how often does it get updated?
What is the migrate out plan like?
Can we request a backup of our data including any customizations?
Company financials
Are you private or publicly owned?
Are you cash flow positive? If not what is the cash burn rate and reserve?
Are you adding new customers? How many?
Do you track your NPS (Net Promoter Score)?
Authentication
Do you support automatic provisioning and de-provisioning of user accounts?
Do you support LDAP.RADIUS or even better SAML authentication and authorization back to us?
Do you use encryption? If so is it for data in flight, at rest or both? What kind of encryption is it?
Compliance and Privacy
Do we get notified of an investigation?
Can our data be seized as part of another companies investigation?
Is our data recoverable by your organization?
Do you have an SSAE16 or ISAE3402?
Are we allowed to have our third party auditors (or internal auditors) to audit your organization?
Contract
Please attach a copy of our master services agreement, terms and conditions or other contracts that we are using.
If you get bought by a competitor can I get my data out and go?
Are there financial penalties for service level agreement failure.
Are maximum increases baked in?
How much notice do you need to give us to terminate?
How much notice do we need to give them if we want to leave? I
Does the contract auto-renew? If so what are the terms?
Performance
Are you globally load balanced? If so explain.
Do you use Akamai or other CDN for better performance?
Who do you use for WAN connectivity?
Do you offer “offline” ability? If so it is automatic, or does the user need to know that they will be offline and plan accordingly?
Development
Do you offer built in integration tools to existing systems like SAP, salesforce.com, etc.
If not, how hard is it to build them?
What toolset is used for “custom development”
Support
Are you staffed 24/7?
Can we proactively request assistance if we are doing something off hours?
Is it onsite, email, phone, web or all?
What sort of response time is available?
What is the average tenure of the tier1 staff?
Is there a public knowledgebase available? Is it the same as the internal one or is it filtered?
Can anyone from Enterasys call, or do we only get a certain amount of “authorized users”?
Architecture
How quickly do new features show up?
Do we need to do anything or do we “magically” get them?
How much notice do we get for training users?
Is the system a true multitenant system?
Do you support multiple clients, like iphone, android, blackberry as well as tablets?
Is it strictly HTML5/browser based? If so which browsers and versions are supported?
Administration
Does the system support delegated administration?
How easy is it to automate tasks?
Can we apply roles to groups?
Do we get visibility into what is shared outside of the company, or what access has been granted to third party applications?
Can we enforce enterprise wide restrictions?
Monday, February 6, 2012
What will IT organizations look like in 2016
If you have been reading this blog or following me on twitter you know I'm a big believer in cloud and consumerization of IT. In the next few years I expect Google's vision of 100% web to be the norm. Users will be able to use any device to access their data with or without IT's help.
So what does this mean for IT organizations, and how should we structure ourselves to be relevant in this new, and frankly for some people, scary new world?
I think of IT as several groups today. There is the most important group, the service desk (or helpdesk). This is the most important group since it is the "face of IT". Frankly if you have a great service desk it can really help hide other issues which, if you as a CIO are paying attention, can fix before they get you in trouble.
Typically then there is either a split with Applications and Operations, or Maintenance and New Projects. Sometimes there is a third group that covers more of running IT as a business type stuff, like service management, financial management, customer relationship managers etc.
In the future though most of the operations will be done by cloud providers. Even now, I hardly ever get involved in any salesforce.com issues. Partly because we don't really have any issues, but if we did it would be to verify connectivity through the Internet to their data center. Beyond that it's a contracts issue.
If we move to Google Apps, which is pretty likely, our email and storage service goes the same way. What changes though it is the pace of innovation. We will really need people focused on discovering pain points, and solutions to resolve them, before users can find the solution and implement it on their own.
Dan Petlon tells the story about when he decided social media was important. The short version is that he read an article about the relevance of the CIO and the quote was "How can you expect to remain relevant when your CEO has to learn about Facebook - the most successful application ever, from his 12 year old daughter."
I want to make sure that IT knows about and understands the next Facebook before the CEO's daughter tells him about it. To do this I think a dedicated group is needed to ensure that we hear about new technology and also encourage adoption of it. This "Change Management" group fills that role. This is a huge shift but with Google releasing 200+ new features a year alone making sure that the users understand the features and can leverage them is going to be the difference between the good companies, and the dead companies.
Development also changes. Many of the cool features in a cloud environment are really integrations between various exisitng cloud applications. Also many times simple applications will be able to be done by power users, assuming the change management team does a good job training on the new tools, so that should free hard core developers up to really work on integrating and making an excellent user experience. Things like single sign on, consistent look and feel etc. will be table stakes to new applications.
Finally the contracts and vendor management piece gains importance since so much depends on vendors providing what they promise. Infrastructure really will become the network and Internet connectivity to allow users to get to the cloud. Clients will be whatever the end user likes and will likely be purchased and supported from the vendor, whether that be Apple Ipad's, Google Chrome or Android devices.
The break down of resources will probably look something like this.
You can see the two biggest departments in IT are really "change management" and "integrations and development".
Anyway this is what I think. I'd love to hear feedback on what others think.
So what does this mean for IT organizations, and how should we structure ourselves to be relevant in this new, and frankly for some people, scary new world?
I think of IT as several groups today. There is the most important group, the service desk (or helpdesk). This is the most important group since it is the "face of IT". Frankly if you have a great service desk it can really help hide other issues which, if you as a CIO are paying attention, can fix before they get you in trouble.
Typically then there is either a split with Applications and Operations, or Maintenance and New Projects. Sometimes there is a third group that covers more of running IT as a business type stuff, like service management, financial management, customer relationship managers etc.
In the future though most of the operations will be done by cloud providers. Even now, I hardly ever get involved in any salesforce.com issues. Partly because we don't really have any issues, but if we did it would be to verify connectivity through the Internet to their data center. Beyond that it's a contracts issue.
If we move to Google Apps, which is pretty likely, our email and storage service goes the same way. What changes though it is the pace of innovation. We will really need people focused on discovering pain points, and solutions to resolve them, before users can find the solution and implement it on their own.
Dan Petlon tells the story about when he decided social media was important. The short version is that he read an article about the relevance of the CIO and the quote was "How can you expect to remain relevant when your CEO has to learn about Facebook - the most successful application ever, from his 12 year old daughter."
I want to make sure that IT knows about and understands the next Facebook before the CEO's daughter tells him about it. To do this I think a dedicated group is needed to ensure that we hear about new technology and also encourage adoption of it. This "Change Management" group fills that role. This is a huge shift but with Google releasing 200+ new features a year alone making sure that the users understand the features and can leverage them is going to be the difference between the good companies, and the dead companies.
Development also changes. Many of the cool features in a cloud environment are really integrations between various exisitng cloud applications. Also many times simple applications will be able to be done by power users, assuming the change management team does a good job training on the new tools, so that should free hard core developers up to really work on integrating and making an excellent user experience. Things like single sign on, consistent look and feel etc. will be table stakes to new applications.
Finally the contracts and vendor management piece gains importance since so much depends on vendors providing what they promise. Infrastructure really will become the network and Internet connectivity to allow users to get to the cloud. Clients will be whatever the end user likes and will likely be purchased and supported from the vendor, whether that be Apple Ipad's, Google Chrome or Android devices.
The break down of resources will probably look something like this.
You can see the two biggest departments in IT are really "change management" and "integrations and development".
Anyway this is what I think. I'd love to hear feedback on what others think.
Sunday, January 8, 2012
Nice customer service story
I, like most of us, am pretty used to bad customer service. I mean the number of times I've been delighted is much less than the amount of times I've walked away frustrated by the lack of caring.
But I was pleasantly surprised by VW of America. They had sent me a recall a month or so ago for a fuel line issue. Now I wasn't really annoyed or even phased by this. Every one has recalls and I knew I'd just schedule time to get it done. No big deal.
But VW did something that really shows great customer service, they actually sent a $50 gift card to their customers to make up for the inconvenience. In it they apologize for the problem, re-iterate their desire to avoid repeating the problem in the future, and for the paranoid in all of us, explain there are no strings attached.
We all make mistakes, but great companies not only fix them and apologize for them, but make it right for the customers, Great job VW!
But I was pleasantly surprised by VW of America. They had sent me a recall a month or so ago for a fuel line issue. Now I wasn't really annoyed or even phased by this. Every one has recalls and I knew I'd just schedule time to get it done. No big deal.
But VW did something that really shows great customer service, they actually sent a $50 gift card to their customers to make up for the inconvenience. In it they apologize for the problem, re-iterate their desire to avoid repeating the problem in the future, and for the paranoid in all of us, explain there are no strings attached.
We all make mistakes, but great companies not only fix them and apologize for them, but make it right for the customers, Great job VW!
Wednesday, January 4, 2012
Employee privacy and corporate liability...
I just read this blog post from
http://bringyourownit.com/2011/12/19/consumerization-101-employee-privacy-vs-corporate-liability-2/
It's a great, thought provoking post. Here's my take on it, for what it's worth. Also thanks to my friend Mark Townsend for pointing me to the blog. Lots of great stuff.
If you are too lazy to read the above, basically a company wiped a users iphone that was connected to the corporate email system. She had signed an acceptable use policy but it had a picture of her son that had just passed away from cancer. She sued and collected 5M...
Cesare asked about that, as well as the company's right to track location and what the company should do about questionable content...
We tell people if they want to use their personal device to get their corporate email. that they need to be aware that we have the right to wipe. if you don't like it, we will get you a corporate device.... but... not sure that this will protect us since in this case, she had signed an AUP, which I assume had the same sort of language in it that we use in ours. Which basically says, if you connect it to us you give us the right to wipe all data off of it.
@CesareGarlati
It's a great, thought provoking post. Here's my take on it, for what it's worth. Also thanks to my friend Mark Townsend for pointing me to the blog. Lots of great stuff.
If you are too lazy to read the above, basically a company wiped a users iphone that was connected to the corporate email system. She had signed an acceptable use policy but it had a picture of her son that had just passed away from cancer. She sued and collected 5M...
Cesare asked about that, as well as the company's right to track location and what the company should do about questionable content...
We tell people if they want to use their personal device to get their corporate email. that they need to be aware that we have the right to wipe. if you don't like it, we will get you a corporate device.... but... not sure that this will protect us since in this case, she had signed an AUP, which I assume had the same sort of language in it that we use in ours. Which basically says, if you connect it to us you give us the right to wipe all data off of it.
Now I feel bad about it, but if she had lost the photo because she dropped the iphone would she have sued apple? Would the building owner be responsible for having too hard of a floor? Would the flooring people be responsible? At some point people need to be responsible for backing up data that they want to keep. I mean she had the picture for a few weeks...
Regarding tracking location. If you don't want the company to do that, don't use it to connect to corporate, turn it off, or leave it on your desk. After all we aren't tracking the user, we are tracking a device that is accessing corporate resources. Is that much different than tracking IP's on a website? Other than the granularity I would say no...
As far as accessing questionable websites while at work. I would say if it was done using the corporate LAN (or WLAN) the company has the right to monitor. If on your personal cell phone plan then no. My network, my rules. IMHO
The trickier piece is if we let you bring your device to work and it already has questionably, or even illegal content on it (piracy, inappropriate etc) is the company liable? Do we have the right or obligation to report it if we see it? We had a case many years ago where a field guy sent his laptop in for repair and it had illegal files on it. Our policy was not to look. but if we saw something illegal to report it. Clear enough if it is a company owned machine, but if it's not what should we do??? I mean if someone has a bag of pot in their car in our parking lot are we liable?
Tricky issues and while I think my answers make sense, that doesn't mean the law will agree. I would not want to be the test case...
Subscribe to:
Posts (Atom)