IT Management Template Suite
Special Offer
Save $2,500 to $6,500
You can order the IT Management Template Suite which contains all of Janco's templates, white papers, policies, and procedures.
We can process purchase orders as long as we have a copy of a purchase order or a letter on company stationary with the signature of an individual who is authorized to purchase items of this magnitude.
There is a company license for each item which allows you to to place the product on your enterprise's INTRANET (not INTERNET) and they can be shared by groups/ divisions/data centers within a single Country / DUNS number.
If you order the update service at the same time you will receive that service for 18 months for the cost of just 6 months. That is a full extra year of service.
This is the best offer that we have ever made or will make on the FULL IT Management Template Suite.
The products that are included in the IT Management Template Suite are:
- Disaster Recovery Template
- Security Manual Template
- IT Salary Survey
- IT Salary Survey 10 year comparative study
- Functional Specification Template
- Safety Program Template
- IT Infrastructure, Strategy & Charter Template
- IT Service Management Template
- Practical Guide IT Outsourcing
- Client Server Management HandiGuide
- Internet & IT Position Descriptions HandiGuide
- Metrics for the Internet & IT HandiGuide
- Internet & PC Workstation Polices & Procedures
- Business & IT Impact Questionnaire
- Threat & Vulnerability Assessment Tool
CIO and CTO Management News
Security Policies Should be Part of Normal Business Practices According to Federal Judge
A federal judge has
rejected a proposed settlement by TD Ameritrade Inc. in a data breach lawsuit.
That marks the second time in recent months that a court has weighed in on what
it considers basic security standards for protecting data. The case stems from a
2007 breach that exposed more than 6 million customer records.
The federal judge did not find the proposed settlement to be "fair, reasonable, or adequate." Rather than benefiting those directly affected by the breach, Ameritrade's proposed settlement was designed largely to benefit the company. The judge described the additional security measures that Ameritrade proposed in the settlement as "routine practices" that any reputable company should be taking anyway and should be defined in their normal security policies and procedures.
In September 2007, Ameritrade said that the names, addresses, phone numbers, and trading information of potentially all of its more than 6 million retail and institutional customers at that time had been compromised by an intrusion into one of its databases. The stolen information was later used to spam those customers.
As part of an effort to settle claims arising from that incident, Ameritrade this May said it would retain an independent security expert to conduct penetration tests of its networks to look for vulnerabilities.
The company also offered to retain the services of an analytics firm to find out whether any of the data that had been compromised in the breach had been used for identity theft purposes. The company also said it would give affected customers a one-year subscription for antivirus and anti-spam software.
- more infoSOA Best Practicdes
SOA Design Patterns & Best Practices
Some of the most important tools in the evaluation, purchase, and ongoing use of Service-Oriented Architecture (SOA) are the best practices that vendors, consultants, and customers have compiled. What factors vary most are the time, cost, and ease of SOA implementation. This template gives you the tools for SOA success by fcousing on the processes and providing a definition of the standard best practices for large-scale technology implementations.
- more infoIT security - Often a Myth
IT Security polices for notebooks and desktops are typically managed by restricting the choices that users have by reducing the number options that are supported. This standards-based process ensures control by reducing flexibility. But try maintaining that system when users can buy a relatively cheap smartphone with as much power as a desktop had in the early 1990s.
Furthermore, attempts by IT organizations to prevent the use of handheld devices has largely failed because of the number of tools available to work around IT policies. For example, users who are restricted from using wireless e-mail often find ways to redirect e-mail to outside ISP services, where they synchronize e-mail to their personally owned devices. This raises the security threat for enterprises because it means that control of e-mail routing has been losts.
- more infoMicrosoft gives Google Chrome an edge in the EU
Microsoft's new browser ballot screen, which is supposed to randomly scramble the positions of the top five browsers, instead gives Google's Chrome the best chance of landing in the preferred first spot, an IBM software architect said today.
"This was a rookie mistake," said a professor, who works for IBM and has a degree in astrophysics from Harvard University. "I was definitely surprised to see an error of this type in the ballot."
- more infoWindows 7 Crushes Vista In terms of adoption
Microsoft has already said that Windows 7 is the fastest selling operating system in history, but, judging by the adoption rate, the platform is simply leaving Vista in the dust. Janco found that Windows 7s market share had skyrocketed to no less than 12.5% since the OS was released. In this regard, the market share of Windows 7 is dwarfing that of Vista, comparing the first seven months after release. - more infoIE Loses 6.21% Market Share in 12 Months
Janco has just released its Browser and Operating System Market Share White Paper. The major findings are that in the last 12 months Microsofts browser market share has continued to erode Microsoft lost over 6% in the last 12 months; Firefoxs market share is unchanged for the last 12 months; Google Desktop and Chrome now have just under 6%; and Netscape is no more. On the operating systems side, Windows 7 is being accepted at a pace is parallel to the way Window XP was in the 90s. The CEO of Janco Associates, Victor Janulaitis said, "The last six months have been a mixed bag for Microsoft. Their browser market share has fallen to level that they back in 1998 with no end in sight. At the same time Windows 7 now has 12% of the OS market in less than 7 months since its release."
The top five browser market share rankings are: 1 - Microsofts IE 64.78%; 2 - Firefox 17.38%; 3 Google (Desktop & Chrome) 5.78%; 4 Mozilla 1.73%; 5 Safari 1.39%. The CEO of Janco Associates, Inc and the ITPC, M. Victor Janulaitis said: "The positive glow on Googles Chrome was dulled in with the identification of some defects in the way it handles XML pages. But the real story is the continued erosion of Microsofts" market.
- more infoIT service management issues that CIOs face
The key service management business questions facing CIOs and senior IT managers today are:
- What are the service management impacts with the ever-increasing technical complexity on margins and customer satisfaction?
- Where are the areas where margin-improvement opportunities exist?
- How can IT minimize the maintenance-contract price pressure to drive new service-revenue opportunities to the bottom line?
- How does improved service management translate into a
competitive advantage?
What is the future as the IT function moves from fixing problems to driving product value? - What are the challenges of off shoring support and how should the enterprise address them?
IT Infrastructure a CIO Challenge
The CIO struggles to manage Infrastructure as they prepare for change
While the business faces changes that require more agility, IT is seen as lagging behind - even when CIOs carefully manage business and IT alignment:
- IT objectives still include only cost reduction and quality. IT objectives rarely reflect enterprise agility objectives. CEOs want greater agility but do not talk about it as a measurable objective. Instead, many firms still measure IT on its contribution to cost reductions inside and beyond the walls of IT, along with its reliability and its availability to run today's business.
- Business agility improvement projects do not easily gain funding. There are a number of current trends that, in theory, should improve agility - such as service-oriented architecture (SOA), on-demand services, pervasive technologies, outsourcing, Dynamic Business Applications, agile development, and offshoring. However, IT still needs to plan for and rightsize these options to reach the agility required while balancing the costs and risks. In addition, these technologies require cross-department investment in enterprises where each business unit manages budgets separately.
Obama administration to ask for more 1984 Big Brother powers
Everyone knows that police can peek inside an email account it if they have a paper search warrant
But cybercrime investigators are frustrated by the speed of traditional methods of faxing, mailing, or e-mailing companies these documents. They're pushing for the creation of a national Web interface linking police computers with those of Internet and e-mail providers so requests can be sent and received electronically.
A federal task force (soon to be released) study says that law enforcement agencies are virtually unanimous in calling for such an interface to be created. Eighty-nine percent of police surveyed, it says, want to be able to "exchange legal process requests and responses to legal process" through an encrypted, police-only "nationwide computer network."
The study also says: "89 percent of investigators agreed that a nationwide computer network should be established for the purpose of linking ISPs with law enforcement agencies so that they may exchange legal process requests and responses to legal process. Authorized users would communicate through encrypted virtual private networks in order to maintain the security of the data."
But the most controversial element is probably the private Web interface, which raises novel security and privacy concerns, especially in the wake of a recent inspector general's report from the Justice Department. The 289-page report detailed how the FBI obtained Americans' telephone records by citing nonexistent emergencies and simply asking for the data or writing phone numbers on a sticky note rather than following procedures required by law.
- more infoOursouring continues
U.S. defense contractors growing use of offshore (outsource) subsidiaries from 2003 to 2008 allowed the Defense Department to save money on contracts but also resulted in the loss of U.S. tax revenue and unemployment benefits for some U.S. workers, according to a new report from the Government Accountability Office.
Practical Guide for IT Outsourcing a HandiGuide
The 29 largest publicly traded defense contractors increased their use of offshore subsidiaries by 26 percent from 2003 to 2008, the report states.
Those subsidiaries helped the contractors reduce taxes, in part by avoiding Social Security and Medicare payroll taxes for U.S. workers hired at the foreign subsidiaries, GAO auditors said.
About a third of the contractors also decreased their effective U.S. corporate tax rates in 2008 in part through the use of foreign affiliates, lower foreign tax rates and indefinite reinvestment of foreign income outside the United States.
- more infoAlmost 200,000 jobs lost in IT during this recession
Job cuts in technology were
fierce in 2009, but 2010 is expected to see modest growth in a number of
subsectors. The last time layoffs were this bad was in 2005.
Job cuts in technology were fierce in 2009. Last year saw 174,629 jobs lost in the sector, catapulting up 12.3 percent from the 2008 cuts of 155,570 jobs, according to an outplacement company which tracks industry numbers on announced layoffs. Technology - still considered by the Department of Labor to be one of the most promising industries for future job creation - has not seen that many layoffs since 2005.
The worst of the downsizing occurred in the first quarter, which is when the overall economy hit rock bottom. The recession's impact on the tech sector was inescapable.
The technology-focused blog TechCrunch developed its own "layoff tracker" Web application, which has been documenting layoffs in the sector since October 2008. For comparison, as of its last update in November 2009, TechCrunch had reported a total of 350,299 employees laid off - roughly 20,000 more, but certainly in the same ballpark.
The tech sector accounted for about 13.2 percent of the total 1.3 million announced job cuts in the United States in 2009, said Challenger, Gray & Christmas. By subsector, electronics fared the worst with 65,000 jobs cut - up 55 percent from 2008 - while telecommunications lost 9.4 percent fewer jobs in 2009. The computer industry was unchanged.
It's going to be a slow climb out of this recession, but computer and electronics firms should be among the first to see the turnaround, as companies try to postpone hiring by achieving productivity gains through technology. Even with the economy showing some nascent signs of recovery beginning the second half of the year, many companies are holding off on investments in new technology. And, with it still [being] difficult for small businesses and startups to obtain loans, there are few opportunities for tech firms to expand their customer base.
Despite the potential for improved hiring in the new year, there are a lot people competing for every opening and many employers are very particular about what skills and experience they want new workers to have. It is critical that technology workers continually update their skills in order to remain competitive. It is necessary to maintain a balance between having specialized skills and having the flexibility of a generalist. It may also be necessary to expand one's search to more industries or geographically.
We'll see a radically transforming marketplace - driven by surging demand in emerging markets, growing impact from the cloud services model, an explosion of mobile devices and applications, and the continuing rollout of higher-speed networks. These transformational forces will drive key players to redefine themselves and their offerings and will spark lots of M&A activity.
- more infoIT Job Descriptions HandiGuide 2010 Version Released by Janco
The
IT job descriptions
contained within the Internet and Information Technology Position
Descriptions HandiGuide® was updated in 2010 and contains over 650 pages; which
includes sample organization charts, a job progression matrix, over 231 job
descriptions, best practices for resume screening and best practices for phone
screening.
The author of this book has extensive experience in job content definition and analysis. He personally is recognized by the courts as an "expert" and has been used by a number of firms as an expert in age and job discrimination cases. The HandiGuide includes some of the tools that he uses in that process.
The book also addresses Fair Labor Standards and the ADA, and is in a new easier to read format. Each job description meets ADA standards and the position description is delivered in electronic format - word which is editable and PDF which is printed. Also included are tools to help you expand, evaluate and define your enterprise's unique additional required. Those tools include:
- Job Evaluation Questionnaire
- Position Description Questionnaire
- Job Progression Matrix (Job Family Classifications)
- Best Practices for
- Screening Resumes
- Phone Screening
- Hiring employees
- Motivating employees
- Mandated Requirements
- American with Disabilities Act (ADA)
- Health and Safety Requirements (Federal and State)
- Fair Labor Standards Act
- Sexual Harassement
- Other Labor Laws
Google personal lead sensitive data in error
It was reported in Computerworld that Google apologized after it
mistakenly e-mailed potentially sensitive business data last week to other users
of its business listings service.
The company's Local
Business Center allows businesses to create a listing for Google's search engine
and Maps application, as well as add videos, coupons or photos.
Google then provides data on how customers found the listing, showing search terms people used before clicking the listing and other data such as the geographic location of someone who looked up driving directions to the business.
Google will send reports to those who are signed up. Early last week, Google sent the reports to third parties by mistake. The mistake affected several thousands businesses registered with Local Business Center, of which there are more than a million.
"Shortly after sending the newsletter to a portion of our users last night, we discovered that some e-mails included statistics for the wrong business," Google said in a written statement. "We promptly stopped sending any further e-mails and investigated the cause, which we found to be a human error while pulling together the newsletter content. We'd like to apologize to all the business owners impacted and assure them that we're fixing the process that led to this mistake."
People who received the data then began to publicize the incident, realizing the privacy implications. Chicago-based Internet consultant David Dalka wrote on his blog that he received information regarding the listing for Boscos, a restaurant in Tennessee that brews its own beer.
- more infoMassachusetts information security requirements
As of January 1, 2010, all organizations with operations and/or customers in the state of Massachusetts are required to follow comprehensive information security requirements regarding both paper and electronic records containing personal information. These requirements include enforcing password security, encrypting all personal information stored on laptops and removable devices and ensuring up-to-date firewall protection, operating system patches and the latest versions of security agent software. Read this whitepaper to learn how your organization can meet the necessary requirements and improve its security practices. - more infoPersonal and Professioal Bonuses Cut By Most Enterprises
Fringe benefits are cut by most entetprises. Health insurance is the only benefit that has reamined.
Companies have started to cut back on the fringe benefits provided to IT Professionals. For example in January of 2008 95% of IT professionals had health insurance supplied by their employers while in June 2009 only 88% did. A full historical comparison of trends in benefits is included with the full version of the Janco IT Salary Survey.
- more infoUser Departments Often Drive IT Infrastructure Excesses
Often a departmental business manager submits a request to the IT organization for a new server to host a critical business-intelligence application. The request itself is unremarkable; after all, it is common for a business unit to ask IT to deploy additional hardware infrastructure to support their application requirements.
However the company may have multiple similar requests in queue, and all include a request for storage arrays dedicated to the applications being added. All too often, it's a common reaction to request dedicated servers and storage for new applications. And some CIOs and IT departments accommodated such requests to a fault. However, at times, this addition of processing and storage capacity occurs without adequate understanding of whether there may be unused capacity available. It also fails to recognize that each new addition of servers and storage adds to the complexity of the IT infrastructure.
- more infoWill Google violate your privacy in the future?
Google Goggles could
violate your privacy
without your knowing it. Goggles lets you send photos of a business card, book
cover or even bar code from your Android-based smartphone to Google for quick
identification and data manipulation. Now if that software is extended to
include photos your personal privacy could be impacted.
The way it works is that you snap a photo by centering your image in the Goggles screen and pressing a small camera icon at the bottom of the screen. Goggles then scans the image, analyzes it and identifies it. If the image is of a business card, Goggles separates the information into fields and lets you put it into your Google Contacts database. If it's a book, the app offers to let you purchase or research it. If it's a store or a landmark, Goggles fetches Google search info about the location. (Objects such as cars, animals or people aren't, according to the instructions, really identifiable yet.)
Imagine pointing your smartphone at anything, clicking a button and having all the information about that object immediate appear.
- more infoSmartPhones - new security risks
As the
iPhone, BlackBerry, and other devices have become more popular, harmful software
such as viruses and spyware is emerging to exploit their vulnerability. Cheaters
beware. In late October, Indonesian developer released mobile-phone software
that can help someone eavesdrop on your conversations.
A distrusting partner or spouse can secretly download the free application, called PhoneSnoop, onto your BlackBerry, remotely turn on the microphone, and listen to conversations held in proximity to the device. PhoneSnoop, downloaded more than 2,000 times since its release, is one of a growing number of applications that can be downloaded onto a smartphone without a user's knowledge. FlexiSPY similarly can be downloaded onto Research In Motion's BlackBerry or the Apple iPhone.
Smartphones and the growing number of people using them are becoming a bigger target for unauthorized and potentially harmful software, including worms, viruses, and spyware that tracks a user's Web activity. The smartphone security threat "is imminent," says a principal analyst at consultant Infonetics Research.
- more infoComputerization does not always save money according to Harvard study
"As currently implemented, hospital computing might modestly improve process measures of quality but does not reduce administrative or overall costs" say a Harvard Medical School study. The stuyd looked at some of the nation's "most wired" hospital facilities found that computerization of those facilities has not saved them any money or improved administrative efficiency.

The recently released study evaluated data
on 4,000 hospitals in the U.S over a four-year period and found that the immense
cost of installing and running hospital IT systems is greater than any expected
cost savings. And much of the software being written for use in clinics is aimed
at administrators, not doctors, nurses and lab workers.
The problem "is mainly that computer systems are built for the accountants and managers and not built to help doctors, nurses and patients," the report's lead author. While many health care experts believe that computerization will improve quality of care, reduce costs and increase administrative efficiency, the Harvard Medical School report notes that no earlier studies closely examined computerization's cost or its effect on a diverse sample of hospitals. Even hospitals on the "most wired" list "performed no better than others on quality, costs, or administrative costs," the study found.
- more infoCongress fails security check
The Washington Post reports that a (now) ex-employee of the U.S. House Ethics Committee put a sensitive report detailing 30+ current investigations on to a public accessible computer. Wired Magazine also reported on this story, saying it was put onto a personal computer, and then placed it into a file folder used for peer to peer file sharing to the Internet.
This lack of compliance with basic security policies and procedures is a major defect in how Congress is protecting sensitive information.
No word on what file sharing application tool was used. If it was setup as anonymous FTP, it may have been from one specific computer or wound up on hundreds if not thousands of computers.
The ethics committee is one of the most secretive panels in Congress, and its members and staff members sign oaths not to disclose any activities related to its past or present investigations. Watchdog groups have accused the committee of not actively pursuing inquiries; the newly disclosed document indicates the panel is conducting far more investigations than it had revealed.
- more infoRisk Management is focus of ISO 31000-2009
ISO has announced that ISO 31000:2009, the new international standard for risk management, has been published.
Entitled 'ISO 31000:2009, Risk management - Principles and guidelines', the standard provides principles, framework and a process for managing any form of risk in a transparent, systematic and credible manner within any scope or context.
The standard recommends that organizations develop, implement and continuously improve a risk management framework as an integral component of their management system.
At the same time, ISO has published 'ISO Guide 73:2009, Risk management vocabulary', which complements ISO 31000 by providing a collection of terms and definitions relating to the management of risk.
All organizations, no matter how big or small, face internal and external factors that create uncertainty on whether they will be able to achieve their objectives. The effect of this uncertainty is risk and it is inherent in all activities. It can be argued that the global financial crisis resulted from the failure of boards and executive management to effectively manage risk. ISO 31000 is expected to help industry and commerce, public and private, to confidently emerge from the crisis.
ISO 31000 is a practical document that seeks to assist organizations in developing their own approach to the management of risk. But this is not a standard that organizations can seek certification to. By implementing ISO 31000, organizations can compare their risk management practices with an internationally recognized benchmark, providing sound principles for effective management. ISO Guide 73 will further ensure that all organizations are on the same page when talking about risk.
- more infoProgrammers can go to jail for their work
IT professionals now have one more
worry on their minds, they have to be aware of what they design and
program is legal.
Two computer programmers who worked for Bernard L. Madoff were arrested and charged in connection with the multibillion dollar Ponzi scheme. They were charged with conspiracy, falsifying books and records of a broker-dealer, and falsifying books and records of an investment dealer according to the U.S. Department of Justice (DOJ).
The two were employed as computer programmers at Madoff's business beginning in the ealy 1990's and were primarily were responsible for developing and maintaining computer programs that supported the operation of Madoff's investment account business.
The
progammers "... allegedly helped construct Bernie Madoff's house of cards," the
U.S. attorney said in a statement. "The computer codes and random algorithms
they allegedly designed served to deceive investors and regulators and concealed
Madoff's crimes. ... they have been charged for their roles in Madoff's epic
fraud."
As a broker-dealer and investment adviser, BLMIS was required, under the federal securities laws and regulations, to keep certain books and records in the ordinary course of its business, including: trade blotters containing an itemized daily record of details about all of BLMIS's purchases and sales of securities; documents reflecting each order underlying the purchases and sales of securities and the times at which the orders were received and executed; and the name and address of the beneficial owner of each account held at BLMIS.
The programmers developed and maintained computer programs that generated numerous false and fraudulent books and records. They created books and records for a small subset of BLMIS investment account clients to help hide the scope and nature of the business; altered details about the number of shares, execution times, and transaction numbers for trades reported on BLMIS trade blotters, by employing random algorithms that produced false and random results;and created false and fraudulent order entry and execution reports that included fictitious times at which orders for equities transactions purportedly were placed.
The programmers allegedly knew that the special programs they developed contained fraudulent information and that they were used in connection with the SEC and European accounting firm reviews. One of the two attempted to delete 218 of 225 special programs from a server and also closed their own BLMIS accounts, withdrawing hundreds of thousands of dollars each.
Handwritten notes found by the FBI in one of the programmer's desk stated, "I won't lie any longer. Next time, I say 'ask Frank.'"
- more infoIs recovery around the corner?
PC processors are the latest tech segment bouncing back from the recession.
Third-quarter shipments of computer processors, or CPUs, climbed 23 percent over the second quarter of 2009, doubling typical growth and setting a record for sequential growth, according to an IDC report released Monday.
Revenue from processor sales also bounced back to hit $7.4 billion, a 14 percent gain over the second quarter, according to IDC's "Worldwide PC Processor 3Q09 Vendor Shares" report.
Most meaningful about 3Q09 is that, since PC processor shipments overall just slightly exceeded shipments in 3Q08--which was itself a record quarter at the time--we know that the processor market is recovering.
- more infoGoogle Falling Behind in Browser War
Google will not fully integrate its Chrome Web browser with Microsoft's new Windows 7 operating system.

The news follows an announcement by the Mozilla Foundation that Firefox 3.6, the next version of the open source browser, would integrate with Windows 7 features such as taskbar thumbnail previews and Jump Lists.
However, according to reports in The Register, Google's internal issue tracking system indicates that work on the features has been pushed back to version 5 of the browser. Chrome is currently on the 3.0 release, while version 4 is currently in development.
Despite the scaled back ambitions, work seems to be progressing on Google's Chrome OS. An early developer build of the operating system has been leaked onto Google's Web site. Stay tuned for more details.
- more infoFree speech and the Internet challenged
The ongoing
case in Cook County Circuit Court also treads into the still developing arena of
Internet speech protection, experts say. Stone acknowledges that she hopes it
sets a precedent for protecting minors from potentially harmful chatter directed
at them online.
A woman was embroiled in a tough campaign for the
Village Board when the Daily Herald published an article about the race the day
before the April 7 election. She won a seat. A Daily Herald story shortly after
the election noted there had been "an unusually nasty tone" in the race as the
women and five other candidates vied for three
seats.
On April 9, in
online comments to the April 6 story on the newspaper's Web site, a person using
the name Hipcheck16 wrote something directed toward women's son that women's
attorney described in court filings as
defamatory.
Since there
have been relatively few cases like this in U.S. courts, a University of Notre
Dame law professor said there is a
strong probability the court proceeding will become an important part of
emerging case law.
Recent court
rulings have tended to side with anonymous posters and against those who want
their identities revealed. And judges are more likely to set a higher threshold
when ruling on identifying anonymous sources in newspaper stories, although in
this case the newspaper was merely hosting an online forum, not providing the
content.
The trend has not been in the direction the women probably would like it to go.
Sensitive Information
Policy
This policy covers the treatment of Credit Card, Social Security, Employee, and Customer Data. The policy is 15 pages in length. This policy complies with Sarbanes Oxley Section 404.
The policy applies to the entire enterprise, its vendors, its suppliers (including outsourcers) and co-location providers and facilities regardless of the methods used to store and retrieve sensitive information (e.g. online processing, outsourced to a third party, Internet, Intranet or swipe terminals).
- more info















