Showing posts with label identify. Show all posts
Showing posts with label identify. Show all posts

Wednesday, August 17, 2011

Four steps to identifying and managing project risks

Some IT consultants overlook risk identification and management, especially on small engagements. Brad Egeland says this oversight could cost you future business.

I’ve run some projects as an internal PM and others as a consultant brought in to either lead a team or perform the work myself.

The way you run engagements will differ somewhat based on your incoming status (employee vs. consultant) and the size of the effort (long-term software implementation vs. short-term consulting gig to implement new processes).

There can also be differences in how you put together the upfront formal planning documents, and the way you formalize and document requirements.

One variable that remains constant regardless of whether you’re an internal or an external project lead is the task of risk identification and risk management. I’ll address the topic of risk below from a consultant’s perspective.

Step one: Identify risks

You’re coming in cold and don’t know the potential risks of the organizational infrastructure, procedures, and personnel. Be careful not to make assumptions before you have all of the facts; otherwise, you can wind up adding more risk.

Even if it’s a one-on-one engagement with the CIO or project sponsor, it’s critical that you run through a risk identification process during a detailed risk planning session.

(The CIO is your best source of initial information.) The onus is on you to ask good questions, because you’re the expert on consulting engagements and can warn the client about the common pitfalls they might encounter. You’re coming in cold and don’t know the potential risks of the organizational infrastructure, procedures, and personnel.

Be careful not to make assumptions before you have all of the facts; otherwise, you can wind up adding more risk.

Step two: Talk to SMEs and users

The next step is to meet with subject matter experts and end users (if these are different people) and any other personnel who will interact with the solution to a significant degree. These individuals can be good resources when you’re trying to identify potential risks.

Step three: Devise risk strategies

You need to work with the project sponsor, the SMEs, and users to determine and document the best strategy to mitigate or even avoid these risks if they arise.

Even if you can’t formulate a detailed risk response to each item, it will still be helpful to identify a strategy to keep in mind as you continue to track these risks.

Step four: Manage risk and provide regular status updates

I’m a proponent of managing consulting engagements on an ongoing basis like you would on a formal long-term project.

I encourage you to conduct weekly status meetings with the client, during which you should provide a revised task schedule and status report. Your risk list should be part of every weekly status report during.

Conclusion

We may not always conduct smaller consulting engagements with the same formality as we would $2 million dollar projects for Fortune 500 companies, but the need to identify and manage risks is still there.

It’s worth the time and effort because mitigating even one risk could mean the difference between success and failure and might land you future business with the client.

Tuesday, February 16, 2010

USB fingerprints identify 'pod slurping' data thieves

WOULD your company know if the blueprints for its next invention had been stolen by an office interloper, who had quietly copied them onto a memory stick or an iPod?

Probably not. But now a telltale "USB fingerprint" has been discovered that can identify which files have been targeted in so-called pod-slurping attacks.

Data theft via USB ports is rife, says Alexandra Brodie, an intellectual property lawyer with Wragge & Co in London. "We are encountering increasing volumes of IP theft committed this way, with companies losing their trade secrets and accumulated know-how," she says.

Pod slurpers might simply steal an individual document by copying it onto a USB stick. Hackers can also copy vast numbers of documents using document-scavenging tools such as USB Switchblade.

This too springs to life when a memory stick is plugged into a PC running some versions of Windows, including XP. It then automatically copies the contents of the My Documents folder and no one is any the wiser. Now there is a way to spot such data theft.

Vasilios Katos and Theodoros Kavallaris at the Democritus University of Thrace in Komotini, Greece, have been testing every make and model of USB stick and iPod/iPhone.

They have discovered that each one has a distinctive transfer rate when copying data from a PC's hard drive (Computers and Security, DOI: 10.1016/j.cose.2010.01.002).

This is due to the differences in the microcircuitry and components that go into making each type of device.

They are able to find out if files have been copied by consulting the Windows registry, which records the make and model of every USB device plugged into that computer with a time stamp.
The pair then check all document folders for any files that were accessed shortly after the USB device was plugged in - the computer registry counts copying as file access.