<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itskeptic.org"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The IT Skeptic - Comments for &quot;ITIL product compliance &quot;</title>
 <link>http://www.itskeptic.org/node/263</link>
 <description>Comments for &quot;ITIL product compliance &quot;</description>
 <language>en</language>
<item>
 <title>Determine Service impact by starting with Services</title>
 <link>http://www.itskeptic.org/node/263#comment-6660</link>
 <description>&lt;p&gt;The illusive creature &quot;Successful, Ongoing CMDB/CMS&quot; debate...&lt;/p&gt;
&lt;p&gt;I would argue that one of the failings of Configuration Management didn&#039;t start with anything wrong in the ITIL books.  I think people took from it what they wanted, decided that it was an inventory, a repository, a warehouse, etc. - which were all incorrect.  &lt;/p&gt;
&lt;p&gt;Starting a CMDB bottom up with technology, data models, relationship diagrams, etc is an excellent source of mental masturbation - but it doesn&#039;t solve the problem of determining service impact.  &lt;/p&gt;
&lt;p&gt;Having been involved with many Configuration Management initiatives, I would have to say the one thing lacking was the service perspective, which at the time was considered &quot;an aspect&quot;.  I think for a CMDB/CMS to have even a chance of being successful (delivering the value intended), services should be &quot;the aspect&quot; and it has to be created and managed;&lt;br /&gt;
- Purely from a Services perspective, ergo, you need to understand your services and the value you deliver to customers first&lt;br /&gt;
- Actively, with tight integration to Change Management;&lt;br /&gt;
- Efficiently, meaning we don&#039;t need to manage CI&#039;s to the bit level (best guidance I got here; Lowest level of independent change the provides business value); and&lt;br /&gt;
- Selectively, meaning based on services, we leverage automated means such as Auto-Discovery to validate CMDB/CMS contents, but our data should represent what is authorized, vs. what is actual.  I would also add that the most important data, typically isn&#039;t discoverable...&lt;/p&gt;
&lt;p&gt;While I always enjoyed the challenges of CMDB/CMS and Configuration Management, from a business value perspective, I have to agree - it&#039;s not on the high priority list.&lt;/p&gt;
</description>
 <pubDate>Tue, 02 Mar 2010 14:49:25 +0000</pubDate>
 <dc:creator>CyberJMC66</dc:creator>
 <guid isPermaLink="false">comment 6660 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>How do you determine service impact?  </title>
 <link>http://www.itskeptic.org/node/263#comment-6654</link>
 <description>&lt;p&gt;Larger enterprises have to do something to manage configuration data and try to get consolidated views of service.   Anything is ugly: either you go into integration hell, or you sell your soul to a vendor.&lt;/p&gt;
&lt;p&gt;Smaller enterprises should consider on-demand CMDB: fix/improve/rehearse the configuration processes first before thinking about technology, rely on people (plural) as your impact engine, and derive the service configuration on demand instead of trying to keep it recorded all the time.&lt;/p&gt;
&lt;p&gt;95% of sites don&#039;t have a CMDB.  So what are you doing folks?  How do you determine service impact?   What techniques, tricks and tools do you use?  How can we do impact analysis better without CMDB/CMS?&lt;/p&gt;
</description>
 <pubDate>Tue, 02 Mar 2010 03:53:00 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 6654 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>What can be done against it?</title>
 <link>http://www.itskeptic.org/node/263#comment-6652</link>
 <description>&lt;p&gt;So if you are not pursuing the holy grail, not believing in monolithic data soultion nor in federation / system integration? So what does work for large enterprises with &amp;gt;1000 IT staff? What is different for smaller IT (e.g. 500, 50 &amp;amp; 5?)?&lt;/p&gt;
</description>
 <pubDate>Mon, 01 Mar 2010 20:16:38 +0000</pubDate>
 <dc:creator>mbuzina</dc:creator>
 <guid isPermaLink="false">comment 6652 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Vendor Lock-in</title>
 <link>http://www.itskeptic.org/node/263#comment-6650</link>
 <description>&lt;p&gt;You make a good point on vendor lock-in.  If memory serves, General Mills was one of SAP&#039;s largest R/2 installs on the mainframe (Amdahl?), for about a decade.  Plenty of time to bake in a monolithic data strategy.&lt;/p&gt;
&lt;p&gt;I suspect SAP and R/3 was the only option when they finally decided to modernize.  If memory holds, they simply switched to HP Superdomes (9000s?), with another mainframe-like strategy, and performed relatively little business process re-engineering.  Not exactly the bold ERP transformation success story touted.&lt;/p&gt;
</description>
 <pubDate>Mon, 01 Mar 2010 02:29:43 +0000</pubDate>
 <dc:creator>Visitor</dc:creator>
 <guid isPermaLink="false">comment 6650 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>The holy grail</title>
 <link>http://www.itskeptic.org/node/263#comment-6649</link>
 <description>&lt;p&gt;One centralised instance of data is certainly the holy grail, and yes there are many instances of success.  Even for Tivoli and Unicenter monolithic strategies.  &lt;/p&gt;
&lt;p&gt;I&#039;m still concerned that a monolithic IT strategy equates to vendor lock-in (as it does for ERP in general)&lt;/p&gt;
&lt;p&gt;The Achilles heel of a more sensible longer-term strategy is perhaps expediency.  In the meantime we need to do something.  let&#039;s do some integration/fereration.  Oooh look we&#039;ve &quot;solved&quot; the problem.&lt;/p&gt;
</description>
 <pubDate>Sun, 28 Feb 2010 19:44:30 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 6649 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Plenty of success stories</title>
 <link>http://www.itskeptic.org/node/263#comment-6648</link>
 <description>&lt;p&gt;I&#039;m only talking about the domain of IT. (But there are plenty of enterprise success stories, such as General Mills in our town with their complete cutover to SAP.)&lt;/p&gt;
&lt;p&gt;Doesn&#039;t have to be an insane, &quot;all-in,&quot; rip and replace. You decide on your target platform and move the various modules over one at a time when the respective legacy versions are up for refresh ... the existence of failure anecdotes has to be weighed against the annual revenues of the vendors which are clear evidence of at least some benefit being gained by some firms. &lt;/p&gt;
&lt;p&gt;This started off as a discussion of the costs/risks of integration... I think for every failed ERP you can cite, I can cite a failed attempt to build up from smaller, uncoordinated systems via integrations... there are tradeoffs on both sides, and sometime centralizing data *does* work. &lt;/p&gt;
&lt;p&gt;Charles T. Betz&lt;br /&gt;
&lt;a href=&quot;http://www.erp4it.com&quot; title=&quot;http://www.erp4it.com&quot; rel=&quot;nofollow&quot;&gt;http://www.erp4it.com&lt;/a&gt;&lt;/p&gt;
</description>
 <pubDate>Sun, 28 Feb 2010 14:15:42 +0000</pubDate>
 <dc:creator>Charles T. Betz</dc:creator>
 <guid isPermaLink="false">comment 6648 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>monolithic </title>
 <link>http://www.itskeptic.org/node/263#comment-6647</link>
 <description>&lt;p&gt;Oh, gotcha.  Rip out all our existing IT management tools, and replace everything with a monolithic system like Tivoli or Unicenter so we lock in to one vendor.  I used to try to sell that idea.&lt;/p&gt;
&lt;p&gt;In a sufficiently large organisation with sufficiently complex business processing, I hear ERP can actually repay the boggling cost of total replacement of staff skills, business processes and technology.  The last time I saw one of the world&#039;s top 100 banks try it, it nearly broke the company and cost them about 2 billion dollars.  Likewise one of the world&#039;s biggest resources companies who ran a project for about five years before anything actually paid off.&lt;/p&gt;
&lt;p&gt;That was doing ERP for the whole company.  I don&#039;t see too many organisations where replacing only the IT silo with a monolithic solution is going to be big enough to have a positive ROI in my lifetime.&lt;/p&gt;
</description>
 <pubDate>Sun, 28 Feb 2010 08:30:42 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 6647 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Don&#039;t move the data at all</title>
 <link>http://www.itskeptic.org/node/263#comment-6646</link>
 <description>&lt;p&gt;I&#039;m not sure what is meant by federating a CMS without moving data at all. It&#039;s simply not possible, in the absence of master data management, which requires *some* movement of at least business keys between systems. There&#039;s been some pretty fuzzy headed statements about CMDB federation along these lines, inconsistent with basic data management realities.&lt;/p&gt;
&lt;p&gt;What I am talking about is consolidating IT systems of record into large transactional systems on one common data model in one large database, supporting multiple modules. You don&#039;t need to move the data because it&#039;s being mastered in one place. &lt;/p&gt;
&lt;p&gt;You know, the approach that has failed so miserably for SAP &amp;amp; Oracle... except, well, wait, it really didn&#039;t fail, on balance.... judging by those companies&#039; revenues... &lt;/p&gt;
&lt;p&gt;Charles T. Betz&lt;br /&gt;
http://www.erp4it.com&lt;/p&gt;
</description>
 <pubDate>Sun, 28 Feb 2010 03:09:36 +0000</pubDate>
 <dc:creator>Charles T. Betz</dc:creator>
 <guid isPermaLink="false">comment 6646 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>both tigers, different stripes?</title>
 <link>http://www.itskeptic.org/node/263#comment-6645</link>
 <description>&lt;p&gt;is there a significant difference in cost/difficulty between federating a CMS and providing regular ETL (extract-transform-load) into a monolithic CMDB?  Especially since many CMS discussions I&#039;ve seen propose ETL in some cases anyway?  Seems to me they are both integration, and both with the same number of data sources...&lt;/p&gt;
</description>
 <pubDate>Sat, 27 Feb 2010 23:55:30 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 6645 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Fools rush into federation</title>
 <link>http://www.itskeptic.org/node/263#comment-6644</link>
 <description>&lt;p&gt;When I was with Accenture (no, not ashamed, Accenture is like college, you get out of it what you put in to it) one of the things I remember was very explicit guidance saying &quot;always treat integrations as one of the most risky areas on your engagement.&quot; &lt;/p&gt;
&lt;p&gt;Sound advice and it spurred an interest in EAI for me that I have maintained off &amp;amp; on, career-wise. That interest led me to take David Linthicum&#039;s 5-day EAI seminar many years ago, and I&#039;ve kept up with his excellent writings on the space. Added a bit more rigor years later in my MS in SW Eng, where I had a formal course on distributed systems &amp;amp; the real math behind them, and then of course there was the three year stint in Best Buy&#039;s leading edge Integration Competency Center, an ambitious attempt to centralize all development and support of system integrations into one unit.  &lt;/p&gt;
&lt;p&gt;Having seen the amazing atrocities that constitute system integrations in so many cases, I am bemused by all the chatter about the importance of CMDB federation, and all the purported risks of overly monolithic systems. (They&#039;re Too Big! Oooooh, Scary!) I wonder if the people making such statements have studied the inherent challenges of data integrity across heterogeneous systems. &lt;/p&gt;
&lt;p&gt;Yes, we have to have integrations, but their risks and costs are sometimes overlooked at the expense of larger, more centralized systems that in fact might be the more manageable alternative.&lt;/p&gt;
&lt;p&gt;Charles T. Betz&lt;br /&gt;
http://www.erp4it.com&lt;/p&gt;
</description>
 <pubDate>Sat, 27 Feb 2010 23:24:06 +0000</pubDate>
 <dc:creator>Charles T. Betz</dc:creator>
 <guid isPermaLink="false">comment 6644 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Here&#039;s one more:</title>
 <link>http://www.itskeptic.org/node/263#comment-6641</link>
 <description>&lt;p&gt;Try this one on:&lt;/p&gt;
&lt;p&gt;14.  How much attention is paid to the integrations?  Do they look like they&#039;re part of the same approach, or are they all different?  It is easy to change and add to them?  Are the integrations documented out of the box, or are they unofficial &quot;field&quot; readmes?  Beware a solution with crappy integration, it will suck the funding right out of your project and erode your street cred with your users.&lt;/p&gt;
&lt;p&gt;By the time you get to  anything that can be called a &quot;solution&quot;, you&#039;re likely to have more than one product.  For example, a CMDB that provides service anatomy and impact analysis, and a Service Desk for Incident/Problem/Change management.  If anyone has a beef with this particular choice of example, save it for a second - what I&#039;m getting at is, despite the preference for one product that does it all, you&#039;re not gonna get that, at least today.  So, you&#039;re always looking at integration.&lt;/p&gt;
&lt;p&gt;The question I&#039;d ask (and I ask this regularly and forcefully of my colleagues) is, how much attention has been paid to the integrations?  Is there a methodology, or does your integration plan (hoping you have one) resemble a complex, finely-tuned bowl of pasta?  I like linguine, with a nice, fresh tomato sauce...but that&#039;s not what he said!  He said &quot;truuuue,  integraaaaaation...&quot;   that is, not a spewing of point-to-point that is added to every time something else is added to the bowl, but having thought about what needs to get integrated from the beginning.  Things to make it more manageable, like, all teh integrations follow a common set of structures, terminology, documentation, and how to change and add to it.&lt;/p&gt;
&lt;p&gt;Point-to-point integations have a certain smell, and &quot;solutions&quot; built on incrementally-added integrations have that burning, high-TCO smell.  It might work, but it creaks under it&#039;s own weight, and it&#039;s brittle - what happens when Bob&#039;s away or leaves, nobody else knows what goes in in between product X and Y.   A vendor MUST get the integrations right to answer many of the first 13.  Don&#039;t let them buy you off with explanations of low-maintenance, without a good look at how that low-maintenance comes about.  Is it because the vendor doesn&#039;t expect you to have to maintain that integration very much?  If so, the vendor is spraying statistical pixie dust on you - overall, the cost is low, but the one time you had to actually extend the integration, it cost a month and five guys and killed yoru other project.&lt;/p&gt;
&lt;p&gt;There is no integration kool-aid.  Integrations must be consumed without dilution.  Get the integrations right.  Beware sham integrations.&lt;/p&gt;
&lt;p&gt;Now, assuming you DO get the integrations right, your portfolio gets a bit of help.  You can as a vendor focus on making your products meet the needs of your market, versus running back to R&amp;amp;D to be in catch-up mode for another year.&lt;/p&gt;
&lt;p&gt;Do you agree or am I drunk on my own Kool-Aid?   I care deeply about getting IT right, if you agree check out my blog at http://www.hp.com/blogs/itsm.  I am transparent.  And apologies to Billy Crystal for the Princess Bride crack.&lt;/p&gt;
</description>
 <pubDate>Sat, 27 Feb 2010 18:39:06 +0000</pubDate>
 <dc:creator>jody_l_roberts</dc:creator>
 <guid isPermaLink="false">comment 6641 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>The 13th ITIL Compliance Criterion</title>
 <link>http://www.itskeptic.org/node/263#comment-1472</link>
 <description>&lt;p&gt;Here&#039;s one more:&lt;br /&gt;
13.  Do the standard manuals talk in ITIL terminology?  or just the brochures and one add-on manual...&lt;/p&gt;
</description>
 <pubDate>Wed, 08 Aug 2007 09:37:34 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 1472 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>the word compliance used deliberately.</title>
 <link>http://www.itskeptic.org/node/263#comment-1265</link>
 <description>&lt;p&gt;yes we&#039;ve been through that arguement.  I was being deliberately provocative by using the word compliance.&lt;/p&gt;
&lt;p&gt;i disagree totally.  The &lt;a href=&quot;http://www.itskeptic.org/node/72&quot;&gt;following remark&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;
So it is quite true that Pinkverify does not claim &quot;compliance&quot;. But it certainly does assert assessment, validation, verification, certification, compatibility, comparison against criteria, explicit demonstration of commitment, reassurance, diligence, support for definition and requirements, and guidance met, which does not leave much else in the thesaurus.
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;applies as much to these discussions around the word &quot;compliant&quot;.&lt;/p&gt;
&lt;p&gt;Common sense says you can tell whether something is compliant to ITIL.  If it looks like a duck, walks like a duck and sounds like a duck....&lt;/p&gt;
</description>
 <pubDate>Fri, 29 Jun 2007 21:38:00 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 1265 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>It isn&#039;t that it isn&#039;t possible...</title>
 <link>http://www.itskeptic.org/node/263#comment-1260</link>
 <description>&lt;p&gt;Alan,&lt;/p&gt;
&lt;p&gt;My point wasn&#039;t that it isn&#039;t possible for a tool to be compliant with ISO 20000, but rather that the compliance would be of limited value, because you could run an ISO 20000 compliant with pen and paper in theory. Conversley, of course, you could implement a &quot;compliant&quot; tool in such a way that it fails to support the requirements of the standard.&lt;/p&gt;
</description>
 <pubDate>Fri, 29 Jun 2007 11:47:40 +0000</pubDate>
 <dc:creator>JamesFinister</dc:creator>
 <guid isPermaLink="false">comment 1260 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>ITIL Compliance</title>
 <link>http://www.itskeptic.org/node/263#comment-1259</link>
 <description>&lt;p&gt;Just add my two cents:&lt;br /&gt;
* Agree that ITIL compliance is an inaccurate phrase.&lt;br /&gt;
* For my money, PinkVerify is a complete waste of time and money for vendors to pursue other than to placate users who want to &#039;implement&#039; ITIL and don&#039;t want to do the leg work to understand either ITIL or the product itself. Many ITIL implementations were successfully completed with pre-ITIL Remedy, and many unsuccessful implementations have been attempted with verified products so that Verify is not a guarantee of success and neither is the absence of it a consignment to failure.&lt;br /&gt;
* I am looking forward to the Pink Verified product that will help me &quot;implement&#039; the new service strategy book. I think that Einstein, Newton and Hawking will need to step up to the plate probably supported by Gödel, Escher and Bach.&lt;br /&gt;
* Verify is of course a great commercial business for Pink and good luck to them as long as they can get away with it.&lt;br /&gt;
*I think that I disagree with Jimbo -  ISO 20000 is a real standard and therefore compliance can be measured as it has &quot;shalls and musts&quot; while ITIL V2 only has one directive comment in the whole library. Compliance with ISO 20000 is both possible and advisable.&lt;/p&gt;
&lt;p&gt;Just feeling quite ancy today :-)&lt;/p&gt;
</description>
 <pubDate>Fri, 29 Jun 2007 11:13:36 +0000</pubDate>
 <dc:creator>Alan Nance</dc:creator>
 <guid isPermaLink="false">comment 1259 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>ISO 20000 compliance</title>
 <link>http://www.itskeptic.org/node/263#comment-1258</link>
 <description>&lt;p&gt;Whilst it applies to other standards I think that claiming ISO 20000 compliance would be somewhat meaningless.&lt;/p&gt;
</description>
 <pubDate>Fri, 29 Jun 2007 10:34:51 +0000</pubDate>
 <dc:creator>JamesFinister</dc:creator>
 <guid isPermaLink="false">comment 1258 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>No such animal as &quot;ITIL Compliance&quot;</title>
 <link>http://www.itskeptic.org/node/263#comment-1257</link>
 <description>&lt;p&gt;ITIL is a non-definitive framework - it was that in v2 and is even more so in v3.&lt;/p&gt;
&lt;p&gt;Therefore no product should be considered as &quot;ITIL Compliant&quot;. A product may be more or less &quot;ITIL Compatible&quot; or &quot;ITIL Enabling&quot;, but not Compliant.&lt;/p&gt;
&lt;p&gt;You can talk about Cobit or ISO standards compliance of a product, but not ITIL.&lt;/p&gt;
</description>
 <pubDate>Fri, 29 Jun 2007 09:15:22 +0000</pubDate>
 <dc:creator>pshotts</dc:creator>
 <guid isPermaLink="false">comment 1257 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>It&#039;s called Pink-Verify, not Pink-ITIL</title>
 <link>http://www.itskeptic.org/node/263#comment-1237</link>
 <description>&lt;p&gt;It&#039;s called Pink-Verify, not Pink-ITIL&lt;/p&gt;
</description>
 <pubDate>Wed, 27 Jun 2007 06:11:06 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 1237 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Trademark infringement?</title>
 <link>http://www.itskeptic.org/node/263#comment-1236</link>
 <description>&lt;p&gt;If it was not for the fact Pink once owned the ITIL trademark in North America I would suggest their basing a product on ITIL is real close to trademark infringement.  We once requested (officially) from OGC a similar use of the name (Enable-ITIL), it was declined, citing the need for an as yet to be produced &#039;value-add&#039; license.  Anyone out their willing to give their free legal advice on use of a brand name in a product for profit seemingly without permission?&lt;/p&gt;
</description>
 <pubDate>Wed, 27 Jun 2007 05:39:47 +0000</pubDate>
 <dc:creator>ianclayton</dc:creator>
 <guid isPermaLink="false">comment 1236 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>The &quot;long list&quot; is dead right!</title>
 <link>http://www.itskeptic.org/node/263#comment-1234</link>
 <description>&lt;p&gt;The &quot;long list&quot; is dead right!   I like that.  And you are right: the only way to know a product&#039;s real capabilities is to use it in anger.  What Pink and other analysts ought to do is to talk to the real users, not tame one&#039;s referred by vendors.  The internet makes it easy to get the answers on the forums.  Sure you get bitter and twisted characters with an axe to grind - one or two of &#039;em on here - but if you mix that with the vendor&#039;s candy you come up with something approaching reality.&lt;/p&gt;
</description>
 <pubDate>Mon, 25 Jun 2007 21:49:18 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 1234 at http://www.itskeptic.org</guid>
</item>
</channel>
</rss>
