Thu 3 Apr 2008
Separation of Duties and the Implications for Product Design
Posted by jtmcarthur under Product development, Security, Startups, Storage and Data Management, Technology, Virtualization
Comments Off on Separation of Duties and the Implications for Product Design
I spent an hour today with an Onaro customer and through the conversation learned a little bit about how different companies handle the separation of duties in IT processing. I met with the customer to better understand the critical decision criteria that were behind his choice of Onaro, what features were most valued and what alternatives were considered. Turns out, at the time of his decision several years ago, he didn’t see many alternatives. Onaro, which was an independent software supplier at the time, was recently acquired by NetApp, a storage systems company.
This customer originally licensed Onaro’s SANscreen offering to ensure that the company’s IT change-control process was being followed in the storage network. SANscreen maps the entire data path from the host bus adapter (HBA) in the server, through the cables and switches, ultimately to the storage array. Anytime someone makes a change to the configuration of his fibre channel storage area network (FC-SAN), he gets a notification. If the change hasn’t been authorized through the change-control process, he investigates. As we were talking he showed me several alerts, that he had just received on his Blackberry, regarding changes that had not been authorized. (more…)