Blog

Shaping up Non-BYOD


[Honeymoon]

To investigate; an idea: Now that the BYOD phenomenon has taken the pressure off of IT departments’ provision of equipment (and software), how can we use the time and budget that has become available, to shape up the Asset / Configuration / Inventory Management regarding the iron that we still have, keep, and service ..?

Out of a desire to maybe see those systems management areas for once be complete and current… Even if only for the efficiency of subsequent maintenance, and the beauty to see insight finally bringing better understanding and razorsharp management.

But it won’t be an easy walk. Because of the backlog… Because of the amount of work, redecorating the shop while it’s still open for business, and while all sorts of other demands are placed on staff; demands that are more urgent, more important, and more interesting ntellectually.

And because so much … user interaction oh the horror, is required. To establish the total landscape of all systems, from the meanest hardware cable and plug, all the way up through the infrastructure, systems software, middleware, applications, parameters, et.etc. up to what the end user would understand to be their ‘system’. And back again, checking the rationale of every tiny part, and every chunk in between and at the top. Indeed, much may be found, that wasn’t suposed to be there, that is, without anyone knowing why, but still working, without anyone knowing why. Or how. Or where…

So far, so good. But now, the shop is still open and all end users want the latest (app!) toys to be connected to just all enterprise ‘systems’ in ways that nobody would know a rationale for but hey, we must quod non give it a try!
Yes, the old demands are still there, reenlivened, with seriously stepped up requirements in terms of timeliness and speed, versatility, and quality. High time to make it happen; high time to start with the basics ..!

Rebooting the CIA


[Nope]

The CIA of information security doesn’t cut it anymore. We have relied on Confidentiality-Integrity-Availability for so long, that even ‘managers’ in the most stale of government departments now by and large know of the concepts. Which may tell you that very probably already by that fact, the system of thought has been calcified into ineffectiveness.
At least we should reconsider where we are, and where we’d want to go.

Lets tackle Confidentiality first. And maybe foremost. Because it’s here that we see the most clear reflection of our deepened understanding of the value merits of information not being in line with the treatment(s) that the information (data!) gets. Which is a cumbersome way to formulate that the value estimation on data, and the control over that data, is a mess.
Add in the lack of suitable (!) tools. User/Group/World, for the few among you who would still know what that was about, is clearly too simple (already by being too one-dimensional), but any mesh of access as can (sic) be implemented today, makes a mess of access rights. Access blocks? Access based on (legitimate, how to verify) value (s), points in time, intended and actually enabled use, non-loss copyability, etc.?
But what is the solution ..? Continue reading “Rebooting the CIA”

Data doesn’t Know


[Unseen Rotjeknor]

In the stories on Big Data et al. (predictive analysis, … , you name it), I often see a big confusion about terms. Some even mix up data and information, or only pay lip service to the fundamental difference..!

Oh yes, many come up with the Information Pyramid; in a most basic picture I took from wipo.int:

* sometimes, Knowledge is bracketed between Data and Information; more on that below.

But there’s something fishy with the way the picture is being used, commonly.
For one thing, any action that produces meta data (i.e., just plain flat derivative data !!) is considered to be ‘enrichment’ onto Information. But that’s wrong! All the aggregation, the averaging, the abstraction that you do, only delivers other data, with the (near-mathematical) translation functions still intact – although also, information gets lost..! Yes, the details count, and have their own ‘information’; a full description of all data points in a set would require at least all the data points themselves, or miss something when they’re described, circumscribed otherwise.
The problem is; no-one really knows how to get from Data to Information as we intuitively (heh) understand it. Information seems to be detached, or separated from Data by a chasm that we do not know how to cross, probably because our understanding of what Information is, and our definitions, are so weak.
Oh, and putting a layer of Knowledge in between Data and Information, doesn’t help anything, either. Even worsens the problem. As it is above, it doesn’t say much either. And instead of Knowledge, above one could also fill in Understanding, or Insight (which would come closer to but remain separated from Wisdom). And above the peak, is there Nirvana? Smells like blog spirit.

So, all the efforts of NLIQ and MITIQ may be fine, as for data analysis to try to achieve predictive analysis (nice pun, the contradictio in those terms!), but as long as Data and Information are used arbitrarily (see the list of publications and the actual articles contents …), one will remain stuck in data analysis and not reach the next level of Information. Or Knowledge, let alone Understanding, Insight or even Wisdom.

But I keep running in circles. Yes, I know, and I also know that in order to advance, we’ll need to get a grip on two things:
1. Definitions, in the traditional sense or by way of aspect/category/label/hermeneutic quality descriptions, of all the levels we may distinguish;
2. Definitions, in both ways, too, of the transitions and transition methods, tools, etc., we may construct theoretically and practically.

I’ll do some work on this, but your help is appreciated..!

Fuzzy risk language


[Antwerp. Seriously.]

In some previous post, I posited that we should move from quantitative (quod non) to qualitative or even intuitive risk management.
And how that may be difficult. ‘cause it is.
As an intermediary step, I propose to build a better language with which to communicate, discuss and calculate (sic) with qualitative risk management.

Because I see a place for a combination of fuzzy logic and wavelet theory, including neural network signal combination functions.
As my time is limited, this time of year, would anyone have pointers to what’s already out there in papers, practical applications, etc..? That could kickstart the discussion. And I’ll return with more, better, more extensive, more thought out stuff on the subject later.

No More Vines


[Cordoba, the oft-overlooked castle]

“The doctor can bury his mistakes, but an architect can only advise his clients to plant vines” by Frank Lloyd Wright.
1. FLlW would never admit defeat; all of his work were masterpieces (by his opinion).
2. Already in his time, there were historical examples of curtain facades. And since, they have blossomed. Would this not undo the bon mot ..?

Bit coin: Money bytes sovereignty


[Berlin again, tucked away, much underrated]

Bitcoin’s hopping up and down in ‘real’ currency terms and everyone is happy to declare it all a pyramid game.
It is, but so is any other currency issued on the promise of maybe some future repayment in … the same or another currency. The underlying value of any currency depends on the future income stream of the issuing entity, or intermediate trade for … other currencies, services, or goods. Exactly like Bitcoin.

Except, of course, that ‘normal’ currencies are issued by governments, geography-based entities from the past when geography mattered.
But does it, still, today, much ..? And will it in the near future? Aren’t we already in a blended world, a blended society, where for the lower layers of Maslow’s pyramid we’re still physical entities and hence geography-dependent (safety, water, food, shelter, etc.) but for the higher layers (group belonging, recognition, self-actualisation) we don’t care from where it comes ..? Once our (developed) world develops further, with so much more automated, silicon- rather than carbon-based, intelligence and sentience becoming available, will the importance of the lower layers not diminish ..?
Up to a point, I know, we can’t ‘shed’ the lower layers. Though the Singularity could, almost, and could at least do without us…

But that’s not the point. the point is that if the sovereignty of nations, understood here in the narrow sense to regard the right and possibility to create and issue money at will, backed by a grossly overestimated guarantee (would you dare to guess how often governments have declared insolvent, in the past few centuries alone ..? On the principle, they all were and are equals…), is lost because others can have the same sovereignty and other sovereignties previously reserved for nation-states, why would we still regard nation-states as the highest entities ..?
[You will now point out that some nations of nation/states spring up, e.g., USofA (sic), EU, UN; right, but their structure is just an amalgamated mesh of more of the same]

And, why would we regard what we previously had, as currency, while not understanding Bitcoin and the many others around (see this and that, possibly incomplete), as such, too ..? Or would we need a ‘real’ economy to underpin a currency; where would you draw the line, then..? What would be the link between a currency and its ‘underlying’ economy, what would be the boundaries of the economy, what definition of sovereign debt would we include or not (there’s many definitions; e.g., would we include guarantees?), how would we establish a ‘value’ in what other ‘currency’..? Gold has been dethroned, remember?

So, we need to study harder, and all of us need to understand more, about the nature of money altogether and only then take a look at digital currencies and their merits (or non-). Would anyone have pointers to good in-depth on-line courses or so ..?

The Compliabullies


[Berlin at dusk]

Just a thought: Would investigation and analysis show that the kids that were bullied in prep school and / or (separate hypotheses…) high school, in later life be the ones that end up in Compliance and Risk Management (not being management of risks…!) departments, to take eternal revenge on those that bullied them..?
Because the latter will not have noticed too much the damage they did (they were kids back then) and have merrily gone their own way as they were allowed to be prepped to do. Now, they find themselves being caught in a web by the ones that have frustration embedded deep in their brains at the lower levels that (truly) developed early on, the ones that want to get even by tossing around and beating the innocent puppets into ill-understood compliance with stupid rules.
The bullying instigators, of course, the ones that were behind the scenes, are the big stingers that happily fly straight through the web that catches only the little bugs.

If so, will there be a fix, so much needed, to the totalitarian bureaucracy explosion of the last decade or will the ossification have to go even further before the current economic structures collapse under the weight of their overhead and inproductivity ..?
Sometimes I’m optimistic that the cycle has already reached its peak (see some earlier posts). Sometimes I’m not, and would appreciate your ideas…

Slight update: From Qual to Intu

A slight update to the previous post: What I propse in the end isn’t as much a shift to qualitative risk management as such, but an even further step to intuitive risk management. Yeah, that’s fuzzy. But doable. And will boil down to the sort of ‘real’, normal management that leaders-managers have already practiced throughout the centuries (and certainly in the better parts of the 20th century).
So no worries, the future isn’t all certain but that makes it fun, right ..?

The 15.5 risk

Your 15.5 risk is of no interest at all! I have a 15.6 risk! Hm, I only have a 13.1
Seriously.
You know you’re doing that. But will you admit it, and learn, and move to something better ..?


[Hi, DC!]

There’s a lot wrong in risk management today. I mean, not only can one still rant about the ‘three lines of defense’ (quod non) as I do regularly on this blog, but one can also dive into the details of how risks are managed, if not when, and find a lot of systemic error and particularly, non-thinking all around.

Let’s start with one core element: weigh(t)ing and comparison of risks. With my guesses, based on decades of experience and science/literature:
Do you include all risks, or just the tiny fraction that your mind can get a hold of? My guess is: The latter. So you miss the vast majority of the risk universe and will be grossly incomplete.
Do you include upside potentials (actions unthought of, and uncontrolled/unsmashed by measures) too? My guess is: No, again you’re incomplete, but also you’re so biased I can’t trust you anymore.
Do you use High-Medium-Low for impacts? My guess is: Yes. Or you use 1-5 scales or so, maybe (sic) even with sort-of indicator thresholds or brackets to determine what goes where. But you don’t realise that impacts can vary, very much so and in time, too. Averages will not do in subsequent calculations or other analysis! You must have (continuous!) impact functions of time and chance. If they’re hard to establish (I’d say: Impossible, given the scarcity of data!), that’s your bad.
Do you use High-Medium-Low for probability (frequency expectations)? My guess is: Yes. Or you use 1-5 scales or so, maybe (sic) even with sort-of indicator thresholds or brackets to determine what goes where. But you don’t realise that probabilities can vary, very much so and in time, too. Averages will not do in subsequent calculations or other analysis! You must have (continuous!) probability functions of time and impact. If they’re hard to establish (I’d say: Impossible, given the scarcity of data!), that’s your bad.
Do you know the difference between statistics and chance calculus? I guess not. Hah, and then you still abuse both ..? Do you know the difference between discrete and continuous mathematics (functions)? If not, you’ll make errors all around. How would you arrive at a 15.5 score when all choices are discrete 1-5 …?
And if you notices the duality of impact functions of probability, and probability functions of impacts; you’re welcome. And if you noticed that on top of this all, you should also calculate (sic) for the cost (impact) of pre-emptive, detective, corrective etc. measures, and the chances of their partial or full (in)effectiveness, in a mesh of cause and effect.
Do you use Impact X Chance to establish severity of risks? Guessed so. But unless you take the whole continuous (!) two-dimensional landscape of every risk into account, you’re gonna fail with certainty.
Do you compare relative risks by their combined scores? Yeah, that indeed was the whole purpose of your exercise. But you failed already on so many points, the results are both literally and figuratively ridiculous
And you continue by considering a ‘15.5’ risk to be worse or higher than some ‘15.4’ risk….

And you don’t consider the enormous mesh of causes and effects (just one by one, or per single event only) with all sorts of feedback and feedforward loops, and the mesh of ‘preventative’, detective and corrective mitigating measures in between, all with their distinct cost(impact!)s, mutual reliance, reinforcements or and other influences, all with their inefficiencies and ineffectiveness (sic) levels – in percentages? In number of incident elements caught and missed?

We may continue. But it’ll lead to more of the same; you’re fooling yourself, and fooling decision makers. Didn’t know that that was in your job description. What would you think would happen if the decision makers would find out?
And oh yes they will! You lead them astray so much, that they will find (you) out about plain wrong negative impact times frequency totals in Write-Offs, and when (not if) they’ll dig deeper, find quite a lot of unnecessary, inefficient and ineffective Risk Mitigation Measures Overhead Cost.

Is there another way? Yes of course.
But it’s not easy. It takes the European (vis-à-vis the wrongly dubbed Anglo-Saxon) approach where the focus is not on data but on qualitative scenarios. As with data, these can be had externally, or internally from experience and insight. As with data, external inputs can be of doubtful relevance and fit. As with data, internal input may (in case of data: will!) be (much) too limited to work with. And yes, going through the motions to determine some risk on all four areas (external vs. internal, data vs. scenario) and finding some gross common denominator, one can get a balanced view on things. But it’ll be balanced over four erroneous outcomes; way to go!
If the outcomes will be understood at all. Value At Risk being the case in point, that would better be called Amount of Company Value Not Being Lost At Some Random Probability. Or so, depending on your working definition and working understanding of VaR…

The only solution seems to be to stop using a quantitative approach and switch to a radical qualitative approach. This may be awkward, but quantities are just so much too weak to describe reality that they are a fly in the face fraud.
And indeed, we we don’t know how to do organisation-wide qualitative risk analysis and management let alone how to do it for meso- and macro-levels, let alone how to communicate, understand and argue about one risk to the next. But we have nothing else that can work; we must. And, it may fit better with the way humans, the human brains, work, with all their psychological ‘flaws’ (quod non!) in the management of risks. Kahnemann, remember? Well, maybe to align with what our brains have gotten used to handle over the aeons, from the savannah to our latter-day deserts of cubicle offices may be the best way to go. And why not? Do you really want to argue that today’s offices differ from hunter-gatherer tribes batteling the elements, predators and prey, and other tribes?

So, qualitative management of risk it is. Any takers?

Maverisk / Étoiles du Nord