Control, not privacy


In the discussions re privacy, there seems to be only two alternatives: Absolute privacy, with any individual holding complete, total and continuous control over who gets to see (not take in) any data point that may be, even in the remotest of ways, be recombined into anything useful for anyone – or Absolutely no privacy, everything being considered lost anyway and all one’s data being out there somewhere.

Which creates not some binary future state, but a bandwidth on which we should be able to choose. Because it is not privacy that people are concerned about, but the loss of control once data slips out of your hands. That is why everyone is so concerned when TLAs are found out to collect so much data on everyone (they have tried, and partially succeeeded, already for decades; nottoo many people were concerned) or when (not if) yet another credit card data processor looses some backup tapes. It is not the privacy in itself (one passes off the credit card number (and CVC) happily to just any unchecked device), it is not being able to get the data ‘back’, not being able to track the use in all the enormous amount of systems one knows is out there handling your data. Those systems ranging all the way from the benign to the crooked, always …

What we should have, then, is some mechanism by which we would be able to transparently and trasitively (sic) release the data we must (in order to get some service in return), and be rewarded for any data other parties earn money with (they are using your resource!), and not more. We’ll have control back; all we wanted.
Anything else, and we’ll end up in one of both extremes. To our own extreme detriment.

Inter faces


[Educational institute x 3, campus Free University, Amsterdam]

When sleeping over problems, one often comes up with solutions that both are real and so all-encompassing that they’ll need much elaboration before being applicable in a nimble way.
This one was/is on information security, again. Recall the ‘discussions’ I posted some days ago about (industrial) process control versus administrative control? Well, I’ve some more elements for a grand new scheme now.

It struck me that the operators at the (chemical) plant control room, are the ones with the dashboards. Not necessarily their managers. Nor their manager managers, etc. What if instead of some machine equipment, we plug in hoomans into the whole ..? And let them interact like the übercomplex ‘machines’ that they are, doing their (administrative / service) thing that they (want to?) do. All the way to the point where we have no equipment, just humans (with tools, by the way, but those would be under ‘complete’ control of the ones using them so are just extensions of them). One ‘manager’ could then control quite a lot; have a huge span of control…

If, big if, if only the manager would understand the overall ‘process’ well enough, that is, to be able to work with the dashboard then provided. Just Continuous Monitoring as a job, not much more (one would have 2nd- and/or 3rd ‘lines of control’ (ugh for the expression) to fix deviations, do planned maintenance, etc.). Probably not. But one can still dream; organizations would be flat without chaos breaking out.

And if you’d say it would be impossible altogether, have a look at your SOC/NOC room where techies monitor IT network traffic and systems’ health. They even have some room to correct..! And they are aware, monitor, the appropriateness of what flows over the lines, having professional pride in catching un(machine)detected patterns of irregularity possibly being break-in/break-out attempts. And they leave the content for what it is, that’s for the experts, the users themselves, to understand and monitor if only they would.
Why wouldn’t other ‘managers’ copy the idea to their own desk? No, they don’t, yet. They get Reports that they hardly read, because someone else had thought for them in determining what should be in there. And reports aren’t continuous. Walking around is, but would (rightly) be viewed as micromanagement and a bit too much given the non-continuous nature of what modern knowledge workers do. So, we’ll have to define some gauges that are monitored semi-continuously.

Now, a picture again to refresh:

[Westpunt, Curaçao]

But with the measurements not influencing the primary production ..! To let knowledge workers do their thing, in mutual cooperation without interference by some busybody thinking (s)he knows better for no reason whatsoever.
Through which we note that the use of dashboards should not, must not, start with ‘Board’s or similar utterly superfluous governance levels. Governance is for governments. As it is ‘implemented’ in larger organizations, it doesn’t look like kindergarten kids playing Important for nothing. The use of dashboards should start from the bottom, and should include quite rigorous (but not merely by the numbers) pruning of both middle-level ‘managers’ (keep the good ones, i.e., not the ones that are only expert in hanging on! otherwise you spell death), and all sorts of groupie secondary and third-line staff.

Which will only work if you haven’t yet driven out all the knowledge workers by dumbing down their work into ‘processes’ and ‘procedures’ that are bereft of any productive (sic) rationale. And if you haven’t driven out all the actual managers and are left with the deadwood that is expert only in toeing the line or rather, sitting dead still in their place.

Now have a look back also on how you do information security. Wouldn’t the little bit of tuning you may need to do, be focused best on the very shop floor level that go into the ‘industrial’ process as inputs? You would only have to informationsecure anything that would not be controlled ‘automatically’, innate in the humans that handle the information (and data; we’ll discuss later). Leave infosec mostly with them, with support concentrated at an infosec department maybe, and have managers monitor it only to the extent necessary.

And, by extension, the same would go for risk management altogether. Wouldn’t this deliver a much more lean and mean org structure than the top-down approaches that lead to such massive counterproductive overhead as we see today? With the very first-line staff that would need all the freedom feasible to be productive (the managers and rest of the overhead, aren’t, very very maybe only indirectly but certainly not worth their current income levels!) then not having to prove their innocence… See Menno Lanting’s blog for details…
Org structures have become more diamond- than pyramid-shaped; which is plain wrong for effectiveness and efficiency…

So let’s cut the cr.p and manage the interfaces, vertically, and horizontally, noting the faces part; human. An art maybe, but better than the current nonsense…

Predictions 2014; little update


[Paris La Defense; Metropolis-like]

Oh, a few notes to add to the Predictions 2014 blog:
Just saw that Smart, Cloud, Analytics and Mobile may abbreviate quite well… T not fitting in there…
Forrester (-‘16) rightly adds a rethink of ‘trust’ and ‘identity’
Gartner has ‘software defined everything’ and ‘3D printing’ in the mix. The former, Forrester has as well, when reading and recombining what they have (and G’s predictions may be regrouped as well, to form the F’s list, or the SCAM-T list).
Both don’t have Analytics, oddly enough. But via @duivestein, too, a good intro into Things.

Maybe we’d include Trust, Identity, Things abbreviated, before SCAM.
Back to predicting, I expect to see some hitherto unseen early signals re the dissolution of the absolute governance power of geography-bound countries / nation-states, and the nascence of (more) virtual communities with some form of barriers. Remember what I dropped as a note below on Bitcoin; I expect to see more of those in(ter)ventions. Interesting to see how the power balances (multiple) may play out: Will some developments be kidnapped / abused by states in a global (cold) cyberwar e.g., via or in the UN; how will the developments resist, and what will hold or not ..? This, too, may not be a thing for 2014 only (it may take decades!), but we’ll see some buds spring up next year.

That’s all. For now. Whether that’s Now, is another discussion entirely.

Check (out Bitcoin) please


[This was my work place, once, for a short while. Yes, actually it was.]

Just a note, on an idea that needs to be spread: When bitcoin makes it, any currency can make it. Seniorage by historic derelicts called geography-bound ‘countries’, may wane. The Community may take over, here, too. May want to speed up my reading of Empire and Multitude – critically, as I certainly don’t agree with everything, out of experience so far and out of principle…

Predictions 2014

Already somewhere below, I noted that the Analytics part of SMAC(T) may need to be rephrased. Already now, I’m unsure whether to do that or just leave it unchanged. What I didn’t yet do, was to opine on the other elements so often put together.
First, a picture.


[Casa de Música Porto, for the chaotic structure of the future]

Now then:
Social everything: Yeah, yeah, of course there will be news. The decline of Fubbuck, etc. But will we see actual breakthrough hitherto unseen inventions of anything game-changingly new? I predict 2014 will be a pause year in which we’ll only see paradigm detailing and quite an improvement (sic) of the use of Social by medium- and larger sized enterprises. In somewhat innnovative ways, but nothing earth-shattering.

Mobile everything: The same, hopefully through the much-wanted huge improvements in cross-platform and cross-screensize compatibility and standardization. Which, too, would be refinement rather than absolutely unexpected New.

Analytics, we discussed, separately.

Cloud, ‘mehhh’ for theory, ‘hey how refreshing to be able to distinguish so clearly a good implementation’ in practice. Because that’s what we’ll see in 2014; cloud stuff deliberately done right. (Being deliberate, not by accident as it was in 2013!)

Things; The Internet Of ~, maybe, but in my view it’ll be too early. More like something for under the [Warning: European + derivative culture reference coming up] Christmas tree, to be played with in the year after.

Any other business?

Yes.

One with long odds: Clarity on the demise of “ERP” software. Of course, pre-2014 already the said administrative software, hardly ever used to its full potential but very often having been relegated into the bookkeeping role only, had been pushed away from the limelight into the back of the stage. But in 2014, we’ll see an acknowledgement of this, with consequences I cannot really predict very well – probably, all sorts of other software, more geared towards front-office functionality and integrating better architecturally with the bandwidth from there to the app/widget-world, will take over center stage.
[Update 2014 02 06: This link]

One with lesser odds: An enormous push for more information security, both at its operational, technical levels and upwards in renewal of structure (away from the stale, outdated ISO2700x sphere!) and inclusion of a more holistic approach (see some of my earlier posts, and probably some to come in the near future).
This will have a second leg in renewed interest in Business Continuity Management, not only by rule-based following of standards but also by more principle-based (sic) implementation of ISO 31000 (with all its drawbacks) throughout the business. If we can get our heads around the eradication of that ‘the business’ nonsense… and really integrate (continuity) risk-based management into general management, not needing too much 2nd or 3rd lines:

A final one: The deflation of TLD. The three lines don’t actually defend against anything but regulatory discovery of all that goes wrong in the business (from top to bottom and back again, there). As the previous prediction will already defend against actual mishaps, TLD will be shown to be emperor’s new clothes where lightning strikes. And oh will it strike; frappez, frappez toujours! it will and I hope. All those busybodies doing busywork, I just can’t stand it. The utter denouncement of humanity and human dignity …!

So, there you have it again; SMAC(T) weighed, and three more. Who make some interesting stuff available when I hit (or overshoot) five or more out of eight ..?

To close, another picture…

[Serralves, Porto – rainy outlook]

Interesting life, or dissolution

Some lament the cease-and-desist against 23andMe’s personal DNA profiling kit. I don’t, too much.


[Of course, a picture. Belém, Portugal: Into the Great Unknown, quite possibly never to return (in the olden days; for seamen this tower statistically would very probably be the last thing they would ever see of their homeland)]

I can understand that some may want their personal genetic footprint, e.g., when one already has an inkling there may be some bad omens in them but these can be undone by (hopefully not too severe) lifestyle changes. Fair enough.

But already in the ‘not too severe’, there’s a catch.
From history (including ‘worthwhile’ history i.e. folk tale, worthwhile for its life lessons beyond data points on kings and queens that are boring and mostly irrelevant for us today) we learn only the omens that have panned out, not the maybe many more ones that lead to nothing.
So, once one knows one’s personal DNA profile, and if (not when) one would from that know the increases, however slight (sic), in probabilities of all the possible diseases that one could, statistically!, get, one could, theoretically, change one’s lifestyle so pervasively that the chance (!) of outbreak of some disease or ailment could be lowered. By what amount, one is (sic) unsure. For how long one can postpone the ‘inevitable’, same. What to do when life style changes conflict for one future disease as opposed to the other, unknown. That one will die in the end, fact.

And, what would you want from life ..? Even living in the most ‘preventative’ way may not help; one is quite completely unsure about that. What does one sacrifice ..? All life’s pleasures, all one’s freedom ..!
Of course the bigger stupidities that are so clearly unhealthy can be done without.
But where to draw the line? Because preventative behaviour also includes the little things one can do without with some effort; but bad stuff in moderation can be good against some other health risk or one would revert to living on artificial ingredients only (e.g., not wine but only the healthy particles in it; who knows what overdoses, who knows how much is still healthy – re-read the story of Job’s pancreas and that actor that got pancreas problems by Job’s fruitarian diet –, who knows whether artifical ingredients work the same as natural stuff maybe only in combination with other neutral or ‘bad’ stuff… and on and on…)
So one misses the pleasures of life and also is unsure about the benefits.

And would you want to live a miserable life, possibly a little or somewhat longer than a full and enjoyable one? Is that what life is for? Or is one to enjoy life, in moderation preventing the obvious no-no’s, and through that be much happier than otherwise – as if happiness hasn’t been demonstrated to be one darn good preventative medicine in the first place. One might actually live longer by giving everything a little (…) try!
Plus, at what age would one want to change one’s life? Does one bother one’s spouse with all the austerity (probably) implied? What if the life you had, bound you together? Get a divorce, be even more miserable, etc..? And would you force your children to life such a miserable life (certainly compared to the non-believers they play with)? Where does abuse start?

And, the fullness of life is to be cherished and enjoyed. Risks, the fundamental unknow of the future, makes it worthwhile. An angst-driven panicked effort to eradicate all risks, will never succeed. Be reasonable and embrace the risks you can bare. Death will not be a risk but a certainty, and with moderate joy in life, one circumnavigates the stupid mistakes while having a fun trip.

And if you would actually know all that is going to happen to you (otherwise, you could not predict which diseases you’d get ..! think that one through, it works out that way), why live at all? You’d be using up resources without any benefit, you will have lived your life already. Your life would dissolve ..!

So, I have quite some questions that may be answered one by one, but in the end ‘One shouldn’t count arguments, one should weigh them’ (Cicero). Genome testing: ethically limited demand.
[Written up while being generally healthy, enjoying in moderation some, not even ‘all’, pleasures of life.]

Control administration(s)

Before I forget: Some work has been done indeed on translating the industrial process (control) model to the administrative world. ACS’s KAD+ model (in Dutch) is an excellent example – especially the original KAD model at operational level that seems unsupported now. Maybe they are just a bit too far ahead of the curve, too clean-cut, to have found the traction they deserve.

That’s all, folks!
For now. Here’s a picture for your viewing pleasure:

[Alhambra, Granada]
Yeah, next up, some seriously long form blog again.

Control industry

First, a picture for your viewing pleasure; you’ll need it:

[Baltimore inner harbour; rec area]

As a backlogged item, I was to give a little pointer to the design of control in (process-oriented!) industry, from which ‘we’ in the administrative world have taken some clues like sorcerer’s apprentices without due and proper translation and without taking the pitfalls of our botched translation job into account.

To start with, a little overview of the basics of how an industrial process (e.g., mixing paint, or medicine) is done, at the factory floor:

In which we see the main process as a (near- or complete) mathematical function of the input vector (i.e., multiple input categories) continuously (sic) resulting in the output vector which is supposed to come as close to a desired output as possible, continuously, on the parameters that matter. The parameters that matter, and the inputs, are measured by establishing values for parameters that we can actually measure, continuously (sic). With the inputs and outputs of course including secondary and tertiary ‘products’ like waste, heat, etc., and with all elements not being picture perfect but with varying variations off set values (the measuring devices and e.g. process hardware, also will have a fluctuating noise factor).
With the input vector being measured via the feedforward loop (control before anything might deviate) and the output vector being measured through the feedback loop (control by corrective actions, either tuning the process (recipe) or, more commonly, tuning the inputs). And the control function being the (near- or complete) mathematical derivative of the transformation function.
And all measurements being seen as signals; appropriately, as they concern continuous feeds of data.

That’s all, folks. There’s nothing more to it … Unless you consider the humongous number of inputs, outputs and fluctuations possible in all that can be measured – and not. In all elements, disturbances may occur, varying in time. So, you get the typical control room pictures from e.g., oil refineries and nuclear plants.
But there’s a bit more to it. On top of the control loop, secondary (‘tactical’, compared to the ‘operational’ level of which the simple picture speaks) control loop(s) may be stacked that e.g. may ‘decide’ which recipe to use for which desired output (think fuel grades at a refinery), and tertiary (‘strategic’ ..? Or would we reserve that for discrete whole new plants ..?). And there’s the gauges, meters and alarm lights in a dizzying array and display of the complexity of the main transformation function – the transformation function can be very complex! If pictured as a flow chart, it may easily have many tens if not hundreds of all sorts of (direct or time-delayed!) feedforward and feedback loops in itself. Now picture how the internals of that are displayed by measurement instruments…

Let’s put in another picture to freshen up your wiring a little:

[Baltimore, too; part of the business district]

Now then, we seem to have taken over the principles of these control designs into the administrative realm. Which may all be good, as it would be quite appropriate re-use of stuff that has proven to work quite soundly in the industrial process world with all its (physical, quality) risks.
But as latter-day newly trade trained practitioners, we seem to have not considered that there are some fundamental differences between the industrial process world and our bookkeeping world.

One striking difference is that the industrial process world governs continuous processes, with mostly linear (or understandable non-linear) transformation and control functions. Even in the industrial world, non-linearity but also non-continuous (i.e., discrete, in the mathematical sense) signals (sic) cause trouble, runaway processes and process deviations, etc.; these push the limits of the (continuous-, duh)control abilities.
Wouldn’t it be wise, then, if we had taken better care when making a weak shadow copy of the industrial control principles into the discrete administrative world …? Discrete, because even when masses of data points are available, they’re infinitely discrete as compared to continuous signals (that they sometimes were envisaged to represent)? Where was the cross-over from administering basic process / production data to administrating the derivative control measurements, and/or the switch from continous signals captured by sampling maybe (with reconstructability of the original signal being ensured by Shannon’s and other’s theories ..!!), to just discrete sampling without even an attempt to reconstruct(ability) of the original signals?

So we’re left with vastly un- or very sloppily controlled administrative ‘processes’, with major parts of ‘our’ processes being out of our scope of control (as is witnessed by the financial industry’s meltdown of 2007– ..!), non-linear, non-continuous, debilitatingly complex, erroneously governed/controlled (in fact, quod non) in haphazard fashion by all sorts of partial controller (groups) all with their own objectives, varying overwhelming lack of actual ‘process’ knowledge, etc.

Just sayin’. If you would have a usable (!) pointer to literature where the industrial control loop principles were carefully (sic) paradigm-transformed for use in administrative processes, I would be very grateful to hear from you.
And otherwise, I’d like to hear from you, too, for I fear it’ll be a silent time…

Interlude: Sing ularity / along

The thought just popped up: What if we’re all already beyond the singularity point, and the transient intelligence of human life has already taken over ..?
No-one is capable of changing the world’s affairs anymore, and it would take all people together to get that done, but getting all people together (including motivating them to band together, to their advantage) will result in all people just doing what they already do.
Since the first 90% of human behaviour is already determined by ultimately (!) self-interest, uncosciously deciding what’s best as fits with the world’s turning as it is today, and the last 10% would then also be captured in conscious deliberation towards rational contribution towards whatever purpose the world’s turning leaves us – which is exactly the play room that the autonomous transient intelligence would leave us.
Just look at how we behave in society; following rules that put us down, queueing up in traffic, standing in line at the shops, working in offices, etc., all tagging along stuck in a rut.
Now, we let algorithms take over the boring work stuff, leaving ever less for us to do or excel in. Even ‘creative’ work is cornered by developments of understanding creativity and shrinking it ever more.

[Ronda, Spain]

So, the current world can already be interpreted as going along its own course and direction, only leaving some wiggle room for the sully us. At least there we have a semi-happy scenario for past the Singularity – but the transient intelligence might improve itself unnoticably to a state where humans are no longer required and (as they already are: l’enfer, c’est les autres; les humains) a nuisance to be gotten rid of. Be warned. Be creative or offed.

First Predictions 2014

[Unfamiliarly, from the West]

What’s up, 2014?

The end is nigh, of 2013. Can we predict what the big business / infosec hype of 2014 will be ..?
No. There’s no predicting the unknown. The somewhat-known will not stand out enough. The known… boring!

The knows are the fall of Fubbuck, maybe Tvitter (both to be replaced by the WeChat’s and hopefully Tumblr’s of this world; will Vine and Snapchat take over?), cloud, BYOD/flexwork, etc.
SMAC: Social, Mobile, Analytics, Cloud. ViNT by Sogeti adds a T of Things.

The Things part, I’m unsure about. Yes, for the long run (i.e., 2-5 years) we will definitely see an explosion. But next year already? It’s the infancy of a sine wave, taking off slowly.

So, my prediction is that the thing we’ll all be talking about as the next thing in 2014, would be … People versus Algorithms.
This was pointed out by some #Coney guy(s), with some lead links elsewhere. But algorithms will not conquer the world in one swallow. Rather, we will see both an increase in the use of algorithms for partial (at most!) data analytics, to support TLA-style use of ‘big’ data both in public and private environments – but also a major development of the People component in tha analysis, a wave of development of specialized functions, methodology and tools, re the human pattern detection and interpretation parts of analytics.

Plus, then a more clear picture of how people and algorithms fit together, as function, profession(s), etc., with spin-off everywhere e.g., the development of a better understanding of how the brain works, how humans work (produce / operate), how to describe the purpose of life. On our way to the Singularity, and Beyond!

Maverisk / Étoiles du Nord