Security StrategiesThis newsletter is sponsored by PacketeerNetwork World's Security Strategies Newsletter, 09/20/07CSIRT Management: Problem-tracking softwareBy M. E. KabayAs I mentioned in my last column, I am presenting three articles (this is No. 2) based on the work of some of my graduate students during class discussions in a course on computer security incident response team (CSIRT) management. What follows is another edited segment based on a summary written by students Mani Akella and Rick Tuttle. Today’s topic is help desk software. * * *
Based on group postings, the most-used software for problem reporting and tracking is BMC Remedy Service Management by a fair margin. The group reported using other software, including Numara Track-It!, Support Magic, Help Box, Heat Service and Support, and Open Source Ticket Request System (OTRS). However, cohort members reported many issues with Remedy that make using it difficult at times. Part of the problem seems to be the number of interface options available for the product - normally a Good Thing. Some Remedy implementations lack a Web interface, limiting end-user input. Other postings decried the lack of an efficient GUI design; organizations have to customize their installation to fit their individual needs. One can interpret a lack of an efficient GUI design coupled with the capability to customize as both a feature and a flaw. It is a valuable feature because that BMC is responding to the wide variation in individual organizations’ needs; it is a challenge to create a single interface that meets everyone’s preferences. However, it is a flaw for small organizations that lack the workforce, ability, or desire to customize commercial off-the-shelf software, thus reducing Remedy’s marketability. One class member suggested that BMC could improve its usability and product acceptance by providing three templates: * Complete (today’s default) An interesting sub-discussion focused on a case where one IT manager disbanded the help desk after implementing user-facing help desk software. The manager’s expectation was that each user would use the software to report issues. He expected the software’s built-in triage function to route the issues to appropriate support teams. The manager believed that both users and IT staff would monitor system reports to track status. This perception eliminated effective service to those users who could not or would not use the software. This viewpoint also provided no capability for dynamic re-prioritization or a method to correct routing of misreported issues. * * * MK adds: The case of the disappearing help desk should remind readers to _test_ new approaches to operational problems before implementing them in production. The hopeful manager could have avoided some of the problems described above by running a pilot project with a few users instead of replacing the help desk outright. Preliminary findings could have prevented the fiasco and prevented a loss of credibility for the team. In the third and last part of this series, Mani and Rick summarize some interesting issues about triage and politics. * * * Mani Akella , CISSP, is President and Technical Director at Consultantgurus, a Bridgewater, N.J., organization focused on providing Information Assurance and Surveillance services to its clients. He can be reached via e-mail. His personal blog is here. Rick Tuttle is a project manager at Sasol North America Inc., a Houston chemical manufacturing company. He manages desktop software deployment, including security patches and updates, and supports the company’s business continuity and compliance efforts. Rick can be reached by e-mail.
|
Contact the author: M. E. Kabay, Ph.D., CISSP-ISSMP, is Associate Professor of Information Assurance and CTO of the School of Graduate Studies at Norwich University in Northfield, Vt. Mich can be reached by e-mail and his Web site. This newsletter is sponsored by PacketeerARCHIVEArchive of the Security Strategies Newsletter. BONUS FEATUREIT PRODUCT RESEARCH AT YOUR FINGERTIPS Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details. PRINT SUBSCRIPTIONS AVAILABLE International subscribers, click here. SUBSCRIPTION SERVICESTo subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here. This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription. Advertising information: Write to Associate Publisher Online Susan Cardoza Network World, Inc., 118 Turnpike Road, Southborough, MA 01772 Copyright Network World, Inc., 2007 |
No comments:
Post a Comment