Thursday, November 17, 2011

IBM Security Portfolio

Ever wanted a quick, no nonsense explanation of what IBM security products are and where they came from? Well, here it is:

  • ISS – network and host security (X-Force acquisition)
  • TIM – identity management (access360 acquisition)
  • TAMesso – desktop single sign on (Encentuate acquisition)
  • TFIM – federation of access (homegrown)
  • TDI – data transformation (Metamerge acquisition)
  • TAMeb – web app access control (Dascom acquisition)
  • TSIEM – security event management (Q1 Lab acquisition)
  • TCIM – compliance dashboard (Consul Risk Management acquisition)
  • DataPower – XML gateway
  • i2 – crime prevention
  • BigFix – patch management
  • Guardium – database security
  • Openpages – governance risk and compliance
  • Algorithmics – financial risk management

Alex Ivkin is a senior IT Security Architect with a focus in Identity and Access Management at Prolifics. Mr. Ivkin has worked with executive stakeholders in large and small organizations to help drive security initiatives. He has helped companies succeed in attaining regulatory compliance, improving business operations and securing enterprise infrastructure. Mr. Ivkin has achieved the highest levels of certification with several major Identity Management vendors and holds the CISSP designation. He is also a speaker at various conferences and an active member of several user communities.

Monday, October 24, 2011

Modernization Project Using IBM Case Manager

Business Application:
Service Purchase Plan Process

Business Challenge:
Prolifics is currently involved in a project at a large public retirement system. In an effort to modernize its infrastructure, the company wanted to ensure that the architecture is interoperable and robust by proving architecturally-significant functionality rather than demonstrate complete business functionality. Equally important is the need for the system to demonstrate that it is agile enough to be modified (e.g. associated business processes and rules) significantly faster than its UPS (Unified Pension System) counterpart. In addition, the Project must demonstrate that straight-through processing is achievable by allowing exception-free instances of processes to execute to completion without any manual intervention.

IBM Case Manager provides an installation framework where you can install IBM Case Manager in a distributed architecture where IBM Case Manager is installed on a separate system from FileNet P8. The IBM Case Manager installation program installs Case Manager Builder, Case Manager Client, the IBM Case Manager administration client, and the IBM Case Manager API.

The distributed system architecture is ideal for large production environments. The following graphic shows the typical architecture of IBM Case Manager in a distributed environment and the features that IBM Case Manager can integrate with.


Solution:
  • Using an existing business process, Purchase Service Request, we designed and built the environment, which will be established on a VM configuration. This includes the installation of the requisite IBM Case Management, ILOG JRules, Lotus Forms, Datacap and Thunderhead software. Here is an example of the process flow and how the difference technologies in Case Manager are leveraged:
  • Case Builder is used for Business Process Modeling and configuring workflows
  • ILOG Rules Studio authors and tests rules in JRules that are harvested from the existing UPS system
  • Develop and integrate Lotus Forms user interfaces
  • Configure a Datacap batch class and release scripts to load documents into FileNet
  • Define and generate XML payloads containing the data necessary for the production of member correspondence
  • Create test data, test cases and validation of the testing results
  • Functional and integration testing of the ICM, ILOG JRules, Lotus Forms, Datacap and Thunderhead application components
Value Proposition:
The company supports Member Service Request transactions online and risk-based quality control, giving them the ability to shorten cycle times, improve service levels, and mitigate risks across their Service Processes. This enables increased throughput and capacity with existing resources and eliminates costs associated with document shipping, inbound document processing and operations processes.

How does IBM Case Manager help our customer?
  • Provides knowledge workers with a contextual environment and 360-degree case view
  • Helps knowledge workers create and participate in ad hoc and structured workflows
  • Delivers real-time case metrics and integrated sentiment and content analyses to streamline workloads and remediate obstacles
  • Offers a business–focused design that includes interview-style interfaces for case construction and the ability to capture industry best practices in templates
  • Facilitates sophisticated decision management using an integrated business rules management approach, which uses automation and dynamic business rules to simplify assessment and payment processes and easily respond to ever-changing policies and legislation
  • Simplifies collaboration and boosts productivity through social software and communication

Key benefits IBM Case Manager Solution:
  • Program efficacy: achieve better outcomes and results
  • Employee and case worker effectiveness: handle more cases with fewer resources
  • Optimal case outcomes: improve safety, cut costs and increase revenue
  • Process efficiency: leverage automation wherever possible and focus on exceptions
  • Compliance and visibility: manage risk and achieve compliance cost-efficiently

Khaled Moawad is a business consultant with 15+ years of experience in the field of IT. He has participated in large IT projects at multinational organizations in different fields. Khaled's business consulting experience is in IBM Enterprise Content Management, IBM FileNet, IBM Advanced Case Manager, and Lombardi Business Process Management. Khaled has excellent analytical and wide application-based process re-engineering skills, including project management expertise. During his career, he has gained a wealth of experience throughout all stages of pre-sales, implementation, support, software development and project management.

Self Service Applications and Case Management

In today’s electronic world, any organization that serves its customers should have a means of communication to provide higher levels of service. Gone are those days where customers use to make phone calls or visit a customer service center to get their work done. Today customers are using electronic mediums like PCs, mobile devices, tablets, kiosks, to perform their tasks. Need therefore arises to build self service applications that are intuitive and time sensitive to information that customers need.

IBM Case Manager is an enterprise case management system that provides a 360 degree view of any case that is being worked upon. Information flow to and from the case management system can be from multiple sources. Case Management systems are predominantly viewed as an internal application to be used by knowledge workers and the management in an organization. Customers normally do not have access Case Management system. In order to provide a seamless integration between the customers and the Case Management system a self service application is required. Self Service Applications could be internet enabled web applications that have seamless connection to the Case Management System. The IBM Case Manager provides industry standard interfaces to enable such Self Service Applications to communicate with the Cases and their data.

Case Study:
Our customer, a large city organization, is in the process of modernizing its systems to provide better services to its members. As part of this Modernization effort, Prolifics is helping this customer in building an enterprise case management solution leveraging IBM Lotus Forms to capture the member inputs in electronic format and submit it to IBM Case Manager for further processing. Members can also view the status of the case using the Self Service Portal deployed in IBM WebSphere.

Benefits of Member Services Self Service Application:
Members can log on to submit their request over the web either from PC or other web enabled devices like smart phones, tablets, touch pads, etc.

Members can have a 360 degree view of their service requests and collaborate with their service provider for processing their requests

The turnaround time for processing member service requests is reduced from weeks (using paper request) to few days (using electronic forms)

Technologies Used:
IBM Case Manager 5.0, IBM Lotus Forms, IBM ILOG JRules Engine, IBM WebSphere Application Server, IBM Cognos Now, IBM FileNet P8 5.0 Platform, DB2, Red Hat Linux

Kiru Veerappan is a senior ECM Consultant with 15 years of Software Development and Management experience. He has been working on Enterprise Content Management and Business Process Management solutions for more than 10 years. He has created unique solutions while mentoring team members in solving real business issues in a timely and cost effective manner using the latest technologies. He believes in interacting with clients not just to deliver a piece of software but acting as an agent for change, delivering ideas while gathering requirements and providing real knowledge transfer. He has specialized in Content and Workflow Management solutions using IBM FileNet suite of products.

Thursday, September 29, 2011

Choosing a Messaging System: WebSphere MQ vs. WebSphere Application Server Service Integration Bus

A question that sometimes comes up in our architecture whiteboarding sessions is about the different messaging strategies that are available in Websphere Application Server. IBM developerWorks has now published a great article detailing the differences between WebSphere MQ and the Service Integration Bus that comes with WebSphere Application Server. Check it out by clicking here.

Thursday, September 15, 2011

Cyber Security in High Demand

The old adage says: "keep your friends close, but your enemies closer". In this day and age, the IT department of your organization does not have to worry about the second part. The enemies are already at the gates. And keeping them out is an increasingly challenging task.

A recent study sponsored by Juniper Networks showed that not only there has been a dramatic rise in the number of security breaches in the past year, but the targets have also gotten bigger. The CIA, the FBI, the U.S. Senate, and various state police agencies had their systems under attack. In the first half of 2011 security and data breaches have cost U.S. enterprises almost $96 billion. At this rate the cost for the whole 2011 will be almost twice as much as it was in all of 2010. Consider the fact that 2010 saw 90% of businesses compromised with least one security breach. More than 50% of the compromised businesses had at least two breaches.

Another problem is that "the gates", where the enemies are trying to get through, are everywhere now. The entry points are in the software used by employees. They are in files, emails, web apps, web sites, databases, in everything that is on the information highway. The number of incidents related to malware went up from 4 million in the first quarter of 2010 to 6 million in the first quarter of 2011. It is expected that last year's record $63 billion that companies spent on security will be $75.6 billion in 2011.

As the study showed, the enemies get smarter and the attacks get more complicated in every year. Throw all your defenses up, get every firewall ready, the host and network intrusion protection and detection system, anti-virus, anti-malware, application firewalls and it will still be not enough, because the enemies are a step ahead. The solution? "Know yourself and know your enemy" (Sun Zhu, "Art of War"). Get the right security talent on board and use the right strategy.

The correct strategy, rooted in the governance, risk management and compliance methodology can go a long way. Consider the governance, a system by which an organization controls and directs security development, as a backbone of the approach to managing security and how it relates to the business (http://www.cert.org/governance/ges.html). Then, focus on the compliance and regulations, a key to proactive defenses and enforced regulations of a company's behavior as it pertains to security for a specific nature of the business. Governance is strategic, while compliance is tactical and specific. Addressing compliance and security regulations allows business to focus on particular challenges and vulnerabilities specific to the business type and the vertical it operates in. Finally, adjust risk management, a set of technologies that address day-to-day security work, and include mature components of security such as penetration testing, application security analysis, firewalls and intrusion prevention systems. The success of the security strategy depends on the attention to all three components.

The talent is a different thing. With the increase in the demand for the security experts, in response to the increased attacks, the security talent is becoming more expensive and harder to find. So far, the number of college students with who focus on cyber-security has not been keeping up with the demand. There are even less opportunities in finding experienced security consultants who are up to par with the criminal masterminds of the security underground. Security may be on the radar for around 1.9 million people, but there are only around 346,000 fully dedicated security professionals.

There are, however, security consulting firms, like Prolifics Security Practice (http://www.prolifics.com/business-solutions-security.htm) that can help you both with the talent and the strategy. They bring the best and the brightest security personnel on site to analyze, architect, develop and implement proper defenses and policies to address modern security threats. They help set up proper strategy, so you protect the flanks, tie up the loose ends and govern smartly.

With the increasing number and the caliber of the security breaches you cannot afford to sit around and wait. Find what others are doing, go to conferences, ask consultants, bring help, but do something, because enemies are at the gate.

If you want to read more on the recent rise of the cyber attacks look here: http://articles.latimes.com/2011/jul/05/business/la-fi-hacking-security-20110705

Prolifics will be discussing cyber security in greater depth as a sponsor and speaker at the upcoming Cyber Security for Energy Delivery Conference on September 27-28. The event takes place in San Jose, CA and brings together major utility and asset owners and key government agencies from across North America. I will be co-speaking with IBM at this conference. With experience providing security solutions for the energy and utilities industry, we will be sharing our security solutions and recent case studies around ID and password management, single sign-on, directory services, Web-based authorization, federation and other areas. For more information on the Cyber Security for Energy Delivery conference, please click here.

Alex Ivkin is a senior IT Security Architect with a focus in Identity and Access Management at Prolifics. Mr. Ivkin has worked with executive stakeholders in large and small organizations to help drive security initiatives. He has helped companies succeed in attaining regulatory compliance, improving business operations and securing enterprise infrastructure. Mr. Ivkin has achieved the highest levels of certification with several major Identity Management vendors and holds the CISSP designation. He is also a speaker at various conferences and an active member of several user communities.

Tuesday, August 16, 2011

Test Automation for SAP Packaged Applications

SAP Packaged Applications allow you to rapidly configure and customize business processes as your environment changes. To ensure the quality, performance and reliability of these applications, you need a sophisticated testing solution that can be configured and customized as quickly as your SAP landscape. In this article, we will show you how you can use your IBM® Rational® Functional Tester (RFT) toolset along with tools from IBM Ready-for-Rational partner, Arsin.

In this blog entry, I will discuss:
  • A structured approach to SAP testing

  • SAP current test automation paradigm and its challenges

  • The need for a new solution for SAP test automation

  • How Arsin Packaged Test Automation for SAP integrated with IBM Rational Functional Tester helps address these challenges

We will examine the functionality of Effecta Validation Engine, in conjunction with RFT, to collect the test requirements, define and build the test cases, build the test procedures, and execute and analyze the reports. Use of RFT and Arsin's tools enables you to greatly expand your test scope, significantly compress your test schedule, and reduce testing costs.


A Structured Approach to SAP Testing
SAP implementations pose some of the most intriguing and difficult challenges in the QA universe. The thickly netted system is extremely integrated and is typically linked to every business process in the enterprise. To tackle such an immense system, QA engineers must approach SAP applications with care.
With more than a decade of experience in testing SAP systems for a large client base in myriad industry verticals, we have developed a test maturity model assessment and improvement framework to bring about an organized and a structured approach to SAP testing. This framework has a three pronged approach, which offers process improvement, knowledge management, and test automation, as follows:

1. Process improvement. Process improvement deals with the assessment of the current Test Maturity Model and developing a plan to improve the Test Maturity Model to the next level and then implement it. A mature test process that has standardized templates, well-defined processes, clear protocols, and no bottlenecks provides for a complete and comprehensively tested SAP system. By comparing the current test maturity model with industry standards and identifying the gaps and focusing on them, test maturity can be improved.

2. Knowledge management. Knowledge management deals with institutionalizing QA knowledge collected over time. Traditional testing for SAP systems relies on the functional and technical consultants of the SAP system for subject matter expertise to deal with various instances. In this phase, test artifact libraries are built for critical business process for regression. The following test artifacts are documented:
  • Test Requirements

  • Test Cases

  • Test Procedures

3. Test automation. After test artifacts have been documented in the regression library during the knowledge management phase, they are ready to be automated. However, before they are automated, these test artifacts are analyzed for feasibility of automation, the effort required for automation, the frequency of use of the business process, and the longevity of the business. With automation, execution components are developed using RFT, and Validation Components are configured using Arsin's Effecta Validation Engine to execute them automatically.

The remainder of this discussion focuses on the test automation aspect of the Structured SAP Testing Approach. Our belief is that RFT, in conjunction with Arsin's Effecta Validation Engine, makes SAP testing thorough, comprehensive, easy, and cost effective.


Importance of Test Automation in SAP Implementations
The SAP landscape is continuously changing, as a result of changes to SAP modules from SAP, business process changes within the client’s company, changes to the system environment, changes to applications interfacing with SAP, and a multitude of regulatory compliance mandates.

In order to keep up with these changes, SAP systems must be thoroughly tested. With every change, there is a regression library of test cases that needs to be executed to ensure stability. Each test requires time and effort when executed manually; by comparison, automated test take a very small fraction of the time and effort to execute. Automation also helps makes most of the test assets reusable.


Current SAP Testing Solutions and their Limitations
The existing SAP testing model on the market today makes a very rudimentary use of automation, in terms of:

Validation: In most cases, user interface (UI) tools that are available are used to automate test execution, which is only about 25% of the total testing effort. Validation represents more than 75% of this effort, and scrubbing the data using UI test automation tools is difficult. A certain level of validation is possible through UI based test automation tools, however it takes a long time to script this validation and any change requires a lot of coding following the first implementation.

Data management: Traditionally, data used for testing is captured and maintained in spreadsheets. Searching and sorting through this data is difficult, as is maintaining the consistency of data across users and locations. This difficulty is compounded by ever increasing volumes of test data to be maintained. In addition, there is no intelligent association between SAP metadata and its corresponding test data.

Managing change: Changes to SAP implementations occur during reconfiguration or the addition of custom-built components (programs). In these situations, the scripts for automated test execution need to be changed regularly, which is difficult. Moreover, when using UI tools for automation, 75% of the effort needs to be constantly re-worked to keep up with the changes to the SAP system.


Addressing these Limitations
The limitations above described call for a new solution that can address these issues. We offer a complete and scalable testing solution that combines Arsin Effecta Validation Engine with IBM Rational Functional Tester.

By automating the validation of data, business processes, custom development and integrations across SAP applications, you can increase the quality of implementation, support multiple changes in their environment and mitigate business risks. Also, by eliminating manual testing you can avoid greater difficulties in production that ultimately impact the quality and performance of the business. Arsin’s Effecta Test Suite provides the benefits of a complete testing solution by automating impact analyses of changes, test data maintenance, test execution and validation.



Figure 1: Arsin Effecta Solution Architecture for testing SAP applications

Test Data Manager
Stores test data along with criteria in the Effecta database. Before executing an automated test, validity of test data is checked on the target system and system is automatically updated. If the test data no longer exists in the target system or cannot be reused, the data set update feature will help to refresh with new valid data.

Script Manager
Automatically enhances recorded scripts and eliminates need for customization. Script manager enables script less automation of IBM Rational Functional Tester.

Change Impact Manager
When changes occur in a system, Change Impact Manager automatically extracts affected objects and identifies test cases to be executed for regression testing. It also identifies objects being changed that don’t have test cases in the library.

Report Manager
Report Manager provides out-of-the-box reports for tracking test artifacts, development and test execution. Detailed test results pinpoint failed events in test case.

Test Manager
Effecta promotes reusability and repeatability with the following features:
- Ability to create Test Requirements and link them to Test Cases and development objects
- Ability to create Test Cases and link them to Test Requirements for coverage analysis
- Ability to create separate Test execution steps in the form of Test Procedures and link them to Test cases
- Defect management
- Dashboard for reporting and metrics

Validation Manager for Middleware
Simulates inbound messages at various data interchange points and validates outbound messages.
Automatically validates translations and mappings

Validation Manager for Transactional Systems
Validation Manager for Transactional Systems is a completely configurable, customizable and readily deployable validation library of components for various business processes. It significantly accelerates validation by automatically extracting the actual data created by transactions and comparing it with expected results. The Validation Manager is specifically designed to support SAP systems.

Validation Manager for BI
Tests Business Intelligence systems during initial implementation and during maintenance and support pack deployments. It also automates the validation of data loaded from multiple ERP and other systems. Provides sophisticated reporting including detailed results.

Conclusion
The benefits of using automation in SAP testing are abundant. Test automation, deployed with minimal effort, enables increased test coverage, which in turn reduces cycle time and enables efficient bug detection early in the development cycle. Since test automation is designed for reusability, routine tasks are eliminated and total cost of ownership is reduced. Test automation is far more precise and consistent, and features standardized reporting, enabling clear test analysis across the QA environment.

Sarat Addanki is the Vice President, ERP Practice. He has 18 years of experience in the ERP arena including design, development and testing of ERP implementations. He was part of a SAP Quality professionals team contributing to the design of SAP Test Accelerator TAO. He founded the ERP Division at Arsin, which focuses on developing frameworks and accelerators to ensure delivery excellence, reduce the overall cost of ownership and increase productivity in ERP implementations. The Test Accelerators he designed significantly improve the testing process, knowledge management and test automation. His division focuses on providing quality services for SAP, Oracle, PeopleSoft, Sterling, Retek and Middleware applications. His domain expertise ranges from Pharmaceutical Distribution, Hi-Tech, Manufacturing to Retail industries. He is a PMI (Project Management Institute) certified Project Management Professional (PMP). Sarat holds a bachelor's degree in Computer Science and Engineering from Osmania University, Hyderabad, India.

Friday, July 22, 2011

Panther Applications in Croatia

Brief History
When the Prolifics application development toolset came to the Croatian market in 1990, independent software vendor company Pardus (then 4-MATE) chose it to develop a back office application for a large retailer. The character-mode JAM5 application was running on an Intel-based UNIX system, with 60+ concurrent users, the largest in the region at that time.

Based on the successful experience with the Prolifics toolset, Pardus developed another large integrated information system for retail banks. The platform was again character mode JAM5 on UNIX, with custom mechanisms for distributed database support. The system has since migrated to the recent version of Panther and is still in use today.

Pardus continued to use JAM and Panther for its own development, and started to distribute it to other Independent Software Venders (ISV) and end user organizations with their own IT staff. Programs for JAM and Panther training, consulting, project management, and end-user development team mentoring were created. This contributed to the rapid success of the tool in the Croatian market.

As a result, Panther is now used by the two largest banks in the country. One of them still uses the originally Pardus-developed software for its core data processing, supported by 70+ in-house Panther developers and a team of Pardus consultants. Other users, apart from ISV houses, include departments like the Croatian postal services, customs, health insurance, several ministries and Zagreb municipal administrations.

An Example: Forensic DNA Database
Pardus uses and encourages other fellow-developers to use Panther for a wide variety of applications. One interesting example is the Pardus-developed eQMS::DNA application, a DNA “fingerprint” database, now in use in Central Forensic Laboratories in two countries.

When the opportunity to develop such an application arrived, Pardus again chose Panther because of its excellent rapid prototyping abilities, flexibility of its scripting language and the versatility of its database transaction generator. Native XML import and export capabilities were an advantage.

The resulting eQMS::DNA application is a system primarily used for maintenance and efficient searching of database of human genotypes for forensic purposes (such as identification of biological traces like blood, hair, skin etc), but also has the capability to be used in fields such as livestock lineage tracking.

DNA fingerprinting relies on the fact that certain points in human (or other) genome (loci) change relatively quickly (display polymorphism) from generation to generation – fast enough to form a combination unique for an individual, but slowly enough to be stable within single individual's cells. The type of polymorphisms and number of loci used for constructing genotypes in eQMS::DNA is configurable, but typical installation will employ a standard set of 13 to 18 STR (short tandem repeat) loci.

The system maintains data on individual donors with optional end-user configurable personal and demographic data, multiple samples containing genetic material taken from the donor, and genotypes obtained from the samples, possibly using multiple techniques and identification kits. Both processed genotypes and optional additional data such as peak quality, confidence parameters and raw electroferograms can be kept. The system also keeps profiles of unidentified traces.

Manual entry of data to Panther screens, from plate gel electrophoresis is possible, but the typical data source results from automated capillary electrophoresis sequencers. Communication with systems such as Interpol DNA Gateway is also supported.

The searches can be performed interactively or in full automatic mode. All searches, including those using partial profiles and relaxed criteria are typically done in less than a second. The system also supports mixed-stain searches with provisions for common contaminant identification (such as genotypes of laboratory or other forensic personnel).

Interpol maintains a list of available DNA profiling systems (probably the most well known being FBI CODIS). eQMS::DNA is the only application from a commercial software developer.

Figure 1:Screen shot of eQMS::DNA profiling application


New Developments
Pardus has assisted many clients in modernizing their legacy character-mode JAM and Panther applications.

For example, a Complex Card Management application for a leading Croatian bank was recently ported from JAM5 character-mode to Panther5 GUI. Initial functionality was complete within a month, with an additional month spent adding capabilities made possible by the new version of the Panther tool.

Pardus mentored several of their customers as they transitioned from character-mode to GUI to the Web environment, and from 2-tier to multi-tier architecture. One example includes developing a Java wrapper to call mainframe-based Web services from within a 2-tier GUI and Web Panther application. Another customer, a public health institution, uses the similar Pardus-provided tool to provide their clients with controlled access to their LIMS software (also developed by Pardus) that contains data on analysis of food and water samples.

Despite the market focus shifting away from dedicated application development toolsets, Panther stays a viable product in the Croatian market, thanks to the high penetration and the level of experience and expertise available to its customers.

For more info see http://dna.pardus.hr/ and http://lims.pardus.hr/.

Dragi Raos is a co-founder of Pardus d.o.o a software development and IT consulting company from Zagreb, Croatia. Pardus is a distributor of Panther and JAM in Croatia. Dragi has three decades of experience in technical and scientific computing, design and development of complex financial applications and training and coaching of development teams, he has served as team leader or technical consultant with clients ranging from International Atomic Energy Agency to large regional banks to public health institutions. Dragi's technical expertise includes database management systems, middleware, CASE tools and a wide range of development environments, including 20 years of experience with Panther and all versions of JAM.