Wednesday, August 17, 2016

Predicted Solar Flares a Security Risk? Really?

Lions and Tigers and Solar Flares, Oh My!


By Ed Higgins


This post may seem a little off-topic, science fictitious, or perhaps it might read a bit like a joke, but nonetheless, I wonder, in our assessment of IT security planning have we seriously considered natural disaster risks such as solar flares?

As a kid of the 70's, I remember that at certain times my CB Radio (remember those?) could receive signals from locations a few thousand miles away which was well beyond the capability of my radio and antenna.  Or, I remember those times when the television reception was just not that good at all, terrible in fact?  These things were all directly related to  solar activity, sun spots, and solar flares.

So, now, we fast forward to current time, a time in which we are heavily dependent on electricity, computers, cellular, digital telecommunications, wireless, satellite communications, radio frequency and infrared devices, and anything pretty much magnetic.

In the past 10 years, we've seen our list of technology requirements grow as has our dependence on these and the resources that support them. Think for a minute... What would your life, right now, be like without a computer, network or cell phone for a week or perhaps several months?  How about no television or satellite communications?  What about our business transactions, electronic commerce, banking and trading? What if there were no electricity for several weeks or perhaps months because our energy grid management systems were broken, not able to automatically open and close the power switches along the grid that deliver electricity to our homes and businesses?  What if energy produced by hydro, wind, nuclear, coal-fired generators were all halted because the microcomputers that control them were all fried and disconnected.  Alarmist? Perhaps a bit. Thought-Provoking? Definitely. At least, I Think So!

Our Nation's energy businesses have all been diligently implementing controls and plans to protect us from the infamous "cyber attack" on our electrical grid systems. But, what if this particular threat was the least of our worries?  Driven by NERC CIP, regulators mandate that energy producers improve Critical Infrastructure Protection, or the cyber-security controls that surrounds critical infrastructure systems that control things such as the energy grid,  water treatment facilities, air filtration fans, and toxic materials disposal. These regulations greatly address the security risks of outages caused by terrorist act, accident, malicious hacker, and other cyber-villains.

While cyber attack is a very legitimate potential threat to our infrastructures, what if the bigger threat was the "11-year cycle of predictably repeated and historically accurate events relating to solar flares and sun spots that goes back millions of years"..

In these most recent of years, and at no other time in history have we all grown to be so very very dependent on microcomputer systems, cellular, and networks which are all most fragile to mass effects of solar flare activity.

In 1859, a solar eruption occurred that was so powerful  it set fire to hundreds of telegraph  offices...  people got nasty electric  shocks simply because  they were working with metal objects.  In 1859, however, we had no televisions, cell phones, power grid management systems, smart-meters, etc so arguably the impact was less visible.

Now continue these 11-year recurring events forward to modern times.....

In 2003, and the most recent peak in solar events, we experienced outages that included computer system failures, magnetic data backup tape failures, electricity outages to homes and businesses, disrupted television and satellite operations, and greatly disrupted radio signals.

NASA and the scientific community accurately predicted the solar events, however the only means of reducing the risks were to simply shut  off high-risk devices. NASA  temporarily shut down certain radar and satellite tracking antennae to avoid their destruction. NASA even grounded space shuttle programs to protect astronauts from the severe threat of deadly radiation exposure as space is not protected by the magnetic field that protects the Earth.

Check out these interesting and informative videos on the solar flare phenomena:
       
  1. Attack of the Sun
  2.    
  3. Nasa Warns Of Super Solar Storm

As we explore and deploy all of the new methods for acquiring  and producing energy... thus  expanding our power grid to accommodate wind  farms...solar arrays...  new nuclear plants ... and other renewable  energy sources. This grid will get larger... and smarter.... With microprocessors inside almost every device...communicating and negotiating  with one another...  running everything from air conditioners to power  plants.

A sudden surge of solar activity could strike the grid     directly...inflicting substantial damage on   our "smart power economy".

A similar storm today, or in 2013 when peak solar flare events are  predicted, could easily cause several trillion  dollars  in damage to  our sensitive high-tech infrastructure, potentially thousands of times greater  than   hurricane Katrina.

Modern information security strategies are focused on physically and  logically protecting data, keeping systems up during brief outages, recovering a destroyed data center to another with waiting equipment, preventing intruders or  insiders from stealing company secrets or sensitive information such as  customer credit cards, health records, et cetera ad nauseam  ad  infinitum.

Our Disaster Recovery Plans and Business Continuity  Plans tend to focus on events with which we  have some prior experience, like the horrible tragedies of September 11th, hurricane Katrina, and even the threat of widespread pandemic influenza. But, what about the global impact on a modern-day solar flare event?  How will we respond? What will we do when these naturally occurring  solar flares generate similar interference as they have over previous  11-year cycles for past millions of years, but this time they cripple the computerized devices that we have become so dependent upon?

Thoughts?  Provocative? Alarming?  Ho-hum?  Let me know...

I hope you enjoyed this article, and hope it was helpful.

Until next time,

Ed

Thursday, March 17, 2016

Gone Phishing! What if you clicked it?

When will we stop clicking on the link or opening the zip file attachment that comes via a spam mail? But what if you click on an attachment by accident, what should you do?


By Ed Higgins

First, if you accidentally click on a potentially malicious attachment, don't stall reporting it because you are embarrassed.  That is the worse thing you can do.  Report it to your IT or Security team, so they can address it immediately, while it is single occurrence, rather than addressing perhaps thousands of infected systems because you failed to report it.

Should we click attachments? This is tougher challenge to address because we all are inclined to trade off good security practices for convenience. Generally, we all would like to think we know better than to "take the bait", but sometimes an email looks so convincing to the eye and we're pressed for time, that we forget to validate the sender or the content we're being asked to click. We get caught up in trying to do things so quickly that we just click it, etc. Once you click the link, if your system is vulnerable to whatever is contained in the link or attached file, it will be too late. Malware operates at the speed of electrons moving within a wire. Your finger beating on the ESC key isn't going to beat the electron - never has, never will.

Some Examples to Consider:


Below is an example of a potential email that a bad actor might send you an email that says:

----- begin email ----
Hi Ed,

Please correct your bank account information. Below is a link to your bank account.

Ed's Bank Account


Thank you,
Your bank

----- end email -----

The link associated within the above text (meaning the destination is not immediately visible to you) might direct you to http://badplace.stealyouridenty.ch

The link directs you to a compromised system somewhere in the Internet, (probably a compromised web server) that contains malicious code (malware) which immediately executes a program when you land on the web page and infects your PC with whatever bad thing the bad actor wants to do. The possibilities regarding the purpose of the malware are endless, as are the means to detect them.

To expand upon the techniques that bad actors use, the email content would display text as if it were the actual link but it's not. For example the following link:

The email text: http://legitimate.bank.com/login (while it look legit)

The embedded link associated with the text: http://badplace.stealyouridenty.ch

Tip: Get in the habit of always inspecting the link before you actually click it. I do this all the time and it doesn't waste much time. Move your mouse over the legitimate looking link. Hover over the link, and your browser will reveal the actual link. You can easily evaluate the link to observe anomalies wish as purposely misspelled works.

This obviously pertains to inspecting emails from your PC, but what about emails and embedded links that you read on your cell phone? It is more difficult to inspect the text/link in your cell phone. I believe cell-phone initiated compromises are replacing the PC varieties. This raises yet another topic created to cell phones, which we'll discuss in another article.

Here's another example. Compare the two links below and find the difference if you can.

http://legitimate.bank.com/login

http://legitimate_bank.com/login

Did you see it?

The two links look somewhat similar but each directs you to two completely different destinations. As you have probably found, the period "." was changed to an underscore "_", thus changing the target destination entirely from bank.com to legitimate_bank.com. If you missed it, look again. Some bad actors are very accomplished at disguising the differences between the good and bad. You have to pay attention.

A Slightly Different Example:


Bad actors may not use a malware infected link to immediately install a malware on your system. Rather, they may create a faked web form on a compromised web server that looks exactly like your bank's website, but it is really not your bank.   This goes right back to the need to inspect the text and the embedded link as I described above.  To continue: the form might show a login page, designed to get you to login with your user ID and password. Once you type your username and password, your account has just been compromised because the bad actor now owns your bank account's access credentials. The motives and techniques used by bad actors in this example are, again, endless.

I believe security vendors should look at the topic of link alteration and provide utilities that automatically detect the text-to-link relationships and analyze the differences, and thus warn the user about the potential fraud. Some vendors are doing such things, but only from the perspective of the source of the email (treating it as if a spam).  Alternatively most security vendors track malware or malicious behavior via a signature file.  The problem with signature based analysis is that all the bad actor needs to do is slightly alter the coded payload or spam message, which will now completed bypass the security control. It would go along way in helping users, if browsers and email tools would do some of the content analysis work, to help users make informed decisions about things we take for granted like simply clicking a link.

Sounds obvious right?  But to repeat, most antivirus and anti-malware tools today don't do this analysis. They operate on the principle of a signature database of known attack behaviors. Security vendors work hard to update signatures and bad actor profiled behaviors, but they are faced with a constantly evolving challenge to keep up, rather than stay ahead.

In all of the above questions, there are literally millions of iterative methods that bad actors use to evade security software's ability to detect the malicious content. I believe browsers and security vendors have the ability to beat this.

Where do most breaches originate?


Most thefts of your personal identity, credit card, and personal data do not occur as the result of negligence by your bank or email services provider. It is quite true that several mass breaches have occurred where a business network is attacked and whole databases are stolen, but this unfortunate problem is not the type I am talking about. Rather, I am addressing attacks on individuals in mass or in singled out attacks.  In the case of the email and web examples described above, every compromise of this type can be attributed to you and me (the end-users).

"Security is Everyone's Responsibility"


This is where you come in. By exercising some caution to inspect links before you click them, by using pass-phrases instead of passwords, and by making sure your IoT gadgets are always kept up to data regarding security updates, and configure your home wireless network with a strong WPA access code, you can greatly protect yourself against these types of attacks described throughout this post.  Of course this comes in addition to having good antivirus and anti-malware tools installed on your PC and kept up to date.

Ok, I clicked the link. Oopsie. What should I do?


If you do happen to accidentally click in a potentially fraudulent attachment, tell your IT or Security team as immediately as you possibly can.  They may or may not be able to disinfect your system, depending on the purpose of the link, but they can take appropriate actions to protect the rest of the network from the spread of virus that you may have introduced by accident.  It is very important that if you do make a mistake, an accident, that you report it so that it can be stopped and prevented in the future.   If you suddenly experience weird behavior on your PC and even remotely think that it could be malware related, then contact your IT or Security team. Treating your PC's infection is a whole lot easier for them then treating every PC in your company's network due to it spreading because you didn't alert them.

If your personal home computer gets infected, the first step would be to disconnect the network and wireless connection. This won't stop the malware from running on your PC, but it will halt the spread to other systems, and will halt any further theft of information until you can get your PC analyzed by a competent security professional.

For work computers, preferably beforehand, check with your Security team (if you haven't already been given instructions).  They will have incident response guidance for what you should do if something like this happens to you.  If you don't have a Security team at your work, then check with IT. If nobody knows what to do, then unplug the computer from your company network.  Whether to unplug or monitor, is a decision for the company to make.  Again, it is a good idea to know these steps in advance of making a mistake.

In future articles, we'll expand upon some of the additional items I touched upon and we'll explore more on the subject of  phishing, spear-phishing attacks (which are the types explored here), as well as some more advanced topics.

I hope you enjoyed this article, and hope it was helpful.  

Stay tuned, and stay safe

Ed

Friday, November 6, 2015

You Have to Measure Before You Can Improve

Power In The Data Center

You Have to Measure Before You Can Improve


By Ed Higgins

Power Monitoring is the first step to savings in your Data Center.

As global competition intensifies, companies are increasingly turning to technology to help turn mountains of data into a competitive edge. With soaring energy prices and the need for round-the-clock data center services, enterprises must find ways to increase energy efficiency and reduce costs. In addition, escalating power consumption by large data centers and the population in general means additional power is not always available to expand computing services. Although power is becoming the most significant cost in running a data center, most data center managers lack the tools to accurately measure power consumption. All of these factors, along with a growing concern for environmental stewardship, are forcing the need for better power-monitoring technologies.

The cost of power is increasing. Power is now the single largest operating cost in the data center. The impending Carbon tax are forcing companies to truly understand their energy use patterns to reduce power usage due to increased costs associated with energy consumption. With today’s limited IT budgets, any energy savings means more money for revenue generating activities that can help bolster the bottom line.

Power failures are expensive and detrimental to business. The high cost of data center downtime due to power failure is another threat that plagues data center managers. Any downtime of the equipment in data centers supporting today’s global companies and organizations can mean millions of dollars in lost revenue, as well as withering customer confidence. Data loss or corruption resulting from power-related issues is equally damaging to a company’s revenue and reputation.

Why It’s Important to Monitor Power

You need to measure it before you can fix it. Analysts continue to rank energy efficiency as the number one concern of data center owners and operators. The truth is, however, you simply can’t improve something, especially energy efficiency, if you’re not measuring it. Energy efficiency projects often pay for themselves in energy savings, but if you don’t know how much energy you’re using and how much it costs, it is very difficult to justify new technologies and best practices or to assess the savings of those new methods. Without a baseline and then continued measurements, it is impossible to determine where to optimize, to evaluate the results of the optimizations, or to show the improvements to management, government agencies, or customers. In addition, you need to be able to identify energy consumption peaks and lows and determine how they relate to operations and key internal and external events (such as marketing campaigns, accounting cycles, and changing weather patterns) to enable you to adequately plan for these events.

A number of organizations, including The Green Grid and the Uptime Institute, are working to develop standards to help companies become more energy efficient. The Green Grid’s Power Usage Effectiveness (PUE) metric is becoming a standard for data center energy efficiency, but PUE cannot be reasonably determined if energy consumption cannot be measured. Measuring at the device plug (after all of the power conversion, switching, and conditioning is performed) is the best way to calculate PUE. Finally, measuring at the device plug is sometimes the only way to accurately measure power usage in a data center—particularly if the data center shares power with other areas in the building.

By measuring power usage you can:

• Identify potential cost savings and set goals
• Identify current power costs and set a baseline
• Implement efficiency improvement projects
• continuously measure to determine success
• Accurately bill departments and tenants
• Balance 3 phase power systems

Data center managers need to understand it to work with it. In most data center today, data center management and facilities management are still handled by two different departments, which means data center managers operate without fully understanding the ramifications of infrastructure changes.
Another reason to monitor power is to avoid costly downtime and loss of data. Systems consuming an inordinate amount of energy might be signalling a performance problem. On the other hand, inadequate power can cause stability problems. The ability to monitor power usage provides yet another tool to help data center staff actively solves potential problems, thereby possibly saving millions of dollars in losses.

The Benefits of Power Monitoring and Management

Increase profitability with lowered energy and operating costs. Even a small drop in energy consumption can deliver substantial cost savings over time.

Ensure accurate chargeback. Collocation providers charge tenants for energy usage. Monitoring power provides accurate data on usage, making it easier to compute charges. Clients are more likely to accept these charges if they are provided with accurate statements. A full accounting of energy usage can also help departments understand how effectively they are using the compute resources they purchase. Power usage data is also enabling service providers to implement a different pricing model determined by such categories as power factor. Tenants with legacy equipment having a bad power factor are charged at a higher rate for excess power usage. This will increase the Collocation provider’s green credentials.

When you understand power usage in the data center, you can also begin to intelligently balance phases on your 3 phase power system to optimize energy use and reduce costs. There are a number of benefits that make efficient load phase balancing a worthwhile objective. One such instance would be increased feeder capacity. The loading on a feeder section is synonymous with the most heavily loaded phase and, in the case of significant imbalance, feeder capacity is used inefficiently. Balancing between phases tends to equalize the phase loading by reducing the largest phase peak while increasing the load on the other phases. This equates to releasing feeder capacity that can be used for future load increases without reinforcing feeder conductors.

Additionally, phase balancing reduces feeder losses because any phase peak reduction affects the losses for the phases as the square of the current magnitude. A feeder section with 1-ohm resistance that has phase currents of 50A/100A/150A will have 35kW in losses. When balanced at 100A/100A/100A, the loss reduces down to 30kW. The same effect is even more evident in the reduction of reactive power losses because the X/R ratio of most feeder sections is greater than 1.

Phase balancing also improves the voltage on a feeder by equalizing the voltage drops in each phase along the feeder. This released feeder capacity provides more reserve loading capacity for emergency loading conditions. It is realistic to assume that the benefits in improved use of feeder capacity and improved voltage quality are of more significance than the value of loss reduction except when loading is already high.

Typically, balancing is accomplished by selecting the phase of the supply for each load so that the total load is distributed as evenly as possible between the phases for each section of feeder.

In summary, the only way to achieve power savings in the data center is to first actively measure current and power at as many granular points as is reasonably possible. From there, you will begin to see the areas of low-hanging fruit (typically the fruits represent 20%) for which you can implement strategies for cost reduction, whether this be consolidation, virtualization, elimination, or advances tactics such as integral power-capping vehicles which instruct systems to "slow-down" when right conditions are met.   Only the best DCIM solutions can provide the real-time monitoring capability to give you this insight.

I hope you enjoyed this article, and hope it was helpful.

Until next time,
Ed



Tuesday, September 8, 2015

Data Center Infrastructure Management... Facilities Management? IT Management? Business Management?

DCIM: What does this mean to you?  Part 1

By Ed Higgins

This is first in a three-part series on DCIM and relevance to facilities, IT, and the business.

First a few questions.

When the words "data center infrastructure management" or "dcim" comes up, what's the first thought that crosses your mind?

A) It's about Facility Management (e.g. the building, the power, the cooling)?
B) It's about IT Management (e.g. the servers, the switches, the storage, the virtual machines, the applications)?
C) It's about Business Management (the folks that pay the electric bill, pay for new data centers, acquire complimentary businesses)?
D) All of the above?

Now scroll down
 |
 |
 |
 |
 |
 |
 |
 |
V

If you guessed "D", then right you are!  Take a bow, for it is the responsibility of Facilities Management, IT Management, and the Business (three entities with different priorities) to work collaboratively as stakeholders in DCIM, whereby the data center operations must have adequate power and cooling, IT assets are run reliably to effectively align, and must execute to the requirements and cost objectives of the business.  The business involvement is critical, for it establishes the priority basis for which information and ranking relative to the requirements most and least important to the business.

Facility Perspective.

Being able to know where power, cooling, and floorspace capacities exist or where it is required, or where the hotspots or deficiencies are, or how much capacity will be needed in the future are considered to be the "Hot Topics" for any facilities experts who confront these topics every day.

When a power or cooling engineer can readily "see" where power or cooling capacity are abundant, or lacking, or about to change, then they can begin to align strategically and work tactically to anticipate the business's requirements.  Furthermore, when they can see further down the road, like 5 years further as an example, then they are truly in alignment to the direction of the business.

Imagine how a facility engineer feels when his environment is creeping towards 60 - 70% capacity and he learns that the business will bring in an acquired business of roughly half his company's existing size.    He'll likely say, "we need a bigger facility".  In some cases, this is the only way. But in more cases, he may have plenty of capacity stranded by inefficient and antiquated consumers of power, cooling and floorspace.

Wouldn't it be nice if the Facility engineer could anticipate these requirements, evaluate where stranded capacity exists, collaborate with IT to evaluate the impact of replacing costly consumers of capacity to free up all that which is stranded?  Well they can.


IT Perspective.

We have to deploy how many application servers into the already crammed facility?  Really?

Stay tuned for Part 2 regarding the IT Perspective, followed by Part 3 relating to the Business Perspective.

I hope you enjoyed this article, and I hope it was helpful.

Until next time,

Ed


Wednesday, September 3, 2014

Will You Throw Up When Your Security Incident Hits The Evening News?

Reporting Security Breaches: Back in 2003 and Now.  What's  changed?


By Ed Higgins

In 2003, an article was posted that presented a hypothetical university security incident in which hundreds of thousands of historic student records and payment card information was compromised. The systems were in place (although nothing is 100%), the personnel were trained, but the study suggested that the university was not prepared to address the public when the story broke on the 6pm Evening News.

So, what has changed? Have laws and regulations been prescriptive enough to educate businesses, universities, and other establishments on their requirements to disclose the incident to the public?

Do entities know what to do when "it" happens? How to notify the victims? Do you notify the victims? You can't really hide it from the public it and keep it private, can you?  Did you know that for several years United States laws, such as California SB-1386, mandate disclosure of a security breach to potentially affected victims. No more head in the sand....


The depth and speed at which cyber crimes occur has significantly changed.  Formerly a form of crash-and-dash, today's cyber criminals operate more stealthy with better tools performing significant reconnaissance before they strike. No longer about fame [the notoriety of spray-painting a web page], these criminals carry out well planned, focused and financially motivated attacks, striking at the perfect moment.


The key to adequate incident response today is speed to identify, stop, and address the situation often using outside private investigators for independence as well as competence in the subject matter. This all has to happen much much much much faster than in the past. Bureaucratic organizations move aside!

Based on studying the incident response processes and situations during real-life actual incident investigations with hundreds of clients, I would suggest that we have a lot of work to do. We kinda need to reinvent our incident detection and response processes.


I hope you enjoyed this article, and I hope it was helpful.  


Until next time, "Watch Out For Yourself".

Ed




Friday, August 29, 2014

DCIM: Strategic and Intrinsic Value

The Role of DCIM Coupled with ITIL/ITSM 


By Ed Higgins


As a rule of thumb, the more integral your Data Center Infrastructure Management (DCIM) solution is to your existing critical management processes , the more strategic and successful your DCIM investment will be. The more flexible and integration-worthy the DCIM solution is, the larger the population of DCIM users (stakeholders) will be. When many stakeholders with diverse disciplines utilize DCIM to its fullest, by enabling those individual stakeholders to "work and think within their own disciple" yet share the work they do transparently to the other business stakeholders, the greater the consequential financial benefits will be from the DCIM for your enterprise business.

DCIM is a relatively new category of IT management and unfortunately it has many interpretations depending on which vendor you are talking to. By generally accepted researcher definitions, DCIM is defined as the integration of information technology (IT) and facility management disciplines to centralize monitoring, management and intelligent capacity planning of a data center’s critical systems.

Achieved through the implementation of specialized software, DCIM enables a common, real-time monitoring and management framework for bringing together formerly disparate management systems spanning the entirety of the IT and Facility infrastructures.

Analysts’ definitions vary and in general are very broadly defined which has created an atmosphere where new vendors are arriving every day with their own interpretation. Power strip manufacturers are claiming a stake in the DCIM market. So are diesel generator manufacturers. These are point-solutions and should be properly reconciled by the Analysts.  The DCIM market promised great growth. Couple this with the fact that the big power equipment providers and a few well-funded startups pay tens of millions of dollars per year to these analysts. Now you might see why there is so much confusion and conflict among the DCIM market.

Many potential DCIM customers start their research and investigation of available DCIM solutions in a very hands-on tactical mode. DCIM comes in all shapes and sizes, and in fact includes everything from sensors and power monitoring, to life cycle management suites. Each potential customer looks at the pieces that appear to have the most relevance to their management goals today. They start their DCIM journey looking for solutions that fit into their existing ways of doing business. New tools applied to obsolete approaches is a waste of your time and money.

Fortunately for astute customers, they are beginning to see the much greater opportunity and their former tactical thinking is quickly transitioning towards strategic value, wider audiences, and having broader impact on the entire picture in alignment with the requirements of the business.  We've seen a similar positive transformation in the storage market where tiered storage concepts are considered. The same transformation and cost-to-value appreciation is represented in the hot, cloud market.

Even the role of the CIO has transformed from a "deliver ALL services at ANY cost" approach to a cost-to-value approach, provide the right level of service, based on VALUE to the enterprise, where cost tolerance, resilience, reliability, longevity, growth and/or reduction are now vital criteria.

DCIM Becomes a Strategic Investment When Connected to ITIL/ITSM

We are beginning to see a fundamental shift in discipline and accountability. Everyone wants to look forward rather than backward, and relatively few are defending their previous methods. ITIL-like approaches (anything that enables discipline and accountability) are much more the operational standards in this new climate.  It is within these transformational shifts that DCIM thrives. DCIM solutions must complement and integrate with existing management applications and DCIM vendors cannot force their preconceived methodology upon any established enterprise.  Some DCIM solutions boast workflow and ticket management processes, which should infuriate the DCIM customer.  While most DCIM vendors can bring a lot of best-practices to customers, many have become so enthralled with their own ideals they make claims that they cannot back up.

IT Service Management or ITSM is the process-based practices intended to align the delivery of information technology services with the business needs of the enterprise.

DCIM when implemented strategically marries the physical infrastructure required to ITSM.

When DCIM is aligned closely with ITSM, it becomes embedded with change management.

When the role of DCIM is successful, then the gaps between facilities, IT and the business will radically close, the determination of "who pays the power/utility bill" will be self-evident, previously hidden areas for cost reduction become clear, planning and deployment operations become transparent,

DCIM directly supports optimization and transformation, which is already occurring across your IT structure whether you are part of the equation or not.

I hope you enjoyed this article, and I hope it was helpful.

Until next time,

Ed

Sunday, September 30, 2012

Who is Rackwise? And, what do we do?

Rackwise DCiM X is Enterprise-Class in DCIM Software


By Ed Higgins

Be forewarned, this is a commercial. 

Rackwise  DCiM enables complete Visualization of your entire data center infrastructure from all of your the data center locations world-wide to power and cooling equipment to all of the racks to the devices (and modules/components inside each device) and full cable management (power and network).  Rackwise  extends this visualization strategy into Cloud and Virtualized environments. Extensive Documentation capabilities are built into the solution for comprehensively managing today’s complex and globally disparate data center environments. Modeling, and unlimited “what if” scenarios as well as capacity analytics are core components of our solution (superior to all other solutions). Rackwise  provides you the ability to analyze data in tabular and rich graphical formats. Make informed decisions, enable day to day efficiencies, distribute compute services using global options for "best-cost" services, and efficient operations necessary for proactive Management of tomorrow's data centers, TODAY, with Rackwise .

Intelligent Placement, a powerful capability found inside Rackwise since 2005, is facilitated by Rackwise‘s revolutionary product functionality to identify the “best place” to deploy an asset based on available capacity for power, current, cooling, weight, contiguous rack units (RU), available power and network ports, and other criteria based on the business requirements needed for a given asset.  This dramatically helps data center managers put critical assets where resilience, capacity, and redundancy are optimal, similar to the industry methods leveraged in the tiered data storage space where you put your critical data where the resilience is greatest and your less critical data on less costly infrastructure.  Rackwise helps customer identify these opportunities and optimize their equipment based on the needs of the business customer.

Rich Visualization provides a dashboard display for a high level view of the data center.  Selectable layers can be added to display power consumption, heat generation, current, and either power or signal port availability. Additional layers can be added to display door swings, hot cold aisles, location and density of perforated tiles, etc., to create truly customized displays. Users can drill through to greater detail, from the data center, to the rack, to the device, and components, including: blades, power supplies, drives, etc.

Detailed Documentation provides clear and descriptive reporting on the IT infrastructure. Powerful Modeling allows the user to perform unlimited “What if” scenarios. Rackwise  quickly determines the impact of data center consolidations, or the resource consumption associated with new data centers. The user can make detailed comparisons of proposed equipment upgrades versus the current environment. Trend and historical reporting provides crystal clear visibility into where resources are being consumed over time, and when they’re likely to be exhausted.

Comprehensive Analysis provides instant access to critical information and enables decision making capability on key data center issues. Direct access to information such as availability of space, power, heat and cooling, port availability, and remaining weight capacity in racks, allows the user to make critical decisions with confidence. Rackwise Advanced Power Management provides the ability to explore the power system, understand the redundancy levels of critical servers, and other equipment. Rackwise advanced power also provides full understanding of the impact of power source, UPS, or PDU shutdowns. Further the system determines if the remaining power infrastructure will be over taxed in the event of an outage, resulting in a cascading failure situation.

With over 100 standard out-of-the-box Reports, who needs to custom reports?  Rackwise Standard Reports range from assembly report that provides step by step instructions to assemble and cable a solution, to connectivity reports, to simulating a cascading power or equipment failure to improve resilience, to delivering weekly or daily power consumption reports, environmental reports, and asset management reports. If you want custom reports, we also include an enterprise-grade reporting engine to easily create sophisticated reports designed for your unique business model. If you don't have time or resources to make any customizations to your reports, then Rackwise can do it for you.

Sophisticated Management capabilities allow the user to deploy and decommission devices quickly and easily. Track equipment through receiving, staging, commissioning, decommissioning, and storage. In addition, Rackwise tracks changes to the data center infrastructure at the data center, rack, and device levels. Custom properties can be used to map applications or other information to devices, providing a clear understanding of what impact the shutdown or failure of the device will have. Planning for new equipment is greatly simplified with Rackwise ability to locate and reserve space, power, cooling, ports, and weight load availability. Additionally, advanced searching is made easy to help you locate physical infrastructure components based on your search criteria.

Don't you owe it to your CEO to explore Rackwise today?  Rackwise can help you save at least 20% on your power costs, and reduce your costs in many other areas.  If you spend over a million $$ on your annual power bill, then that's a ton of immediate bottom-line value - and that's just the start.



I hope you enjoyed this article, and I hope it was helpful.  

Until next time,

Ed