Tuesday, May 17, 2011

IT leadership challenges and solutions


Takeaway: Information Technology management can be a hard job. This Article provides you with a look at some personnel-related challenges and how you might mitigate them.

Let’s face it, managing a herd of IT pros isn’t always the easiest thing in the world. Between tight work schedules, short deadlines, egos, and life in general, there are a lot of ways that the apple cart can get knocked over. Although I’m far from being a perfect manager, here’s how I try to handle specific situations as they arise. This method is effective if the team members are mature. If the team is made up of younger, inexperienced members then a list of possible activities should be available for them and guide them through the options. When the team is involved with the decision making, the members are empowered and more likely to participate. This will lighten up the load of management.

IT pros don’t always punch a clock
The challenge: Typical management challenge, but with some added twists. Many, if not most, IT pros are exempt, meaning that they don’t get paid by the hour. They are paid to get a job done, not to do routine line work. In addition, many IT pros tend to have to work at odd hours to accomplish maintenance tasks and upgrades that can’t be done during business hours. Further, just like many human beings, life sometimes gets in the way of IT pros, and they need to occasionally juggle a bunch of both professional and personal priorities. This can lead to absenteeism or odd working hours or requests to work from home at times.
My take: So what? To me, as long as the job is getting done, I don’t care where the person is working from or when they’re doing it as long as their long-term situation doesn’t lead to degraded work performance. I routinely allow the people who can to work from home when life throws them a curveball. I also tend to be relatively generous when it comes to vacation approvals and requests to adjust hours when necessary. The reason is simple: When I’ve had to ask a member of my staff to make an adjustment for the College’s benefit, they almost always step up, even if it presents some difficulty for them. The least that I can do is to return the favor. It’s a give-and-take that simply needs to be respected.
As much as I hate to say it, there does need to be some oversight to make sure that flexibility isn’t abused in a way that reduces overall productivity.
 The solution: Be flexible. Trust, but verify.

My staff needs to be in the know
 The challenge: Ensuring that staff knows everything reasonable in order to help them do their jobs better.
The very best team building game should foster interest and awareness in ethical organizations. Concepts such as fair trade, sustainability, corporate social responsibility and the likes should be tackled during the activities. Most people don’t have the least idea what these concepts stand for. Team activities and discussions should make these principles clear to people and make social responsibility more pronounced than by just reading the theory behind it.
This is also true for the company’s mission statement. People would savor a new mission statement when they know more about it. Discussions should make it clear what it means instead of it just a bunch of words written by someone at the head office.

 With the exception of the stuff that I really can’t talk about, I don’t hide things from my staff, whether it’s good news or bad news. For example, if we were in a situation in which enrollment numbers were showing weakness, I’d step up and tell my staff. To me, having that kind of information helps them to frame their own decisions, and there might be some great ideas for mitigation from the group.

 Obviously, there are limits to how much I can really say sometimes, but I’ve never understood management that held back critical business metrics from the staff. Although I’m sure that no one wants their people to walk around constantly worried if things are a bit sour, potential solutions can come from many places.
 Of course, I don’t tell them everything. To do so would both bore them and be a complete waste of their time. So, the challenge is making sure they know what they need to know.
 The solution: Find a balance and stick to it, but most of all, make sure your people know what they need to know.

Policy isn’t always policy
 The challenge: Blind adherence to what is considered “policy” is akin to saying “I was just following orders.”

 I almost hate to use the word “policy” any more when, in fact, I believe that the term “guidelines” is much more meaningful. It’s obvious that some policies are and must be set in stone — fraud-related policies, for example. However, what most people consider to be policies, I look at as a standard operating procedure only when it makes business sense. For example, suppose you have an equipment-lending policy whereby staff members can borrow equipment for a work-related purpose. In order to provide the best possible support, you request 48 hours’ notice in order to pick up equipment. Nine times out of ten, that “policy” is probably perfectly adequate, but there is always that one request that comes in that makes your policy look really stupid.
Employers are considered socially irresponsible when they are apathetic to the concerns of workers who have partners or started their family young. Strong work commitments can put pressure not only on the employees but also on their families and partners. Big multinational corporations would require their employees to travel and stay away from home. Ethical socially responsible organizations must minimize these trips to not make things worse at home.
If possible, invite families and partners to company outings and team buildings to gain their loyalty and support. Companies should stay away from staff-only events. Employer’s liabilities from these types of situations are unclear but there are principles such as social responsibilities that are in play.
 In other words, if you allow people to hide behind a crazy policy as a way out of making a decision, you’re doing something wrong. I’ve seen it happen far too often, and the results are almost never positive, although the person that was able to hide behind a policy didn’t have to lift a finger.

 In some cases, an exception to “policy” needs to be made. IT staff members must feel comfortable making exceptions when it makes sense, and it’s up to you to let them know when it makes sense — in general — or at least be available if there really is a question. Obviously, if you’re providing exceptions for every instance, something is wrong; perhaps your policy is poor, your culture doesn’t lend itself to full adherence, or the IT staff is providing too many exceptions. That said, make sure your staff can and does make exceptions when it makes sense. Also make sure to understand that every exception requires additional time to handle it, but, sometimes, it’s simply the right thing to do.

 I will admit that I tend to err on the side of customer service — maybe too often. I want to make sure that we do our absolute best to serve, but at the same time, our guidelines are a function of available resources, so sticking a bit closer to guidelines when possible is helpful.

 The solution: Make sure your people know where they can and can’t make on-the-fly judgment calls. If they blow it, tell them, but don’t reprimand unless it becomes an ongoing issue.

 This one is, by far, the hardest for me.

Labels: , ,

Wednesday, November 10, 2010

Getting up to Speed on VLANs



IT managers are always looking for ways to do their jobs more efficiently, while still providing the quality of service that their clients expect. Virtual LAN technology (VLAN) can help them on both fronts, by easing administrative chores and improving enterprise network performance. VLANs allow IT managers to group users and resources in any way they like, regardless of the physical LAN segment to which those resources are attached. An organization may want to group all users in the marketing department on the same
VLAN with the servers that host the applications and data they use most often, for example. The users who belong to that marketing group may be spread throughout a building, or even the country, but they can still belong to the same VLAN. This type of flexibility in grouping users and resources stands in stark contrast to the days when IT managers were restricted to grouping resources solely by the port to which they were connected. Any changes to the network configuration required a visit to one or more wiring closets to physically move the user or resource from one port to another.With VLANs, such changes can be performed in software, from a central administrative console, thus greatly improving efficiency. At the same time, VLANs can be used to improve network performance in a number of ways – by grouping users that communicate often with one another on the same VLAN, for example, or by creating a VLAN for use by “power users” that tend to consume a lot of network bandwidth. VLANs are most suitable for mid- to large size companies, but even smaller companies with highly demanding users may benefit. Essentially, any organization with a network large enough that it needs to be segmented in some fashion can benefit.

Types of VLANs
When they first came on the scene in the mid 1990s, there were three basic ways to build a VLAN on any given switch or router. The port-based model called for assigning each router or switch port to a specific VLAN. Ports 1-5, for example, might be the engineering VLAN, while ports 6-10 belong to the marketing
VLAN. Some ports may be assigned to more than one VLAN, such as a port that connects a server used by multiple groups. Administrators could make changes to port and VLAN assignments from a central console, rather than physically pulling and rearranging wires. If a repeater was attached to any port, however, all the devices connected to that repeater must belong to the same VLAN.
Another approach was to assign resources to VLANs based on their unique media access control (MAC) address. The switch or router supporting the VLAN maintained a list detailing which MAC addresses belong to which VLAN, and routed traffic accordingly based on the source or destination MAC address. The drawbacks to this method included the time required to assign each MAC address to a given VLAN.
Assigning the same MAC address to multiple VLANs could also wreak havoc with bridges and routers, making it difficult to share server resources among separate VLANs.
Layer 3-based VLANs group resources according to the protocol and Layer 3 address they employ. In this fashion, all IP or IPX traffic can be assigned to its own VLAN, or perhaps all wireless LAN and Voice over IP (VoIP) traffic. The Layer 3 approach also enables all non-routable protocols to share a VLAN, thus limiting the effect of broadcasts on the rest of the network, improving performance for all users.

To promote interoperability between devices from different vendors that may be used to support a VLAN, such as switches and network interface cards, the IEEE developed a couple of key VLAN standards.Most VLANs today employ these standards, perhaps in conjunction with one of the above approaches.
The first standard, 802.1q, defines the format of a tag that is added to each Ethernet frame to detail the VLAN it belongs to. This is especially important in creating large VLANs that span multiple network switches. Enterprises identify their VLANs by giving each one a VLAN identifier (VID), which is a number
between 1 and 4,094. That VID is carried within the 802.1q tag, thus defining what VLAN the frame belongs to. The other key standard, 802.1p, provides a way to preserve quality of service levels for different VLANs, even as they traverse multiple switches. The standard defines three bits that indicate the level of priority for each packet, enabling each switch to reorder packets, if necessary, to ensure that higher-priority packets get through first. That is especially important for VLANs that support delay-sensitive traffic such
as video or VoIP.

Putting it all together
The ability to segment different traffic types is one of the key benefits behind VLANs. Even as organizations strive to create all-IP networks, they will want to give different levels of priority to different types of traffic.
Additionally, many organizations still have other protocols at work, including some “chatty” protocols such as DEC net that generate broadcast packets. The ability to segment those broadcast packets, keeping them from flooding the larger network, will benefit the enterprise as a whole. Similarly, some organizations are now assigning all wireless LAN users to their own VLAN, in an effort to help ensure they stay connected to the network even as they roam about. Security is another concern. VLANs are one way to ensure that
users have access only to the resources they need to do their jobs. If there is no reason that users in the sales group should have access to potentially sensitive engineering documents, a VLAN can be created that ensures the sales team has no visibility into engineering servers. Put another way, VLANs can be used to keep all but authorized users from getting at any given set of enterprise resources. If a client that is not an authorized member tries to connect to any resource on a given VLAN, it will be denied.
At the same time, VLANs promote maximum mobility. Since a client machine can be identified irrespective of the port to which it is attached, users are free to connect from anywhere in the enterprise that their VLAN is supported, and still maintain access to all their usual resources. It should be noted that these benefits are not limited to a single building or campus location, but can also accommodate an enterprise that spans the country or even the globe. Because VLANs are “virtual”, there are no real boundaries. Administrators can configure any given VLAN to support users who may work anywhere the enterprise network reaches, thus improving performance for those users. Add to all these benefits the fact that VLANs dramatically improve the productivity of IT administrators, enabling configuration changes to be made from a central console instead of
from the wiring closet where the device is physically located.

For more detailed info about VLANs visit Cisco.com



Labels: , ,