Author: way0utwest

  • Slow Fixes

    Moving Slow

    Today we have an editorial reprinted from Jan 15, 2006 as Steve is on vacation.

    There’s an interesting piece at the Washington Post on Microsoft’s delays in releasing patches, with some analysis showing that when the flaw is disclosed to the public, a patch comes out much quicker. After some analysis over the last 3 years and researched the dates Microsoft knew about the issue and the dates that the patches were released.

    Surprise, when everyone knows, the patches come out quicker. It seems that the piece is intended to take a shot at Microsoft’s patching process, and maybe it is, but there are some interesting things in there to talk about. First of all is the time lag.

    Is this any different from any software vendor or even internal corporate software? If your boss knows, or the client knows, don’t you work a little harder and a little quicker? Isn’t it more critical and don’t you rush things in addition to working harder when it’s a “public” patch that is needed?

    I’m sure we all do. And it’s human nature to put more effort into something that’s widely perceived as an issue and less effort if you know that you may have more time. We all do that and our work schedules, effort, and productivity change depending on a variety of things, including the importance of the work.

    The piece also leaves open a number of questions and mentions this, noting that the analysis might be flawed. There’s no mention of if the rushed (or delayed) patches had to be repatched later. There’s concern over patches applying to one area, but other similar flaws found in other parts of the software remaining unpatched. That’s something for sure that should be examined in looking for re-patches or whether things are rushed. There’s also the lack of examination on what else was happening inside Microsoft, and whether people working on other projects had to be pulled off them.

    We all know that delays things as well. They take time to get their head back into code, they may be annoyed, a critical person could be out, etc. Not to mention that the statistical methods might not be the best ones, but I’ll leave that to the mathematicians to figure out.

    Patching is hard. As is finding bugs. I think Microsoft has done a much better job over the last 3-4 years and the quality of software, at least SQL Server, has improved. However there is still definitely room for more improvement.

    Steve Jones

    (published at http://www.sqlservercentral.com/articles/Editorial/72365/)

  • What Sarbanes-Oxley Won’t Do

    Sarbanes-Oxley Act

    This is interesting. Another case of corporate fraud under the title of “What Sarbanes-Oxley Won’t Do”. Apparently someone got loans, blah, blah, fraud, blah, blah, etc. You get the idea and I’m tired of having to hear and write about it.

    But since S-O affects most IT groups and many of us are dealing with it, it’s worth talking about and writing about. S-O has required more documentation, processes, and accountability for how corporations deal with their financial data. It is intended to prevent another Enron or MCI like occurence by making high level executives accountable for the company’s actions.

    But it doesn’t prevent fraud. It doesn’t prevent dishonesty, and it certainly doesn’t guarentee that your investment is safe in some company. It should make it easier to send people to jail, but even that hasn’t been shown to be the case yet.

    It does, however, make a lot of work for many companies. I was talking with a professional services company recently and they said that many of their clients, public and private, are trying to adhere to S-O because public companies have to, but private ones are either looking for an IPO or to be bought by a larger company, and S-O compliance is often part of the due diligence they’d need.

    If you’re an ISO company, you probably can use one set of docs for both certifications, although you’ll need to dive deeper in certain areas for each one. That’s the good thing since we know how much you IT folks love documenting your processes, procedures, and environments.

    I’m just happy to say that SQLServerCentral.com is not complying and I, for one, am thrilled 🙂

    Steve Jones

    (published at http://www.sqlservercentral.com/articles/Editorial/72358/)

  • Data Quality

    Beautiful Colorado

    Today we have an editorial reprinted from Dec 12, 2005 as Steve is on vacation.

    My wife and I were out looking at new houses this past weekend and I was amazed at the data quality issues that we found in various listings. These weren’t new houses as I’m not quite in the place where I can afford a new house with some land, at least not the 30+ acre plots we were looking at.

    What we found as we went from place to place was an amazingly inconsistent amount and quality of data in the listings. Before all the IT guys that work in real estate come after me, I’m not blaming the applications, the developers, etc. This is really a data quality issue probably from the data entry people.

    As we’ve researched properties and looked at the information online, we’ve often encountered conflicting information between what we’ll actually see in the listings and what the property looks like. More often, we don’t see the same information in each listings. We tend to look for acreage, and it’s amazing how many listings leave off the size of the property, or leave off the garage spaces. It’s usual in Colorado to have 3 spaces in newer homes and it seems that unless the house has more, the count is often left off, even when there are only two spaces.

    My Mom is in real estate and I’ve been around agents my whole life, so I’ve seen the issues first hand. Each agent writes up their own listing, using forms that are preprinted. Most agents seem to still work on paper, which means transcribing the data into the computer. Which means the chance for lots of mistakes as the human factor is involved. I don’t think it’s all laziness or lack of effort, but we all just make mistakes. And the more of us involved, the more chances it will occur. Just think of how many times you mistype something in email.

    I think this business could get a lot better, especially with more standardization and more IT tools in use. Using PDA-type applications or Java powered phone apps that could take listings in real time where the owner could double check things and ensure all the data is accurate. After all, better data quality will likely help the owner more than anyone.

    This isn’t limited to real estate, as many industries and processes suffer from data quality problems. There isn’t much that DBAs and other data professionals can do about the quality of the data we get; we can only ensure that the quality and integrity remains the same.

    But we sure get the blame when it’s not accurate.

    Steve Jones

    (published at http://www.sqlservercentral.com/articles/Editorial/72364/)

  • Recharging

    I’m in the Bahamas!

    This is a week off for me from SQLServerCentral, so if you’re expecting a response, you might not get one on Twitter, in email, etc. My wife won a trip back to the Caribbean for her work in sales last year for her company, and this is the week the two of us are getting away from kids and enjoying ourselves at Atlantis in the Bahamas.

    This is my continuing with an attempt to better balance life and work, and take all of my vacation in a year. My wife and I went away last January, and again for a long weekend in the summer. This winter we took Thanksgiving and Christmas to be with the kids and ski, trying to recharge my batteries and enjoy life with my family.

    I hope the rest of you get the chance to enjoy your life away from work, and find the balance that I’m striving for in mine. I’ll see you next week when I’m back at my desk, and typing away at the computer.