The importance of a risk – and vulnerability assessment.

The heading of this post states a topic that for many infrastructure – and service providers in my view have changed over the past decade. I for one used to spend much more time around physically checking how all elements in a service offering really looked like, talking about the behind the scene Power Point.

 

I have for many years been interested in the lower layers in the OSI model since if one get that part wrong, not much higher up works as planned.  In the past months we have had some outages on both digital services and important IT systems supporting the work of important Government services. Often we can blame the weather in my parts of the world but the incidents I am thinking off this time is not so much about the weather causing challenges in the service delivery.

What “surprise” me more than the weather causing challenges is how quick the digital services fall down and how slow they are back up again. I ask myself over and over again why this happens and part of my conclusion I will give here.

Like the heading of this blog states it is important to really do a check on how services are set up and at times there is a correlation between price and quality based on again my experience.

One interesting aspect of a modern economy like the Norwegian is that everything has to be a digital services. The public sector in Norway is working on moving as many services as possible on to The “Internet”. I wonder what the same people are answering when people from several areas in Norway all are off-line? Again the digital world is more than just a “click away”!

A modern economy needs to have the right information around how a service offering is put together. In this line of work it is very important to ask the right questions and if possible do a physical verification. I am sure that not many do this these days!

According to what I read on different newspaper sites in Norway I can see that areas go offline. Why is that?

The answers I see from the service providers are the same, finger pointing at other elements…

This is what risk and vulnerability is all about. I think we need to get back to the service offering where the phones actually worked even if the electrical power was out…;-)

I do not believe that everything was so much better before but I know that valuable knowhow on how the actual physical sides of a service offering has “left the building”. I see it in my day job when trying to figure out how duct systems are put in the ground to be able to guarantee the physical diversified routs and redundant paths on both the physical and logical layers in a serious service offering. It is the same few people that where there when the first ducts where placed in the ground and power- and Telco companies still had a long time view on the investment for an always on service. I guess they also understood the risk handling, end to end?

It is all about asking one self “easy” questions about what if? The answers may be much harder to solve, but at least we have thought it through and made a decision on what to do if something occur.

By handling known risks we have moved one step further in a controlled professional service offering. I honestly believe that is a better solution than ignoring the risks and hope for the best like many do in the modern digital service offering

regards

bj

p.s the jumper on the picture landed in 4 meters off powder-alarm-snow, so not risky 😉

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.