GSS delivers Electronic Government Procurement (e-GP) System and world-class Data Centre

Hyderabad, India (June 2, 2011), saw the inauguration of the much-awaited National Electronic Government Procurement (e-GP)System by the Honorable Prime Minister of Bangladesh Sheikh Hasina, in the presence of Planning Minister Mr. AK Khandker, Science and Information & Communication Technology Minister Mr. Yeafesh Osman, World Bank Country Director (Dhaka Office) Ms. Allen Goldstein, IMED Secretary Mr. Md. Habib Ullah Majumder, and Director General of Central Procurement Technical Unit (CPTU) Mr. Amulya Kumar Debnath.

Funded by World Bank, the e-GP System is an online platform to carry out procurement activities by the public agencies in Bangladesh, Procuring Agencies (PAs) and Procuring Entities (PEs), and Bidder and the Tenderer community will also participate online. The purpose of e-GP is twofold; to ensure smooth, transparent, secure and hassle free public procurement processes and also to manage the complete contract life cycle after the contract is awarded. The e-GP System will provide transparency and accountability in public procurement. The e-Tendering is part of Phase 1 of e-GP and it is live now. Contract Management System will be implemented in Phase 2 of e-GP and it is in development.

As a Lead Partner of the consortium and System Integrator, GSS was responsible for the overall e-GP System Program Management and management of, and coordination between vendors, partners, sub-contractors and all stakeholders.

The e-GP Software, designed, developed and implemented by GSS, is a one stop web portal for all e-procurement activities related to public money. The PAs and PEs will be required to use a dedicated secure web based dashboard for this purpose. Also many nationalized Banks have registered with e-GP to provide payment facility. Bidder and Tenderer can register in the portal and participate in the-Tendering process. The e-GP System provides a portfolio of tools to all users to make e-Tendering easy.

GSS designed, developed implemented and commissioned the e-GP Data Centre, end-to-end process and management capabilities. This work included civil works, electrical works, procurement of hardware and software, configuration, testing, handover.

To start with, the e-tendering will be introduced in four target agencies under the Public Procurement Reform Project -2 (PPR-II), a mission supported by World Bank. These target agencies are Local Government Engineering Department (LGED), Roads and Highways Department (RHD), Bangladesh Water Development Board (BWDB) and Rural Electrification Board (REB).

“GSS is proud to be part to be part of this historic moment.” Said Mr.Bhargav Marepally, CEO, GSS Infotech”. He added that the e-GP system will benefit public procurement and also help us to expand further in the Asia Pacific region, which has a strong potential.

Ramesh Yerramsetti, the Managing Director of GSS Infotech, who was present at the e-GP inauguration in Dhaka, said, “It gives me immense pleasure today to announce that GSS has brought about a revolutionary change in e- procurement process.”

While launching the new web portal in presence of huge audience at Bangabandhu International Conference Centre (BICC) in Dhaka, Honorable Prime Minister of Bangladesh Sheikh Hasina said “Around 75% money of the annual development program is used for public procurement. The government is accountable to the people for ensuring standard of the procured goods and service and usage of the public money. Tender manipulation in public procurement would come to an end with the launching of the e-GP. The opening of e-GP is another addition to our march towards building digital Bangladesh”.

To know more, please visit us at www.gssinfotech.com

Sandy Cohn nominated by Excelsior College as a key Partner in Lifelong Learning

GSS is proud to announce that Sandy Cohn has been nominated by Excelsior College as one of their key Partners in Lifelong Learning  Scholarship Event. As a part of its celebrations for the 40th anniversary Excelsior College decided to honor 20 Capital Region leaders who have significant contribution to Excelsior College  in terms of professional talent, personal commitment, or financial support that have helped the institution grow from its roots in 1971 into a 21st century role-model for non-profit distance education for students worldwide. Sanford A. Cohn, better known as Sandy Cohn, Senior Vice President, Technology Solutions, GSS Infotech and an Excelsior alumnus, was selected as one of the honoraries of 2011.

Sandy Cohn has more than 40 years in the IT industry. He started his career working with mainframe and minicomputer operations and programming in companies like IBM, DEC, and Prime Computer. In the early 80s, Cohn started his first company that centered on the integration of distributed systems primarily around Novell’s architecture. Cohn started his second company in nineties around Microsoft’s new server OS and Citrix’s Thin Client Computing. In 2000, he joined Atec Group as the manager of professional services, and has played a pivotal role in propelling Atec Group to one of the top regional integration players in the rapidly growing virtualization market, with partners like VMware and NetApp.

Today, working as the Senior Vice President, Technology Solutions, GSS Infotech, Cohn is the key decision maker in sales, and service delivery of Infrastructure Technology Solutions (ITS) division in US. With his commitment to excellence, intelligent planning, and focused efforts he aspires to make the organization a global IT player.

Sandy holds a degree in Electronics AAS from Community College of the Air Force and holds a BS degree in Math and Computer Science from State University of New York. He has pursued his Masters in Computer Science from Rensselaer Polytechnic Institute.

Sandy’s relationship with Excelsior began when he earned a bachelor’s degree from Excelsior in 1980. He has proven to be an outstanding partner as Excelsior has worked with Atec Group and now with GSS Infotech.

A Proactive Automated Approach to Remote Infrastructure Management Services

The case for Remote Infrastructure Management Services (RIMS) for Small and Medium Businesses (SMBs) has been made many times over. Put simply, the outsourcing of the management of IT infrastructure (Servers, Desktops, and Network and Storage devices) to a specialist third party who accesses the systems remotely has several benefits. An intelligent approach to RIMS could save you up to 40% of your IT operations costs, give you access to a diversified skilled resource pool, reduce the costs and efforts associated with recruiting and training people to handle these tasks and free up those resources to focus on your core business. Applying service delivery best practices from ITIL and tight measurement of the SLAs being delivered are the two key elements to deriving the maximum from RIMS.

Tool based IT infrastructure management is a growing trend that makes RIMS more proactive in its approach. Not only do these tools perform recurring tasks automatically, they provide for proactive identification of possible problems and resolve them before they occur. In the quest to create an effective RIMS framework the identification of these tools is the first step.

Some of the critical functions of proactive RIMS tools are outlined below. These should form part of your checklist while you evaluate your investment in RIMS.

  • Monitoring & Automated Ticketing Tools: Does the RIMS tool provide for monitoring of user defined parameters such as CPU load, disk space with the use of integrated dashboards? This is essential to a business where different IT users come with different requirements based on business needs. The monitoring system should also issue automated notifications (emails, SMS alerts) and generate automated tickets. Monitoring of performance across the system should also be enabled with the option of generating reports that provide actionable information.
  • Patch Management: Can the management of patches being deployed be made human interaction independent? So also the task of making antivirus updates. These greatly reduce the load on human resources and are a more efficient way of handling recurring tasks.
  • Remote Access, Control and Monitoring: Does the system allow remote access to the affected servers or desktops to enable support staff to directly trouble shoot and resolve the issues? The ability to support heterogeneous environments is a desirable feature as well.

In following blogs we will examine the role of ITIL in effective management of RIMS, drawing upon the basic requirement of aligning IT and business objectives.

To know more about how GSS assists in setting up proactive RIMS frameworks for your business click here www.gssinfotech.com

Evolution of RIM

The Evolution of Remote Infrastructure Management (RIM) has not happened overnight. It is the result of years of thinking that transformed basic labor arbitrage into meaningful business solutions. Though the primary intention was to reduce cost, the benefits of RIM go far beyond than that. With rapid advancement in tools, processes and technologies (the advent of robust enterprise tools, ubiquitous broadband coverage and highly skilled technicians, etc), RIM offshoring is fast becoming an effective solution and strategy for CIOs wanting to better use of labor arbitrage, providing reliable IT services without compromising on service quality or network performance.

The primary customer pain points that made IT managers sit up and find RIM as a better alternative were:

  • Lack of centralization and person-dependent processes hampering productivity
  • Unclear or undefined pricing models
  • Lack of service level commitment
  • Frequent system or service failure
  • Absence of disaster recovery solutions

With RIM, they saw higher productivity, lower cost, and of course better resource utilization and process improvement. In addition, RIM offshoring also empowered them with technology, tool, and resource availability 24/7/365.

RIM has evolved from tools for device management to integrated offerings that are capable of supporting end-to-end IT services. This has led to a major paradigm shift in remote infrastructure management —hardware utilization, procurement, and financial capabilities to IT architecture flexibility and productivity.

RIM services provide a single window that caters to all IT infrastructure needs and aims at transforming the IT infrastructure of customers that not only ensure a well managed Infrastructure support services but also provide competitive advantage by delivering more value to the end user.

Remote Infrastructure Management Offerings
Remote Infrastructure Management offered by most companies includes:

  • Remote monitoring services
  • Administration
  • Reporting
  • Vendor co-ordination
  • Trend-based consulting
  • 24×7 infrastructure management

Remote Infrastructure Management and Cloud
Speaking on these lines, it is worth mentioning that RIM outsourcing and cloud can go a long way together. Considering that today’s businesses are waking up to the multifarious benefits of Cloud are have already started moving their applications (like email, ERP, and CRM suites) on to the cloud means good news for RIMS providers. Companies are now planning to manage and monitor private clouds long term and turn to RIM outsourcing as a solution.

For More Information Visit: www.gssinfotech.com

GSS Infotech Achieves CMMI Level 5

GSS Infotech, a leading IT managed services provider with headquarters in Hyderabad, India today announced that it has been successfully assessed at the highest maturity Level 5 of the SEI CMMI-DEV model.

The appraisal was conducted by SITARA Technologies Pvt Ltd., in accordance with theStandard CMMI Appraisal Method for Process Improvement(SCAMPI)methodology and assessed the software development process within the Application Development & Maintenance, (AD&M) Unit, GSS America Infotech Ltd*, Hyderabad, Andhra Pradesh, India, at the Maturity Level-5 (Optimizing Level) of CMMI-DEV v1.2.

On this accomplishment, Mr. Bhargav Marepally, GSS Infotech CEO, said that,“the high maturity journey of GSS has ensured alignment of business objectives and software processes with the CMMI-DEV v1.2 based process improvement model. The Level 5 achievement recognizes our abilities to delight customers as an elite partner and deliver significant business benefits.”

The MD of GSS Infotech, Mr. Ramesh Yerramsetti stated that,“The assessment at Level 5 is the assurance of our continued commitment to deliver cost effective, time-bound and high quality services to all our customers.”

Mr. Siva Kumar Nuti, GSS COO, said that the“CMMI Level 5 achievement is a true reflection of our focus on process optimization and innovation in service delivery.” He went on to say, “This is a key milestone in our quality journey and going forward, our endeavor is to sustain this momentum and drive continuous improvements.”

Commenting on this appraisal, Mr. Raghav Nandyal, the SEI Certified High Maturity Lead Appraiser, observed that, “the AD&M unit of GSS America Infotech* successfully demonstrated the required capability to operate at higher levels of software development maturity. This process capability, coupled with leadership team’s commitment and support for a clearly defined vision and mission supported by quantitative goals, sets this organizational unit apart from the many in the same category.”

GSS strongly believes and recognize processes and systems form the backbone of any people intensive IT services organization. GSS started its quality journey with the certifications of ISO 9001 and CMMI Level 3 in 2007. The business processes have been certified to ISO 9001: 2008, ITSM (ISO 20000: 2005) and ISMS (ISO 27001:2005) quality standards and now assessed at Maturity Level 5 of SEI CMMI-DEV v1.2.

*At the time of appraisal, GSS Infotech was known as GSS America Infotech Ltd.

About GSS Infotech:

Founded in 1999 GSS Infotech is a pioneer in applying innovative, technology-based solutions to common business problems. GSS helps organizations leverage the power of virtualization, cloud computing and outsourced models of technology services delivery. Utilizing these technologies, we help organizations gain competitive advantage, reduce costs, ensure system stability, and improve efficiency.

Learn more at: http://www.gssinfotech.com

About CMMI:

Capability Maturity Model Integration (CMMI) is a process improvement approach that helps organizations improve their performance. CMMI can be used to guide process improvement across a project, a division, or an entire organization. CMMI was developed by experts from industry, government, and the Software Engineering Institute (SEI) at Carnegie Mellon University (CMU), USA. CMMI models provide guidance for developing or improving processes that meet the business goals of an organization. A CMMI model may also be used as a framework for appraising the process maturity of the organization.

About SITARA:

SITARA Technologies is a professional services company with core competencies in strategic management consulting, and high maturity process assessments using the Software CMM, People CMM, and the CMMI. SITARA Technologies, Inc., in the USA, is a dedicated research and development center conducting pioneering research in Software Strategies, Competency Management, Software Metrics, Process Automation, and building self-sustaining process improvement programs. SITARA’s proprietary work products and professional services have been rendered in world-class companies such as Affiliated Computer Services, LG-EDS Systems, Inc (South Korea), Motorola (India, Malaysia), Satyam Computer Services Ltd., Network Solutions Ltd. (India), and Visteon Software Operations (India), to name a few. SITARA specializes in high maturity process appraisals. SITARA provides SEI authorized Introduction to CMMI.

On Cloud 9

GSS INFOTECH IS ONE OF THE FASTEST GROWING MANAGED IT SERVICES COMPANIES, HEADQUARTERED IN HYDERABAD, INDIA. FOUNDED IN 1999, IT OPERATES WORLDWIDE THROUGH ITS OFFICES IN INDIA, SINGAPORE, MIDDLE EAST AND THE USA. GSS OFFERS INFRASTRUCTURE AND APPLICATION MANAGEMENT SERVICES TO GLOBAL CUSTOMERS.

With multiple centres of excellence to offer technology services in cloud computing and open source software, it partners with technology vendors such as Microsoft, Cisco, Symantec, APC, tripwire, VMWare, BMC, HP, NetApp, Redhat, netiQ, Cloud.com and Citrix. GSS Infotech was ranked among Forbes’ list of Asia’s 200 Best Under $1 Billion Companies in 2009 and is rated as the “Best Small Cap” in “Asia’s Best Managed Companies” by Finance Asia in 2008.

As a service

Cloud-IT is a proprietary and innovative advisory service, which is implemented using a three step approach, as per GSS Infotech. This approach helps customers determine if adoption of cloud is appropriate for their business. If Cloud adoption is a choice for customers, companies help them in defining a cloud strategy, evaluating and migrating customer’s IT applications and infrastructure to the right cloud platforms.

Siva Kumar Nuti“Using cloud computing has multiple benefits”, says Siva Kumar Nuti, Head, Global Delivery and Operations, GSS Infotech. The most significant among these are pay-per-use, in which it follows a subscription/usage based pricing, low barriers to entry, in which one just needs a credit card to get started, procurement of new software/servers, which earlier used take weeks, now can be done in few minutes.

Among the advantages is also elasticity, in which a user can scale up & down based on the resource utilization, faster time to market & avoid data centre operation costs almost totally.

Pavan MaddaliSpeaking on taking GSS’s business forward with Cloud, Pavan Maddali, CTO, GSS Infotech, says “Cloud is here to stay and is a game changer. Having said that, it is still an unconsolidated market. There are too many players and varied offerings and promises at the moment. Hence there is too much hype, which prevents companies in making the right decisions.”

Cloud initiatives necessitate taking an integrated view of the applications and the underlying infrastructure components else it would prove counter productive. The Cloud-IT methodology helps customers in ‘Underplaying the Excitement’ and ‘Taking the right engineering steps’.

GSS’ Cloud IT framework includes three main steps.

Assimilation – Here, GSS conducts workshops with customers and helps them understand the true value of cloud platforms, available options and assesses the need for utilization of such platforms.

Strategization – GSS conducts workshops with the decision in the customer organization and helps in building their technology roadmap to actualize their desired business outcomes. This will include cost-benefit analysis, ROI calculations along with recommendations on the next steps which may include conducting proof of point evaluation.

Prove and on-board – This involves identifying the scenarios for performing evaluation and creation of a verifiable pilot implementation at very a minimal cost to assess the benefits and implementation challenges. This helps customers in taking a well informed decision on Cloud adoption within their enterprise.

The Big advantage

Using Cloud provides the “computing environments as-a-Service” thus minimizing the capital expenditure in the organization. Also, these environments are “scalable on demand” and this helps to avoid deployment delays.

Organizations tend to struggle with rapid changes in technology resulting in skills shortage, in-house. By moving to a cloud environment they are protected against the skill related concerns. Spending on maintaining a large team of support staff can also be reduced to the minimum and best of all is that if you are a non IT company, you do not have to own IT infrastructure anymore. A cloud company will own and maintain IT infrastructure for you and you get to pay only for what you use.

Infrastructure of the Cloud Infrastructure is maintained by the cloud platform vendors like Google, Microsoft, Amazon etc., in their large data centres. Enterprise customers build their own cloud using existing data centres. They are maintained by internal IT teams or by outsourced IT service providers. Cloud Applications are maintained in the same ways as traditional applications.

In adopting cloud solutions, one has two dimensions to the challenges to deal with, the first set is regarding the cloud infrastructure and the second set pertains to the lack of clarity on what needs to be hosted on the cloud.

From the infrastructure standpoint, there are a few major parameters that enable or inhibit enterprise customers from moving to Cloud. Application performance needs to be same or better than before. Security is the biggest inhibitor of adoption at this time, organizations are not comfortable, yet of moving their data to public environments outside their firewalls. Visibility and control of the cloud infrastructure (for users), is another problem.

The Cloud environment needs to provide extensive monitoring, logging and reporting support to troubleshoot the environment. Cloud Computing environment providers, while claiming a very robust environment, have yet to provide high levels of service guarantees, at an operational level and security level. On the application/solutions front, the biggest inhibitor is the lack of clarity on what applications (from their portfolio) make good business sense to move to cloud.

The second dimension is, while the application in the cloud is very economical, the transformation of applications to be “in the cloud” is expensive and takes time and effort.

GSS Cloud and SaaS Service offerings are developed based on this very understanding to help customers adopt cloud successfully.

GSS, with its expertise in infrastructure virtualization, skills in cloud related platforms is positioned to help customers migrate to a cloud environment and develop applications that run on cloud using these platforms. It strongly believes that customers will take to Cloud as a strategy to minimize their capital expenditure and as the adoption of cloud increases; GSS sees spotential to its offerings that help customers migrate their applications and infrastructure to a cloud environment.

GSS Infotech- What we do

RamananAn IT Services company, headquartered in Hyderabad, India and founded in 1999, GSS Infotech operates worldwide through its offices in India, Singapore, Middle East and the US. GSS offers infrastructure and application management services to customers across the globe. It provides customized infrastructure management services (IMS), which include end user computing services, data centre services, network and security Services, virtualization and cloud computing services.

With multiple centres of excellence in Cloud Computing and Open Source Software, GSS Infotech is a preferred partner with leading technology vendors. Each COE consists of solution architects, developers and analysts who constantly evaluate technologies and develop proof points for customers to evaluate their solutions.

It has embraced open source technologies to build affordable solutions for small and medium businesses across the globe. These solutions include process automation tools for managing sales, human resources, finance, supply chain and workflow processes that are needed to manage businesses.

Remote Infrastructure Management: The Impact of Cloud

What does Cloud Computing actually mean for Remote Infrastructure Management Service providers, and how can they harness its potential to deliver superior value to businesses?

The shift to Remote Infrastructure Management Services (RIMS) has made eminent business sense in the light of increasing levels of service demanded by both internal and external customers. Service providers are seeking ways to make their RIMS contribution more relevant; this is where the adoption of technologies such as Cloud Computing finds mention. But with the hype that surrounds the Cloud and its perceived risks and rewards, what does it actually mean for RIMS providers and their customers?

The case for RIMS has been founded on the simple fact that as a business you should be focusing on what you do best. By outsourcing the function of monitoring and managing the IT infrastructure components, you are left with more time and resources to focus on your core functions. It is possible to bring down IT infrastructure management costs up to 60% by outsourcing intelligently.

Let us take a look at Cloud Computing before we examine its effect on RIMS. In theory, taking an application onto the Cloud should provide the following key benefits:

• Eliminate (or significantly reduce) need for the customer to invest in IT infrastructure
• High scalability to adjust rise or fall in user demands for resources,

Businesses waking up to seeming benefits of Cloud are seeking to begin by moving their applications like email, ERP and CRM suites and even parts of computing infrastructure like storage networks on to the cloud rather than keeping them on the traditional infrastructure incurring more expenditure on maintenance and management. This continuing trend could see SMBs leveraging the Cloud for IT infrastructure management thus having a resultant impact on traditional RIMS providers.

Let us begin by looking at reasons businesses do not trust the cloud entirely, and how RIMS can address these reasons and harness Cloud’s power:

How secure will my data be on the Cloud? It is not easy for a CIO to rest easy when sensitive business data is sitting on servers that the company has no control over. Though there are ways to address this concern, RIMS providers will do well to offer storage across Cloud networks where data security is assured.

What if the on-demand payment model ends up costing more? This question can only crop up if the payment model is not clearly defined. There is no way a nebulous payment model will make sense to a value seeking business, and clear definitions of the pay-as-you-go model need to be worked out, in terms of scenario analyses and modeling to let CIOs rest assured that their decision will save costs.

How can I bring operations back in-house in case I’m not satisfied? The fact of the matter is that moving lock stock and barrel to the Cloud may not make immediate business sense considering the emerging nature of the technology. RIMS providers need to build in the flexibility in the system to handle this scenario.

To conclude, the ability to deliver monitoring and management services for a client’s IT environment through an offsite shared service delivery model while harnessing the cost-effective model based on the Cloud can see businesses freeing up IT investments. The way ahead for RIMS providers would be to package Cloud based solutions and services to enable SMBs to make the shift. It would not be long before the allaying of fears surrounding the Cloud results in it becoming a part of most IT investment forecasts.

Desktop Virtualization: The Reality and the Myth

Does Virtualization of Desktops or end points mean startling savings and enhanced user-experiences alone? We examine the claims with a pinch of reality.

A recent Gartner study reports a startling statistic: Any matured or well managed enterprise spend an average of $5000 annually on managing a single end-point machine (the humble desktop or laptop). This is exclusive of the cost of applications installed; rather it is the cost of the effort involved in ensuring that it is productive to the end-user! This fact has been influential enough to send CIOs across the board scouring the IT landscape for vendors who can rapidly deploy Virtual Desktop Infrastructure (VDI) as a solution, and take the stress of managing individual machines out of the daily agenda and let the business users do the work they do best. But this blog post examines this euphoric quest with a pinch of reality.

There is no doubting the fact that there are several benefits that arise out of anytime, anywhere access that VDI enables: Thin Clients at work and Net Books while telecommuting are enabling a growing workforce to work without having to spend time and money on traveling to work. Coupled with instant scalability to meet emerging business needs, the ability to streamline software upgrades, and insure against data loss via the security of a central repository, VDI appears to be the silver bullet. The bottom-line is clear: VDI has the potential to save you TCO (Total Cost of Ownership) by bringing down capital expenditure (Capex) as thin clients are cheaper and sturdier, and the ability to remotely manage and resolve issues on a virtual infrastructure reduces desktop maintenance and management costs remarkably.

But this is where the CIO needs to pause and take a look within the organization to see if there is something more to VDI than what it appears. Additional licensing costs associated with virtualization, management, and desktop software could offset the advantages of lower capital outlay. That’s not all, more demanding desktop engineering requirements that stem from the complexity of designing and managing VDI environments can drive up costs.

That’s not all. According to another study by Gartner VDI may not be geared up to handle the high IOPS (Input/Output per Second) levels of ‘chatty’ Operating Systems like those on the Windows platform. Whether it is server performance, storage hassles or network issues of the average office worker, the traditional fat-client model may score higher on all the counts over VDI.

At the end of the day it is the user needs that should determine the decision. Rather than focus on Return on Investment (RoI) in VDI, which most impact measurements speak of, it would be worthwhile to look at Total Cost of Ownership (TCO) which in any scenario looks at a combination of Capex, cost of OS, applications, and the cost of managing and supporting the users.

That’s not all. There’s more to go. The needs of users vary with the nature of the business that the company is involved in. For instance, take the case of a Design Engineer whose job is to create intricate designs using advanced tools in the realm of CAD/CAE. Typically such users need a plethora of applications that run out of different platforms to effectively execute their tasks. This user scenario would not benefit from VDI, because the cost involved in virtualization of such a specific environment far outweighs the savings from it. It has been seen that users who have purely transactional business needs with a limited number of applications draw the maximum benefit from VDI. Accounting, purchasing and order processing are examples that come to mind.

Determining your readiness for virtualization is an area where GSS specializes: our process-driven approach makes the use of the VDI-Fitment Tool that takes into account the nature of your business and the needs of your users before coming up with an answer to whether VDI will deliver actually the value that it promises. We have the necessary expertise to take the call whether virtualization makes sense for your work environment.

Would you like to know more about how we can make VDI work for you? Click here to read more about GSS Infotech’s service offerings in this space.

Shifting Paradigms: A Fresh Approach to Application Security Frameworks

The gap between hacker threats and suitable security defenses is widening, faster than ever[1] – Forrester Research, August 2010.

The need for security in IT systems is greater than ever as businesses operate in today’s uncertain environment. This need runs the gamut of all aspects of the IT universe — Applications, Networks, Systems, and Databases, etc. Today’s threat canvas spares no aspect of IT, and things that were taken for granted until recently are now at risk unless steps are taken, and this translates into a need for robust security testing frameworks.

Even though security managers realize the need to keep up with an ever-changing landscape of threat perceptions their efforts are hamstrung by two key reasons: efforts towards superior security are undertaken in isolation, and security testing is largely treated as an afterthought towards the end of the software development lifecycle. Rather than a reactive approach as has been the trend in the past, it would make eminently more sense to incorporate the rigor of the Security Testing methodologies before the threats loom overhead.

The critical link in the chain with organizations are now waking up to is for security testing to be built into the Software Development Life Cycle (SDLC) rather than be a retro-fitted activity that begins once  a security threat is detected. Integration of security testing with SDLC provides early visibility to security vulnerabilities and defects. This provides sufficient time to deploy remedial measures.  This integration involves tasks right from the Inception state all the way to Transition.

Abuse Cases, Threat Modeling and Risk-based Security Testing are some of the activities that need to come in during the early stages of the SDLC creating an effective security perimeter around the application development exercise. As the lifecycle draws to a conclusion, tasks such as Penetration Testing, and finally a continuous evaluation of extant threats and their mitigation plans need to form a part of the plan from the start. Ongoing analysis and review of threat mitigation should form a part of the cycle.

At GSS we help clients build robust Security Testing Framework and so that they mitigate risks before they become risks. For more information on this, visit us at www.gssinfotech.com


[1] August 13, 2010, ‘The New Threat Landscape: Proceed With Caution’, Kark, Khalid, Forrester Research

Widen your vision: Experience Exchange 2010 on a virtualized platform

Running Windows exchange 2010 on a virtualized platform (with Hyper-V or VMware ESX) gives you a plethora of availability and recovery options, each providing varying levels of protection and cost.

Zero time invested in upgrade or system downtime:

A good deal of time, energy, and capital is involved in traditional physical environmental upgrades. It also means risk of data loss and extra time required for the recovery process. Virtualizing exchange server helps save substantial amount of time and money in the following ways—

  • Planning and implementation time
  • Sizing and acquisition of new hardware
  • Downtime for system upgrade, which incurs higher costs and risks of data loss

Faster data recovery minus time and data loss:

Data recovery and systematic storage are the two main concerns for IT professionals. Virtualized Exchange environments can help you recover from:

  • Planned or unplanned hardware outages
  • Hardware degradation
  • Application failure or Failover Clusters

Virtualized capability automatically balances workloads and shared storage on a virtual platform helps in keeping incidents of application failures at bay.

High performance mailbox servers:

Running your exchange server 2010 on a virtualized platform gives you the advantage of enormous largest mailbox server which that exceeds physical performance. In addition, you get the following—

•Virtual Machine scalability up by 8 vCPU and 256 GB of memory

• Disk IO scalability increased to more than 350,000 IOPS, enabling VMware ESX to support IO-intensive applications such as Exchange and large Databases

• Network IO increased to 40 Gbps

This also means enhanced architecture and improved features of Microsoft Exchange 2010 and 2007 that significantly reduce the IO requirements as compared to Exchange 2003.

Do more with enhanced exchange infrastructure:

A virtualized platform for windows exchange server 2010 allows you to scale exchange mailboxes on multiple smaller virtual machines to maximize the throughput of the physical server. Windows Exchange server can be scaled out on 8 Virtual Machines, each supporting 2,000 very heavy mailbox users, to support 16,000 users on one 16-core server.

GSS Infotech, which has VMWare as one of its strategic alliances helps you leverage the inherent benefits of a Microsoft® Exchange Server 2010 deployment on VMware vSphere.