Friday, January 13, 2012

Agile PMO

Over at Eight to Late, Mike Griffiths has a slide presentation on the agile PMO. He tells how the PMO can go from Present Many Obstacles to Provide Many Opportunities.

It's a nice play on the words, but there are some instructive ideas in the slide deck (available for download), if you can abide the agile-is-only-way arguments.

First, Griffiths builds the presentation around 9 bullets that are the things that PMO's are supposed to do:


Then he fills in details--from his point of view--about how traditionally managed PMO's need to change--a new game theory in his mind--to be compatible and useful to agile projects.

Of course, a balanced point of view is not Mike's forte. This is a red meat "preaching to the choir" presentation given to an agile conference of agilists.

For example, under bad old way, we read:
Monitor and control project performance – track progress against
inappropriate measures such as getting requirements fully documented and
signed off

Under agile is the silver bullet, we read:
Monitor and control project performance – track velocity, track team and
sponsor satisfaction ratings, look for dangerous velocity trends, check
backlog size, monitor iteration and release plans

Now, I count myself among practical agilists, as explained in my book, but I also know that literally billions of lines of code written the bad old way are up and working fine, so whereas I agree this generation has a good idea in agile, it's not the only game in town.

For another perspective on portfolios and agile, take a look at this:



Wednesday, January 11, 2012

Disorder

Brian Greene is a superstring theoretical physicist and mathematician with a flair for communications. This fall he has been hosting a public broadcasting series on the fabric of the cosmos, based in part on his book, brilliantly written, of the same title.

Of course, the fabric of the cosmos is not about project management, but it is about complexity, and that's something we all endure in projects and in life.

One principle Dr Greene writes about struck me as spot on: the more complex a system is, the more disorderly it is. In fact, the natural tendency of complex systems, if not otherwise constrained, is to seek disorder.

On one level it's intuitively obvious: the number of communication paths between N devices approaches N-squared when N is large. Every communication path is a potential pathway to trouble.

So, when I read the literature on Lean thinking, the ideas of small batches, limited backlog, and minimialist tasks is all the more striking. Maybe the lean guys are onto something!

And the agilists and Kanban'ers have it going also: keep everything as small and simple as possible--like one sentence story cards and simple use case models--just like our friend Einstein counseled ("Make everything as simple as possible but not simpler"). Of course the simplest possible can still be complex, but at least we made the effort.

And, one more thing: that principle we started with--it was developed in the 19th century as the 2nd Law of Thermodynamics. Who knew!?

Monday, January 9, 2012

Adopting agile

To succeed with agile, management’s need for results must be greater than their need for control. —Israel Gat, formerly of BMC Software

This statement is so profound, I think I'll just let it stand on its own.

Source: Originally quoted by Dean Leffingwell in "Agile Software Requirements", Chapter 22.

Delicious Bookmark this on Delicious
 

Saturday, January 7, 2012

Predicting the future

The best way to predict the future is to invent it
Alan Kay, computer scientist

One might have thought this would have been a Steve Jobs quote, but no--there are other innovators.

Of course, the point is that opportunities are only as valuable as we make them by engaging and applying ingenuity and effort. And, if the future is not as bright as needed, then envision what's needed and go "all in"

Thursday, January 5, 2012

IT risk management spending

In a recent posting, we are told that IT spending on various business services for risk management in business processes will out pace the traditional IT spending on financial applications.  Everything from asset management to information security. 

And, in another article, we are told that personal data privacy is only going to grow in importance and compliance demands. That's a good thing!

Wow! That's quite a development. Perhaps risk management has arrived at last.

And to projects and project managers, it all rolls downhill. We should expect to be evaluating, developing, and validating all manner of risk management applications and services.

And here's a thought: We may find ourselves using risk management to evaluate risk management!

Tuesday, January 3, 2012

NICE Cyber

The National Initiative for Cyber Education (NICE) is hard at work.  From their website, we learn that: "Today, there is little consistency in how cybersecurity work is defined and described throughout the nation. The lack of a common language to discuss and understand the work requirements of cybersecurity professionals hinders our nation's ability to:
-Baseline capabilities,
-Identify skill gaps,
-Develop cybersecurity talent in the workforce, and
-Prepare the pipeline of future talent."

Thus, a workforce framework has been developed by NICE, a unit of the National Institute of Standards and Technology (NIST).

The seven NICE categories are:

1. Securely provision - conceptualizing, designing and building secure IT systems;
  • Information assurance compliance
  • Software engineering
  • Enterprise architecture
  • Technology Demonstration
  • Systems requirements planning
  • Test and evaluation
  • Systems development.

2. Operate and maintain - the support, administration and maintenance necessary to ensure effective and efficient IT system performance and security;
  • Data administration
  • Information system security management
  • Knowledge management
  • Customer service and technical support
  • Network services
  • System administration
  • Systems security analysis.

3. Protect and defend - the identification, analysis, and mitigation of threats to IT systems and networks;
  • Computer network defense
  • Incident response
  • Computer network defense infrastructure support
  • Security program management
  • Vulnerability assessment and management.
4. Investigate - investigation of cyber events or crimes, which occur within IT systems or networks, as well as the processing and use of digital evidence;
  • Investigation
  • Digital forensics.

5. Operate and collect - the highly specialized collection of cybersecurity information that may be used to develop intelligence;
  • Collection operations
  • Cyber operations planning
  • Cyber operations.
6. Analyze - review and evaluation of incoming cybersecurity information to determine its usefulness for intelligence;
  • Cyber threat analysis
  • Exploitation analysis
  • All source intelligence
  • Targets.
7. Support - specialty areas that provide critical support so that others may effectively conduct their cybersecurity work;
  • Legal advice and advocacy
  • Strategic planning and policy development
  • Education and training.