Invensys, the $2B London-based industrial conglomerate, has announced that it is looking to divest its holdings in a number of its businesses, including Baan. Baan, once an up-and-coming contender to SAP, fell onto hard times in the late 1990s and was acquired by Invensys in 2001 as part of its strategy to provide enterprise systems "from the plant floor to the boardroom." But Invensys itself is facing a slump in demand and needs to find ways to increase cash. The move creates additional uncertainty for the Baan installed base. Baan's announcing its intentions prior to having a deal in place certainly didn't help sooth the concerns of users. Unfortunately, good choices for ERP from financially stable vendors are becoming fewer and fewer.
As a side note, AMR is reporting that the Invensys Protean ERP product for the process industries and the Wonderware MES are not part of the divestiture plan.
Computerworld has some observations from customers and analysts on Baan's situation.
Since 2002, providing independent analysis of issues and trends in enterprise technology with a critical analysis of the marketplace.
Wednesday, April 16, 2003
Monday, April 14, 2003
Microsoft sees enterprise applications as key to future growth. BusinessWeek has a good overview of Microsoft's plans to establish itself as a dominant play in enterprise applications, such as ERP and CRM, for small and mid-size businesses. I wrote previously about the problems Microsoft will face in executing this strategy, especially in terms of competing against its current ISV partners and creating channel conflict among its resellers. BusinessWeek points out that Microsoft intends to train the 24,000 resellers of its system software to sell its applications also. I don't understand how this can fail to result in channel conflict and dissatisfaction among those value-added resellers (VARs) that really understand how to sell and implement enterprise systems.
Monday, April 07, 2003
On a personal note. On Wednesday evening, April 16, I'll be speaking at the joint dinner meeting of APICS Orange County and ASQ on the subject of "Enterprise Systems in an FDA-Regulated Environment." Here's the abstract.
Reservations are due by noon, April 14, and may be made by calling APICS Orange County at (949) 863-7625. Or, contact me if you would like more information.
Manufacturing firms in all industries use computer systems, such as ERP, Product Data Management, Supply Chain Management, and Quality Management to meet requirements for managing resources and ensuring product quality. But companies in regulated industries, such as the life sciences (pharmaceuticals, biotech, medical devices, etc.), must comply with additional governmental requirements to ensure the integrity and trustworthiness of such systems.
In this fast-moving presentation, Frank Scavo will outline how FDA regulations affect the use of computer systems in the design, manufacture, and distribution of medical devices, drugs, and biologic products. Specifically:
- How FDA regulations for Good Manufacturing Practices (GMP) and Quality Systems affect use of computer applications such as such as ERP, Supply Chain Management, and Product Data Management
- What FDA expects you to do to validate a computer system "for its intended use"
- New FDA draft guidance regarding use of electronic records and electronic signatures (21 CFR Part 11)
Saturday, April 05, 2003
PeopleSoft is tired of being the best kept secret in supply chain management. PeopleSoft is well-known as an ERP developer with strong roots in the HR function. But what is not well known is that when it comes to supply chain management (SCM) applications, PeopleSoft has more installs than Manugistics, a big name in SCM. Last year, AMR released statistics that show PeopleSoft with 7% of the SCM installed base, following SAP (26%), in-house/custom (23%), Oracle (10%), and i2 (9%). Manugistics has 5%. Interestingly, the category "other" has 38%, showing that the supply chain management category is still a highly fragmented market and ripe for a financially sound vendor such as PeopleSoft to increase market share.
Recognizing this opportunity, PeopleSoft lately has been pushing its significant capabilities in SCM. Last year, PeopleSoft hired Patrick Quirk out of i2, to serve as VP and GM of PeopleSoft's SCM division. This year, the release of PeopleSoft 8.8 is slated to include increased functionality for supply chain planning and better integration with the rest of the enterprise suite. This latter point is important because for too long PeopleSoft has allowed its SCM modules, which it picked up years ago in its acquisitions of Red Pepper and Distinction, to stand apart from its core system. In Version 8.8, these modules are now completely rewritten in PeopleSoft's development toolset, PeopleTools. It is also being reported--and a local PeopleSoft sales manager confirms--that PeopleSoft is hiring over 100 new salespeople. Expect to see a good part of these feet on the street to be hunting for SCM deals.
Manufacturing Systems has more on PeopleSoft's renewed focus on SCM.
Recognizing this opportunity, PeopleSoft lately has been pushing its significant capabilities in SCM. Last year, PeopleSoft hired Patrick Quirk out of i2, to serve as VP and GM of PeopleSoft's SCM division. This year, the release of PeopleSoft 8.8 is slated to include increased functionality for supply chain planning and better integration with the rest of the enterprise suite. This latter point is important because for too long PeopleSoft has allowed its SCM modules, which it picked up years ago in its acquisitions of Red Pepper and Distinction, to stand apart from its core system. In Version 8.8, these modules are now completely rewritten in PeopleSoft's development toolset, PeopleTools. It is also being reported--and a local PeopleSoft sales manager confirms--that PeopleSoft is hiring over 100 new salespeople. Expect to see a good part of these feet on the street to be hunting for SCM deals.
Manufacturing Systems has more on PeopleSoft's renewed focus on SCM.
Tuesday, March 18, 2003
RIAA continues crackdown on piracy on corporate networks. Reuters is reporting that the RIAA, an industry association of the major record labels, has sent letters to 300 U.S. companies complaining about alleged acts of piracy and copyright infringement in their corporate computer networks and warning of possible fines. The RIAA is not disclosing which companies received the letter, but it backed it up with evidence of piracy, listing specific instances where individuals on the companies' networks accessed file-sharing services such as Kazaa and iMesh. The letter was also sent with a CD containing copies of pirated materials found on the recipient's corporate network being offered for file sharing. As I wrote earlier, companies need to do their own desktop auditing to ensure that their house is in order, or face significant legal liability. CIN has an article on the RIAA's latest actions.
Wednesday, March 12, 2003
Strengthening the weak link in enterprise system security. Last year, I wrote a short post pointing out that the weak link in enterprise security is the user, in particular the typical user's inability to formulate or remember strong passwords. Strong passwords -- those that follow certain rules such as minimum length, mix of characters and numbers, and avoidance of dictionary words, etc.-- are difficult to break, even with automated cracking tools. But strong passwords are difficult to remember. So, most users recycle the same personal passwords over and over, employing names of spouses or pets or birthdays that are both easy-to-remember and easy-to-guess. It's a serious problem. One report last year found that a consultant hacker using a publicly available password cracking program was able to hack or crack 30% of the passwords for 10,000 user accounts at a health care firm -- in less than an hour!
So, I paid attention when David Harding from BrowserPlus offered a couple months ago to let me beta-test a new "extension" to Internet Explorer, called Login Manager, which he claimed was a solution to the problem of maintaining strong passwords. The program does a lot: it provides a searchable bookmark capability, it can automatically populate Web forms and log you into a favorite site with a single click, and it can generate, remember, and manage strong passwords. This last point is goes to the heart of the "weak link" problem.
Login Manager turns typical password administration upside down. Instead of asking the user to generate or remember a strong password, the Login Manager can be configured to manage all passwords on behalf of the user. For the highest level of security, an organization’s security administrator can even hide passwords from the users themselves. Although hiding passwords from users might seem counter-intuitive, there are several attractive benefits to this approach:
Because Login Manager operates as an extension to Internet Explorer, it won't administer passwords for legacy client-server or mainframe systems. Still, with more and more systems adopting a browser client, in some companies it could serve as an important element of a comprehensive security policy.
A 30 day free trial of the Login Manager (both home and professional editions) is available at the BrowserPlus web site.
So, I paid attention when David Harding from BrowserPlus offered a couple months ago to let me beta-test a new "extension" to Internet Explorer, called Login Manager, which he claimed was a solution to the problem of maintaining strong passwords. The program does a lot: it provides a searchable bookmark capability, it can automatically populate Web forms and log you into a favorite site with a single click, and it can generate, remember, and manage strong passwords. This last point is goes to the heart of the "weak link" problem.
Login Manager turns typical password administration upside down. Instead of asking the user to generate or remember a strong password, the Login Manager can be configured to manage all passwords on behalf of the user. For the highest level of security, an organization’s security administrator can even hide passwords from the users themselves. Although hiding passwords from users might seem counter-intuitive, there are several attractive benefits to this approach:
- As Kevin Mitnick points out, the easiest way to steal a password is to ask the user for it. A significant number of users are vulnerable to "social engineering," where the password thief over the phone poses as someone with legitimate need for the password. But if users don't know their own passwords, they can't give them away.
- If employees don't know passwords, they can’t share them with friends or relatives. No more "sharing" of access to proprietary research sites, such as Gartner. More seriously, no more sharing of access to company intranets with outsiders, such as recruiters, or competitors.
- If employees don't know passwords, they can't take them when they leave the company. No more worry about terminated employees continuing to access employer Web accounts or extranets.
- Finally, in some departments (e.g. purchasing) it is necessary for several users to share a common "corporate account" and password (e.g. several buyers in Purchasing using a common account for an e-commerce site). But if the users don't actually know the password, it's no longer necessary to change it every time one of them leaves the company.
Because Login Manager operates as an extension to Internet Explorer, it won't administer passwords for legacy client-server or mainframe systems. Still, with more and more systems adopting a browser client, in some companies it could serve as an important element of a comprehensive security policy.
A 30 day free trial of the Login Manager (both home and professional editions) is available at the BrowserPlus web site.
Tuesday, March 04, 2003
Technology trends, 2003 and beyond. Andrew Grygus has a very long and interesting analysis of current information technology trends. It goes pretty deep in terms of Microsoft directions. Although the focus is on the small business segment, much of it applies generally.
Friday, February 21, 2003
FDA drops the other shoe on Part 11
FDA has just announced that it is issuing a single new draft guidance document for 21 CFR Part 11, and it is withdrawing all prior agency draft guidance on Part 11. In its announcement, FDA stated clearly that a re-examination of Part 11 is already underway that may result in revision of Part 11 itself. FDA also indicated that for the time being it will "not normally take regulatory action to enforce Part 11 with regard to systems that were operational before August 20, 1997. . . while we are examining Part 11." In other words, for now, legacy systems are grand-fathered. Furthermore, FDA indicated specific concerns over some Part 11 requirements for validation, audit trails, record retention, and record copying.
I was at the Medical Device Manufacturing conference in Anaheim when word began to spread through the exhibit floor regarding this announcement. But after carefully reading the new guidance this morning, it is clear that FDA is not abandoning its concern about use of computer systems. I say this for three reasons:
As I wrote earlier this month, FDA is not abandoning its interest in regulating use of electronic records and electronic signatures. Regulated companies should continue to implement the administrative and procedural controls called for by Part 11, since for the most part they are not difficult to implement, and they represent best security practices that will increase the trustworthiness and reliability of any system. Vendors of packaged software (such as ERP, PDM, document management, and quality assurance systems) that are working on adding technical controls required by Part 11 should continue their efforts. Nevertheless, FDA’s announcement gives both users and software vendors some breathing space to implement proper controls over electronic records and signatures, with hope of a more well-defined risk-based approach to Part 11 to come in the future.
I was at the Medical Device Manufacturing conference in Anaheim when word began to spread through the exhibit floor regarding this announcement. But after carefully reading the new guidance this morning, it is clear that FDA is not abandoning its concern about use of computer systems. I say this for three reasons:
- Even though FDA withdrew Part 11 guidance regarding validation, validation of computer systems is still a requirement under predicate rules (e.g. 21 CFR Part 210, 211, and 820). Validation was a requirement even before Part 11 was originally promulgated.
- FDA stated clearly that it will continue enforcement of certain controls for closed systems (11.10) and open systems (11.30), such as limiting access, operational checks, authority checks, device checks, and administrative/procedural controls.
- FDA stated it would continue to enforce all of the Part 11 requirements for electronic signatures. Nearly no legacy system meets these requirements without remediation or adoption of a hybrid system of handwritten signatures executed to electronic records.
As I wrote earlier this month, FDA is not abandoning its interest in regulating use of electronic records and electronic signatures. Regulated companies should continue to implement the administrative and procedural controls called for by Part 11, since for the most part they are not difficult to implement, and they represent best security practices that will increase the trustworthiness and reliability of any system. Vendors of packaged software (such as ERP, PDM, document management, and quality assurance systems) that are working on adding technical controls required by Part 11 should continue their efforts. Nevertheless, FDA’s announcement gives both users and software vendors some breathing space to implement proper controls over electronic records and signatures, with hope of a more well-defined risk-based approach to Part 11 to come in the future.
Friday, February 14, 2003
Corporations—the next target for crackdown on piracy
Just three weeks ago, I predicted that large corporations would be the next target for the entertainment industry’s crackdown on Internet piracy of copyrighted media content. But it turns out that my prediction is coming true faster than I expected. The entertainment industry is already distributing a brochure to hundreds of corporations around the world, urging them to take action against employee downloading, or face legal consequences. ZDNet has a full report on this latest warning from the entertainment industry.
As I noted earlier, companies need to get their desktops under control. Many companies already have policies in place regarding acceptable use of corporate systems and desktops, but many of the same companies do not take the next step to directly audit desktops for compliance. All companies, large and small, need to adopt periodic desktop auditing as a best practice to mitigate liability.
My firm, Strativa, has already conducted one such audit on behalf of a large company, with a worldwide network, and the results were a real eye-opener. We wrote a white paper on the subject, which is available here [no longer available--contact me if interested--FS].
As I noted earlier, companies need to get their desktops under control. Many companies already have policies in place regarding acceptable use of corporate systems and desktops, but many of the same companies do not take the next step to directly audit desktops for compliance. All companies, large and small, need to adopt periodic desktop auditing as a best practice to mitigate liability.
My firm, Strativa, has already conducted one such audit on behalf of a large company, with a worldwide network, and the results were a real eye-opener. We wrote a white paper on the subject, which is available here [no longer available--contact me if interested--FS].
Wednesday, February 05, 2003
FDA signals change in approach to Part 11
Last week, FDA announced that it is withdrawing its draft guidance regarding the electronic copies requirements of 21 CFR Part 11. This is good news for all companies regulated by FDA. When FDA first issued this draft guidance less than three months ago, it was clear to me that if something wasn’t changed it was going to be nearly impossible to implement. For example, the guidance called for companies to provide FDA with capabilities to "perform the same kinds of data processing" on the electronic copies that the company’s own system allows on the original records. Other consultants I’ve spoken to had basically the same reaction. So, withdrawal of this guidance is welcome.
There are hints that FDA soon may be making more changes to its approach to Part 11. FDA made this announcement in the context of the initiative it began last August to update its current good manufacturing practice (cGMP) program to a more risk-based approach. In this context, FDA indicates that the withdrawn guidance on Part 11 "may no longer represent FDA’s approach under the CGMP initiative." Furthermore, FDA announced that main responsibility for implementing Part 11 is shifting from the Office of Regulatory Affairs to the Center for Drug Evaluation and Research (CDER), the FDA center that regulates drugs.
The implications of FDA’s announcement are a) that a more risk-based approach to Part 11 may be forthcoming, something that practitioners have been calling for since Part 11 was first promulgated, and b) that Part 11 should be applied on an industry-specific basis, by those who best understand industry issues and risks. Although CDER will take the lead in implementing Part 11, it would seem likely that inspection to Part 11 would take place by investigators from each FDA Center.
Companies struggling with Part 11 compliance should view FDA’s announcement and its implications as providing some breathing space--not as an abandonment of FDA’s interest in regulating use of electronic records and electronic signatures. Regulated companies should continue to implement the administrative and procedural controls called for by Part 11, since for the most part they are not difficult to implement, and they represent best security practices that will increase the trustworthiness and reliability of any system. Vendors of packaged software (such as ERP, PDM, document management, and quality assurance systems) that are working on adding technical controls required by Part 11 should continue their efforts. Nevertheless, FDA’s announcement may indicate that both users and vendors may be able to deal with Part 11 with less uncertainty than in the past.
For more discussion on Part 11 and its implications for users and vendors, see the posts I wrote in October, November, and December of last year.
There are hints that FDA soon may be making more changes to its approach to Part 11. FDA made this announcement in the context of the initiative it began last August to update its current good manufacturing practice (cGMP) program to a more risk-based approach. In this context, FDA indicates that the withdrawn guidance on Part 11 "may no longer represent FDA’s approach under the CGMP initiative." Furthermore, FDA announced that main responsibility for implementing Part 11 is shifting from the Office of Regulatory Affairs to the Center for Drug Evaluation and Research (CDER), the FDA center that regulates drugs.
The implications of FDA’s announcement are a) that a more risk-based approach to Part 11 may be forthcoming, something that practitioners have been calling for since Part 11 was first promulgated, and b) that Part 11 should be applied on an industry-specific basis, by those who best understand industry issues and risks. Although CDER will take the lead in implementing Part 11, it would seem likely that inspection to Part 11 would take place by investigators from each FDA Center.
Companies struggling with Part 11 compliance should view FDA’s announcement and its implications as providing some breathing space--not as an abandonment of FDA’s interest in regulating use of electronic records and electronic signatures. Regulated companies should continue to implement the administrative and procedural controls called for by Part 11, since for the most part they are not difficult to implement, and they represent best security practices that will increase the trustworthiness and reliability of any system. Vendors of packaged software (such as ERP, PDM, document management, and quality assurance systems) that are working on adding technical controls required by Part 11 should continue their efforts. Nevertheless, FDA’s announcement may indicate that both users and vendors may be able to deal with Part 11 with less uncertainty than in the past.
For more discussion on Part 11 and its implications for users and vendors, see the posts I wrote in October, November, and December of last year.
Subscribe to:
Posts (Atom)