Tuesday, October 28, 2014

Happy Birthday: Mainframe Security Celebrates 50 Years

•   April 8, 2014


You Use Mainframes Everyday and Might Not Know It

Mainframe
You may not realize it, but mainframes play a large part in your everyday activities. Did you visit your ATM? Make airline reservations? Swipe your credit card? Then you “touched” a mainframe today. Did you know that 80 percent of the world’s corporate data resides on or originates from mainframes?
Why? For one reason, mainframes are still the most trusted platform, with an EAL5+ security evaluation. Companies rely on mainframe security to provide industrial-strength protection. Mainframes are still the platform of choice for processing mission-critical applications and hosting essential corporate information for banks, health care, insurance, retail, government and other industries largely because of mainframe security.

Furthermore, mainframes have become the true mother of reinvention: They have evolved and reinvented themselves with new technology, supporting cloud, mobile, big data and social innovation. Mainframes have transformed from isolated glass house systems to fully connected servers for Internet web applications, data analytics and private clouds. Security has also evolved to keep pace with innovation. It has been an interesting journey.

Mainframe in the Beginning

At first, System/360 security was very simple: To protect sensitive information, you created data set passwords specified on batch jobs with Job Control Language (JCL). While it was easy to share the password to allow data access, it was far more difficult to deny someone access later, which required changing the password and notifying all the other valid users.
The first step in the security journey was to establish user identification (user IDs) and authentication. Access control lists indicated who could access the data and how. This security information needed to be administered by authorized security managers in secure repositories. In 1976, IBM announced IBM Resource Access Control Facility for mainframes, with capabilities including:
  • User groups and privileged roles, such as auditors, operators and special administrators.
  • Resource protection for data sets, files, tapes, programs, applications and general resources.
  • Auditing of security events, including user log-on, data access and privileged operations.

Mainframe Security and Applications Evolved

As the mainframe evolved to support new applications beyond batch processing, security evolved along with these applications:
  • IBM TSO (Time Sharing Option) allowed multiple interactive real-time users.
  • IBM DB2 offered field-level security controls that wouldn’t impede performance.
  • IBM IMS and CICS protected transaction applications.
  • IBM Security AppScan identifies application vulnerabilities and generates reports with intelligent fix recommendations to ease remediation.

Communication Security Expanded to Internet and Mobile Access

Mainframes began to communicate outside their enterprises and across public networks, which required new encryption protocols and new security capabilities, including:
  • User directories that uniquely identified users across enterprises and domains.
  • Trusted authentication protocols that utilized certificates instead of passwords.
  • Secure communication protocols with distributed untrusted systems and mobile users.

Early “Cloud” Capabilities

Many people do not realize that the mainframe offered virtual machine capabilities long before today’s cloud options were available. Mainframes have provided a number of virtualization options over time:
  • Secure hypervisors that could run software virtual machines.
  • Physical logical partitions (LPARs) that run virtual machines with physical isolation.
  • Most recently, blade servers that run systems under the covers of the latest mainframes.

Growth of Database to Big Data Analytics

Mainframes provide robust information security, so it makes sense that mainframes have grown over time to host data warehouses, big data and data analytics. Mainframe data security has been enhanced with IBM Security zSecure and IBM InfoSphere Guardium security solutions. Big data by nature is enterprise-wide, so many other data sources connect with the mainframe. Guardium’s ubiquitous support for a wide variety of platforms and data sources ensures that any potential threats from within or outside the platform are detected, blocked and reported in virtually real time. InfoSphere Guardium Data Encryption for DB2 and IMS Databases provides additional protection of data at rest and in motion over communications at the column, row and segment levels. Security encryption key management solutions protect those keys from disclosure.

Security Intelligence and Compliance

As mainframes transformed, they were exposed to new threats. The overall volume of mainframe and enterprise-wide security events that requires analysis is staggering. Mainframes have new capabilities to obtain actionable insight with security intelligence using zSecure and QRadar SIEM to automate threat analysis, create alerts, monitor status and respond.
As the occurrence of big data breaches grew, new security standards and compliance regulations have been adopted to help protect user payment card information, sensitive financial information, medical health care records and other vulnerable data. These regulations require privileged user monitoring, vigilant audit reporting, data encryption and other security controls that help safeguard information. zSecure offers new compliance framework reporting to demonstrate governance and compliance.

Continued Transformation

Over the past 50 years, the mainframe has evolved from a siloed system to supporting databases, applications, networking, virtual machines, Internet, cloud, mobile, big data and business analytics. Mainframe security has transformed to secure these new capabilities and help customers create the ultimate security platform for their mission-critical workloads. Mainframe security has stood the test of time for 50 years and is still going strong.

Tuesday, July 29, 2014

System z Takes BackOffice Role in IBM-Apple Deal

29 july 2014


I didn’t have to cut short my vacation and race back last week to cover the IBM-Apple agreement. Yes, it’s a big deal, but as far as System z shops go it won’t have much impact on their data center operations until late this year or 2015 when new mobile enterprise applications apparently will begin to roll out.
The deal, announced last Tuesday, promises “a new class of made-for-business apps targeting specific industry issues or opportunities in retail, healthcare, banking, travel and transportation, telecommunications, and insurance among others,” according to IBM. The mainframe’s role will continue to be what it has been for decades, the backoffice processing workhorse. IBM is not porting iOS to the z or Power or i or any enterprise platform.
Rather, the z will handle transaction processing, security, and data management as it always has. With this deal, however, analytics appears to be assuming a larger role. IBM’s big data and analytics capabilities is one of the jewels it is bringing to the party to be fused with Apple’s legendary consumer experience. IBM expects this combination—big data analytics and consumer experience—to produce apps that can transform specific aspects of how businesses and employees work using iPhone and iPad devices and ultimately, as IBM puts it, enable companies to achieve new levels of efficiency, effectiveness and customer satisfaction—faster and easier than ever before.
In case you missed the point, this deal, or alliance as IBM seems to prefer, is about software and services. If any hardware gets sold as a result, it will be iPhones and iPads. Of course, IBM’s MobileFirst constellation of products and services stand to gain. Mainframe shops have been reporting a steady uptick in transactions originating from mobile devices for several years. This deal won’t slow that trend and might even accelerate it. The IBM-Apple alliance also should streamline and simplify working with and managing Apple’s mobile devices on an enterprise-wide basis.

CICS V5 Performance: Impact 2014 Presentation

Improved performance of CICS V5-V5.2 vs. previous versions
Download Now
According to IBM its MobileFirst Platform for iOS will deliver the services required for an end-to-end enterprise capability, from analytics, workflow and cloud storage to enterprise-scale device management, security and integration. Enhanced mobile management includes a private app catalog, data and transaction security services, and a productivity suite for all IBM MobileFirst for iOS offerings. In addition to on premise software solutions, all these services will be available on Bluemix—IBM’s development platform available through the IBM Cloud Marketplace.
One hope from this deal is that IBM will learn from Apple how to design user-friendly software and apply those lessons to the software it subsequently develops for the z and Power Systems. Would be interesting see what Apple software designers might do to simplify using CICS.
Given the increasing acceptance of BYOD when it comes to mobile, data centers will still have to cope with the proliferation of operating systems and devices in the mobile sphere. Nobody is predicting that Android, Amazon, Google, or Microsoft will be exiting the mobile arena as a result, at least not anytime soon.
Finally, a lot of commentators weighed in on who wins or loses in the mobile market. In terms of IBM’s primary enterprise IT competitors Oracle offers the Oracle Mobile Platform. This includes mobile versions of Siebel CRM, JD Edwards, PeopleSoft, and a few more. HP offers mobile app development and testing and a set of mobile application services that include planning, architecture, design, build, integration, and testing.
But if you are thinking in terms of enterprise platform winners and losers IBM is the clear winner; the relationship with Apple is an IBM exclusive partnership. No matter how good HP, Oracle, or any of IBM’s other enterprise rivals might be at mobile computing without the tight Apple connection they are at a distinct disadvantage. And that’s before you even consider Bluemix, SoftLayer, MobileFirst, and IBM’s other mobile assets.


http://enterprisesystemsmedia.com/article/system-z-takes-backoffice-role-in-ibm-apple-deal?utm_source=z%2Fflash&utm_medium=newsletter&utm_content=zF+-+art+1&utm_campaign=w4xed

Sunday, June 22, 2014

The Luckiest Man in the World

 34 129Print Email

The Luckiest Man in the World

The 2014 Master the Mainframe World Championship winner concepted his entry right before the competition started

May 21, 2014 |
As part of its Mainframe50 celebration, IBM named Yong-Siang Shih of National Taiwan University the winner of the first Master the Mainframe World Championship at the April 8 event in New York. The 2009 winner of the Taiwan Master the Mainframe competition bested 42 other competitors from 23 countries to take the title.

Previous participants who had demonstrated superior programming skills on the mainframe were invited to the competition. While participating, the students sharpened their programming skills; cultivated advanced development tools and learned how the mainframe platform supports cloud, big data and analytics, mobile and security initiatives. In March, competitors were given an already-built application to refine and improve upon, and were tasked with constructing an application that real-world business would use.

April 6, the competitors were brought to IBM in Poughkeepsie, N.Y., where they presented their results to a panel of judges. Scores were collected, tallied and six finalists were named. On April 7, those six presented their projects to another set of judges. The top three winners were announced the next day during the Mainframe50 live event.

The top winners for the 2014 Master the Mainframe World Championship are:

First Place: Yong-Siang Shih of National Taiwan University, Taiwan
Second Place: Rijnard van Tonder of Stellenbosch University, South Africa
Third Place: Philipp Egli of University of Brighton, United Kingdom
Fourth Place: Mugdha Kadam of University of South Florida, United States
Fifth Place: Shahini Sengupta of RCC Institute of Information Technology, India
Sixth Place: Aaron Call Barreiro of Universitat Politècnica de Catalunya, Spain

“One of the most exciting parts of this competition was getting to meet these bright students in person, and getting to know them on a personal level,” says Troy Crutcher, Master the Mainframe project manager, IBM Academic Initiative, System z.

“One of the main goals of the IBM Academic Initiative Master the Mainframe contest is helping these students gain enterprise systems skills that they will be able to use well into the future. Employers are continually looking for these skills,” he explains. “This contest is a way to get them excited and on the System z platform in a fun and educational way.”

Competition Brings Out Confidence


As a student at National Chiao Tung University, World Championship winner Shih got involved in Master the Mainframe in the hopes of winning an external hard drive, the 2009 prize for winning the second stage of the three-part competition. Despite this win, he said he was surprised to be invited to the World Championship. However, he was excited to have the opportunity to continue with Master the Mainframe and visit the U.S. for the first time.

“The most rewarding part of this experience was that I got to meet so many people and talked a lot” with others who have similar interests, Shih says. “My favorite memory was presenting my work; I enjoyed the demonstration and I got some very nice feedback. I also felt more confident after this competition.”

Shih attributes his win to luck based on timing and circumstances before the competition. In addition to having technical skills—including having recently taken a course about cloud computing—and participating in the National Taiwan University English Debate Society, he came up with the idea of creating a mobile application for debit cards shortly before the competition. In his application, a card is enabled to make an online purchase and disabled immediately afterward so no other charges can be incurred online. That way, if any information gets in the hands of the wrong person, he or she cannot make an unauthorized charge.

“If the third stage were not about an application, I might not have been able to think of another bright idea,” Shih notes. “Everything worked so perfectly together that this itself is incredible.”

Shih, in his first year of graduate school, has professional experience with an internship on IBM’s DataPower quality assurance team, mainly developing a test framework. After college, he said he hopes to work as a software engineer.

Students Benefit From Experiences

Although no concrete plans are in place for another World Championship, Crutcher says there are talks of such an event. He had heard positive feedback and that the students had an amazing time in New York.

“Not only did the participants get to compete with some of the best minds around the world, they got to explore the city,” he says. “A few of them had never even been on a plane before, let alone leave their home country. This was a huge event that they will continue to benefit from in the future.”

The Master the Mainframe competition is open to high school and university students that go to schools involved in the Academic Initiative. To learn more about the competition, visit the Master the Mainframe page here. Read Shih’s first-person account of the competition and his application in his blog here.

Valerie Dennis is site editor of Destinationz.org.
- See more at: http://www.destinationz.org/Academia/Articles/The-Luckiest-Man-in-the-World.aspx#sthash.gCURGMoO.dpuf

Friday, May 23, 2014

Back to the future: Why z/OS mainframe is the ideal cloud platform

Back to the future: Why z/OS mainframe is the ideal cloud platform


By Pat Toole and Frank DeGilio
Fifty years ago, IBM CEO Thomas Watson Jr. unveiled the System/360—the first general purpose computing system specifically designed for business—calling it “the beginning of a new generation, not only of computers, but of their applications in business, science and government.”
It was this vision for computing that made possible the creation of bar codes, ATMs, electronic stock trading, online travel reservations, weather modeling and countless other inventions that have changed the way the world works.
Watson’s statement is as timely and true today as it was then, in the context of the evolution that’s occurring within IT via cloud computing. The System/360 ushered in the era of flexibility, adaptability, and economy for IT. It pioneered the concepts of backward and forward compatibility, the ability to add capacity as you needed it, and protecting the client’s investments in their technology, applications and data.
As we talk about the next inevitable phases of cloud, like platform as a service (PaaS) and software as a service (SaaS), we encounter some very specific themes and challenges that cry out for systems with those qualities:
• How do I provide multi-tenancy with the greatest number of people sharing the same machine as possible, securely and efficiently?
• How do I dynamically scale an environment immediately without waiting to provision?
• How do I provide each user a unique performance experience on the smallest number of systems possible?
• How do I keep track of how much capacity each user is using?
• How do I support thousands of users with a handful of IT professionals?
If there were an ideal operating system that could provide multi-tenancy, dynamic scaling, a unique user experience, fine-grained usage monitoring, and that could support thousands of users with a small group of admins, PaaS and SaaS solutions would be simple. Oh wait, there is—z/OS.
What was once only accessible to COBOL and Assembler programmers is now available to anyone. Today, a team of young IBM hardware and software developers in Poughkeepsie is creating simple web-based interfaces for z/OS, which will allow any programmer with web development experience to use this powerful platform for PaaS and SaaS.
IBM also continues to refine the technology and the delivery of mainframe computing for cloud applications. The new IBM Enterprise Cloud System can support up to 6,000 virtual machines in a single system, provide a secure multi-tenant environment and dynamically share resources across enterprise workloads, with higher system efficiency and greater scalability that lowers the total cost of Linux cloud deployments by up to 55 percent over comparable x86-based cloud infrastructure.
And the new “IBM MSP Utility Pricing for System z” pricing model, delivered through IBM Global Financing, provides consumption-based pricing designed especially to make mainframe technologies more widely accessible to Managed Service Providers. This consumption-based approach allows MSPs to focus on building their businesses, rather than on the cost of their infrastructure.
These innovations unlock the potential for z/OS and the modern mainframe to be the cloud platform of choice, enabling people to create business solutions built on the most secure, available, reliable cloud infrastructure ever known.


http://thoughtsoncloud.com/2014/05/back-future-zos-mainframe-ideal-cloud-platform/

Sunday, May 18, 2014

Make the Extraordinary possible: IBM Mainframe50

Make the Extraordinary possible: IBM Mainframe50

possible
IBM Mainframe50
The mainframe is a revolutionary computing system that is transforming business, whole industries, and the world as we know it.
By continually adapting to trends and evolving IT, we’re driving new approaches to cloud, analytics, security and mobile computing to help tackle challenges never before thought possible. We do that by collaborating with our clients to build better technology every day.
But the pioneering innovations of the mainframe all serve one enduring mission: Deliver game-changing technology that makes the extraordinary possible and improves the way the world works.
See the link below to watch a replay of the April 8 NYC Mainframe50 event.

The Engines of Progress

They transform our lives. Their visionary endeavors make our world smarter and more connected.
Previous

First National Bank

Critical financial services to Africa’s unbanked 80 percent
FNB's "bank in a box" enables millions of individuals across Africa to startup new businesses, save for college and improve lives
 

Met Office

Vital reports to empower industries and save lives
The Met Office generates thousands of weather forecasts a day to help global industries and governments make crucial decisions
 

Walmart

Helping 250 million people a week save money and live better
From a Five and Dime in Bentonville, Arkansas to a retail superforce serving customers in 27 countries around the world, Walmart has built an empire on one simple value: the customer always comes first.
 

First National Bank

Critical financial services to Africa’s unbanked 80 percent
FNB's "bank in a box" enables millions of individuals across Africa to startup new businesses, save for college and improve lives
         

 

GENERATION z

They will create the future.
Every year, students at over 1,000 universities across 67 countries are learning to solve tomorrow’s grand challenges with the mainframe.
The top 43 students from around the globe met in New York City for the first ever Master the Mainframe World Championship.

50 extraordinary years

They invented the modern world. Organizations and leaders have reinvented business, transformed industries and helped solve some of the world’s greatest challenges with the world’s most innovative and trusted platform. These achievements are woven into the fabric of industry and society.

Sabre reservation system

The world’s first automated passenger reservation system, Sabre, is the basis for today’s web-based travel industry. Launched on two IBM 7090 mainframes, the application written in the 60s is able to process billions of transactions a week today.

Wednesday, March 5, 2014

Enterprise COBOL 5.1—Where Tradition Meets Innovation





COBOL is the most ubiquitous programming language for developing business applications. Despite that its specification was created more than 50 years ago, COBOL is still running the world’s most critical business applications. Many of us might not realize how much we rely on COBOL applications in our day-to-day lives. Every time we use an ATM, book an airline ticket, process a check or make an insurance claim, we’re using a COBOL application to process the transaction, and there’s a good chance this application is running on System z.

Modernizing Enterprise COBOL

Enterprise COBOL is a premier enterprise-class COBOL compiler on System z, powering many business-critical applications. Time proven and reliable, COBOL has a long history of delivering new and innovative features for developers to modernize key applications, and increase productivity.
Modern System z servers—z10, zEnterprise 196 and zEnterprise EC12 (zEC12), for example—are designed with high-performance microprocessors and are reshaping the IT landscape. COBOL developers are expected to deliver new functions faster with higher quality and performance. As the hardware become more complex, it’s becoming increasingly difficult for application developers to simultaneously handle business logic and performance issues in the applications they’re working on. They need state-of-the-art compilation technology to provide advanced optimization and hardware exploitation to deliver leading-edge performance so they can focus on the business logic. To satisfy this requirement, Enterprise COBOL needs to transition to a new technology base to ensure timely delivery of System z hardware exploitation and advanced optimizations.

Improving Performance

Announced in April, Enterprise COBOL for z/OS V5.1 was re-architected to include a new optimization framework based on proven technology shipped in Java on System z. IBM has been shipping this technology since 2006. Unlike Java, this new framework for COBOL is static in nature. It provides advanced COBOL specific optimizations, and full z/Architecture exploitation (z900 through zEC12). A new option, ARCH, enables users to specify which z/Architecture to optimize their applications for. Increasing performance of COBOL applications provides savings in CPU utilization and the ability to meet service-level agreements.
Enterprise COBOL V5.1 runs on z/OS V1.13 and later. It provides significant performance improvements over Enterprise COBOL V4. According to internal IBM test results, many well-structured, CPU-intensive batch applications have seen performance increases greater than 10 percent. Many numerically intensive programs have shown performance increases greater than 20 percent.
Users don’t have to optimize the entire application because optimized code works with non-optimized code. They can, therefore, achieve performance goals by selectively optimizing performance hotspots in an iterative and controlled way.

Maintaining Compatibility

Organizations can stage the upgrade effort to COBOL V5. They don’t need to recompile an entire application to use Enterprise COBOL V5. It’s source- and binary-compatible with older releases of COBOL compilers for System z. Most correct programs will compile and execute without changes, producing the same results. “Old” and “new” codes can interoperate within an application, communicating by static or dynamic calls.
Some old language syntax and options have been removed in the new compiler. They include supports for millennium language extension, label declaratives, non-reentrant programs above 16MB, OS/VS COBOL inter-operation, AMODE 24, and XMLPARSE(COMPAT).

Modernizing Applications

Application modernization promotes reuse of proven software assets. Enterprise COBOL V5.1 enables developers to methodologically modernize existing COBOL applications and integrate them with new ones running on modern infrastructures (e.g., Web, cloud or mobile). It allows organizations to deliver new enhancements quicker with lower risk and cost.
Enterprise COBOL V5.1 also supports Java 7 and provides users better control over generation of XML documents. It uses the z/OS XML parser, allowing parsing to be offloaded to specialty engines to reduce cost. It also provides support for unbounded tables and groups, which allows developers to enable top-down mapping of data structures between XML and COBOL applications.
As one IT architect with a North American health care company puts it, “XML is increasing in importance for our company, and IBM has enhanced XML support in Enterprise COBOL V5 with changes that allow us to take advantage of z/OS XML System Services to reduce the cost of COBOL-based XML processing.”


Improving Productivity

Enterprise COBOL V5.1 raised the total size of all data items in a working-storage or local-storage section to 2GB, and the maximum size of an individual data item to 999,999,999 bytes. New built-in functions are added to improve programmability of UTF-8 applications, thus improving COBOL applications’ ability to process UTF-8 data in DB2 and XML documents.
The new release continues to allow debugging of optimized production code. Debug information is stored in the NOLOAD segment of the program object. As a result, the footprint of the executable won’t increase. To improve application maintainability, a new floating comment indicator (*>) is added for developers to use anywhere in the program-text area to indicate that the text on the line is a comment line.
“COBOL V5 emphasizes IBM’s commitment to our existing COBOL application base while improving its interoperability with our open systems components, explains Michael A. Todd, a software architect for a multi-national financial services company. “IBM has addressed a number of architectural limits within the previous compiler, thereby extending the life of my extensive COBOL inventory. They continue to improve XML capabilities and UNICODE support, enabling us to reuse existing components.”
Additional benefits offered by Enterprise COBOL V5.1 include:
  • Reduced administration costs. The latest version supports a new level of z/OS System Management Facilities (SMF) tracking, allowing users who implement subcapacity tracking to reduce their administrative overhead.
  • Support for the latest middleware. It provides up-to-date programming interfaces for latest CICS, DB2 and IMS. The integrated DB2 and CICS coprocessors enable strong integration with the latest middleware technologies.
  • Support for modern development tools and solutions. By supporting the ecosystem of COBOL development tools from IBM and ISVs, it enables companies to expedite migration and application-performance tuning with IBM’s latest continuous integration solution.

COBOL Commitment

Enterprise COBOL for z/OS V5.1 affirms IBM’s commitment to COBOL customers on System z. With the new optimization framework, it delivers compelling performance improvement. Because it maintains source and binary compatibility with older COBOL releases, many applications may gain performance simply by recompiling the code.
Going forward, the new optimization framework will provide a solid foundation for delivering a release-to-release performance improvement roadmap for COBOL on System z. Therefore, it’s important to stay current with latest COBOL technology. Organizations can’t maximize their return on investment unless they stay current with latest compiler technology.

DUO claimt diverse schades na KPN-storing

Fouten in z/OS Catalogs uitwijkmainframe legden applicaties plat

05-03-2014 11:55 | Door Rik Sanders | Lees meer artikelen over: Disaster recovery, Mainframes, Replicatie, System z | Lees meer over de bedrijven: KPN, ministerie van Onderwijs, Cultuur en Wetenschap | Er zijn nog geen reacties op dit artikel | Permalink
De technische storing in het IBM-mainframe, die op zondag 27 oktober 2013 diverse systemen bij de Dienst Uitvoering Onderwijs (DUO) platlegde, heeft verschillende soorten schades veroorzaakt. Pas na afronding van de inventarisatie van de aard en de hoogte van de totale schade zal DUO bij ict-infrastructuurbeheerder KPN een mogelijke schadeclaim neerleggen. Ook vindt er nog een evaluatieonderzoek plaats naar de storing.
Dit blijkt uit de beschikking die het ministerie van Onderwijs, Cultuur en Wetenschap (OC&W) opstuurde, naar aanleiding van het door Computable opvragen van documenten over de storing op basis van de Wet Openbaarheid van Bestuur (WOB). Daarin wordt gesproken over een complicerende factor bij het bepalen van de aard en hoogte van de schade, namelijk dat er sprake is van 'verschillende soorten schades met elk hun eigen kenmerken'.

Extra handmatig werk

De storing in het mainframe legde vanaf eind oktober 2013 tot 4 november het studiefinancieringssysteem en het portaal Mijn DUO plat. Ook het personeelszakensysteem van Raet zou er uit hebben gelegen. Studenten konden door de storing niet inloggen op Mijn DUO. Medewerkers van de uitvoeringsorganisatie van OC&W waren niet in staat het studiefinancieringssysteem te raadplegen als studenten belden, mailden of langskwamen. Wel konden studenten via de website van DUO een aantal formulieren downloaden om bijvoorbeeld wijzigingen in de studiefinanciering door te geven.
De storing leidde tot veel extra werk in de uitvoering bij DUO, omdat medewerkers wijzigingen van klanten handmatig moesten noteren en, nadat de storing was opgelost, in het systeem moesten invoeren. DUO laat, sinds de systemen weer in de lucht zijn, het portaal Mijn DUO zwaar monitoren.

Catalog-fout

DUO event map Mainframe-verstoring
DUO event map Mainframe-verstoring
Volgens KPN is de storing veroorzaakt door een samenloop van twee omstandigheden: een fout in de replicatie van data tussen twee datacenters in combinatie met een geplande uitwijktest. De storing zorgde ervoor dat systemen niet benaderbaar waren en applicaties op die systemen niet gebruikt konden worden.

Uit een vrijgegeven WOB-document blijkt dat na het opstarten van het mainframe op de uitwijklocatie er een verstoring in het opslagsysteem plaatsvond. Daardoor ontstond er een inconsistentie in de z/OS Catalogs. Deze catalogs, die aangeven waar op welk volume een dataset is opgeslagen, verwezen in een aantal gevallen naar verkeerde locaties. Vervolgens werd het 'shared mainframe platform' onbruikbaar en konden de klantapplicaties niet meer beschikbaar worden gesteld (zie afbeelding).

Complex

DUO proces uitwijktest Mainframe
DUO proces uitwijktest Mainframe
Maar wat precies de oorzaak is geweest, wil DUO noch KPN aangeven. KPN, die als ict-infrastructuurbeheerder optreedt voor DUO, spreekt van een complexe storing. Een woordvoerder van het DUO stelt: 'De oorzaak was een fout bij KPN waarvan niet aannemelijk is dat die zich zal herhalen.'
Computable deed vervolgens een beroep op de WOB en vroeg de documenten op die te maken hebben met de storing. Het ministerie van OC&W, waar het DUO onder valt, wees het verzoek grotendeels af. Slechts drie van de 34 geïnventariseerde documenten zijn openbaar gemaakt, waaronder een persbericht en de pdf's 'DUO event map Mainframe verstoring' (zie afbeelding hierboven) en 'DUO proces uitwijktest Mainframe' (zie afbeelding hiernaast).

Afwijzen

Het ministerie staat op het standpunt dat openbaarmaking van de andere 31 documenten 'de positie van DUO bij de contractuele afhandeling van de storing en de bepaling van (de hoogte van) een mogelijke schadevergoeding zou kunnen verstoren.' De juridische dienst van OC&W voert ook nog aan dat openbaarmaking van de betreffende documenten DUO onevenredig zou benadelen, omdat de uitvoeringsorganisatie met KPN afspraken heeft gemaakt over de woordvoering omtrent de storing. 'Openbaarmaking zou ingaan tegen de afspraken rond de woordvoering en tevens de onderhandelingspositie van DUO kunnen verstoren en zo onevenredig kunnen benadelen', schrijft de dienstdoende jurist.
Wat OC&W met dit laatste punt bedoelt, wordt verder niet duidelijk gemaakt. Computable tekent bezwaar aan tegen deze beschikking.



Read more: http://www.computable.nl/artikel/nieuws/overheid/5020424/1277202/duo-claimt-diverse-schades-na-kpnstoring.html#ixzz2v5ZxVYE9