Wednesday, May 7, 2014

Patrick's Professional Challenge

Here are the interviews I conducted with two IT professionals at Banner Health.
 Interview with Robert Rost
Banner Health
Director – IT Security
Question 1: What made you want to get into Information Technology?
Rob: Good question. Number 1: Job opportunities. Number 2: Specifically IT Security for catching bad people doing bad things.
Question 2: What is one big project that you have recently completed?
Rob: The big one is really the Banner Cyber-Threat Roadmap, completed in 2012. It’s a five-year plan to bridge the gap between Banner’s current state in cyber security with an optimal state of cyber security. The major deliverable was the roadmap of what we are going to do:
            - Gap analysis
            - Staffing needs
            - Optimal state
Question 3: What successes and failures did you come across while working on this project?
Rob: I guess one success is that we had buy-in and support from the CIO from the start. The responsiveness was a success, in terms of status we got it done on time. The project was well-respected and well-received, even by three different third parties.

Wish we could have done the gap analysis differently, more than just Dave and I.

Question 3a: Who were the major players in this project?

Rob: CIO, Chief Information Security Officer, IT Ops Director
Question 4: Was there any particular type of formal approach/process that you used for the duration of the project?
Rob: Nope. I think that the roadmap isn’t really a static document. I’m wrestling with how I’m going to go about updating it and making modifications, with which a structured process would be very useful.
Question 5: What – in your opinion – is the biggest threat to information security?
Rob: From a consumer perspective, we as individuals either willingly (or unknowingly) share too much information about ourselves. From a corporate perspective, we feel the need that data needs to be available in a heartbeat anytime anywhere; the mobility of data is what can cause it to be a threat.

Interview with Mike Nelson
Banner Health
IT Security Analyst
Question 1: What made you want to get into Information Technology?
Mike: When I was younger, I had a strong interest in computer programming. I enjoyed solved problems through automation and learning how to troubleshoot my applications. I majored in Computer Science in college and developed a strong interest in computer security. I found that I enjoyed programming, but I enjoyed breaking things through penetration testing even more.
Question 2: What is one big project that you have recently completed?
Mike: Mobile Device Management for Banner has been a big project to work on. From the ground up, I lead the team to determine the direction of the project, new company policy, vendor selection and product implementation.
Question 3: What successes and failures did you come across while working on this project?
Mike: Success is the easy one. We found a solid product that would work very well for what we needed. We also got to take advantage of buying the licensing through a third party to get cheaper prices. Failures are few but one that I recall is IT support buy-in. With every IT team at Banner being stretched on resources, it was difficult to schedule meetings and have strong commitment to the project form other IT teams.

Question 3a: Who were the major players in this project?

Mike: Information Security, IT Messaging (email management team), IT Infrastructure, IT Operations, Enterprise Applications, and Customer Relations.
Question 4: Was there any particular type of formal approach/process that you used for the duration of the project?
Mike: Banner Health implements their own spin on Project Management. I utilized the Banner PM framework to help manage communication and documentation for the project as well as the project schedule.
Question 5: What – in your opinion – is the biggest threat to information security?
Mike: I would say it might be information availability. As we integrate technology more and more into our lives, we like to have the information we need readily available. Information Security unfortunately, is usually an afterthought when setting the data availability as the priority. As consumers, we don’t really demand that our information should be secure as long as we can get to it quickly and easiliy.


No comments:

Post a Comment