Showing posts with label Big Data. Show all posts
Showing posts with label Big Data. Show all posts

Thursday, August 10, 2017

Demonstrate Data Compliance !


Enterprise data are subject to various regulations depending on their geographical location and type of business. An increased effort is expected and mandated to respect those rules, typically meant to better secure and protect the accuracy and privacy of enterprise data. In various regulations, it is also expected to actually demonstrate Compliance, which is not a piece of cake.
In addition, most people think that external threats (such as an external hacker trying to access corporate data) are the most common data security issues. In reality, various studies have shown that internal threats comprise 80% of all security threats. In other words, companies should make sure to protect their corporate data against their own employees.

Examples of regulations


Sarbanes-Oxley Act (SOX) : The goal of SOX is to regulate corporations in order to reduce fraud and conflicts of interest, to improve disclosure and financial reporting, and to strengthen confidence in public accounting. Specifically, the section 404 of this act, the one giving IT shops fits, specifies that the CFO must do more than simply vow that the company’s finances are accurate; he or she must guarantee the processes used to add up the numbers. Those processes are typically computer programs that access data in a database, and DBAs create and manage that data as well as many of those processes.

Health Insurance Portability and Accountability Act (HIPAA) : This legislation contains language specifying that health care providers must protect individual’s health care information even going so far as to state that the provider must be able to document everyone who even so much as looked at their information. Aka. can a DBA produce a list of everyone who looked at a specific row or set of rows in any database ?

Payment Card Industry & Data Security Standard (PCI DSS) : This well-known standard was developed by the major credit card companies to help prevent credit card fraud, hacking and other security issues. A company processing, storing, or transmitting credit card numbers must be PCI DSS compliant or they risk losing the ability to process credit card payments. Given the availability and volume concerns of payment card transactions this information is typically stored in an enterprise database.

General Data Protection Regulation (GDPR) : This new regulation applies to organizations that do business in the European Union, and will be effective in May 2018. It is meant to strengthen and unify data protection for individuals within the European Union, but it also focuses on the export of data (or even accessing the data) outside the EU. The stated objective of GDPR is to return control of personal data back to the individual. This includes data retention requirements, data privacy rules and huge penalties for being out of compliance.

Personal Information Protection and Electronic Documents Act (PIPEDA) : This Canadian regulation specifies the rules to govern collection, use, or disclosure of the personal information in the course of recognizing the right of privacy of individuals with respect to their personal information. It also specifies the rules for the organizations to collect, use, and disclose personal information.

Demonstrate Compliance!


It’s (almost) as simple as a 1-2-3 process!

Step 1 to Data Compliance : Define Data Compliance for your business

Depending on the type of corporate data you own, the type of business you are in, and the geography you do business with, the regulations you want to comply with will be different. And the definition of Personal Information to protect will be different!
As a typical example, the format of social security numbers is different from one country to another. If you do business in Czech Republic (for example), the social security numbers (Rodné číslo) have a specific format
  [0-9]{2}[0,1,5][0-9][0-9]{2}/?[0-9]{4}
 



Step 2 to Data Compliance : Locate the sensitive personal data

While most companies understand the need to comply to regulation(s), a typical challenge is to determine where all the sensible personal data are actually located within the corporate data.
When you have defined what kind of data you are going after (Step 1), the challenge is to make sure you know where those are stored : where are those “Rodné číslo” in the corporate data ?
You may think you know where all these are stored, but … are you sure? Remember: the goal is to demonstrate compliance, so you better be sure you know exactly where all those “Rodné číslo” are stored.



Step 3 to Data Compliance : Secure, protect, and demonstrate compliance

When you know what personal data you are going after, and you know where they are located, the game is to make sure the authorizations and security settings are defined properly, so that only the individuals that must have access to it… have access to it.
In other words, you need to produce a report that clearly states what personal data are where, and who has access to it.

Find and control regulated mainframe data and classify for compliance with CA Data Content Discovery (DCD) 

Compliance and adherence to regulations is critical to help prevent data breaches.

CA Data Content Discovery helps you identify data exposure risks on z Systems™ by scanning through the mainframe data infrastructure.
By discovering where the data is located, classifying the data to determine sensitivity level and providing comprehensive reporting on the scan results, mission essential data can be protected and exposure risks can be mitigated.



CA Data Content Discovery (DCD) comes with a number of pre-defined classifiers out-of-the-box, to comply with various well-known regulations.
In addition, CA Data Content Discovery (DCD) can be configured to look for sensible industry-specific or country-specific data in your corporate data, aka. you can create custom classifiers such as a “Rodné číslo” (as discussed above) : 

[0-9]{2}[0,1,5][0-9][0-9]{2}/?[0-9]{4}



SQL Adria - June 2017 - Summary


SQL Adria is a DB2 Regional User Group for Croatia and Slovenia, founded 20+ years ago. This non-profit organization organizes conferences and seminars, as a mean to continuously provide technical education, to share knowledge, to exchange ideas and experience among users and vendors.

Those events are regularly attended by dozens of DB2 Users, both DB2 Administrators and DB2 Application Developers.

The SQL Adria 2017 summer event happened in Šibenik, Croatia from 11th June 2017 to 15th June 2017.

Sessions during the SQL Adria Seminar


Tracking Guide to #db2 Galaxy by Denis Tronin @trode05

Steve Thomas @Steve_db2 is talking about Locks, Latches, Drains & Claims 

Protecting the Crown Jewels - your #data by Andy Ward

Eberhard Hechler from #IBM speaks about #MachineLearning and Data Lakes

Jane Man at #SQLAdria discusses how to create #DB2 mobile applications

Full room for Zeljen Stanic @staze01 SLA presentation

IDAA News from IBM Development by @Hrle1 (Namik Hrle)

Mainframe Operations Intelligence Solutions by Tom Juhl @tomjuhl


Reference


https://www.sqladria.net/en/seminar/european-sqladria-seminar-%E2%80%93-%C5%A1ibenik-2017

https://twitter.com/SQL_Adria

https://twitter.com/DB2forZ

If you attended the Conference, feel free to leave a comment below to indicate, for example, which session / presenter you enjoyed the most !

Monday, June 9, 2014

News about the DB2 Analytics Accelerator



During SQL Adria conference, Namik Hrle (IBM Fellow) revealed some features that are likely to be delivered onto the DB2 Accelerator technology, hopefully soon. The DB2 Analytics Accelerator (formerly called IDAA) is an appliance that helps execute Business Intelligence (BI) queries much faster. DB2 for z/OS is built on an architecture  that is optimized for transactional queries, but admittedly falls short when running complex analytics that nowadays business demands. The DB2 Analytics Accelerator is the solution that IBM is pursuing to provide high-performance BI queries against DB2 data (almost) transparently. 

Namik used an interesting analogy, explaining that DB2 for z/OS with the DB2 Analytics Accelerator vision is to be like an hybrid car, that can decide to use either its petrol engine or its electrical engine, transparently to the driver (the end-user). Namik also indicated that the IBM lab is considering to provide the ability to:
* Create a table within the accelerator (that would reside solely in there, but would be accessible transparently through DB2)
* Provide a method to load non-DB2 data directly in the DB2 Analytics Accelerator (such as loading a flat file)

These 2 features would open the door to process complex BI queries, joining business data residing in DB2, and many other data sources, structures or unstructured …

Thursday, January 23, 2014

IDUG North America is around the corner

Back from Xams vacation, let me wish everyone a Happy New Year !

As the tradition mandates, I have been taking a few resolutions for 2014, and if you wonder which ones, here you go:
1-      Attend the IDUG conference in Prague
2-      Write a XMLquery without SQL syntax error in less than 10 minutes
3-      Become friend with iterative SQL coding techniques

And since we are at the beginning of the year, it’s time to look at all the great DB2 upcoming events in 2014. As you probably know, IDUG North America is around the corner, it will take place in Phoenix on May 12-16 [more info here]. Unfortunately, I probably won’t make it. I have however looked at the many sessions scheduled, read carefully the description, and selected the ones that matches my interests (and my new year’s resolutions). So here is the top 10 sessions that I recommend (ordered by session’s code) :

1-      A10 DB2 for z/OS: Disaster Recovery for the Rest of Us
2-      B02 How to Optimize a DB2 z/OS Application without any SQL or Program Change?
3-      E03 PARLEZ-VOUS KLINGON - DB2 RECURSION SQL FOR DATABASE MAGICIANS
4-      E07 Going Native: Leveraging DB2 for z/OS SQL Procedures and UDFs
5-      F04 Big Data Disaster Recovery Performance
6-      F06 With the Emergence of Big Data, Where do Relational Technologies Fit?
7-      F08 IBM DB2 Analytics Accelerator - The Performance Revolution Continues
8-      F10 A Big Data Roadmap for the DB2 Professional
9-      G02 The DB2 11 catalog – something new, something old, something changed
10-   G10 Unleash the power of XML retrieval with Xpath and Xquery, are you still with me ?

I must also indicate that I’m gladly surprised that the IDUG Planning Committee (finally!) accepted a z/OS session that really targets “beginners”:
E08 A 50 Cent tour of DB2

Of course, this is only my opinion, and if you have your own suggestions, or if you want to share which sessions you recommend, feel free to comment this article.

Thursday, October 17, 2013

csDUG Conference 2013 in Prague


35 attendees from the Czech and Slovak Republics met at the CA Technologies office in Prague on the 8th of October 2013 for a one-day conference. It was the first DB2 user conference in the Czech and Slovak region.



The attendees were a mix of database administrators, systems programmers, application developers and other specialists in the DB2 for z/OS and mainframe area. 

Steen Rasmussen (CA) talking about changes in DB2 10 catalog
The conference focused on the new features in DB2 10 and 11 and IBM DB2 Accelerator. The speakers were experienced DB2 specialists and architects from IBM and CA Technologies. The attendees appreciated the value of the sessions because they received a lot of new information that is related to their job.


Michał Bialecki (IBM), Philippe Dubost (CA), Peter Priehoda (IBM) and Robin Hopper (CA)  
The event was free and sponsored by CA and IBM. There were 5 sessions plus an open and closing session. You can see full agenda at October 8, 2013 – csDUG Conference.

One of the attendees won a free pass for the next IDUG conference in Phoenix, Arizona (USA).

Winner of the free pass for the next IDUG
If you missed the conference this year you will have opportunity to attend next year. As we shape the next event, we would like to hear from you with your preferred city (Prague, Brno, Ostrava or Bratislava), the most convenient time of year for you, and what topics are you interested in. Please post a comment to the blog article. Thank you.








Monday, July 29, 2013

What means Big Data to you ?

Whether you are an insurance provider, a bank, an advertising company, or any company of medium-to-large size, you need to consume and exploit huge amount of data internally. You would also benefit from analyzing additional, external, data which are available to you, but can be difficult to collect and process in a simple and meaning way.

As an insurance company, you might want to intercept Facebook updates of your clients who publish skiing activities while receiving an insurance for a broken leg.

As an international bank, you might want to monitor the GPS location of mobile transactions to intercept two transactions made on the same personal account at the same minute, one from South Africa, and the second from China.

As an advertising company, you might want to monitor, analyze, and react accordingly to the Tweets on a particular theme, in real-time. Similarly, as a manufacturer (for example a shoes or a car manufacturer), you might want to monitor discussions and complaints on specialized forums to gather data regarding to quality of the products, understand which parts / models breaks more often, in order to improve the quality of your manufactured products (using, for instance, the 6 sigma model).

As a software company, you might want data regarding the real utilization of each function / feature in your products, in order to make educated decision, and pro-actively improve the quality and focus the development accordingly (using, for instance, the Agile/Scrum methodology).

As a political party, you might want to have much better and much more granular information regarding voting intentions and more especially to be able to locate (and convince) undecided voters that are most likely to accept your political opinions (for example, if your party wants to abolish the 2nd amendment, there’s probably no chances to convince an individual who renewed his NRA membership last month, who’s favorite movie is Rambo II, and who just bought yet another rifle to add in his 20 pieces living room collection).

And to some degree, any company would benefit from a better understanding of their clients’ needs, satisfaction level, profiles, … you name it.

The term “Big Data” is just raising, and its meaning may evolve, but it so far covers:

  1. The idea of using vast amount of data, from various sources, such as internal company records up to social media activity.
  2. The idea of analyzing the above described data in real-time
  3. The idea that the real-time analyzes will help to trigger actions (as automatically as possible) to
  • Improve security
  • Detect frauds
  • Better understand the market / the clients
  • Monitor / Adjust ideas and discussions in social networking web-sites
Since almost a decade, millions of people openly share their profile (Facebook), share synthetic information (Twitter) to the world, and publish opinions and concerns on various blogs, forums, and the like. Big Data is a logical extension of this trend, as an exploitation of the data generated by this new mentality, mentality that can be summarized by the openness and visibility of individuals’ profiles and opinions. So … Big Data =  Big Brother ? Yes, in a way, in a Big way. And as any evolution in IT, some companies will make use of these new trends and dynamics, some will stay behind, will you ?