Showing posts with label IT management. Show all posts
Showing posts with label IT management. Show all posts

Thursday, April 28, 2011

Protecting Yourself Against Data Theft


Protecting Yourself Against Data Theft
by Michael Ehart, CISSP, etc.

There has been a rash of reporting of data theft lately that has a very strange effect of causing many to become complacent about their data protection measures because, after all, their system is working.

The problem is that there is no way to know if your data is bulletproof. You can only be certain when it is not, and you have evidence that your security has been breached. The vast majority of data theft is undetectable and unprosecutable, because unlike physical theft the stolen data is still there. If someone sneaks into a museum in the dead of night, dressed in spandex and night goggles and makes off with a Bottecelli, in the morning there is a big square of unfaded wall, an empty nail, a light dusting of tracked-through laser-detection talcum powder and no painting. 

The problem with stolen data is that most of the time there is no way to know that your system has been breached, or if it has been, that anything is missing because nothing is actually missing.
So what do you do to keep your data secure? The threats come in three flavors, and there are steps that you can take to protect yourself from each one.

1. The Barbarians at the Gates. There are people out there who don't like you. There are people out there who don't care about you, but want what you have. And there are people out there who don't care about you, or what you have, but want inside just because they can. These are the folks that firewalls were invented to thwart, and I assume that you have covered this loophole. Firewalls, encryption, strong passwords, and some sort of Intrusion Detection System (IDS) cover you there. If you don't understand or like this stuff hire someone who does. A competent IT security consultant can set up security for most small offices in a few hours of system hardening. Do make sure that the contract includes some basic training for your users concerning the changes and best practices.

2. The Enemy Within. Far more likely to cause you grief is the viper cherished in your bosom. No one knows for sure, but I would guess that the retail model applies here--- 90% internal theft. After all, who else holds the keys to your kingdom? Training, monitoring, set usage policies and careful terminal check-out procedures can help, but you never know. If you have 20 employees and they all seem perfectly content, either you are the shining example all other bosses should aspire to or at least 5% of your workforce is adept at hiding their dissatisfaction. I know which one seems most likely to me.

3. Stupid is as Stupid Does. And Stupid seems to be doing more than his fair share lately. Data theft is the classic crime of opportunity. "It was just laying there, so I took it." Or "The web site was unsecured" or "The safe was left open" or -one that I recently was asked about- "I left the box of records in the back seat, and someone borrowed my car." I love consulting, but dang, please make it harder for me, will ya? No more post-it notes with passwords conveniently stuck to the monitor, or so cleverly stuck under the keyboard. No more backup tapes on a shelf behind your desk, or stacked on top of the server. No more shared passwords for the entire office. 

Once again, if you don't know about this stuff contract someone who does. It is so very much cheaper and less stressful to spend a few bucks and a few hours hardening your system and providing a few hours of common sense training for your crew than it is to learn about your data disclosure from the guy with good hair and too many teeth holding the mike and standing sideways in your lobby so his cameraman can get a good shot.

Michael Ehart is a Certified Information Systems Security Specialist (CISSP) and carries certifications as a HIPAA Professional and HIPAA Security Specialist (among other things). Visit Michael Ehart's HIPAA blog Comply With Me

Wednesday, February 16, 2011

Finance and Accounting Support in Franchise Systems


Finance and Accounting Support in Franchise Systems

There has always been somewhat of a love/hate relationship between franchise operators and their franchisees.  While many entrepreneurs elect to leverage a known brand, documented operating procedures, and combined purchasing power that is often a benefit of a franchise operation, the reluctance to “open the books” to the franchisor is largely based upon a fear that “big brother” will use the information to take advantage of the business owner.  

Logic would indicate that both parties would recognize the validity of sharing financial and business performance data for the benefit of the entire system, where benchmark data and performance comparisons can become the basis of tremendous business intelligence.  But some franchisors, as their networks expand in size, find that their success in selling units begins to outweigh their concern for individual unit performance, and the brand value creates sufficient momentum to overcome a few bad business experiences.  Especially in larger systems, the franchisors don’t often consider the benefits of providing back-office and accounting support for their franchisees, because they simply don’t feel they have to. Reliance on quality accounting and financial data, however, may begin to take on an entirely new meaning, given the nature of the economy right now. 

High unemployment and low consumer confidence have caused spending decreases which have impacted even the strongest of established businesses.  With credit markets being as tight as they are, business owners are unable to obtain the financing required to expand their businesses when required, to new locations or with additional personnel.   The 2010 Franchise Business Outlook[1]  suggests that, even as the economy starts to recover, franchised small businesses will continue to face these financing struggles.  The forecast is for “a slow recovery with marginal increases in the number of establishments, jobs and output.”

Looking to Washington for help, a number of small business organizations, along with The International Franchise Association, are “calling upon Senators to include more provisions in new job creation legislation to help small businesses access credit.” [2] The fear is that if credit access for small business isn’t made available now, the best opportunity to create sustainable business and subsequent job growth will be lost.  Reliance by small businesses upon credit is unquestionable.  

According to the IFA, “the depletion of [SBA loan] funds last fall is proof that the SBA programs were, and continue to be, critically important for our nation’s credit-worthy entrepreneurs”.  However, without sound business accounting and provable data, even the most business savvy entrepreneur may find their business “unbankable” and must therefore rely upon personal credit guarantees to support business growth.

Possibly the strongest point in the argument for franchisors facilitating accounting and financial management assistance to the franchisee centers on Item 19 of the FTC and state Franchise Disclosure Documents (FDD)/Uniform Franchise Offering Circular (UFOC).  Item 19 is the Earnings Claim, which are estimates or historical figures detailing sales, expenses, and income a prospective franchisee might realize as the owner of a particular franchise.

The Earnings Claim is often considered to be the single most important factor in buying a franchise.  As with purchasing any business, it is critical to have a realistic and supportable projection of sales, expenses, and profits earned.  Particularly in a case where a potential new franchisee has no experience running a business, or no applied experience in that particular type of business, the earnings claim becomes the only guidance available.  Unfortunately, the only source for this information is the franchisor itself, which often introduces doubt as to the veracity of the data.  It is difficult to determine which could raise more doubt about the sincerity of the franchisor: using unverifiable data, or not providing an earnings claim at all.

When a franchisor elects to provide services to their franchisees, such as back-office accounting support or financial management oversight, then the opportunity to obtain data for the earnings claim, performance benchmarking, and royalties verification become realistic goals.  Further, the ability to verify and substantiate the data can prove invaluable in a tough franchise market where buyers want good, verifiable information, and Item 19 helps sell units.

Offering accounting support to small business owners isn’t a new concept, but the technology to facilitate a truly seamless relationship has only become available in recent years.  As Internet and Web-based application services emerged on the market, businesses flocked to them in order to gain the benefits of anytime, anywhere access to applications and data.  However, the poor performance and lack of features left some business users without the tools they needed to handle all their requirements efficiently, so many returned to manual or local PC-based systems. 

Application hosting approaches offer a technology model which adapts trusted and proven software and systems to a cloud-based, collaborative online working model.   This technology model allows the businesses to continue use of applications with the functionality required to support the business, but improves the IT environment by managing and securing the systems within a secure facility, and utilizes the resources of the service provider to facilitate the ongoing management and support of the systems.  

Owners are able to retain their investments in software applications and processes, while introducing new efficiencies and flexibility in their working model.  The evident benefits are the ability to access information from any location, to have multiple locations work seamlessly together, and to allow outside accountants or other service providers to work seamlessly in the organization.  

Application hosting services also offer centralized management and administration, professionally-secured systems, and deliver reduced costs of IT management, predictability in ongoing IT costs, and an improved ability for the business owner to focus on the business.  Further, the solutions delivered allow for the integration of data with reporting systems designed to assist in the translation, analysis, and comparison of data from a single business to an entire franchise system.

In summary, the franchisor market must look more closely at the fiscal management and reporting systems of their franchisees, and provide avenues to better-address accounting and bookkeeping responsibilities in order to gain credible performance data and useful benchmark metrics.   Only through the ongoing participation of accredited accounting and financial personnel can the business financial data provide the information – and the insight – required to support aggressive business growth in this difficult economy.   

The key is seamless integration, and the technology solution is the cloud-enabled model.

J


[1] Report that measures the economic impact of franchising in the United States, prepared by PricewaterhouseCoopers (PwC), and commissioned by the International Franchise Association Educational Foundation.  http://franchise.org/uploadedFiles/Franchise_Industry/Resources/Education_Foundation/2010%20Franchise%20Business%20Outlook%20Report_Final%202009.12.21.pdf


Thursday, June 10, 2010

QuickBooks POS in a Hosted Environment

http://www.entrepreneur.com/microsites/postrelease/index.php?prx_adv=126&prx_ap=0&prx_rk=1374787251045&prx_t=23209527
entrepreneur.com
QuickBooks Point of Sale in a Hosted Environment

Retail operators and multi-location store owners often face difficulties in attempting to bring cohesion to their accounting, financial, and operational data.  In so many situations, the retail location –  where inventory is sold and money is exchanged – is far-removed from the administrative location where the financial systems and business reporting exist.  It seems that the best case scenario is to create a means for the remote (retail) locations to operate with real-time access to centralized customer, inventory, and financial data from a primary source. Application hosting services can provide this centralization,  and a platform for standardization, of systems.  Further, the application hosting model can deliver security and managed service which ensures that the systems are available and performing as required. 

Even though hosted applications and centralization of the systems and processes in a POS environment may appear to be the right answer, there are caveats and considerations that speak to the realities of today’s technologies.  These caveats should be strongly considered prior to undertaking any reformation of systems and processes relating to the retail locations.

The first fundamental reality which must be addressed is connectivity.  While a retail or store location may enjoy Internet or network connectivity, there should be great consideration given to the wisdom of connecting these locations only and exclusively via remote access systems.  Retail is a dynamic business, and the sale is made when the customer is ready and willing to buy.  Any retail location must be able to process this sale in order to meet the immediacy of customer demand.  If the systems in use are exclusively accessed remotely, then the connectivity to those systems become of paramount importance in the ability to do business.  At the very minimum, any remotely-served retail location should have redundant connectivity options, with local personnel being familiar with the connection failover process.

A second strong consideration for a hosted or remotely-deployed POS or retail system is local device support.  Devices, such as card readers, scanners, cash drawers, receipt printers, etc. typically require local PC/computer drivers in order to function.  When served by a remote system, this connection between the host and the local devices may not function.  Limited device support for POS hardware can significantly impact the location’s accuracy and efficiency.

Another area of consideration for POS and retail systems centralization is integration or synchronization of POS data with core accounting and financial data.  Depending on the software solution in use, this integration may require that the POS software/data and the financial software/data reside on the same computer and/or within the same network.  This may be one area where a hosted implementation may offer a great deal of benefits, but the benefits to be derived are often a function of the design and behavior of the applications integrating.

QuickBooks Point-of-Sale, for example, was designed for use on a single-user PC environment.  The application is not well-suited to a hosted deployment for multiple users, as the software only allows one instance of itself to run on each computer. While there is a “multi-store” option for this solution, the option requires all stores be connected via a LAN/WAN connection to the same network. RDS (remote data sharing) functionality might possibly be used to allow communication between locally-run POS locations and the “master location” at a hosting service provider, but this method of communication has previously been found to be somewhat problematic and platform-specific (see notes following relating to multi-user/store configuration and Vista OS).  Further, the potential poor performance of RDS connections often negatively impacts the value of the integration.  


In many cases, the suitable answer is to keep the POS systems running on the local computers and network, and run the financial applications and the POS integration at the host.  With an installation of the QuickBooks financial application and the point-of-sale solution with the hosting service provider, the core financial data is able to be secured and protected in the virtual environment without risking lost productivity (and lost sales!) due to connectivity failures at the retail locations.  The end-of-day process at each location is to then move a copy of the POS data file to the host system, where it would be integrated with the QB financial data.  In environments where is is desirable to have the POS systems reading customer and/or inventory data directly from the QuickBooks financial data files, the recommendation is to keep an available copy of the financial data file in the POS network, on the local computers.  This copy of the data file provides the point-of-sale systems with necessary customer and product information, and would be copied/updated during the same end-of-day process where POS data is moved up for integration on the host system. 

This process is very similar to the way in which a localized system might be utilized, where the POS application runs at the front counter and the accounting application and data run from a back-office system.  In this scenario, many businesses elect to simply log off from the front counter system so that they can launch the POS application from the back-office computer, and then integrate the POS data with the QB financial data on that same computer.  Even in remote network configurations (WAN configuration), this is often a method which delivers better performance and stability than utilizing the remote data sharing service.



Wednesday, January 20, 2010

Implementing Intuit Statement Writer on a Secure Network

The Intuit Statement Writer is a custom reporting and financial statement tool for use with QuickBooks Premier Accountant and Microsoft Excel. The solution has a few peculiarities that must be addressed in order to make it function properly (or at all!) in a networked or hosted environment.

The issues center primarily around the fact that the application was designed for use on a standalone PC, and doesn’t take into consideration the potential for redirected or restricted data folders. Further, the method of integration with Microsoft Excel requires specific support from the Excel application, so care must be taken in selecting the version of Excel (or Microsoft Office) to be used.

In computing environments where the QuickBooks and Office applications are installed directly on each PC, and where data is stored locally on the PC, most of these issues become irrelevant. When the applications are utilized within a strictly controlled domain, however, a variety of issues may arise. If the applications are to be utilized in a terminal server environment, then many issues will certainly come into play.

The Intuit Statement Writer solution requires QuickBooks Premier Accountant v2010, and Microsoft Office 2003 or greater. The version of Office or Excel used must be at least version 2003, and it must be either the full standalone version of Excel, or Excel as part of MS Office Standard, Professional, or Enterprise. Excel as part of MS Office Small Business, Basic, or Student/Teacher editions is not compatible. All editions of Excel 2007 are compatible.

By default, the Intuit Statement Writer (ISW) stores its files on the local PC where the application is installed. The application utilizes the local “My Documents” folder as the location for ISW files. In an environment where the My Documents folder is redirected to a network folder or share, the program fails to install or run properly. The specific error messages encountered may vary, but are essentially indicating the same issue: you are attempting to use an unsupported file folder location.

Intuit Statement Writer (ISW) requires full trusts and permissions to the My Documents folder, which is automatically granted when the folder is local to the PC. When My Documents folder is pointed to a shared network drive, the trusts and permissions are no longer granted and the error message will appear. According to Intuit, “Intuit Statement Writer files and appearance files (.gsm and .gss) can be stored on a server or network drive, but it is not possible to open and work with the files while they are located on the server without modifying security policies on the machine. Because we don't recommend this, the files must be local when working with them." It is necessary to copy the ISW file you wish to work with to your local drive, and, when finished working with the file, copy it back to the server.

In addition to having difficulties using server or network drives, ISW also will not function as a multi-user application, due to the architecture and reliance upon the MyDocuments folder. While ISW may be used without issue while QuickBooks is in multi-user mode, only one user at any time is able to work with the Intuit Statement Writer files.

Relating to the policy and permissions issue, there is a Microsoft Support article which describes a potential resolution (http://msdn.microsoft.com/en-us/library/9w6bd8f1.aspx How to: Grant Permissions to Documents and Workbooks in Shared Locations (2003 System)) This article addresses this issue and provides information on modifying security policies around the Office Document Membership Condition on the computer(s) where ISW will run.

Two methods are provided: using Visual Studio command line tools, or using the Microsoft .NET Framework configuration tool.

In an effort to simplify making these changes on your systems, Intuit has provided a batch file which can be run on the system where ISW is installed, and where the My Documents folder is redirected for the user.

Obtain the batch file here: https://www.quickbase.com/db/bewwfafti?a=GenNewRecord

This batch file (actually 2 batch files) grant full trust to the ISW dll files, checks to see if and where the My Documents folder is redirected, and attempts to grant full trust to the specific network location of the My Documents folder through the Microsoft .NET Framework 2.0 assemblies. Care must be taken any time .NET security policies or configurations are adjusted, especially when working within a secure domain. The .NET Framework Configuration tool (Mscorcfg.msc) enables users and administrators to modify security policies for the machine policy level, the user policy level, and the enterprise policy level.

From Microsoft: "Prior to the .NET Framework, most Windows applications had free access to all of the local computer resources, including the registry, file system, event logs, environment variables or available printers. Due to the limitations of role-based security, administrators were conditioned to accept that nothing was off limits to a running application as long as the user (or the user context under which the application is running) was authorized to use the resource.With the proliferation of distributed component-centric systems, it's not uncommon for applications to download and execute components from Internet/intranet sites or network shares. The possible negative consequences of such applications are obvious. Malicious code, whether by design or not, could be loaded from an external entity and wreak havoc on a local computer or the network on which it resides. There is also the threat of security breaches that could jeopardize the privacy of sensitive data."

Because the Intuit Statement Writer utilizes features of Microsoft Excel, it relies heavily on the behavior of the Office applications and document permissions on the computer and network. These permissions are often controlled by establishing security profiles or policies via the .NET framework. If the location of a Microsoft Office 2003 document is not secure (for example, a SharePoint site or file share that users—possibly including malicious users—can write to), or if you are not sure who has permission to upload content, you can grant permissions only to documents and workbooks in the location, rather than to all content. You do this by using the Office Document Membership Condition, and modifying the security policy to check for this condition on the computers on which your solution will run.

When you use the Office Document Membership Condition, only Office documents are trusted; assemblies and executables are not granted permissions to be run from the share.This permission or trust is often assigned to a “code group”. Code groups can provide information on how the system determines the allowed permissions. The allowed permission set for the policy level is the permission set associated with the code group that has this attribute.

When all policy levels are considered, the runtime never grants the code more permissions than those associated with the Exclusive code group. Within a given policy level, code can be a member of no more than one code group that has the Exclusive attribute. This may be problematic for some administrators who wish to implement the Intuit “fix”, which creates a policy group and then establishes that group with the Exclusive attribute. Network administrators with pre-existing security policies may well find that the Intuit fix will not work as delivered, due to the fact that Exclusive policy groups may already exist to govern the permissions of Office or other documents.

Intuit KB Article: http://support.quickbooks.intuit.com/support/Pages/KnowledgeBaseArticle/1011230

1. After the zip file is downloaded, you will need to extract it to the desktop...

2. After the file as been unzipped, open up the ISWFix1 folder and double-click on the ISWFix1.bat file.

3. These steps will need to be performed for each computer or user account that needs access to ISW.

4. Terminal Services/Citrix: Ensure the ISWprefs.ini file is set to not delete itself when the user logs out.

http://msdn.microsoft.com/en-us/library/2bc0cxhc(VS.71).aspx#cpconnetframeworkadministrationtoolmscorcfgmscanchor4

Microsoft .NET Framework configuration tool

Tuesday, January 19, 2010

Turning to IT When Times are Tough


-->
Turning to IT When Times are Tough
When budgets get tight and the economic outlook is bleak, business owners and executives tend to turn to information technology departments and projects as a potential area for cost cutting. The reason for this is that many businesses view IT purely as a cost center, making it a prime target when driving to reduce operating costs. A recent survey by McKinsey & Company, however, indicates that the current trend is a bit different.
The new research indicates that many non-IT executives "seemed to have a developed a healthier appreciation for their information technology functions" according to Joe McKendrick in a recent ZD Net article on the subject. McKendrick mentions that business executives generally seem pleased with the way the information technology is helping organizations get through these difficult economic times, "navigating the rough seas" as he puts it.

"The survey also suggests that organizations that took the most advantage of information technology going into the recent downturn may have come out the strongest" observes McKendrick.

The McKinsey & Co Study, authored by Roger Roberts and Johnson Sikes, reported that the recent economic downturn actually increased awareness of the role information technology can play in improving business processes and reducing costs. As for the quality of services delivered? The study revealed that non-IT executives largely believe their IT functions responded effectively to the economic crisis. A majority said current performance in providing basic IT services is very or extremely effective. In contrast, IT executives had a dimmer view of their performance, with only a minority being satisfied with service delivery levels.
There have always been questions about the alignment of information technology to the business need, and IT is often perceived as being out of touch with the business. In this new research, McKinsey & Co indicate that IT executives are very aware of the issues of keeping up with the business and are finding innovative ways of addressing them.
Joanie