CA Community






This Blog

The Consumerization of IT – What and Why?

Published: September 06 2011, 04:51 PM
by Sumner Blount

"I'm sorry, but you can't use that device because we don't support it in IT"

Sound familiar? If so, you may want to share this blog post with the person who said that to you.

Some users have chafed under the restrictions that IT has placed on them, in terms of how they access IT resources.  Sometimes it has felt to them as if IT had all the control, and the users must conform, like it or not.

But, IT has been undergoing a significant shift recently called the "consumerization of IT." This trend will probably continue as the flood of new and more intelligent devices continues, and as the typical worker becomes more mobile. 

Some people believe that consumerization of IT means only supporting new, smarter consumer devices.  But, although that was the first symptom, this trend is actually far more important and impactful than that. It also includes the massive popularity of social media vehicles for communicating with others - Facebook, Twitter, LinkedIn, Google+ and many, many more. It also is often viewed to include the strong growth of cloud-based services.

But, it's not just about devices - it's about the shift of control. The role of IT is changing, and this change is highly likely to be long-lasting.  IT can no longer be rigid about how the users will interact with IT resources and what devices and access methods are acceptable.  Users will be using these devices, so IT must accommodate them while both ensuring security and supporting the convenience that they provide. It used to be that IT could say to users - "you play by our rules." Now, IT must play by the rules of their users as a group. 

Users also are changing in terms of their expectations of IT. Today's social-media savvy user has grown accustomed to near-instant gratification on their new sites and applications, and these expectations are carried over to IT. No longer will they tolerate long approval cycles, support for only antiquated devices, and the lack of control that they typically have had in the past.

The impact of these trends will result in a new model of information technology, accurately termed "Consumer-driven IT".  Users will be driving the requirements for IT, in part due to their adoption of consumer devices that are not controlled by a central IT group. This will result in new relationships not only between IT and their users, but also between IT and the business.  IT can become more of a business enabler rather than a mere gatekeeper of technology. In this regard, this trend has the potential to serve as a transformational driver for a new model for IT. 

Why is this trend occurring now? Several factors are relevant here:

  • Continued innovation in personal devices - consumer information technology devices have become powerful, ubiquitous, and cheap.
  • High growth in use of social media and related applications - as of this writing, Facebook has over 750 million active users, 250 million of them access it via a mobile device, and users spend over 700 billion minutes a month using it.
  • Externalization of the business - including use of cloud-based services and outsourcing of other functions.
  • The blurring of the line between personal and work life - the workforce is becoming more distributed, more mobile, and more home-based every day.

The consumerization of IT is likely to have important organizational impacts.  Paradoxically, this trend is likely to both expand the scope and reduce the control of IT. The scope of responsibility for IT will be expanded because its role now doesn't stop at the firewall - the corporate network now extends out to the user and their unique access devices. For example, users might download confidential information to their iPhone, and then mistakenly (or worse, intentionally) email it to someone outside the organization. Security for these varied devices needs to be a critical element of IT planning, and there needs to be comprehensive identity and access management capabilities to guard against attacks or improper actions by authorized users. 

But, at the same time, the control that IT can exert has diminished. Decision-making will become more democratic (some IT folks might interpret it as being more "chaotic" than democratic) as users begin to wield more power purely on the basis of their need for flexible use of IT resources. 

There will also be technology impacts. Security will become even more important because access to corporate IT resources from consumer devices introduces new risks that must be mitigated.  In addition, enforcement of access policy should become more flexible and dynamic, as contextual parameters become important in the evaluation of policy enforcement.  For example, contextual parameters of an attempted user authentication (such as location, time of day, recent user activity, etc.) will become important for deciding whether the authentication will be accepted, or whether additional, stronger authentication methods will be required. Finally, transparency of access will increase. The boundaries of IT services are gradually becoming more and more transparent to the outside user, as the assets that are accessed become virtualized, or available through on-premise, cloud, or a hybrid of the two. The user will not care where these assets reside, as long as access is quick, convenient, and secure.

Let's summarize - consumerization of IT is an important trend that has been going on for several years.   It will cause important changes in the way that users access IT resources, and the way that IT relates to its users and the business. 

Stay tuned for some more thoughts on this topic in a future blog ... meanwhile, you can read additional content here and more on security challenges here. But let us know in comments what security impacts you think exist?  How do the security risks of these devices differ from a simple laptop?  What do you think an IT leader should consider when dealing with multiple consumer devices and their security risks? 

 

By: Sumner Blount
Sumner Blount has spent his 25-year career focused on the development and marketing of software products for a range of top-tier enterprise IT firms. Currently, he’s a Director in the Security business unit at CA. Previously he managed the large computer operating system development group at Digital...
Read More..

6 people have left comments:

Playing Devil's Advocate here. :) Security isn't the only issue here, but it's a big one. How will desktop support times and costs be impacted by supporting whatever devices users want to use? If I have to train my team to support a broader range of devices, that is going to take time and other resources. And there is a context-switching cost here too - if my help desk team had been trained in supporting Dells, and now we have to treat Blackberries, iPads, Galaxies and other devices as first-class support citizens, it is going to require people who can switch their thinking from context to context.

Posted by: Bruce Onder | September 6, 2011 6:22 PM

Bruce,

you raise a good point.  I think it's clear that the effort to "support" these new devices is additive to the existing support load.  In other words, users aren't going to substitute consumer devices for their existing laptops, so IT will need to support existing devices, plus these new ones.

However, it seems to me that "support" for consumer devices will be less rigorous than with other, more tightly controlled devices, like a laptop.  I think most companies will establish policies about how these devices will be handled, and will communicate (probably strongly) the security and management policies that they will enforce.  But, in the final analysis, they are often employee-owned, and the enterprise has limited ability to control what software is running on those devices.  So, I don't see IT as being able, or responsible, for supporting these devices in their full capability.

So, yes....the burden on IT will increase, but not as much as if the device were a company-issued and fully supported access point.

Posted by: Sumner Blount | September 6, 2011 8:44 PM

It seems like users/businesses want to have their cake and eat it too... They want to drive IT costs down. They want to use whatever device they want, but they'll expect IT to support them on it. They want IT to maintain security and minimise downtimes, but they want to retain control of their devices and play their flash games, install random software etc. Consumerisation of IT sounds like a fantastic idea, but unless users are both encouraged and able to manage those devices efficiently and responsibly it will always be at odds with the demands to lower costs and maintain services securely.

Posted by: James Spinks | September 9, 2011 8:33 AM

James,

yep....you're completely right.  But, let's differentiate between the needs of the business and the needs of the users - I don't think you can merge them as you did in your first sentence.  The business wants to drive IT costs and protect assets.  The users want to use whatever device they want.  Those are the needs that are often in conflict.

Your last point is very well taken.  Use of these devices require clear and well-communicated use policies, at a minimum.  Each employee needs to know what the constraints are, and commit to following the rules.  Granted, that might not impact a rogue employee, but nothing tends to impact those types.

In the final analysis, IT can't (in all cases) dictate what software is or is not installed on the devices.  But, with certain security controls in place (eg, strong auth, etc), you can have adequate security for IT assets when accessed from these devices.  In a couple of weeks, I hope to have another blog on this topic, laying out this idea in more detail.

again, thanks a lot for the comments.  It's always good to explore issues like this with folks who are on the "front lines" of it.

Posted by: Sumner Blount | September 9, 2011 8:48 AM

A few months ago, I posted a blog on Consumerization of IT ( here ) where I explored some of the causes

Posted by: CA on Security Management | December 13, 2011 3:59 PM

A few months ago, I posted a blog on Consumerization of IT ( here ) where I explored some of the causes

Posted by: Consumer Driven IT: Are You Ready? | December 13, 2011 5:23 PM

Leave a Comment

* An asterisk indicates a required field

* :  

:

* :  

 Submit