How Risk Management Affects Data
Centre Design
A Practical Approach to Complex Issues
My Three Fundamental Beliefs
• Facilitative Leadership
– All of our experience and expertise is of value
– The diversity of our experience and expertise should not be
exclusive or divisive, but rather used to help reach healthy
consensus
• There are no magic bullets
• Our customers don’t care about cabling
In the News!
• Welding mishap blamed for
Amazon data center
construction fire
• Cabling experts suggest FAA
fire is the tip of the
sabotage iceberg
• Destroyed in 60 Seconds: Riser Closets Offer Easy Target for
Disgruntled Building Tenants to do Damage – Blog Article
Downtime Costs!
Technology researcher Infonetics Research, now part of IHS, Inc. (NYSE: IHS), recently conducted in‐
depth surveys with 205 medium and large businesses in North America and discovered that companies
are losing as much as $100 million per year to downtime related to information and communication
technology (ICT).
According to the survey, the most common causes of ICT downtime are
failures of equipment, software and third‐party services; power outages;
and human error. Infonetics’ respondent organizations said they
experience an average of two outages and four degradations per month,
with each event lasting around six hours.
“Fixing the downtime issue is the smallest cost component," adds Machowinski. "The real cost is the toll
downtime takes on employee productivity and company revenue, illustrating the criticality of ICT
infrastructure in the day‐to‐day operations of an organization."
Overview
• Data centre growth is exceeding the market
• Shift to managed and cloud based services
• ‘Big Data’ is here to stay and is only getting bigger
• Risk management should be part of every DC design, and
operations review, but;
– Are we focused too much on cataclysmic events, nefarious acts, and
acts of nature?
– What about the innocent, accidental or evolutionary events that pose
threats to the DC
Agenda
• Introductions
• Market Drivers and Industry Guidance
• Risk Assessment Methods
• Types of Risk
• Group Activity and Review – Identifying Risks
• Supplementary Tools & Concepts
• Group Activity & Review – Making a Plan
Who we are and what we do
INTRODUCTIONS
Presenter
Henry Franc RCDD OSP CDCDP
Solutions Specialist
t. 416.476.1336
e. [Link]@[Link]
BICSI Member
Member, BICSI Standards Committee
TIA Engineering Committee Participant (Premises, Copper & Fiber)
Chair TIA TR42.3 (Pathways & Spaces)
Vice Chair TIA TR42.10 (Sustainable Information Communications Technology )
Member, Standards Council of Canada (SMC/JTC1/SC25)
Past Chair TR42.1 (Commercial Buildings), TR42.4 (OSP) & Editor ANSI/TIA 758
Past Member CSA T104 Standards Committee (disbanded)
Market Drivers and Trends
INDUSTRY GUIDANCE
Lots of Buzz
The World We Live In …
The Internet of Everything …
Internet of Information
60T web pages (Google Index, October 2014)
Internet of People
1.3B Facebook active users (June 2014)
Cisco Connections Counter, October 2014
Internet of Mobility
Mobile devices account for 44% of all IP traffic (2013)
… Connected to 50B Things by 2020
2015 Tech Trends
The Merging of the Real and the Virtual Worlds
1 Computing Everywhere
2 Internet of Things Data Characteristics
Multiple “Layer 0”
3 3D Printing Volume
Intelligence Everywhere Technologies
Source
4 Advanced Pervasive Invisible Analytics
Location Required
5 Context‐Rich Systems
Flow
6 Smart Machines to Support
Frequency
IT for the Digital Business
Future Needs
7 Cloud/Client Architecture Diversity
Software‐Defined Infrastructure &
8
Applications
9 Web‐Scale IT
10 Risk‐Based Security & Self‐Protection
Source: Gartner, 2014
Two Distinct Markets
LAN Data Center
• Standard driven using ‘commodity’ technologies • Rapidly transforming (and departing from LAN)
• Installed base responding to current needs • Robust growth fuelled by
• Modest growth tied to − More data
– New construction − Greater bandwidth
– IP Convergence − Improved efficiency
– Power‐over‐cabling
• Cloud providers are changing the rules!
– WLAN
− Hotbed for new ideas, new technologies,
• New technology: POLAN new topologies
• Conventional and slow‐paced • Dynamic and fast‐paced
• Upgrade path: Cat5e/6 to Cat6A • Cloud vs. Enterprise segmentation leading to
multiple roadmaps and customization
Evolving ICT Model
Data Center Options
• What’s in it, where is it, how is it managed, who
owns it?
Data Center Investment Market Drivers
Enterprise Owned Multi-Tenant Cloud
Monthly bill for gas, electric, water, data…
Enterprise Owned Multi‐Tenant Cloud
Stimulates Innovation
Building: Provider
Infrastructure Buyer Enterprise Provider
Cabling: Enterprise Leaf‐Spine
Investment Large Capital Capital / Operational Operational
HSA
Agility / Scalability Low Med High
White Optical
Performance “Best Compliant” “Min Compliant” “Purpose Built” Boxes Shuffle
Technology (Cloud,
Standard driven Pick & Choose Bleeding Edge 25G
Mobility, Performance)
Data Center Market Segments
Enterprise Owned Multi-Tenant Cloud
$3.4B TAM, -4% CAGR $1.2B TAM, +2% CAGR $1.1B TAM, +31% CAGR
Key Attributes: Key Attributes: Key Attributes:
• Capital investment model • IT owned by enterprise • Operating expense model
for new builds client, while space and for clients
• Cloud applications and power are leased • Enabler of accelerating
virtualization driving • Multi-tenant providers mobile / cloud usage
segment decline seeking differentiation are • Competitive advantage lies
• Full spectrum of scale and expanding into hosting in DC performance: driving
technologies reside in services custom switches and
enterprise owned DCs servers (white box)
Cloud Server Shipments Will Exceed Enterprise Server Shipments by 2018
Sources: Dell Oro, Gartner, 451, Cicso Networking Report, Facebook
VOC
Technology Trends
COMMERCIAL
MATURITY 40G –SR4
40G/100G 100G –SR10
HSA
10GBASE‐T
Passive Optical 2015
LAN
2015
Power over ? 2020
HDBaseT 2.0 Cabling
25G/50G/100G
EARLY
DEPLOYMENT
?
40G BiDi 802.11ac Wave
2
25G/50G/100G
Ultra Wideband ?
MMF
40GBASE‐T
Category 8 Silicon ?
Photonics
R&D
LOW GROWTH POTENTIAL HIGH
LAN DC
Continuity and Availability
• It’s all about availability
– Which includes resiliency, redundancy, and recovery
• Many methods
– Uptime Tiers
• Tier 1 – Single Path ~ 99.67%
• Tier 2 – Single path with redundant components ~ 99.75%
• Tier 3 – Concurrently maintainable and operable ~ 99.98%
• Tier 4 – Fault tolerant ~ 99.99%
Note: these are guidelines and targets not guarantees also there are no half steps
for Uptime e.g. Tier III.5 or mixed tiers
– BICSI, TIA, Others
Redundancy
• There are multiple ways of achieving, expressing and
measuring redundancy
– N – basic requirement, no redundancy
– N+1 – provides one additional unit/module/path/system in addition to
the basic requirement
– N+2 – provides two additional u/m/p/s in addition to the basic
requirement
– 2N – provides two complete ‘basic’ requirements
– 2(N+1) – provides two complete (N+1) units
Redundancy – Not Clear Cut
• Sometimes it’s easier to see – lets use the birthday example
a birthday party for my daughter and 4 guests
Redundancy – Multiple Systems
• But that was only one system … we have many
One Size Doesn’t Fit All
• Most Systems are similair but use different terms
– BICSI uses Facility Availability Classes (F0‐F4 for different classes of availability)
– TIA uses the TEAM (Telecommunications, Electrical, Architectural, Mechanical)
– Ratings (TIA) /Classes (BICSI) /Tiers (Uptime) build upon each other
• Type 1 – Basic requirements
• Type 2 – All Type 1 requirements plus ‘some’ redundant components / systems and
additional requirements
• Type 3 – All Type 1 & 2 requirements plus duplicate services / systems and additional
requirements
• Type 4 – All Type 1, 2 & 3 requirements plus redundant components / systems / services
and additional requirements
Note: All services do not have to be at the same class (for TIA) e.g. T1E2A1M2
Lets Take a Break
Methods for
RISK ASSESSMENT
What is it?
What Not to Do … Other than Keep Calm
Basic Premise and Concept
• Risk management is a ‘process’
Control
• Control cannot be achieved
without an effective all
encompassing security
program
• In isolation tools, processes
and countermeasures are
not enough
Components of Risk Management
• Some risks can’t be seen • A multi‐step process
• Some threats can’t be • Plan for the known and
avoided unknown
• Sometimes • Regular review should
countermeasures will fail be mandatory
• What happens when • Should adapt to
during an outage? changing requirements
(assets), threats and
vulnerabilities
Situational Analysis
• A thorough analysis should be
done, and there are many
tools
• A common tool is the SWOT
analysis
• It changes based on
perspective owner, provider,
partner etc.
Threat Evaluation
•
Very High
Button
5 Button
10 Button
15 Button
20 Button
25 Threats
5
High
– Probability
Button
4 Button
8 Button
12 Button
16 Button
20
– Impact: scale, recovery and operational
Probability
4
Medium
Button
3 Button
6 Button
9 Button
12 Button
15 • Basic Evaluation
3
– Red (Critical) needs attention
Low
2
Button
2 Button
4 Button
6 Button
8 Button
10 – Amber (Warning) may require attention
Very Low – Green (‘OK’) no attention required
Button
1 Button
2 Button
3 Button
4 Button
5
1
• Once evaluated priorities can be set
Very Very
Low Low Medium High High – Controls designed/implemented
1 2 3 4 5 – Countermeasures prepared
Impact
Many Shades of
RISK
Vulnerabilities & Risks
• There are many types of vulnerabilities that have
risk attached
– Facilities (TEAM)
– Systems & software
– People
– Processes
– Products (can also be a viewed as a subset)
TEAM ‐ Telecommunications
• Telecommunications guidance
– Standards compliance
– Diversity & redundancy
• What’s the difference?
• What about recovery and continuity?
– Cabling & pathways
– Power supplies, fan trays, uplinks etc.
– Administration and management
TEAM ‐ Electrical
• Electrical guidance
Maintenance Monitoring/analysis Points of failure
Utilities UPS PDU
Transfer switch(s) Grounding (protection) Emergency Power Off (EPO)
Batteries Standby Generation Fuel Considerations
Loadbank & Testing Topology
TEAM ‐ Architectural
• Architectural guidance
– Site Selection (floods, airports, proximity to services etc.)
– Access (parking, roadways etc.)
– Type of construction (structural, tenancy, roofing, doors, windows etc.)
– Organization of spaces (administration, entry, loading dock, washrooms
etc.)
– Special considerations (security,
fuel/generator/batteries, monitoring,
bullet resistance etc.)
TEAM ‐ Mechanical
• Mechanical guidance
Redundancy Pipe routing Drains
Air pressure (+/‐) Drains Cooling systems
Heat rejection HVAC controls Fuel oil system requirements
Fire suppression Smoke detection Water leak detection
Published Guidance
• Most published guidance is about failure, acts of
nature and/or nefarious acts
– What about change, accidental, innocent, evolutionary,
business and other risks?
– People make mistakes
– Processes have gaps
– Products wear, fail, or can be improperly used
Regulatory Compliance
Payment Card Industry
Data Security Standards
Federal Information
Security Management Act
Statement on Standards for
(FISMA)
Attestation Engagements
(SSAE)
Lets Take a Break
Group Activity
RISK ASSESSMENT
Supplementary
TOOLS & CONCEPTS
The Ones You Don’t See Coming
• The Sunscreen song:
“Don't worry about the future; or worry, but know that worrying is as effective as trying to solve an
algebra equation by chewing bubblegum. The real troubles in your life are apt to be things that
never crossed your worried mind. The kind that blindside you at 4pm on some idle Tuesday.”
• A recent survey of DC & IT operations professionals had interesting
results:
– On average 2 downtime events per respondent in the 2 year study period
– 62% of IT executives believed unplanned outages don’t happen frequently (41% rank and file
agreed with this assessment)
– 75% of senior level respondents believed they fully support efforts to prevent and manage
unplanned outages (31% of supervisory and lower staff agreed with the statement)
Examples TEAM
• Events • Countermeasures
– Patching the wrong port – DCIM, AIM, asset
– Accidental removal of management
patching – Traceable cords
– Dirty fiber – Tabs & locks
– Design mismatch – Design review
– Labelling and administration
Examples TEAM
• Events • Countermeasures
– Phase balancing – Labelling and administration
– Load sharing – Metering, monitoring, DCIM
– Plug removal – Locks and clips
– Panel access – Design review (BIM)
– Breaker trip, fuse removal – Finger guards
– EPO – AHJ coordination/covers
Examples TEAM
• Events • Countermeasures
– Door height/width – Procedural checklists
– Loading docks – Shipment/material
– Access/security bypass verification
– Location (flood plain) – Security audit
– Address – Monitoring and surveillance
Examples TEAM
• Events • Countermeasures
– Airflow blockage – Cross‐team collaboration and
– Air bypass coordination
– Venturi effect – Work flow management
– Aisle alignment – Commissioning
– Containment ‘work‐arounds’ – Design review
– Monitoring and alarms
– DCIM
Examples Systems and Software
• Events • Countermeasures
– Decreasing budgets – Factory terminations
(loss/length) – Solution flexibility and
– Connector wars common footprint
– Polarity – Common‐sense design
– Software – Workflow process
– Airflow mismatch – Connectivity management
(DCIM)
Examples People
• Events • Countermeasures
– Language barriers (acronyms, – Training & equipment
terms, understanding etc.) – Skills mapping
– Lack of skilled/qualified resources – Established & documented
– Human nature (multi‐tasking, workflow
assuming, shortcuts) – Monitoring and surveillance
– Honest mistakes – Dispatch management and alarms
– Tools – Asset and connectivity
management (DCIM)
Examples Processes
• Events • Countermeasures
– Wrong disconnect – Workflow documentation
– Unscheduled disconnect – Audit and review
– Load balancing – Monitoring and alarms
– Stop work / shutdowns – Dispatch management
– Scheduling conflicts, multi‐ – DCIM, asset and connectivity
disciplinary conflict management
Examples Products
• Events • Countermeasures
– Product mismatch – Solution commonality
(Category/Class/Connector) – Product rationalization
– Polarity and pinning – Standards based design
– Product availability – Modular design
– Explosion of SKUs – Common building blocks
– Wear and tear – Spares & ERKs (Emergency
restoration kits)
Create a Project Charter
• char∙ter ˈCHärdər/
noun
noun: charter; plural noun: charters
1. a written grant by a country's legislative or sovereign
power, by which an institution such as a company, college,
or city is created and its rights and privileges defined.
• Essentially a definition
– Concept
– Goals, objectives and constraints
– Specifications
– Measures of success
• Aligns and focuses the team
Dealing with Issues (FSNP)
F Forming
Learning about each other
• Understand:
– Tribalism
S Storming
Challenging each other – Motives
– Point of view
N Norming
Working with each other
• Manage Conflict
P Performing – Compete, collaboration,
Working as one
compromise, avoid,
accommodation
Growth and Evolution in the DC
• Green Grid
– Expects organizations to progress
through the model
– Encourages to move up when feasible
taking into account business and facility
constraints
• Not just regarding efficiency
– Changes in organization, business model
– Technology capabilities and requirements
RACI Matrix
• What is a RACI Matrix? Accountable
“A responsibility assignment matrix
(RAM), also known as RACI matrix
Responsible RACI Consulted
/ˈreɪsiː/ or ARCI matrix or linear
responsibility chart (LRC), describes
the participation by various roles in A
RRR
completing tasks or deliverables for a Informed
CCCCCC
project or business process.” ‐ IIIIIIIIIIIIIIIIIII
Wikipedia The RACI Triangle
How to Use a RACI Matrix
• Mapping overall risk management
RAM
– Sub‐sets of the procedures
– Good for what‐if scenarios
• Any component of the RACI
matrix may have no, one or more
levels of expectation of a
particular function in the matrix
• Ensures accountability through all
steps and roles
Objectives
• Primary objectives of a risk management plan:
– Identification of potential for negative events and their causes
– Reduction of negative events (e.g., errors, outages, loss of data
etc.)
– Recovery from negative events
– Limit impacts of negative events
– Review events to evolve the risk management plan
Group Activity & Review
MAKING A PLAN
Sidebar – New In Standards
• New DRAFT Addendum to
ANSI/TIA‐598‐D.1 in ballot
stage, additional colours for
fiber
– Because of MPO(16) &
MPO(32)
– Lime, Tan, Olive, Magenta
– For 17‐32 black tracer
– For >32 different tracers
Thank You!