IT operation and maintenance is the core and key part of IT management. It is also the most contentful and complicated part. It is mainly used for daily operation management within the IT department. The objects involved are divided into two parts, namely IT business systems and operation and maintenance personnel. Its management content can be subdivided into seven subsystems:
First, equipment management: monitor the operating status of network equipment, server equipment, and operating systems, and monitor and manage various application support software such as databases, middleware, groupware, and various general or specific services, such as email systems, DNS, WEB, etc.;
Second, data/storage/disaster recovery management: unified storage, backup and recovery of system and business data;
Third, business management: including the monitoring and management of the operation of the company's own core business systems. For business management, the main focus is on the CSF (Critical Success Factors) and KPI (Key Performance Indicators) of the business system;
Fourth, directory/content management: This part is mainly for content management and public information management that enterprises need to publish uniformly or customize according to individual needs;
Fifth, resource asset management: manages the resource assets of each IT system in the enterprise. These resource assets can exist physically or logically, and can interact with the enterprise's financial department for data;
Sixth, information security management: This part contains many aspects. The current international standard for information security management is ISO17799. This standard covers ten control aspects of information security management, 36 control objectives and 127 control methods, such as enterprise security organization method, asset classification and control, personnel security, physical and environmental security, communication and operational security, access control, business continuity management, etc.;
Seventh, daily work management: This part is mainly used to standardize and clarify the job responsibilities and work arrangements of operation and maintenance personnel, provide quantitative basis for performance appraisal, and provide means to accumulate and share experience and knowledge.
Each subsystem of IT operation and maintenance management contains very rich content. The realization of perfect IT operation and maintenance management is the key for enterprises to improve their operation and service levels.
Current situation
It has a large number of expensive Unix hosts to support 80% of key information technology core businesses. There are security holes and hidden dangers in the account management of these hosts, and there are problems such as zombie accounts and shared accounts.
· The neural nodes of information services are mostly supported by expensive switches and routers. The management of these key nerves relies heavily on people to maintain them.
· Equipment operations cannot be effectively recorded, leaving review vouchers, and accounts that are completely controlled by humans can invisibly increase security risks.
·The authentication strength of servers and network equipment is not high, and usually only static password authentication methods are used, and static passwords are often weak passwords, resulting in the risk of unauthorized access to core servers.
· The complexity of information applications determines the cross-management of multiple roles (system/database/security/audit administrator/maintenance vendor, etc.). The authorization of partners cannot be effectively supervised, and evidence cannot be provided quickly, comprehensively, and effectively after a failure occurs, which creates a bottleneck for business growth.
· Operation and maintenance personnel use the omnipotent Telnet/SSH remote management tool, which provides opportunities for internal illegal employees, dissatisfied employees, and resigned employees to deliberately sabotage. Because there is no reliable tracing and positioning mechanism, losses are caused and liability cannot be held
· "A good horse can stumble." Users with legal authority have caused losses due to negligence and mistakes in operation, which cannot be identified.
Development
With the advancement of informatization, operation and maintenance management will cover traditional IT operation and maintenance, and also expand business operation and maintenance and daily management and operation and maintenance. Participating companies will comprehensively elaborate on the social and economic benefits brought by the integrated operation and maintenance management model. It is not only a change in the management model, but more importantly, it emphasizes the integrated management and control of corporate IT resources, comprehensively improves the ability of various departments to coordinate management and operate efficiently, so as to continue to promote the enterprise's informatization construction and establish an overall vision that is compatible with the development of informatization. Through continuous and scientific management, the rapid, coordinated and sustainable development of enterprise informatization is guaranteed, and a top-down active management system is established. The IT operation and maintenance management platform is a comprehensive and centralized management of computer systems. It is both resource-oriented and application-oriented, as well as management and maintenance personnel. It lays a good foundation for reducing the workload of operation and maintenance personnel in each branch. It is a trinity system that closely integrates talents, processes and tools.