logo

NJP

Data Governance with Kasthuri Nagappan and Sameer Kumar Pandey - part 2

Import · Jan 25, 2023 · video

hi Chuck here with a quick note to let you know that this episode on data governance was so full of great information that it went a little longer than our standard break point episode so I opted to break it into two parts this is part two of my discussion with kasturi nagapon and Samir Kumar Pandi from servicenow on data governance if you haven't listened to part one I invite you to go back one episode and get the full story and now on with part two welcome to breakpoint servicenow developer podcast here's your host Chuck tomasi I've got another question for you because story not not ignoring you Samir we'll come back to you are there specific tools that servicenow offers to help customers with data governance quite a lot to the customer number one I would say the cmbb data Foundation dashboards and the cstm dashboards which gives a detailed perspective and insights of how a cmdb can be configured and like I said when we are talking about data cmdb forms the foundation or the base and it gives details about the duplicate CIS what are the CIS without serial numbers how it can be tracked and also it get taxed with a remediation Playbook on how you can fix that as well and something that I really liked in the recent Tokyo updates or the the recent release is that there are customers who make customizations or changes to cmdv and they want to know how they can revert back after a while the new dashboard provides all such nice information it also gives details about the ipsm best practices that the developers should focus on on whether a serial number is tied to an incident or a business service so those key small things where we have to spend a lot of manual effort it's all available in the dashboard and that's going to help you achieve your data quality and data Integrity as well and the second being the health dashboards which is already there for quite some time which will give a details about the cmdb often CIS the tlcis which are not used for quite some time and we duplicate CIS uh from there the cleanup and the data audits can also be performed and based on my experience what I've seen is that when you're talking about the company data or the vendor or manufacturer it could be possible that the data references that we are making so if if at all there are any variants or duplicates enabling the data normalization plugin can help you normalize that we we can actually enable that with the standard name that is in place and finally for data accuracy we can enable data certification that can be performed against a specific field like for example if you want to validate the CPA account for a Windows Server that's based in Sydney you can enable the data certification rule that will assign a specific task to the teams we can authorize and make sure that audits are in place so these are the key things that can definitely help the developers but there are much more I recently took a look at the normalization and transformation Services you can find in the documentation if you look up field normalization and I it didn't actually fit my use case I was doing an import of about 100 records one time and I thought well I've got all these variations on an answer but by the time I stood it up it would have been quicker just to normalize it manually so there are use cases for this if you've got a constant let's say a nightly import and things are coming in in a known fashion and you say well if I see this variation of a CI name or a company name or vendor name something you can normalize that because I know it's always coming in from this source as that value but rather than having three or four variations on that you can normalize that down to a single instance of it uh if it's coming in on a regular basis or if you've got tens of thousands of records that are coming in you may want to normalize that even if it's a one-time thing it will save you a lot of time in the post migration of that so there are there are times when things like normalization are very very useful and times such as mine where it would have been quicker to do it manually but I got that experience of understanding what it's all about and that's valuable too yeah I mean it has Cascade benefits for the advanced functionality for example machine learning when the data is already normalized oh right system is able to protect the right kind of choices or the decisions that it needs to take so probability of the confidence of making the decision by the system is higher I wish I had known about field normalization when I wrote the karaoke out you hurt ways they could spell a band name [Laughter] is it Ray Parker Jr with a DOT is it Jr without a DOT is it spelled out junior is it even have a Jude it's like oh my gosh so I I kind of had to write that all myself that's not funny there Samir what can you tell me about the new and exciting stuff in Tokyo well Tokyo is very exciting release for us it brings in a lot of a lot of updates to various part of product Suite uh some notable ones that I'll try to quote and I'll try to pull in from where kasturi was also concluding so we have updates to data foundation and cmdb and csdm dashboards we also have updates to CI attestation which is when you want to verify the actual infrastructure how is it there and then be able to create a CI testation task for same TV manager you can have that logic defined so CI testation is there then we have new updates or functionality for how do you want to manage the orphan CIS and duplicate CIS if the parent becomes orphan or if the child becomes Urban then what do you want to do or the parent becomes orphan then how do you want to action on the child Ci's then we have something around data anonymization uh so you let's say want to clone production over to sub production and you want to anonymize the user data so some of the fields such as email ID and phone numbers you want to anonymize uh you can do that now through data anonymization plugin then we have something called a Secrets management which is one of the things that I look up to uh we we did not have so it's sort of a data anonymization for credentials okay so Vault management or credentials management credential also is a data configuration data like eight categories broad categories that I was talking about so how do you want to manage the secrets within service now so that is what Secrets management is about so a lot of that documentation is up to date on now learning and docs.seracenow.com around these features all right I was listening and I wrote it down so let me see if we can reiterate for The Listener updates to the cmdb and csdm dashboards wow that's hard to say uh that we've got the CI attestation data anonymization which I absolutely am intrigued by and want to go play with that and secrets management now Samir will stick with you do you have an example of when attention to data governance has paid off well definitely I mean this is so vivid uh I had this Global retail customer and right from the get go the team was really focused we had architect platform architect who was focused on how that data onboarding or ingestion will happen from The Source at that time we did not have CI certification module and other areas but so data Gathering used to happen using a Word document and an Excel file but right at the when we were having these kind of discussion there was a kid that was prepared just to explain what is the purpose of the data what how we want to ingest the data explaining the data owners what their data would have effect on servicenow and overall process making them aware about how their data is going to play a role in overall cross process was very critical and it it really helped everyone we had a local technical governance board where any kind of technical functionality was assessed but there was a bullet item for data Focus as well so every developer was asked for how that data is going to be utilized what is the source whether that data retention requirements are there if we are bringing any PI information I'm talking about 2016 when there was no such importance to Pia at that time and and that really paid off uh in a in a big way in terms of successful goalies now I have to mention when you talk about data governance as some customers even think about things like data protection or the policies that are involved like gdpr be an example of that uh do we do we get involved with that or is that just something about the the data governance process that everybody should be aware of customers may have a data privacy office which control has an overall control over the automation data spanning across multiple platform or systems service now being one of them so it is possible that service now a team will have to talk to data privacy office as well for what data is coming into servicenow and how that is going to privacy of data is going to be maintained so definitely uh these external parties or stakeholders definitely come into a picture Samir you gave us an example of when data governance works because story what happens if you don't pay attention do you have an example of that yes I I had that painful experience during the early stage of when we were implementing the customer was too focused on getting the process right make sure we are following the best practices the development guidelines workflows are built in but the foundation and core data was not uh was not that important they did not realize that it's it's important for the process to run and because of that I would say that there was a considerable delay and last minute rush during our implementation as well one like we were discussing for quite some time on the user data the proper data Clean cleaning activity or the normalization was not done and unnecessary data sets were brought in there were multiple records and there were multiple sources bringing in the same set of information and we had to work in the last minute when we were actually doing the go live to do that cleanup and it's quite a similar experience with the cmdb input as well where the data quality was not prioritized which resulted in a lot of rework and we had to do that tune-up exercise after our go live as well so that's that's why I would say remember the earlier three important criteria that we discussed about data migration and input it's important to follow those and then make sure that we are aligned and following the best data governance policies that we have in place you know that expression that you learned by your mistakes we've all we've all learned a lot from this stuff so we want to make sure that you don't the the listeners don't fall on their face or or get in trouble this is one of those things that you you look to a consultant you look to service now and say how do we protect ourselves we you've got the knowledge we we learned a lot of this the hard way so please don't do that again if you've been warned because story let's talk about security and throw some light on what developers should be aware of security is absolutely a mandate for all the customers and my advice for the developers is start these discussions in early stage of implementation don't leave it to the end and ensure that the right data is accessed only by the authorized users the authentication process that we have to enable have discussions with the customer if they want to enable additional security like multi-factor authentication or adding additional security rules like access controls one other way of Security is to completely understand the encryption Concepts there are ways we can encrypt your personal data for the data in transit versus the data at rest there is a detailed uh white paper also available it's it's highly important that the developer understand the concepts of encryption and the security and it's also recommended that they execute Health Scan and validate Authority score periodically and something which I always educate my customers when being on such Health Scan is that one example is public reports don't have public reports without any access or additional information that's going to affect your health score and there are other health definitions and criterias make sure you avoid that mistakes when you do the development and having instant security Center enabling that is going to help you monitor the compliance it will give you the compliance score and it will also help you understand the security health and if there are any security gaps that you have missed during the hardening process you will get a complete Insight of that in the security instant security Center and in addition to all these the data certification rules is going to help you in managing the audit and data integrity and finally depending upon where your customer is and be aware of the country rules and regulations like gdpr and other data regulation and protection policies not that we have to be a master of it but making sure you understand the basic is very very important for the developers wow that's a it's quite the list I think I'm gonna have to publish that in the show notes but that's excellent stuff hopefully everybody was writing that down as they were going or you rewind in about two minutes and listen to it again okay another one for you Samir what are the top three challenges related to data quality and integrity well I can think of three important ones and it is always around people process and Technology so having the developers or the team aware about data privacy data policies data governance rules the golden rules that are set up so there may be a new developer that is onboarded uh please make them aware about what policies are in practice in that environment and have those followed as well so you may want to have a doer and Checker kind of policy somebody do does it and then other person checks it or utilize uh right rules to make sure that that is followed second is about the technology what kind of trust do you have on the source so there may be a technology stack that is utilized which is primitive which is Legacy system so do you trust that data talk to the data owner if that data is not trustable maybe find another data source that is one option second is to be able to normalize that data so that you are able to then before you load it you are able to transform it so that it is usable by you or normalize it before you load it then third is collaboration between different teams or the process to collaborate so you might have a requirement to let's say have a site information now is that site information exactly as location information could you use the foundation data or do you have to necessarily create a custom table to information utilize site information if you are not talking or not collaborating between the Foundation team and the specific let's say Incident Management stream then if these two teams are not talking to each other or there is no forum for these team to talk or collaborate then there may be some siled decision that may be made and then you would run into situation where you are creating redundancy of the data by creating custom tables storing the data and that is moment and that is just truth in that moment but will become stale because core table will be maintained and your custom table may not get that updates so those are the three areas if I have to reiterate people process and Technology making sure your developers are up to date help them educate them coach them second is to trust the source if you don't have trust make sure that you are equipped to make those decisions and make the data consumable by service now third is process to collaborate okay I just did a little quick math and between the three of us I think we've got about close to 40 years of experience with data and governance and bad accidents we'll call them let's talk to the new listener or the new developer for a moment what advice do you have for them Samir well conventionally realize that data has not been developers responsibility but since the times have changed you are at the front run you are at the mainstream so this becomes your response to whether you like it or not no matter how technologically great solution you make data is very core important part of it for leaders to make decisions so you have responsibility be aware about the functionality that service now offers some of the tools that kasturi mentioned about some of the data mistakes that we make which can be avoided to make those meet meet those outcomes uh then is Success blueprint for data governance so there are a lot of tools that kasturi talked about today data certification Health Scan uh dashboards for foundation cmdb and CMD cstm then cmdb Health dashboards all those tool sets helped you manage that redundancy make sure that you are talking collaborating with the right teams to be able to make those data decisions and are also run through data governance policies that's a lot for the new person to know about but it's important stuff it really is trust me you don't want to ignore this or you will you will end up with the same scars the rest of us have at this point it everything's not perfect but you can certainly mitigate a lot of problems by following this what resources am I going to put in the show notes this time that people can refer to so that they don't have to rewind and write down everything that we said in the last uh episode or two we have a lot of material that is available now as short videos a short learning nuggets on now learning okay especially around data anonymization that we talked about Secrets management and so a lot of these features that are released as part of Tokyo and the earlier ones as well those practices are there there is customer success Center where is there is a detailed Playbook on data governance we would want everybody to look nice even though it is customer facing but every developer and the other folks such as business process Consultants so the teams that are working on service now project they should look at it and then we have sort of snow dogs for latest and the best light source for information that's where I just went while we were recording I went and looked at field normalization and transformation it's like yep still there that's the page I looked at so and make sure this is obvious but make sure you use it looking at the page related to the release you're on it never hurts to look ahead and say well what we talked about what's new in Tokyo so you might want to explore that there may be things in the release that you're on that weren't available in the previous release or that are coming so just a general awareness about that you can find all that on our doc site as well I love the fact that we've got that those Snippets I'm now learning too I was not aware of those thank you once again castori and Samir for all this wonderful information I can't tell you how passionate I am about getting data right again if you don't get the data right nothing else really works I think this is this is one of those garbage in garbage out metaphors or or if you want to think about it there's another one that is very common that data leads to information information leads to knowledge wisdom that's it that's it it's like a triangle thing you know data leads to information information and knowledge knowledge to wisdom and you want to be at the top of that pyramid with the wisdom if you don't get that Foundation of data right it doesn't work it's it just doesn't thank you very much can you let the listeners know how they can get in touch with you yes we have we can share the LinkedIn IDs we are always available and it's the same name that we have it's called perfect and Sami like exactly kasturi said uh it's Sumit Pandey on LinkedIn I will put links to those as well in the show notes so you don't even have to learn to spell them like I did listener for joining us today don't forget check out all the other servicenow podcasts you can find them at servicenow.com Community under the events menu and be sure to subscribe to this podcast for absolutely free you can use whatever favorite podcaster you've got you can find it on any of the directories the popular directory Spotify Google Amazon Apple you get the idea have that automatically delivered to you so you never miss another one in the future breakpoint is brought to you by servicenow executive producer will that be me tomasi video and captions are provided by Earl Duque and to find out more about the servicenow developer program please I invite you to head over to developer.servicenow.com again thank you kasori and Samir for sharing with us today great stuff thank you thank you so much so much chuck thanks for this opportunity we're glad to be here please let us know what you think about this podcast you can leave feedback or ask questions in the servicenow community for more great information on servicenow development check out the servicenow developer portal at developer.servicenow.com thanks for listening and I lost my cursor so I'm trying to find it I have to pay better attention to these words okay I was listening so let me just reiterate we have updates to the CD can't say it but I've got it right in front of me you know I should just learn to stick the words are right there why don't I just read them just stick with the script Charles I don't know what's wrong with my brain today I think I had too much Thanksgiving dinner last night maybe maybe a little too much wine I don't know my brain is not working this morning

View original source

https://www.youtube.com/watch?v=9aCRJoG7t3k