Application Security
7/2/2013
11:15 AM
Connect Directly
LinkedIn
Google+
Twitter
RSS
E-Mail
50%
50%

University Of San Francisco Puts ServiceNow Apps To Work

ServiceNow's new app builder tool helps nonprogrammer cobble together solid tracking apps for everyone from campus police to university fundraisers.

10 Job Search Tools For Recent Grads
10 Job Search Tools For Recent Grads
(click image for slideshow)
Jim Uomini doesn't consider himself a programmer, but at the University of San Francisco he is often the one who can whip up an app quickly for use by everyone from the campus police to university fundraisers.

Uomini, who serves as USF's service level manager, has become adept at stretching the limits of ServiceNow's cloud software, which is best known as a platform for IT service management and help desk functions. This reflects a trend that ServiceNow has been encouraging with the latest release of its platform, which enhanced mobile support and introduced an app builder to turn users of the platform into all-purpose problem solvers.

"I'm not a particularly technical person," Uomini said. "My background is journalism, and I came up through the help desk world, so I'm not a coder per se." The reason he can get things done anyway is that the core features of the ServiceNow platform -- for recording a problem or request as an open issue, tracking the follow-up on that issue, and eventually marking it resolved -- can be applied to a variety of business processes beyond IT functions.

[ Put students to work: How To Close Gaps In Campus Apps.]

One of the things that attracted USF to ServiceNow in the first place was its support for form customization with HTML and JavaScript, Uomini said. His strategy is to "beg and borrow scripts" other ServiceNow users have shared and tweak them for his needs. "If you're good at networking -- in the human sense -- you can pick up a lot of things," he said.

Business processes can also be modeled in a flowchart-style visual workflow tool, providing additional opportunities for automation, Uomini said. When presented with an application challenge, "The answer is almost never 'You cannot do it'" in ServiceNow, he said. "It's good for most any app where there's information coming in, with some sort of a ticketing process where that information is looked at and scored, a service is provided, and a response is provided," he said. As a bonus, every app built in this way can take advantage of the platform's metrics tracking for reports on the quality of service provided, he said.

The ServiceNow apps are not necessarily sexy, but they're functional, and support for devices like the iPad is actually making them a bit sexier, he said.

As a result, the university program-management office now steers a significant fraction of the requests it gets for data tracking apps to Uomini. When he created an app for tracking fundraising requests for the development office, "I got it because their request for a more expensive system was turned down. They came to me because I was more or less free," he said, meaning they only needed to cover the cost of additional ServiceNow licenses. "I was kind of a Plan B."

In another instance, the campus police were trying to use a generic ServiceNow incident response app to handle tasks related to building security, but it wasn't really meeting their needs, Uomini said. "They were dealing with things like alarms and door access cards -- nothing IT-specific, but they had their own hardware, their own requests -- things like, 'I need this vendor to have door access to this building from this date to this date.'"

Uomini was able to create something more specific to their requirements. In that case and many others, the need for a better solution probably wouldn't have been met at all if he hadn't been able to provide it, he said.

In other cases, he has addressed tasks with even less related to technology, such as issuing transit passes to students or rating budget requests.

The university selected ServiceNow in 2008 as a replacement for BMC's Remedy. A case study on the ServiceNow website gives more detail on the reasons for the switch and the speed of implementation -- accomplishing what was planned as an 18-month transition in just three months.

Follow David F. Carr at @davidfcarr or Google+, along with @IWKEducation.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
David F. Carr
50%
50%
David F. Carr,
User Rank: Apprentice
7/2/2013 | 6:23:25 PM
re: University Of San Francisco Puts ServiceNow Apps To Work
Are you thinking of Salesforce in terms of the apps that could be built on their cloud platform?
lacertosus
50%
50%
lacertosus,
User Rank: Apprentice
7/2/2013 | 5:26:58 PM
re: University Of San Francisco Puts ServiceNow Apps To Work
Strange that USF has opted to go with ServiceNow instead of Salesforce.com which is a much superior product. They are also they're neighbors which to me warrants some kind of an advantage over other vendors.

Salesforce.com offers a complete package including CRM, support, marketing, etc where SN is a help desk type application.
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
DevOps’ Impact on Application Security
DevOps’ Impact on Application Security
Managing the interdependency between software and infrastructure is a thorny challenge. Often, it’s a “developers are from Mars, systems engineers are from Venus” situation.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4594
Published: 2014-10-25
The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment.

CVE-2014-0476
Published: 2014-10-25
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.

CVE-2014-1927
Published: 2014-10-25
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928....

CVE-2014-1928
Published: 2014-10-25
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulner...

CVE-2014-1929
Published: 2014-10-25
python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to have an unspecified impact via vectors related to "option injection through positional arguments." NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.