Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

7/2/2013
11:15 AM
Connect Directly
LinkedIn
Google+
Twitter
RSS
E-Mail
50%
50%

University Of San Francisco Puts ServiceNow Apps To Work

ServiceNow's new app builder tool helps nonprogrammer cobble together solid tracking apps for everyone from campus police to university fundraisers.

10 Job Search Tools For Recent Grads
10 Job Search Tools For Recent Grads
(click image for slideshow)
Jim Uomini doesn't consider himself a programmer, but at the University of San Francisco he is often the one who can whip up an app quickly for use by everyone from the campus police to university fundraisers.

Uomini, who serves as USF's service level manager, has become adept at stretching the limits of ServiceNow's cloud software, which is best known as a platform for IT service management and help desk functions. This reflects a trend that ServiceNow has been encouraging with the latest release of its platform, which enhanced mobile support and introduced an app builder to turn users of the platform into all-purpose problem solvers.

"I'm not a particularly technical person," Uomini said. "My background is journalism, and I came up through the help desk world, so I'm not a coder per se." The reason he can get things done anyway is that the core features of the ServiceNow platform -- for recording a problem or request as an open issue, tracking the follow-up on that issue, and eventually marking it resolved -- can be applied to a variety of business processes beyond IT functions.

[ Put students to work: How To Close Gaps In Campus Apps.]

One of the things that attracted USF to ServiceNow in the first place was its support for form customization with HTML and JavaScript, Uomini said. His strategy is to "beg and borrow scripts" other ServiceNow users have shared and tweak them for his needs. "If you're good at networking -- in the human sense -- you can pick up a lot of things," he said.

Business processes can also be modeled in a flowchart-style visual workflow tool, providing additional opportunities for automation, Uomini said. When presented with an application challenge, "The answer is almost never 'You cannot do it'" in ServiceNow, he said. "It's good for most any app where there's information coming in, with some sort of a ticketing process where that information is looked at and scored, a service is provided, and a response is provided," he said. As a bonus, every app built in this way can take advantage of the platform's metrics tracking for reports on the quality of service provided, he said.

The ServiceNow apps are not necessarily sexy, but they're functional, and support for devices like the iPad is actually making them a bit sexier, he said.

As a result, the university program-management office now steers a significant fraction of the requests it gets for data tracking apps to Uomini. When he created an app for tracking fundraising requests for the development office, "I got it because their request for a more expensive system was turned down. They came to me because I was more or less free," he said, meaning they only needed to cover the cost of additional ServiceNow licenses. "I was kind of a Plan B."

In another instance, the campus police were trying to use a generic ServiceNow incident response app to handle tasks related to building security, but it wasn't really meeting their needs, Uomini said. "They were dealing with things like alarms and door access cards -- nothing IT-specific, but they had their own hardware, their own requests -- things like, 'I need this vendor to have door access to this building from this date to this date.'"

Uomini was able to create something more specific to their requirements. In that case and many others, the need for a better solution probably wouldn't have been met at all if he hadn't been able to provide it, he said.

In other cases, he has addressed tasks with even less related to technology, such as issuing transit passes to students or rating budget requests.

The university selected ServiceNow in 2008 as a replacement for BMC's Remedy. A case study on the ServiceNow website gives more detail on the reasons for the switch and the speed of implementation -- accomplishing what was planned as an 18-month transition in just three months.

Follow David F. Carr at @davidfcarr or Google+, along with @IWKEducation.

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
David F. Carr
50%
50%
David F. Carr,
User Rank: Apprentice
7/2/2013 | 6:23:25 PM
re: University Of San Francisco Puts ServiceNow Apps To Work
Are you thinking of Salesforce in terms of the apps that could be built on their cloud platform?
lacertosus
50%
50%
lacertosus,
User Rank: Apprentice
7/2/2013 | 5:26:58 PM
re: University Of San Francisco Puts ServiceNow Apps To Work
Strange that USF has opted to go with ServiceNow instead of Salesforce.com which is a much superior product. They are also they're neighbors which to me warrants some kind of an advantage over other vendors.

Salesforce.com offers a complete package including CRM, support, marketing, etc where SN is a help desk type application.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15037
PUBLISHED: 2020-07-07
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Reports-Devices.php page st[] parameter.
CVE-2019-4323
PUBLISHED: 2020-07-07
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
CVE-2019-4324
PUBLISHED: 2020-07-07
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
CVE-2020-15036
PUBLISHED: 2020-07-07
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Linked.php dv parameter.
CVE-2020-15577
PUBLISHED: 2020-07-07
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Cameralyzer allows attackers to write files to the SD card. The Samsung ID is SVE-2020-16830 (July 2020).