About Sean Mullen
Sean Mullen, Chief Growth Officer at Lumentum Holdings, participated in a 2023 Senate Environment Committee hearing where he questioned a witness who advocated for ending plastic manufacturing. Mullen argued that modern manufacturing, including automotive production, depends on plastics and that eliminating the industry would harm economic mobility and disproportionately affect low-income communities. He cited the example of Nissan’s plant in Smyrna, Tennessee, as a case where industrial growth lifted a community out of poverty, and stated that poverty itself causes worse health outcomes and trauma.
In a 2012 interview, Mullen discussed his role as chair of The Open Group Security Forum while at IBM. He outlined plans to expand security standards into cloud and virtualization, and noted the approval of the ARMOR specification for role-based access control across Unix systems. Mullen also described work on the Automatic Compliance Expert Markup Language (OSML) to automate compliance with regulations like SOX and PCI, and efforts to integrate security initiatives into the next version of the TOGAF enterprise architecture framework.
Source: AI-verified profile updated from Sean Mullen's recent appearances.
Browse all interviews →
Transcript (12 segments)
J
Jim Hietala0:03
Hi I'm Jim Hietala, I'm VP of Security with The Open Group. I'm here with Sean Mullen. Sean's from IBM, he's a security architect, and Sean you were recently elected the chair of the Security Forum. Can you tell us about your plans for the Forum?
S
Sean Mullen0:18
Yeah, the Forum has been run quite well for a number of years. I want to carry that on. I also want to expand in some new areas of security, especially with cloud security, virtualization. There's a lot of areas, especially in the virtualization layer, that we can have standards. Four or five years ago we would be saying it's safe to go to the cloud, safe to go to a virtualization model, but now with the technology we're putting in the virtualization, we can bring security technology and features that weren't possible in the old monolithic computer systems. The problem is those security technologies have gone into the virtualization layer but there's no standards around it, so it's difficult to manage. The security technology is great but the burden of managing those security technologies is high. If we have standards on those, then we can create management that's homogenized across all the different virtualization platforms. Now we've got a good autonomic security solution that covers it from the virtualization layer up through the OS and applications, and that's one of the directions I want to take the Forum.
J
Jim Hietala1:36
Okay, I want to ask you about some of the current projects the Forum is working on. But before I do that, I thought it'd be interesting to ask you because you've been a member and now you're the chair, what's the time involvement been for you in terms of being involved in the Security Forum? What's that experience been like?
S
Sean Mullen1:53
There is a time commitment depending on your level of involvement, but there's a return on that also. When I'm doing my day job, architecting security products, I've been able to stay laser focused on the technologies I need to bring to market, but my aperture and understanding is much broader across the enterprise. I think those rewards have come back, they've been reflected in the products that we've released. PowerSC is an example that looks at dependable, simple, return on investment across the enterprise. It's not these little siloed security features; it's much broader than that. That's what The Open Group has returned to me for my investment of time driving these standards and participating in these conversations.
J
Jim Hietala2:46
Okay, so I wanted to ask you, I know that building security into the next version of TOGAF is a big project for the Security Forum. Can you talk a little bit about that effort, sort of where that's come from and where you think that's going?
S
Sean Mullen3:01
That's been a great opportunity for us to take some of the initiatives that we've had within the Security Forum, like the Risk Management Taxonomy, and bringing that and inserting that into the next TOGAF. This is important because all of these different disciplines stay focused and drive in their direction and that's good, but this gives us the opportunity to merge the two and have a stronger TOGAF Next with the latest and best security technologies that we've been developing on our side.
J
Jim Hietala3:38
So Sean, the ARMOR specification was approved as a Technical Standard from The Open Group this week. Something the Security Forum worked on. Can you tell us a little bit about that?
S
Sean Mullen3:47
This has been a real success. This is something where the major Unixes got together: HP-UX, Solaris, Linux represented there, and of course AIX. It was a problem with RBAC, role based access control. We all had our RBAC versions, they were very similar but there was a management issue. So we were able to come out with some basic roles and define those. One of the rewarding experiences is working with our competitors, especially HP-UX and Solaris, really understanding their technology but coming together for a common solution that benefits all of our customers. You go into almost any large enterprise, they're going to have a variety of Unixes and Linux, and this helps them manage it in a similar manner.
J
Jim Hietala4:37
Okay, so another standard that I know we produced recently that you were involved in is OSML. Can you tell us kind of the business problems that that standard addresses and kind of the experience of working on that in The Open Group?
S
Sean Mullen4:51
Yeah, that was one of the first standards I worked on. OSML is the Open Group Automatic Compliance Expert Markup Language. It's mainly about authoring compliance in an XML form. Every time my left foot hits the ground there's a new regulatory compliance out there with their own definition of how to configure systems, how to do security. OSML allows them at a very high level to say, for example, 'I want my password length 8'. They don't have to understand the technology underneath the device. It could be a mobile device, it could be an AIX system, it could be a network device. When that XML is pushed down to that device, it's the one that is OSML aware and it knows how to interpret that into an actionable command. It writes that actionable command back into the XML and then executes the command to configure it and puts the result back in the XML. So now the XML file is actually all of your artifacts for reporting that the device is indeed compliant. It also has remediation. Many of our customers have to be SOX compliant, PCI compliant on the same device. This is a way to blend those two and remediate and have a compliance that's automatically authored to meet both compliances. We'll be working with NIST later this week around SCAP to see how we can insert and merge OSML with SCAP. That work has been ongoing and we meet later this week.
J
Jim Hietala6:26
Okay, so last question for you. It sounds like there's a lot going on in the Security Forum. How can folks get involved with the Security Forum and The Open Group?
S
Sean Mullen6:36
The easiest way is probably just to go to the opengroup.org website. I would encourage everybody to do this because you'll have a broader view of what it is to be a security architect. It'll help you grow personally in your career. Additionally, it'll help your products that you're developing or whatever you're doing in your organization. It'll give you a better understanding of the different areas that you need to do for your job. Basically, you come to The Open Group, you find out what benefits you and your job, and that's the forum you insert yourself in and become active. Additionally, you start looking at the other forums and again that broadens your aperture and understanding of enterprise architecture, security, real-time embedded systems. It's all here.