smart lean government nascio direction, state … · 29/04/2014  · project and portfolio...

48
SMART LEAN GOVERNMENT NASCIO Direction, State Experiences and Federated Identity Management April 29, 2014 Eric Sweden, Program Director, Enterprise Architecture & Governance

Upload: others

Post on 13-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

SMART LEAN GOVERNMENT NASCIO

Direction, State Experiences and Federated Identity Management

April 29, 2014

Eric Sweden, Program Director, Enterprise Architecture & Governance

Page 2: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Overview

• Enterprise . . . . Federation . . . . Ecosystem

• Cross-Jurisdictional Joining Up

• Enablers – Identity Management – Smart Lean

• Rationalize – Optimize – Simplify

Page 3: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Source: NASCIO State CIO Survey, November 2013

1. Security

2. Consolidation / Optimization

3. Cloud Services

4. Project and Portfolio Management

5. Strategic IT Planning

6. Budget and Cost Control

7. Mobile Services / Mobility

8. Shared Services

9. Interoperable Nationwide Public Safety

Broadband Network (FirstNet)

10.Health Care

A. Priority Strategies, Management Processes

and Solutions

Move

First

Page 4: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Source: NASCIO State CIO Survey, November 2013

Security:

• risk assessment, governance, budget and resource

requirements, security frameworks, data protection,

training and awareness, insider threats, third party

security practices as outsourcing increases, determining

what constitutes “due care” or “reasonable”

A. Priority Strategies, Management Processes

and Solutions

Page 5: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Source: NASCIO State CIO Survey, November 2013

Project and Portfolio Management:

project management discipline,

enterprise portfolio management (EPM), oversight,

portfolio review, IT Investment Management (ITIM),

training/certification of staff, traceability to mission and

strategy, scope management, execution

A. Priority Strategies, Management Processes

and Solutions

Page 6: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Source: NASCIO State CIO Survey, November 2013

Project and Portfolio Management:

project management discipline,

enterprise portfolio management (EPM),

oversight, portfolio review,

IT Investment Management (ITIM), training/certification of staff, traceability to mission and

strategy, scope management, execution

A. Priority Strategies, Management Processes

and Solutions

Page 7: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Source: NASCIO State CIO Survey, November 2013

Page 8: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

IT Project and Portfolio Management

• Widely implemented but generally not effective

• Need enterprise-wide governance

• Good at monitoring ongoing projects

• Ineffective in driving IT investment

Page 9: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

IT Project and Portfolio Management

Page 10: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

IT Project and Portfolio Management

Page 11: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

IT Project and Portfolio Management

37% of State CIOs -

Portfolio Management Practices are Effective

• Statewide Standards for Business Cases

• Stronger Executive-Level Engagement

• Strong Enterprise-wide Oversight Role by CIO

Keys to Effective IT Investment Management

Page 12: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

NASCIO on Enterprise Portfolio Management

Page 13: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Enterprise Architecture - the path to Government Transformation

State CIO Challenge – Balancing Needs and Resources

Page 14: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Portfolios

Policies

Obligations

Mandates

Populations

Technologies

Best Practices

Lines of Business

Special Interests

Roles

Constituents

Risks

Opportunities

Many “Portfolios”

Page 15: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Enterprise Architecture - the path to Government Transformation

Observe

the

Contextual

Environment

Fiscal Circumstances

Macroeconomics

Customer Expectations

Customer Behavior

Regulations

New Technology

Competition

Mandate

Observe

the

Need

or

Opportunity

(Market)

SWOT Analysis

Risks Analysis

Assumptions

Policies

Stakeholders

Supply / Demand

Economics

Access

Enable

Strategic

Business

Intent

Business

Relationships

Processes

Information

Organizations

Value Chains

Management

Initiatives

Analytics / Six Sigma

Balanced Scorecard

Geospatial Capabilities

Records Management

Security

Capabilities

Determine

Strategic

Business

Intent

Mission

Vision

Goals

Objectives

Strategies

Performance

Decisions

Enterprise Architecture Value Chain

Page 16: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Enterprise Architecture - the path to Government Transformation

Issues Portfolio

Page 17: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Enterprise Architecture - the path to Government Transformation

Issues Portfolio

Observe

the

Contextual

Environment

Fiscal Circumstances

Macroeconomics

Customer Expectations

Customer Behavior

Regulations

New Technology

Competition

Mandate

Surfaces

Business

Needs

Environmental

Natural Resources

Public Health

Public Safety

Defense

Education

Economics

Page 18: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Enterprise Architecture - the path to Government Transformation

Public Health

Health Equity Primary Care

Workforce

Adequacy &

Capacity of

Governmental

Health

Infrastructure

Substance

Abuse

Pandemic /

Emergency

Preparedness

Health Quality Health

Information

Exchange

Public Health Portfolio

Page 19: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Enterprise Architecture - the path to Government Transformation

Public Safety Portfolio

Public Safety

Protecting &

Supporting

Victims of

Crime

Human

Trafficking

Recidivism Substance Abuse Pandemic /

Emergency

Preparedness

Securing Borders Crime

Prevention

Substance abuse – what is happening here?

Page 20: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Economics

Public Safety

Education

Public Health

Inter-related Public Sector Spheres

Page 22: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Evaluation

Prioritization

Business

Need Business

Need Business

Need Business

Need Business

Need Business

Need

Requirements Requirements

Requirements Requirements

NASCIO EA Value Chain Expanded

Page 23: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

IT Procurement

• Widespread adoption of reforms is slow

• Two Major Focus Areas for this survey

• contract terms & conditions

• the procurement process

Page 24: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

IT Procurement Challenges

• Lengthy process

• Risk averse nature inhibits innovation

• Identify and mitigate all perceived risks

• Equitable sharing of risk

Page 25: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

IT Procurement Recommendations

• Recommendations

• Establish a reasonable cap on vendor

financial exposure

• Adopt “license” rather than “acquisition”

• Limit indemnification obligations to

tangible losses

• injury

• death

• damage

Page 26: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

IT Procurement

How would you rate the effectiveness of your IT procurement

process?

Page 27: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

IT Procurement

Page 28: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cybersecurity

• Most states have adopted continuous

vulnerability testing

• Challenges

• documenting program effectiveness

• developing cybersecurity disruption

response plans

Page 29: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cybersecurity Threats

• Require formal strategy

• Adequate resources

• Constant vigilance

Page 30: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cybersecurity Threats

Page 31: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Identity and Access Management

• Half of the states have an IAM model

implemented or under way

• Some states are extended their IAM model

to include citizens

Who are you?

Can you prove it?

Page 32: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Identity and Access Management

Page 33: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Identity and Access Management

Page 34: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

9. For identity and access management, how would you

classify your state’s progress? (State Government only)

11%

23%

40%

26%A. My state has an enterprise approach to identify and access

management.

B. My state has a siloed and incompatible identity management

systems, but we want to move to an enterprise approach.

C. There have been discussions on identity management systems,

but little progress has been made

D. It’s just not a priority at this time

Page 35: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cross Jurisdictional Collaboration

• Most states include on strategic agenda

• Challenges

• governance

• turf

Page 36: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cross Jurisdictional Collaboration

Page 37: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cross Jurisdictional Collaboration

Types of services states are providing – particularly to

local government

Page 38: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cross Jurisdictional Collaboration

Page 39: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cybersecurity

Cybersecurity continues to be one of the most pressing

challenges facing State Chief Information Officers (CIOs)

and Chief Information Security Officers (CISOs) today.

Security threats to states have been widely reported,

however the nature of the game has changed.

Cybercriminals and hacktivists — a new breed of hacker

with a political or social agenda — use increasingly

sophisticated methods involving rapidly evolving

technologies to target cyber infrastructure for monetary

gain and to make political statements.

Page 40: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cybersecurity

Page 41: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cybersecurity

Page 42: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Cybersecurity

Page 43: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

10. Which security risk concerns you the most?

(State Government only)

59%

9%

11%

15%

7% A. End-user downloads of non-approved apps

B. Insider threats

C. Email – malware and phishing

D. Mobile devices and BYOD

E. Sophisticated, pre-meditated attacks by hackers

Page 44: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Identity and Access Management

Page 45: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Scaling Interoperable

Trust through a

Trustmark Marketplace

John Wandelt

[email protected]

Georgia Tech Research Institute

October 2013

Page 46: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Advancing Government through Collaboration, Education and Action

Smart Lean Government (SLG)

21st Century Collaborative Solutions

Serving Customers

More Responsively, Quickly, Efficiently

April 29, 2014

Presented by:

Eric Sweden

NASCIO

Page 47: SMART LEAN GOVERNMENT NASCIO Direction, State … · 29/04/2014  · Project and Portfolio Management: project management discipline, enterprise portfolio management (EPM), oversight,

Resources

• Cyberspace Law: Identity Management Legal Task Force

https://apps.americanbar.org/dch/committee.cfm?com=CL320041

• CyberSecurity Newsbriefs

http://www.infoinc.com/NASCIO_CyberSecurity/mailinglist.cfm?FORMID=1&SERVICEID=466

• EA Newsbriefs

http://www.infoinc.com/NASCIO_EnterpriseArchitecture/mailinglist.cfm?FORMID=1&SERVICEID=487

• The Heart of the Matter: A Core Services Taxonomy for State IT Security Programs

October 2011 www.nascio.org/publications