Assessment of Software for Government
|
|
|
- Nancy Harrell
- 10 years ago
- Views:
Transcription
1 Version 1.0, April 2012 Aim 1. This document presents an assessment model for selecting software, including open source software, for use across Government, and the wider UK public sector. 2. It is presented in recognition that potentially better value for money software, including open source software, is underused across Government and the wider public sector. It aims to address the lack of a consistent approach to the selection of software across Government, and to improve the transparency of these selection processes undertaken by Government or suppliers to Government. 3. In particular, it aims to emphasise that open source software is considered against the same selection criteria as closed proprietary software, whilst also explaining how these same criteria can be evaluated in the context of the different open source development model and ecosystem. 4. This document does not aim to encourage only the selection of software which shows topmost indicators for each criterion, but instead the more appropriate matching of software characteristics with actual risk and requirements. It is important that risk and requirements are justifiable, as these can drive significant unnecessary cost. 5. This document also covers some characteristics of service providers and integrators, particularly with respect to open source software. The aim is help select service providers and integrators by making clear the capabilities and behaviours which can enable Government to derive value from open source software. Context 1. The Coalition Government believes open source software can potentially deliver significant short and long term cost savings across Government IT. This document is part of the Open Source Toolkit developed as an action of the UK Government ICT Strategy Typical benefits of open source software include lower procurement prices, no license costs, interoperability, easier integration and customisation, compliance with open technology and data standards enabling autonomy over your own information and freedom from vendor lock in. 3. Open source software is not currently widely used in Government IT, and the leading systems integrators for Government Departments do not routinely consider open source software for IT solution options, as required by existing HMG ICT policy.
2 4. There are significant and wide ranging obstacles to open source software in Government. Some of these are a lack of clear procurement guidance, resistance from suppliers, concerns about license obligations and patent issues, misunderstanding of the security accreditation process, and myths around open source quality, its development and support ecosystem. How To Use 1. This document presents criteria for assessing the suitability of software for a particular business requirement. It extends previous work by explaining how these criteria can be evaluated in the context of open source software, its development model and ecosystem. It also clarifies criteria which should not be used to assess the suitability of software. 2. The primary audiences for this assessment model are technical and enterprise architects, commercial / procurement officers and project managers within the civil service, and those from the supplier and integrator community who influence the design and makeup of ICT solutions to Government. Customers and suppliers in the wider public sector are also encouraged to make use of this document. 3. This set of assessment criteria can be used to: a. Inform the design of new IT solutions. b. Suggest opportunities for IT service or solution refreshes. c. Challenge a proposed solution that does not use open source technology. 4. Software under consideration does not need to conform to the topmost positive indicators listed for all criteria. This assessment model will help Government challenge themselves, and suppliers, that potentially better value for money software has sufficient positive characteristics to meet justifiable business requirements and risk position. It is not expected to be used to argue for more expensive IT solutions. For each criterion, the reader is encouraged to ask What level of indicator is really required? Is the requirement justifiable? 5. This document does not remove existing requirements for due diligence and assurance on the part of Government. In particular it does not transfer any technology risk from IT integrators and suppliers to Government, where it has previously been contractually placed with those suppliers and integrators. It also does not supersede any government standards for security and accreditation. 6. This document should be used in conjunction with the wider Open Source Toolkit published via the Cabinet Office website. Government, public sector, existing and potentially new suppliers are encouraged to engage the open source surgery process to discuss queries or issues, via [email protected]. 7. This model for software selection has been developed in consultation with the SI Forum, a cross government board established as an action of the UK Government ICT Strategy Its members include Atos, BT, Fujitsu, HP, IBM, Logica, Serco, Sirius and Steria. It is not expected that this assessment model conflicts with, or deviates significantly from, their internal assessment processes. 2
3 Feedback & Suggestions Please provide feedback and suggestions to 3
4 Overview of Software Selection 4
5 Principles for Software Selection The following key principles are highlighted to address current known barriers to the use of better value software, including open source software. Value & Cost the value and cost of software is realised beyond its initial deployment, particularly through dependencies on other systems. Refer to the London School of Economics report and the guide to software total cost of ownership, both published as part of the Open Source Toolkit. In particular, the practice of comparing the only purchase cost of software is deficient, and risks being subject to artificial manipulation of up front pricing. It also omits potentially critical in-life change, and end of life exit and migration costs. Risk - Software and the services supporting it should be selected to meet actual and justifiable business risk, and no more. Overestimating risk can significantly drive up unnecessary costs. Risk should be unbundled to better match different kinds of software sourcing to optimise for value. Requirements Challenge and Commodity Business requirements should be challenged if their adjustment can lead to better value from different software solutions. Furthermore, the greater the divergence of business requirements from the wider market, the more bespoke IT solutions become, which drives cost. Commodity IT means commodity requirements, commodity technology, and also the commodity use if that technology. Technical Refresh It is expected that software options are evaluated not only for new builds, but also at technology refresh points. Technology refresh triggers should not only be used to upgrade existing software to more current versions. Reuse and Diversity It is a common strategy of government departments to reuse software and reduce technology duplication and diversity. However this strategy must be applied to optimise value. This means not reusing or extending technology which is not aligned to the ICT Strategy or a desired future architectural state. It also means that multiple software for similar functions may be more optimal if sufficient use cases do not require the more expensive software. For example, it can be better value for a licence-free open source application server used for almost all such departmental functions, with an expensively licensed application server for the very few exceptional requirements. Security Open source software is no more or less secure, as a category of software, than closed proprietary software. CESG GPG 38 discusses this and related issues around the evaluation of risk for software including open source software. This means open source software cannot be excluded from an options analysis on the premise that it is less secure than closed proprietary software. It is a misunderstanding of the accreditation process to assert that some software is pre-accredited. For further discussion see CESG GPG 38 and the associated security note published with the Toolkit. Brand Recognition & Innovation Brand recognition on its own must not be used to justify the procurement of any software. 5
6 Assessment of Software for Government Criterion High Intermediate Low Proven There are many real world examples of the software in use. There are some real world examples of the software in use. There are no real world examples of the software in use. There are existing uses of the software in Government. The software, though in use, has not been used in Government or the wider public sector. There are only insignificant uses of the software. The software has proven significant use with respect to some or all of: o performance The software has proven moderate use with respect to performance, scale or criticality. The software has not been demonstrated in the real world under any significant use with respect to performance, scale or critical function. o o large scale critical function (eg safety, security) The software has been successfully used over a long term with respect to ICT product cycles. The software has been successfully used over a medium term with respect to ICT product cycles. The software is new and has not been proven over any significant time to ascertain its operating characteristics. Publicly available performance and scaling benchmarks, including repeatable test configuration are available, with results publicly shareable for analysis. Software supplier publishes performance and scaling indicators, but these are not publicly repeatable, due to insufficient test configuration detail, for example. No performance or scaling data available. Services & Support Support exists at several levels, including for mission critical services if needed. Software is supported but not for mission critical services. For open source, community support can be sufficient. No support arrangement. 6
7 Support has been proven over a number of years. Support is new and has not been proven over a number of years. No support. Support has been proven over a range of sectors, including demanding sectors such as finance and Government. Support has only been proven over a limited range of sectors. Software support includes bug fix and code change capability, as well as configuration support. Support capability only covers configuration support. No support. Support supplier is, or has productive links to, the software developers, or development community. Support supplier is not the software developer, nor has productive links to those developers, or development community. No support. Security Changes to software are strictly assessed, audited and controlled through mature governance. This applies to commercial software organisations as well as community development. Changes to the software are limited to selected developers who have proven their ability to maintain software quality. These trusted developers have write / commit access to the code repository. Changes to the software are subject to minimal, or no, assessment and governance. Third party assurance covers change control and governance, not just testing the resultant software. Ad hoc contributions to the software are channelled through these selected developers for assessment and approval. Software is subject to regular security and penetration testing undertaken by the developer. Outcomes drive security fixes. Software is regularly security tested by third parties. No software security testing. Software is security / penetration tested and assured by an independent and trusted third party. The software supplier is fully open and The software supplier selectively The supplier does not discuss 7
8 transparent about publicising known vulnerabilities and exploits. Impact assessment of vulnerabilities and exploits is issued. All known vulnerabilities are acknowledged by the supplier. publicises vulnerabilities and exploits. The supplier does not acknowledge all known vulnerabilities. vulnerabilities or exploits. The supplier does not acknowledge vulnerabilities discovered by the wider community. The time to fix vulnerabilities is minimal and timely, minimising exposure to exploits. All known vulnerabilities are fixed. The time to fix is moderately timely. Not all known vulnerabilities are fixed. Time to fix is long, or no fix is issued. No management of vulnerabilities and fixes. Design and architecture decisions taken to support software security. For example, use of minimal privilege, privilege isolation, and defence in depth across development, and approaches such as static code analysis. Normal software design and development practices with no design or architectural decisions to support software security. No software design and development discipline. For security enforcing products, the software has received an appropriate certification of assurance, for example from CESG. This only applies to a limited set of software functions such as firewalls, virtualisation, VPN and encryption software. n/a No assurance of security enforcing function. Software Development Software development is well managed and governed. Software development is open to user contributions or feature suggestions, but these are assessed and only enter the code in a well managed and governed manner. Software development is loosely managed, with change control but minimal coherent direction or quality criteria. Software development is arbitrarily open to contributions from the user community but there is no formal assessment or governance around this. Software development is undisciplined, not following any process or governance. Software development is not open to public contribution. 8
9 Software issues and bugs are managed by a bug tracking and resolution system that is transparent and has public visibility. Software issues and bugs are managed internally, with no public visibility. There is no coherent approach to tracking issues or bugs to resolution. Software development is fully auditable for code changes, their source, and the reason for change. Software development is change controlled but with limited auditability for code changes, their source, and the reason for change. Software development is not auditable. Software is fully documented and documentation is updated and available when required. Software is documented but updates sometimes lag behind software development. Documentation is available when required. Alternatively, software is sufficiently well written and commented to allow nonspecialist developers to understand its workings. Software is not documented or is documented in an ad-hoc manner. Software is not sufficiently well coded and commented to allow non-specialist developers to understand its workings. Software development broadly follows published roadmaps. It is recognised that roadmaps evolve. Software development, though well managed, does not intend to provide predictability into the medium to long term. Only short term or immediate changes are predictable. No predictable development direction or roadmaps. Legal Software is developed with full understanding and tracking of incorporated code from third parties, patents and inherited license obligations. Documented clarity around compatibility of licenses for constituent software (in-licences) and compatibility with licence of resultant product (out-licence). Software is developed and documented in a fairly well controlled manner to provide confidence, but not guarantees, with respect to incorporated code from third parties, patents and inherited license obligations. Software is developed with no understanding of incorporated code from third parties, patents and inherited license obligations. 9
10 Liability & Indemnity Customer is shielded, or indemnified, from legal action related to patents, licenses or other issues by the software support vendor or the integrator. This can be done directly from the software developer, or indirectly through third party insurance. Software has a track record of no significant legal challenges. The open source software has successfully defended against legal action, with respect to copyright, patents or other issues, in a comparable jurisdiction, thus setting a legal precedent. Customer has to undertake its own due diligence for legal liability around open source software, because it cannot be obtained from the software support vendor or the integrator. In the event of legal action, it must defend itself. The software is subject to ongoing but as yet unresolved legal action, or is the subject of negative commentary from commercial rivals. Note that this can be common in the software sector, with legal action and commentary sometimes used for competitive advantage and to influence customer behaviour. Customer cannot obtain any assurances around legal liability for the open source software in question. The open source software has failed in defending against legal action, with respect to copyright, patents or other issues, in a comparable jurisdiction. Terms of Use, License or Contract Software terms allow use for primary requirement, and also for varying requirements or use cases. Software terms only allow use for specific requirement. Use for varying requirements is not permitted. Software terms forbid use for, or are incompatible with, primary requirement. Software terms allow subsequent reuse across Government, including for varying requirements. Software terms do not allow reuse across Government. Software terms allow use across any sector, for any requirement, as per many open source licenses. Note open source licenses are generally terms of use, not units of sale for payment. Software terms places no onerous obligations on customers, subsequent to its use. Most open source licenses, including the GPL, MIT, Apache and BSD licenses are not onerous for expected Government use cases. Software license places some obligations or constraints on customers, subsequent to its use. Licenses which require the public release of sensitive code fall into this category. Most open source licenses do not require such release for expected Government use cases. Software license places onerous obligations on customers, subsequent to its use. This is rarely true for common open source software. For example, the rare Affero GPL variant requires making available the full source code for an application which is used over 10
11 a network, to those users. This is distinct from the more common GPL where only redistribution of the executable beyond an organisation s boundary triggers the need to share the source code. Costs Software does not impose costs by creating or enforcing dependencies to other software or technologies. Software imposes costs by creating or enforcing dependencies to other software or technologies. Extent of dependencies into infrastructure is moderate or limited. Software imposes costs by creating or enforcing dependencies to other software or technologies. Extent of dependencies into infrastructure is significant. Exit costs from software are known and minimal. In particular, business information (content, metadata, workflows, for example) can be fully exported to a neutral format ready for migration to a subsequent technology, with ease and at minimal cost. Exit costs from software are known but significant. Business information can be fully exported to a neutral format ready for migration to a subsequent technology, but this process is expensive and requires specialist and rare knowledge or skills, and therefore a risk in itself. Exit costs from software are able to be determined. There is no identifiable mechanism to export business information to a neutral format such that it can be migrated to a subsequent technology. Software s function is subject to realistic competition, ensuring software vendor is subject to competitive tension. Software s function is subject to minimal competition. Software vendor is subject only to mild competitive tension. Software s function is not subject to realistic competition, and software has effective monopoly, not subject to competitive tension. Software has a price history which suggests no unexpected future price rises. Software has a history of periodic price rises, which cannot be budgeted for presently, but which will have to be accommodated as and when they arise. n/a Strategic Alignment Software is aligned to the Government ICT Strategy and vision. This covers domains including commodity IT, competitive markets, accessibility to SME suppliers, open standards and interoperability, and value for money. n/a Software is in conflict with the Government ICT Strategy and vision. 11
12 Software is aligned to departmental enterprise architecture and technology roadmaps. n/a Software is in conflict with departmental enterprise architecture and technology roadmaps. 12
13 Suppliers and Integrators of Open Source Software for Government Criterion High Intermediate Low IT Integrator or Supplier Integrator understands the software development model, and its ecosystem, including for open source. Integrator only understands proprietary software ecosystem. Integrator understands open source software and its ecosystem only enough to make occasional use of software, primarily imitating other integrators. Integrator does not understand open source software and its ecosystem, and has no intention to use it strategically. Integrator s legal and commercial units understand open source software and are fully engaged with it business as usual. Integrator s legal and commercial units partially understand open source software and only engage with it tactically and by exception. Integrator s legal and commercial units do not understand or engage with open source software. Open source software plays a primary tier role in the integrator s strategic vision and approach to IT solutions and services. Integrator maintains permanent internal expertise for strategic open source software. Open source software does not play a primary tier role in the integrator s strategic vision and approach to IT solutions and services. It only plays a secondary role where it is used tactically or by exception. Integrator s internal expertise is incidental. Integrator buys in open source expertise on a temporary and case by case basis. Open source plays no part in the integrator s strategic vision or approach to IT solutions. Integrator has no internal expertise in open source software, and does not engage temporary expertise. Integrator has established channels to support and maintenance for open source software. Integrator also has partnerships with design and integration specialists for specific open source software. Integrator engages channels to support and maintenance for open source software on a case by case basis, and often by exception. Integrator only forms partnerships with design and integration specialists for specific open source software by Integrator has no channels to open source support and maintenance. Integrator has no partnerships with open source software specialists. 13
14 exception. Integrator has proven successful experience of open source software, over a wide range of solutions and services, including mission critical. Integrator has some proven successful experience of open source software, over a limited set of solution and service types. Integrator has no proven experience of open source software as part of its solutions and services. Integrator is capable of managing open source software which has been modified to better meet the customer s requirements. The modification is undertaken internally or through partnerships with 3 rd party specialists. Integrator does not manage modified open source software, only using well known releases from upstream support suppliers and developers. n/a Software developer, supplier and integrator are financially robust to the extent appropriate to the use of the software and associated business risk. Only the integrator is financially robust to the extent appropriate to the use of the software and associated business risk. The integrator will, in effect, cover for financial instability. Software developer, supplier and integrator are not financially robust to the extent appropriate to the use of the software and associated services. 14
Open Source System Integrator Forum
Open Source System Integrator Forum Bill McCluggage Deputy HM Government CIO & Director of ICT Strategy and Policy Qamar Yunus Government Open Source Lead Daniel Stacey Government Open Source Advisor 21
ICT Advice Note - Procurement of Open Source
ICT Advice Note - Procurement of Open Source October 2011 1. Objectives and Context The objective of this document is to provide high level advice on how to ensure open source software is fairly considered
End User Device Strategy: Design & Implementation
End User Device Strategy: Design & Implementation This document establishes the technology, commercial and security principles for designing infrastructure to implement the End User Device Strategy. Together
Informatics: The future. An organisational summary
Informatics: The future An organisational summary DH INFORMATION READER BOX Policy HR/Workforce Management Planning/Performance Clinical Document Purpose Commissioner Development Provider Development Improvement
Business Operations. Module Db. Capita s Combined Offer for Business & Enforcement Operations delivers many overarching benefits for TfL:
Module Db Technical Solution Capita s Combined Offer for Business & Enforcement Operations delivers many overarching benefits for TfL: Cost is reduced through greater economies of scale, removal of duplication
Open Source, Open Standards and Re Use: Government Action Plan
Open Source, Open Standards and Re Use: Government Action Plan Foreword When Sir Tim Berners Lee invented the World Wide Web in 1989, he fought to keep it free for everyone. Since then, not everyone in
COMESA Guidelines on Free and Open Source Software (FOSS)
COMESA Guidelines on Free and Open Source Software (FOSS) Introduction The COMESA Guidelines on Free and Open Source Software are a follow-up to the COMESA Regional FOSS Framework of 2009 whose main objective
Thales Service Definition for PSN Secure Email Gateway Service for Cloud Services
Thales Definition for PSN Secure Email Gateway Thales Definition for PSN Secure Email Gateway for Cloud s April 2014 Page 1 of 12 Thales Definition for PSN Secure Email Gateway CONTENT Page No. Introduction...
ehealth Architecture Principles
ehealth Architecture Principles Version 3.0 June 2009 Document Control Details Title: ehealth Architecture Principles Owner: Head of Architecture and Design, Scottish Government ehealth Directorate Version:
Mapping the Technical Dependencies of Information Assets
Mapping the Technical Dependencies of Information Assets This guidance relates to: Stage 1: Plan for action Stage 2: Define your digital continuity requirements Stage 3: Assess and manage risks to digital
THE BRITISH LIBRARY. Unlocking The Value. The British Library s Collection Metadata Strategy 2015-2018. Page 1 of 8
THE BRITISH LIBRARY Unlocking The Value The British Library s Collection Metadata Strategy 2015-2018 Page 1 of 8 Summary Our vision is that by 2020 the Library s collection metadata assets will be comprehensive,
ARCHITECTURE SERVICES. G-CLOUD SERVICE DEFINITION.
ARCHITECTURE SERVICES. G-CLOUD SERVICE DEFINITION. Table of contents 1 Introduction...3 2 Architecture Services...4 2.1 Enterprise Architecture Services...5 2.2 Solution Architecture Services...6 2.3 Service
ITIL Managing Digital Information Assets
ITIL Managing Digital Information Assets Shirley Lacy, ConnectSphere Frieda Midgley, Digital Continuity Project Judith Riley, Digital Continuity Project Nigel Williamson, Digital Continuity Project White
How To Use Open Source Software For Library Work
USE OF OPEN SOURCE SOFTWARE AT THE NATIONAL LIBRARY OF AUSTRALIA Reports on Special Subjects ABSTRACT The National Library of Australia has been a long-term user of open source software to support generic
National Approach to Information Assurance 2014-2017
Document Name File Name National Approach to Information Assurance 2014-2017 National Approach to Information Assurance v1.doc Author David Critchley, Dave Jamieson Authorisation PIAB and IMBA Signed version
Network Rail Infrastructure Projects Joint Relationship Management Plan
Network Rail Infrastructure Projects Joint Relationship Management Plan Project Title Project Number [ ] [ ] Revision: Date: Description: Author [ ] Approved on behalf of Network Rail Approved on behalf
Transition and Transformation. Transitioning services with minimal risk
IBM Global TECHNOLOGY Servicess and Transformation ing services with minimal risk Summary To transition services is a complex process involving many issues. When outsourcing to IBM, you gain the benefit
CPNI VIEWPOINT CONFIGURING AND MANAGING REMOTE ACCESS FOR INDUSTRIAL CONTROL SYSTEMS
CPNI VIEWPOINT CONFIGURING AND MANAGING REMOTE ACCESS FOR INDUSTRIAL CONTROL SYSTEMS MARCH 2011 Acknowledgements This Viewpoint is based upon the Recommended Practice: Configuring and Managing Remote Access
Industry. Head of Research Service Desk Institute
Asset Management in the ITSM Industry Prepared by Daniel Wood Head of Research Service Desk Institute Sponsored by Declaration We believe the information in this document to be accurate, relevant and truthful
The rise of the hybrid network model
The rise of the hybrid network model Hybrid networks offer the promise of greater flexibility and capacity, improved application performance and cheaper price points than traditional Wide Area Networks
Role Profile. Directorate Corporate Support Department Customer Service and Business Transformation
Role Profile Job Title Head of Customer Service Job No. (Office Use) C6029 Band/Band Range-(for career grades) Grade J Directorate Corporate Support Department Customer Service and Business Transformation
The Cadence Partnership Service Definition
The Cadence Partnership Service Definition About Cadence The Cadence Partnership is an independent management consultancy, specialising in working with a wide range of organisations, solving complex issues
BT Contact Centre Efficiency Quick Start Service
BT Contact Centre Efficiency Quick Start Service The BT Contact Centre Efficiency (CCE) Quick Start service enables organisations to understand how efficiently their contact centres are performing. It
Lot 1 Service Specification MANAGED SECURITY SERVICES
Lot 1 Service Specification MANAGED SECURITY SERVICES Fujitsu Services Limited, 2013 OVERVIEW OF FUJITSU MANAGED SECURITY SERVICES Fujitsu delivers a comprehensive range of information security services
Document management concerns the whole board. Implementing document management - recommended practices and lessons learned
Document management concerns the whole board Implementing document management - recommended practices and lessons learned Contents Introduction 03 Introducing a document management solution 04 where one
Procuring Penetration Testing Services
Procuring Penetration Testing Services Introduction Organisations like yours have the evolving task of securing complex IT environments whilst delivering their business and brand objectives. The threat
An example ITIL -based model for effective Service Integration and Management. Kevin Holland. AXELOS.com
An example ITIL -based model for effective Service Integration and Management Kevin Holland AXELOS.com White Paper April 2015 Contents Introduction to Service Integration and Management 4 An example SIAM
Digital Continuity in ICT Services Procurement and Contract Management
Digital Continuity in ICT Services Procurement and Contract Management This guidance relates to: Stage 1: Plan for action Stage 2: Define your digital continuity requirements Stage 3: Assess and manage
Data Protection Act 1998. Guidance on the use of cloud computing
Data Protection Act 1998 Guidance on the use of cloud computing Contents Overview... 2 Introduction... 2 What is cloud computing?... 3 Definitions... 3 Deployment models... 4 Service models... 5 Layered
Growth Through Excellence
Growth Through Excellence Public/Private Cloud Services Service Definition Document G- Cloud 5 REFERENCE NUMBER RM1557v Table of Contents Table of Contents... 3 Executive Summary... 4 About the Company...
The South Staffordshire and Shropshire Health Care NHS Foundation Trust Digital Strategy 2014 2019
The South Staffordshire and Shropshire Health Care NHS Foundation Trust Digital Strategy 2014 2019 Peter Kendal Associate Director for Information Management and Technology Development 01/12/2014 1 Page
Request for Proposal. Supporting Document 3 of 4. Contract and Relationship Management for the Education Service Payroll
Request for Proposal Supporting Document 3 of 4 Contract and Relationship December 2007 Table of Contents 1 Introduction 3 2 Governance 4 2.1 Education Governance Board 4 2.2 Education Capability Board
Migrating to the Cloud. Developing the right Cloud strategy and minimising migration risk with Logicalis Cloud Services
Migrating to the Cloud Developing the right Cloud strategy and minimising migration risk with Logicalis Cloud Services Organisations are looking for new ways to deliver IT services and demanding that ICT
MANAGING THE SOFTWARE PUBLISHER AUDIT PROCESS
MANAGING THE SOFTWARE PUBLISHER AUDIT PROCESS 3 THE USE OF BUSINESS SOFTWARE AND SPORTS ARE DEFINITELY QUITE SIMILAR; IF YOU WANT TO PLAY (USE THE SOFTWARE), YOU HAVE TO ACCEPT THE RULES. THIS INCLUDES
MANAGING DIGITAL CONTINUITY
MANAGING DIGITAL CONTINUITY Project Name Digital Continuity Project DRAFT FOR CONSULTATION Date: November 2009 Page 1 of 56 Contents Introduction... 4 What is this Guidance about?... 4 Who is this guidance
Service Integration &
This is a DRAFT document, being published for review & comment The content is therefore subject to change & revision This document is part of the XGOV Strategic SIAM reference set Service Integration &
G-Cloud Service Definition Lotus Notes to Microsoft SharePoint Migration Discovery Service
G-Cloud Service Definition Lotus Notes to Microsoft SharePoint Migration Discovery Service Lotus Notes to Microsoft SharePoint Migration Discovery Service This service provides an opportunity to review
Intelligent Customer Function (ICF)
CAPABILITY AUDIT FOR HEIs Higher Education Institutions (HEIs) should organically develop their own to successfully manage the process of strategic sourcing. The capability audit provides an assessment
How To Use Open Source Software In Government
Open Source Software Options for Government February 2011 Aim 1. This document presents options for Open Source Software for use in Government. 2. It is presented in recognition that open source software
Delivering progress towards meeting HMG targets on the SME growth agenda
Delivering progress towards meeting HMG targets on the SME growth agenda Action Plan Version 1.1 dated 16 th August 2013 Author: Robert Astall, Head of Commercial Profession and Capability Background The
Enterprise Architecture (EA) Principles
FINAL January 2016 Enterprise Architecture (EA) Principles Introduction The Enterprise Architecture principles express how Highways England needs to design and deploy information systems across the organisation.
POSITION DESCRIPTION. Role Purpose
POSITION DESCRIPTION Position Title Senior SharePoint Administrator/Developer Position Number Reports to Head of Solutions Development Functional Auth HRM Auth Region N/A Enterprise role Date Date Function
Embrace the G-Cloud. Ultra Secure Colocation Services for the Public Sector. thebunker.net Phone: 01304 814800 Fax: 01304 814899 info@thebunker.
Embrace the G-Cloud Ultra Secure Colocation Services for the Public Sector 1 Phone: 01304 814800 Fax: 01304 814899 info@ Contents Introduction What is G-Cloud? Types of accreditation: Business Impact Levels
Information Management Policy
Title Information Management Policy Document ID Director Mark Reynolds Status FINAL Owner Neil McCrirrick Version 1.0 Author Deborah Raven Version Date 26 January 2011 Information Management Policy Crown
Internal Audit Quality Assessment Framework
Internal Audit Quality Assessment Framework May 2013 Internal Audit Quality Assessment Framework May 2013 Crown copyright 2013 You may re-use this information (excluding logos) free of charge in any format
Customer Guide Helpdesk & Product Support. [Customer Name] www.four.co.uk Page 1 of 13
Customer Guide Helpdesk & Product Support [Customer Name] www.four.co.uk Page 1 of 13 Table of Contents HELP DESK AND PRODUCT SUPPORT SUMMARY... 3 1 FOUR HELP DESK STRUCTURE AND CALL ESCALATION... 6 2
expense@work Overview Pricing & Features Summary
expense@work Overview Pricing & Features Summary 1 st March 2012 Copyright Notice Produced By: Published: Contact Details: systems@work - Solution Delivery Division Mar-12 systems@work Limited http://www.systemsatwork.co.uk
Christchurch Polytechnic Institute of Technology Information Systems Acquisition, Development and Maintenance Security Standard
Christchurch Polytechnic Institute of Technology Information Systems Acquisition, Development and Maintenance Security Standard Corporate Policies & Procedures Section 1: General Administration Document
PORTFOLIO, PROGRAMME & PROJECT MANAGEMENT MATURITY MODEL (P3M3)
PORTFOLIO, PROGRAMME & PROJECT MANAGEMENT MATURITY MODEL (P3M3) 1st February 2006 Version 1.0 1 P3M3 Version 1.0 The OGC logo is a Registered Trade Mark of the Office of Government Commerce This is a Value
Digital Asset Manager, Digital Curator. Cultural Informatics, Cultural/ Art ICT Manager
Role title Digital Cultural Asset Manager Also known as Relevant professions Summary statement Mission Digital Asset Manager, Digital Curator Cultural Informatics, Cultural/ Art ICT Manager Deals with
Document control for sensitive company information and large complex projects.
Data sheet Problem FTP-Stream solves four demanding business challenges: Global distribution of files any size. File transfer to / from China which is notoriously challenging. Document control for sensitive
Cloud Computing in the Victorian Public Sector
Cloud Computing in the Victorian Public Sector AIIA response July 2015 39 Torrens St Braddon ACT 2612 Australia T 61 2 6281 9400 E [email protected] W www.aiia.comau Page 1 of 9 17 July 2015 Contents 1.
How To Ensure Information Security In Nhs.Org.Uk
Proforma: Information Policy Security & Corporate Policy Procedures Status: Approved Next Review Date: April 2017 Page 1 of 17 Issue Date: June 2014 Prepared by: Information Governance Senior Manager Status:
Enforcement Operations. Module Db. Technical Solution
Module Db Technical Solution Capita s Combined Offer for Business & Enforcement Operations delivers many overarching benefits for TfL: Cost is reduced through greater economies of scale, removal of duplication
SOFTWARE LICENCE MANAGEMENT
SOFTWARE LICENCE MANAGEMENT MANAGING SOFTWARE COMPLIANCE AND COSTS DOESNʼT HAVE TO BE DIFFICULT Software Lifecycle Services from Computacenter Managing software compliance and costs doesnʼt have to be
Information Governance Policy
Information Governance Policy Information Governance Policy Issue Date: June 2014 Document Number: POL_1008 Prepared by: Information Governance Senior Manager Insert heading depending on Insert line heading
ROLE PROFILE. Business Function: Software Operations Managed Cloud Services eg s Head Office, Dunston Business Village, Staffordshire
ROLE PROFILE Job Title: MCS Service Manager Grade/Salary Banding: Reporting To: Head of Software Operations Business Function: Software Operations Managed Cloud Services Location eg s Head Office, Dunston
How much do you pay for your PKI solution?
Information Paper Understand the total cost of your PKI How much do you pay for your PKI? A closer look into the real costs associated with building and running your own Public Key Infrastructure and 3SKey.
The Department for Business, Innovation and Skills IMA Action Plan PRIORITY RECOMMENDATIONS
PRIORITY RECOMMENDATIONS R1 BIS to elevate the profile of information risk in support of KIM strategy aims for the protection, management and exploitation of information. This would be supported by: Establishing
SERVICE DEFINITION G-CLOUD 7 SECURE FILE TRANSFER DIODE. Classification: Open
SERVICE DEFINITION G-CLOUD 7 SECURE FILE TRANSFER DIODE Classification: Open Classification: Open ii MDS Technologies Ltd 2015. Other than for the sole purpose of evaluating this Response, no part of this
G-CLOUD SPECIALIST CLOUD SERVICES
ITSUS CONSULTING G-CLOUD SPECIALIST CLOUD SERVICES Page 1 of 13 SPECIALIST CLOUD SERVICES ITSUS is a specialist network consultancy which delivers that crucial combination of security and efficiency, both
IBM G-Cloud Microsoft Windows Active Directory as a Service
IBM G-Cloud Microsoft Windows Active Directory as a Service Service Definition IBM G-Cloud Windows AD as a Service 1 1. Summary 1.1 Service Description This offering is provided by IBM Global Business
Records management in SharePoint 2010
Records management in SharePoint 2010 Implications and issues Crown copyright 2011 You may re-use this information (excluding logos) free of charge in any format or medium, under the terms of the Open
POSITION DESCRIPTION. Role Purpose. Key Challenges. Key Result Areas
POSITION DESCRIPTION Position Title Manager, Technical Services Support Position Number Reports to Manager Technology Services Functional Auth HRM Auth Region IT Services Centre Head Office Date Feb 2011
Contents. visualintegrator The Data Creator for Analytical Applications. www.visualmetrics.co.uk. Executive Summary. Operational Scenario
About visualmetrics visualmetrics is a Business Intelligence (BI) solutions provider that develops and delivers best of breed Analytical Applications, utilising BI tools, to its focus markets. Based in
Cyber Security Consultancy Standard. Version 0.2 Crown Copyright 2015 All Rights Reserved. Page 1 of 13
Cyber Security Consultancy Standard Version 0.2 Crown Copyright 2015 All Rights Reserved Page 1 of 13 Contents 1. Overview... 3 2. Assessment approach... 4 3. Requirements... 5 3.1 Service description...
Back to Basics. Managing the Audit Department: Resource Management
Back to Basics Managing the Audit Department: Resource Management In her article in the last newsletter, Bev Cole provided an overview and roadmap for managing the audit department and also provided more
CREATING A LEAN BUSINESS SYSTEM
CREATING A LEAN BUSINESS SYSTEM This white paper provides an overview of The Lean Business Model how it was developed and how it can be used by enterprises that have decided to embark on a journey to create
Aggregation. Is bigger always better?
Aggregation Is bigger always better? Contents Purpose of this guidance 1 What is aggregation? 2 When should aggregation be considered? 4 Why use aggregation? 6 Some practical considerations 8 Further reading
OPEN SOURCE SOFTWARE CUSTODIAN AS A SERVICE
OPEN SOURCE SOFTWARE CUSTODIAN AS A SERVICE Martin Callinan [email protected] Wednesday, June 15, 2016 Table of Contents Introduction... 2 Source Code Control... 2 What we do... 2 Service
NSW Government. Cloud Services Policy and Guidelines
NSW Government Cloud Services Policy and Guidelines August 2013 1 CONTENTS 1. Introduction 2 1.1 Policy statement 3 1.2 Purpose 3 1.3 Scope 3 1.4 Responsibility 3 2. Cloud services for NSW Government 4
Open Source Telephony. for Government
Open Source Telephony for Government Open Source has the power to improve established industries Open Source has the power to improve established industries and is offering a real alternative to proprietary
Information governance strategy 2014-16
Information Commissioner s Office Information governance strategy 2014-16 Page 1 of 16 Contents 1.0 Executive summary 2.0 Introduction 3.0 ICO s corporate plan 2014-17 4.0 Regulatory environment 5.0 Scope
January 2016. Communications Manager: Information for Candidates
January 2016 Communications Manager: Information for Candidates Thank you for expressing interest in the role of Communications Manager. We have compiled this information pack to tell you more about The
PROGRAMME OVERVIEW: G-CLOUD APPLICATIONS STORE FOR GOVERNMENT DATA CENTRE CONSOLIDATION
PROGRAMME OVERVIEW: G-CLOUD APPLICATIONS STORE FOR GOVERNMENT DATA CENTRE CONSOLIDATION 1. Introduction This document has been written for all those interested in the future approach for delivering ICT
GOOD PRACTICE GUIDE 13 (GPG13)
GOOD PRACTICE GUIDE 13 (GPG13) GPG13 - AT A GLANCE Protective Monitoring (PM) is based on Good Practice Guide 13 Comprises of 12 sections called Proactive Monitoring Controls 1-12 Based on four Recording
Beyond Data Governance Beyond Definitions and into the Business Reality
Beyond Data Governance Beyond Definitions and into the Business Reality About Diaku 2008 Diaku begins as a data strategy & data governance consulting firm, running large data programmes for tier 1-2 banks
Newcastle University Information Security Procedures Version 3
Newcastle University Information Security Procedures Version 3 A Information Security Procedures 2 B Business Continuity 3 C Compliance 4 D Outsourcing and Third Party Access 5 E Personnel 6 F Operations
Digital Continuity Plan
Digital Continuity Plan Ensuring that your business information remains accessible and usable for as long as it is needed Accessible and usable information Digital continuity Digital continuity is an approach
Cloud Cube Model: Selecting Cloud Formations for Secure Collaboration
Cloud Cube Model: Selecting Cloud Formations for Secure Collaboration Problem Cloud computing offers massive scalability - in virtual computing power, storage, and applications resources - all at almost
What is Open Source? Open source is defined by three key components:
Integrating Open Source into your business To help businesses deal with the complexity of globalization, unanticipated opportunities, unexpected threats, competitive demands and fiscal constraints, a business
OPEN SOURCE SECURITY
OPEN SOURCE SECURITY February 2008 The Government of the Hong Kong Special Administrative Region The contents of this document remain the property of, and may not be reproduced in whole or in part without
A discussion of information integration solutions November 2005. Deploying a Center of Excellence for data integration.
A discussion of information integration solutions November 2005 Deploying a Center of Excellence for data integration. Page 1 Contents Summary This paper describes: 1 Summary 1 Introduction 2 Mastering
Middlesbrough Manager Competency Framework. Behaviours Business Skills Middlesbrough Manager
Middlesbrough Manager Competency Framework + = Behaviours Business Skills Middlesbrough Manager Middlesbrough Manager Competency Framework Background Middlesbrough Council is going through significant
Specialist Cloud Services Lot 4 Cloud Printing and Imaging Consultancy Services
Specialist Cloud Services Lot 4 Cloud Printing and Imaging Consultancy Services Page 1 1 Contents 1 Contents... 2 2 Transcend360 Introduction... 3 3 Service overview... 4 3.1 Service introduction... 4
How To Use Open Source Software In Defence
Open Source Software in the Defence Industry Anthony Harrison Thales [email protected] Abstract: There are an increasing number of defence programmes incorporating open source software
GPG13 Protective Monitoring. Service Definition
GPG13 Protective Monitoring Service Definition Issue Number V1.3 Document Date 27 November 2014 Author: D.M.Woodcock Classification UNCLASSIFIED Version G-Cloud 6 2014 Copyright Assuria Limited. All rights
JOB PROFILE. For more detailed information about Internal Affairs, go to our website: www.dia.govt.nz.
JOB PROFILE Job Title: Enterprise Architect Business Unit: Chief Architect Business Group: Government Technology Services Branch: Reporting to: Chief Architect Location: Wellington Grade: 22 Date last
