Search This Blog

The FY 2012 IT Budget for DoD

The OMB prepared analysis of the FY2012 IT budget for DoD offers new insights into the existing spending.  An understanding of the structure of IT spending is important for gaining a realistic insight how the just announced strategic directions can be achieved.

The key insight of 2012 spending is an increase of 5%, not a decrease in IT spending. The following table shows the changes:

/FIGURE 1/

 The following shifts in spending are significant:
1. The shift of spending from services to agencies is continuing.  40% of the total DoD spending and 36% of all development is in agencies. Any proposed consolidations of applications must concentrate on the diversity of programs that are widely dispersed in a variety of agency organizations.
2. The Army shows a large increase in IT spending whereas the Air Force shows a remarkable decrease in the costs of ongoing operations. It appears that the Air Force is making good progress in the consolidation of shared applications.
3. The Navy shows a 57% increase in development costs. Since the Navy still continues operating with what is a mature NMCI systems and NGEN is just getting started, it is hard to understand the reasons for such an increase.

The projected $38.4 billion of DoD spending does not include the payroll costs of the uniformed and civilian workforce. According the DoD CIO, there are approximately 170,000 personnel supporting IT operations classified as support for information technology. If conservatively priced, this would add more than $17 billion to the total IT expense, or 44%. This manpower is by far the single largest cost component, far exceeding expense for computer hardware. In planning cost reductions the primary focus should be therefore on headcount reductions.

One also needs to consider the relative size of this manpower because it equals the headcount of the entire projected Marine Corps force. When DoD re-examines its “tooth-to-tail” ratios, the information workforce must be seen as a major opportunity to decrease the number of support personnel.

Missing from the DoD IT budget are most intelligence costs, such as the expenses for the DIA, NSA and a variety of national security functions. Since the future of DoD depends on the leveraging of intelligence efforts with warfare and a variety of cyber operations, a partial exclusion of such spending removes from the OSD oversight a critical component of enterprise networks.

A functional examination of DoD IT spending raises many questions about the organization of its projects. OMB divides IT spending into several categories:

/FIGURE 2/
 
1. 481 programs in Information and Technology Management consume half of the IT budget. In commercial terms that is usually classified as IT “overhead”. It deploys a variety of applications used primarily to deal with the proliferation of contractual relationships. For instance, the DoD Controller keeps track of IT spending with more than 5,000 expense line items. There is no question that any consolidation program should start with a sharp focus on how to reduce such expenditures.
2. A surprising discovery is found in the 656 supply chain management programs with a $3 billion budget – many with limited budgets – to keep track of asset records. A reduction in such systems should be seen not only as a way of reducing costs, but also as a means for streamlining the workflow so that tracking materials is simple.
3. The fact that only 28% of programs support Defense and National Security, which is the core business of IT, suggests that all reporting is incomplete and that the bulk of information technologies are classified as “weapons”, which takes them out of the IT classification. For instance, there are huge expenses for avionic systems or for missile defense. Though most of these costs deal with hardware and software, they are nevertheless defined as weapons and not as IT, where it would be excluded as a military capital cost.

SUMMARY
The FY2012 budget identifies line items that would affect the sequence of execution of an enterprise strategy for DoD. The current IT approaches have an enormous task of “cleaning up” the accumulation of up to thirty years of localized proliferation of programs that keep on consuming funds for support and maintenance.

Close to $14 billion/year development funds in FY2012 will have to be re-directed to generate the short-term savings while steering programs in the desired direction as outlined in http://pstrassmann.blogspot.com/2012/01/new-information-systems-directions-for.html.

Whether such funds will be available after austerity budgets become effective after FY2013 is not known.

There are many choices where to start. However, the $19.7 programs in the Information Technology and Management appear to offer the greatest potential. First, it is a functional area where the OSD CIO has unquestioned authority. Second, it does not intrude on National Defense or National Security mission-oriented programs or on functions that are tightly coupled to military operations. Third, it is the IT management programs that support the current proliferation of program initiative. By seizing control over the administrative processes that perpetuate the continuation of past practices, the ability to guide DoD programs towards a more consolidated approach will enhance the ability of central management to steer the development budgets towards the desired directions.

FIGURE 1

FIGURE 2

Does DoD Have an Adequate IT Strategy?

According to the newly released IT strategy documents, the “Enterprise Computing Centers” (ECC), become the default location for over 60,000 DoD servers in use.  Servers that do not fit into a small number of ECCs will remain in “Area/Regional Processing Centers” and in “Installation Processing Centers” that will be granted exceptions from consolidation. This entire migration should be mostly complete sometime after 2015.

The proposed streamlining of most of DoD’s data center capacity on such a short schedule is unprecedented. The only comparable effort was dictated by DMRD 918 in 1992, but did not get completed until ten years later. Though its original plans projected the folding of 122 data centers into five DISA operated services, the total number of data centers outside of DISA grew enormously as components found it attractive to operate their own computing facilities.

The fundamental flaw in the implementation of DMRD plans was its sole concentration on the consolidation of data center locations, with insufficient regard to the streamlining of related collateral processes, applications and communications. Just consolidating data centers was an inadequate strategy.

To make the ambitious data center consolidations feasible, DoD will have to include in its plans the problems associated with the termination of hundreds of contractors that currently deliver local data centers support services. This includes a significant share of locally managed “set-aside” contractors, which are primarily minority-owned firms. Congressional intervention to keep local contractors employed will inhibit the proposed strategy.

The latest IT strategy has added simultaneous consolidations of network controls as well as the elimination of individual networks. These are essential steps, but introduce an enormous effort to alter existing long-term contract relationships for 15,000 networks. The entire GIG 2.0 connectivity will have to be reconfigured.

The new IT strategy is also adding a replacement program for the multiplicity of existing security programs, network control centers and help desks. Such a substitution will create turmoil among the staffs now operating such services because the existing security arrangement represent a diversified patchwork of local adaptations that offer a large variety of security solutions.

The new IT is changing end-user services at the same time, such a central coordination for all testing, certification and procurement of information technology. This includes a centralized approach to administering a new generation of hardware and software purchases while imposing on contractor operations innovative application development platforms. Whether the existing contractual arrangements can accept such changes on the proposed schedule is doubtful. Software development practices of hundreds of contractors are difficult to alter while maintenance of existing code must continue without a flaw.

The new IT strategy proposes to address the methods used in connecting over seven million desktops that somehow must interact with the new data center configuration of virtual servers that have fail-over capabilities. Shifting millions of computers and smart-phones to become virtual devices requires a redesign in switching and in software, which involves substantially more than just changing hardware
The new IT strategy proposes shifting much of the existing technologies to web-based desktop and smart phone productivity suites. Divestment of existing hardware while keeping customers operating without interruption is going to be difficult on account of the time that will have to be used for retraining.
Implementation schedules will have to be extended unless large support staffs will be available to administer dual operations in the interim.

The new IT also strategy wishes to pursue a parallel approach to systems reconfiguration with integration of voice, video for all types of devices, including mobile computers. How that can be sequenced without disruption is a formidable task that could take more than a decade to complete.

The failure of DMRD 918 was its neglect of applications and data services. Proceeding with data center consolidation without synchronization of interoperable applications is perilous on an accelerated schedule. Any IT plans conceived in isolation, without prior assurance of close cooperation from clerical and administrative bureaucracies, needs examination. An effort to achieve standardization and unification of data definitions across DoD components has been in place since 1993 in DISA, but so far has managed to make only minor progress.

There are also technical issues that need to be considered before accepting the proposed strategy. As yet the Office of the DoD CIO has not published a comprehensive and all-inclusive reference enterprise architecture that would support the proposed overhaul of systems. There are no technical standards in place for a federated enterprise solution that delegates the roles of military services and agencies into a support position. The consequence of uprooting existing commitments, especially for multi-billion programs with multi-year schedules, has not been detailed.

The work that needs to be done in competitive selection of a limited set of development platforms is still waiting completion. From an acquisition standpoint this may consume most of the time available. DoD with its FY12 projected IT budget of $38 billion is more than ten times larger than the IT budgets of the largest commercial organizations. Dictating the adoption of a limited set of open source software development platforms in DoD will create an upheaval among software supplier firms. Congressional interventions will slow down vendor selection for an extended time.

Agreements on how to implement the concept of application development where every function is accepted by all components after getting tested by only one, is still to be worked out. This may be one of most sticky issues for reaching agreements across all components.

The long lingering effort how to assure an enterprise-wide binding acceptance of MetaData should be completed. There are at least 3,000 individual systems now in place. Each has its own separately maintained information stores. Proceeding with a standard DoD enterprise effort is too risky for venturing into a consolidated environment where data stores become a pooled service.

To obtain widespread acceptance of certified code from development platforms such as Forge.mil, should be improved. So far, only a negligible part of DoD programs have benefited from the use of pre-fabricated software code.

The endorsement of digital signatures now requires enterprise-wide implementation. To proceed with shared enterprise-level processing on the current schedule requires DoD-wide agreements about accepting enterprise-level messaging and collaboration applications.

SUMMARY
The newly released IT strategy documents are certainly commendable. However, from the standpoint of the speed of implementation the risks are too great. We have counted over twenty risks, each with a capacity to inhibit progress of the entire proposed strategy.

As a rule, individual program managers can always concentrate on delivering results with only a small number of known risks, for projects that have a limited budget. However, in this case, which is the most ambitious proposal for a total reconfiguration of DoD IT ever conceived, the known as well as the unknown risks are just too great to accept the proposed rapid schedule. The history of on-time and on-budget performance of IT projects shows that the larger the scope of any effort, the greater the likelihood that neither schedule nor results will follow the original plans.

As has been always the case before, IT reform depends on the leadership of the key IT executives, on the capabilities of the workforce, on the support of the contractors and on the skills of the technologists to guide DoD into a completely different information environment.

The existing strategic plan has not given sufficient consideration to the prevailing social situations (also called “politics”). It does not include an analysis what the DoD organizations are capable of executing. The strategy is too extensive, trying to solve too many of the existing problems all at once. It is too fast while engaging in multiple simultaneous radical innovations. As proposed, the new strategy needs more work to show how many of the projected results can be delivered in the foreseeable future.

Objections to Cloud Computing Security

Security vulnerability is the most frequently voiced objection to cloud computing. Everyone will readily attribute greater efficiency and effectiveness to platform or software as a service. However, the subject of security assurance is always cited as an issue for which adequate safeguards are not adequately specified. Such objections reflect an insufficient understanding of the far more demanding technical capabilities that the security of cloud computing requires.

From a policy standpoint the following views on the security issues are applicable: [1]
·      Consolidation into a limited number of clouds enables secure services because the number of data centers exposed to attack is a much less than the hundreds of existing sites.
·      With tightly controlled identity authorizations as wells as access privileges information can be made securely accessible to all.
·      Deploying enterprise-wide standard identity and access management protocols will extends security protection from the network to the data stored on servers.
·      DoD networks can be better protected from threats, both internal and external, by the ability of blocking a much smaller number of potential gaps in the information infrastructure.
·      Deployment of the limited number of staff as well as of costly forensic software engaged in computer network defenses makes it possible to anticipate attacks.
·      Tightly managed assurance processes, counter-intelligence, expert security management and automated command structures will ensure that military networks remain available at all times.
·      The smaller number of standard cloud environments can ensure an ability to recover instantly from any attack.

SUMMARY
The security assurance of a cloud-based DoD environment is a highly technical issue. What is currently practiced as safeguarding of highly distributed operations does not apply under conditions that would prevail in a consolidated cloud-based environment.

Objections to cloud computing require the installation of unprecedented countermeasures as computing assets become concentrated into a vastly smaller number of targets. From a policy standpoint, as noted above, cloud-based computing can be protected. It will now take a very large and costly effort to proceed with implementation.



[1] Signed_ITESR_6SEP11. Version 1.0 – 6 SEP 2011

New Information Systems Directions for the DoD

We have a new a DoD IT Enterprise Strategy and Roadmap.  The strategy has been just signed by the DEPSECDEF as well as by the OSD CIO. (1) This makes it the highest-level statement of IT directions in over two decades. The new strategy calls for an overhaul of policies that guide DoD information systems. Implementation of the strategy now becomes a challenge in an era when funding for new systems development declines.

The following illustrates some of the key concepts that require a complete reorientation how DoD manages information technologies:

1. New policy: DoD personnel will have seamless access to all authorized information, enabling the creation, location, uses and sharing of information. Access will be through a variety of technologies, including special purpose mobile devices.
Current condition: Seamless access to information is presently not possible. DoD personnel use computing services in 150 countries, 6,000 locations and in over 600,000 buildings. This diversity requires standardization that would be difficult to make available.
Conclusion: Extremely hard to do. Requires a change in the way DoD systems are configured.

2. New policy: Commanders will have access to information available from all DoD resources, enabling improved command and control, increasing speed of action, and enhancing the ability to coordinate across organizational boundaries or with mission partners.
Current condition: Over 15,000 uncoordinated networks prevent access that offers increased speed as well as real-time coordination.  Consolidation of all of the networks under centrally managed network control centers becomes a key requirement for further progress.
Conclusion: This becomes an extremely difficult undertaking. Can be done, but would require a complete reconfiguration of the GIG.

3. New policy: Individual service members and government civilians will be provided with a standard IT user experience, enabling them to do their jobs and providing them with the same look, feel, and access to information on reassignment, mobilization, or deployment.
Current condition: DoD systems depend on over seven million devices for input and for display of information. There may be millions of unique and incompatible formats for the delivery of user experiences.
Conclusion: To remedy format incompatibilities requires the replacement by means of standard software of all the existing interfaces. That becomes a multi-billion task, though shifting costs from low cost thin clients to a highly reliable cloud makes this option feasible.

4. New policy: Common identity management, access control, authorization, and authentication schemes are necessary to permit access based on a user’s credentials.
Current condition: This policy calls for the adoption of shared networks as well as the revision of access privileges that are currently included in close to 70,000 servers.
Conclusion: The workflow between the existing personnel systems and the access authorization authorities must be revised. Overhauling the systems access privilege granting process will require a change in organizational relationships. This policy can be implemented rapidly and at a low cost.

5. New policy: Common DoD-wide services, applications, and tools will be broadly usable across the DoD, thereby minimizing duplicate efforts, reducing data fragmentation and translation, and reducing the need for retraining when users are reassigned, mobilized, or deployed.
Current condition: This policy cannot be executed within the organizational and funding structures currently in place.
Conclusion: Standardization of applications and of software tools will necessitate junking much of the code already in place, or temporarily storing it a virtualized legacy codes. Reducing data fragmentation would require full implementation of the DoD MetaData directory, currently in a decade-long development program. This policy will most likely be the most costly part of the entire new strategy. May take a decade to implement.

6. New Policy: Streamlined IT acquisition processes must support rapid fielding of capabilities, inclusive of enterprise-wide certification and accreditation of new services and applications.
Current conditions: Presently there are over 10,000 operational systems in place, controlled by hundreds of acquisition personnel. There are 79 major projects (with current spending of $12.3 billion) that have been ongoing for close to a decade and that have a proprietary technology deeply ingrained.
Conclusion: Disentangling DoD from several billions worth of non-interoperable software can be done by changing OSD policy and obtaining Congressional approval.

7. New Policy: Consolidated operations centers will provide pooled computing resources and bandwidth as needed. Standardized data centers will make it easier to access, reallocate, and monitor resources.
Current conditions: The existing number of data centers, estimated at over 770, represents a major challenge in consolidation without major changes in the software that currently occupies over 65,000 servers.
Conclusion: Can be done by shifting the workload to commercial Infrastructure-as-a-Service suppliers, but under tight DoD control to make a shifting of the workload possible.

SUMMARY
There is no question that the new OSD IT policy is in line with what are the requirements of the new military environment. The problem is how to implement the transition, because the financial, technical and organizational hurdles are challenging.

The idea of reprogramming 10,000 operational systems into a standard environment, with standard desktops, is neither affordable nor technically executable on an acceptable schedule. DoD will have to consider radically new ways how to achieve the goals of the new policies.

One of the options is to shift DoD systems to a Platform-as-a-Service environment where a standard DoD enterprise infrastructure supports multiple systems, even virtualized legacy applications. Another option is to migrate “commodity applications” such as document processing, collaboration and e-mail to Software-as-a-Service offering.


 (1)  Signed_ITESR_6SEP11. Version 1.0 – 6 SEP 2011