All bodies  ›  California State Auditor  ›  Summary

CSA

Summary

California State Auditor · 2002-111 · 2002-01-01

Read the report at California State Auditor ↗

Information Technology: Control Structures Are Only Part of Successful Governance February 2003 2002-111 rotiduA etatS ainrofilaC S T I D U A E T A T S F O U A E R U B The first five copies of each California State Auditor report are free. Additional copies are $3 each, payable by check or money order. You can obtain reports by contacting the Bureau of State Audits at the following address: California State Auditor Bureau of State Audits 555 Capitol Mall, Suite 300 Sacramento, California 95814 (916) 445-0255 or TDD (916) 445-0255 x 216 OR This report is also available on the World Wide Web http://www.bsa.ca.gov/bsa/ The California State Auditor is pleased to announce the availability of an online subscription service. For information on how to subscribe, please contact David Madrigal at (916) 445-0255, ext. 201, or visit our Web site at www.bsa.ca.gov/bsa Alternate format reports available upon request. Permission is granted to reproduce reports. � � � ��������� ���� ������ ������������� ������������������� ������������ ����������������������� February 27, 2003 2002-111 The Governor of California President pro Tempore of the Senate Speaker of the Assembly State Capitol Sacramento, California 95814 Dear Governor and Legislative Leaders: As requested by the Joint Legislative Audit Committee, the Bureau of State Audits presents its audit report concerning the governance, structure, and mission of the former Department of Information Technology and what reforms are needed to revise the statewide information technology (IT) program so that it can better meet the State’s needs. This report concludes that a variety of IT governance models could be made to work in California, as long as the statewide IT program includes factors our consultant identified as common among other successful programs. Factors that contribute to successful governance include exerting continuous executive leadership support for IT, using a collaborative management approach, showing commitment to IT employees during periods of change, and developing and implementing IT initiatives in modular form. Whatever IT governance model is ultimately chosen, the resulting organization and staff must address a number of challenges such as deciding on the proper amount of centralization and standardization the statewide IT program should have, the level of IT activity that should be outsourced, and how to mitigate the negative effects on long-term IT priorities and initiatives caused by changes in administrations and the lengthy budget cycle. Our report also concludes that the success of a new IT governance structure in California depends on the support and cooperation of many stakeholders, including the governor’s office, the Legislature, control entities, client entities, and technical entities that will be affected by the IT program. The selection, adoption, and development of a governance structure should, therefore, be a collaborative effort involving stakeholders at all levels. Respectfully submitted, ELAINE M. HOWLE State Auditor ������������������� �������������������������������������������������� ���������������������������������������� ������������������ CONTENTS Summary 1 Introduction 5 Chapter 1 California Continues to Search for an Effective Way to Govern Information Technology 13 Chapter 2 Though Their Governance Models Vary, Successful Information Technology Programs Share Factors Mostly Absent From California’s Past Efforts 21 Chapter 3 States Grapple With Some Common Problems That Have No Universal Solutions 35 Chapter 4 California Needs to Collaborate on the Governance Structure of Its Information Technology Program 45 Recommendations 45 Appendix A Profiles of States Chosen for Review Whose Information Technology Governance Programs Are Successful and Whose Circumstances Are Comparable to California’s 53 Appendix B A Summary of the Department of Information Technology’s Progress Toward Implementing the June 2001 Recommendations of the Bureau of State Audits 67 Response to the Audit State Chief Information Officer 73 California State Auditor’s Comments on the Response From the State Chief Information Officer 75 Response to the Audit Department of Finance 77 California State Auditor Report 2002-111 11 SUMMARY RESULTS IN BRIEF In 1995 the Legislature created the Department of Information Technology (DOIT) to provide leadership, guidance, and oversight for information technology (IT) Audit Highlights . . . initiatives and projects throughout the State. In July 2002, DOIT ceased operation, but the need for what it was chartered to do Although the Department continues to exist. of Information Technology (DOIT) ceased operations on July 1, 2002, the need California is governed by a multitude of agencies and for what it was chartered to departments, each with a focus to support the business of do continues to exist. Our the State by supplying a myriad of goods and services. The review of California’s and complexity of the State’s governance and other circumstances other states’ information technology (IT) governance created challenges for DOIT as it attempted to achieve its structures revealed the mission. Some of these challenges can be traced to the following: composition and organizational placement of the department, þ DOIT faced many others stem from the all-encompassing charter of being both an challenges, including advocate and a control organization, and still others are a result its composition and of the inability of state IT stakeholders to effectively collaborate. organizational placement, an all-encompassing charter to be both an To determine what lessons can be learned from states advocate and a control with exemplary practices in IT governance, our consultant organization, and conducted case studies in New York, Virginia, Pennsylvania, the inability of state IT stakeholders and Illinois. The studies revealed three models for achieving to collaborate. effective IT governance. They varied substantially in the extent to which formal authority is concentrated in the state’s highest- þ Effective IT governance level IT office as well as where that office is located in at the state level can be achieved under widely the governance structure and how it interacts with other varying structural and stakeholders in IT initiatives. procedural arrangements. þ Successful IT governance Analyses of case studies plus a review of relevant research models tend to have literature enabled our consultant to identify a number of the support of executive common factors likely to account for successful IT programs leaders, a participative under any of the different governance models observed. leadership style, and an incremental approach Successful models tend to have executive leaders who are to development and champions of IT and emphasize its value for achieving state implementation of missions, a participative and collaborative management style IT initiatives. that emphasizes “carrots” over “sticks” and that evidences continued on next page a commitment to employees during periods of change, and a modular, incremental approach to development and implementation of IT initiatives. These factors typically did not characterize California’s approach to IT governance. California State Auditor Report 2002-111 11 þ Regardless of their A number of common challenges also face states, regardless approach to IT of their approach to IT governance. Most of these challenges governance, states face involve making decisions about tradeoffs among competing common challenges interests and approaches, with no glaringly right or wrong that lack universal solutions, including the answers. Among the most critical is the need to determine the degree of centralization appropriate amount of consolidation and centralization of of IT functions and state IT functions such as data center services and the degree of standardization of IT systems, turnover in standardization of IT systems. A related challenge is ensuring administrations, lengthy equity through competitive procurement when deciding on the budget cycles, and an degree of standardization. The decision whether to outsource IT aging workforce. operations poses another challenge for state government, which must weigh the benefits of the flexibility gained from contractor- provided services against developing an over dependence on such services. States face a challenge in developing a strategic plan focused on IT or developing a business strategy in which IT plays a supporting role. Another issue faced by state governments is the establishment of an IT inventory and regular replacement of obsolete IT office equipment, and lessening the burden of the approval and procurement process requirements for such routine purposes. Operating in the public sector poses some unique challenges that state governments must face in carrying out their IT operations. One such challenge is the effect of administration turnover on the continuity of the statewide IT vision. The lengthy budget cycle also causes major problems for IT development, as does the impending retirement of a significant number of older workers because of government’s limited ability to hire enough personnel with the needed IT skills to replace those who retire. RECOMMENDATIONS The success of a new IT governance structure depends on the support and cooperation of many stakeholders, including the governor’s office, the Legislature, control entities, client entities1, and technical entities that will be affected by the IT program. The selection, adoption, and development of a governance structure should, therefore, be a collaborative effort involving stakeholders at all levels. 1 The major users of IT in the course of carrying out their respective missions. 22 California State Auditor Report 2002-111 California State Auditor Report 2002-111 33 Regardless of the governance model California adopts for its IT program, it should make sure the program includes common success factors and other vital elements by taking the following steps: • Select a chief information officer (CIO) to direct and coordinate the State’s efforts to use IT in better providing services to residents and businesses. The CIO should be a knowledgeable champion of IT and emphasize its value for effectively achieving the State’s mission. (The governor recently appointed a new state CIO.) To ensure no disruption occurs in the planning and implementation of the goals and objectives of its IT program, the state CIO should be a permanent position, reporting to the governor. • Adopt a participative management approach that stresses collaboration and communication between public and private stakeholders and builds teams to facilitate information sharing and decision making. Additionally, the CIO should develop regular, collegial relationships among IT stakeholders and meet regularly with public and private sector advisory boards. • Provide incentives for agencies and departments that develop effective statewide IT initiatives. • Make a commitment to employees during periods of change, particularly in the treatment of IT employees as new systems and skills are required. • Adopt an evolutionary strategy for IT initiatives stressing modular development and early successes that involve stakeholders in the planning and implementation. • Develop a statewide inventory of IT equipment and systems. This inventory would serve as the baseline for understanding yearly costs for installed IT-related systems and services, and for establishing standard cycles and their associated costs and savings for replacing outdated equipment. California will also have to make decisions regarding governance structure issues that are common to any statewide IT program, but for which no universal solutions exist. Some of the more critical challenges that will need to be considered and addressed include the following: 22 California State Auditor Report 2002-111 California State Auditor Report 2002-111 33 • Determine the role and responsibilities of the state CIO and the amount of authority to vest in that position. Decisions with respect to policy making, project approval and oversight, IT procurement, and operations, will drive the size and nature of the IT governance structure required to accomplish the CIO’s purpose. • Determine the appropriate degree of centralization and consolidation of IT services. • Determine the appropriate degree of standardization that should take place in statewide IT applications. • Establish the proper level of outsourcing for IT activities. • Develop a strategy to mitigate the interruptions and distractions from statewide IT initiatives caused by the periodic turnover of state administrations. • Develop a strategy to mitigate the delays and negative effects caused by the length of the budget cycle on the approval and implementation of IT projects. • Determine the proper balance between the creation of IT-specific plans with agencies’ desires for integrated business plans. • Develop a strategy to minimize the disruption that will be caused by the large number of IT employees with expertise concerning older IT systems and applications that are scheduled to retire in the near future. AGENCY COMMENTS The state CIO found our report to be comprehensive and useful in listing many of the challenges the State confronts in effectively and efficiently managing its IT resources. He agreed with several of our recommendations, but needed further discussion before agreeing with others. The director for the Department of Finance agrees that successful use of technology is important to the State, and values having a strong IT governance structure in place to develop appropriate strategies for the future. Toward that end, he will thoughtfully consider the ideas proposed in our report. n 44 California State Auditor Report 2002-111 California State Auditor Report 2002-111 55 INTRODUCTION BACKGROUND Because of its vast power to process information quickly, information technology (IT) continues to revolutionize most aspects of industry and government. State governments across the country recognize IT as key to improving the way government serves its citizens. The Illinois Technology Office proclaims that technology holds the key for better management of government data and dollars, which translates directly to better service for those who depend on government assistance, for customers who wish to use a state service, and for businesses who must meet government requirements to operate. The New York State Office for Technology states that it strives to use technology to improve government services, reduce costs, and increase communication between state agencies and among state and local governments. Similarly, the State of Iowa Information Technology Department recognizes that information is both a significant resource for, and a major product of, state government. In 2000 California’s governor ordered a new push for state agencies and departments to make it easier for Californians to receive services on the Internet, expressing the view that state government should take every opportunity to use IT to make state services and programs more accessible and user-friendly. Statewide initiatives that, through the Internet and other technologies for electronic commerce, pursue the linkage of the programs and services of different agencies and departments to provide easy access for the public are known as “e-government.” However, developing and implementing a major IT project carries considerable financial risk. These projects can be complex, costly, and time-consuming tasks involving the efforts of many state employees and often the assistance of outside consultants. Because it demands a significant commitment of resources—both financial and human—developing an IT project is disruptive to an organization and may shift its resources away from its primary mission. Many IT projects cost more and take longer to complete than originally planned, and others are abandoned altogether when concerns mount regarding cost overruns or system malfunctions. Surveys of large companies and federal government agencies reveal that only 44 California State Auditor Report 2002-111 California State Auditor Report 2002-111 55 one-quarter of all large-scale systems development projects are completed on time and within budget, and almost 30 percent are abandoned because they cannot meet the developing entities’ requirements, resulting in lost taxpayers dollars for governments and substantial lost revenues and profits, even bankruptcy, for businesses. California has had its share of costly failed IT projects. In 1997, after spending more than $111 million, the State abandoned development of a system to establish a statewide automated network for tracking child support payments. A new statewide system––known as the California Child Support Automation System––is scheduled for full implementation in 2005. The delay in implementing this system left the State subject to penalties and a reduced federal share of reimbursements to offset administrative expenditures for child support. The penalties are expected to continue through fiscal year 2004–05 and amount to $1 billion, according to estimates by the Legislative Analyst’s Office, and will total $188.2 million in fiscal year 2002–03 alone, according to the governor’s office. Other major project failures, including those at the Department of Motor Vehicles and the Department of Corrections, have cost the State and taxpayers a total of about $400 million. The costs related to these failures are even greater considering the inefficiencies and service delivery problems that departments continue to experience because they could not implement the projects intended to remedy those problems. SUCCESSFUL IMPLEMENTATION OF A STATEWIDE INFORMATION TECHNOLOGY PROGRAM REQUIRES AN EFFECTIVE GOVERNANCE STRUCTURE The successful use of IT to increase the accessibility and efficiency of government programs and services relies on an effective plan for managing IT projects and system operations. States across the country have established e-government functions within their management structure to collaborate with state and local agencies and experts from outside government to effectively plan and implement statewide IT systems intended to promote the use of IT in government services in a fast-changing technology environment. California’s attempts to establish an effective system of IT management, to date, have not met with success. The State twice established management within the Department of 66 California State Auditor Report 2002-111 California State Auditor Report 2002-111 77 Finance (Finance). Neither effort proved effective in producing a successful IT program. In 1995 the State created the Department of Information Technology (DOIT) to improve its ability to apply IT effectively by providing leadership, guidance, and oversight for projects initiated by state departments. However, DOIT also was not successful in its mission, and on July 1, 2002, the Legislature disbanded the department. The Figure shows the prescribed process for developing IT projects under DOIT. Following its closure, the governor appointed a new state chief information officer (CIO) and transferred certain of DOIT’s responsibilities to Finance. Because this new structure is still evolving, we discuss the structure that was in place when we started our audit. FIGURE The State’s Information Technology Development Process Under the Department of Information Technology �������� �������� ����������� �������������� ���������� ���������������� ������������ ��������������������� ���������������� ������������� ����������������������� ��������������������� ��������������������� ����������������� �������������� ������������������� �������������������� ������������ ������������������� �������������� ���������������������� ������������������ ������������� ����������������� ������������������ ����������������� ����������������������� ������������������� ������������� ���������������� ������������������� �������������������� ���������������� ��������������������� ������������������� �������������������� ������������������� ������������������� ������������������� ����������������� ���������������������� ������������������� �������������������� ����������������� �������������������� ����������������� ������������������ ���������������������� ������� ����������������� ������������������ ������ ��������������������� ������������������ ���������������� ������������������ ����������������� ������������������ ����������������������� ������������������ ���������������� ������������������� ������������������� ��������������������� �������������������� ������������� ������������� ���������������� ��������������������� ����������� ������������������� ����������������������� Source: Bureau of State Audits’ report 2000-118, issued June 2001. 66 California State Auditor Report 2002-111 California State Auditor Report 2002-111 77 THE STATE’S INFORMATION TECHNOLOGY GOVERNANCE STRUCTURE IS COMPLEX The state’s ability to manage its IT efforts is complicated by the inter-relationships of many state agencies, departments, and other parties. Overall • The governor establishes a vision for how the State will use IT and provides direction to departments on how to implement this vision. • The Legislature authorizes project development by appropriat- ing funds. Client Entities • The agency secretary oversees the planning, development, and operation of IT systems within an agency and the departments he or she is responsible for. • Departments plan, develop, and operate IT projects to carry out their responsibilities. • The department CIO is primarily responsible for coordinating internal IT activities. • A department project manager manages the development of internal IT projects. Control Entities • Finance approves funding for IT projects primarily through its Technology Investment Review Unit. Finance has authority over departments’ budget activities. • General Services administers the procurement of IT goods and services from private vendors, primarily through its procurement division. General Services has authority over departments’ procurement activities. • The state CIO monitors most departments’ implementation of the governor’s vision and, up until July 1, 2002, oversaw DOIT. State law made the State CIO the leader for its IT efforts. 88 California State Auditor Report 2002-111 California State Auditor Report 2002-111 99 Technical Entities • Data centers provide data processing services to departments and, in some instances, help evaluate bids prior to vendor selection and contract award. The data centers include those that serve statewide needs—for example, the Stephen P. Teale Data Center and the Health and Human Services Agency Data Center—and those that serve a narrower client base or are dedicated to a single department—for example, the Hawkins Data Center in the Department of Justice and the Legislative Data Center serving the Legislature. • Office and director of e-government advise the governor on policy and coordinate with departments on the State’s e-government initiative, which is designed to promote the provision of services and information by state government to the public through the Internet. Other Entities • Advisory councils assist the state CIO by providing advice and input on IT strategy and policies. • Private vendors and consultants provide software development services, computer hardware, and other specialized technical services to departments. To make the overall use of IT within California even more complex, some state entities initiate, approve, and procure their own IT projects and are ultimately responsible for development. These include the California State University system, the University of California system, the Public Employees’ Retirement System, and the California State Lottery. SCOPE AND METHODOLOGY The Joint Legislative Audit Committee (audit committee) requested that the Bureau of State Audits (bureau) determine the extent to which the current governance, structure, and mission of DOIT comply with best practices and what reforms would better meet the State’s needs. Subsequent to the audit committee’s approval of the audit in May 2002, the Legislature allowed DOIT to sunset, and the department ceased all operations as of July 1, 2002. We therefore revised the focus of the audit to address what lessons could be learned from the State’s IT program under DOIT’s stewardship and to identify best 88 California State Auditor Report 2002-111 California State Auditor Report 2002-111 99 practices that other states use that would be appropriate for California to adopt as it formulates future governance of its IT program. To assist us in conducting this audit, we engaged the services of RAND (consultant)—a nonprofit public policy research institution. To understand the infrastructure of the State’s IT program as it existed before and after DOIT ceased operations, the consultant reviewed relevant laws, rules, and regulations; it also conducted numerous interviews with appropriate state officials representing stakeholders, including those in the control, client, and technical segments. To learn how other states approach providing policy direction and oversight to their IT programs, our consultant visited with appropriate state officials representing control, client, and technical entities in each of four states. Our consultant selected those states whose IT programs it would review based on the criteria of population size, the maturity of the state-level IT agency, and recognition for using best practices. The consultant selected states large enough that the issues of scale, scope, and complexity are reasonably similar to those facing California in its efforts to effectively deploy IT to carry out its diverse missions. The states selected also have had an IT governance structure in place long enough to provide lessons learned from implementing significant IT initiatives. At a minimum, each was in place prior to January 2000. Finally, only states evidencing successful practices worth emulating were selected. Using these criteria, our consultant selected New York, Virginia, Pennsylvania, and Illinois to review. For a compilation of information from the study, see Appendix A. To obtain information from experts in the area of information technology governance from the State and local level, as well as those representing the private sector and academic institutions, our consultant conducted in-person and telephone interviews and reviewed external literature on this subject. To understand the IT governance structure under DOIT, our consultant reviewed studies and reports relative to the management and oversight of IT programs in California and interviewed staff that worked for DOIT before its sunset date of July 1, 2002. 1100 California State Auditor Report 2002-111 California State Auditor Report 2002-111 1111 To assess whether DOIT had implemented the recommendations made in a report on IT issued in June 2001,2 the bureau interviewed various staff prior to DOIT’s sunset date, obtained and reviewed all materials relevant to those recommendations they provided, and met with staff from Finance to confirm what recommendations, if any, they have or intend to implement. For the status of the recommendations, see Appendix B. n 2 Information Technology: The State Needs to Improve the Leadership and Management of Its Information Technology Efforts (report number 2000–118) 1100 California State Auditor Report 2002-111 California State Auditor Report 2002-111 1111 Blank page inserted for reproduction purposes only. 1122 California State Auditor Report 2002-111 California State Auditor Report 2002-111 1133 CHAPTER 1 California Continues to Search for an Effective Way to Govern Information Technology CHAPTER SUMMARY The Department of Information Technology (DOIT)— created by the Legislature in 1995 and beginning operation in January 1996—was California’s most recent attempt to organize information technology (IT) governance at the state level. Like its predecessor, DOIT emerged as a result of the State’s inability to prevent costly IT project failures. The Legislature created DOIT distinct from the Department of Finance (Finance), the entity that had historically performed state IT governance, but still charged Finance with certain IT-related responsibilities. Our consultant believes that this distinction and the fact that DOIT’s charter included leadership, guidance, and oversight led to several problems that plagued the new and unproven entity throughout its existence. By definition, DOIT was required to interact with control and client entities throughout the IT development process, demanding that it fulfill both advocacy and control roles. This required a balance in perspective that DOIT struggled to maintain. It also meant that DOIT had to share in the responsibility for portions of the process, namely the approval of IT projects with Finance. Over time, the delineation of roles between the two departments became a source of ambiguity. In conducting oversight—an area where it had sole responsibility— DOIT heavily relied on other entities to support or execute its objectives. Furthermore, DOIT attempted to make inroads on many issues, perhaps too many issues, all at once. This scattershot approach did not allow it to garner accomplishments that would engender support and credibility. DOIT’s success was clearly linked to its ability to work with others, and to the willingness of others to work with it. Intermittent executive support, perceptions of ineffectiveness, competing interests, and uncertain authority all made the collaborative environment that much more difficult. Today the need for what DOIT was envisioned to do still exists, possibly even more so given the State’s increasingly growing reliance on IT to execute its mission and objectives. 1122 California State Auditor Report 2002-111 California State Auditor Report 2002-111 1133 IT GOVERNANCE IN CALIFORNIA HAS A CHECKERED PAST The Legislature created DOIT largely in response to a number of Following three separate costly and embarrassing problems with implementing various IT studies that identified projects. In 1994 three separate studies reviewed and identified fundamental problems fundamental problems with the State’s planning, coordination, with the State’s planning, and leadership for IT. In response, the Legislature formed DOIT coordination, and as an independent department, and the governor designated the leadership for IT, the state chief information officer (CIO) its director. Legislature formed DOIT as an independent Prior to the creation of DOIT, responsibility for IT oversight department, and the belonged to the Office of Information Technology within governor designated the Finance, created in 1983. It replaced the State Office of state chief information Information Technology, also housed in Finance, as another officer as director. of the State’s attempts at consolidating and integrating its policy on IT. The Legislature gave the Office of Information Technology the responsibility to develop plans and policies for the effective application and development of IT in the State, and for oversight of agency IT projects. It was sharply criticized for failing to adequately perform these responsibilities after a number of costly IT project failures—most notably, the Department of Motor Vehicles database redevelopment project that cost the State $49 million and did not result in a working system. An audit by the Bureau of State Audits and studies by the Legislative Analyst’s Office and the governor’s Task Force on Government Technology Policy and Procurement (governor’s task force) identified problems with the State’s planning, implementing, and managing of IT that prompted legislative hearings and the creation of a new department that would provide badly needed leadership and oversight for the State’s IT program. In 1994 legislation was introduced to create DOIT. In its original form, the bill called for a cabinet-level IT agency and CIO, and included transferring all of the IT personnel from Finance, as well as IT and telecommunications acquisition personnel within the Department of General Services (General Services), to the new agency. It also called for the consolidation of the administration of the State’s data centers under the new agency. The legislation failed to pass in this form because of competing interests, and the Legislature approved a revised bill, Senate Bill 1 (SB 1), in October 1995. One member of the governor’s task force and a member of the Legislature expressed concern over the modified bill, citing as a major problem that Finance retained key positions and power. Although SB 1 transferred oversight responsibility to the new department, Finance retained financial approval authority for IT projects in its newly created Technology Investment and Review Unit (TIRU). 1144 California State Auditor Report 2002-111 California State Auditor Report 2002-111 1155 DOIT was charged with providing leadership, guidance, and oversight of IT in state government. Most of its responsibilities centered on developing plans and policies to support the effective use of IT. This included improving the development and contract management of IT acquisitions; providing guidance for the appropriate use of IT in state agencies; recognizing the inter-relationships between various federal, state, and local government stakeholders, as well as those in private industry, in its policies and plans; and ensuring that agencies’ IT plans and projects were in line with the State’s vision and goals. SB 1 also gave DOIT direct oversight authority to suspend, reinstate, or terminate IT projects after consultation with the affected client, control, and technical entities. From the very beginning of DOIT’s existence, a number of problems threatened its ability to effectively operate in accordance with the Legislature’s intent. Its Need to Balance Advocacy and Control and Struggle to Build Trust Hampered DOIT’s Ability to Plan IT Projects DOIT’s responsibilities in the planning phase were primarily to collaborate and to advise. One problem it faced was trying to balance this advocacy role with its control function. Another DOIT struggled to problem was that it never quite established itself as a trusted and balance its advocacy credible advisor. role with its control function and never quite In its collaborative role, DOIT tried to work with IT leaders from established itself as a agencies and departments when they began forming project trusted and credible initiatives, a step that some IT leaders thought beneficial to advisor. the development and subsequent review of a feasibility study report (FSR). Agencies and departments use FSRs to justify the development of IT projects to control entities (DOIT and Finance in California prior to July 1, 2002). The FSR spells out business and technical reasons to justify investing state resources in the project, why the proposed project is needed, the means for ensuring its success, and a comprehensive analysis of its benefits and costs. Effective IT project definition requires consideration of the business objectives, which determine the requirements and the knowledge and proficiency needed for the type of technology proposed. Agencies and departments put significant emphasis on the up-front phase to prepare a strong FSR. The nature of this up-front involvement, which DOIT was trying to become more involved in, is quite distinct from the remaining phases of the IT development process. The initial phase is focused on advocacy, while the latter phases focus on control. 1144 California State Auditor Report 2002-111 California State Auditor Report 2002-111 1155 In its advisory role, DOIT developed a statewide strategic plan that was supposed to guide agency and department IT plans and projects. However, due to California’s size, the diversity of priorities, and the complexity of intrastate reporting structures, updating such a plan proved challenging. The process that DOIT used was not adequately inclusive or responsive to agency or department CIOs, and the plan it drafted was not well received. In some cases, state IT leaders were not even aware of its existence. DOIT Had No Clearly Defined Approval Role or Responsibilities SB 1 did not clearly define or distinguish DOIT’s role and responsibilities relative to other control organizations such as Finance (through TIRU), in particular for approval. The legislation gave project approval authority to both Finance and DOIT. DOIT, Finance, and General Services to some extent, all had a role in the approval process. In principle, DOIT was supposed to review the merits of the technology of a proposed IT project; Finance would review the business case and approve funding, relying on DOIT’s expertise to inform its decision; and General Services would approve contracts not otherwise delegated or exempted for the procurement of IT goods and services from private vendors and have final authority for the general procurement procedures. In practice, however, DOIT became primarily a “rubber-stamp” department, while Finance made the final decisions about IT project funding approval. Client entities saw Finance’s and DOIT’s roles as overlapping, at best. This ambiguity and imbalance of power eroded trust and confidence in these two control entities from the client agency perspective. DOIT’s failure to finalize an updated statewide strategic plan may have also contributed to another problem. Client entities indicated that the approval process appeared preferential, DOIT’s failure to finalize arbitrary, and shortsighted. For example, when Finance an updated statewide initially denied a mission-critical prison IT system because the strategic plan may have project’s FSR did not make a strong enough business case, the contributed to client Department of Corrections (Corrections) appeals overturned entities’ perception that this decision because Corrections argued that the outcome of the approval process was not approving the system would create unacceptable conditions preferential, arbitrary, in the prisons. Having a statewide strategic plan (and related and shortsighted. supporting plans) might have alleviated some ambiguity in the approval process by serving as a guide to assess and judge the priority of projects against established statewide goals and priorities. Frustration with the approval (and budgeting) process 1166 California State Auditor Report 2002-111 California State Auditor Report 2002-111 1177 motivated some agencies and departments to keep projects under the dollar threshold triggering the requirement for an FSR, thus limiting their exposure to control phases of the IT development process because it became increasingly arduous and mired in mistrust. DOIT’s Role in Procurement Was Minor Of all the IT development process phases, DOIT’s role in procurement was the least prominent. DOIT saw its role as identifying or developing best practices and guidance in acquiring, managing, and using IT, as well as directing how the DOIT was beginning State could use IT to reduce the cost of government. DOIT was to take on the task of beginning to take on the task of facilitating the leveraging of the facilitating the leveraging State’s buying power (a task that many consider appropriate for of the State’s buying a statewide entity), but its first attempt was not well executed. power, but its first attempt Legislative hearings held from April to June 2002 accused was not well executed. DOIT of failing to review and assess the need for a proposed sole-source statewide contract with the Oracle Corporation that would have resulted in a costly and excessive purchase of database software licenses. Managing the tension between statewide efforts to obtain cost efficiency and effectiveness through volume purchases versus competitive procurements as a means to foster equity and public trust was and will continue to be a significant challenge. A related problem that DOIT faced was the definition and use of standards. Several of the state officials interviewed agree that standards are needed and that DOIT made some attempts to establish them, but budgetary concerns regarding the cost impact on projects derailed such endeavors. Even had this not been the case, vendors may have felt threatened and locked out of competition if DOIT had set standards other than those calling for their products. DOIT’s inability to make progress in this area contributed to a perception by some of ineffectiveness. One of DOIT’s Main Roles Was Oversight of Implementation and Evaluation DOIT’s oversight role included reviewing project progress, assessing the resultant system, and, when necessary, redirecting or terminating a project. Highly publicized IT failures have led to the evolution and expansion of the oversight process with the objective of preventing the next troublesome project. As previously stated, one of the main reasons DOIT was created was to provide oversight, a task that its predecessor allegedly did not perform well. 1166 California State Auditor Report 2002-111 California State Auditor Report 2002-111 1177 Project oversight occurs at many levels both internal and external to agencies or departments, but opinions vary as to how much is necessary and where it should occur. DOIT initiated several strategies to fulfill its oversight responsibilities, including the use of independent project oversight consultants and independent verification and validation contractors. The agency or department usually paid for these extra personnel because Some agencies and DOIT did not have the resources to undertake such an enormous departments perceived task. The burden of meeting DOIT’s oversight requirements was DOIT’s project oversight considered excessive, redundant, and at times trivial by some process to be excessive, agencies and departments. In particular, they felt that DOIT’s redundant, and at times oversight requirement should have been flexible and measured trivial. to the capability of the entity; for example, entities with proven track records for successful IT project development would receive little or no oversight. On the other hand, some felt that independent oversight was an absolute must because the entities cannot effectively police themselves. When asked, interviewees could not recall a specific incident where DOIT actually exercised its authority to terminate a project, possibly due to its lack of influence or political support. In addition, some interviewees indicated that DOIT did not seem to have clear authority to oversee projects, causing confusion among agencies and departments. DOIT Had Other Problems Related to Its Environment Aside from the problems it encountered with the IT development process, DOIT also faced a series of other problems related to the environment in which it operated. These problems originated from DOIT’s inability to effectively collaborate with other organizations, as well as the ambiguity in its role and function. Lack of Other Organization and Executive Support Hindered DOIT’s Effectiveness IT leaders from California’s agencies and departments noted that the entities previously charged with overseeing IT planning and management generally had similar constraints and similar challenges—namely, collaboration with other stakeholders in the process. Control and client entities alike at times did not collaborate with and support DOIT. As an example, interviewees cite Finance’s reluctance to support DOIT’s proposal for additional verification and validation contractors, severely cutting the forecast amount of contractor support needed for oversight. 1188 California State Auditor Report 2002-111 California State Auditor Report 2002-111 1199 According to the Legislative Analyst’s Office, for it to provide meaningful oversight and increase the chances for success of IT projects, DOIT and the state CIO needed the active support of the governor and an adequate number of staff to carry out all the responsibilities it was given. DOIT was disadvantaged from the beginning because none of the staff from the former oversight entity were permitted to transfer to the new department as it was established. DOIT thus lacked the institutional knowledge, particularly for control-phase tasks, from which to draw upon in carrying out its numerous responsibilities. The Administration Offered Intermittent Support for DOIT’s Roles and Functions DOIT received support from the governor on one highly successful initiative—the Year 2000 conversion effort—but IT initiatives in general received little attention from the administration, according to a Little Hoover Commission report issued in 2000. DOIT received high praise for its role in the According to a Little Year 2000 conversion effort and was credited with providing Hoover Commission strong leadership in identifying and acting on problems early report, although DOIT in collaboration with state agencies. On the other hand, DOIT received support from the was only minimally involved in the My California Web Portal governor for its successful project, another highly successful initiative that enjoyed the Year 2000 conversion public backing of the governor. Instead, the governor created effort, IT initiatives in within his office the Office of e-Government and named a general received little separate director to advise him on the electronic government attention from the initiative and to coordinate those efforts with DOIT and other administration. state departments. This dispersion of IT responsibilities was seen by some as a lack of confidence in DOIT’s ability, according to our consultant. DOIT’s presence as a statewide IT organization may have created inconsistent and unrealistic expectations. California interviewees identified several roles they thought appropriate for a statewide entity. These included responsibility for functions that touch all aspects of government, for example, developing IT policies, advancing initiatives for such things as security standards from a statewide perspective, and providing a community forum to address common issues involving IT. DOIT attempted to do all of these. According to our consultant, its efforts were less than successful, possibly because DOIT attempted to tackle too many challenges at once rather than establish a set of priorities and take on only the most important issues, as time and resources permitted. 1188 California State Auditor Report 2002-111 California State Auditor Report 2002-111 1199 Lastly, from the client agency perspective, the manner in which DOIT approached these challenges did not always seem collaborative. Several CIOs interviewed by our consultant felt that DOIT did not consider or listen to what the agencies and departments needed in terms of standards and best practices. Rather, they felt it mandated many requirements and issued policy without eliciting appropriate feedback and involvement of those most affected. In its relationships with both other control and client entities, DOIT sometimes found itself at odds with other IT stakeholders. INTERIM RESPONSIBILITY FOR PROJECT OVERSIGHT, STANDARDS, AND SECURITY RESIDES IN FINANCE In Executive Order D-59-02, dated July 1, 2002, the governor gives agencies and departments primary responsibility for their IT activities. This order also gives Finance, through its Technology and Investment Review and Technology Oversight and Security units, an oversight role for state IT projects. In response, Finance developed and is implementing an oversight framework. The framework establishes the minimum required practices and processes for project management and oversight. Finance will assess the project management and oversight practices of agencies and departments based on the requirements in the oversight framework. Finance is also working on developing a statewide security program, capitalizing on the knowledge and assets of state entities to form a security advisory group that will provide advice to Finance as it establishes new policies and procedures. It will continue to develop security plans over the coming months, with periodic updates. The governor has appointed a special In September 2002 the governor appointed a special advisor on advisor, who will also IT who would also function as the new state CIO. The purpose function as the state CIO, of this position is to provide leadership on IT policy and to to assist in identifying a collaborate with other IT leaders in state government. This permanent solution to the action was in response to the closure of DOIT on July 1, 2002, issue of IT governance. and the departure of the previous state CIO in June 2002. The special advisor is currently active in aiding the State in identifying a more permanent structure. n 2200 California State Auditor Report 2002-111 California State Auditor Report 2002-111 2211 CHAPTER 2 Though Their Governance Models Vary, Successful Information Technology Programs Share Factors Mostly Absent From California’s Past Efforts CHAPTER SUMMARY Case studies of four states our consultant considered exemplary—New York, Virginia, Pennsylvania, and Illinois—revealed three significantly different models for achieving effective information technology (IT) governance. The models differ most notably in the extent to which formal authority is concentrated in the state’s highest-level IT office. In Virginia, for instance, a great deal of responsibility for IT activities, ranging from policy development and enforcement to project technical approval and technical services operations, resides with its cabinet-level Secretariat of Technology. In Illinois, by contrast, the state’s Technology Office has no formal governance authority; housed within the Office of the Governor, it acts chiefly by making recommendations to the governor and, through him, to the cabinet. These differences notwithstanding, the states studied have highly successful IT track records. Our consultant’s review of these states’ governance models and relevant research literature revealed a number of factors associated with successful IT governance, regardless of the model employed. One of the most important of these overarching factors is having executive leaders who are champions of IT and who emphasize its value in achieving the state’s mission. These executives have an in-depth understanding of both the technical aspects of IT and good business processes. They demonstrate their commitment by communicating the importance of IT initiatives throughout state government and by giving staff the authority to carry out those initiatives. Designating the state chief information officer (CIO) as a cabinet-level position or otherwise including the CIO as a member of the governor’s office also demonstrates support for IT. 2200 California State Auditor Report 2002-111 California State Auditor Report 2002-111 2211 Other IT success factors are associated with management style. One such factor is using a participative management style that emphasizes collaboration and communication. This approach enhances the exchange of information and ideas, fosters buy-in from staff, and enables people to identify opportunities for collaboration, which, in turn, can lead to statewide initiatives and concomitant economies of scale. Involving personnel in team efforts also provides opportunities for them to develop the trust and interpersonal skills that support statewide efforts. Another aspect of management style our consultant observed as positively affecting IT governance is an approach that emphasizes “carrots” rather than “sticks.” For example, instead of mandating collaboration, one state has set aside funds available to agencies that develop cross-agency IT initiatives. A third aspect of exemplary management style is showing a commitment to employees during periods of change. States that have experienced major change in their IT organizations that proved successful have made commitments to retrain and redeploy personnel, often giving them opportunities to learn new skills and assume new roles. These practices allay fears and engender employees’ support for new initiatives. A final factor associated with states’ success in IT governance is using a modular approach when developing and implementing IT initiatives. Projects are designed in pieces, each of which can show value in a short time and can be fully functional if the larger project is stopped. The ability to quickly demonstrate results also fosters employee motivation and support from constituents. These factors typically did not characterize California’s past approach to IT governance. THREE GOVERNANCE MODELS EMERGE FROM REVIEWS OF OTHER STATES Effective IT governance at the state level can be achieved under Effective IT governance widely varying structural and procedural arrangements. As at the state level can be depicted in the Table, our consultant’s study of four states achieved under widely yielded three distinct models that differ markedly in where varying structural and the highest-level state IT office is located structurally as procedural arrangements. well as the nature and extent of its influence over major IT initiatives relative to other stakeholders. For a fuller discussion of the IT governance models used in the states our consultant studied, see Appendix A. 2222 California State Auditor Report 2002-111 California State Auditor Report 2002-111 2233 TABLE Three Successful IT Governance Models Model Example Comments Consolidated New York Central IT office has technical, operational, and control Virginia some procurement (Virginia) authority. Financial authority is separate, but centralized at the state level. The state budget office generally approves IT office recommendations. Collaborative Pennsylvania Central IT office has technical and operational leadership authority but must collaborate with other departments, which have financial and procurement authority. Advocacy Illinois Central IT office has no authority but serves as an advocate for IT with departments that have technical, financial, operational, and procurement authority. According to our consultant, this does not mean to suggest that this set of models exhausts the options for effective IT governance; a study broader in scope might well have surfaced a larger set of models from which to draw lessons. Nonetheless, the consultant believes the models identified are sufficiently varied to provide the ground for highly useful comparisons and contrasts. New York and Virginia Consolidate Authority for Many Control Functions in a Central IT Office Both New York and Virginia concentrate a significant degree of control over IT policy, planning, and standards, as well as technical, operational and procurement authority, in their highest-level IT organization. Within that organization, both states divide major roles among constituent entities so that some are predominantly engaged with IT strategies and policy guidance, while others have more hands-on responsibilities for things like data center and telecommunication services and procurement. In both cases, the highest-level IT offices also already control or are planning to control a limited central fund for stimulating new enterprise-level IT ventures, but the large part of financial authority is formally retained by a finance or budget department. Technical approval is required before a project can be funded. When proposed IT projects are aligned with state priorities and judged to be technically sound, their funding requests are rarely denied. Future directions for both states include steps toward greater centralization and concentration of IT authority. 2222 California State Auditor Report 2002-111 California State Auditor Report 2002-111 2233 Pennsylvania Achieves Strong Collaborative Control Relationships Between the Central IT Office and Other Stakeholders Pennsylvania’s IT governance relies on the sharing of authority among diverse stakeholders. Its control center, the Office for Information Technology, for instance, formally empowers client entities to share control over the development and The effectiveness of implementation of the statewide projects that will affect them. Pennsylvania’s approach Pennsylvania’s Department of General Services delegates a to IT governance depends substantial part of its IT procurement authority to this central IT on clear articulation office. And the state’s budget office seeks and values the office’s and constructive IT funding recommendations while retaining official financial integration of all parties’ control. The effectiveness of this approach depends on clear separate roles. articulation and constructive integration of all parties’ separate roles. What makes this distribution of power effective rather than divisive is the close collaborative relationships cultivated by the stakeholders. Mutual respect and frequent open communication and consultation are cited as major contributors to Pennsylvania’s success. Illinois Achieves Effective IT Governance Through a Central IT Office That Has a Strong Advocacy Role but No Formal Control Functions In Illinois, the state’s highest-level IT office has no formal governance authority. It achieves its effectiveness by playing a strong advocacy role; in that role it acts as a change agent and brokers relationships among other key IT stakeholders. The governor created the position of director of technology for Illinois by an executive order; the position reports to the governor’s office but is not a cabinet-level post. However, as a member of the governor’s senior staff, the director of technology has immediate access to the top state position and sits in on all cabinet meetings as well. Because it sits within the governor’s office, the Technology Office does not have to compete with other departments to win support for its plans and priorities. On the other hand, all its authority derives from the governor. To accomplish IT initiatives, the director of technology makes recommendations to the governor, who then directs the cabinet to act on them. A board of advisors made up of CIOs from the client entities in turn provides advice and feedback to the director. 2244 California State Auditor Report 2002-111 California State Auditor Report 2002-111 2255 Financial approval for IT projects rests mainly with the Bureau of the Budget. However, agencies may draw on a special IT proj- ect revolving fund to cover project initiation costs if the director of technology approves; these funds allow agencies to get off to a fast start on approved projects. The Technology Office reports quarterly to the Bureau of the Budget, the governor, and other interested parties on the status of the revolving fund. COMMON SUCCESS FACTORS THAT WERE NOT A PART OF DOIT’s STRUCTURE ALLOW OTHER STATES’ IT GOVERNANCE TO SUCCEED Although the four states studied use three different models for achieving effective IT governance, each has a highly successful IT track record. Thus, factors that transcend formal governance structures and processes account for their positive IT outcomes. Our consultant identified factors for success from the literature and interviews so that whatever IT governance mechanism California adopts in the future might be designed with these explicit characteristics and attributes in mind. Factors that contribute to successful IT governance include exerting continuous executive leadership support for IT, using a collaborative management approach, showing commitment to employees during periods of organizational change, and designing and implementing IT initiatives in modular form. These factors focus largely on organizational processes rather than technical specifications, policies, or standards. This emphasis reflects a recurring theme heard from interviewees—the technology part is easy; the organizational part is difficult. Social and technical studies confirm the importance of having good organizational, social, and technical processes for effective performance. Continuous Executive Leadership Support for IT Is Essential for Success It is our consultant’s opinion that states with exemplary IT All four states with practices have executive leaders who are champions of IT exemplary IT practices that initiatives. All four of the states visited have this characteristic. our consultants visited These leaders emphasize the value of IT for the state in have executive leaders performing its mission. They view IT as an investment rather who are champions of IT than a cost, and they focus on using IT to improve service initiatives. delivery to citizens rather than emphasizing return on investment, for instance. Indeed, empirical research in the 2244 California State Auditor Report 2002-111 California State Auditor Report 2002-111 2255 public sector concludes consistently that IT investment pays off. Studies at local, county, state, and federal levels show that public sector IT investment has a direct, positive effect on productivity and performance. A study of IT investment by state governments, based on data from all 50 states, shows a direct, positive effect on economic productivity, as measured by gross state product. This holds true whether IT investment is measured in financial terms or by a performance index based on total computer processing power. Support for IT from governors and state CIOs is demonstrated in concrete ways. First, IT is an important part of the Governors in the four administration’s agenda. Governors in the four states visited states visited have clearly have clearly articulated goals for the use of IT that are well articulated goals for the known to the rest of their respective administrations. According use of IT in their states to state officials in Pennsylvania, the governor gave the Office that are well known to for Information Technology substantial authority to carry out its the rest of the respective mission through both a management directive and an executive administrations. order that outlined his priority to bring Pennsylvania to the forefront of the IT world. Interviewees in all four states cited consistent support from top leadership as key to the success of their IT initiatives. Executive support is also demonstrated through the organizational structure for IT governance. For instance, in Virginia, the secretary of technology is a cabinet-level position. Some interviewees in Virginia stated that this structure communicates the message that the position has significant authority. In Illinois, while not a cabinet position, the director of technology sits within the governor’s office and reports directly to him. Interviewees in Illinois reported that having direct access to the governor but not being at the same level and in competition with other cabinet-level departments for resources and attention has a major advantage. In New York, although the CIO position sits outside the governor’s office, the governor issued an executive order establishing the position and its powers. Research literature supports the importance of having top- level sponsors of IT. In studies at the local and county levels, researchers found that management support and leadership had a direct, positive influence on the commitment of employees to IT projects, organizational performance after IT implementation, and the realization of expected benefits. A study of Fortune 1000 companies and government agencies found a significant positive relationship between top management leadership and the 2266 California State Auditor Report 2002-111 California State Auditor Report 2002-111 2277 sophistication of IT infrastructure. Other studies in the private sector found that CIO support, sponsorship, and commitment are critical for IT assimilation, for meeting procurement goals in large organizations, and for successful implementation of IT security. In fact, research on organizational change shows consistently that top management support is critical to the success of change efforts or other organizational initiatives, whether the initiatives are generated from the top down or from the bottom up. Knowledge of IT at the Executive Level Is Crucial A factor that contributes to placing value on IT is having executive leaders who understand the technical aspects of IT as well as good business processes. The Pennsylvania CIO is a superb example of a state IT leader who embodies these attributes. Through his experience in management positions in state government, both in IT and other aspects of business, the CIO has gained the knowledge of how IT can help the state’s internal operations and provide better services to its citizens. Likewise, in Virginia both the governor and CIO have substantial previous experience in the IT industry, which has enabled them to recognize how IT can improve business practices in the state. In fact, several interviewees in Virginia commented that the current governor and CIO understand the importance of IT. Having administrators who have such an understanding not only contributes to the development of sound IT practices, but it enhances the leaders’ credibility, which, in turn, engenders needed support from staff. Based on comments from state officials our consultant interviewed, the implementation of their statewide IT programs can be made easier or more difficult as a result of the support the programs receive from the legislature. In Representatives from Pennsylvania, for instance, the CIO has good relationships Pennsylvania and Illinois with legislative members. Consequently, they support many consider the support and of his recommendations. Similarly, according to Illinois state understanding of IT by officials, the director of technology has a very strong working the legislature to be an relationship with the House Technology Committee that has important component of served the office well. Both states consider the support and their success. understanding of IT by the legislature to be an important component of their success. In contrast, several respondents in Virginia and New York commented that members of their legislatures do not understand IT and view it as a cost. Some interviewees in Virginia also commented that current or future legislation might make it difficult to implement the strategic IT 2266 California State Auditor Report 2002-111 California State Auditor Report 2002-111 2277 plan by restricting the power of the secretary of technology’s office. While Virginia’s CIO and governor work together effectively, it was not clear that they have such relationships with members of the legislature. A Collaborative Management Style Is a Key Factor in States With Exemplary IT Governance According to our consultant, another factor that contributes to successful IT governance is using a participative management style, with an emphasis on collaboration and communication. This process has two key aspects—executive leadership that involves staff and the use of teams to share information and make decisions. Involving Staff in Decision Making Is One Key Executive leadership involves staff in making decisions that Involving staff members affect them. Involving staff members helps create the buy-in in decision making that can make projects successful, which is particularly helps create the important in achieving organizational change. It also guarantees buy-in that can make fewer surprises for personnel affected by changes in policies and projects successful, procedures, which engenders trust in leadership. which is particularly important in achieving Consistent with a participative management style, Pennsylvania’s organizational change. CIO emphasizes “carrots” versus “sticks.” One example of a carrot is funding to help agencies develop new IT projects. Together with the Office of Budget, the CIO established a Technology Improvement Program, which furnishes seed money for agencies that develop cross-agency initiatives, e-government applications in particular. This money allows them to be responsive to rapid changes in IT without having to go through the 18-month funding and procurement cycle for each new purchase. The central IT office told agencies they could use the seed money if they put together a business case outlining why their request was important and how they would partner with other agencies to show a single face of government. Building Teams Facilitates Sharing Information and Making Decisions The second aspect of executive leadership is the use of teams to share information and make decisions. In the past decade, management literature has stressed the value of using teams. They have a diversity of knowledge and skills to bring to a project, which enhances performance on complex tasks. 2288 California State Auditor Report 2002-111 California State Auditor Report 2002-111 2299 Team collaboration enables organizational members to share With respect to IT information and perspectives that can improve local business governance, collaboration processes. With respect to IT governance, collaboration gives gives staff opportunities staff opportunities to learn about other IT initiatives across the to learn about other IT state and potentially to join forces and realize greater economies initiatives across the state of scale. A collaborative approach also provides opportunities and potentially to join for members of control and client entities to work together, forces and realize greater developing the trust and interpersonal skills that support economies of scale. statewide efforts. The primary role of business units or agencies in determining the goals of IT is emphasized in several studies. A program to introduce IT in the Charlotte-Mecklenberg (North Carolina) Police Department began with several rounds of interviews and focus groups to find out what kind of information officers and other employees thought they needed to do their work better. Once the resulting IT system was implemented, one-half to three-quarters of the officers reported a marked improvement in productivity, efficiency, call response, problem solving, and communication. Several studies emphasize the importance of letting business units or agencies that will use the IT set the agenda by proposing initiatives, justifying the financing, and being continuously involved in the planning and testing of IT projects. Two studies also demonstrate the benefits of using teams with diverse knowledge and skills; these researchers found that involving people with both business and technical expertise in procurement and outsourcing decisions was better than either group operating alone. In Pennsylvania many of the state representatives our consultant interviewed identified the state CIO’s collaborative approach as a key factor underlying the success of IT in that state. He meets regularly with agency CIOs and other agency IT personnel as well as with members of the central IT office. He rarely issues mandates; instead, he involves personnel, uses a problem-solving approach to situations, and empowers staff to implement plans. For example, the central IT office’s Bureau of Consolidated Computer Services (Computer Services), which was responsible for consolidating the state’s data center operation, had access to a large transition fund that could be used for unanticipated costs that arose during the consolidation effort. This allowed Computer Services to make quick decisions when faced with a roadblock, without having to go to the Office of Budget for each new request. 2288 California State Auditor Report 2002-111 California State Auditor Report 2002-111 2299 The Pennsylvania CIO uses collaborative approaches in other ways as well. He has a board of 18 corporate CIOs from the The Pennsylvania CIO has private sector, which excludes technology service providers a board of 18 corporate to avoid conflicts of interest. As noted by an interviewee in CIOs from the private Virginia, the states can learn a lot from the private sector, and sector, which excludes credibility is enhanced when IT initiatives have the backing of technology service the corporate world. The Pennsylvania group meets quarterly providers to avoid with members of the central IT office to provide advice and act conflicts of interest, that as a sounding board. The state CIO also collaborates with his meets quarterly with peers in other agencies. For instance, he decided early on to members of the central IT form partnerships with his counterparts in the Office of Budget office to provide advice and the Office of Human Resources. His efforts have gone a long and act as a sounding way in establishing the trust of the Office of Budget, which has board. financial authority over projects. It is unusual for the Office of Budget to reject a request supported by the central IT office because of this relationship. The CIO’s relationship with the Office of Human Resources has been advantageous because of its involvement with personnel and training issues. Another important aspect of collaboration exemplified by the Pennsylvania CIO is his emphasis on building coalitions with local governments and explaining successful IT projects in terms of service delivery and benefits to local communities, rather than just the return on investment. For example, Pennsylvania’s Justice Network is a nationally recognized model for interagency sharing of public safety information. The central IT office stressed successes like the number of criminals taken off the streets to illustrate the project’s impact on the community. It also worked hard to get the endorsement of local police departments for the project. This grassroots support makes the selling of IT projects much easier, especially to the legislature, which hears positive feedback from its constituents. The Illinois director of technology also employs strong collaborative methods. Lacking formal authority, he relies mainly on communication and collaboration with state agencies to achieve IT objectives. As in Pennsylvania, Illinois’ director of technology has a board of advisors comprised of agency CIOs. According to the state officials interviewed, this board began as an informal group established to hear complaints, but it now serves a formalized advisory role to the director of technology. The director also serves as facilitator for a seminar series in which agencies share their IT activities with their peers. In addition, he sponsors a popular exhibit hall at the state fair called “Tech Town,” where agencies present to the public how IT is used in government. The exhibit hall also serves 3300 California State Auditor Report 2002-111 California State Auditor Report 2002-111 3311 as a networking and information-sharing activity between agencies as they have the opportunity to learn about how each is using IT. All of these activities facilitate important internal collaboration and information sharing. Executive Control Is Still Needed This does not mean that every decision is based on collaboration or that collaboration is always necessary for successful outcomes. For instance, in Pennsylvania, the governor mandated the use of a single e-mail system and desktop software in an effort to facilitate communication and information sharing across the state. This initiative, called “Commonwealth Connect,” saved Pennsylvanians an estimated $9.2 million in software costs over 3 years and continues to save taxpayers an estimated $9 million a year in productivity gains and related savings, as calculated in a study conducted by Xerox. Standardization of e-mail and desktop software also has facilitated communication and file saving among employees. This initiative was a winner in the National Association of State Chief Information Officers 2001 Recognition Awards for Outstanding Achievement. In another example, Virginia required its Department of Motor Vehicles (Motor Vehicles) to use the Virginia Information Providers Network Authority (VIPnet). As described below, Motor Vehicles was successful in this initiative. Despite the compulsory nature of these projects, in both situ- When Pennsylvania ations the agencies affected by these decisions were given the and Virginia mandated freedom to determine how to implement the directives. This certain IT changes, strategy is consistent with research literature that argues that they gave the agencies teams are motivated to perform when they are given the ends affected by those changes but are allowed to determine the means to achieve those ends. the freedom to determine The literature also states the importance of establishing achiev- how to implement them. able goals and providing organizational resources and support that enable teams to meet their objectives. States With Successful IT Initiatives Demonstrate Commitment to Employees During Major Changes In concert with a collaborative approach, our consultant found leaders who demonstrate a commitment to their employees’ continued employment and career opportunities in states with exemplary IT practices. Virginia offers several examples. For instance, when the state directed Motor Vehicles to participate in VIPnet—a system to provide government information services to state residents and businesses via the Internet—executive 3300 California State Auditor Report 2002-111 California State Auditor Report 2002-111 3311 leadership used the situation as an opportunity to restructure the department and make it more efficient, to cross-train staff, and to implement a new model of customer service. That example of leadership allayed fears about Motor Vehicle employee layoffs across the state. In another example, when the Virginia Department of Taxation began a public/private partnership with its consultant’s staff, the commissioner explained to employees that the change was not about cutting jobs and that all employees were needed to make the project work. Employees were flexible, took on new roles, took advantage of opportunities to learn by working side by side with the consultant’s staff, and ultimately became owners of the project. When a new software system was implemented in Virginia’s Department of Corrections, the department involved By keeping its promise employees through cross-training and open communication, to train and redeploy emphasizing that employees would not lose their jobs. personnel displaced by its consolidation of Similarly in Pennsylvania, when the central IT office decided 23 independent data to consolidate 23 independent data centers into one, it made centers, Pennsylvania’s a commitment to train and redeploy personnel who would be central IT office displaced by the consolidation. The central IT office followed strengthened its credibility. through on this promise, which strengthened its credibility as an entity that keeps its word. A number of interviewees commented that through restruc- turing and retraining, employees gained opportunities to learn new skills. These efforts also freed up personnel to take on new projects, enabling the agencies to accomplish more of their IT objectives. Using a Modular Approach for Statewide IT Initiatives Has Numerous Benefits Another common success factor our consultant identified is using a modular approach when developing and implementing IT initiatives. Pennsylvania uses a concept in which an agency’s vision and guiding principals rather than long-term strategic plans determine projects. An agency can design projects in modules in which benefits are delivered every 90 days. It can stop the full project and still have fully functional pieces with only 3 months of risk invested. This process shows value in a short time, and the ability to demonstrate results fosters 3322 California State Auditor Report 2002-111 California State Auditor Report 2002-111 3333 subsequent employee motivation and support from budget and Using an incremental program people. A specific example is Pennsylvania’s Web portal approach, an agency can for small business owners. The state added a new piece to its design projects in modules Web site every 90 days until it became fully interactive. In 1995 in which benefits are Pennsylvania was one of only three states that did not have such delivered every 90 days, a Web site; by 2001, it had earned second place in Government giving it the ability to Technology’s prestigious “Best of the Web” competition. stop the full project and still have fully functioning This modular approach also applies to the way in which initia- pieces with only three tives are rolled out. For instance, initially Pennsylvania chose a months of risk invested. few key agencies to participate in its Web portal; currently 42 of the 48 state agencies participate in the project. Our consultant also saw examples of this approach in Virginia within specific agencies. For instance, the Department of Taxation undertook a large IT initiative to reengineer its tax collection processes 4 years ago. The reengineering efforts include centralizing functions such as document scanning, customer service, call center operations, and executive offices. The department began by replacing all the existing software with new technology to support reengineered processes in imaging and scanning, followed by an Internet initiative and a customer relations initiative, accounting system changes, and an electronic collections system. The department decided to implement the system in small infrastructure improvements that could be felt by those who used the system—beginning with the aspects of the system that affect customers, then employees, and finally the mainframe component. The department is also in the process of closing all of its field offices except one that will be used as a backup to the tax processing and service center in Richmond. The department began the closure of its field offices as a pilot project, which proved effective. Under the new business structure, auditors and collectors will work from home or go to other agency offices for services such as using conference rooms and teleconferencing. Ultimately, all 250 audit and collection personnel will be mobile. n 3322 California State Auditor Report 2002-111 California State Auditor Report 2002-111 3333 Blank page inserted for reproduction purposes only. 3344 California State Auditor Report 2002-111 California State Auditor Report 2002-111 3355 CHAPTER 3 States Grapple With Some Common Problems That Have No Universal Solutions CHAPTER SUMMARY A variety of information technology (IT) governance models could be made to work in California, given appropriate attention to the common factors for success discussed in the previous chapter. But whichever approach it adopts, the resulting organization and staff must address a number of challenges—the same as those faced in other states—most of which involve making decisions about trade-offs among competing interests and approaches. This process will often involve value judgments with no right or wrong answers, and these decisions will affect the way IT leadership, oversight, and management operates within California government. Two of the most critical challenges are the need to determine the appropriate amount of centralization and the degree of standardization of state IT systems. Economies of scale and consequent cost savings resulting from centralization must be weighed against the potential loss of flexibility and mastery of meeting agency-specific needs. The degree of standardization also has implications for public values such as equity in competitive procurement. The decision to outsource IT operations also poses a challenge in that a state must weigh the benefits of independence from public sector budgetary constraints and the flexibility gained from contractor-provided services against developing over dependence on such services. Of major concern is the deterioration of IT skill levels within state government. California could also put itself at risk by limiting the market from which it purchases services; over time, state operations could become increasingly dependent on that contractor’s continued involvement. Operating in the public sector poses some unique challenges that state governments must face in carrying out their IT operations. One challenge frequently cited by interviewees is the effect of administration turnover on the continuity of the statewide IT vision. The continuous change in elected executive 3344 California State Auditor Report 2002-111 California State Auditor Report 2002-111 3355 leadership that occurs in state government brings changes to policy goals, priorities, and personnel that can disrupt progress on long-term IT initiatives. The lengthy budget cycle and annual rejustification for long- term projects in the public sector can also cause major problems for IT development. By the time projects receive funding, requirements and assumptions may have changed considerably, which in turn requires another round of time-consuming reporting and approvals to amend outdated proposals. The appropriate approach to IT strategic planning is also a common challenge. A state must decide whether to focus on IT alone or develop a business strategy in which the role of IT in achieving business goals is emphasized. Equipment and employees present additional planning challenges. Its IT system will deteriorate if a state fails to establish a workable and regular replacement cycle for equipment. This replacement cycle should be based on an actual statewide inventory; the inventory will also aid in forecasting equipment needs and identifying redundancies and opportunities for consolidation. A state must also plan for employee replacement, especially in light of the impending retirement of older workers who provide increasingly rare specialized knowledge of aging systems and mainframe skills. REGARDLESS OF THE APPROACH CALIFORNIA CHOOSES, IT MUST ADDRESS SIGNIFICANT CHALLENGES Our consultant chose to highlight the challenges the State faces in determining its future IT governance because multiple inter- viewees in California and other states mentioned them and because the sample states have different ways of handling them. Our consultant’s perception from interviews with California’s agencies and departments is that clear, consistent decisions and guidance are needed to address these challenges and reshape the State’s IT policy. California Must Determine the Advantages of Consolidation Versus Meeting Unique Agency Needs Consolidating state IT functions can produce savings in training, education, maintenance, and documentation. For example, both Pennsylvania and New York consolidated, to different degrees, their data centers. Pennsylvania reduced its number of 3366 California State Auditor Report 2002-111 California State Auditor Report 2002-111 3377 data centers from over 20 to one. This state chose to consolidate Pennsylvania reduced its and outsource the operational functions of its data centers but data centers from over retains application development within its departments. State 20 to one, citing the cost officials cited the cost savings of eliminating redundant activities savings of eliminating and the ability to redeploy 200 employees as the consolidation’s redundant activities and benefits. New York, on the other hand, halved the number of the ability to redeploy staff working in its data centers, from 600 to 302. Consolidating 200 employees as the hardware such as servers, switches, and routers can also lead to consolidation’s benefits. less redundancy and spare capacity. Centralizing information security functions is another important example of where consolidation can pay off. According to our consultant, these activities are becoming increasingly complex, requiring specialized skills in firewall configuration, intrusion detection systems, and use of encryption schemes. Security is often only as good as the weakest link in the chain: one entry point into a state’s decentralized system through improper protection can provide access to linked systems and data. A centralized IT office can also provide more extensive career paths for professionals in comparison to smaller agencies within which IT is not a major component of their operations; the same would hold true for a consolidated data center. On the other hand, agencies have unique requirements; differ- ing relationships with their “customers” (state residents and businesses); and information systems with differing hardware, software, and interfaces. A one-size-fits-all policy can limit flexibility and may be inappropriate or costly. Moving from a highly decentralized environment to one of complete centralization is an enormous undertaking. In Virginia, for example, although numerous respondents agreed with the philosophy of consolidating and centralizing IT functions, some reported concern and even fear about the scope of the state’s plans for consolidation. In California, which does not have a history of smooth collaboration among agencies, radical consolidation (especially in the short term) may not be realistic. And, according to our consultant, complete consolidation may not be appropriate in that a one-size-fits-all approach will not meet the needs of all agencies and residents. The challenge is to find the right balance between centralization and decentralization, and to determine the domains in which centralization is appropriate. 3366 California State Auditor Report 2002-111 California State Auditor Report 2002-111 3377 The Most Appropriate Degree of Standardization Must Be Decided A related issue is determining the optimal degree of standardization. Pennsylvania standardized 90 percent of its desktop software and established Microsoft Exchange as its e-mail system. Agencies still maintain their own data and other applications in the way they choose, as long as it is complementary with the standard system. The chief information officer in New York reported similar plans to standardize that state’s office software and e-mail systems. It is unclear whether New York’s plans will be carried through to the level of standardization found in Pennsylvania, but the advantages to doing so include efficiencies in training, help-desk functions, and software maintenance, as well as enabling agencies to exchange documents, spreadsheets, database files, and e-mail. A challenge for standardization is dealing with the tradeoff between cost effectiveness and efficiency versus ensuring A challenge for competitive procurements to foster equity and public trust. standardization is Standardization might mean only one authorized contractor dealing with the tradeoff supplies office automation, e-mail, or database systems, which between cost effectiveness could prompt complaints of favoritism and locking out other and efficiency versus suppliers. These decisions are perhaps even more difficult in ensuring competitive California, with its Silicon Valley full of potential suppliers. procurements to foster Some agencies or employees may resist standardization because equity and public trust. they will need to learn to use different systems, and some may argue that the standard does not meet their particular needs. Once such standardization is instituted, changing to other systems becomes difficult and expensive, requiring the retraining of thousands of government employees. The Balance Between Outsourcing and Developing In-House Competence Must Be Established Pennsylvania and Illinois decided to outsource certain of their IT operations; Pennsylvania outsources all data center operations, and Illinois outsources some. According to our consultant, when a state chooses outsourcing, contractors are not subject to hiring freezes, wage levels, and other government personnel constraints. Contractors can also provide substantial career paths, training and education, and more attractive compensation packages for their staff; and they can respond to changing business needs with more flexibility and speed. Also, by competitively contracting out such services, state governments may pay less than if such operations were 3388 California State Auditor Report 2002-111 California State Auditor Report 2002-111 3399 performed in-house. On the other hand, one interviewee stated that outsourcing offers flexibility but no cost savings and should be used mainly for unique, short-term needs. It is our consultant’s opinion that such outsourcing of vital state IT operations and services has significant disadvantages. For example, over time IT skill levels may atrophy within government, making oversight and monitoring of outsourced operations more difficult. A state could become highly dependent on a contractor that could become insolvent or bankrupt with little warning. State operations become tailored to the specific hardware and operating system configurations of that contractor, making it difficult and expensive to move or migrate to another contractor, or to bring outsourced activities back in-house. These are complex tradeoffs for which statewide guidance and policies should be developed, especially if they involve fundamental IT operations. Based on a model developed by California’s Franchise Tax Board, Virginia has created a public/ private partnership for its tax operations, a self-funded project that gave the state the opportunity to upgrade systems and significantly improve service capabilities without using general fund appropriations. Such partnerships allow states to capitalize on the strengths and expertise of contractors without becoming dependent upon them. Working side by side with members of the partner organization also prevents the deterioration of skills among state IT personnel. California should consider how it might apply or expand this type of model to manage a variety of IT functions. Methods for Measuring Progress in Complex IT Development or Procurement Can Vary According to our consultant, if a new entity is to be given an oversight role in major IT developments, appropriate measures are needed to judge whether or not a project is on target. A key challenge with the oversight role of the Department of Information Technology (DOIT), and potentially any entity taking on this responsibility, is the definition of failure. When should a project be considered a failure? The operating definition is often some predefined variance from the baseline budget or time schedule. Evidence suggests that this variance should be anticipated, partly because users are unable initially to fully anticipate or appreciate the impact of a new technology 3388 California State Auditor Report 2002-111 California State Auditor Report 2002-111 3399 on their task or mission.3 Additionally, other factors beyond the actual implementation of the project can contribute to changes in its cost or time line; these factors include changes in the IT development process prompted by control entities, the level of collaboration among stakeholders when an IT project spans organizational boundaries, and the dynamics of the state and its needs. Finally, the definition of a failed project may be misleading because failed projects can often end up as useful systems, according to our consultant. Clearly, simple measures, such as expenditure of resources or the number of lines of code produced, are not sufficient. Any new oversight entity should give attention to creating other meaningful ways to measure project development and discuss these measures with agencies and departments so that all parties know how oversight will be conducted. Virginia uses a reporting system called “Dashboard” to monitor progress on IT projects. Dashboard is used for projects that are over $1 million, statewide, or otherwise considered critical. Performance data is available to different levels of agency personnel and enables management to take corrective actions before a project is permanently impaired. SOME CHALLENGES ARE GOVERNMENT-SPECIFIC Large-scale IT projects are problematic in the best of circum- stances. They often exceed budgets and schedules in the private sector, and some aspects of the state government setting make successful IT development even more challenging. Two cited by interviewees in this study are political forces influencing the continuity of the IT vision and the lengthy budget cycle in state government. Periodic Turnover of State Administration Affects Continuity of the Statewide Vision An inherent challenge in operating in the public sector is the potential for a change in administration every 4 to 8 years and the resulting shift in the state’s policy priorities and agenda. Although many interviewees expressed the importance of executive-level support for IT, they also noted the negative 3 In military information systems, studies suggest that early point-in-time estimates for systems are often wrong. 4400 California State Auditor Report 2002-111 California State Auditor Report 2002-111 4411 effects of proximity to politics for the advancement of IT goals. The continuous change in management and strategic direction that can accompany new executive leadership creates serious challenges to achieving IT goals. This was cited as a problem in Illinois and Virginia, particularly in the latter because state law precludes the governor from serving successive 4-year terms. Interviewees from both states noted that it usually takes a year for a new administration to become acclimated on the issues. In the last year of a governor’s 4-year term, focus on the agenda may begin to dissipate as personnel anticipate a new administration. Given the time needed to get new IT initiatives started because of long legislative, budget, and procurement processes, stakeholders may be reluctant to respond to new mandates and simply wait out new initiatives pushed by an administration. Although this difficulty will always be present in the public sector, evidence from some states suggests that it is not impossible to make lasting progress toward IT goals. Collaborative initiatives Collaborative initiatives that have gained the buy-in from key stakeholders in client that have gained entities and the legislature and are tied to a strong strategic plan the buy-in from key that shows results may be able to survive political shifts. For stakeholders in client example, in Pennsylvania, interviewees said that the state’s data entities and the center consolidation and outsourcing effort cannot be threatened legislature and are tied because it has shown how it is contributing to the global strategic to a strong strategic plan plan for the state, with proven successes recognized by the may be able to survive agencies. Another strategy is to develop and design projects so political shifts. that they deliver tangible results and demonstrate successes early on. As previously discussed in Chapter 2, the strategy of modular development, starting with prototypes and then producing intermediate deliverables whose success can be assessed, is an effective way to demonstrate the worth of IT projects. A Yearly Budget Cycle Causes Delays and Constraints A strong, recurring theme heard by our consultant during interviews was the negative effect of a rigid yearly government budget cycle on IT developments. This lengthy process almost guarantees that by the time a project receives funding, the assumptions built into the feasibility study report regarding technology to be used, costs of hardware and software, and requirements to be met will have changed. In turn, these changes, when they exceed a modest threshold above or below the original estimate, require additional reporting and paperwork. These, too, enter into the yearly cycle and are in danger of obsolescence by the time they take effect. 4400 California State Auditor Report 2002-111 California State Auditor Report 2002-111 4411 Another factor is that funding is on a yearly basis, increasing the uncertainty that money will be available in later years to Multi-year appropriations complete a longer-term project. and special funds for certain IT costs are two Our consultant’s study of other states provides some alternative of the strategies used by strategies. In Illinois, agencies can be approved for multi-year other states to mitigate appropriations, which frees them from having to justify annual the adverse effects the funding requests for approved projects from the Office of budget process can have Budget. New York, Pennsylvania, and Illinois each have a fund on IT projects. available to give agencies the opportunity to pay for certain kinds of IT costs without having to go through the arduous 18-month budget cycle. THE STATE’S IT LEADERS IDENTIFIED OTHER CHALLENGES FACING CALIFORNIA The State’s IT leaders have identified some of the challenges facing California and the elements they believe are needed for a successful program. They have expressed opinions on the necessity of building executive leadership in IT, considering both an IT and a business strategy, creating a statewide IT inventory, and anticipating the impact that the retirement of a large number of older state employees will have on the State’s IT program. California Needs Executive Support for IT and for Creating a Collaborative Organizational Culture Many of the success factors that exist in other states can be considered challenges for California. Most notably, executive leadership in all of the states visited demonstrated strong continuing support for IT initiatives. In addition, leaders in several of these states have a participative management style, involving personnel from their central IT offices and other agencies in decision making and making full use of advisory boards of experts from the public and private sector to share information and obtain guidance and feedback. These aspects of management style are consistent with good management practice and are important considerations in determining the appropriate organizational structure and processes for the future of IT governance in California. 4422 California State Auditor Report 2002-111 California State Auditor Report 2002-111 4433 A Focus on Business Strategy Must Be Considered Some California interviewees question an overall emphasis on an agency IT plan rather than a strategic business plan in which IT plays a supporting role. They argue that all IT developments should be justified by, and subsumed by, a business plan that concentrates on who the customer or recipient of the service is, how it might be provided, and how this service fits in with larger agency plans and programs. IT is a means to this end, they say, and can only be understood within this larger context. A side effect of concentration on a business strategy is greater emphasis on agencies and departments as business units rather than on a separate IT department or a state IT strategic planning function. Even if a successor to DOIT is created in some form, it should balance the creation of IT-specific plans with agencies’ desires for integrated business plans. The State Needs an IT Inventory and a Workable System for Regular Replacement of Obsolete IT Equipment California currently has no overall inventory of state IT equipment. Without a baseline inventory, it cannot accurately estimate what portion of that inventory needs replacement as part of a normal cycle during coming years. It is also more difficult to find redundancies or extra capacity that could be reallocated. This information is particularly necessary if the State plans to centralize functions or pursue statewide initiatives. Without a baseline In fact, Virginia agencies are currently going through a “due inventory, California diligence” process to document hardware, software, and systems cannot accurately in their first step toward consolidation. estimate what portion of that inventory needs Interviewees in California also expressed frustration that normal, replacement or identify routine replacement of obsolete office automation equipment redundancies or extra such as personal computers involves excessive justification and capacity that needs to paperwork rather than being treated as a normal, predictable be reallocated. process. Any revised IT oversight entity should consider a means to standardize this process, including establishing guidelines for reasonable replacement intervals, thereby eliminating needless delay or paperwork predicated solely on the dollar amount involved. Respondents in Illinois offered this same suggestion. 4422 California State Auditor Report 2002-111 California State Auditor Report 2002-111 4433 A Large Number of the State’s IT Workforce Is Nearing Retirement Most California interviewees mentioned the issue of age in the government’s IT workforce, citing statistics showing the large number of employees eligible for retirement. According to our consultant, retirement of this segment of the workforce raises concern about who will maintain the computer code, much of which is written in outdated languages such as COBOL, that operates many of the State’s older automated business and service applications. Even if it were possible to hire replacement personnel, they are unlikely to have the needed skills or want to learn these increasingly obsolete systems and programming languages. This same problem is being encountered in other states, espe- cially ones such as Illinois, which has an early-out retirement incentive for employees over age 55. Greater reliance on out- sourcing of system operations is a possible solution to this problem, but it comes at the expense of some loss of control, as noted earlier. n 4444 California State Auditor Report 2002-111 California State Auditor Report 2002-111 4455 CHAPTER 4 California Needs to Collaborate on the Governance Structure of Its Information Technology Program Given the State’s increasing reliance on information technology (IT) to execute its varied missions and objectives, the need for what the Legislature and other stakeholders envisioned for the Department of Information Technology still exists today. In a period of resource constraints, it is even more imperative that the power of information technology be focused on effective and efficient provision of services to all Californians. A variety of IT governance models could be made to work in California, given appropriate attention to the success factors outlined in Chapter 2. Whichever approach is adopted, the resulting organization and staff must address a number of challenges. RECOMMENDATIONS The success of a new IT governance structure depends on the support and cooperation of many stakeholders, including the governor’s office, the Legislature, control entities, client entities, and technical entities that will be affected by the IT program. The selection, adoption, and development of a governance structure should, therefore, be a collaborative effort involving stakeholders at all levels. Regardless of the governance model California adopts, it should make sure its IT program includes common success factors and other vital elements by taking the following steps: • Select a chief information officer (CIO) to direct and coordinate the State’s efforts to utilize IT in better providing services to residents and businesses. The governor has already taken a major step in implementing this recommendation by recently appointing a CIO to improve the oversight, procurement, management, and operations of the State’s IT systems. However, to ensure no disruption occurs in the planning and implementation of the goals and objectives of its IT program, the state CIO should be made a permanent position reporting to the governor. 4444 California State Auditor Report 2002-111 California State Auditor Report 2002-111 4455 • Ensure continuous support from executive leaders who are both knowledgeable and champions of IT and emphasize its value for effectively achieving the State’s mission. • Adopt a participative management approach that stresses collaboration and communication between public and private stakeholders and builds teams to facilitate information sharing and decision making. • Provide incentives for agencies and departments that develop effective statewide IT initiatives, including a special revolving fund to be allocated at the discretion of the administering agency to stimulate and promote new cross-agency initiatives. To promote accountability, the administering agency should periodically report on the projects it funds to the Legislature. • Make a commitment to employees during periods of change, particularly in the treatment of state IT employees as new systems and skills are required. Effective retraining programs should be established, and career paths for IT professionals should be developed. • Adopt an evolutionary strategy for IT initiatives stressing modular development and early successes that involve stake- holders in the planning and implementation. Those early successes are vital in establishing credibility and trust upon which the effectiveness of a state IT program depends. • Build regular, collegial relationships among IT stakeholders. Those relationships can help educate stakeholders regarding opportunities, costs, and benefits of new statewide IT initia- tives, share information regarding expected overall IT funding for various agencies and departments, and stimulate shared IT initiatives among several agencies or departments that might allow the sharing of development costs and elimination of redundancies. • Develop a statewide inventory of IT equipment and systems. This inventory would serve as the baseline for understanding yearly costs for installed IT-related systems and services, and for establishing standard cycles and their associated costs and savings for replacing outdated equipment. • Hold regular meetings between the state CIO and public and private sector advisory boards to help in sharing information, assessing future directions of technology, and obtaining 4466 California State Auditor Report 2002-111 California State Auditor Report 2002-111 4477 lessons learned from IT governance within major corporations and nonprofit organizations. These private sector advisory boards should not have members affiliated with entities that are, in fact or potentially, suppliers of IT goods and services to the State. California will also have to make decisions regarding governance structure issues that are common to any statewide IT program, but for which no universal solutions exist. As discussed previously in Chapter 3, this process will often involve trade-offs among competing interests, approaches, and value judgments on questions regarding IT governance with no specifically right answers. Some of the more critical challenges that will need to be considered and addressed include the following: • Determining the role and responsibilities of the state CIO and the amount of authority to vest in that position. Decisions with respect to policy making, project approval and oversight, IT procurement, and operations, will drive the size and nature of the IT governance structure required to accomplish the CIO’s purpose. • Determining the appropriate degree of centralization and consolidation of IT services. For example, the State should consider consolidating its data centers to realize savings in training, education, and maintenance while strengthening system security, avoiding redundancy, and limiting spare capacity. Additionally, such a consolidation would provide enhanced career opportunities to attract and retain IT staff. • Determining the appropriate degree of standardization that should take place in statewide IT applications. • Establishing the proper level of outsourcing for IT activities. • Developing a strategy to mitigate the interruptions and distractions from statewide IT initiatives caused by the periodic turnover of state administrations. • Developing a strategy to mitigate the delays and negative effects caused by the length of the budget cycle on the approval and implementation of IT projects. • Determining the proper balance between the creation of IT-specific strategic plans with the agencies’ desires for integrated business plans furthered by the use of IT. 4466 California State Auditor Report 2002-111 California State Auditor Report 2002-111 4477 • Developing a strategy to minimize the disruption that will be caused by the large number of IT employees with expertise concerning older IT systems and applications that are sched- uled to retire in the near future. If, after collaboration among IT stakeholders, it is decided that a single consolidated IT agency is needed, our consultant, who believes that IT should be centralized in a new state agency, offers the following recommendations. OUR CONSULTANT’S RECOMMENDATIONS FOR A CENTRALIZED IT GOVERNANCE MODEL Our consultant believes that California needs statewide IT system advocacy, planning, and coordination that will require a core cadre of professional IT specialists with significant skills. To achieve these goals, our consultant made recommendations in the following areas: the structure and organization of a new IT agency for the State; and roles and functions to be performed by this agency. The following recommendations portray a gover- nance model that stresses centralized control and substantial consolidation of IT operations. The Governance Structure and Organization of Statewide IT Functions Will Contribute to Its Success Our consultant believes that the State should establish a new agency for information technology. Based on the experiences of other states that the authority and interest of the Office of the Governor in creating momentum behind statewide IT initiatives is significant, California should consider having the new CIO position and the agency report directly to the Office of the Governor, to a cabinet-level office, or otherwise have direct access to the Office of the Governor to demonstrate the importance of IT development. Because other states see benefits of consolidating their data centers—including reduced operating costs through centralization and standardization, the ability to obtain and retain a critical mass of in-house IT expertise, and improved statewide system security—California should consider taking steps to consolidate its data centers. The existing statewide data centers (the Stephen P. Teale Data Center and the Health and Human Services Agency Data Center, for example) would then report directly to the new agency, which should have 4488 California State Auditor Report 2002-111 California State Auditor Report 2002-111 4499 operational authority over statewide IT systems and services. To the extent that the agency can demonstrate savings from consolidation, other data centers could, over time, consolidate with the statewide data centers. To consolidate policy-making functions, provide a single vision for IT in state government, and facilitate the credibility of the new IT agency, the existing office of e-government, now located within the governor’s office, and any future office set up to promote IT initiatives should be placed within the new agency. Among the activities these consolidated offices can perform—most likely in conjunction with advisory committees—is forecasting. These forecasts can help guide IT planning throughout the State’s agencies and departments. The current authority the e-government office has to advise the governor and coordinate with state agencies and departments on the operation of California’s Web portal should reside in the new IT agency. The State should consider that to be successful and respected by the agencies and departments it serves, the new agency will need expert staff with some institutional knowledge of IT in California. The State should, therefore, consider transferring the technical expertise of the existing Technology and Investment Review and Technology Oversight and Security units within the Department of Finance (Finance) to the new agency. Not just the technology charter of these groups, but rather the majority of the technical personnel with the skills and experience existing within those groups should be transferred. With these skilled personnel and statewide data center personnel, the new agency will be properly staffed and positioned to provide technical approval and oversight for major IT development projects. The agency should be responsible for reviewing major initiatives for consistency with the State’s IT strategy and priorities, with existing or planned statewide applications, with technology standards, and with emerging trends based on forecasting. The agency should also review, initially and at follow-up intervals, proposed project management activities and progress measures. The resulting recommendations should be reported to Finance, whose job would be to approve funding, taking into account the new IT agency’s recommendations. Our consultant cautions that, critical to the success of this new statewide IT agency, is having operational authority over the state data centers and transferring the technical expertise now located in the Technology Investment Review and Technology Oversight and Security units within Finance to the new IT agency. 4488 California State Auditor Report 2002-111 California State Auditor Report 2002-111 4499 The State Must Carefully Define the Roles and Functions of a Statewide IT Agency The roles and functions to be performed by the new IT agency should be determined and presented with clarity to mitigate any perception of ambiguity of authority or ineffectiveness on the part of the new agency. Key roles should involve advocacy of statewide initiatives, coordination of activities, and technical approval of major projects and procurements. Among the specific activities that should be given priority by the new IT agency as follows: • Be the “single voice” for advocating and developing statewide IT initiatives. • Develop and promulgate a statewide IT strategy and priorities for improving the performance of the State’s mission. • Provide technology scanning and forecasting functions for the State and its agencies and departments. • Administer a special fund to stimulate and promote new cross-agency initiatives. To promote accountability, the IT agency should periodically report the projects it finances and request replenishment funds from the Legislature. • Stimulate development of significant statewide IT applica- tions, such as initiatives to enhance security of the State’s information systems. Information security and safety is one of the primary statewide IT initiatives that require a high degree of technical skill and coordination, since a weak link in the system may allow access to other agencies’ data and systems. • Establish criteria (such as consistency with the state strategic plan, priorities, and measures it develops to determine the effectiveness or importance of an initiative) by which new IT initiatives are to be judged and approved. Funding decisions on IT-related projects that Finance makes should be justified in terms of these criteria. Lead in developing a statewide inventory of IT equipment and systems. This inventory would serve as the baseline for understanding yearly costs for installed IT-related systems and services, and for establishing standard cycles and their associated costs and savings for replacing outdated equipment. 5500 California State Auditor Report 2002-111 California State Auditor Report 2002-111 5511 We conducted this review under the authority vested in the California State Auditor by Section 8543 et seq. of the California Government Code and according to generally accepted government auditing standards. We limited our review to those areas specified in the audit scope section of this report. Respectfully submitted, ELAINE M. HOWLE State Auditor Date: February 27, 2003 Staff: Doug Cordiner, Audit Principal Norm Calloway, CPA Sang Park Consultant: RAND 5500 California State Auditor Report 2002-111 California State Auditor Report 2002-111 5511 Blank page inserted for reproduction purposes only. 5522 California State Auditor Report 2002-111 California State Auditor Report 2002-111 5533 APPENDIX A Profiles of States Chosen for Review Whose Information Technology Governance Programs Are Successful and Whose Circumstances Are Comparable to California’s New York State Size Rank 3 (2000 U.S. Census) Highest Level State IT New York State Office for Technology Office Reporting Structure The chief information officer (CIO) reports to the Office of the Governor but is not cabinet level. The Office for Technology reports to the CIO, as do other IT-related agencies such as the Office for Cyber Security that are not part of the Office for Technology. Advisory Bodies Two advisory bodies serve the CIO. The CIO Advisory Counsel is comprised of the senior IT leadership of state and local agencies, authorities, and public benefit corporations; it provides feedback on proposed new technologies. The Architecture Board represents stakeholders in statewide systems and advises the CIO on statewide standards for system architecture. Technical Authority The Office for Technology reviews agency IT project proposals and grants technical authority. The CIO is responsible for developing IT policies and developing and implementing strategic plans. (Agencies must prepare strategic plans that are consistent with the state’s plan.) The CIO also decides on standards for basic platforms and statewide technology. Operational Authority The Office for Technology is responsible for the operations of the data centers as well as telecommunications and networks, including e-commerce. It is also responsible for training and mentoring client entities in IT project management. Procurement Authority The Office of General Services is responsible for most procurement. However, the Office for Technology handles IT procurement when many or all agencies are involved. It also reviews smaller IT procurement requests for consistency with planned or existing tools and platforms, and negotiates all IT contractual agreements with vendors. Financial Authority Financial authority rests with the Division of the Budget, which reviews the business case for IT projects and makes funding decisions. The state maintains a $10 million Technology Entrepreneurial Fund from which the CIO and the Office for Technology can pay for certain IT projects without going through the formal budget process. These funds are provided in the form of loans that must be repaid by the borrowing agencies within 5 years. Exemplary Won an award for its e-government Web site, “Government Achievements Without Walls.” 5522 California State Auditor Report 2002-111 California State Auditor Report 2002-111 5533 CONSULTANT’S KEY OBSERVATIONS Procedural Project Planning • Agencies file intent to procure for each proposed project that is reviewed by the IT office; this process is migrating to an annual technology plan for each department or agency. Once implemented, all proposed projects would be included in the annual plan. • The IT office created a project management guidebook that includes project planning. Client entities contributed lessons learned to its development. Approval (technical and budget) • The Office for Technology places projects in three categories: (1) strategic, (2) continuing expenditure, and (3) replacement of aging systems. The IT office decides whether it will grant technical approval based on the status of a project in one of these three categories. • Budget approval authority for IT projects lies solely within the Division of the Budget. Procurement • The Office of General Services has many products such as personal computers that are covered by standing contracts and can be ordered directly. Services or technology can also be obtained on broad, existing contracts. These standing contracts have standard boilerplate terms and conditions, which, if used, speed the procurement process. • A mini-bid process allows vendors to be pre-approved for consulting services. This greatly speeds procurement of such services. Project Oversight Project oversight is primarily the responsibility of client orga- nizations. When interagency coordination is needed, the CIO coordinates project oversight. 5544 California State Auditor Report 2002-111 California State Auditor Report 2002-111 5555 Management Statewide Cross-Agency Governance • The new CIO has plans to consolidate three data centers into one with an additional site for backup (down from 25 in 1998). He also plans to standardize much of the office auto- mation software such as e-mail. • The state has a Technology Entrepreneurial Fund with about $10 million that the Office for Technology can allocate to agencies for certain projects. The funding is provided to agen- cies in the form of loans that must be repaid within 5 years. Strategic Planning The state is using an IT strategic plan of less than five pages that contains a broad description of its desired accomplishments along with the risks and mitigating strategies. Individual agency strategic plans will be required to be much more detailed and will be reviewed by the CIO’s office for consistency with the statewide strategic plan prepared by the IT office. Leadership Style Consolidated control—the CIO believes he has authority from the governor to act boldly in creating standards, centralization, and consistency across agencies and departments, and to eliminate waste and redundancy. Client entities argue that “one size fits all isn’t going to work.” Workforce Issues • New York lost many state employees 55 and older from an early retirement program. • Agencies complain they cannot compete for employees with IT skills, such as those with expertise in database administra- tion or Windows. Technology Infrastructure Development The IT office has an annual budget of about $250 million. Most of the budget is for services provided to and billed to other agencies. About $50 million a year is internal to the Office for Technology. 5544 California State Auditor Report 2002-111 California State Auditor Report 2002-111 5555 VIRGINIA State Size Rank 12 (2000 U.S. Census) Highest Level State IT Secretariat of Technology Office Reporting Structure The secretary of technology is part of the cabinet and reports to the governor. The Secretariat of Technology consists of four agencies, headed by the secretary, which include the Department of Technology Planning, the Department of Information Technology, the Center for Innovative Technology, and the Virginia Information Providers Network Authority. Advisory Bodies Council on Technology Services (COTS) board consists of CIOs of some state agencies and members of local government; it advises the secretary of technology. Advice tends to be conceptual rather than tactical. Some members do not participate on a regular basis; they argue that the COTS board is not as involved as it could be. The CIO advisory board is comprised of CIOs in the private sector and meets infrequently. Technical Authority For projects over $100,000 but less than $1 million, the secretary of technology or designee (usually the Department of Technology Planning) has project approval authority. For projects over $1 million, the secretary of technology must give approval. The secretary of technology has veto power. The Department of Technology Planning sets guidelines for IT development, which is voluntary, as well as standards, which agencies are required to follow. Operational Authority The Department of Information Technology runs the data centers and telecommunications. Procurement Authority The Department of Information Technology has procurement authority for IT purchases. Financial Authority The Office of Budget and Planning has financial authority for IT projects. Exemplary • Received “Best of Breed” award from the Center for Achievements Digital Government for e-government portal in 2002. • Public-private partnerships that encourage innovative IT projects. CONSULTANT’S KEY OBSERVATIONS Procedural Project Planning • Projects are initiated by agencies and submitted to the Department of Technology Planning annually. • The Department of Technology Planning handles statewide strategic planning. 5566 California State Auditor Report 2002-111 California State Auditor Report 2002-111 5577 Procurement Previously agencies handled their own procurement with the Department of General Services. On July 1, 2002, a new law was passed that delegated all IT procurement to the Department of Information Technology. Project Oversight Project oversight is largely decentralized. For large projects, the Department of Technology Planning has oversight responsibility, but it has been inconsistent in fulfilling that responsibility. In some cases, the department was involved from the beginning of the project; in others, it did not become involved until the project was in trouble. Management Currently Decentralized Agencies are responsible for their own equipment and appli- cations. They have access to the Department of Information Technology’s services, but large agencies often have in-house expertise. Strategic Planning • Strategic planning until recently was decentralized. Some agencies regularly update IT strategic plans; others argue that IT should support the business plan. • The secretary of technology recently announced a sweeping strategic plan to centralize all IT resources, systems, and control; it is described as the most ambitious in the country. It will eliminate both the departments of Information Technology and Technology Planning and integrate them with IT personnel and resources from all the state’s agencies (this will involve consolidating 2,300 personnel) into a new IT control agency. Leadership Style Centralized control—the secretary of technology has designed an extensive strategic plan with little input from agency heads and CIOs. His office is drafting legislation to gain increased con- trol over IT policy. Agency IT personnel are concerned about the effects of consolidation on unique agency applications. 5566 California State Auditor Report 2002-111 California State Auditor Report 2002-111 5577 Workforce Issues Some concerns about the number of IT employees eligible for retirement exist, particularly about those with knowledge of older systems. Technology Infrastructure Development • Agencies are responsible for implementation. • Secretary of technology’s office is considering a plan for a statewide fund to assist agencies. Standards The Department of Technology Planning develops guidelines and standards. Guidelines are voluntary unless an agency is rated obsolescent in an IT area. Standards are required, and agencies must determine how to implement them. 5588 California State Auditor Report 2002-111 California State Auditor Report 2002-111 5599 PENNSYLVANIA State Size Rank 6 (2000 U.S. Census) Highest Level State IT Office for Information Technology Office Reporting Structure The CIO, as a deputy secretary, reports to the cabinet- level Office of Administration Secretary. The Office for Information Technology comprised of seven organizational units, reports to the CIO. Advisory Bodies The CIO has an advisory body comprised of 18 private sector CIOs who provide guidance on statewide projects. Technical Authority The Office for Information Technology reviews and approves agency project plans and makes recommendations to the Office of Budget for funding. The Office for Information Technology sets the guiding vision for IT in the state and develops standards for IT products and procedures with substantial feedback from agencies. Operational Authority The Office for Information Technology has operational authority over data centers and basic computer and network infrastructure as well as statewide initiatives. Procurement Authority The cabinet-level Department of General Services is responsible for statewide policies and procedures for procurement. Hardware procurement is managed by the Department of General Services, which maintains a list of prequalified vendors. Small acquisitions are done by agencies themselves from those vendors; large acquisitions are handled by the Department of General Services via bidding to achieve economies of scale. The Department of General Services delegates routine procurement of IT services to the Office for Information Technology, which developed a master services contract and method for prequalifying vendors. Large software and system integration procurements are also delegated to the Office for Information Technology; the Department of General Services helps guide and review the bids and contracts. Financial Authority The Office of Budget has financial authority for IT projects. Although the Office for Information Technology formally has an “advisory role,” in practice the Office of Budget usually concurs with its decisions on IT project approvals. The Office for Information Technology administers a Technology Investment Program that ranges from $20 million to $30 million a year to provide seed money to initiate agency IT initiatives, pilots, and transitions to new systems. Exemplary Received the National Association of State Chief Information Achievements Officers 2001 Recognition Award for Outstanding Achievement for Pennsylvania’s e-mail and software standardization effort, “Commonwealth Connect.” Received “Best of Breed” award from the Center for Digital Government for e-government portal in 2002. Successfully consolidated data centers from 23 to one. Standardized e-mail and desktop applications statewide. 5588 California State Auditor Report 2002-111 California State Auditor Report 2002-111 5599 CONSULTANT’S KEY OBSERVATIONS Procedural Project Planning • IT initiatives for agency-specific applications are planned and managed by agencies but comply with policy planning guides (from Office of the Budget) and IT standards (from the Office for Information Technology). Concept plans and draft budgets are submitted early for feedback, with detailed plans and budgets to follow. • Statewide initiatives may be generated by the Office for Information Technology or from the bottom up when multiple agencies submit concept plans reflecting shared needs. The Office for Information Technology is responsible for statewide projects, with formal guidance from agency representatives. Project Oversight • Agency-specific initiatives are overseen by the agencies; methods vary. • Large or statewide projects require quality assurance by the IT provider with oversight from an advisory body of agency representatives (may use measurable milestones or benchmark against other states). A consulting firm may do an independent review. Management Statewide Governance (“Breaking Through Barriers,” a 1996 strategic plan, announced this aim.) • The Office for Information Technology led consolidation of data centers from 23 to one. It outsources data center opera- tions but retains oversight and management. • The Office for Information Technology standardized desktop technologies and implemented a common, centralized e-mail system; this saves over $9 million a year in technology costs (not including savings on maintenance, support, training and integration). 6600 California State Auditor Report 2002-111 California State Auditor Report 2002-111 6611 • The Office for Information Technology has Technology Investment Program funds—ranging from $20 million to $30 million—to be used as seed money for investing to jump-start agency initiatives, to fund IT pilot projects, and to help with the transition to new systems. Strategic Planning • Although its strategic plan is still a guiding vision, Pennsylvania no longer requires annual strategic plans; invariably, these plans will need mid-course corrections due to rapidly changing technology. Currently, the Office for Information Technology develops brief guiding principles and direction-setting objectives. • Individual agencies vary in approaches. Some agencies regularly update IT strategic plans and others do not, maintaining that strategic plans should focus on mission performance (no need for an IT strategic plan separate from the business strategy). Leadership Style Collaborative and participatory—agency CIOs have “dotted- line” relationships to the state CIO, who meets quarterly with them and also encourages informal communication (open-door policy). Statewide projects have agency representatives on advisory boards with formal voting rights. The state CIO empowers agency CIOs and maintains strong collegial ties to counterparts in the Office of Budget and the Department of General Services. Workforce Issues • Concern over civil service hiring and salary constraints (cannot compete with private sector for IT talent). • The retirement of employees who specialize in mainframes will create problems for maintaining big systems. • Outsourcing of back-end system operations works well, with the Office for Information Technology performing highly skilled oversight. With consulting advice from KPMG, the office decided to consolidate its data centers and outsource the operational functions but keep applications development and ownership in the agencies. However, it continues to 6600 California State Auditor Report 2002-111 California State Auditor Report 2002-111 6611 act as the permanent oversight organization. Back-end functions include mainframe upgrades in hardware, software, and services; data processing and hosting of data processing systems; and backup and security. Technology Infrastructure Development • Centralized funding for statewide projects to accommodate needs of small and large agencies (plus the Technology Investment Program). • Strong push toward modular development (for example, enterprise resource planning modules) and incremental implementation (deploy in selected subsets of agencies over time) to yield steadily growing function and promote positive change fed by small successes visible in relatively short periods. The Enterprise Resource Planning software that Pennsylvania has chosen can, like most such systems, be implemented and used in relatively self-contained but subsequently integratable parts; for example, the financial accounting package might be implemented first, then the payroll system. Standards, Technology Forecasting • Standards (procedural, product-oriented, or hybrids) circulated in draft information technology bulletins by the Office for Information Technology for response before finalization; agency comments can affect the final standard. Standardization is generally welcomed now. • Agencies track IT developments in mission-specific areas by participation in professional societies, use of consulting groups, and benchmarking against counterparts in other states. The Office for Information Technology is charged with promoting IT innovation; a council of private-sector CIOs reviews and comments on proposed new initiatives. 6622 California State Auditor Report 2002-111 California State Auditor Report 2002-111 6633 ILLINOIS State Size Rank 5 (2000 U.S. Census) Highest Level State IT Illinois Technology Office Office Director of technology sits within the Governor’s Office and Reporting Structure reports directly to that office. Advisory Bodies An advisory body of agency CIOs serves the director of technology. Technical Authority Client entities develop IT project proposals with input and guidance from the director of technology, but projects need approval from the Strategic Planning Office and the Office of Performance Review. The Office of Performance Review is responsible for project evaluation. Operational Authority Operational authority for data center services is mostly decentralized; agencies manage (almost) all operations, many of which are outsourced. Procurement Authority Central Management Services has authority for all procurement. Although the director of technology has no authority for procurement, he or she works with Central Management Services in its effort to establish standards that have major implications for procurement. Financial Authority The Bureau of the Budget has authority to approve all funding requests. The director of technology has a $29 million Special IT Project Revolving Fund that can be allocated to agencies for IT projects, which improve customer service or increase the state’s efficiency or economy. Exemplary Received “Digital State” award in 2001 for use of Achievements technology in government. In the few years since its creation, the Illinois Technology Office has managed to complete 22 state-level IT projects. CONSULTANT’S KEY OBSERVATIONS Procedural Project Planning Projects are initiated by agencies with guidance from the direc- tor of technology. Approval (technical and budget) • The Strategic Planning Office and the Office of Performance Review in the Bureau of the Budget must approve projects. • Some projects are approved for multi-year appropriations up-front so agencies do not have to request funds each year. 6622 California State Auditor Report 2002-111 California State Auditor Report 2002-111 6633 Procurement Central Management Services, which is responsible for procure- ment statewide, established master contracts with vendors that reduce the time and effort required by agencies to purchase hardware and software. Project Oversight The Office of Performance Review is responsible for project over- sight. It uses the Illinois Technology Enterprise Planning System, a software system that measures progress on projects by tracking agency IT plans and requests. Management Statewide Governance Across Agencies • The director of technology has a $29 million Special IT Project Revolving Fund that can be allocated to agencies that make a compelling business case for improving customer service or increasing state efficiency or economy. • The director of technology facilitates communication and col- laboration among state agencies by taking the following actions: Formally involving agency CIOs through an advisory board n that meets regularly. Hosting an internal seminar series for agencies to share IT n activities with each other. Sponsoring “Tech Town,” an exhibit hall at the annual state n fair where agencies present to the public how they are using IT to deliver services. Strategic Planning Agencies are required to address IT in their strategic business plans. The Strategic Planning Office integrates these plans into the statewide plan within the Bureau of the Budget (a cabinet- level department). 6644 California State Auditor Report 2002-111 California State Auditor Report 2002-111 6655 Leadership Style • Advocacy—the director of technology has no formal authority but has made progress by brokering strong relationships with the Bureau of the Budget and Central Management Services, the agencies, and the legislature. • Placement of the Illinois Technology Office within the Governor’s Office gives the director of technology access to executive support and the ability to influence in the absence of formal power; the disadvantage of the arrangement is greater susceptibility to political entanglements. Workforce Issues • The state will be losing many employees because of an early retirement initiative. Critical knowledge about older automated systems will be lost, and the ability to hire replacements is in question. • Some look at this initiative as an opportunity to boost innovation in state government. Technology Infrastructure Development • Centrally funded public key infrastructure initiative for use by state agencies. The purpose of this initiative is to establish a statewide infrastructure for facilitating government services by verifying the identity of users and the authenticity of documents. • $29 million Special IT Project Revolving Fund allocated by the director of technology for agency projects that improve customer service or increase the state’s efficiency or economy. Standards, Technology Forecasting • The director of technology established Web accessibility standards for agency Web sites. 6644 California State Auditor Report 2002-111 California State Auditor Report 2002-111 6655 • Master contracts create de facto standards by providing an incentive for agencies to use standard terms and conditions with selected vendors. • The Illinois Technology Office is responsible for identifying appropriate IT procurement standards for the state but has encountered difficulty because of procurement concerns about fairness to all potential vendors. 6666 California State Auditor Report 2002-111 California State Auditor Report 2002-111 6677 APPENDIX B A Summary of the Department of Information Technology’s Progress Toward Implementing the June 2001 Recommendations of the Bureau of State Audits The Bureau of State Audits (bureau) made a variety of recommendations to the Department of Information Technology (DOIT) in its June 2001 report titled Information Technology: The State Needs to Improve the Leadership and Management of Its Information Technology Efforts (report number 2000-118). The table below shows the bureau’s recommendations and DOIT’s progress in implementing those recommendations as of its sunset date of July 1, 2002. After DOIT’s closure, the governor ordered the Department of Finance (Finance) to assume the responsibilities of information technology (IT) oversight and security until a new statewide IT governance strategy could be implemented. Where applicable, we also provide comments related to the former DOIT functions that Finance has assumed. DOIT’S PROGRESS IN IMPLEMENTING RECOMMENDATIONS Recommendations DOIT’s Progress To provide strategic guidance for the Partially implemented. State’s IT activities, DOIT, in conjunction DOIT completed a draft statewide IT plan. with the state departments, the governor, However, its management stated that this the Legislature, Finance, and other plan was still incomplete. relevant parties, needs to update the statewide IT plan to address the current IT environment. In particular, the plan should establish measurable objectives to show how the State intends to reach its goals. Also, the plan should communicate priorities for approval and funding of projects. To facilitate establishing such priorities, DOIT should work in collaboration with the entities previously mentioned. continued on the next page 6666 California State Auditor Report 2002-111 California State Auditor Report 2002-111 6677 Recommendations DOIT’s Progress To ensure departments’ IT strategic Partially implemented. plans are consistently evaluated for DOIT made some progress in developing their compliance with the statewide a way to review departments’ IT strategic IT strategy, DOIT should implement a plans through the use of an enhanced process to review department plans. review checklist. However, after developing this checklist, DOIT granted the departments until August 2002 to bring their strategic plans into compliance. Since the August 2002 deadline was after DOIT’s sunset date, this checklist was never used. To provide appropriate department Implemented. guidance and direction for the IT DOIT developed a framework to manage development process, DOIT should its policies, procedures, and guidelines to consolidate the various sources of update its guidance issued to departments. policy and guidance, remove outdated The framework defined whether such policies from published documents, documents would be maintained in and revise policies as needed to reflect the State Administrative Manual or the changing state needs. In addition, Statewide Information Management DOIT should resolve the contradiction Manual. In addition, DOIT stated that it between its management memorandum had reviewed IT policies, procedures, and and the State Administrative Manual guidelines and provided recommendations over the applicability of the alternative to consolidate or remove specific outdated procurement process. Finally, DOIT documents. However, it did not implement should work with the Department of these recommendations. DOIT rescinded General Services (General Services) to the management memorandum that evaluate the alternative procurement conflicted with the State Administrative process and provide information to Manual and deferred all future policy departments about how the process decisions regarding the alternative could be most effectively used. procurement process to General Services. Finance has eliminated the redundant directives from the above sources and consolidated the remaining sections to provide clearer direction to state agencies and departments for initiating and implementing IT projects. As policy and process revisions become necessary, Finance will make needed changes. DOIT should continue its efforts to Partially implemented. improve its project review and approval DOIT did not ensure it fully documented process. However, it should ensure its project review decisions. In all 12 of that the changes result in a process the projects we reviewed, DOIT could that will subject proposed IT projects not provide evidence that it tracked to a thorough evaluation. Further, the departments’ compliance with the DOIT should ensure that departments conditions it included in its project are properly assessing IT projects by approval letters notifying them of its comparing departments’ feasibility study concerns. reports with established criteria, such as the fundamental decision criteria. Finance’s protocol for project review is Moreover, to ensure that it can defend addressed in its Technology Investment its approval of costly IT projects, DOIT Review handbook. should thoroughly document its approval decisions. 6688 California State Auditor Report 2002-111 California State Auditor Report 2002-111 6699 Recommendations DOIT’s Progress To ensure departments assess and Partially implemented. mitigate project risks, DOIT should DOIT stated that it had enhanced the require complete risk assessment reports risk assessment model and ensured that from departments. Further, DOIT should it applied to all projects, regardless of the properly analyze the responses and procurement process. However, DOIT document how it resolves any concerns. could not provide consistent evidence that Finally, DOIT should require departments it reviewed all the risk assessment models using the alternative procurement that departments submitted. In addition, process to assess risks at the beginning of we could not see a strong link between the their projects. If DOIT believes its current risk-related comments submitted by the model is inappropriate for alternative departments and the risk-related comments procurements, it should modify its risk made by DOIT for those models it did review. assessment model to more appropriately address alternative procurements. In its protocol for IT project approval, Finance has eliminated the requirement for agencies and departments to prepare and submit the risk assessment model developed by DOIT. Rather, Finance has instructed agencies and departments to address project risk in their project feasibility study reports. In addition, Finance developed a framework for IT project management and oversight and released it on February 7, 2003. Risk identification and management is a main focus of the framework. To ensure that it receives and effectively Implemented. uses the proper information to monitor DOIT modified its project status report to departments’ IT projects, DOIT should include approved budget, budget variance, take the following actions: expenditures to date, and planned and • Continue with its efforts to restructure actual start and completion dates for the oversight process to ensure that major project milestones. DOIT adequately the process allows DOIT to properly accounted for these reports. DOIT also monitor and guide projects. modified the project approval letter that • Modify the required progress reports required certain conditions be met. to include two types of critical information: the project’s monthly Finance’s protocol for monitoring project actual costs and revised estimates of status is addressed in the framework it total projected costs compared with issued on February 7, 2003. the budget, and actual and revised projected completion dates for project phases compared with the original schedule. DOIT should use this modified progress reporting to closely monitor projects that may be required to submit special project reports. • Ensure that analysts sufficiently review and document their oversight of projects and track the receipt of required reports. To hold departments accountable Not implemented. for the benefits expected from their DOIT management stated that they did not IT projects, DOIT should ensure that track projects for the purpose of ensuring departments submit post-implementation that departments submitted their post- evaluation reports. Further, DOIT should implementation evaluation documents. continue with its effort to reengineer the evaluation process, including the Finance’s protocol for post-implementation incorporation of lessons learned from evaluation is addressed in the State project development. Information Management Manual and the requirement is reiterated in its project management and oversight framework. continued on the next page 6688 California State Auditor Report 2002-111 California State Auditor Report 2002-111 6699 Recommendations DOIT’s Progress To promote coordination on IT projects Partially implemented. and avoid redundant efforts, DOIT should To fulfill this recommendation, DOIT establish a formal mechanism to initiate facilitated meetings with two groups. discussions between departments that The first was the Information Technology are developing projects based on similar Coordination Council/Enterprise technologies or processes. To facilitate Coordination Council, which consisted this coordination and improve project of agency information officer and chief oversight, DOIT should complete its IT information officer (CIO) workgroup project inventory based on its survey of chairpersons. The second was the CIO departments. DOIT should ensure that meetings. These meetings focused on departments’ reported data are accurate policy decisions. Based on the meeting and should update this information when notes, it appears DOIT used these meetings departments report new information so to get input in developing IT standards that the project inventory stays current. and policies. Although this was a valuable DOIT also needs to consider how activity, it is not consistent with our departments and the Legislature can recommendation that specifically calls for effectively access this information, taking a formal mechanism to initiate discussion into consideration privacy issues and among departments that are developing other concerns that may limit the release projects based on similar technologies of this information. or processes. In addition, DOIT did not complete its IT project inventory. Although it conducted a survey of departments, none of this information had been reviewed for accuracy or completeness at the time of its sunset. Finance does not use permanent formal advisory groups, but convenes advisory groups as necessary to explore IT issues. Finance maintains a listing of only approved IT projects that are reportable. To improve compatibility and properly Partially implemented. guide IT development, DOIT should As of its July 1, 2002, sunset date, DOIT expedite its work on implementing had not developed and issued standards standards by determining which for security, infrastructure, accessibility, standards need to be addressed first and data, or applications development. Rather, focusing its efforts accordingly. Further, it issued general policies for three of the DOIT should work with departments to five categories it identified—security, ensure that all necessary standards have infrastructure, and accessibility. These been implemented. policies offered general objectives but did not provide the standards needed to ensure consistency and compatibility among departments. In its February 2003 framework, Finance has established minimum required practices and processes for project management and oversight, and will assess agencies’ and departments’ adherence to those practices and processes. Finance will develop and issue standards as the need is identified. 7700 California State Auditor Report 2002-111 California State Auditor Report 2002-111 7711 Recommendations DOIT’s Progress To ensure that DOIT is fully employing Implemented. the IT advisory councils and receiving To fulfill this recommendation DOIT the benefits intended by law, DOIT met with three groups: the Information should continue to meet with the private Technology Coordination Council/ commission and the public committee Enterprise Coordination Council, CIOs, on a regular basis to guide its strategic and the California Information Technology planning efforts, provide input on new Commission. Our review of its agendas and policies, and ensure that the State follows notes from those meetings revealed that best practices. DOIT should ensure that DOIT met with these groups on a regular the public committee makes all findings basis (the first two groups served as the and recommendations in writing, as public committees, and the third served required by state law. DOIT should also as the private commission) to receive monitor the progress of its CIO work guidance for its strategic planning efforts groups to ensure that they reach their and input on new policies, and to discuss established goals. best practices issues. Finance does not use permanent formal advisory groups, but convenes advisory groups as necessary to explore IT issues. To ensure that it completes initiatives, Not implemented. DOIT should establish timelines and DOIT management stated that, as of goals for meeting future initiatives. If its July 1, 2002, sunset date, it would DOIT does not believe it can complete cease operations. To protect the State’s initiatives within established guidelines, $1.7 billion IT portfolio, DOIT stated it should communicate its priorities and that the administration was committed resource requirements to the Legislature. to establishing a short-term interim IT In addition, it should notify the oversight agency. This interim agency Legislature when a change in the State’s will continue to assess how to reorganize IT environment prompt adjustments to the operation and management of these priorities or resource requirements. California’s IT systems after July 1, 2002, and will continue to communicate with the Legislature regarding changes in the IT environment that require adjustments to priorities and resources. Finance stated that its current authority addresses only project approval, funding, oversight, and security; not the broader responsibilities associated with DOIT. Within its responsibilities, Finance stated it has established initiatives, priorities, and time frames for their accomplishment. To organize and focus its efforts, DOIT Partially implemented. should adopt an internal strategic plan DOIT management stated that it to identify key responsibilities and completed much of this recommendation establish priorities. This plan should with the publication of its 2001–2004 clearly describe how the organization strategic plan, but it did not complete its would address its many responsibilities, business plan as part of that effort before particularly those that we observed it has its sunset date. not sufficiently accomplished. Further, it should build on past efforts to the extent possible rather than reinventing processes and practices when planning its future activities. 7700 California State Auditor Report 2002-111 California State Auditor Report 2002-111 7711 Blank page inserted for reproduction purposes only. 7722 California State Auditor Report 2002-111 California State Auditor Report 2002-111 7733 Agency’s comments provided as text only. State Chief Information Officer 1400 10th Street Sacramento, CA 95814 February 13, 2003 Ms. Elaine M. Howle* California State Auditor Bureau of State Audits 555 Capitol Mall, Suite 300 Sacramento, CA 95814 Dear Ms. Howle: Thank you for the opportunity to comment on your report, “Information Technology: Control Structures Are Only Part of Successful IT Governance.” I find the report to be an extremely comprehensive and useful study listing many of the challenges the State confronts in effectively and efficiently managing its information technology resources. The study is thus an excellent starting point for discussion of these issues by the State’s policy-makers. The comparison to governance structures in selected other states is also useful, if only because it presents some alternative models for further consideration. However, I would caution against too great a reliance upon the experience in other states without considering constitutional, structural and organizational differences between states. Constitutional, structural and organizational 1 differences may have a substantial impact upon the success of any particular governance model, and we need an IT governance structure that will work well in the context of California’s somewhat unique governmental structure. I agree with your recommendations regarding the need for a State chief information officer to lead and coordinate the State’s IT programs, the benefits of a participative management approach that stresses collaboration and communication, and the commitment to the State’s workforce during periods of change. These elements are part and parcel of my own recommendation to the Governor for the State’s IT governance structure, a copy of which I am attaching to this letter.† While I don’t necessarily disagree with your other suggestions, I am not prepared at this point to express full agreement without further discussions. A few words on each of these recommendations will suggest to you my concerns, some of which you very well may share. *California State Auditor’s comments appear on page 75. †We have not included this attachment in the report; however, it is available for review at the Bureau of State Audits. 7722 California State Auditor Report 2002-111 California State Auditor Report 2002-111 7733 2 First, it is not clear to me that the State needs to establish a revolving fund for IT initiatives right now, although this is a topic I have certainly been examining. At a minimum, before we start making money available through such a fund, we need to agree upon statewide IT strategies so that what- ever money is made available through such a fund is spent pursuing common goals. Second, it is not clear to me that an evolutionary strategy for IT initiatives is always the best approach. As a general matter, I prefer incremental to revolutionary change, particularly since incremental approaches tend to be less risky. But the rate of organizational change is driven by many factors, and we also have to be relentlessly opportunistic in driving change when those opportunities present themselves. Adopting an inflexible policy of incremental change may unnecessarily interfere with much needed reforms. To the extent that this recommendation is focused upon the issue of establishing a modular approach to project development as a strategy for reducing the risk of project failure, I certainly can express my agreement in principle with that philosophy. Projects often can be broken into smaller, more manageable pieces, and statewide projects usually will benefit from staged implementation, including pilot projects and incremental rollout. 2 Third, I am concerned that directing resources right now to develop a comprehensive statewide inventory of IT equipment and systems may not be the wisest allocation of our scarce resources. This was not something which DOIT was able to accomplish even with its much more substantial staffing over a period of years. More important, an inventory divorced from strategic business planning is not likely to be as useful as an inventory that is part of a more focused, particularized planning effort. No doubt you would agree with this observation, and that may have been the spirit in which your recommendation was made. Unfortunately, in my experience, a stand-alone requirement for an inventory almost guarantees that creating the inventory will become an end in itself, and I am reluctant to go down that road prematurely. The remainder of your recommendations highlight many of the critical issues that will need to be addressed as we consider adopting a new governance structure. I agree that these are some of the issues deserving attention. Indeed, each of these issues arises periodically in my discussions with the State’s IT leadership. I want to congratulate you, your team and your consultant upon concluding such a comprehensive report in such a comparatively short period of time. This is a huge topic, and your report does a fine job of making the subject matter accessible and moving the discussion forward. Sincerely, (Signed by: J . Clark Kelso) J. Clark Kelso Chief Information Officer State of California 7744 California State Auditor Report 2002-111 California State Auditor Report 2002-111 7755 COMMENTS California State Auditor’s Comments on the Response From the State Chief Information Officer To provide clarity and perspective, we are commenting on the state chief information officer’s response to our audit report. The numbers below correspond to the number we have placed in the response. 1 As we clearly state on pages 35 and 45, a variety of models could be made to work in California. What we provided were success factors that were common among the states reviewed—irrespective of their constitutional, structural, or organizational differences. 2 We did not intend to imply that all of our recommendations should be enacted immediately. However, we feel that all of these elements are important and should be part of whatever model is eventually adopted by the State. 7744 California State Auditor Report 2002-111 California State Auditor Report 2002-111 7755 Blank page inserted for reproduction purposes only. 7766 California State Auditor Report 2002-111 California State Auditor Report 2002-111 7777 Agency’s comments provided as text only. Department of Finance 915 L Street Sacramento, CA 95814 February 11, 2003 Ms. Elaine M. Howle State Auditor Bureau of State Audits 555 Capitol Mall, Suite 300 Sacramento, CA 95814 Dear Ms. Howle: Thank you for the opportunity to review and comment on your audit “Information Technology: Control Structures Are Only Part of Successful IT Governance”. Our review encompassed parts of Chapters One and Four, and Appendix B. In Chapter Four, your consultant recommends that if a single consolidated Information Technology (IT) agency is needed, the new agency will require expert staff with institutional knowledge in order to be successful and respected. The consultant then suggests transferring the technical expertise of Finance’s Technology Investment Review and Technology Oversight and Security units to the new agency. Beyond the obvious questions raised by the proposed creation of a new bureaucracy, I note that the expertise of these units is essential to the work done by the Department of Finance. The staff in these units conduct business case and investment reviews of IT proposals and also recommend appropriate funding levels. IT funding decisions are an integral component of the state’s fiscal planning; removing this expertise from Finance would impede our ability to make comprehensive statewide funding proposals. In Appendix B, the report mentions Finance’s IT Project Management and Oversight Framework several times. We were very pleased to share a copy of the Framework with your staff on February 6, 2003; the Framework was published statewide on February 7, 2003. This Framework provides a consistent statewide standard for effective project management and oversight and will be used by Finance to assess the technology management and oversight practices of departments and agencies. We agree that successful use of technology is important to the state, and we value having a strong IT governance structure in place to develop appropriate strategies for the future. We look forward to discussing a permanent IT governance structure and will thoughtfully consider the ideas your report proposes. If you have any questions, please contact Debbie Leibrock, Chief of the Technology Investment and Review and Technology Oversight and Security Units at 445-1777 extension 3202. Sincerely, (Signed by: Steve Peace) Steve Peace Director, Department of Finance 7766 California State Auditor Report 2002-111 California State Auditor Report 2002-111 7777 cc: Members of the Legislature Office of the Lieutenant Governor Milton Marks Commission on California State Government Organization and Economy Department of Finance Attorney General State Controller State Treasurer Legislative Analyst Senate Office of Research California Research Bureau Capitol Press 7788 California State Auditor Report 2002-111