CSA
Summary
Read the report at California State Auditor ↗
REPORT BY THE STATE AUDITOR
OF CALIFORNIA
THE STATE NEEDS TO REENGINEER ITS
MANAGEMENT OF INFORMATION TECHNOLOGY
94022 DECEMBER 1994
The State Needs To Reengineer Its
Management of Information Technology
94022, December 1994
California State Auditor
Bureau of State Audits
Table of Contents
Page
Summary S-1
Introduction 1
Chapter
1 The Office of Information Technology’s
Statewide Leadership Is Ineffective 7
2 The Office of Information Technology’s
Oversight of Projects Is Limited 27
3 The State’s Current Information Technology
Program Does Not Work and
Needs To Be Reengineered 41
Response to
the Audit Department of Finance 59
California State Auditor’s Comments on the
Response From the Department of Finance 91
Summary
Results in Brief The State’s use of information technology has increased steadily over
the years and now must be considered one of the State’s most critical
investments. The State currently spends an estimated $1.3 billion
annually on information technology. The Office of Information
Technology (OIT) within the Department of Finance is the office that
has overall responsibility for the State’s information technology
investment.
The State’s current model for managing statewide information
technology does not work. The OIT has not provided the statewide
leadership and coordination for information technology as intended by
the 1983 legislation that established the office. Additionally, the
41
OIT’s oversight of information technology projects is limited and does
not ensure that state departments implement projects successfully.
Specifically, we noted the following:
The OIT has been ineffective in its role of providing statewide
leadership. Statewide leadership, which includes coordination
activities, is critical as California significantly expands its
investment and reliance on information technology. The OIT has
not provided sufficient guidance for the State’s decentralized
information technology environment, it has provided only limited
assistance in designing and implementing information technology
projects, and it has provided limited leadership for personnel and
training matters. Additionally, the OIT has failed to effectively
coordinate multi-agency projects and data center activities and is
not currently ensuring that the State’s information technology
community is involved in developing policy.
These problems have occurred because the OIT has narrowly
interpreted its enabling legislation in such a way that it effectively
limited its authority over information technology matters.
Additionally, the OIT’s resources have not kept pace with the
growth in the State’s information technology, and the OIT has
chosen to focus these limited resources on budgetary oversight
rather than statewide leadership.
42
The OIT’s oversight of projects is limited to reviewing documents
that it requires departments sponsoring the projects to submit.
However, the OIT does not verify the accuracy of the information
in the reports it receives. Additionally, the scope of the OIT’s
document review is limited. It views itself as an “investment
committee” to ensure that proposed projects are reasonable
investments of public funds. The OIT does not do an in-depth
technical review of a project’s viability, nor does it assess the
individual qualifications of key staff members assigned to projects
to ensure that they have the appropriate skills and experience for the
particular project. Further, the OIT does not ensure that
departments adhere to the conditions it believes are essential to the
success of projects. It has further limited its review by relying on
an exception reporting system as the primary mechanism for the
ongoing oversight. Finally, the OIT is most effective before the
funding for the project is approved. Once a project is underway,
and problems begin to surface, it is difficult for the OIT to
successfully intervene on the project.
The State’s Because of these deficiencies, the State must reengineer the entire
Information statewide information technology program to ensure that the State’s
Technology interests and assets are protected and used to their maximum potential.
To initiate the reengineering process, the State should establish a
Program Needs To
statewide chief information officer (CIO) position. The CIO should
Be Reengineered
serve as a member of the governor’s cabinet and head a new statewide
information resources office.
The CIO and the information resources office should be given the
powers, duties, and responsibilities to develop and implement a
statewide plan for information technology. They should provide
leadership and guidance to departments, manage and coordinate
statewide resources, and monitor and oversee projects based on a risk
assessment. In addition, the State should reevaluate the commitment
of resources for managing its information technology. Finally, the
State will need to address the statutory changes necessary to complete
the reengineering process, and the proposed CIO will need to
implement appropriate procedural changes.
Agency In its response, the Department of Finance (DOF) states that there are
Comments many issues throughout the audit report with which it agrees.
However, the DOF also responds that it has a number of fundamental,
philosophical differences with us on how to manage information
technology in the State as well as a few specific disagreements. In
particular, the DOF is concerned about the balance between centralized
versus decentralized control of information technology projects.
43
Although the DOF believes that it is now appropriate to reconsider how
the State manages its computer and telecommunications technologies, it
also believes that the OIT has met its assigned responsibilities and
made substantial contributions to the State’s successes in using
information technology. Our comments follow the response from the
DOF.
44
Blank page inserted for reproduction purposes only.
Introduction
The State’s use of information technology has increased steadily over
the years and now must be considered one of the State’s most critical
investments. The State currently spends an estimated $1.3 billion
annually on information technology. The California Government
Code, Section 11702, defines information technology as all
computerized and auxiliary automated information handling, including
such items as systems design and analysis, conversion of data,
computer programming, and related communications. Information
technology is pervasive throughout state government, with some
departments totally dependent on automated systems to perform their
fundamental responsibilities. The use of information technology in the
State will increase as departments continue to identify more efficient
and effective ways of providing services using limited resources.
Currently, information technology management in the State is highly
decentralized. Generally, departments determine their needs and the
means of fulfilling those needs. Individual departments manage
projects to develop new information systems. However, certain
entities have statewide information technology responsibilities. The
Office of Information Technology (OIT) has statewide authority and
responsibility for the leadership and oversight of information
technology management, and the Department of General Services has
oversight responsibility for procuring any goods and services acquired
as part of an information technology project.
The information technology environment within the State is diverse
because of the different computing systems among departments.
Additionally, over the years, departments have moved from centralized
computing on large mainframes for many of their applications to
smaller, yet powerful, computers within departments. A significant
volume of the State’s computer use is now decentralized through the
use of microcomputers including personal computers and local area
networks managed by individual departments.
Furthermore, various data centers provide processing services within
the State; however, only two are very large general purpose centers
45
serving multiple clients. These data centers are the Stephen P. Teale
Data Center and the Health and Welfare Agency Data Center.
The OIT’s The OIT is the office that has overall responsibility for the State’s
Responsibilities information technology program. The Government Code provides the
OIT with broad statutory responsibility and authority to guide the
State’s use of information technology. Its responsibilities encompass
three areas: leadership, coordination, and oversight.
The OIT was created in 1983 as an office within the Department of
Finance. Previously, the State Office of Information Technology, with
different overall authority and responsibilities, existed within the
Department of Finance. The Government Code, Section 11700, which
expresses the legislative intent for the OIT, states that a need existed to
consolidate and integrate the State’s policy and planning for
information technology to ensure coordination of the State’s needs.
The purpose of the OIT, as defined by the statute, is to identify new
applications for information technology, improve productivity and
services to clients, and assist agencies in designing and implementing
the use of information technology.
The statutes require the OIT to have various leadership and
coordination responsibilities, including developing plans and policies to
support and promote the use of innovative information technologies.
The Legislature’s intent was that there be specific objectives and
definitive policies to guide the development of information technology
systems, procedures, and techniques. It was also legislative intent that
the plans encompass such objectives as providing for the optimum use
of equipment and the maximum practical integration of systems.
Additionally, the plans are to address the objective of ensuring
appropriate compatibility of systems and interchange of data and
information. Further, the Government Code specifically requires the
OIT to develop coordinated plans and policies for the state data centers;
information management personnel, including the training and
qualifications of such personnel; and office automation, including the
use of personal computing and electronic mail. The statutes also state
that it is the Legislature’s intent that the OIT director be the State’s
advocate for information technology to increase the effectiveness and
efficiency of government services.
Additionally, the statutes require the OIT to have oversight
responsibilities. The Government Code requires the OIT to adopt
policies to carry out budgeting and expenditure control responsibilities.
These policies must be published in the State Administrative Manual.
The OIT is to approve proposed expenditures only if these policies and
procedures have been followed.
The OIT’s responsibility for information technology extends to most
state departments. However, the statutes exclude several entities,
46
including the University of California, the California State University,
and the Legislature, from the OIT’s oversight.
The OIT’s According to the Government Code, Section 11710, the director of
Resources the OIT is appointed by the governor and reports to the
director of the Department of Finance. The OIT has had one director
since the inception of the office in 1983. An acting director was in
charge of the OIT from September 1989 through March 1991, at which
time the former director returned.
The OIT currently has 16 staff members. In addition to the director,
the staff consists of one deputy director, nine analysts who oversee
department plans and projects, two staff members in a planning and
policy unit, one office automation specialist, and two administrative
staff members. The OIT’s budget for fiscal year 1994-95 is
$1.96 million.
Recent Concerns Recent events have generated concern over the State’s management and
Regarding the use of information technology. For example, in 1994, the Department
State’s Management of Motor Vehicles (DMV) terminated its database redevelopment
of Its Information project because of significant unresolved problems and deficiencies
Technology Projects after spending more than $49 million. Additionally, a consultant for
the California Student Aid Commission (commission) issued a report in
June 1994 that evaluated the commission’s financial aid processing
system implemented in 1993 and concluded that the $50.9 million
system was flawed and would not meet the commission’s needs.
Finally, several of the State’s major information technology projects
currently under development have experienced significant schedule
delays and cost increases, indicating that there may be more trouble in
the future. These problems have raised concerns regarding the
management of these projects as well as the effectiveness of the OIT.
In August 1994, we issued a report on our audit of the DMV’s database
redevelopment project. The following are several problems we noted:
The DMV continued to implement the project despite significant
unresolved problems and deficiencies that led to the project’s
ultimate failure.
47
The DMV spent $34.6 million on the project unnecessarily because
it progressed beyond the developmental stages of the project
without accomplishing the objectives of each stage and resolving
significant technical problems.
The OIT continued to recommend additional funding for the project
even though the DMV had not followed approved policies and
plans to minimize financial risk to the State.
In May and June 1994, the legislative analyst issued two reports critical
of the OIT. In one of these reports, the legislative analyst
recommended that legislation be enacted to transfer responsibility for
statewide information technology leadership and oversight to a new
office reporting to the governor. Additionally, in the other report, the
legislative analyst made various recommendations to improve oversight
and coordination of information technology projects and to enable
departments to use information technology more effectively.
In response to problems identified at the DMV and other departments,
the governor created a Task Force on Government Technology Policy
and Procurement made up of individuals from the private sector with
management expertise in technology and information systems. The
governor directed the task force to review the State’s information and
technology procurement practices and the manner in which the State
plans for, manages, and oversees the development of information
systems. In September 1994, the task force issued its report after a
60-day review. In its report, the task force concluded that major
reforms were needed to the processes by which the State
purchases and manages information technology. Among the task
force’s recommendations were the elimination of the OIT and the
creation of a new chief information officer, who would report directly
to the governor to develop and oversee a statewide information
technology infrastructure.
Scope and The Budget Act of 1994 (budget act) requires the Bureau of State
Methodology Audits to conduct a management review of the OIT. Specifically, the
budget act requires us to review and evaluate the processes used by the
OIT for reviewing information technology projects and purchases and
to evaluate the degree to which the OIT provides statewide oversight,
coordination, and leadership, as well as effective uses of
information technology. Further, the budget act requires us to make
recommendations for necessary statutory and procedural changes.
Our review is limited to the OIT and its role, responsibilities, and
authority over the State’s information technology operations.
Accordingly, we did not review the Department of General Services’
48
role in managing procurements, nor did we review information
maintained at departments related to projects under the oversight of the
OIT.
To determine whether the OIT has established policies and procedures
that are in accordance with statutory requirements, we reviewed the
California Government Code, the State Administrative Manual, and
OIT publications. Additionally, we interviewed the director, the
deputy director, and current and former OIT staff members. Further,
we interviewed officials at various departments that interact with the
OIT.
To determine whether the OIT has consistently followed its established
policies and procedures and to assess the extent to which the OIT’s
current policies and procedures have allowed problems to continue, we
reviewed project files that the OIT maintained for some of the State’s
largest information technology projects. A project file contains
documents required by the OIT, such as the feasibility study report,
subsequent reports submitted by the department related to the progress
of a project, and budget change proposals. Additionally, a project file
contains the OIT’s analyses of these documents as well as any
correspondence.
We interviewed officials from other states to compare their approach
toward managing their states’ information technology needs with the
approach used by California. Additionally, we reviewed publications
issued by the U.S. General Accounting Office on managing information
technology.
49
Blank page inserted for reproduction purposes only
Chapter 1 The Office of Information Technology’s
Statewide Leadership Is Ineffective
Chapter Statewide leadership is critical as California significantly expands its
Summary investment and reliance on information technology. This leadership is
needed to ensure that the State’s information technology interests and
assets are protected and used to their maximum potential.
However, the Office of Information Technology (OIT), the office
responsible for this leadership, has been ineffective in this role. The
OIT has not provided sufficient guidance for the State’s decentralized
information technology environment, it has provided only limited
assistance in designing and implementing information technology
projects, and it has provided limited leadership for personnel and
training matters. Additionally, the OIT has failed to effectively
coordinate multi-agency projects and data center activities, and it is not
currently ensuring that the State’s information technology community
is involved in developing policy.
This has occurred because the OIT has narrowly interpreted its
enabling legislation in such a way that it effectively limited its authority
over information technology matters. Additionally, the OIT’s
resources have not kept pace with the growth in the State’s information
technology, and the OIT has chosen to focus these limited resources on
budgetary oversight rather than on statewide leadership.
As a result, the State has not benefited from a coordinated approach to
managing information technology; departments have not received
sufficient support and guidance in the design, implementation, and
operation of information technology projects; and multi-agency
information technology projects and data center activities are left
without statewide direction and collaboration.
50
This lack of information technology leadership has left California
without an effective statewide direction to promote needed innovation,
advocacy, and use of information technology resources.
The OIT The Government Code assigns the director of the OIT responsibility for
Provides Limited leadership of information technology in the State. These statutes
provide the OIT with broad statutory responsibility and authority for a
Statewide
comprehensive range of leadership activities, including coordination.
Leadership
The OIT is responsible for developing plans and policies to support and
promote the use of innovative information technologies, and for
guiding the development of information technology systems and
procedures. The plans are to address such objectives as ensuring that
equipment is used optimally, systems are integrated to the maximum
practical extent, and systems and interchange of data are appropriately
compatible.
Additionally, the Government Code specifically requires the OIT to
develop coordinated plans and policies for the state data centers;
information management personnel, including the training and
qualifications of such personnel; and office automation, including the
use of personal computing and electronic mail. Further, the statutes
state that the Legislature intends the director of the OIT to be the
State’s advocate for information technology to increase the
effectiveness and efficiency of government services.
It is essential that the State have effective statewide leadership as it
significantly expands its investment and reliance on information
technology. This leadership is needed to ensure that the State’s
interests and assets are protected and used to their maximum potential.
Insufficient Guidance
The OIT has limited its direction of information technology to
establishing broad policies and has not provided the guidance necessary
to ensure that statewide interests are met. State law grants the OIT the
authority for overall leadership of the State’s information technology
program. However, under the OIT, the State’s information technology
program has become highly decentralized, lacking a coordinated
approach to managing its information technology needs. Because OIT
chose not to exercise strong leadership and guidance, California’s
information technology program reflects the direction of individual
departments rather than the State as a whole. Without sufficient
state-level guidance in a decentralized environment, the State lacks
assurance that it is implementing information technology in the most
cost-beneficial manner. For example, departments may be using
51
resources to solve problems that other departments have already solved.
Additionally, the State lacks assurance that it delivers necessary
services in the most effective way.
The OIT considers the management of information technology in the
State to be primarily the responsibility of individual departments. In
developing statewide policy, one of the OIT’s considerations has been
to respect the management authority of the departments. Thus, by
design, the OIT has limited its direction to establishing broad policies,
rather than specifically directing departments to manage their
information technology operations in a particular manner.
The OIT views its role as providing a policy structure that helps
departments effectively use information technology, yet allows enough
flexibility for departments to develop the management they need.
Through its policies established in the State Administrative Manual, the
OIT intends that departments follow proven management practices in
planning, developing, acquiring, and using applications of information
technology. However, although the departments are required to follow
certain policies, the existing policy structure allows departments a
significant amount of discretion with regard to how they manage their
information technology needs without considering the State’s overall
program. For example, as the OIT noted in its publication entitled
“Managing Information in California State Government,” it imposes
few constraints on how departments determine their needs or fulfill
them.
The OIT allows even more flexibility in the area of personal computers.
The OIT views personal computers and related networks as
commodities to be controlled by rules that differ from the rules applied
to larger systems or systems requiring moderate to extensive
development. The OIT delegates full authority to departments to
acquire and oversee the use of personal computers and related networks
as long as the department adopts a policy that is in accordance with the
model policy established by the OIT. Such an approach allows
significant diversity within and among state departments and provides
limited assurance that such diversity is cost beneficial.
Generally, the OIT has provided high-level guidance on how
departments should manage their information technology projects. For
example, from October 1987 through May 1989, the OIT issued a
series of guideline publications on topics ranging from how to conduct
a feasibility study to how to manage an information technology project.
The OIT also periodically issues a newsletter that provides general
information for the State’s information technology personnel.
Additionally, the office periodically issues state-level planning
documents. The OIT’s most recent planning document, issued in
1993, summarizes general visions for information technology uses in
52
the State over the next six years and general strategies to improve the
use of information technology in the State. However, the planning
document does not contain an implementation component regarding
how certain strategies should be implemented, including assignments of
responsibility and measurements for successful implementation.
We spoke to information technology officials at several departments
and found general agreement at the larger departments that the current
guidance provided by the OIT was not meeting their needs. For
example, officials at some of the larger departments found the OIT’s
publications to be so general that they were of limited value.
However, it appears that these publications may be more useful to
smaller departments that do not have considerable information
technology and management expertise.
The OIT has recently advocated a strategic planning emphasis and has
required departments to develop strategic plans for information
technology. Strategic planning emphasizes the development of
business strategies to support a department’s mission and a plan for
information technology to support these business strategies.
Generally, the departments we spoke to like the strategic planning
emphasis. For example, according to an official at one department, the
OIT’s requirement that its information technology plan be based on a
strategic business plan was the best advocacy the OIT had done to help
that department with its information technology. However, other
officials thought that the six-year statewide plan that presented the
State’s strategic direction contained good general information but did
not go far enough. For example, one official commented that without
an implementation plan, the document lacked a working solution to the
State’s information technology problems.
The OIT also has been reluctant to provide specific direction, such as
state-level standards. Generally, the OIT has preferred to let the
vendor marketplace determine standards. According to the director of
the OIT, it adopted this philosophy to avoid overregulation of
information technology in the State based on the goal of not falling
behind new technologies.
As an alternative to formal standards, the OIT in 1991 planned to issue
a series of guideline publications, known as preferred practices, to
assist departments in making informed choices about key technologies
and management practices. The preferred practice publications were
to document recommended professional practices for a single aspect of
information management or the application of a specific information
technology. The OIT envisioned the preferred practices as
benchmarks against which state agencies could assess and plan their
own management practices. Additionally, the OIT planned to consider
the extent to which departments adopted these practices or their
53
equivalent as one factor in determining the nature and level of
delegation of approval authority that it granted the departments.
However, the OIT was unsuccessful in implementing its preferred
practice program. After issuing one publication on computer-aided
systems engineering in June 1992, the OIT discontinued the preferred
practice program in fiscal year 1992-93 because of funding reductions.
The OIT’s position on standards can also be illustrated by how it has
approached the State’s electronic mail needs over the years. The
Government Code, Section 11712, requires that the State develop plans
and policies for electronic mail; however, the OIT has not provided
specific direction in this area. In March 1986, the OIT reported that a
cost and benefit analysis supported the creation of a statewide
electronic mail system and that the implementation plan would be
completed during 1986. The OIT hired an outside consultant who
prepared a feasibility study; however, the system was not implemented.
In 1992, the subject of electronic mail came up again when a
subcommittee for the California Forum on Information Technology, an
advisory group for the OIT, planned to establish standards and
guidelines for acquiring electronic mail systems for the State.
However, the subcommittee did not carry out its plan, and as discussed
later, the State subsequently eliminated the California Forum on
Information Technology. The OIT now believes that a statewide
standard is unnecessary because many of the state departments use one
system and vendors of other systems have developed “gateways” that
allow these systems to communicate with the system most in use.
Thus, the OIT believes that an appropriate de facto, or informal,
standard evolved from the marketplace without OIT intervention.
However, although this flexibility may satisfy a department’s internal
electronic mail needs, a process dependent on gateways may not be the
most efficient and effective method for communications and document
transfer between departments.
In its 1993 six-year statewide plan, the OIT acknowledges that adopting
statewide standards may now be in the State’s interest in certain
functions and technologies. For example, the OIT points to imaging as
an emerging technology that will have a substantial impact on
government operations. The OIT further states that the State has a
one-time opportunity to establish a standard that will ensure
interagency compatibility and assist individual agencies in adopting an
approach to imaging that will meet their long-term needs. However,
the OIT sees its role in this area as being limited primarily to
monitoring the standards as they emerge and supporting the successful
adoption of standards rather than setting the standards.
Generally, officials we spoke to at various departments thought that the
OIT should provide more specific direction and, in some instances,
54
standards. A few officials commented that the lack of an electronic
mail standard hinders departments from efficiently and effectively
communicating with each other. Another official stated that the OIT
should at least advocate a few standard methodologies for project and
system development with explanations of the types of environments in
which each methodology is best applied.
Limited Assistance to Departments
According to the legislative intent stated in the Government Code,
Section 11700, one of the purposes of the OIT was to assist agencies in
designing and implementing the use of information technology.
However, the assistance that the OIT provides in the design and
implementation of information technology is very limited. Because
the OIT has focused its limited resources on reviewing required
documents, such as feasibility study reports and budget change
proposals, the OIT’s assistance is limited primarily to guidance related
to specific documents it reviews. Staff members do not spend the time
at an agency that would enable them to thoroughly understand an
agency’s business needs and operations, and even though they can
provide some assistance on the projects they review, it is limited.
In the first few years of its existence, the OIT had a small consulting
unit. The purpose of the consulting unit was to directly assist state
agencies with information technology management issues, complex
procurement issues, and vendor negotiation strategies. Additionally,
the unit was to assist department management in analyzing feasibility
and evaluating alternatives for highly complex or sensitive projects.
However, in November 1985, the OIT eliminated this consulting unit
because it believed it needed to redirect its resources to its ongoing
analysis and oversight of projects proposed by state agencies, a
workload that had increased significantly. After that time, the OIT no
longer dedicated specific staff members to provide consulting support.
Instead, the analysts reviewing documents submitted by the
departments provided informal assistance to the departments on those
projects. The OIT’s ability to provide useful assistance was affected
further by staff reductions during early fiscal year 1992-93. According
to the director of the OIT, after the staff cuts, the remaining staff
members focused their efforts primarily on processing required
documents. He stated that any existing consulting or advocacy
programs and any proactive involvement with departments by the OIT
took on secondary importance, and thus these efforts were cut back.
Another purpose of the OIT, as defined by the legislative intent
contained in the Government Code, Section 11700, was to identify new
55
applications for information technology. However, the OIT sees its
role as supporting effective new applications for information
technology rather than identifying them as they are required to do.
According to the OIT’s deputy director, the identification of new
applications is primarily the departments’ responsibility because the
OIT believes technology decisions should be made as they relate to the
departments’ business needs, not for technology’s sake alone. He
added, however, that the OIT has encouraged departments in a number
of ways to explore the opportunities with new technologies and pointed
to presentations by the OIT’s director. Additionally, one of the ways
in which the OIT believes that it has supported new applications is
through its sponsorship of legislation for advanced technology projects
in 1988. This legislation authorizes the State to participate with
private industry and other government organizations in developing
promising new technologies and requires the OIT to establish policy for
these advanced technology projects.
However, even the OIT’s ability to effectively support new applications
for information technology is limited. The OIT’s ability to provide
meaningful guidance regarding the use of new technologies is
questionable considering the office’s inability to effectively keep
abreast of emerging technologies. Although OIT staff members may
try to stay current with developments in technology through
publications and other means, the formal training that is provided to
them is minimal. The OIT currently does not have a formal training
plan, and its training budget for fiscal year 1994-95 is $4,000 with
some additional funds for conferences available from the Department
of Finance’s budget.
56
Multi-Agency Projects Are Not
Effectively Coordinated
One of the reasons that the Legislature created the OIT was to ensure
coordination of the State’s information technology needs. The OIT
has been unable to successfully coordinate multi-agency projects.
Further, the high-level group that the governor formed two years ago to
provide the coordination that the OIT believed it was unable to provide,
has been ineffective.
Multi-agency projects are of critical importance because opportunities
exist for reducing costs and improving services through applications of
information technology that can be successfully addressed only through
the combined efforts of multiple agencies. In a memorandum on the
topic, the OIT director recognized the importance of multi-agency
projects, citing the State’s need to maximize return on investment by
reducing duplication of effort and realizing savings through economies
of scale, as well as the need to create statewide shared databases,
consolidated communications networks, and standard user interfaces.
Although the OIT recognizes the coordination of multi-agency projects
as one of its responsibilities authorized by statute, the director
acknowledged that the OIT has never been able to successfully
coordinate multi-agency projects. He stated that he believes the OIT
lacks sufficient statutory authority to coordinate the projects.
Additionally, the OIT’s deputy director stated that the OIT has no
authority to mandate coordination and that the OIT cannot carry out
this role without the cooperation of department directors and cabinet
secretaries. In the absence of such coordination, specific legislation has
been required to achieve commitment from various departments. For
example, the electronic funds transfer project arose out of legislation
that required the Board of Equalization, the Franchise Tax Board, and
the Employment Development Department to study the feasibility of
electronic funds transfer and report to the Legislature.
Because the OIT did not believe that it could successfully coordinate
multi-agency projects, it recommended that the governor designate
responsibility for coordinating multi-agency projects to a cabinet-level
committee consisting of agency undersecretaries. In October 1992, the
governor issued an executive order that established the Multi-Agency
Information Management Authority (MAIMA), comprising the
undersecretaries of all cabinet-level agencies and the chief deputy
director of the Governor’s Office of Planning and Research. The
MAIMA was to provide continuing leadership within state government
for the identification, initiation, and implementation of multi-agency
projects and was to report on its status in October 1993.
57
However, the MAIMA has not proven to be an effective mechanism for
coordinating these projects. According to the chief deputy director of
the Office of Planning and Research, MAIMA meetings were held in
conjunction with the regular weekly undersecretaries’ meetings. Over
several months, the group received roughly a dozen presentations about
information technology issues. He further stated that the group was an
experimental attempt to develop a strategic vision for the State’s
information technology. However, the group concluded after several
discussions that it lacked the expertise for setting high-level
information technology policy. In the opinion of the chief deputy
director, more experienced specialists with strategic, not technical,
information technology achievements were needed, particularly from
the private sector. As a result of this decision and because of other
problems in the State’s management of information technology, the
governor created the Task Force on Government Technology Policy
and Procurement (task force). The chief deputy director stated that the
MAIMA report called for in the October 1992 executive order was
deemed to add little value and was canceled.
According to the May 1994 executive order that created it, the governor
directed the task force to review the State’s information and technology
procurement practices and the manner in which the State plans for,
manages, and oversees the development of information systems. In
September 1994, the task force issued its report. As part of the
restructuring it recommended, the task force advocated the creation of a
new chief information officer whose responsibilities would include
coordinating multi-agency projects. However, the task force, which
was a one-time effort, does not by itself represent an ongoing
mechanism for coordinating multi-agency projects and thus was not an
effective replacement for the MAIMA in this regard.
As a result of the OIT’s and the MAIMA’s ineffectiveness, the State
continues to have a leadership void with regard to coordinating
multi-agency projects. Therefore, the State is not managing
multi-agency projects in the most effective manner. Additionally,
other opportunities for effective multi-agency projects may exist that
are not recognized.
58
Data Center Activities Are Not
Effectively Coordinated
The data centers represent a significant information technology
resource that is not being effectively coordinated at the state level.
Instead, the State’s two primary data centers, the Stephen P. Teale Data
Center (Teale) and the Health and Welfare Agency Data Center
(HWDC) are generally allowed to operate as independent entities
without overall coordination by the OIT. Further, the State continues
to have data centers in individual departments. No overall analysis has
been done regarding the degree to which the existing data centers
should be consolidated or coordinated or the degree to which the State
would be better off using private data center services.
The Government Code, Section 11712, requires the OIT to develop
coordinated plans and policies for the state data centers; however, the
OIT’s involvement with the State’s two primary data centers is limited.
The OIT has established broad guidelines in the State Administrative
Manual, Section 4982.2, with regard to data center management, such
as the requirement that the data centers operate on a break-even cost
basis, charging its users based on a published rate schedule. Further,
in the State Administrative Manual, Section 4982.1, the OIT has
provided guidelines as to the data center that departments can use
unless otherwise approved by the OIT. However, beyond these
policies, the OIT’s involvement with the data centers generally relates
to feasibility study reports and other documents that departments and
the data centers submit when departments are using data center
services.
The OIT’s director believes that the OIT does not have sufficient
authority to coordinate data center projects or assist in the planning for
the data centers; thus, it assisted only in developing broad policy for the
data centers. Further, he stated that both the Teale and the HWDC
tended to be very independent and not open to the OIT’s involvement
or the OIT’s review of documents submitted by the data centers.
The OIT acknowledges that there are issues regarding the data centers
that need to be addressed. The OIT’s deputy director stated that the
OIT believes a study of the merits of consolidating the data centers and
sending some of their workload to private data centers should be
conducted, although the OIT does not believe that savings from
consolidating the State’s two primary data centers would be substantial.
However, the deputy director believes that consolidation of data centers
other than Teale and HWDC would be beneficial. According to the
deputy director, the OIT believes that significant economies of scale
could be achieved by eliminating the separate mainframe operations
from departments such as the Department of Transportation, the Board
59
of Equalization, the State Treasurer, and the Public Employees’
Retirement System.
In addition to these issues, other items warrant attention. According to
the OIT’s deputy director, the data centers often wish to have complete
service offerings, although it would be less expensive to offer a
particular service at only one data center. He stated, however, that the
OIT’s ability to determine which services the data centers offer is
limited to its influence during the budget process. Additionally,
although the OIT outlined a policy in the State Administrative Manual
requiring the data centers to charge for their services based on
published rate schedules, there is no assurance that the data centers do
so.
For example, during previous audits of Teale, the Bureau of State
Audits and the Office of the Auditor General reported that Teale did
not always charge state agencies for services provided based on its
published rate schedule. Specifically, for fiscal year 1991-92, we
reported that Teale had made an arrangement with the Governor’s
Office to charge a rate of $250 per telecommunication line, as opposed
to the published rate of $905 per line. As a result of the decreased
rate, we estimated in June 1994 that Teale undercharged the Governor’s
Office approximately $94,300 during fiscal years 1991-92 through
1993-94. Additionally, for fiscal years 1987-88 through 1990-91, the
Office of the Auditor General reported that Teale undercharged the
Department of Motor Vehicles for conversion processing and database
redevelopment services by approximately $14 million. To the extent
that certain agencies are undercharged for services, other agencies are
overcharged for services because all costs are borne by the agencies for
which Teale provides services. During its audit of Teale for fiscal year
1992-93, the Bureau of State Audits found that Teale had not made any
attempts to collect the amounts undercharged in previous years or
refund amounts overcharged to other agencies, although the data center
significantly reduced its published rates twice during fiscal year
1993-94.
60
Limited Leadership for Personnel
and Training Matters
The State’s ability to respond to new opportunities in information
technology depends on the capabilities of its employees. As a result, it
is critical that the State have the necessary leadership in the areas of
training and qualifications of information technology personnel.
However, the OIT has provided limited leadership for personnel and
training matters.
The OIT shares its responsibility for these issues
with other departments. For example, the Department of Personnel
Administration (DPA) and the State Personnel Board have primary
responsibilities for personnel matters. Additionally, the State EDP
Education Program within the Department of General Services
conducts classes on information management software and issues.
However, the OIT’s enabling legislation clearly intended for the OIT to
provide leadership in these areas. The Government Code,
Section 11712, requires the OIT director to develop coordinated plans
and policies regarding information management personnel, including
the training and qualifications of such personnel.
The OIT has provided only limited input in these areas. In the State
Administrative Manual, Sections 4852 and 4854, the OIT states its
belief that training and personnel development are primarily the
responsibility of line management and that each department is
responsible for identifying needs, establishing priorities, and
implementing training. The OIT’s policy is to provide guidance for
the identification of needed skills and the development of a training
plan. The OIT will assist departments in determining their staffing or
training needs. However, this assistance is provided only if requested
by the departments.
Additionally, the OIT’s guidance for personnel control agencies is
limited. For example, according to a senior manager within the DPA,
the DPA consults with the OIT approximately once a month about
high-level position classification issues as they relate to the complexity
of the information technology environment; the DPA does not discuss
recruitment or retention issues with the OIT. Additionally, the chief of
the Departmental Services Division of the State Personnel Board
indicated that the board has not had any interaction with the OIT on
matters relating to the State’s personnel system for information
technology for at least four years. At that time, the OIT and the State
Personnel Board addressed personnel classifications and examinations.
The OIT also provides only limited guidance on training issues to the
Department of General Services. The Information Technology and
Education Center (ITEC) is the office within the Department of
61
General Services that oversees the State EDP Education Program.
According to the general manager of the ITEC, the OIT has informal
discussions with the ITEC approximately every few months that are
usually of a general nature and focus on state personnel training needs
relative to the OIT’s observations. The general manager of the ITEC
stated that the OIT worked more closely with the ITEC when the OIT
recently revised the planning process to emphasize strategic planning.
During this effort, the OIT assisted the ITEC in implementing the
master service agreements with planning consultants so that expertise
would be available if departments needed assistance with strategic
planning. Additionally, the OIT states that its staff members
periodically teach classes. This typically occurs after the OIT has
revised policy.
In the past, the OIT was more involved with personnel and training
matters through its advisory group, the California Forum on
Information Technology (CFIT). For example, in 1989, a CFIT
subcommittee conducted a study on various issues within data
processing management development and made recommendations,
including the creation of a data processing manager’s training academy
that was implemented subsequently. Additionally, the CFIT drafted
allocation guidelines to determine the appropriate level for proposed
data processing positions. These guidelines were implemented in
1988. However, as discussed later, the CFIT was eliminated, and thus
the OIT no longer has this group as a resource to address personnel and
training matters.
The OIT has recognized that there are personnel and training needs to
be addressed. For example, in 1991, the OIT planned to work on a
project to refine staffing guidelines for information technology
classifications based on their contribution to departmental productivity.
However, according to the OIT’s chief of strategic planning and
education, this effort was postponed because neither the OIT nor the
DPA had the resources to undertake a project of this magnitude.
Further, in its statewide planning document issued in July 1993, the
OIT identified five different tasks it should work on with other
departments during the subsequent six-year period. The list includes
conducting a review of the recruitment and retention of information
technology personnel and developing a program to broaden training
opportunities available to information technology staff.
State’s Information Technology Community
Not Currently Involved in Policy Development
62
The OIT currently does not have an effective mechanism for involving
the State’s information technology community in developing policy.
The State eliminated an advisory group that previously existed, and
neither the OIT nor any other group has been able to fill the void.
As part of the legislation that created the OIT in 1983, the Legislature
authorized the creation of a user committee consisting of
representatives from various departments who were knowledgeable
about information technology. The purpose of the user committee was
to provide guidance and input to the OIT’s director and other state
officials, to identify barriers preventing the optimum use of information
technology and management techniques, and to recommend necessary
changes in policy. In 1983, the director of the OIT recommended that
the CFIT be created and invited representatives from all state
departments to participate. An executive group of 20 to 25 members
met more often than the entire CFIT and was the actual working group.
The OIT’s director was the permanent, nonvoting chairman of the CFIT
and its executive committee.
The CFIT fulfilled various roles. In addition to providing advice on
policy to the OIT’s director, the CFIT meetings also provided an
opportunity for state information technology personnel to communicate
on issues and thus provided a level of coordination within the State’s
information technology community that did not otherwise exist.
Additionally, the CFIT represented a pool of information technology
expertise that could be used to study issues of importance to the State’s
information technology personnel.
Although the OIT considered the CFIT to be a valuable resource for
achieving its objectives, the CFIT was eliminated in 1993. In response
to legislation, the Department of Finance conducted a review of
boards, commissions, and similar bodies existing within the State to
determine whether the State could eliminate these entities. The
Department of Finance concluded that the CFIT was one of the entities
that could be eliminated because other groups provided advice.
According to the director of the OIT, the Department of General
Services’ Information Technology Customer Council and MAIMA
were left in place, thereby justifying the elimination of the CFIT.
According to its statement of purpose, the Information Technology
Customer Council advises the Department of General Services
concerning opportunities for improving its information technology,
programs, policies, and procedures. Additionally, an annual Executive
Institute Seminar is held to address challenges facing information
technology executives. However, neither of these groups serves as an
advisory group to the OIT. Further, as discussed previously, the
MAIMA has not been effective. Generally, there is agreement among
the information technology personnel we spoke to, including the
director of the OIT, that a group similar to the CFIT is needed.
63
The Reasons for The OIT has not been effective at providing leadership for information
the OIT’s technology in the State for several reasons. Specifically, the OIT has
narrowly interpreted its enabling legislation in such a way that it
Ineffectiveness
effectively limited its authority over information technology matters.
Additionally, the OIT’s resources have not kept pace with the State’s
information technology growth, and the OIT has focused its limited
resources on budgetary oversight.
Enabling Legislation Narrowly Interpreted
The OIT’s interpretation of the statutes that set forth its responsibilities
has played a key role in how the office has carried out its
responsibilities. Generally, the OIT has limited its role to the
provisions outlining the director’s specific responsibilities and not the
more broadly focused intent language related to the purpose of the OIT.
Specifically, the intended purpose of the OIT, as defined by the
statutes, included such responsibilities as identifying new applications
for information technology and assisting agencies in designing and
implementing the use of information technology. According to the
director of the OIT, he believed that the individual statutes addressing
the director’s responsibilities better outlined the OIT’s role than did the
broader statute describing the purpose of the OIT. As a result, the OIT
focused more on the specific provisions outlining the director’s
responsibilities.
Additionally, the OIT’s interpretation of its ability to carry out its
statutory responsibilities influenced how the office operated.
Specifically, although the OIT recognizes that the statutes give it
certain planning and coordination responsibilities, the OIT does not
believe that the statutes give it sufficient authority to mandate the
cooperation of other state departments. For example, the Government
Code, Section 11712, requires the OIT director to develop coordinated
plans and policies for the state data centers. However, the OIT does
not believe that it has the authority to be more than minimally involved
in planning for the data centers. Additionally, one of the reasons the
Legislature created the OIT was to ensure coordination of the State’s
information technology needs, and statutes gave the director authority
to develop necessary plans and policies. However, again, the OIT
does not believe it has sufficient authority to coordinate projects
involving more than one department. The OIT deputy director stated
that the OIT believes it does not have the authority to direct any
department to operate in any particular manner.
64
The OIT considers information technology to be a support function for
departments’ business decisions. Thus, according to the director, the
OIT interpreted its enabling legislation to favor decentralized
responsibility to departments for recognizing and managing projects,
but centralized control over decisions to invest state monies in
proposed activities.
Although the OIT had the option of recommending changes to the
statutes that outlined the office’s responsibilities, it has not exercised
this option. The Government Code, Section 11711, requires the
director to recommend to the governor, Legislature, Department of
General Services, and Department of Finance changes needed in state
policies to accomplish the purposes of the law. The director of the
OIT indicated that he did not attempt to change the overall legislation
or his interpretation of the legislation over the years because there had
not been any indication from external bodies that there was a need to do
so.
Resources Have Not Kept Pace With Growth
Since the OIT was created in 1983, the amount of money the State has
spent on information technology has steadily increased. According to
the OIT’s records, in fiscal year 1983-84, the State’s executive branch
spent almost $490 million on information technology, including
telecommunications. By fiscal year 1992-93, the amount had
increased to approximately $1.2 billion and is expected to reach
$1.3 billion during fiscal year 1994-95, a growth of approximately
165 percent. Additionally, the technology itself has grown
increasingly more complex over that period.
The OIT’s resources have not kept pace with the growth in the State’s
information technology spending. In fiscal year 1983-84, the first year
after the OIT was created, the office was authorized for 15 positions.
Over the ensuing four years, the number of authorized positions
increased until it reached 28, a level it maintained from fiscal year
1987-88 through fiscal year 1991-92. However, during the first few
months of fiscal year 1992-93, because of General Fund reductions, the
Department of Finance reduced the OIT’s authorized positions by
40 percent. The OIT currently is authorized to be staffed with 17
positions, 16 of which are filled.
Figure 1 presents a comparison of the change in the OIT’s authorized
positions with the State’s executive branch expenditures for the fiscal
years 1983-84 though 1994-95.
65
Comparison of OIT’s Authorized Positions
With Executive Branch Expenditures
for Information Technology for the
Fiscal Years 1983-84 Through 1994-95
50
45
40
35
30
25
20
15
10
5
0
66
snoitisoP
48-3891 58-4891 68-5891 78-6891 88-7891 98-8891 09-9891 19-0991 29-1991 39-2991 49-3991 59-4991
$1,400
$1,200
$1,000
$800
$600
$400
$200
$0
)snoilliM
nI(
Figure 1
a
a
a
Authorized Positions Executive Branch Expenditures
a Executive branch expenditures for fiscal years 1993-94 and 1994-95 are estimated.
Source: OIT records, Salaries and Wages Supplements, Department of Finance Changes in
Authorized Positions, and Legislative Analyst.
Limited Resources Focused on Budgetary Oversight
Because its resources were limited, the OIT made decisions regarding
its most critical priorities and determined that its role was primarily to
support the State’s budget process. Thus, the OIT considers its most
critical priority to be analyzing department documents that affect the
budget process, and the OIT focuses on the oversight tasks associated
with review of these documents.
Especially after the OIT’s significant staff cuts in fiscal year 1992-93,
the remaining staff members primarily focused their efforts on
processing required documents, and the OIT cut back its leadership
efforts. For example, since the staff cutbacks, the OIT has not issued
any more publications or revised any of the existing publications that
were designed to provide guidance to departments. It did, however,
issue its 1993 state-level planning document and has revised policy in
the State Administrative Manual since then.
A review of the existing organization of the OIT also illustrates the
secondary role that leadership has in the office. The staff consists
primarily of analysts for which analysis of required documents takes
the majority of their time. Only two staff members work in its
planning and policy unit.
Limited Because of the OIT’s limited leadership, state departments are not
Leadership Has receiving the guidance and support they need to effectively manage
their information technology projects. Additionally, there is no
Resulted in
assurance that departments are implementing information technology in
Projects Without
a manner that is in accordance with a state vision and best meets the
Statewide
needs of the State. The extent to which the State benefits from its
Coordination, information technology investment depends on the ability of
Support, or departments to effectively use information technology. Certain state
Guidance departments currently have considerable expertise, whereas others do
not. However, all departments would benefit from improved
leadership at the state level.
Under the current process, the OIT provides high-level guidance but
does not get actively involved in the departments’ projects beyond the
analysis it performs on the documents it reviews. Thus, because staff
members do not thoroughly understand the departments’ business and
operations, the assistance they provide is of limited use. It may not be
effective to have each department attempt to implement information
technology projects without the appropriate state-level guidance. For
example, under the current process, departments may be using
resources to solve problems that other departments have already solved.
Additionally, departments may continue to use inefficient processes
because department management may not be aware of a better
methodology. Further, because of the limited leadership, departments
67
lack an understanding of the State’s vision, and the State has limited
assurance that the departments’ implementation of information
technology is consistent with its vision.
In addition to the effect of the OIT’s limited leadership on individual
departments, the State lacks assurance that it is implementing
information technology, when considering the State’s resources as a
whole, in the most cost-beneficial manner. There is limited assurance
that the State does not have duplicative systems, facilities, and
equipment. Additionally, because of the limited leadership, the State
lacks assurance that it delivers necessary services in the most effective
way.
68
]
Blank page inserted for reproduction purposes only.
Chapter 2 The Office of Information Technology’s
Oversight of Projects Is Limited
Chapter The failure of the database redevelopment project at the Department of
Summary Motor Vehicles (DMV) and the problems that have plagued other
information technology projects of state departments have raised
questions about the effectiveness of the Office of Information
Technology’s (OIT) oversight of the State’s information technology
projects. In our August 1994 report “The Department of Motor
Vehicles and the Office of Information Technology Did Not Minimize
the State’s Financial Risk in the Database Redevelopment Project,” we
concluded that the OIT should not have recommended continued
funding for the database redevelopment project when the DMV did not
follow the State’s approved policies designed to minimize risk. The
DMV ultimately terminated the project because of significant
unresolved problems and deficiencies after spending more than
$49 million. On another project, the California Student Aid
Commission (commission) already faces the need to evaluate
alternatives to its $50.9 million financial aid processing system
implemented in 1993 in light of its consultant’s conclusion that the
system is flawed and will not meet the commission’s needs.
The effectiveness of the OIT’s oversight of information technology
projects is hampered by gaps in the oversight system. Also, the design
of certain parts of the oversight system is flawed. The OIT’s review of
projects is limited to the review of the documents that the departments
sponsoring the projects are required to submit to the OIT. OIT
analysts spend little time at the departments where the projects are
being managed. Therefore, the OIT’s impact on each project is limited
to those points in the process in which it is required to approve a
particular document. Even though the OIT’s oversight depends so
heavily on the review of the documents it receives from the
69
departments, the OIT does not verify the accuracy of the information in
the reports it receives.
Added to these shortcomings is the fact that the scope of the OIT’s
document review is limited. The OIT views itself as an investment
committee to ensure that proposed projects are reasonable investments
of public funds. It does not do an in-depth technical review of a
project’s viability. Also, it does not assess the individual
qualifications of the staff members assigned to projects, including the
project manager and key technical staff members, to ensure that these
individuals have the appropriate skills and experience for the particular
project. Further, the OIT has not shown an ability to enforce specific
conditions it sometimes imposes on departments at the feasibility report
and special project reporting stages of a project.
The OIT has further limited its review by relying on an exception
reporting system as the primary mechanism for the ongoing oversight
of projects. Specifically, if a project is beginning to experience budget
variances or schedule delays, the sponsoring department is required to
submit a special project report to the OIT. In our view, this special
project reporting process is flawed because the OIT depends on the
department’s “good faith” to submit the special project report.
The OIT has acknowledged that its oversight role has been most
effective at the outset of a project before the funding has been
approved. At this stage, the sponsoring department is seeking the
OIT’s approval of the feasibility study report and is seeking funding
approval for the project. Authorization of new funding for a project
requires the approval of both the OIT and the Department of Finance’s
budget unit. However, once a project is underway and problems begin
to surface, it is difficult for the OIT to intervene successfully.
The OIT’s In accordance with Section 11731 of the Government Code, the OIT is
Oversight responsible for adopting policies and providing guidance to carry out
the budgeting and control of expenditures for electronic data
Responsibilities
processing. This code section also states that the OIT must approve
proposed expenditures for electronic data processing only if the
departments have followed the established policies and procedures
published and maintained in the State Administrative Manual. The
State Administrative Manual sets forth guidelines that departments are
to follow in identifying the need for information technology projects, as
well as assessing the feasibility of such projects. The State
Administrative Manual also guides departments in overseeing and
evaluating information technology projects.
The departments sponsoring information technology projects are
required to submit feasibility study reports, special project reports, and
70
other reports to the OIT. The OIT oversees the projects through its
review of information included in the various reports, as well as
through discussions with departmental staff. Also, the OIT’s role
includes recommending budget augmentations to the Department of
Finance’s budget units. These recommendations, once approved by
the budget units, the governor, and the Legislature, allow departments
to obtain the funding necessary to complete their projects.
OIT Project Approval and Review Process
Once a department has identified the need for a new information
technology project, it must, except under specified circumstances,
complete a feasibility study of the project and document the results of
the study in a feasibility study report. The report must supply enough
technical detail to show that the project is workable. If the OIT is to
review a project, the OIT receives the report. However, the OIT does
not review all information technology projects. In certain instances,
the OIT has exercised its discretion to delegate to the department’s
director the responsibility of reviewing the feasibility study report.
Nonetheless, whether it is the OIT or a department director reviewing
the report, the information provided is required to identify the reasons
for undertaking the project and to analyze its costs and benefits. For
projects in which the OIT retained its responsibility for oversight, if the
OIT determines that the department has established a strong business
case for investment of state resources in the project, the OIT may
approve the project, approve the project on some modified basis, or
approve the project subject to conditions.
The OIT’s review of a feasibility study report focuses first on the
technical viability of the proposed project. The OIT determines the
prudence of spending public funds on the project by questioning
whether the proposed technology addresses the department’s business
needs. If the OIT concludes that the technology is viable, based on the
department’s presentation in its report, the OIT then reviews the fiscal
viability of the project. The feasibility study report includes a
cost-benefit analysis that compares the project’s expected benefits with
the costs of implementation and operation. If the OIT concludes that
the project’s benefits are sufficient relative to the project’s costs, it
approves the project.
71
Project Reporting
Until recently, the OIT required sponsoring departments to submit
project reports each quarter. The quarterly project report would briefly
summarize the status of the project, explaining any minor deviations
from the original project plan. The report also would contain an
updated project management schedule showing actual completion dates
of specific tasks or deliverables. In its 1994 revision to the reporting
requirements for information technology projects, the OIT eliminated
the requirement for quarterly reports.
Although the requirement to prepare quarterly reports has been
eliminated, the OIT continues to require other periodic reports that
enable it to monitor the project’s progress. For all projects subject to
OIT oversight in which the project milestones, costs, or benefits change
by 10 percent or more, the department is required to submit a special
project report identifying the significant change in the project and the
reason for the change. The OIT reviews those projects to determine if
the cause of the change appears reasonable.
Additionally, for each project the OIT considers to be major, the OIT
requires the sponsoring department to submit an annual status report
(special project report), which is a comprehensive assessment of the
project’s progress. The OIT may designate any large project as a
major project, and when it does so it notifies the sponsoring department
of the designation. According to the State Administrative Manual, the
OIT considers several factors when designating a project as a major
project, including risk to the State, implementation costs, and the
technology employed. Also, if the project is to be implemented over
multiple years it is likely to be considered a major project.
Oversight The OIT’s review of information technology projects is limited to the
Limited to documents that the departments sponsoring projects are required to
submit. OIT analysts spend little of their time at the departments
Document
where the projects are managed. Therefore, the OIT’s impact on each
Review Only
project is limited to those points in the process when the OIT is
required to approve a specific document.
Also, the OIT’s effectiveness is limited by the accuracy of the
documents it receives from departments. However, the OIT does not
verify the accuracy of the information in the feasibility study reports or
the special project reports. These reports, especially the feasibility
study reports, describe the business problem the department is
attempting to address with information technology, the technology
alternative selected to address the problem, an economic analysis of
each alternative considered, and the costs and benefits of the
72
technology selected over the life of the project. This information is
critical to the OIT’s oversight because it is the basis for the OIT’s
approval of the project and often for the commitment of millions of
dollars of state or federal funds. However, the OIT does not verify the
accuracy of this information. Instead, the OIT may ask for additional
information from the department to assess the overall reasonableness of
the project. Beyond that, the OIT relies on the “good faith” of the
sponsoring departments to provide accurate data in their reports. This
is a risky approach for the oversight of information technology projects.
For example, in a 1990 special project report to the OIT, the DMV, for
its database redevelopment project, overestimated the benefits to be
derived from software and personnel savings, significantly
underestimated computer equipment costs, and incorrectly reported the
status of the project.
The deputy director of the OIT told us that some state
departments resist the OIT’s oversight efforts. We suggest that
because departments could bias the data that they report to the OIT, it is
therefore prudent to validate the accuracy of the information in these
reports. The Department of Finance has acknowledged the need to
supplement the reviews currently performed by the OIT. As discussed
later in this chapter, in July 1993, the Department of Finance assigned
its Office of State Audits and Evaluations the responsibility of
conducting in-depth reviews of information technology projects,
although only a few of the highest risk projects are being reviewed.
The Scope of the In each feasibility study report submitted to the OIT, the department
OIT’s Document must describe the capabilities of the information technology that it
proposes and discuss how this technology will address the department’s
Review Is
needs. At the project’s inception, the OIT reviews this information.
Limited
However, the OIT does not verify the information or ensure compliance
with the feasibility study report.
According to the deputy director of the OIT, the role of ensuring a
project’s success has always belonged to the department’s project and
executive management. The OIT has never viewed its role as
performing a detailed technical analysis of agency proposals. The
deputy director stated that making this part of OIT’s role would
duplicate the extensive analyses departments undertake before
73
beginning information technology projects. The deputy director also
stated that the OIT has never been staffed to perform such analyses, and
he does not believe it is necessary to repeat the departments’ analyses.
The OIT’s deputy director also rejects the notion that it is the OIT’s
role to ensure that the department’s staff is performing the evaluations
necessary to ensure that the technical and performance requirements
established in the feasibility study reports are satisfied. According to
the deputy director, the OIT has always believed this role belonged to
the executive management of the department.
We disagree with the OIT. We believe that the significance of the
State’s investment necessitates an independent validation of feasibility
data and analyses provided by departments. Further, because the OIT
recommends funding for projects at various points, it is critical that it
ensures that the technical and performance requirements of the project
are satisfactorily accomplished. If the OIT approves a feasibility study
report based on the projected benefits and conditions that must exist to
satisfy each defined objective, it seems that the OIT would find it
necessary to ensure that the objectives of the project were being met
and that the investment was still sound.
Another way in which the OIT’s project reviews are limited has to do
with how the OIT attempts to determine whether the department
possesses the capability to implement a project successfully. In the
guidelines that OIT analysts use to review feasibility study reports, the
OIT has identified one of its critical determinations as being whether
the department has acquired, or will be able to acquire, the necessary
resources, including project management and technical expertise. The
OIT limits its review to an assessment of the types, levels, and
quantities of personnel classifications that the department plans to use
to accomplish the project. Additionally, the OIT bases its assessment
of the department’s ability to implement a project successfully on the
outcome of the department’s previous information technology
endeavors. The OIT does not, however, assess the individual
qualifications of any of the staff members assigned to the project,
including the project manager and key technical staff members, to
ensure that they possess the appropriate skills and experience for that
particular project.
The OIT limits its review because it believes the department is
responsible for hiring individuals who can perform the duties assigned
to the position and states that it does not have the authority to place a
specific individual in a particular job. Additionally, the OIT does not
believe that it is responsible for assessing the competence of specific
individuals. Although we recognize that the OIT does not have
authority over hiring decisions made by departments, we believe it is
well within the OIT’s authority to assess whether a department
74
currently has the staff capable of implementing the project successfully
or whether the department needs to acquire outside assistance. Unless
the OIT reviews individual qualifications of at least the project
manager and key technical staff, we question the OIT’s ability to make
an informed decision regarding the department’s ability to implement
the project successfully.
When departments attempt to implement projects without the
appropriate project management or technical expertise, they risk cost
overruns and project delays. This problem surfaced on the DMV’s
database redevelopment project, where the DMV attributed some of the
difficulties that it suffered to the fact that its project staff did not have
the appropriate experience. In the project staff’s periodic assessments
for management, staff members indicated that they lacked knowledge
of the computer equipment being purchased and were having difficulty
in recruiting staff experienced with that equipment.
Sometimes, departments may initially believe that their existing staff
can implement the project, only to find that they unexpectedly have to
obtain outside expertise later in the project. For example, in
January 1992, when the OIT approved a feasibility study report for the
Board of Equalization’s (board) Teale Migration Project, the board
thought it could implement the project with existing staff although it
recognized that it needed to make a significant investment in
developing and training staff members. However, in a special project
report submitted in September 1993, one year and eight months after
the OIT had approved the feasibility study report, the board recognized
that its existing staff did not have the specific knowledge and expertise
to successfully complete the project and concluded that it needed to
contract with a private vendor.
The OIT’s The OIT has limited itself to an exception reporting system as the
Ongoing Oversight primary mechanism for ongoing oversight. That is, as a project is
Relies on Exception being implemented and it is beginning to experience budget variances
or schedule delays, the sponsoring department is required to submit to
Reporting
the OIT a special project report notifying the OIT of the variance. In
our view, this special project reporting process is not an effective
oversight mechanism because the OIT depends entirely on the
department’s willingness to submit the special project report. The
weakness in this arrangement is that the OIT relies on the “good faith”
of the sponsoring department for the system to be effective. In other
words, the OIT is relying on the department to admit that its project is
over budget or behind schedule and then to prepare the special project
report.
The California Student Aid Commission’s (commission) financial aid
processing system project illustrates a project with serious difficulties
75
for which the commission did not always keep the OIT properly
informed. This project was begun in 1987 and fully implemented by
January 1993. During this time, the requirement to submit quarterly
project reports to the OIT was still in effect, and in May 1992, the
commission submitted a quarterly progress report to the OIT stating
that the complete system was to be in production in August 1992.
However, in October 1993, after not having received any updates from
the commission for 17 months, the OIT finally sent a letter to the
commission asking for an update on the project. During this 17-month
period, there appears to have been no interaction between the
commission and the OIT. In response to the OIT’s letter, the
commission submitted a special project report to the OIT in
February 1994.
At this point, the project was significantly over budget and behind
schedule. Based on the budget approved for the February 1994 special
project report, the project was estimated to cost 48 percent beyond its
most recently approved budget. Yet, the commission did not submit
the special project report that such variances from the budget require.
Additionally, as of February 1994, the post implementation evaluation
report for the project that was scheduled for December 1992 was
14 months overdue. This is exactly the type of risk the OIT assumes
when it relies on the good faith of the sponsoring departments to report
when the projects begin to deviate from the established budget and
schedule.
The OIT does not have to rely solely on such an exception reporting
approach. It has other choices that would require departments to
report regularly during the implementation of projects. One option is
to designate a project as “major,” which then requires that the
sponsoring department submit annual status reports. However, for two
of the four projects we reviewed, the OIT did not designate the projects
as major, even though both involve millions of dollars of expenditures
and were to be implemented over several years and are therefore
high-risk projects. For example, the Corrections Management
Information System project at the California Department of Corrections
began as a $55 million project that was estimated to have a project life
of six years, including a system development and installation period of
three years. Additionally, it was considered to be technically complex,
and outside expertise, in the form of a contractor, was considered
necessary. But in January 1992, at the outset of the project, the OIT
did not designate this project as major. Not until August 1994, more
than two and one-half years later, after the project’s budget more than
doubled to $118 million, did the OIT designate this project as major.
Another reporting option that the OIT has been able to use in the past,
but that it has recently eliminated, is the quarterly project report.
According to the deputy director of the OIT, the quarterly reports were
76
ineffective. However, as noted in the OIT’s guidelines that the
analysts use to review projects, these reports were designed to help the
OIT determine if a special project report was warranted.
Recently, the Department of Finance has taken steps that should
improve the assessment of some information technology projects. In
July 1993, the Department of Finance assigned its Office of State
Audits and Evaluations the responsibility of conducting in-depth
reviews of selected projects. Some of these reviews are to be
conducted while these projects are in the midst of being implemented
rather than after the projects are fully implemented. In this way, if the
auditors determine that the department is not proceeding in a prudent
fashion to implement the project or is not doing the analyses necessary
to ensure that the technical and performance requirements established
for the project are met, the auditors can immediately bring needed
attention to these conditions before the problems become
insurmountable. Although this new function provides a level of
assurance that was not present before, the resources that the
Department of Finance has allocated to this effort are minimal. Thus,
only a few of the highest risk projects are being reviewed.
One of the OIT’s Another flaw in the OIT’s oversight of information technology projects
Fiscal Controls involves a specific fiscal control that the OIT requires to gauge how
closely project expenditures are tracking with the original budget for
Is Flawed
the project. One of the circumstances under which a department must
submit a special project report is when the total costs of the project
deviate or are expected to deviate by 10 percent from the project’s
initial budget. The State Administrative Manual specifies that if the
department is required to submit a special project report, the
department shall not expend additional funds to implement the
proposed change until the OIT approves the special project report.
The OIT uses this fiscal control so that the 10-percent threshold is
applied to the total costs of the project rather than strictly to the
development costs of the project. (Development costs are those
one-time costs associated with the analysis, design, programming, staff
training, data conversion, acquisition, and implementation of
information technology projects.) Applying the 10-percent threshold
to the total costs of the project weakens the effect of this fiscal control
because the total costs of a project are always greater than the
development costs since the total costs include the development costs
as well as the cost of operating and maintaining the project throughout
its life. Applying the 10-percent threshold to the total costs of the
project allows the sponsoring department a much higher threshold
before the department is required to report that the project is exceeding
its initial budget.
77
Also, it allows for the possibility that actual overruns in development
costs can be masked by estimated savings in the cost of operating and
maintaining the project throughout its life. This is because the
department could experience significant overruns in development costs
but would not need to submit a special project report if the department
also projected a decrease in the operating and maintenance costs that
caused the total project costs to change by less than 10 percent.
Because many of the operating and maintenance costs are estimated
costs over the life of the project that are based on various assumptions
that may be optimistic and may not be realized, these costs are subject
to uncertainty. In contrast, the incurred overruns in development costs
represent the actual experience with the system to date. An early
warning mechanism to identify projects that may be experiencing
problems is most effective if it is triggered by actual variances in the
development phase of the project.
For example, suppose that a state department received
approval to undertake a $40 million project that involves $15 million
in development costs and $25 million in costs of the ongoing
operations and maintenance. The department experiences overruns of
$7.5 million in its development costs. However, the department
believes that it can offset these overruns partially through $4 million of
estimated savings in operations and maintenance costs in future years.
Thus, the department would estimate an overrun of $3.5 million for the
total project costs, and because this is less than 10 percent, would not
turn in a special project report to the OIT. Thus, the OIT would not be
aware that the department had already exceeded its development costs
by 50 percent.
We spoke to the director of the OIT about why it established its control
at the total project level rather than at the component level, such as the
development costs. He stated that until the last few years, the OIT
thought that the total project level provided appropriate control.
Projects tended to be shorter and less complex. Also, departments
would often request budget augmentations through budget change
proposals to continue the funding for a project. The subsequent review
of the budget request would serve as a check on the project’s progress.
However, in the last few years, projects have become longer and more
complicated. Also, the State’s fiscal climate has caused departments
to use more of their existing resources for their information technology
projects rather than obtain budget augmentations. When this occurs,
the OIT never sees a budget change proposal, because the department is
simply redirecting previously budgeted funds to increase the project’s
budget. A way in which the OIT has tried to deal with this difficulty is
to designate certain large projects as major projects and thus require an
annual progress report. However, the director of the OIT agreed that
under current conditions, establishing control at the component level
rather than at the total project level would provide the OIT with a better
78
early warning mechanism for large, multi-year projects. Another
approach that he favors is to break large projects into manageable
phases with specific deliverables and to condition future development
on satisfactory completion of prior phases.
No Assurance Another limitation in the current process for overseeing information
That Critical technology projects can be seen when the OIT grants approval for a
sponsoring department to proceed subject to the department’s meeting
Issues
specific conditions as the project progresses. According to the OIT’s
Are Sufficiently
deputy director, the OIT frequently approves projects with stipulations
Addressed
intended to provide reasonable checkpoints or milestones so that the
OIT and the management of the sponsoring department can determine
that certain critical tasks are completed before the department proceeds
to the next step. For example, the OIT might require that a department
successfully complete a pilot project that is a less comprehensive
version of the proposed project before it can proceed to the next step in
the implementation of the full project. However, here again, the OIT
generally relies on the good faith of the department that it will fulfill
the conditions set forth by the OIT. The OIT does not follow up to
ensure that the department has actually fulfilled all the conditions.
Instead, the OIT relies on subsequent reports, such as the special
project reports from the department, as an assurance that the
department has met the conditions.
A project to expand the central processing capacity of some of the
computers at the Franchise Tax Board (board) illustrates the OIT’s
inability to enforce a department’s compliance with conditions that the
OIT has set forth for the project. In January 1992, the board obtained
OIT approval for an upgrade of some of the board’s computers. As the
project progressed, the board determined that the project as it was
originally proposed would not entirely meet its needs. Therefore, in
July 1992, the board submitted a special project report to the OIT in
which the board requested approval for an augmentation to the project
to provide for additional computer processing capacity. The OIT
approved this special project report in September 1992 but conditioned
its approval on the board’s conducting studies that would link the
growth in its workload to the need for additional computer processing
capacity. The OIT also indicated then that it had requested previously
that future feasibility study reports and special project reports for
computer upgrades include this type of data. However, in spite of this
requirement, the board did not produce the study. In January 1994, the
OIT approved an emergency request from the board for additional
capacity in which, yet again, the OIT admonished the board for the fact
that the required capacity study was not completed. Finally, in
June 1994, the OIT concluded that the board was now able to relate
workload increases directly to the need for additional computer
processing capacity.
79
The California Student Aid Commission’s (commission) project for its
financial aid processing system provides another example of how the
OIT sometimes appropriately recognizes that there are issues critical to
the success of a project but is ineffective at ensuring that those critical
issues are addressed. When the OIT approved the commission’s
feasibility study report for the project in January 1987, it acknowledged
the commission’s conclusion that it did not currently have adequate
staff expertise for the scope and complexity of this project and planned
to use a contractor to develop and implement the system. The
commission intended to increase its staff in the data processing unit and
have its staff work closely with the contractor to ensure the staff’s
familiarity with the system. Once the system was implemented, the
commission was to take over the system operation and support. The
OIT approved the report based on this premise. Also, the OIT pointed
out that it was critical for the commission to plan how it would transfer
the contractor’s expertise to the commission staff. However, other
than reviewing the commission’s request for proposal to ensure that it
had the appropriate provisions regarding staff development, there is no
indication that the OIT proactively ensured that staff expertise was
being developed throughout the project. Ultimately, the commission
was unable to develop the necessary staff expertise. In October 1991,
nearly five years after the OIT approved the feasibility study report, the
commission reported to the OIT that it had experienced difficulties in
acquiring sufficient qualified data processing personnel and proposed
that another contractor assume full responsibility for completing the
project and for operating and maintaining the system thereafter. The
OIT approved the commission’s proposal, and the commission
effectively abandoned its previous intent to operate the system.
On the database redevelopment project, the OIT required that the DMV
develop a working model of the project before proceeding to the next
phase of the project. In the feasibility study report and other
documents, the DMV agreed to design and implement such a working
model. In fact, the OIT considered the model to be the key step in
determining whether the project, as designed, would be successful.
However, the DMV failed to develop the planned working model.
Instead, it continued its efforts to implement the project despite
unresolved technical problems noted when it tried to develop the
working model. The OIT allowed the DMV to continue with the
project, spending an additional $34.6 million, and it allowed the DMV
to attempt to put the database redevelopment project into operation
despite its failure to satisfy the OIT’s requirement. The DMV
ultimately terminated the project because of significant unresolved
problems and deficiencies after spending over $49 million.
80
Limited According to the deputy director of the OIT, its oversight of a project is
Effectiveness most effective when the feasibility study report is submitted, before
funding for the project has been approved. At this stage, the
Once Project
sponsoring department is seeking the OIT’s approval of the report and
Funding Has
is seeking funding approval from the Department of Finance’s budget
Been Approved
unit. In addition to approving a department’s feasibility study report,
the OIT plays a key role in approving the funding for an information
technology project, because a project’s funding requires the approval of
both the OIT and the Department of Finance’s budget unit. However,
once a project is underway and problems begin to surface, it is difficult
for the OIT to stop the project. According to the deputy director of the
OIT, its strategy has not been to stop troubled projects, but to get them
back on track.
According to the OIT’s director, he never saw the OIT as responsible
for managing ongoing projects or stopping projects. However, some
projects need to be stopped, and steering the project back on track is
not necessarily in the State’s best interests, as illustrated by the DMV’s
database redevelopment project. Even though in 1990 the OIT was
aware that this project was significantly different from the project
previously approved, the OIT continued to recommend approval for
additional funding for the project. In our August 1994 report “The
Department of Motor Vehicles and the Office of Information
Technology Did Not Minimize the State’s Financial Risk in the
Database Redevelopment Project,” we concluded that the OIT should
not have recommended continued funding in November 1990, when the
DMV requested an additional $3.9 million for fiscal year 1991-92. As
of June 30, 1994, the DMV spent an additional $34.6 million on the
project, which ultimately failed.
The OIT’s According to the deputy director of the OIT, the decision to employ
Perspective information technology is a two-part decision: a business decision and
an investment decision. The business decision is a fundamental part of
the management responsibilities of the state departments that are
sponsoring information technology projects. State departments must
develop the business case for the use of information technology. In
other words, the state department must show how the proposed
technology will enable the department to better perform its mission or
better serve its customers. So, for example, in justifying its recent
acquisition of a new computer system, the California Student Aid
Commission (commission) was required to show that the new system
would help the commission improve its processing of student loans and
grants. According to the deputy director of the OIT, the OIT’s role is
to be involved in the investment decision. That is, the OIT views itself
as an investment committee that should review the business plans, from
both a technical and economic perspective, to determine whether a
81
proposed project is a good strategic investment of limited public
resources.
The OIT has adopted the philosophy that the ultimate responsibility for
project success or failure resides with the department sponsoring the
project. According to the director of the OIT, because the ultimate
approval of information technology projects requires both OIT and
budget staff approval, the OIT’s role mainly emphasizes support of the
budget process, not independent authoritative oversight. He stated that
the OIT “was not the state information technology watchdog as it now
appears was the expectation of the legislation.”
Chapter 3 The State’s Current Information Technology
Program Does Not Work and
Needs To Be Reengineered
Chapter The State’s current model for managing statewide information
Summary technology does not work. The Office of Information Technology
(OIT) has not provided the statewide leadership and coordination for
information technology in the State as intended by the 1983 legislation
that established the OIT. Additionally, the oversight of information
technology projects provided by the OIT is limited and does not ensure
that state departments implement projects successfully.
To protect its information technology interests and assets, the State
must reengineer the entire program. To initiate the reengineering
process, the State should establish a statewide chief information officer
(CIO) position. The CIO should serve as a member of the governor’s
cabinet and head a new statewide information resources office.
The CIO and the information resources office should be given the
powers, duties, and responsibilities for developing and implementing a
statewide plan for information technology, providing leadership and
guidance to departments, managing and coordinating statewide
information technology resources, and monitoring and overseeing
projects based on a risk assessment. In addition, the State should
reevaluate the commitment of resources for managing its information
technology resources. Finally, the State will need to address the
statutory changes necessary to complete the reengineering process, and
the proposed CIO will need to implement procedural changes.
82
The Current Model The State’s current model for managing statewide information
technology does not work. The OIT has not provided the statewide
Does Not Work
leadership and coordination for information technology in the State as
intended by the 1983 legislation that established the OIT.
Additionally, the oversight of information technology projects provided
by the OIT is limited and does not ensure that state departments
implement projects successfully. Although the current decentralized
leadership allows state departments the flexibility to determine and
fulfill their own needs, it assumes that the vendor marketplace sets
technology standards and that departments possess the expertise to
manage information technology projects. Additionally, the OIT
perceives it has minimal statutory authority over data centers and
multi-agency projects, resulting in minimal coordination of information
technology projects, activities, and services. Further, the State’s
information technology managers lack a user committee to
communicate technology information, experience, and successes and
failures among departments, and to serve as an advisory group to the
OIT. Finally, the OIT’s interpretation of its investment committee role
with limited authority to stop projects restricts its oversight
effectiveness to front-end project analysis without effective ongoing
follow-up on the progress of the projects.
The OIT recently became more involved in managing information
technology resources by requiring departments to develop strategic
plans for the use of information technology. Strategic planning
emphasizes the development of business strategies to support a
department’s mission and a plan for information technology to support
those business strategies. This approach began to shift the OIT’s focus
to department strategic planning and management of information
technology resources. However, the State has not committed adequate
resources to the overall management of information technology
resources in the State, and the OIT focuses most of its minimal
resources on oversight. Although the State’s trend has been to
increase spending on information technology, the OIT’s staff resources
have not kept pace with information technology spending. As a result
of budget cuts in fiscal year 1992-93, the OIT’s staff was cut by
40 percent, after reaching its peak in fiscal year 1987-88 and
maintaining that level through fiscal year 1991-92. The trend toward
increased spending for information technology is expected to increase
throughout the 1990s.
Information technology management trends in other states are moving
toward better management of a state’s overall information technology
resources with focused attention on the planning and procurement
processes. This management philosophy incorporates all information
and technology resources under one management function, including
data processing systems, telecommunication systems, office automation
systems, systems development, data administration, data centers,
83
purchasing, personnel, and other information resources, such as state
libraries and records management. In contrast, California has limited
central management because the OIT focuses its resources mainly on
the oversight of information technology projects and has minimal
involvement in telecommunications, data centers, procurement,
personnel, and the other information resources noted.
In the following sections of this report, we have made several
recommendations that should be addressed in the reengineering
process. Certain aspects of these recommendations may to a limited
degree exist already under the current model for managing statewide
information technology. For example, we suggest that the CIO
implement management practices that require project milestones. To
some extent, the OIT requires project milestones, like the prototype and
pilot project requirements for the Department of Motor Vehicles’
database redevelopment project. However, the management model
that we have proposed here is intended to be comprehensive.
Reengineer the In view of the limitations of the current processes, the State must
Statewide reengineer the entire statewide information technology program to
Information ensure that the State’s information technology interests and assets are
protected and utilized to their maximum potential.
Technology
To initiate the reengineering process, the State should establish a
statewide CIO position. The CIO should serve as a member of the
governor’s cabinet and head a new statewide information resources
office. The CIO and information resources office should be given the
following powers, duties, and responsibilities:
Develop and implement a comprehensive statewide information
technology plan that provides the vision and strategy to promote
innovation, advocacy, and efficient use of information technology
resources;
Provide leadership and guidance to departments developing and
implementing information technology projects;
Manage and coordinate statewide information technology
resources, such as telecommunications, data center activities, and
multi-agency information technology projects; and
Monitor and oversee information technology projects based on a
risk assessment. The CIO should have the power to recommend to
the governor whether a project is continued, modified, or canceled.
84
Establish a CIO Many of the OIT’s leadership, coordination, and oversight problems
in the Governor’s can be attributed to the office’s placement within the Department of
Finance. The OIT has evolved to serve as a support function for the
Cabinet
Department of Finance, reviewing business plans and feasibility studies
for information technology. The OIT mainly supports the budget
process and is not an independent entity providing authoritative,
technical oversight. The director of the OIT states that the Department
of Finance’s budget staff could be as influential over an information
technology project decision as is the OIT. In effect, the OIT’s power
and authority over department directors is compromised because it is
within the Department of Finance and not independent of the budget
approval process.
In addition, the OIT has a narrow interpretation of its statutory role, a
perceived lack of authority, and limited resources. In view of these
considerations, the OIT has not provided sufficient guidance on
information technology matters to state departments or effectively
coordinated the State’s information technology resources. Further, the
design and implementation of OIT’s oversight of projects have been
flawed. To improve the statewide information technology program,
the State should eliminate the OIT and establish a new statewide
information resources office. The CIO should serve as director of this
new independent office and advise the governor on information
technology.
The responsibilities of the information resources office should be
expanded beyond those of the existing OIT and encompass
management or oversight of telecommunications and the State’s data
centers. The State also should consider what role the information
resources office should have in procuring information technology and
how the office can help to reform state personnel practices to attract a
sufficient number of highly qualified information technology
personnel. Both of these issues, which are beyond the scope of our
work as it directly relates to the OIT, are discussed at the end of this
chapter.
The Department of Finance and its director, who acts as the governor’s
chief fiscal policy advisor, provide a good organizational model for a
new statewide information resources office. The director effectively is
the State’s chief financial officer, responsible for the fiscal affairs of
the State. The director of the proposed new statewide information
resources office should act as the State’s chief information officer,
responsible for the information technology affairs of the State at a level
of responsibility equal to that of the State’s chief financial officer. In
effect, the chief financial officer model provides the appropriate
authority, policy setting, and advisor framework that is necessary for
the CIO to manage the information technology resources of the State.
85
Promote The State needs a statewide information technology plan with vision to
Innovation, promote innovation, advocacy, and use of information technology
resources. The plan should include strategies for all information
Advocacy, and Use
technology resources in the State and recommend implementation
of Information
methods to put the strategies into action. The plan should be based on
Technology
the State’s overall vision, business strategies, and direction for effective
Resources
government operations and public service. Based on our review of
other states, we noted that one large state’s information technology plan
includes the following:
An overall plan for information technology resources, based on a
vision to empower that state’s citizens through direct and easy
access to the specific information and services they need, allowing
them to fulfill their needs and express their opinions directly,
wherever they are, at any time of day;
Goals supporting the state’s vision, which include improving the
information technology systems and the personnel developing and
operating those systems, efficiently acquiring and implementing the
improvements to the information technology systems, and
enhancing program effectiveness by basing information technology
improvements on an understanding of citizen and user needs;
Implementation strategies for each of the goals, including
measurements for successful implementation of each strategy; and
The assignment of responsibility to carry out those strategies.
California’s CIO should develop a statewide strategic plan for
information technology based on the State’s vision and business
strategies. This plan should then be communicated to all departments
and key state personnel to ensure that information technology planning
at the department level is consistent with the State’s plan.
In addition, the CIO should continue to emphasize and monitor
strategic business planning and information technology planning at the
department level. This planning approach, encouraged by the OIT, has
prompted departments to evaluate and change the way they do business
while using information technology to support those changes.
According to the U.S. General Accounting Office (GAO) in its
“Executive Guide: Improving Mission Performance Through Strategic
Information Management and Technology,” this approach focuses
information technology strategies on addressing external customer
needs, attaining the overall department mission, supporting business
strategies, and improving the methods of doing business.
Further, this approach can lead to the highest potential gains in
86
customer satisfaction and cost savings, rather than the marginal
efficiency gains normally associated with initiatives that computerize
existing procedures.
Develop Preferred Management Practices
The CIO should develop preferred management practices to improve
the management of the State’s diverse information technology
environment. Such practices should address the need for efficient and
effective design, development, implementation, and operation of
information systems that are capable of adapting to rapid legislative,
program, and information technology changes. Overall, the statewide
information technology program must address the need to lead
departments in the direction of building an effective information
technology infrastructure, including the hardware, software,
communications, personnel, policies, and plans that support the
development and operation of information systems.
In addition, the State should evaluate and reconfigure, if necessary, the
alignment of program managers with technology managers and the
responsibility for the development, operation, and use of information
technology. Because information technology planning should be
based on departments’ business strategies, management structures must
reflect the changing roles of program and information technology
managers at all levels. According to the GAO, program managers
must be held accountable for the impact of information management on
their program functions. In addition, the GAO suggests that
departments establish chief information officers at the senior executive
level rather than at the line manager level. Both these suggestions
address the need to incorporate information technology in all aspects of
programs and at all levels of management to ensure that information
technology benefits the entire organization as intended by senior
decision makers.
Also, the State should consider the use of performance budgeting in the
management and delivery of information technology systems
throughout all levels of government, including the proposed
information resources office. As noted in the 1994-95 Governor’s
Budget, the State’s Performance Budgeting Pilot Project introduces the
concept of changing organizational behavior by rewarding measurable
results that are tied directly to the organization’s mission and business
strategies. Emphasizing the same approach in the management of
information technology allows both program and information
technology managers at all levels to measure performance of the
information systems development and operations efforts. With
performance measurement tools, the State’s managers, project
87
managers, staff members, and outside contractors should become
accountable for results, compared to predefined performance standards.
The desired results should be improved customer service based on
improved information systems performance, better management of
business and information technology risks, and better information
systems development.
Further, to introduce performance budgeting in the process for
developing information systems, the CIO should adopt formal project
management methodologies that focus on evaluating project risk and
tracking progress throughout a systems development project.
Quantitative tools should be made available with training to state
departments. Such tools could include project accounting, which
compares budgeted resources to actual resources expended; change
management, which tracks requested and unavoidable software
changes; and issues management tools, which assess a project
manager’s ability to identify and resolve business, technical, and
contractor problems arising during the development of information
systems. Such tools give departments and the statewide information
resources office mechanisms to identify early system development
problems. According to the GAO, in its “Information Technology:
Audit Guide for Assessing Acquisition Risks,” management and
auditors can use these tools to assess how well a department is
managing the systems development process.
Finally, the CIO should implement management practices that reduce
the development time for information systems and require project
milestones to periodically reassess project feasibility and measure
progress. Shorter project development times and project milestones
improve the probability of success and reduce the overall risk of system
failure. One state department attempts to limit the length of projects or
major project sections to one year and individual project tasks to
between 40 and 80 hours, which allows it to better manage the project
and closely evaluate individual staff performance. Additionally,
during our audit of the Department of Motor Vehicles, we found that it
bypassed the prototype and pilot project milestones for its database
redevelopment project without analyzing project feasibility at either
stage. Not adhering to those milestones cost the Department of Motor
Vehicles an additional $34.6 million in development costs it might not
have spent if it had analyzed the project’s technological feasibility
before incurring additional costs.
Develop Preferred Technology Practices
The CIO should determine the appropriate level of preferred
technology practices, guidelines, and standards for the State.
Statewide preferred technology practices and standards should provide
overall guidance for moving information systems of state departments
88
in the same technical direction; however, extensive standardization may
have a greater cost than benefit.
As discussed in Chapter 1, the OIT was given the responsibility of
developing plans and policies that include the objective of ensuring that
systems and the interchange of data are appropriately compatible.
However, the OIT believes that establishing standards to accomplish
this objective may not always be in the best interests of the State and
that reliance on the vendor marketplace for standards is appropriate.
We recognize that too much standardization may inhibit the effective
implementation of information systems. For example, officials we
interviewed in one state attempted to standardize methods for
developing information systems that were later determined to be too
restrictive and inefficient. They found that these restrictive standards
limited the departments and, in some cases, their contractors from using
the best methods for particular situations. The state eventually
eliminated the strict standards and replaced them with a program to
assist and train departments to implement standard methodologies most
suited to the departments’ situations. The trade-off between no
standards and restrictive standards should be analyzed by the CIO in
order to adopt the appropriate level of statewide standards.
The CIO should continue the State’s effort to explore emerging new
technologies and their application to the State’s information technology
plan. In conjunction with the private sector, the statewide information
resources office should identify and coordinate opportunities for new
advanced technologies. In the past, the data centers and various
departments have independently developed emerging technologies,
such as the Info/California kiosks, document imaging, merging of voice
and data communications, and new computer operating systems for
optimizing mainframe applications. According to the OIT’s 1993
strategic direction document, many departments have made several
advances in emerging technologies; however, the CIO should centrally
manage this effort to ensure that state resources are appropriately
allocated only to those projects that meet the State’s business strategies
and information technology plan.
89
Relationships with the community of information technology vendors
provide the State with additional resources to analyze and apply
advanced technologies to state use. In addition, partnerships with the
vendor community potentially allow the State to share the risks
associated with systems development projects with private industry.
Allowing vendors to propose solutions to the State’s information
technology problems in addition to allowing departments to share the
risks and benefits of systems development projects may further
improve relationships with information technology vendors while
reducing the State’s risks. The CIO should centrally manage the
State’s efforts to develop these relationships to optimize this resource
in achieving the State’s overall business strategies and information
technology plans.
Provide The ability of the CIO to communicate with information technology
Leadership and managers, assist with the development of department information
Guidance to technology infrastructure, and provide training to information
technology managers and staff in the State will be critical to the
Departments
leadership role of the information resources office. The statewide
information technology plan, programs, and policies developed by the
information resources office need to be based on input from various
public and private sources and effectively communicated to state
departments. In addition, several other leadership and guidance issues
that address the development of information technology infrastructure
in departments throughout the State should be considered by the State
when reengineering the statewide information technology program and
by the CIO when establishing the information resources office.
To ensure that the information technology needs of the state
departments are met, the State should establish an advisory group or
groups that assist the CIO in developing its statewide information
technology plans, programs, and policies. In addition, the State must
develop well-defined advisory groups and related policies that
effectively communicate with the State’s information technology
community, the Legislature, and the private sector. The State should
determine the appropriate group or groups and empower them to
perform these tasks.
The California Forum on Information Technology (CFIT) is one
example of an advisory group for information technology in the State.
As noted in Chapter 1, the OIT’s director created the CFIT and served
as its chairman. The CFIT consisted of representatives from state
departments and served as a liaison between state departments and the
OIT. Because of the 1992-93 budget cuts resulting in the elimination
of certain boards and commissions, the State eliminated the CFIT.
Several information technology managers whom we interviewed
expressed the need to create another forum to improve the
90
communication of information technology issues, including discussions
of the State’s information technology successes and failures.
In addition, two information technology advisory groups were
recommended by the governor’s Task Force on Government
Technology Policy and Procurement in its September 1994 report
recommending a restructuring of the State’s information technology
management and oversight. The governor’s task force also
recommended an internal advisory council, consisting of information
technology executives from state departments, which would provide the
CIO with advice on policies, standards, major projects, and strategic
technologies. In addition, the task force recommended an external
commission that would comprise information technology executives
from the private sector and possibly individuals from the Legislature to
advise the State on the best information technology practices in other
organizations; on how to improve relationships with private industry,
including participating in joint projects; and on the State’s long-term
information technology vision and strategies.
When creating advisory groups, the State should exercise care in
determining the appropriate group members and establishing the
groups’ purposes. The effort to establish advisory groups should focus
on the need to address the State’s highest risks and highest rewards.
Consistent with the risk management approach discussed in the section
on monitoring and oversight on page 53, the State needs to focus its
limited resources on those issues that lead to minimizing risks and
maximizing benefits to the State rather than to individual departments.
In addition to improving its communications, the CIO should establish
programs to help departments implement preferred management and
information technology practices. Consistent with the trend of
information resources offices in other states, the State should take a
proactive approach to improve information technology infrastructure in
departments throughout the State by focusing on the ability of state
departments to develop and manage information technology. Such an
approach should include assistance in department information
technology planning, project management and implementation, systems
development methodologies, and information technology training and
staff development.
91
The CIO also should be involved in analyzing and justifying resources
for developing the information technology infrastructures of
departments. To the extent that certain departments require additional
resources to improve methods and procedures for developing
information systems, the CIO should be actively providing guidance.
For example, according to the Department of Social Services’ deputy
director of the Information Technology Division, this department needs
to allocate significant resources to implement project management and
systems development methodologies and tools for its information
technology systems, including the State’s largest information
technology project, the Statewide Automated Welfare System.
Developing an infrastructure capable of managing major projects is
imperative to the State’s information technology program success.
The CIO needs to ensure that adequate resources are allocated to
departments to develop this infrastructure.
Furthermore, the State should allocate more resources to training
program and information technology managers and staff members as
part of its effort to improve the information technology infrastructure of
departments. Training should focus on both information technology
and administrative topics, including project management and contract
management for contracts with information technology vendors. In
addition, the State should consider moving the statewide training
programs for information technology into the information resources
office. The CIO could then match the training curriculum with
statewide information technology issues and problems experienced by
departments. Further, the State should consider the continued support
of the Data Processing Managers Academy, which provides advanced
training to junior-level data processing managers. A similar
organization for project managers also should be established.
Manage and Management of the State’s information technology resources is the
Coordinate basic theme of the proposed reengineering process. The State should
consider moving the management of various resources into the
Statewide
information resources office to coordinate all the State’s related
Information
information technology resources. Coordination of resources at the
Technology
project level among various departments and the federal and other local
Resources governments also should result in a more efficient use of the State’s
resources.
The State should move its telecommunications division out of the
Department of General Services and into the information resources
office under the management of the CIO. Many of the State’s
information technology systems involve telecommunications. For
example, the Department of Motor Vehicles, the California Department
of Corrections, and the Department of Social Services all have
telecommunication systems that link field operation computers to the
92
main data processing center. Because the relationship between the
information technology systems and telecommunication systems is
close and will be even closer in the future, the State could benefit by
combining the management and coordination of these resources into the
information resources office.
In addition to managing both information technology and
telecommunications, the CIO also could identify potential
consolidation opportunities for various telecommunications networks
and promote a statewide telecommunications network to improve
efficiency and minimize duplicated systems in the State. For example,
the OIT has stated its concern that the State continues to develop
telecommunications networks that duplicate existing facilities, with the
result that costs increase and service levels do not reach levels that
could be attained. In addition, according to one department we
interviewed, due to the lack of standards and insufficient infrastructure
development, departments such as theirs must undertake complex
technical tasks and assume considerable risk in accomplishing the data
communications function. If the State provided an appropriate
telecommunications network, the department believes it could more
cost effectively solve its data communication problems.
The State should provide the CIO with the appropriate authority to
plan, coordinate, and oversee the activities of data center management
to ensure that statewide interests are met. The coordination of these
data processing resources should improve use and efficiency while
providing more cost-competitive services. A centralized approach to
managing the State’s data center resources would provide the State the
opportunity to review data center consolidation as well as other options,
such as the use of private companies, that could result in decreased data
processing costs to the State.
The statutes establishing the CIO should clearly provide the CIO with
the appropriate authority to identify, coordinate, and ensure the
implementation of information technology projects that affect multiple
departments of the State. Such multi-agency projects can potentially
reduce government operating costs resulting from improved program
efficiencies that cross departmental lines. The CIO should have the
responsibility to promote and coordinate such governmental
reengineering projects. For example, in 1990, the Legislature
mandated the Franchise Tax Board, the Employment Development
Department, and the Board of Equalization to explore electronic funds
transfer as a means of collecting tax payments. According to the chief
of the Information Management Division at the Board of Equalization,
the State Controller’s Office facilitated the development of this project
with some assistance from the OIT. However, as noted in Chapter 1,
the OIT does not believe it has the authority to coordinate these types
of projects.
93
The statutes establishing the CIO also should clearly provide the CIO
with the appropriate authority to coordinate certain information
technology projects with various departments of the federal and local
governments affected by such projects. For example, according to the
chief of information technology at the California Department of
Corrections (CDC), the Legislature mandated the CDC to make
corrections information available to local police departments.
However, the Department of Justice system, which gives local law
enforcement agencies access to computerized state and federal
information, is the logical conduit for information from the CDC. This
is an example of a project that could benefit from the CIO’s
coordination of the project implementation between departments.
Monitor and The planning, leadership, and resource management sections above
Oversee emphasize the information resources office and the CIO’s role in
proactively assisting in the development and management of the State’s
Information
information technology resources. The State should also place the
Technology
oversight emphasis of the CIO and the information resources office on
Projects Based on
analyzing and assessing each department’s ability to develop and
Risk Assessment manage information systems that support the department’s business
strategies. In addition, the oversight effort of the information
resources office should be based on the CIO’s active involvement with
departments and some form of independent review of major
information technology projects.
The CIO should apportion its oversight effort based on the existing
information technology infrastructure at the department, the magnitude
of the project, and the overall risk to the State. For example, the
Department of Social Services and its Statewide Automated Welfare
System, with estimated development and operating costs of
approximately $800 million over the expected 12-year life of the
project, would consume more oversight resources than many
information technology projects in smaller departments. Since these
smaller projects would generally pose minimal financial or technical
risk to the State, the CIO could provide consulting assistance and
ensure that a good information technology infrastructure existed. A
risk management approach allocates more resources to the oversight of
larger departments that have significant information technology
budgets or projects and that have neither an adequate infrastructure in
place nor a successful track record in developing and managing
information technology projects.
For high risk projects, the CIO should monitor the progress of projects
identified for oversight by being directly involved in the development
process throughout the life of the projects. To augment the CIO’s
oversight, the State should consider requiring an independent review of
94
projects by personnel not involved in the project’s development.
Before approving a project or completing major project milestones, this
independent review could validate the cost and benefit
estimates and the technical feasibility of the State’s higher risk projects.
An independent review process could provide department management
and the CIO with a summary of project issues and status reports
developed by experienced information technology personnel not
directly involved with the project.
For lower risk or smaller projects, the CIO should analyze project risk
as part of the overall oversight of information technology plans for
departments. If departments in this category cannot demonstrate the
ability to develop information systems, the information resources office
should provide the department with consulting services to improve the
information technology infrastructure in accordance with the State’s
preferred practices and to help ensure the success of a project. The
CIO also may need to recommend other resources, such as an
independent review, if critical to project success.
In addition to adopting a risk assessment approach to oversight, the
State should provide the CIO with the appropriate authority to
independently recommend to the governor whether a project should be
continued, modified, or canceled. The CIO should monitor projects
and, at key, predetermined milestones, assess the feasibility and
progress of the projects. In addition, the CIO should be empowered to
recommend that funding be withheld, reduced, or suspended or that
other actions be taken when a project is not meeting expectations. The
CIO should ensure that information technology projects that are not
consistent with state and department information technology plans, do
not meet state criteria, or have not met project milestones are not
funded or supported for continued funding. The OIT currently has the
ability to affect funding decisions; however, authority for project
funding approval is shared jointly between the OIT and the budget units
of the Department of Finance.
Because adequate planning is the key to successful development and
implementation of information technology projects, the CIO should
evaluate the existing level of documentation necessary to approve
information technology plans and projects. The new oversight process
should be adapted to the statutes, policies, and procedures adopted as a
result of reengineering the State’s current information technology
program. Moreover, rather than create additional documentation and
unnecessary bureaucracy, the CIO’s monitoring and oversight should
be based on periodic key site visits and information-gathering meetings
at the department under review. This process should not burden the
project but should provide the CIO and department officials with an
independent assessment of the project to allow timely decisions.
95
Other Issues Other functions of the State’s operations affect the development and
Affecting management of information technology. Because these areas are
outside the scope of our audit, we have limited our discussion here to
Information
general areas that the State should evaluate and consider changing to
Technology
minimize any potential negative effect on the development and
Systems
management of information technology systems.
Evaluate Practices for Procuring
Information Technology
The State should evaluate procurement practices for information
technology to reduce the time required to approve and develop
information technology systems and limit the State’s risk from slow
project implementation. As noted in the 1994-95 Governor’s Budget,
the existing procurement and contracting procedures incorrectly
emphasize process rather than results, low price rather than value, and
detailed specifications rather than functional requirements. In
response, the Department of General Services, at the direction of the
governor, has initiated a procurement reform effort. In addition, we
noted certain issues regarding information technology procurement that
were brought to our attention while performing our review. We feel
that the following issues should be considered as part of the overall
procurement reform effort and the reengineering effort that we have
suggested:
The State should consider whether the information resources office
should manage information technology procurement and how much
of the procurement oversight should be delegated to departments.
In conjunction with potential changes in the delegation of
procurement oversight to departments, the State should ensure that
it properly trains department staff in procurement and contract
management.
The information resources office should encourage departments to
write requests for proposals that define information technology
problems for contractors to solve instead of specifying solutions.
Departments should develop information technology approaches
that share more risk with contractors and hold contractors more
accountable for results.
The State should improve its vendor protest rules to minimize
project delays that result when unsuccessful bidders submit protests
after contracts have been awarded.
96
Evaluate and Change Information
Technology Personnel Practices
The State should evaluate and change personnel practices for
information technology personnel as needed to improve information
technology expertise in the State. As noted in the 1994-95 Governor’s
Budget, the State is considering reforming state personnel practices to
address this need. In our interviews with various state departments,
information technology managers consistently expressed their concern
about attracting experienced project managers and technical staff into
state service.
An Increase The State needs to increase its commitment of resources to the
Needed in statewide management of information technology. Also, the State
should consider appropriate funding sources to expand the scope of the
Resources
statewide information resources program. One potential funding
method would be to consider the CIO and the information resources
office as a service agency in which billings for services could offset all
costs of the information resources office. Oversight costs could be
charged to projects requiring direct oversight from the CIO. Costs for
independent review of information technology projects could be built
into the cost of the projects. Training, consulting, and other services
provided by the information resources office could be billed to
departments based on services provided.
Required The recommendations to establish a new statewide information
Statutory and technology program and to reevaluate the commitment of resources to
this program will require significant statutory and procedural changes.
Procedural
The issues we have identified and developed in this chapter should be
Changes
considered and included in legislation to reengineer the State’s
information technology program.
Conclusion The State’s current model for managing statewide information
technology does not work. The State must reengineer the entire
statewide information technology program to ensure that the State’s
information technology interests and assets are protected and used to
their maximum potential.
The State should consider our proposed recommendations when
reengineering the statewide information technology program. The
most important reengineering decision should be to establish a
statewide CIO position. The CIO should serve as a member of the
97
governor’s cabinet and head a new statewide information resources
office responsible for managing and developing the State’s information
technology resources.
Overall, information technology provides the State with an opportunity
to improve public service while increasing program efficiency.
Unfortunately, state departments find it difficult to keep pace with
evolving management practices and skills necessary to precisely define
critical information needs and to select, apply, and control changing
information technologies. As the Legislature, the federal government,
and local governments continue to add program changes, the
information technology infrastructures of state departments continue to
fall further behind.
The proposed recommendations provide the State with a framework to
create effective leadership for the State’s departments, program
managers, and information technology managers, as well as effective
management for the State’s information technology resources. With
the responsibility of managing and developing the State’s information
technology resources, the CIO’s efforts must result in the development
of dynamic information technology systems and infrastructure that can
readily adapt to change.
98
We conducted this review under the authority vested in the state auditor by Section 8543
et seq. of the California Government Code and according to generally accepted
governmental auditing standards. We limited our review to those areas specified in the
audit scope of this report.
Respectfully submitted,
KURT R. SJOBERG
State Auditor
Date: December 7, 1994
Staff: Steven M. Hendrickson, Audit Principal
Karen L. McKenna, CPA
Kimberley A. Reed, CPA
Mark J. Denning, CPA
Virginia Anderson Johnson
Jerry A. Lewis
99
100