CSA
Summary
Read the report at California State Auditor ↗
Year 2000
Computer
Problem:
The State’s Agencies Are Progressing
Toward Compliance but Key Steps
Remain Incomplete
February 1999
98116
rotiduA
etatS
ainrofilaC
S
T
I
D
U
A
E
T
A
T
S
F
O
U
A
E
R
U
B
The first copy of each California State Auditor report is free.
Additional copies are $3 each. You can obtain reports by contacting
the Bureau of State Audits at the following address:
California State Auditor
Bureau of State Audits
555 Capitol Mall, Suite 300
Sacramento, California 95814
(916) 445-0255 or TDD (916) 445-0255 x 248
OR
This report is also available
on the world wide web
http://www.bsa.ca.gov/bsa/
Permission is granted to reproduce reports.
February 18, 1999 98116
The Governor of California
President pro Tempore of the Senate
Speaker of the Assembly
State Capitol
Sacramento, California 95814
Dear Governor and Legislative Leaders:
As requested by the Joint Legislative Audit Committee, the Bureau of State Audits presents its
audit report concerning state agencies’ progress in resolving computer system problems caused by
the year 2000. This report concludes that 11 of the 14 agencies we believe provide the most vital
services to Californians have not finished correcting the computer systems supporting those
program services. Equally unprepared are almost two-thirds of all 462 state programs, which are
not fully year 2000 ready because state agencies have not completed key remediation steps for
computer systems supporting their programs. We further found that one of the State’s large data
centers does not have a complete strategy for testing its mainframe computer system, which could
place hundreds of state clients at risk from the ill effects caused by year 2000 problems. Finally,
the State lacks a clear picture of the year 2000 preparations for essential electrical and
telecommunication utilities.
Respectfully submitted,
KURT R. SJOBERG
State Auditor
CONTENTS
Summary 1
Introduction 5
Chapter 1
Many Agencies That Provide Critical
Services to Californians Are Not Yet
Year 2000 Ready 11
Recommendations 24
Chapter 2
More Than Half of the State’s Programs
Need to Complete Remediation and
Business Continuation Plans 25
Recommendations 31
Chapter 3
The State’s Two Primary Data Centers Are Not
Equally Prepared for Year 2000 Problems 33
Recommendations 37
Chapter 4
The State Must Coordinate Efforts to
Ensure Year 2000 Problems Will Not
Interrupt Essential Utilities, Such as
Electricity and Telephone Services 39
Recommendation 44
Appendix A
State Agencies We Identified With
Vital Program Services 47
Appendix B
State Agencies’ Year 2000 Readiness:
A Review of Programs Listed
in the Governor’s Budget 51
Appendix C
Year 2000 Planning at State Agencies
Not Required to Report to the
Department of Information Technology 73
Responses to the Audit
Governor’s Office R-1
Teale Data Center R-3
California State Auditor’s Comments
on the Response From the
Teale Data Center R-9
SUMMARY
RESULTS IN BRIEF
T
his is our second report on state agencies’ progress in
resolving the problems with their computer systems
caused by the year 2000, or the millennium bug, as it is
Audit Highlights . . . sometimes called. As we reported in August 1998, state agencies
are making progress toward correcting critical computer systems
Our second review of the
to ensure the uninterrupted delivery of essential services to
State’s readiness to deliver
Californians; however, we are concerned that many of the 14
critical services at the change
of the century revealed that: agencies that provide the most critical services are still not done.
Eleven agencies have not completely tested their computer
(cid:254)
Key remediation efforts at
systems, nor have 7 corrected or replaced the embedded chips
11 of 14 agencies that
provide the most critical that control certain of their systems’ computerized activities.
services still are not
complete. For example, the Employment Development Department esti-
(cid:254) mates that it will not complete testing of the unemployment
Similarly, almost two-
thirds of all 462 state insurance system until September 1999. This critical system
programs still have key manages over $2.9 billion in annual payments to unemployed
tasks to complete.
workers. In another instance, the Department of Corrections
(cid:254) does not expect to correct and test embedded technology in the
Nearly half of all state
agencies need to complete electrified fences at 23 prisons until September 1999. Such late
business continuation
completion dates may not give the agencies enough time to
plans to ensure delivery of
resolve unforeseen problems before January 1, 2000, which
services in the event the
year 2000 causes delays could cause financial hardship to or imperil the safety of Califor-
or failures. nians. Additionally, five agencies have not completely resolved
(cid:254) critical issues with their data exchange partners.
One of the State’s large
data centers must take
additional steps to protect Moreover, 14 of 20 computer systems at these vital agencies are
its clients from year 2000 mission-critical, or essential to core business functions and,
problems.
according to a governor’s executive order, should have been
Moreover, although electrical fixed by December 31, 1998, but were not. Worse yet, with less
and telecommunication than 11 months until the new millennium begins, 11 agencies
utilities are essential in
still have no business continuation plans if their computer
delivering services to the
systems are not corrected in time or fail to work. Equally unpre-
public, no single entity is
overseeing these utilities’ pared are almost two-thirds of all 462 state programs because
year 2000 readiness. agencies still have critical tasks to complete, such as executing
and documenting full system testing, correcting embedded
technology, or remedying data exchange problems. Over half of
all programs must also develop business continuation plans to
cover the possibility that their remediation efforts might fail.
C A L I F O R N I A S T A T E A U D I T O R 1
We further found that one of the State’s two large data centers
that support hundreds of state clients has a poor strategy to
protect its clients from the ill effects caused by year 2000 prob-
lems. The Teale Data Center (Teale) lacks a year 2000 plan that
addresses critical client services and has allocated few resources
to year 2000 tasks in general. Although Teale has developed a
time machine environment for testing a system’s ability to
function after December 31, 1999, it does not monitor its cli-
ents’ use of this environment. Neither has Teale required clients
to abandon noncompliant software that could corrupt data or
destabilize its processing environment.
In contrast, the Health and Welfare Data Center (HWDC) has a
comprehensive year 2000 plan that addresses critical client
services and has devoted significant resources to executing its
plan. The HWDC also encouraged its clients to perform year
2000 testing in its time machine environment and is monitoring
client use to ensure its mainframe computers are year 2000
ready. In addition, the HWDC is precluding its clients from
using software that is not year 2000 compliant.
With time running out and no potential for an extension, it is
troubling to find so many computer systems that support such a
large number of state programs—many delivering vital services
to Californians—are still in need of some remediation before
state agencies can ensure the risk of failure is minimal. What is
more disturbing is that many of the same agencies that have not
fully remediated the computer systems supporting their pro-
grams also have not completed business continuation plans to
deliver services if their efforts are further delayed or fail to work.
Finally, of additional concern is the fact that no single entity is
charged with overseeing the year 2000 readiness of electric and
telecommunication utilities essential to the delivery of state and
other public services. Instead, a variety of entities, including
commissions, elected boards, and nonprofit organizations,
regulate and monitor portions of the systems. For example, the
California Public Utilities Commission is monitoring portions of
the electrical industry and all of the telecommunication provid-
ers in California, but it just began these efforts and may not
present results until at least April 1999. Further, although the
North American Electrical Reliability Council is monitoring
efforts on a national level, its reported results are preliminary
and based on self-reported information.
2 C A L I F O R N I A S T A T E A U D I T O R
RECOMMENDATIONS
To ensure that state agencies’ systems are year 2000 ready and
that California’s vital services are not interrupted at the begin-
ning of the new millennium, the governor or the Legislature
should do the following:
• Appoint an independent quality assurance agent or indepen-
dent verification and validation group to review critical
systems supporting the 17 programs we believe are vital to
California to validate that state agencies have found and
corrected all date references in their systems.
Until this appointed authority certifies that an agency has
completed all testing, remediated embedded technology, and
fully addressed all data exchange issues within its control,
the governor or the Legislature should direct the Department
of Information Technology or other governing body to deny
the agency approval for any new information technology
projects.
• Closely monitor the progress of the systems supporting state
programs that have not completed efforts to resolve year
2000 problems. If progress appears to be falling behind
completion milestones, the governor or the Legislature
should consider what tasks remain, whether adequate
resources are available to complete them, and take appropri-
ate action to ensure successful completion. Such action could
include assisting agencies in obtaining outside resources,
such as consultants, or reallocating knowledgeable staff from
other agencies.
• Monitor all agencies’ efforts to ensure the completion of
business continuation plans by June 30, 1999.
• Designate one authority to assess, oversee, and report on
the year 2000 preparations of critical public utilities
serving California, such as electricity and telecommunica-
tion services.
To affirm that its own computer systems will operate properly
after January 1, 2000, Teale should monitor its clients’ use of its
time machine environment and consider further testing for
those portions of the systems not tested by clients. Further, to
ensure that its clients are given the opportunity to investigate
whether they could be at risk of system interruptions, Teale
C A L I F O R N I A S T A T E A U D I T O R 3
should notify the six clients that used an earlier software version
in its time machine environment. Finally, to avoid the potential
for data corruption and instability in its operating system, Teale
should remove any noncompliant software products from its
computers before January 1, 2000.
AGENCY COMMENTS
The governor’s office (office) agreed with our findings and stated
that the new administration is keenly aware of the challenges
posed by the year 2000 problem. The office also stated that the
governor will soon announce a plan that will address the issues
identified in our report.
The Teale Data Center (Teale) agreed with our recommendation
that it notify clients that used an earlier software version in its
time machine. Teale disagreed with our conclusion that it lacked
a successful strategy for its year 2000 remediation plan, but is
researching methods available to monitor clients’ use of its time
machine. The Health and Welfare Data Center agreed with our
findings but chose not to respond formally.
4 C A L I F O R N I A S T A T E A U D I T O R
INTRODUCTION
BACKGROUND
T
he State faces a tremendous challenge as it prepares
its computer systems for processing dates beyond
December 31, 1999. Most computer systems are designed
to use only the last two digits of a year because this convention
conserves computer storage space that was once at a premium.
However, on January 1, 2000, systems using two-digit date fields
may produce invalid results or fail because they will read the
date “00” as 1900 rather than 2000.
The year 2000 date recognition problem will affect many of the
State’s computer systems. Resulting errors could impair benefits
eligibility, motor vehicle licensing and registration, or any other
date-sensitive functions. The year 2000 problem also affects
systems using embedded technology, such as computer chips to
control or operate equipment, and those systems that depend
on the exchange of data with other organizations, such as local
counties or the federal government.
Many state and local agencies also receive computer hardware
and software support for the applications they use in delivering
program services from two state data service centers: the Health
and Welfare Data Center (HWDC) and the Teale Data Center
(Teale). The HWDC caters to the information technology needs
of the State’s health and human services agencies while Teale
offers information technology services to all other agencies that
need it. Both data centers provide extensive data telecommuni-
cations network services that allow their clients to do business
electronically with other entities spread all over the State and
offer sophisticated mainframe computer support and the use of
Internet services. To assist clients in determining whether they
have successfully freed their application programs from year
2000 problems, both data centers also offer isolated computer
test environments, called time machines. These time machines
provide a way for the two data centers’ clients to test all applica-
tion programs comprising their respective computer systems in a
production environment by physically setting the internal clock
of the data centers’ computers to various dates occurring in both
the current and future centuries.
C A L I F O R N I A S T A T E A U D I T O R 5
Because of the magnitude of the problem and the potentially
disastrous consequences to Californians, the former governor
issued an executive order in October 1997 requiring all state
agencies to identify and fix year 2000 problems in their essential
computer systems no later than December 31, 1998. Essential or
mission-critical systems are defined in the State Administrative
Manual as so important that their failure would cause a signifi-
cant negative impact on the health and safety of Californians,
the fiscal or legal integrity of state operations, or the continua-
tion of essential state agency programs.
To address this important issue, the former governor designated
the Department of Information Technology (DOIT) to oversee,
coordinate, and report on the efforts agencies are making to
ensure that the State’s computer systems are fixed to recognize
the year 2000. DOIT requires agencies, departments, boards, and
commissions (state agencies) under its purview to report the
status of both their critical and noncritical computer systems
and associated remediation efforts on a monthly basis.
The new governor recognizes the significance of the year 2000
bug and proposed action. Specifically, the governor stated in his
1999-2000 budget, “The Administration will appoint a task force
to immediately evaluate the State’s mission-critical systems. The
Administration will perform assessments to validate that mis-
sion-critical services have been identified and are ready to
function smoothly in the new millennium. Should the evalua-
tion uncover any significant concerns about any mission-critical
activity, the Administration will recommend actions necessary
to minimize the risk of failure and ensure that appropriate
contingency plans are in place.”
Figure 1 illustrates the typical remediation phases necessary to
ensure that a computer system is fixed and thus ready to support
an agency’s uninterrupted delivery of services.
Most agencies have completed the first few remediation phases
and are now working on the testing or implementation phase.
Industry experts consider testing to be the most crucial and
time-consuming phase, sometimes taking up to 70 percent of
total project time and resources needed to fix a system. Each
system component must be thoroughly tested, preferably in a
time machine environment. Agencies must also exercise due
diligence by adequately planning their testing activities and by
retaining sufficient test documentation to demonstrate that the
6 C A L I F O R N I A S T A T E A U D I T O R
FIGURE 1
Phases Necessary to Ensure Uninterrupted Service Delivery
Identify Systems with Year 2000 Problems O
N
G
O
System Assessment
I
Determine the remediation strategy N
G
System Solution, Design, and Planning B
U
Develop detailed plan with activities, costs, and time lines S
I
N
System Development and Modification E
S
Execute the remediation plan S
C
System Testing O
N
Thoroughly test the system, including the following:
T
.
Testing internal interdependencies I
. N
Testing external data exchanges
. U
Testing in a simulated production environment, A
using time machine or other suitable tests T
.
Testing for the effect of embedded chips I
. O
Testing the system for compatibility when it is
N
part of a larger system, including tests of all
external data exchanges
. P
Acceptance testing conducted by agency L
program delivery managers A
N
N
I
System Implementation
N
The system is integrated into the business use G
Uninterrupted Service Delivery
agencies met test objectives. Additionally, each agency must
correct problems with embedded technology and resolve any
data exchange issues with other organizations.
While addressing these six phases, sound business practices
dictate that each agency should develop an appropriate business
continuation plan to back up their remediation efforts. Such
C A L I F O R N I A S T A T E A U D I T O R 7
plans identify alternative procedures to ensure uninterrupted
service delivery in the event that remediation efforts are not
completed by January 1, 2000, remediation is unsuccessful, or
data from external data-exchange partners corrupts a system.
STATE AGENCIES RELY ON ELECTRIC AND
TELECOMMUNICATION UTILITIES
Nearly all state agencies use computer systems to deliver the
services they provide. In turn, these computer systems are
largely dependent on electric and telecommunication utility
providers to operate. The utility industries, like state agencies,
face the daunting task of making their respective infrastructures
ready for the year 2000, including minimizing the risks of
disruptions or outages in power and telecommunications caused
by year 2000 problems. Private, investor-owned entities—for
example, Pacific Gas & Electric and Pacific Telephone—or public
entities, such as the Sacramento Municipal Utility District,
supply California with electricity and telecommunications. State
and federal agencies regulate many, but not all, utility providers.
The California Public Utilities Commission (PUC) regulates
investor-owned utilities but not public entities, which local
officials, such as a city council, board of directors, or county
board of supervisors, generally oversee. According to the PUC,
its regulated utilities serve about 75 percent of the electricity
customers and all telecommunication customers in California.
The federal government also regulates utilities. For example, the
U. S. Federal Communications Commission regulates interstate
and international communications for wired and wireless tele-
phone communications, and the U. S. Nuclear Regulatory
Commission regulates nuclear power plants.
SCOPE AND METHODOLOGY
The Joint Legislative Audit Committee asked us to assess state
agencies’ year 2000 progress. We were primarily to determine
the status of year 2000 remediation for agencies that have
defined their systems as mission-critical and also to assess
progress on selected systems that are not as critical. We also
surveyed the progress of state agencies not required to report
to DOIT. Finally, we determined the extent to which state
agencies have addressed year 2000 threats caused by
embedded technology.
8 C A L I F O R N I A S T A T E A U D I T O R
To gain an understanding of the year 2000 problem and the
measures the State is taking to ensure compliance, we reviewed
applicable laws and other background information. We selected
14 agencies whose programs affect the immediate safety, health,
or economic well-being of a large number of Californians. To
choose the 14, we considered the number of residents their
critical services would immediately impact and the likelihood
that the services would be needed at the beginning of the mil-
lennium. We visited these agencies and assessed their progress
toward year 2000 remediation for selected computer systems as
of December 31, 1998. Table 3 in Appendix A lists the 14 agen-
cies and 17 programs we identified and briefly describes their
critical services. We also visited 2 state data centers that provide
vital computer services to state agencies and assessed their
remediation efforts.
Our focus was not to measure technical compliance with DOIT’s
reporting requirements, but rather to assess the status of systems
critical in supporting program services vital to California at
December 31, 1998. Therefore, for remediation to be considered
complete for the systems supporting these vital programs, we
considered three key steps: all planned testing must have been
completed, threats from embedded technology must have
been removed, and potential problems caused by data exchange
partners must have been addressed.
In addition, we assessed whether the agencies had developed
business continuation plans that would ensure the delivery of
critical services should efforts to fix the computer systems be
unsuccessful or not completed on time.
To gain a broader perspective on the overall readiness of the
State’s computer systems for the year 2000, we developed a
questionnaire and surveyed all 140 agencies listed in the
1998-99 Governor’s Budget. Collectively, these 140 agencies
administer all of the 462 separate budgetary programs listed in
the budget. We distributed two different surveys to gather
information on agencies’ awareness of the year 2000 problem
and to assess their progress toward fixing their computer
systems.
The first survey asked seven questions designed to measure the
year 2000 readiness for the computer systems supporting each of
the 462 programs administered by the 140 agencies. We focused
these questions on four distinct areas: fixing and testing the
systems, fixing threats from embedded technology, identifying
C A L I F O R N I A S T A T E A U D I T O R 9
and fixing potential problems caused by data exchange partners,
and establishing business continuation plans. Appendix B
presents the results of this survey. To analyze this information,
we separated the survey responses into three groups: those from
agencies with mission-critical systems, those from agencies with
only noncritical systems, and those from agencies that are not
required to report to DOIT.
To assess whether the 45 agencies that are not required to report
to DOIT will be ready for the year 2000, we used a second survey
to obtain additional information. Specifically, we asked each
agency whether it had a plan to become year 2000 compliant
and a central person to implement the plan, and whether it
made periodic progress reports. The results of this survey are
shown in Appendix C.
Our assessment of agencies’ progress differs from DOIT’s moni-
toring. DOIT primarily monitors progress toward fixing systems
designated by the agencies as mission-critical. In contrast, our
first survey asked agencies to consider all systems that support
each of their programs. We believe that our broad focus more
accurately reflects the overall readiness of state agencies to
provide the variety of services California depends upon.
Finally, we also assessed how state agencies will be affected
by public infrastructure (electricity and telecommunications
utilities) and determined what actions state regulators are
taking to measure and report the year 2000 readiness of these
critical utility providers. Specifically, we contacted the PUC and
reviewed other infrastructure information. n
10 C A L I F O R N I A S T A T E A U D I T O R
CHAPTER 1
Many Agencies That Provide Critical
Services to Californians Are Not Yet
Year 2000 Ready
CHAPTER SUMMARY
T
he 14 agencies that administer what we believe are
California’s 17 most critical programs affecting public
health and safety, revenue collection, and benefit pay-
ments have all developed comprehensive plans for making their
computer systems free of year 2000 date problems. In doing so,
most have identified and fixed the computer date recognition
code and have tested, or plan to test, their systems’ ability to
accurately recognize dates after the new millennium begins.
However, 11 agencies have yet to take one or more key steps to
completely fix their systems. None of these 11 agencies have
fully tested their computer systems, and many have not ad-
dressed the threats posed by embedded chips that control cer-
tain computerized activities or completely resolved critical issues
with their data exchange partners. Although some agencies
consider their systems fully remediated, we found these agen-
cies’ systems may not be ready to operate in the next millen-
nium, which would interrupt services vital to Californians.
Furthermore, because their test plans were incomplete and they
did not document test results, some agencies will not be able to
quickly identify and correct problems should their systems fail,
nor can they demonstrate they exercised due diligence in
remediating their computer systems. Without sufficient test
plans and documentation of the outcome of the testing, these
agencies have little defense against lawsuits if a system fails.
Finally, while most of the agencies we visited indicated they are
currently developing business continuation plans to ensure the
uninterrupted delivery of critical services in the event
remediation efforts fail or are delayed, only one had completed
such a plan. Having a back-up plan becomes even more crucial if
the agencies have not completed all fundamental steps to year
2000 readiness. In fact, seven of these agencies estimate they
C A L I F O R N I A S T A T E A U D I T O R 11
will not complete business continuation plans sooner than
June 1999—possibly too late to properly test and implement
them.
BACKGROUND
State agencies are rushing to fix their computer systems prior to
the new millennium. In our August 1998 report, which assessed
the State’s preparations for the year 2000, we voiced concerns
about overly optimistic reports to the Department of Informa-
tion Technology (DOIT) on the readiness of over 600 critical
state computer systems. When the Legislature requested an
additional review in June 1998, we assessed the importance of
the services provided by the 140 agencies listed in the 1998-99
Governor’s Budget and identified 14 with programs that deliver
the most vital services to Californians. To select the 14 agencies,
we considered which services affect the immediate health,
safety, or economic well-being of large numbers of Californians.
We also considered the number of people the services immedi-
ately impacted and the likelihood they would need the services
at the beginning of the new millennium. We visited each of the
14 agencies and reviewed a sample of 20 systems that support
the delivery of these most vital programs. The results of our
on-site reviews are summarized in Table 1.
ALL 14 CRITICAL AGENCIES HAVE DEVELOPED
COMPREHENSIVE YEAR 2000 PLANS, BUT MOST
HAVE NOT COMPLETED KEY STEPS IN THE PLANS
Each of the 14 agencies we visited appointed a year 2000 project
manager and developed an overall year 2000 plan. The agencies
were also actively working to complete their planned tasks,
although some were further along than others. For instance,
most agencies have fixed the date recognition code and have
tested, or will test, this component of their systems. The plans
also appeared to have sufficient executive support and oversight
to help ensure their success. Additionally, the agencies’ plans
appropriately included strategies to address embedded technol-
ogy and potential difficulties with data exchange partners.
Despite their active planning and specific efforts to remediate
critical systems, 11 agencies still had not completed key steps
in one or more of the following areas: testing, embedded tech-
nology, and data exchange. Moreover, the Employment
12 C A L I F O R N I A S T A T E A U D I T O R
C
A
L
I
F
O
R
N
I
A
S
T
A
T
E
A
U
D
I
T
O
R
13
TABLE 1
Summary Of Systems That Support Vital Services
Agencies and Systems Reviewed Reasons For Not Being Done Due Diligence
Agency did not
complete Agency has not Agency has not Agency has not Agency did not Agency did not
year 2000 completed all fixed all threats to completely resolved have an adequate have adequate
Agency System remediation planned testing the system imposed critical issues with test plan testing
of system by embedded the system’s data documentation
by 12/31/98 technology exchange partners
Public Health and Safety
1. Health Services 1. Medi-Cal Eligibility Data System l l l
2. Water Resources 2. Dispatch l l l l
3. California Data Exchange Center l l l l l
3. Office of Emergency 4. Response Information
Services Management System l l
5. Local and Wide Area Networks l l l
4. Military Department 6. Intrusion Detection System
5. Justice Department 7. Automated Criminal History l l
8. California Law Enforcement
Telecommunications System l l
6. Corrections 9. Inmate Roster Classification System
10. Electrified Fences l l l l
7. University of California 11. Patient Scheduling (VERSYSS) l l l l
12. Medical Equipment l l l
Payments
8. Social Services 13. Case Management Information
Payrolling System l l l
9. Public Employees’ 14. Benefits System l l
Retirement System
10. State Teachers’ 15. On-line System l l l l l l
Retirement System
11. State Controller’s Office 16. Direct Deposit Claims
17. Warrant Print Processing
Revenue Collections
12. Board of Equalization 18. Integrated Revenue Information
System l l l l
13. Employment 19. Unemployment Insurance l l l
Development Department
14. Franchise Tax Board 20. Taxpayer Information
Totals 15 13 8 6 5 3
Development Department (EDD) was the only agency that
completed a business continuation plan, a final measure to
ensure uninterrupted services. Another 2 of the 14 agencies did
indicate, though, that such planning did not apply to their
systems.
MANY AGENCIES HAVE NOT COMPLETED KEY STEPS
FOR YEAR 2000 REMEDIATION OF CRITICAL SYSTEMS
In October 1997, the former governor issued an executive order
requiring state agencies to find and fix year 2000
problems in all critical systems no later than De-
Eleven Agencies Reviewed Have Not cember 31, 1998, including protecting systems from
Completed Year 2000 Remediation corrupted data received from data exchange part-
Board of Equalization ners. The executive order requires agencies not
exempted to report to DOIT concerning their
Corrections
progress. Further, the executive order precludes
Emergency Services
state agencies from beginning any new information
Employment Development Department technology projects until all such critical systems
Health Services are fixed. We are concerned that of the 14 agencies,
only the Military Department, Franchise Tax Board,
Justice Department
and State Controller’s Office had completed all the
Public Employees’ Retirement System
necessary measures to ensure their ability to per-
Social Services
form critical business operations after the new
State Teachers’ Retirement System millennium by the December 1998 deadline.
University of California
If agencies have not completed all their planned
Water Resources
testing, addressed threats posed by embedded chips
in devices their systems depend on, and completely
resolved critical issues with their data exchange
partners to ensure that data transmitted through interfaces will
not corrupt their computer systems, then California may not
continue to receive the critical services it depends on.
Furthermore, according to our understanding of the former
governor’s executive order, 14 of the systems we reviewed
should have been completed by December 31, 1998, but are not.
Specifically, monthly reports submitted to DOIT by agencies
label 8 systems as mission-critical. Our inquiries to the respon-
sible agencies identified the remaining 6 systems.
14 C A L I F O R N I A S T A T E A U D I T O R
Not only have the 10 agencies responsible for these
These Three Agencies Incorrectly
critical systems failed to meet the former governor’s
Reported Systems as Complete on
executive order deadline, 3 asserted to DOIT in
December 31, 1998
their year-end status report that 3 of the systems we
Employment Development Department
reviewed were fully remediated when they were
Unemployment Insurance system
not. Specifically, the agencies reported that as of
Justice Department
December 31, 1998, all year 2000 remediation work
Automated Criminal History system
had been completed for these systems and no
Water Resources further work was planned or foreseen. Contrary to
Dispatch system these assertions, we found that 2 of these agencies
had not completed all of their planned testing. One
agency also had not tested the information received
from one or more of its data exchange partners, and another
had not removed threats posed by embedded technology.
For example, the EDD reported that it had completed all
remediation work for its critical unemployment insurance
system and that no further work was planned or foreseen.
However, we found the EDD plans further testing of this system
in the third quarter of 1999. Moreover, it still must address
threats posed by embedded technology. The year 2000 project
manager for the EDD believes its report is accurate and
technically complies with DOIT’s criteria for indicating that
remediation of the system is complete. Nevertheless, our focus
was not to measure technical compliance with DOIT’s reporting
Reporting that systems requirements. Rather, we focused on assessing the status at
are complete when they December 31, 1998, of systems critical in supporting program
are not could lead to services vital to California. Irrespective of technical compliance
incorrect resource criteria, if our review determined that more testing was planned,
allocation decisions. that embedded technology the system depends on to operate
still needed to be corrected or replaced, or that the exchange of
data still posed a risk to the system, we considered that system
not yet remediated. We found that the EDD still had work to do
in two of these areas. Moreover, the fact that the EDD still plans
to test its system using a time machine precludes reporting that
the system is fully remediated when using DOIT’s reporting
criteria.
The EDD’s unemployment insurance system pays $2.9 billion to
over 3 million unemployed workers each year. If this system
fails, those who are temporarily out of work may not receive
unemployment payments and could suffer severe hardship. The
EDD said it is confident it has identified and corrected the
system’s year 2000 issues, in part because three external reviews
found no areas of potential failure. Nevertheless, it plans to
conduct time machine testing as part of its risk management
C A L I F O R N I A S T A T E A U D I T O R 15
plan, which includes taking additional measures to further
reduce the possibility or severity of failure of the most critical
parts of its unemployment insurance system.
Reporting that systems are complete when they are not could
lead to decisions in the reallocation of year 2000 resources to
work on lower-priority activities, thus jeopardizing the comple-
tion of critical remediation work.
Eleven Agencies Plan to Do More Testing
Testing a system to make sure it works as expected is a crucial
step in solving the year 2000 problem. Because proper testing
takes significant time and resource commitment, by now all
state agencies should be done with the
Testing is Incomplete testing of their critical computer systems.
at These 11 Agencies However, of the 20 systems we reviewed,
11 agencies have yet to complete planned
Testing will finish in February/March 1999
testing for 13 of the systems they identi-
Justice Department
fied as critical to the delivery of vital
Social Services
program services.
State Teachers’ Retirement System
Testing will finish in May/June 1999
For example, although the California
Board of Equalization Public Employees’ Retirement System
Emergency Services
(CalPERS) has fixed the program code and
Health Services
put the system back into production, it
University of California
plans to further test its critical benefits
Water Resources
system and projects it will not complete
Testing will finish in August/September 1999
the testing until the end of August 1999.
Corrections CalPERS is the largest public pension
Employment Development Department
system in the United States, serving over a
Public Employees’ Retirement System
million active and retired employees and
their families. Its benefits system manages
most of the members’ retirement, disabil-
ity, and survivor benefits and pays out $4.4 billion a year to
331,000 recipients. Failure of the benefits system would delay
retirement, disability, and beneficiary payments to thousands of
Californians.
Six Agencies Must Complete Time Machine Testing
Six agencies we reviewed have not completed planned time
machine testing of their systems. Time machine testing is con-
ducted in an isolated environment where the computer’s inter-
nal clock is manually set to a future date. It assures that both the
16 C A L I F O R N I A S T A T E A U D I T O R
computer application and the operating system software and its
hardware (the platform on which the application runs) will
function correctly.
Although we are encouraged that these agencies have scheduled
time machine testing, we are concerned that one agency, the
Department of Water Resources (Water Resources), has no plans
to conduct time machine testing on the dispatch system that
schedules water delivery from the state water project, which
stretches over 660 miles across the length of the State and
supplies water to two-thirds of California. Water Resources states
it does not plan to conduct time machine testing on this system
because it would be extremely time-consuming and expensive.
As we discuss further on page 20, Water Resources did state it
performed simulation testing on the dispatch system. However,
because it did not prepare any test plan or retain any documen-
tation of the results, we could not assess the sufficiency of the
testing it performed. Based on the professional literature we
researched, we believe time machine testing would thoroughly
test this critical and complex dispatch system. Therefore, we
believe Water Resources should perform time machine testing on
this system to minimize the risk of its failing and, in turn,
jeopardizing water delivery to millions of Californians.
Embedded Technology Affecting Several Critical
Computer Systems Remain Uncorrected
To reduce the risk of computer failure, state agencies must
Embedded technology is identify and correct year 2000 problems found in embedded
found in electrified fences technology affecting their systems. Embedded technology affects
around correctional a wide variety of systems that use microprocessors or chips to
institutions, in wide area control, monitor, communicate, or operate equipment. Ex-
networks, and in amples include the telecommunication servers in the statewide
terminals controlling emergency response system of the Office of Emergency Services
California’s aqueduct (Emergency Services), the optical scanners used to process EDD’s
water gates. unemployment insurance eligibility forms, remote terminal
units Water Resources uses to record water levels and control
gate settings along the California Aqueduct, and medical equip-
ment, such as heart monitors and ventilators, at the University
of California’s hospitals. To identify and fix embedded technol-
ogy is generally very labor intensive and takes a significant
amount of time. Therefore, it is imperative that these activities
are promptly undertaken.
C A L I F O R N I A S T A T E A U D I T O R 17
Seven agencies responsible for eight of the systems we reviewed
have not yet replaced or corrected embedded microchips in
equipment their systems rely on. For
example, the Department of Corrections
Seven Agencies Have Not Fixed Threats has not yet fixed the embedded technology
From Embedded Technology in electrified fences. The electrified fence
system uses electronic sensors, controllers,
Board of Equalization
Corrections computers, and programs to detect and
Emergency Services report possible attempts to breach either
Employment Development Department side of the electrified fences surrounding
State Teachers’ Retirement System
23 of the department’s 33 correctional
University of California
institutions housing over 156,000 inmates.
Water Resources
The department expects to begin repairs
and testing of the technology in February
1999 and plans to complete its work at affected prisons by
September 1999. We are concerned that such a late completion
date may not give the department enough time to thoroughly
test or correct the embedded technology in the fences should
any unforeseen delays occur.
In another example, Emergency Services will not complete its
remediation of embedded chips in its wide and local area net-
works until June 30, 1999. Californians rely on Emergency
Services to coordinate disaster response and recovery from civil
emergencies through its automated Response Information
Management System (RIMS), which runs on the office’s net-
works. RIMS electronically links areas requesting emergency
assistance with Emergency Services and other agencies that can
supply needed resources. If the networks are not fixed, the
critical RIMS will not work, and Emergency Services will have to
revert to cumbersome manual processes, significantly increasing
response time to disasters.
Data Exchange Partner Concerns Remain
In addition, we found that five agencies have not completed all
the steps necessary to protect their six
critical computer systems from missing or
Data Exchange Issues
corrupted data supplied by external data
Remain at Five Reviewed Agencies
exchange partners. The computer systems
Board of Equalization of these agencies rely on exchanges of
Health Services electronic data with other state agencies,
Social Services
governments, and private sector organiza-
State Teachers’ Retirement System
tions. Regardless of these agencies’ efforts
Water Resources
18 C A L I F O R N I A S T A T E A U D I T O R
to correct their own critical systems, corrupt data from one
noncompliant partner may cause a fully remediated system to
fail.
For example, although the Department of Health Services has
programmed its Medi-Cal Eligibility Data System (MEDS) to
accept all date formats from its data exchange partners, it has
not yet tested these programs with all its partners. MEDS gives
millions of Californians access to health care and is vital for the
payment of medical claims to thousands of health care provid-
ers. MEDS exchanges data with 58 counties, numerous medical
providers, and several state and federal agencies to determine
eligibility for health services. Until it fully tests the data ex-
changed with all its partners, the Department of Health Services
cannot assure that MEDS will continue to work seamlessly in the
year 2000.
The State Teachers’ Retirement System (STRS), the Board of
Equalization, and Water Resources have not completed the
Regardless of remediating necessary testing of externally exchanged data because they are
their own systems, some waiting for one or more of their data exchange partners to fix
agencies are at risk the systems they exchange data with. Specifically, these agencies
because they receive data have contacted their various business partners, established new
from external partners. data formats, and set tentative schedules for testing, but they are
currently waiting for one or more of their partners to finish
remediating their systems before they can test the partners’ data.
While we acknowledge that these agencies have done all that
they can at this point, remediation of their systems will not be
complete until such time as the respective data partners have
completed modifications and exchanged data are tested by the
agencies to ensure that the systems will continue to work
seamlessly in the next millennium.
For the remaining 14 systems we reviewed, 8 did not have any
interfaces with external data exchange partners. For the 6 sys-
tems that did, the responsible agencies had established contact
with their respective data exchange partners, developed sched-
ules for testing and implementing new date formats, and tested
the data supplied by the external parties.
C A L I F O R N I A S T A T E A U D I T O R 19
FOUR AGENCIES MAY NOT BE ABLE TO QUICKLY
DETERMINE THE CAUSE OF YEAR 2000 FAILURES
BECAUSE THEY LACK COMPLETE, DOCUMENTED
TEST PLANS
State agencies must exercise due diligence in remediating their
critical systems. Should these systems fail, it is crucial that the
agencies quickly isolate the causes. Analyzing previously tested
components to locate overlooked areas is one of the quickest
ways to determine the cause of a failure. However, four agencies
we reviewed will not be able to do these analyses because they
either did not prepare sufficient test plans or retained insuffi-
cient documentation of their test results. Complete documenta-
tion and a reasonable test plan are necessary to demonstrate due
diligence if a system fails and an agency is sued as a result.
We assessed whether each agency we reviewed had adequate test
plans and had documented the testing on each of 20 critical
systems. To assess the adequacy of test plans, we
Four Agencies Did Not determined if the agencies prepared any existing
Develop Adequate plans prior to the testing, appropriate end users
Test Plans for Their Systems participated in the planning and testing, and the
plans clearly identified the required results to verify
Corrections
the success of the test.
Electrified Fence system
State Teachers’ Retirement System
We found that four agencies did not develop ad-
On-line system*
equate test plans for five different systems. Water
University of California Resources, for example, neither prepared a test plan
Patient Scheduling (VERSYSS)*
for the simulation testing of its critical dispatch
Water Resources system nor retained documentation of the test re-
Dispatch system* sults. As discussed earlier in this chapter, this system
California Data Exchange Center
schedules water delivery to two-thirds of California.
* For these systems, the agency also Without a test plan, Water Resources has no evidence
failed to document test results. that it used an organized, structured method to test
and that it considered all the elements necessary to
ensure the dispatch system will continue to function
properly in the new millennium.
STRS also failed to develop an adequate test plan for the time
machine testing of its on-line system because it did not clearly
identify the criteria required to successfully pass the test. The
on-line system incorporates most of the agency’s critical busi-
ness functions into one system. It records contributions and
earnings data for over 400,000 teachers, determines benefit
eligibility, and calculates monthly payments for retirees and
their beneficiaries. In addition, the system tracks teachers’
20 C A L I F O R N I A S T A T E A U D I T O R
disability payments and payments to health insurance carriers
on behalf of its retirees. If this large and complex system were to
fail, 175,000 disabled and retired teachers and their beneficiaries
might suffer severe hardship. Without an adequate test plan,
STRS cannot ensure it has fully tested all of the critical processes
for its on-line system and safeguarded financial security for all of
its members.
Furthermore, STRS is one of three agencies that failed to suffi-
ciently document their testing. Were the on-line system to fail,
reviewers will not have the documents necessary to quickly
identify and analyze the cause of the failure by retracing the
tests performed. STRS states it is not maintaining adequate
documentation because it plans on replacing its on-line system
in March 2000 with its new State Teachers’ Automated Redesign
Team system.
If these agencies have insufficient records of system testing, they
cannot quickly isolate the cause of a failure and Californians
who depend on these agencies may have to do without critical
services for an indeterminate period.
MOST AGENCIES HAVE NOT FINISHED
THEIR BUSINESS CONTINUATION PLANS
All of the 14 agencies supplying vital services to
Estimated Completion Dates for California are highly dependent on informa-
Business Continuation Plans tion technology. During our review, we noted
that 11 have not completed business continua-
March 1999
tion plans for 16 core computer systems,
Health Services although all of these agencies indicated that
State Controller’s Office
they are now creating such plans. Despite
April 1999 efforts to fix their critical systems, these agen-
Corrections cies must develop comprehensive business
Public Employees’ Retirement System continuation plans to avoid disruption if their
remediation efforts are unsuccessful or are not
June 1999
completed in time.
Board of Equalization
Franchise Tax Board
In addition to their own risk, some agencies are
Justice Department
Social Services also susceptible to the failures and delays of
State Teachers’ Retirement System their data exchange partners. These agencies
August 1999 depend on the electrical power and telecom-
munications infrastructure. In order to have
University of California
useful business continuation plans, the agen-
Water Resources
cies’ efforts must address potential failures and
C A L I F O R N I A S T A T E A U D I T O R 21
delays of others, including data exchange partners and utilities
providers. One weak link in the chain of critical dependencies
may halt the delivery of vital services.
Agencies need to complete their business continuation plans
well in advance because long lead times are often necessary to
test and implement them. For example, if the plan is to revert to
manual operations, the agencies must hire and train new staff or
redirect and train current staff. Likewise, if an agency decides to
contract out any back-up functions, it must locate the appropri-
ate contractor and complete lengthy contract negotiations. For
planned alternatives to be successful, agencies should set sched-
ules and deadlines for implementing them. Additionally, busi-
ness continuation plans need enough lead time to adequately
test all backup systems to see if they are capable of providing the
Business continuation desired results and can be implemented within the required time
plans are important to periods.
ensure uninterrupted
services in the event that Finally, three agencies had either developed a business
remediation efforts fail or continuation plan or such planning did not apply for the
are not finished on time. systems we reviewed. The EDD completed a business continua-
tion plan for its critical unemployment insurance system. Emer-
gency Services and the Military Department, by the nature of
their respective missions, already had back-up systems in place
to ensure continued delivery of vital services supported by the
systems we reviewed.
TWO AGENCIES DEPEND ON THE FEDERAL
GOVERNMENT FOR REMEDIATING CERTAIN
CRITICAL HEALTH AND SAFETY SYSTEMS
Two agencies we visited, the Military Department and the
University of California (UC), have ties with the federal govern-
ment that may affect whether certain program services continue
or are halted after January 1, 2000. As a result, they have to
depend on federal agencies to ensure their services are not
interrupted.
We examined the Military Department to determine whether it
could deploy National Guard troops to assist in any potential
emergencies. We found that the federal Department of Defense
is responsible for remediating embedded technology in some of
the National Guard’s equipment, such as the Huey and
Blackhawk helicopters. We are concerned about this situation
because, according to a December 1998 report issued by the
22 C A L I F O R N I A S T A T E A U D I T O R
United States Office of Management and Budget (OMB), the
Defense Department received poor grades on its efforts to pre-
pare itself for the year 2000. Specifically, the OMB designated
the Department of Defense along with five other departments,
as “tier one” agencies. The OMB assigns tier one designations
when it has insufficient evidence of adequate progress. The
Department of Defense’s poor preparation may prevent the
National Guard from promptly responding to an emergency.
In addition, UC operates three research laboratories—Lawrence
Livermore National Laboratory, Lawrence Berkeley National
Laboratory, and Los Alamos National Laboratory—that research
national security issues for the United States Department of
Energy. Their projects include stewardship of the United States
nuclear stockpile and computer modeling of weapons physics.
According to UC, the Department of Energy established require-
ments for year 2000 readiness and monitors the labs’ progress
toward correcting their year 2000 problems. However, according
to the OMB, the Department of Energy is another tier one
agency showing insufficient evidence of year 2000 progress. In
fact, according to the OMB’s report, the Department of Energy
has not identified all mission-critical systems at its government
and contractor sites, and it is still assessing embedded chips and
lab equipment. The OMB report further states that the Depart-
ment of Energy’s acting chief information officer is conducting
The military department site compliance reviews in cooperation with the Office of the
and UC-managed labs Inspector General and the Office of Oversight, but the OMB
are relying on federal criticized this effort because no independent verification and
agencies for year 2000 validation contractors are being used.
assistance—but these
federal agencies received UC officials from the Laboratory Administrative Office state the
a poor rating by the labs have been preparing their critical and noncritical systems
OMB. for several years. In addition, this office said it monitors the labs’
progress by reviewing the year 2000 plans and progress reports
the labs provide to the Department of Energy and by participat-
ing in site reviews conducted by the Department of Energy. We
asked the UC for the results of one of these reviews at Lawrence
Livermore National Laboratory. UC stated that it could not
provide us the results until the report was finalized by the
Department of Energy. Because the UC is responsible for the
labs’ operation, we believe if the Department of Energy’s site
reviews indicate any deficiencies in year 2000 preparedness, the
UC must take a proactive role in monitoring corrective action to
ensure the labs are ready for the next millennium.
C A L I F O R N I A S T A T E A U D I T O R 23
RECOMMENDATIONS
To ensure that state agencies’ computer systems are year 2000
ready and that California’s vital services are not interrupted at
the beginning of the new millennium, the governor or the
Legislature should appoint an independent quality assurance
agent or an independent verification and validation group to
review the systems supporting the 17 vital programs at the 14
agencies we reviewed to validate that all date references in these
systems have been found and corrected.
In addition, to ensure that 11 of these 14 agencies focus re-
sources on remediating critical programs, DOIT (or the appropri-
ate governing body of the agency) should not approve any new
information technology projects until the independent quality
assurance agent or group certifies that the agencies have com-
pleted all testing and embedded technology remediation,
and addressed the data exchange issues over which they
have control. n
24 C A L I F O R N I A S T A T E A U D I T O R
CHAPTER 2
More Than Half of the State’s
Programs Need to Complete
Remediation and Business
Continuation Plans
CHAPTER SUMMARY
W
ith less than one year left until the new millennium,
state agencies reported that work remains to resolve
year 2000 problems in one or more of the computer
systems for over 64 percent of the 462 programs they administer.
Until all such work is done, agencies cannot be sure that the
program services they are responsible for, and on which Califor-
nians depend, will be delivered uninterrupted into the next
century. In addition, agencies responsible for over half of all
state programs have not prepared business continuation plans
for delivering program services should their year 2000 remedi-
ation efforts fail or be delayed. Although we do not consider all
of them to be as critical as those discussed in Chapter 1, we have
similar concerns about these programs.
BACKGROUND
We surveyed all 140 of the state agencies listed in the 1998-99
Governor’s Budget about the computer systems that support
their program services. These 140 state agencies administer 462
programs and provide a broad spectrum of services, from welfare
payments to the needy to apportionment funding for education.
Each program within an agency comprises a group of operations
that has common objectives. For example, the Department of
Transportation has a highway transportation program that
maintains and builds new highways and operates toll bridges
throughout the State.
We divided the 140 agencies into three groups: 55 agencies that
report on mission-critical computer systems1 to the Department
of Information Technology (DOIT), 40 agencies that report only
1As noted in the Introduction, the State Administrative Manual defines mission-
critical systems as so important that their failure would negatively impact the
health and safety of Californians or jeopardize essential state programs.
C A L I F O R N I A S T A T E A U D I T O R 25
on noncritical systems to DOIT, and 45 agencies that DOIT does
not require to report. We included the 14 agencies discussed in
Chapter 1 in the survey to obtain information on the computer
systems supporting all their programs, not just the systems
supporting the critical programs we reviewed.
These three groups of agencies have important distinctions. For
the 55 agencies reporting on mission-critical systems, the former
governor’s executive order requires that all such systems be year
2000 compliant by December 31, 1998, and precludes the agen-
cies from beginning any new information technology projects
until this goal is met. In addition, these agencies must report
their progress in remediating these critical systems to DOIT on a
monthly basis. The 40 agencies reporting noncritical systems
must also report their monthly progress to DOIT, but they have
no deadline for year 2000 compliance. DOIT does not require
the remaining 45 agencies to report on their remediation efforts
because they are either statutorily exempt or are already year
2000 compliant. Included among this last group are some fairly
large entities, such as the California Public Employees’ Retire-
ment System (CalPERS), the University of California (UC), and
California State University (CSU).
KEY REMEDIATION STEPS REMAIN INCOMPLETE
FOR ONE OR MORE COMPUTER SYSTEMS
SUPPORTING OVER HALF OF ALL STATE PROGRAMS
We determined how soon agencies estimated they will complete
remediation steps for the systems supporting their programs.
Based on our research, we believe that until all
three key steps are taken, a system cannot truly
Key Steps to Year 2000 Readiness for
be considered complete or remediated for year
Computer Systems
2000 problems. Moreover, because agency pro-
(cid:252) Complete all planned testing.
grams are typically supported by more than one
(cid:252) Remove threats caused by embedded computer system, it is important that the agen-
technology.
cies complete these steps for all systems before a
(cid:252) Resolve potential problems associated
program can be considered remediated and the
with data exchange partners.
risk of service interruptions minimized. Unless
the risks posed by year 2000 problems are elimi-
nated for all systems supporting a given program,
Californians depending on that program’s services may be
deprived on January 1, 2000.
26 C A L I F O R N I A S T A T E A U D I T O R
Over 64 percent of all state programs still have not completed all
three key steps to prepare their computer systems for the year
2000. In responding to our survey, agencies indicated that they
had not completed one or more steps for the computer systems
supporting 296 programs by December 31, 1998. Table 2 sum-
marizes the results of our survey. The full survey appears in
Appendix B.
TABLE 2
Summary of Survey Results for All 462 State Programs
Number Number
Responses of Agencies of Programs
At least one key step for year 2000 83 296
remediation had not been completed
by December 31, 1998
Year 2000 remediation (except 52 97
business continuation plans) had
been completed by December 31, 1998
None of the seven survey questions 38 62
applied to the program
No response 6 7
Totals 179a 462
a Agencies total is greater than 140 because some agencies have more
than one program.
To analyze the survey results in more depth, we determined on a
quarterly basis when the agencies within each group estimated
they would complete the three key steps. Following, we discuss
our findings by group.
The 55 Agencies Reporting Mission-Critical Systems
As shown in Figure 2, as of December 31, 1998, the 55 agencies
that report mission-critical systems to DOIT indicated they still
have not completed year 2000 steps for 200 (76 percent) of their
262 programs. Moreover, key steps will remain incomplete for
74 programs on July 1, 1999, only six months from the final
deadline.
C A L I F O R N I A S T A T E A U D I T O R 27
FIGURE 2
Estimated Schedule of Completion for
55 Agencies Reporting Mission-Critical Systems
200 Number of Programs Not Complete
160
74
43
0
Jan-01-1999 Apr-01-1999 Jul-01-1999 Oct-01-1999 Jan-01-2000
Forty Agencies Report Only Noncritical Systems
We next analyzed the survey responses from the group of
agencies that report only noncritical systems to DOIT. These
40 agencies administer 100 state programs. As shown in
Figure 3, the respondents indicated they did not complete by
December 31, 1998, at least one key step toward year 2000
compliance for one or more computer systems supporting 40
percent of their programs. Moreover, the agencies estimate that
at least one step will remain incomplete for 7 programs on
July 1, 1999.
FIGURE 3
Estimated Schedule of Completion for
40 Agencies Reporting Only Noncritical Systems
40
36 Number of Programs Not Complete
7
3 0
Jan-01-1999 Apr-01-1999 Jul-01-1999 Oct-01-1999 Jan-01-2000
28 C A L I F O R N I A S T A T E A U D I T O R
DOIT Reporting Is Not Required of 45 Agencies
Finally, we analyzed the survey responses from the group of
agencies that are not required to report to DOIT. These 45
agencies include UC, CSU, and CalPERS, and are collectively
responsible for administering 100 state programs. As shown in
Figure 4, they did not complete at least one key year 2000
remediation step by December 31, 1998, for 56 of the programs.
Furthermore, by July 1, 1999, at least one step will remain
for 37 programs.
The delayed completion for many programs in this group may
be partially explained by the survey responses we received from
CSU. As shown in Appendix B, page 65, CSU indicated a
completion date of December 1, 1999, for all of its nine pro-
grams related to each of our seven questions. According to its
year 2000 director, CSU used the last date any of its campuses
identified as the completion date for all programs at all cam-
puses. Further, CSU indicated that it could not organize its data
on year 2000 progress in the same manner as our survey, which
focused on budgetary programs. Although UC had a similar
problem with the format of our survey, it provided alternative
information, which appears in Tables 5 and 6 in Appendix B.
Finally, like CSU, Hastings College of the Law also used the date
of December 1, 1999, for many survey responses but did not
explain further. (A list of these 45 agencies is found in Table 7,
beginning on page 74.)
FIGURE 4
Estimated Schedule of Completion for 45 Agencies
Not Required to Report to DOIT
56
52
Number of Programs Not Complete
37
20
1
Jan-01-1999 Apr-01-1999 Jul-01-1999 Oct-01-1999 Jan-01-2000
C A L I F O R N I A S T A T E A U D I T O R 29
KEY REMEDIATION STEPS REMAIN
FOR STATE AGENCIES
Overall, we are concerned that critical year 2000 remediation
steps remained for one or more of the computer systems sup-
porting nearly two-thirds of all state programs on December 31,
1998. Moreover, based on agency estimates, by July 1, 1999, key
steps will remain for 118 programs. While state agencies have
clearly progressed toward year 2000 readiness and are estimating
continued advancement, the ultimate due date of January 1,
2000, cannot be delayed. As time runs out, any unforeseen
problems may further delay completion, thereby increasing the
risk that some programs may fail to provide important services
to Californians.
ALMOST HALF OF ALL STATE AGENCIES ALSO NEED
TO DEVELOP BUSINESS CONTINUATION PLANS
In addition to surveying agencies about their progress toward
remediation, we asked whether the agencies had developed
business continuation plans for all 462 programs. The agencies
had not completed business continuation plans for 248 pro-
grams. Moreover, agencies will not complete 90 of these plans
until after July 1, 1999. The agencies did, however, indicate that
they had completed business continuation plans for 96 pro-
Agencies estimate that grams. They also responded that 111 others did not need plans,
business continuation presumably because these programs are nonessential. Finally, we
plans for 90 state received no reply from 6 agencies responsible for 7 programs.
programs will not be
completed until July 1999 We believe that agencies should have business continuation
or later. plans completed for all their essential programs no later than
June 30, 1999, because long lead times are often necessary to test
and implement these plans. This becomes increasingly impor-
tant when the three remediation steps—completing all planned
testing, removing threats caused by embedded technology, and
resolving potential problems associated with data exchange
partners—are also incomplete, as is the case for 296 programs.
NEARLY ALL AGENCIES NOT REPORTING TO
DOIT HAVE COMPREHENSIVE YEAR 2000 PLANS
Agencies reporting to DOIT must submit comprehensive year
2000 remediation plans; however, because no single state agency
oversees the efforts of the 45 nonreporting agencies, they may
30 C A L I F O R N I A S T A T E A U D I T O R
not be required to do this. We sent these agencies a separate
survey to determine whether they have a general year 2000 plan
and a designated person to implement it, and whether they
have regularly reported on their progress. These factors are
essential for a comprehensive and successful year 2000 effort;
however, prior to our survey, no single entity knew whether
these agencies had such plans. Some entities included in this
group are UC, CSU, Board of Governors of the California
Community Colleges, CalPERS, and the judicial branch of
state government.
The results of our survey, which appear in Appendix C, indicated
that 39 of the 40 agencies responding either had a year 2000
plan or did not need one. One agency, the Santa Monica Moun-
tains Conservancy, indicated that it was too small and did not
have any budget for a year 2000 plan. In addition, 73 percent
indicated that they had a specific person responsible for imple-
menting the agency’s plan. Moreover, the large agencies in this
group, such as UC, CSU, and CalPERS, have plans and a desig-
nated person to oversee them, and they each periodically report
to executive management on the progress of their efforts.
RECOMMENDATIONS
To ensure that state agencies complete all the necessary tasks to
make their computer systems year 2000 ready, the governor or
the Legislature should closely monitor the progress for any
systems whose resolution of year 2000 problems is not complete.
If progress appears to be falling behind planned completion
milestones, they should consider what tasks remain, whether
adequate resources are available to complete them, and if not,
take prompt action to ensure successful completion. Such action
could include assisting agencies in obtaining outside resources,
such as consultants, or reallocating knowledgeable staff from
other agencies.
In addition, to ensure that state agencies are prepared to
deliver essential services even if their computer systems fail on
January 1, 2000, the governor or Legislature should monitor the
agencies’ efforts to complete business continuation plans by
June 30, 1999. n
C A L I F O R N I A S T A T E A U D I T O R 31
Blank page inserted for reproduction purposes only.
32 C A L I F O R N I A S T A T E A U D I T O R
CHAPTER 3
The State’s Two Primary Data Centers
Are Not Equally Prepared
for Year 2000 Problems
CHAPTER SUMMARY
T
wo of the State’s large data centers serve the information
technology needs of most state agencies. The success of
literally hundreds of state agencies’ year 2000
remediation efforts depends upon the ability of these data
centers to support the agencies’ computer programs with a
reliable and compliant operating environment. No matter how
much effort these agencies expend in fixing and testing their
respective computer programs, such efforts will fail if the data
centers are not equally vigilant in remediating the computer
systems that support their state clients’ programs.
One of the centers, the Health and Welfare Data Center
(HWDC), has an overall year 2000 plan that addresses the
services critical to its clients and has allocated significant re-
sources to execute its plan. The HWDC has also encouraged its
clients to perform year 2000 testing in its time machine environ-
ment and is monitoring clients’ use of this testing facility to
ensure its mainframe computers are year 2000 compliant. In
addition, the HWDC is precluding its clients from using software
that is not year 2000 compliant.
In contrast, the Teale Data Center (Teale) lacks a year 2000 plan
that addresses critical client services and has dedicated few
resources to year 2000 tasks in general. Although Teale has
developed a time machine testing environment, it does not
monitor its clients’ use of this testing facility. Further, Teale
has not required clients to abandon noncompliant software
products.
BACKGROUND
The State operates two large data centers, the HWDC and Teale,
which provide information technology infrastructure to over
300 clients, including state agencies and several county
33
governments. This infrastructure is composed of large main-
frame computers and data management systems. The data
centers operate and maintain the hardware and the operating
system software, while the individual clients generally
maintain specific applications developed to support their
business functions.
The two large data
centers provide computer Both data centers also operate large data telecommunication
infrastructure to over 300 networks that connect their clients to remote local area net-
clients, including state works as well as to the data centers’ mainframe computer
agencies and county systems and the Internet. Teale’s network connects approxi-
governments. mately 1,000 state offices and HWDC’s network connects ap-
proximately 1,500 state and county offices.
To assist their clients in preparing for the year 2000, both data
centers provide special isolated computer environments, called
time machines, as a way for their clients to test critical systems
by setting the computer’s internal calendar to various dates in
the future, including January 1, 2000, and beyond. We believe
that such testing is an important step agencies can take to
increase their assurance that their computer systems will operate
uninterrupted by year 2000 problems.
THE HWDC’S PLAN APPEARS REASONABLE
We reviewed the overall year 2000 plan for one of the State’s two
large data centers, the HWDC, and found it to be generally
sound. Specifically, the HWDC has a well-developed plan and
has dedicated 17 full-time staff to implement it. The plan identi-
fies systems with year 2000 problems, outlines a remediation
strategy, and defines how its management will monitor the
remediation efforts. The HWDC also encourages its clients to use
its time machine to test their critical computer programs. As an
added benefit, the HWDC plans to monitor client time machine
testing to gain assurance that its computers will operate cor-
rectly after January 1, 2000. In addition, this data center has
appropriately precluded clients from using noncompliant soft-
ware that could jeopardize its mainframe computers.
The HWDC provides large computers and related hardware, such
as tape drives and printers, plus the operating system software
and the telecommunications network needed to connect 1,500
state and county offices throughout California to the data
center’s computers in Sacramento. In turn, clients provide the
specific application software necessary to fulfill their respective
34
business requirements. For example, the Department of Health
Services is responsible for maintaining the application software
for its Medi-Cal Eligibility Data System (MEDS), while the
HWDC provides the computer hardware and operating system
on which the MEDS operates.
Of the 30 critical systems identified by the chief information
officers at the State’s health and human services agencies,
25 are supported at the HWDC by an IBM operating system
called Multiple Virtual Storage (MVS). The HWDC encouraged
its clients to schedule time machine testing, and, as of
December 31, 1998, five state agencies had used the time ma-
chine to test 16 systems. The HWDC has created, or will create,
different time machine environments for each major type of
computer it operates. We focused our review, however, on the
MVS mainframe time machine because most of the data center’s
clients use this type of computer.
The HWDC’s year 2000 The HWDC monitors all client testing to verify that the MVS
plan includes monitoring operating system software will function properly in the next
client testing to verify millennium. Specifically, the HWDC tracks which portions of
that its MVS operating the operating system software clients use. If clients do not test
system will function critical components of the software, then the HWDC may either
properly in the next test it, investigate whether another organization (not an
millennium. HWDC client) has successfully tested that same version at a
different data center, or accept a vendor’s certification for the
untested components.
As an additional effort to ensure that its clients’ software pro-
grams are free from year 2000 problems, the HWDC requires
that they discontinue using noncompliant software products. To
help them do so, the HWDC notified clients of the dates when
compliant software would become available and when it would
remove all older, noncompliant versions of software from its
computers.
According to experts we contacted, removing noncompliant
software is prudent for two reasons. First, retaining this software
heightens the risk that it could pass corrupted data on to other
client applications and programs. Second, there is a small risk
that noncompliant software could destabilize the underlying
operating system software, which could jeopardize all data
center clients using the same computers.
35
TEALE’S APPROACH IS RISKY
In contrast to the HWDC, Teale, the other critical state data
center, lacks a successful strategy for its year 2000 remediation
plan. Teale also has devoted few resources to year 2000 activities.
Even though the data center serves over five times more clients
than the HWDC—about 250 agencies and local governments—it
has assigned only two full-time staff to year 2000 remediation.
To its credit, Teale has created a time machine environment
In contrast to the HWDC, for its clients to test its MVS operating system, and, similar to
Teale does not monitor the HWDC, plans to use client testing to affirm that its own
clients’ use of the MVS computers will operate properly after January 1, 2000. However,
time machine and thus, Teale does not monitor its clients’ use of the time machine to
cannot assure clients that determine which components of the system clients are testing.
the operating system will Unless Teale monitors these tests, it cannot ensure it has success-
work in the next fully remediated its operating system to support its clients’
millennium. business needs into the next millennium.
For instance, one of Teale’s clients, the State Controller’s Office
(Controller’s Office), which is responsible for disbursing all state
funds, is considering moving its mainframe computer systems to
Teale’s mainframes. According to the Controller’s Office, the
computer it uses to support 24 mission-critical systems is out-
dated, and it is almost constantly in use so it cannot be used for
time machine testing. By transferring its systems to Teale’s more
modern mainframes, the Controller’s Office has the option to
use Teale’s time machine. If it does transfer its systems to Teale,
the Controller’s Office will rely upon Teale to ensure that the
mainframe operating system is year 2000 compliant. However,
Teale’s failure to track the portions of the MVS operating system
its customers test will limit its ability to measure the year 2000
readiness of the system and to provide such assurance to its
clients.
Additionally, Teale allowed six clients to use the time machine
with an earlier, compliant version of system software to deter-
mine year 2000 readiness and failed to inform them of this fact.
As of November 1998, the clients had already tested 10 of their
computer systems with the time machine. According to Teale
staff, the center upgraded the MVS operating system software on
December 27, 1998; therefore, the software that will actually be
in use beginning January 1, 2000, is a newer version than the
one the six clients tested.
36
We asked two independent experts, the Garner Group and IBM,
whether this software upgrade would adversely affect the valid-
ity of the time machine tests performed prior to December 27,
1998. According to both experts, the software upgrade would
probably not affect date calculations and, thus, the validity of
the tests; however, to be sure, Teale should give each client the
opportunity to investigate the potential impact on their indi-
vidual systems. We suggested that Teale notify the six clients
affected by the software upgrade, and Teale indicated it would
do so.
Finally, Teale is not requiring its clients to discontinue using
noncompliant commercial software products. Instead, Teale used
a letter to notify its clients on December 1, 1998, that certain
Teale is not requiring its software products are not year 2000 ready. However, it did not
clients to discontinue identify when compliant software would be available or set a
using noncompliant date when the noncompliant software would be removed from
commercial software. the data center computers. Instead, Teale stated in the letter that
it will not assume responsibility or accept any liability arising
from the functioning of agencies’ systems, applications, or
software after December 31, 1999. However, because of the
potential risk that noncompliant software could corrupt data or
lead to an unstable processing environment, we believe that
Teale should be more aggressive and set a deadline for removing
all noncompliant software from its computers.
RECOMMENDATIONS
To affirm that its own computers will operate properly after
January 1, 2000, Teale should monitor its clients’ use of its time
machine and consider further testing for those components not
tested by the clients. Further, to ensure that its clients’ computer
systems operate without interruption and to allow certain
clients the opportunity to research whether additional testing is
required, Teale should notify the six clients that used an earlier
software version in Teale’s time machine. Finally, Teale should
take action to remove any noncompliant software products from
its computers before January 2000. n
37
Blank page inserted for reproduction purposes only.
38
CHAPTER 4
The State Must Coordinate Efforts to
Ensure Year 2000 Problems Will Not
Interrupt Essential Utilities, Such as
Electricity and Telephone Services
CHAPTER SUMMARY
E
ven state agencies’ best efforts to make their computer
systems year 2000 ready could prove meaningless if
essential utilities are not available. Nearly all state agen-
cies, as well as the private sector, deliver essential services to
Californians by means of computer systems that depend on
electric and telecommunication utilities. The major power
failure that occurred in San Francisco in December 1998 dra-
matically illustrates how quickly and broadly the loss of
electricity in particular can impact everyone.
Although no single entity is charged with overseeing the
year 2000 preparedness of all utilities in California, the Califor-
nia Public Utilities Commission (PUC), has recently begun
collecting year 2000 information from telecommunication
providers and the electric utilities it regulates. Nevertheless, it
will not complete its analysis before April 1999, delaying both
identification of, and enforcement against, unprepared provid-
ers. Additionally, its survey does not give a complete picture of
electric utilities’ readiness because it does not regulate all of
these providers.
Moreover, the State’s electrical systems are interconnected with
larger, multi-state networks, so problems outside California
could also cause service disruptions within the State. Although
results of a national assessment conducted by the North Ameri-
can Electric Reliability Council (NERC) give an encouraging
report of the electric industry’s year 2000 readiness, we consider
the results preliminary because more than half of the mission-
critical systems have not been tested. Neither has the NERC
required 2,900 distributors to prepare contingency, or business
continuation, plans.
39
Although regulators and others are collecting information on
segments of utility companies’ year 2000 remediation efforts,
we believe that a more comprehensive assessment, coordinated
and focused by a single entity at the State level, is needed to
provide state agencies with the greatest level of assurance that
essential utility services will not be interrupted by year 2000
problems.
BACKGROUND
The electrical industry in California is composed of a complex
network of local distribution lines, regional transmission lines,
and generating facilities. The electric utilities the PUC regulates
typically operate the transmission and local distribution lines
that distribute electricity to individual homes and businesses
and, in some instances, also operate the generation facilities,
such as hydroelectric, geothermal, and nuclear plants. With the
recent deregulation of the electrical industry, two new entities,
the Independent System Operator and the California Power
Exchange (Power Exchange) also play roles in California’s elec-
trical system. The Independent System Operator manages the
regional transmission lines and reliability of the system, and the
Power Exchange provides a competitive marketplace for utilities
and power marketers, brokers, and suppliers. Both organizations
are nonprofit, and the California Electricity Oversight Board
oversees them.
These electrical systems belong to one of three major electrical
grids, or regions, in North America. California is part of the
California’s electrical Western Interconnection (western grid), which serves over
systems are part of an 65 million people in 14 western states, 2 Canadian provinces,
interconnected grid and a small portion of Mexico. All of the generators and electri-
which serves 65 million cal loads within the western grid are interconnected and operate
people in 14 states and together. Overseeing the western grid is the Western Systems
portions of Canada and Coordinating Council (Coordinating Council), which develops
Mexico. operating reliability criteria and policies that its voluntary
members agree to follow. The Coordinating Council, in turn, is
part of the North American Electric Reliability Council.
Telecommunication services in California are also delivered
through a network, although it is less complex than the electri-
cal industry’s system. Typically, one carrier, such as Pacific Bell,
supplies local service, and another carrier, such as AT&T or MCI
WorldCom, provides long-distance service. However, local
40
carriers connect most long-distance calls to the long-distance
provider. Further, telecommunication providers must rely on the
electrical industry’s network to deliver their services.
ALTHOUGH THE PUC IS SURVEYING CALIFORNIA’S
TELECOMMUNICATION PROVIDERS ON YEAR 2000
READINESS, NO SINGLE STATE ENTITY IS
MONITORING CALIFORNIA’S COMPLEX NETWORK
OF ELECTRIC UTILITIES
In determining the degree of year 2000 readiness of the State’s
essential utilities, we discovered that no single organization has
a full understanding of their progress. The PUC, the Indepen-
dent System Operator, and the California Electricity Oversight
Board monitor various parts of the electrical grid, but none
monitor the progress made for all facets of the industry or report
on the year 2000 readiness of this critical service on a statewide
basis.
In fact, no single entity regulates or monitors California’s entire
electrical industry. Instead, a variety of entities, including com-
missions, elected boards, and nonprofit organizations each
The PUC regulates monitor portions of the system. For example, the PUC regulates
investor-owned utilities investor-owned utilities, such as PG&E, but does not monitor
but does not monitor municipal utilities, such as the Sacramento Municipal Utility
municipal utilities or the District, which an elected board of directors governs. Nonprofit
western grid. organizations oversee other portions of the State’s electrical
system. For instance, the nonprofit Independent System Opera-
tor controls the high-voltage transmission lines. The result is a
loose confederation of oversight and regulation. This condition
is further complicated by California’s connection to the multi-
state western grid.
Although NERC monitors efforts at a national level, it is compil-
ing self-reported information and does not isolate data from
individual states. Therefore, we cannot draw conclusions about
California’s readiness for the year 2000 from this information.
The major power failure in San Francisco on December 8, 1998,
which snarled traffic and left more than 300,000 customers
without electricity for nearly eight hours, is a dramatic example
of how quickly and broadly the loss of this utility can affect
everyone. Traffic signals and computers did not work, mass-
transit trains did not run, and businesses were forced to close for
the day. Although this outage was not attributed to a year 2000
41
problem, it illustrates the domino effect a seemingly isolated
power outage can have. Electric power is particularly vulnerable
because many systems are interconnected, underscoring the
importance of comprehensive monitoring for year 2000 readi-
ness in California’s electrical industry.
The PUC’s data on the telecommunication industry is more
comprehensive than for electric providers because it does regu-
late all of the State’s telecommunication providers. In addition,
most state agencies use a statewide telecommunications network
operated by Pacific Bell and MCI WorldCom for their telecom-
munication services. Although a recent contract between the
State and these providers requires that the network function
properly in the new millennium, portions of the network will
use existing telecommunication equipment that serve both state
and private users. As a result, state agencies will have to rely on
the general year 2000 readiness of Pacific Bell and MCI
WorldCom. Their readiness is monitored by the PUC and is
subject to the same limitations we discuss below.
THE PUC SURVEYED THE UTILITIES IT REGULATES
ON THEIR YEAR 2000 PREPAREDNESS
In November 1998, the PUC surveyed all the electric and tele-
communication utilities it regulates on their year 2000 progress.
It modeled the survey after the United States General Account-
ing Office’s Program Assessment Checklist and solicited details
on remediation efforts, replacement schedules, contingency
plans, testing, and high-priority systems, as well as other infor-
mation. The initial survey responses (progress reports) were
due on December 15, 1998, with quarterly updates beginning
March 15, 1999. In addition, the PUC asked each utility to
Results from the PUC’s certify by November 1, 1999, that all of its essential service
survey may not be delivery systems are year 2000 compliant or ready.
available until April 1999
and will provide The PUC’s survey of year 2000 progress is important; however,
information only for we are concerned about this undertaking for three reasons. First,
those utilities it regulates. we question whether the PUC can quickly identify those utilities
that are slow to progress. Second, we question whether the
PUC’s planned enforcement actions will be effective. Third,
although the PUC does have jurisdiction over the entire tele-
communication system, it does not have jurisdiction over
portions of the electrical system.
42
To assess whether a particular utility provider is slow in
remediating year 2000 problems, jeopardizing overall comple-
tion by January 1, 2000, we believe the PUC would need to
compare at least two progress reports. Since the first progress
report was due on December 15, 1998, and the second is not due
until March 15, 1999, it appears that the earliest the PUC could
identify lagging progress would be April 1999, presuming it
needs time to compile the survey responses.
We asked the PUC whether it will be able to take swift corrective
or enforcement actions once it identifies slow progress. Its
response was, “If formal enforcement action appears to be the
only clear way to secure a utility’s compliance, the commission
has the option to issue an Order Instituting Investigation.
Formal actions such as these can be initiated within a few weeks
but can take considerably longer to resolve.” If the PUC does
not identify until April utilities that may not complete year 2000
remediation by January 2000, and its enforcement actions
require a considerable amount of time to resolve, it is doubtful
whether such enforcement actions will be timely or effective.
Moreover, even if each electrical utility the PUC regulates rem-
edies its year 2000 problems, because the PUC does not regulate
about 25 percent of the electric providers in California or the
high-voltage transmission lines, it cannot assess the readiness of
the statewide electrical system.
ALTHOUGH OTHER AGENCIES MONITOR PORTIONS
OF THE ELECTRICAL INDUSTRY, A COMPLETE PICTURE
OF YEAR 2000 PREPARATIONS IS LACKING
While the PUC is monitoring its regulated utilities, the Califor-
nia Electricity Oversight Board tracks the year 2000 efforts of the
Independent System Operator and the Power Exchange. Addi-
The NERC conducted a tionally, NERC has collected national information on the elec-
national survey but its tric industry’s year 2000 readiness at the request of the United
results are preliminary States Department of Energy. Based on its survey of almost 3,100
because more than half entities responsible for generating and distributing electricity in
of mission-critical the nation, NERC indicated that 44 percent of the electrical
components have not system’s mission-critical components have been tested as of
yet been tested. November 1998. Findings thus far indicate only minimal opera-
tional difficulties, such as incorrect dates in event logs or dis-
plays, which do not appear to affect the industry’s ability to
43
supply electricity. Finally, NERC reported that approximately
200 bulk power transmitters will have operational contingency
plans completed by the end of June 1999.
In September 1998, NERC issued a report recommending that
year 2000 remediation and testing be completed by May 31,
1999, and that mission-critical year 2000 systems be ready by
June 30, 1999. To test operations under year 2000 conditions,
NERC will conduct two coordinated drills on April 9, 1999, and
September 8 and 9, 1999. NERC’s report is optimistic about the
readiness of the nation’s electrical utilities.
Although we view the report as encouraging, it is still prelimi-
nary because more than half of the mission-critical components
have not been tested yet, and NERC’s conclusions are based on
self-reported information rather than on objective assessments.
Additionally, NERC did not require 2,900 distributors to prepare
contingency, or business continuation plans. Without these
plans, NERC cannot assure the public that utilities will deliver
electricity regardless of lingering year 2000 problems.
RECOMMENDATION
The governor or Legislature should designate one representative
or agency to assess and disclose the year 2000 readiness of
critical public utilities serving California, such as electrical and
telecommunication services, to assure that utilities critical to
state agencies are year 2000 ready.
44
We conducted this review under the authority vested in the California State Auditor by
Section 8543 et seq. of the California Government Code and according to generally accepted
governmental auditing standards. We limited our review to those areas specified in the audit
scope section of this report.
Respectfully submitted,
KURT R. SJOBERG
State Auditor
Date: February 18, 1999
Staff: Doug Cordiner, Audit Principal
Bill Shepherd, CPA
Robert Cabral, CPA, CIA
Alan Ma
Reed M. McDermott, CPA
Michelle J. Tabarracci, CISA
45
Blank page inserted for reproduction purposes only.
46
APPENDIX A
State Agencies We Identified With
Vital Program Services
A
s discussed in the Scope and Methodology, we selected
14 agencies whose programs affect the immediate safety,
health, or economic well-being of a large number of
Californians. To choose the 14, we considered the number of
residents their critical services might immediately affect and the
likelihood the services would be needed at the beginning of the
millennium.
Table 3 lists the 14 agencies and 17 programs we identified and
briefly describes their critical services.
47
48
TABLE 3
State Agencies We Identified With Vital Program Services
Agency Name Program Description of Critical Program Services
Public Health and Safety
1. Department of Health Services Health Care Services Furnishes publicly financed health care to millions of low-income
California residents.
2. Department of Water Resources Implementation of the State Water Supplies water for two-thirds of California’s residents through a massive
Resources Development System water storage and delivery system of reservoirs, aqueducts, power plants,
and pumping stations, which spans two-thirds of the State.
Public Safety and Prevention of Protects life and property from damage or destruction by floods.
Damage
3. Office of Emergency Services Mutual Aid Response Coordinates response to major disasters.
4. Military Department Army National Guard Mobilizes troops in emergencies. Safeguards arms and ammunition.
5. Department of Justice Criminal Justice Information Services Supplies law enforcement and courts with critical information on criminal
histories, wanted persons, and stolen vehicles.
6. Department of Corrections Institution Program Houses over 156,000 inmates.
7. University of California Research Safeguards hazardous materials or biological substances used in
laboratory research.
Teaching Hospitals Ensures life-sustaining medical equipment at university hospitals functions
properly.
8. Department of Social Services Welfare Program Operations Assists the needy in meeting basic needs for food, shelter, and clothing.
Social Services and Licensing Provides subsistence payments for in-home care of elderly, blind, and
disabled residents, as well as neglected, abused, or exploited children and
adults who cannot protect their own interests.
49
Agency Name Program Description of Critical Program Services
Payments
9. Public Employees’ Retirement System Retirement Provides retirement benefits to over 331,000 retired public employees
and their beneficiaries.
10. State Teachers’ Retirement System Services to Members and Employers Provides retirement benefits to over 175,000 retired teachers and their
beneficiaries.
11. State Controller’s Office Disbursements and Support Disburses payment for the State’s obligations, including payments for
vendor-provided products and services; personal income tax refunds;
public employee payroll; and retirement benefits of teachers, public
employees, and their beneficiaries.
Revenue
12. State Board of Equalization Sales and Use Tax Program Collects business taxes statewide and redistributes funds to local
counties, cities, andspecial taxing authorities.
13. Employment Development Tax Collections and Benefit Payment Collects withholdings from businesses for unemployment and disability
Department Program insurance.
14. Franchise Tax Board Tax Programs Collects state income taxes from individuals, banks, and corporations
that make up a significant portion of the State’s General Fund revenue.
Blank page inserted for reproduction purposes only.
50
APPENDIX B
State Agencies’ Year 2000
Readiness: A Review of Programs
Listed in the Governor’s Budget
T
o review state agencies’ readiness for the year 2000, we
surveyed each agency listed in the 1998-99 Governor’s
Budget. Our survey asked each agency to respond to
seven questions for all computer systems supporting each of
their programs. The questions focused on the agencies’ efforts to
test their computer systems, identify and remediate interfaces
with external parties, address embedded systems, and prepare
business continuation plans. We believe that each of these areas
must be assessed, and if necessary, fixed before an agency can
consider itself prepared to deliver uninterrupted services to
Californians in the next millennium.
As Table 4 shows, we surveyed all 140 state agencies that
provide services to Californians through 462 programs. Agencies
responded to each question either by indicating the task was
complete, not applicable, or by listing an estimated completion
date. In summary, for 296 of the programs (64 percent), agencies
indicated that they had not completed one or more key steps—
conducting planned testing, removing threats caused by embed-
ded technology, and resolving potential problems associated
with data exchange partners—by December 31, 1998, for one or
more computer systems.
We analyzed the results of this survey in Chapter 2.
SURVEY QUESTIONS
Questions 1 through 4 related to testing, which is an important
part of preparing computer systems to operate correctly in the
year 2000. Industry experts generally believe that testing a
computer system will take between 50 to 70 percent of the total
time and resources necessary to make a computer system year
2000 ready. Our four questions were designed to address testing
issues for a wide variety of computer systems, including main-
frame systems where thousands of lines of computer code must
51
be reviewed, fixed, and tested. More modern systems may use
off-the-shelf software but may still require testing to be sure that
the system will operate correctly.
• Question 1: Is program code remediated and is unit-level
testing complete?
• Question 2: Is integrated testing of software units and
applications complete?
• Question 3: Have all application software and hardware
been tested in a production environment and accepted by
the users?
• Question 4: Have all systems that support this program been
tested in an isolated environment where the hardware clock
has been manually set to future dates?
Question 5 asked whether all external data exchange partners
had been identified and contacted, a data format established,
and shared data tested. Data exchange partners are external
parties who supply data to, or receive data from, an entity. In
either case, one entity relies on the other to provide data in an
agreed-upon format. Despite having completed planned testing,
improperly formatted data from exchange partners could easily
corrupt critical operations.
Question 6 asked whether embedded systems that support this
program had been surveyed, assessed, prioritized, and fixed.
Embedded systems use microprocessors or chips to control,
monitor, communicate, or operate equipment. Examples include
telecommunication equipment, control equipment in high-
speed scanners, and medical devices used in hospitals. Because
embedded systems can be found almost anywhere, agencies
must identify all of their embedded systems, assess the potential
impacts of those systems in the year 2000, and, if necessary,
develop plans to fix or replace the systems.
Finally, Question 7 asked whether business continuation plans
had been established to ensure uninterrupted services. A busi-
ness continuation plan should address problems an agency may
experience if its year 2000 efforts fail or result in delays. The
plans must also address potential failures or delays of others,
including data exchange partners and infrastructure providers.
While it is not possible for anyone to be 100 percent certain that
critical operations will continue in a real environment without
52
interruptions, business continuation plans should have clear
and well-reasoned solutions to potential problems. This is
especially important to ensure that Californians receive uninter-
rupted services, in case unforeseen problems crop up.
Table 4 contains a detailed list of the survey results, categorized
into the following groups:
• Agencies reporting mission-critical systems to the Depart-
ment of Information Technology (DOIT)
• Agencies reporting only noncritical systems to DOIT
• Agencies that are not required to report to DOIT
• Agencies that responded “n/a” to all seven questions
• Agencies that did not respond for some programs
• Agencies that did not respond to our survey
53
54 TABLE 4
Readiness Survey: Responses From Agencies About Their Programs
Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
Agencies With Mission-Critical Systems
Agricultural Labor Relations Board 10-Board Administration n/a Yes Yes Yes n/a n/a Yes
20-General Counsel Administration n/a Yes Yes Yes n/a n/a Yes
30-Administrative Services n/a Yes Yes Yes n/a n/a Yes
Air Resources Board 15-Mobile Source 12/31/99 12/31/99 12/31/99 12/31/99 Yes 12/31/99 Yes
25-Stationary Source Yes Yes Yes Yes Yes Yes Yes
30-Program Direction and Support Yes Yes Yes Yes Yes Yes Yes
35-Subvention Yes Yes Yes Yes Yes Yes Yes
Alcoholic Beverage Control Appeals Board 10-Administrative Review n/a n/a n/a n/a n/a 3/30/99 n/a
Alcoholic Beverage Control, Department of 10-Administration of the Alcoholic Beverage
Control Act 12/31/98 12/31/98 12/31/98 12/31/98 12/31/98 6/30/99 6/30/99
Boating and Waterways, Department of 20-Boating Operations 10/1/99 n/a 10/1/99 10/1/99 10/1/99 10/1/99 10/1/99
40-Administration Yes 1/31/99 1/31/99 1/31/99 n/a n/a Yes
Conservation, Department of 10-Geologic Hazards and Mineral Resources
Conservation Yes Yes Yes Yes Yes n/a n/a
20-Oil, Gas, and Geothermal Resources 6/30/99 6/30/99 6/30/99 6/30/99 6/30/99 n/a n/a
Consumer Affairs, Department of 03-Board of Accountancy 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
06-Board of Architectural Examiners 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
09-Athletic Commission 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
18-Board of Behavioral Science Examiners 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
30-Contractors’ State License Board 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
36-Board of Dental Examiners 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
51-Board of Registration for Geologists and
Geophysicists 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
54-Guide Dogs for the Blind n/a n/a 8/1/99 10/1/99 n/a 12/31/99 6/30/99
63-Medical Board of California 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
69-Board of Optometry 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
72-Board of Pharmacy 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
75-Board of Registration for Professional
Engineers and Land Surveyors 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
78-Board of Registered Nursing 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
81-Board of California Court Reporters 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
84-Structural Pest Control Board 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
55
Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
Consumer Affairs, Department of (continued) 90-Veterinary Medical Board 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
91-Board of Vocational Nurse and Psychiatric
Technician Examiners 6/1/99 7/1/99 8/1/99 10/1/99 9/30/99 12/31/99 6/30/99
Control, Board of 11-Citizen Indemnification Yes Yes Yes 3/31/99 Yes Yes Yes
21-Disaster Relief Claim Program 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 Yes
31-Civil Claims Against the State 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 Yes
41-Citizens Benefiting the State (Good
Samaritans) Yes Yes Yes 3/31/99 Yes Yes Yes
51-Administration 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/30/99
Controller, State 10-Accounting and Reporting Yes Yes Yes n/a Yes 6/30/99 6/30/99
20-Audits Yes Yes Yes n/a Yes 6/30/99 6/30/99
30-Personnel/Payroll Services Yes Yes Yes n/a Yes 6/30/99 6/30/99
40-Information Systems Yes Yes Yes n/a Yes 6/30/99 6/30/99
50-Collections Yes Yes Yes n/a Yes 6/30/99 6/30/99
60-Disbursements and Support Yes Yes Yes n/a Yes 6/30/99 6/30/99
Corporations, Department of 10-Investment Program 12/31/98 12/31/98 3/31/99 3/31/99 n/a 4/1/99 6/30/99
20-Lender-Fiduciary Program 12/31/98 12/31/98 3/31/99 3/31/99 n/a 4/1/99 6/30/99
30-Health Plan Program 12/31/98 12/31/98 3/31/99 3/31/99 n/a 4/1/99 6/30/99
50-Administration 12/31/98 12/31/98 3/31/99 3/31/99 n/a 4/1/99 6/30/99
Corrections, Department of 21-Institution Program Yes Yes 3/1/99 n/a n/a 12/3/99 5/31/99
22-Health Care Services Program Yes Yes 1/25/99 Yes n/a 6/30/99 5/31/99
31-Community Correctional Program 4/22/99 5/15/99 5/19/99 5/28/99 n/a 6/30/99 5/31/99
41-Administration Yes 3/1/99 3/1/99 5/1/99 Yes 6/30/99 7/1/99
Criminal Justice Planning, Office of 20-Administration Yes Yes Yes 6/30/99 n/a 3/1/99 6/30/99
50-Criminal Justice Projects Yes Yes Yes 6/30/99 n/a 3/1/99 6/30/99
Developmental Services, Department of 10-Community Services Program Yes Yes Yes Yes Yes n/a 6/30/99
20-Developmental Centers Program Yes Yes Yes 2/28/99 Yes 8/31/99 6/30/99
35-Administration Yes Yes Yes Yes Yes n/a n/a
Education, Department of 10-Instruction Yes Yes Yes Yes Yes 6/30/99 Yes
20-Instructional Support Yes Yes Yes Yes Yes Yes Yes
30-Special Programs Yes Yes Yes Yes Yes Yes Yes
41-Executive Management and Special Services Yes Yes Yes Yes Yes Yes Yes
42-Department Management and
Administrative Services Yes Yes Yes Yes Yes Yes Yes
Emergency Services, Office of 15-Mutual Aid Response n/a n/a n/a n/a n/a 6/30/99 6/30/99
35-Plans and Preparedness n/a n/a n/a n/a n/a 6/30/99 6/30/99
45-Disaster Assistance n/a n/a n/a n/a n/a 6/30/99 6/30/99
Note: Agencies, data centers, and programs listed in italics provide critical services to the public and were visited and reviewed by the Bureau of State Audits.
56
Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
Emergency Services, Office of (continued) 55-Administration and Executive n/a n/a n/a n/a n/a 6/30/99 6/30/99
98-State Mandated Local Programs n/a n/a n/a n/a n/a 6/30/99 6/30/99
Employment Development Department 10-Employment and Employment Related 6/4/99 7/30/99 7/30/99 12/21/99 7/30/99 n/a Yes
21-Tax Collections and Benefit Payments
Program 6/4/99 7/30/99 7/30/99 12/21/99 7/30/99 9/30/99 Yes
22-California Unemployment Insurance
Appeals Board 6/15/99 5/21/99 5/21/99 5/14/99 4/23/99 Yes Yes
30-Administration program 6/4/99 7/30/99 7/30/99 12/21/99 7/30/99 n/a 3/31/99
40-Welfare-to-Work Program Yes Yes Yes n/a n/a Yes n/a
60-Job Training Partnership Act Program Yes Yes Yes Yes n/a n/a n/a
Energy Resources Development Commission, 10-Regulatory and Planning 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99
Conservation and 20-Energy Resource Conservation 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99
30-Development 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99
40.01-Policy, Management and
Administration 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99
Environmental Health Hazard Assessment, Office of Office of Environmental Health Hazard
Assessment 3/31/99 3/31/99 3/31/99 Yes 12/30/98 12/15/98 12/15/98
Equalization, Board of 15-County Assessment Standards Program 2/26/99 3/30/99 3/30/99 n/a Yes Yes 6/30/99
20-State-Assessed Property Program 2/26/99 3/30/99 3/30/99 n/a 2/26/99 Yes 6/30/99
25-Timber Tax Program 3/8/99 5/10/99 5/31/99 5/31/99 Yes Yes 6/30/99
30-Sales and Use Tax Program 5/1/99 6/1/99 6/15/99 n/a 3/30/99 Yes 6/30/99
35-Hazardous Substances Tax Program 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
40-Alcoholic Beverage Tax Program 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
41-Tire Recycling Fee Program 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
45-Cigarette and Tobacco Products Tax 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
50-Motor Vehicle Fuel License Tax 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
55-Diesel and Use Fuel Tax 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
56-Occupational Lead Poisoning Prevention
Fee Program 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
57-Integrated Waste Management Fee
Program 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
58-Underground Storage Tank Fee 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
59-Oil Spill Prevention 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
60-Energy Resources Surcharge 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
62-Childhood Lead Poisoning Prevention
Fee Program 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
65-Emergency Telephone Users Surcharge 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
70-Insurance Tax 3/1/99 3/30/99 3/30/99 n/a 3/30/99 Yes 6/30/99
80-Appeals From Other Government Programs1/15/99 1/29/99 1/29/99 n/a Yes Yes 6/30/99
85.01-Administration 5/1/99 6/1/99 6/15/99 n/a Yes 7/1/99 6/30/99
Note: Agencies, data centers, and programs listed in italics provide critical services to the public and were visited and reviewed by the Bureau of State Audits.
57
Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
Fair Political Practices Commission 10-Fair Political Practices Commission 7/1/99 7/1/99 7/1/99 7/1/99 n/a n/a 7/1/99
Financial Institutions, Department of 10-Licensing and Supervision of Banks and
Trust Companies n/a Yes 3/1/99 1/31/99 n/a Yes Yes
20-Payment Instruments n/a Yes 3/1/99 1/31/99 n/a Yes Yes
30-Certification of Securities n/a Yes 3/1/99 1/31/99 n/a Yes Yes
50-Supervision of California Business and
Industrial Development Corporation n/a Yes 3/1/99 1/31/99 n/a Yes Yes
60-Credit Unions n/a Yes 3/1/99 1/31/99 n/a Yes Yes
70-Savings and Loan n/a Yes 3/1/99 1/31/99 n/a Yes Yes
80-Industrial Loan Companies n/a Yes 3/1/99 1/31/99 n/a Yes Yes
90-Administration n/a Yes 3/1/99 1/31/99 n/a Yes Yes
Fish and Game, Department of 10-Enforcement of Laws and Regulations n/a n/a n/a n/a n/a 4/1/99 8/1/99
15-Legal Services n/a n/a n/a n/a n/a 4/1/99 8/1/99
35-Wildlife Management and Natural Heritage
Programs 7/1/99 7/1/99 7/1/99 7/1/99 7/1/99 4/1/99 8/1/99
55-Fisheries Management 7/1/99 7/1/99 7/1/99 7/1/99 7/1/99 4/1/99 8/1/99
60-Environmental Services n/a n/a n/a n/a n/a 4/1/99 8/1/99
65-Oil Spills Prevention Program 7/1/99 7/1/99 7/1/99 7/1/99 7/1/99 4/1/99 8/1/99
70-Administration 9/1/99 9/1/99 9/1/99 9/1/99 9/1/99 4/1/99 8/1/99
Food and Agriculture, Department of 11-Agricultural Plant and Animal, Pest and
Disease Prevention n/a n/a 9/30/99 n/a n/a 9/30/99 n/a
21-Marketing; Commodities and Agricultural
Services Yes Yes 9/30/99 Yes Yes 9/30/99 Yes
31-Assistance to Fairs and County Agricultural
Activities n/a n/a 9/30/99 n/a n/a 9/30/99 n/a
41-Executive Management and Administrative
Services Yes Yes 9/30/99 n/a Yes 9/30/99 Yes
Forestry and Fire Protection, Department of 10-Office of the State Fire Marshal 1/18/99 2/26/99 3/31/99 2/26/99 n/a 6/30/99 3/31/99
11-Fire Protection 2/26/99 4/30/99 6/30/99 5/28/99 4/30/99 6/30/99 3/31/99
12-Resource Management 1/29/99 2/28/99 3/12/99 3/1/99 n/a 6/30/99 3/31/99
20-Administration 2/26/99 4/30/99 6/30/99 4/30/99 4/9/99 6/30/99 3/31/99
Franchise Tax Board 10-Tax Programs 6/30/99 Yes Yes Yes Yes 11/1/99 11/1/99
20-Homeowners and Renters Assistance 1/28/99 Yes Yes Yes 1/28/99 11/1/99 11/1/99
40-Child Support Collections Yes Yes Yes Yes Yes 11/1/99 11/1/99
50-DMV Collections Yes Yes Yes Yes Yes 11/1/99 11/1/99
60-Court Collection Program Yes Yes Yes Yes Yes 11/1/99 11/1/99
70-Contract Work Yes Yes Yes Yes Yes 11/1/99 11/1/99
98-State Mandated Local Programs Yes Yes Yes Yes Yes 11/1/99 11/1/99
Note: Agencies, data centers, and programs listed in italics provide critical services to the public and were visited and reviewed by the Bureau of State Audits.
58
Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
General Services, Department of 10-Building Regulation Services 3/31/99 4/30/99 5/30/99 Yes Yes 6/30/99 9/30/99
15-Real Estate Services Yes Yes Yes Yes Yes 6/30/99 9/30/99
20-Statewide Support Services 10/31/99 10/31/9910/31/99 Yes Yes 6/30/99 9/30/99
30.01-Administration Yes Yes Yes Yes Yes 6/30/99 9/30/99
Health and Welfare Data Center 10-Facilities Operations Yes Yes Yes Yes Yes 9/30/99 6/30/99
20-Administration Yes Yes Yes Yes Yes 9/30/99 Yes
30-Systems Management Services Yes Yes 6/1/99 6/1/99 3/31/99 6/1/99 3/31/99
Health Services, Department of 10-Public and Environmental Health 3/31/99 3/31/99 3/31/99 6/30/99 10/15/99 6/30/99 6/30/99
20-Health Care Services 6/30/99 6/30/99 6/30/99 6/30/99 10/15/99 6/30/99 6/30/99
30-Administration Yes Yes Yes Yes 10/15/99 6/30/99 6/30/99
Highway Patrol, California 10-Traffic Management Yes 4/1/99 4/1/99 4/1/99 6/1/99 7/1/99 7/1/99
20-Regulation and Inspection Yes 4/1/99 4/1/99 4/1/99 Yes 7/1/99 7/1/99
30-Vehicle Ownership Security Yes 4/1/99 4/1/99 4/1/99 6/1/99 7/1/99 7/1/99
35-Protective Services Yes 4/1/99 4/1/99 4/1/99 Yes 7/1/99 7/1/99
40.01-Administration Yes 4/1/99 4/1/99 4/1/99 6/1/99 7/1/99 7/1/99
Housing and Community Development, 10-Codes and Standards Program Yes Yes Yes Yes n/a 6/30/99 n/a
Department of 20-Community Affairs Program Yes Yes Yes Yes n/a 6/30/99 n/a
30.01-Housing Policy Development Program Yes Yes Yes Yes n/a 6/30/99 n/a
50.01-Administration Yes Yes Yes Yes n/a 6/30/99 n/a
Industrial Relations, Department of 10-Regulation of Workers’ Compensation
Self-Insurance Plans Yes Yes 2/28/99 2/28/99 n/a n/a n/a
30-Workers’ Compensation Administration Yes Yes Yes Yes 2/15/99 n/a 2/15/99
35-Industrial Medical Council Yes Yes 3/31/99 3/31/99 n/a n/a n/a
40-The Prevention of Industrial Injuries and
Deaths to California Workers Yes Yes 4/15/99 4/15/99 Yes n/a 2/15/99
50-Enforcement and Promulgation of Laws
Relating to Wages, Hours, and
Conditions of Employment, and
Licensing and Adjudication Yes Yes 3/31/99 3/31/99 n/a n/a n/a
60-Promotion, Development, and
Administration of Apprenticeship and
Other On-the-Job Training Yes Yes Yes Yes Yes n/a 2/15/99
94-Administration n/a n/a 4/15/99 4/15/99 n/a n/a n/a
Information Technology, Department of 10-Administration of Information Technology n/a n/a n/a n/a n/a 6/30/99 n/a
Insurance, Department of 10-Regulation of Insurance Companies
Insurance Producers 12/31/98 3/31/99 3/31/99 3/31/99 6/30/99 6/30/99 6/30/99
20-Fraud Control 12/31/98 3/31/99 3/31/99 3/31/99 6/30/99 6/30/99 6/30/99
Note: Agencies, data centers, and programs listed in italics provide critical services to the public and were visited and reviewed by the Bureau of State Audits.
59
sesnopseR
yevruS
7Q
6Q
5Q
4Q
3Q
2Q
1Q
emaN/rebmuN
margorP
emaN
ycnegA
99/03/6
99/03/6
99/03/6
99/13/3
99/13/3
99/13/3
89/13/21
tiduA
dna
noitcelloC
xaT-03
)deunitnoc(
fo
tnemtrapeD
,ecnarusnI
99/03/6
99/03/6
99/03/6
99/13/3
99/13/3
99/13/3
89/13/21
tnemeganaM
dnuF
yrevoceR
ekauqhtraE-04
99/03/6
99/03/6
99/03/6
99/13/3
99/13/3
99/13/3
89/13/21
noitartsinimdA-10.05
99/03/6
99/03/6
99/13/3
99/13/1
99/13/1
seY
seY
noitartsinimdA
dna
etarotceriD-10.11
fo
tnemtrapeD
,ecitsuJ
99/03/6
99/03/6
a/n
a/n
a/n
a/n
a/n
smargorP
evitucexE-52
99/03/6
99/03/6
seY
seY
seY
seY
seY
waL
liviC-03
99/03/6
99/03/6
seY
seY
seY
seY
seY
waL
lanimirC-04
99/03/6
99/03/6
seY
seY
seY
seY
seY
sthgiR
cilbuP-54
99/03/6
99/03/6
seY
seY
seY
seY
seY
tnemecrofnE
waL-05
99/03/6
99/03/6
99/13/3
99/13/3
99/13/3
99/22/1
seY
secivreS
noitamrofnI
ecitsuJ
lanimirC-06
99/03/6
99/03/6
a/n
a/n
a/n
a/n
a/n
gnilbmaG-56
99/03/6
99/03/6
a/n
a/n
a/n
a/n
a/n
smargorP
lacoL
detadnaM
etatS-89
99/03/6
seY
99/03/6
99/03/5
99/03/6
99/03/5
99/1/5
noissimmoC
yrettoL
etatS
etatS
ainrofilaC
,noissimmoC
yrettoL
99/1/7
99/1/7
seY
a/n
seY
seY
seY
secivreS
ytinummoC-01
fo
tnemtrapeD
,htlaeH
latneM
99/1/7
99/1/7
seY
seY
seY
seY
seY
secivreS
eraC
mreT
gnoL-02
99/1/7
99/1/7
a/n
a/n
a/n
a/n
a/n
noitartsinimdA
latnemtrapeD-10.53
dna
noitacifitnedI
lesseV/elciheV-11
fo
tnemtrapeD
,selciheV
rotoM
99/13/3
a/n
99/03/9
99/03/6
seY
seY
seY
ecnailpmoC
99/13/3
a/n
99/03/9
99/03/6
99/03/6
seY
seY
noitacifitnedI
lanosreP
dna
gnisneciL
revirD-22
99/13/3
seY
a/n
99/11/1
99/11/1
seY
seY
ytefaS
revirD-52
evitagitsevnI
dna
gnisneciL
lanoitapuccO-23
99/13/3
seY
a/n
99/3/5
99/3/5
seY
seY
secivreS
99/03/6
a/n
a/n
a/n
a/n
a/n
a/n
draoB
elciheV
rotoM
weN-53
99/13/3
a/n
99/03/6
99/03/6
99/03/6
99/03/6
seY
noitartsinimdA-14
99/03/6
99/03/6
a/n
a/n
99/03/6
89/13/21
a/n
noitaerceR
dna
skraP
fo
tnemtrapeD
fo
tnemtrapeD
,noitaerceR
dna
skraP
99/03/6
99/03/6
seY
seY
seY
seY
seY
sdradnatS-01
,gniniarT
dna
sdradnatS
reciffO
ecaeP
99/1/4
a/n
a/n
a/n
99/1/4
seY
seY
gniniarT-02
no
noissimmoC
99/1/4
a/n
a/n
a/n
99/13/5
99/13/5
seY
gniniarT
reciffO
ecaeP-03
99/1/4
99/1/7
a/n
a/n
seY
seY
seY
noitartsinimdA-10.04
99/03/6
99/03/6
seY
seY
seY
seY
seY
noitaulavE
htlaeH
dna
noitartsigeR-21
fo
tnemtrapeD
,noitalugeR
edicitseP
,gnirotinoM
latnemnorivnE
,tnemecrofnE-71
99/03/6
99/03/6
seY
seY
seY
seY
seY
tnemeganaM
ataD
dna
99/03/6
99/03/6
seY
seY
seY
seY
seY
secivreS
evitartsinimdA
dna
evitucexE-02
a/n
seY
a/n
seY
seY
seY
a/n
rednefeD
cilbuP
etatS-01
etatS
,rednefeD
cilbuP
.stiduA
etatS
fo
uaeruB
eht
yb
deweiver
dna
detisiv
erew
dna
cilbup
eht
ot
secivres
lacitirc
edivorp
scilati
ni
detsil
smargorp
dna
,sretnec
atad
,seicnegA
:etoN
60
Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
Real Estate, Department of 10-Licensing and Education 8/31/99 9/27/99 9/30/99 10/29/99 n/a Yes Yes
20-Enforcement and Recovery 8/31/99 9/27/99 9/30/99 10/29/99 n/a Yes Yes
30-Subdivisions 8/31/99 9/27/99 9/30/99 10/29/99 n/a Yes Yes
40-Administration 8/31/99 9/27/99 9/30/99 10/29/99 n/a Yes Yes
Rehabilitation, Department of 10-Vocational Rehabilitation Services Yes Yes Yes Yes 3/31/99 Yes 1/31/99
20-Habilitation Services Yes Yes Yes Yes Yes Yes Yes
30-Support of Community Facilities Yes Yes Yes Yes Yes Yes Yes
40-Administration Yes Yes Yes Yes Yes Yes Yes
Social Services, Department of 16-Welfare Programs 1/12/99 1/28/99 1/28/99 6/30/99 6/30/99 6/30/99 6/30/99
25-Social Services and Licensing 1/11/99 1/15/99 3/31/99 6/30/99 1/28/99 6/30/99 6/30/99
35-Disability Evaluation and Other
Services Yes Yes Yes n/a Yes 6/30/99 6/30/99
60-Administration 1/11/99 1/11/99 1/12/99 n/a Yes 6/30/99 6/30/99
State Lands Commission 10-Mineral Resources Management Yes 4/30/99 Yes 4/30/99 Yes 6/30/99 6/30/99
20-Land Management Yes Yes Yes Yes Yes 6/30/99 6/30/99
30-Executive and Administration 6/30/99 Yes Yes Yes Yes 6/30/99 6/30/99
40-Marine Facilities Management Yes Yes Yes Yes Yes 6/30/99 6/30/99
Statewide Health Planning and Development, 42-Facilities Development Yes Yes Yes Yes n/a n/a 6/30/99
Office of 60-Health Facilities Data Yes Yes Yes 1/31/99 6/30/99 n/a 6/30/99
80-Administration Yes Yes Yes n/a 3/31/99 6/30/99 6/30/99
Stephen P. Teale Data Center 10-Service Bureau Operations Yes 10/31/9910/31/9910/31/99 10/31/99 10/31/99 3/31/99
20-Executive and Administrative Operations Yes Yes Yes Yes Yes Yes 3/31/99
Teachers’ Retirement System, State 10-Service to Members and Employers Yes Yes Yes 2/28/99 Yes Yes 4/3/99
20-Administration n/a n/a n/a n/a Yes Yes 4/3/99
Toxic Substances Control, Department of 12-Site Mitigation Yes Yes Yes n/a n/a n/a n/a
13-Hazardous Waste Management Yes Yes Yes n/a n/a n/a n/a
15-Statewide Support Yes Yes Yes n/a n/a n/a n/a
Transportation, Department of 10-Aeronautics Yes Yes Yes Yes Yes Yes Yes
20-Highway Transportation Yes Yes Yes n/a Yes 6/30/99 7/30/99
30-Mass Transportation Yes Yes Yes Yes Yes Yes n/a
40-Transportation Planning Yes Yes Yes Yes Yes n/a n/a
50-Administration Yes Yes Yes n/a Yes 6/30/99 7/30/99
60-Equipment Service Center Yes Yes Yes n/a Yes Yes 7/30/99
Treasurer, State 10-Investment Services Yes Yes Yes Yes Yes Yes 3/31/99
20-Cash Management 3/31/99 3/31/99 3/31/99 3/31/99 3/31/99 Yes 3/31/99
30-Public Finance Yes Yes Yes Yes Yes Yes 3/31/99
50-Administration and Information n/a n/a n/a Yes n/a Yes 3/31/99
Note: Agencies, data centers, and programs listed in italics provide critical services to the public and were visited and reviewed by the Bureau of State Audits.
61
Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
Veterans Affairs, Department of 10-Farm and Home Loans to Veterans 4/1/99 4/1/99 5/28/99 4/1/99 4/1/99 4/1/99 4/1/99
30-Care of Sick and Disabled Veterans 6/1/99 6/1/99 6/1/99 6/1/99 6/1/99 6/1/99 6/1/99
40-Farm and Home Loans to National Guard
Members 4/1/99 4/1/99 5/28/99 4/1/99 4/1/99 n/a 4/1/99
Water Resources, Department of 10-Continuing Formulation of the California
Water Plan Yes Yes Yes Yes Yes Yes 8/1/99
20-Implementation of the State Water
Resources Development System Yes Yes Yes Yes Yes 3/31/99 8/1/99
30-Public Safety and Prevention of Damage n/a Yes Yes 3/31/99 Yes Yes 8/1/99
50-Management and Administration Yes Yes Yes Yes Yes 6/30/99 8/1/99
Water Resources Control Board, State 10-Water Quality Yes Yes 6/1/99 n/a n/a 6/1/99 9/1/99
20-Water Rights Yes Yes 6/1/99 n/a n/a 6/1/99 9/1/99
30-Administration Yes Yes 6/1/99 n/a n/a 6/1/99 9/1/99
Youth Authority, Department of the 20-Institutions and Camps 9/2/99 9/2/99 9/2/99 10/15/99 Yes 6/30/99 6/30/99
30-Parole Services and Community
Corrections 9/2/99 9/2/99 9/2/99 10/15/99 Yes 6/30/99 6/30/99
40-Education Services 9/1/99 9/1/99 9/1/99 10/15/99 Yes 6/30/99 6/30/99
50-Administration 9/2/99 9/2/99 9/2/99 10/15/99 5/31/99 6/30/99 6/30/99
Agencies With Noncritical Systems
Administrative Law, Office of 10-Regulatory Oversight 3/1/99 3/1/99 3/1/99 Yes n/a n/a 3/1/99
Aging, Department of 10-Nutrition Yes Yes Yes Yes Yes Yes Yes
20-Senior Community Employment Yes Yes Yes Yes Yes Yes Yes
30-Supportive Services and Centers Yes Yes Yes Yes Yes Yes Yes
40-Special Projects Yes Yes Yes Yes Yes Yes Yes
50.01-Administration Yes Yes Yes Yes Yes Yes Yes
Alcohol and Drug Programs, Department of 15-Alcohol and Other Drug Services Program 12/31/98 12/31/98 6/30/99 6/30/99 12/31/98 12/31/98 6/30/99
Business, Transportation and Housing Agency, 10-Administration of BT&H Agency 12/31/98 12/31/9812/31/98 12/31/98 12/31/98 12/31/98 12/31/98
Secretary for 30-Agency Audits Office 12/31/98 12/31/9812/31/98 12/31/98 12/31/98 12/31/98 12/31/98
Coastal Commission, California 10-Coastal Management Program Yes Yes Yes 4/15/99 4/15/99 6/1/99 6/1/99
20-Coastal Energy Program Yes Yes Yes 4/15/99 4/15/99 6/1/99 6/1/99
30-Administration and Support Activities Yes Yes Yes 4/15/99 4/15/99 6/1/99 6/1/99
Coastal Conservancy, State 15-Coastal Resource Development Yes Yes Yes Yes Yes n/a Yes
25-Coastal Resource Enhancement Yes Yes Yes Yes Yes n/a Yes
Note: Agencies, data centers, and programs listed in italics provide critical services to the public and were visited and reviewed by the Bureau of State Audits.
62
Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
Community Services and Development, 20-Energy Programs Yes Yes Yes Yes Yes Yes Yes
Department of 40-Community Services Yes Yes Yes Yes Yes Yes Yes
50-Administration Yes Yes Yes Yes Yes Yes Yes
Consumer Affairs, Department of Department of Consumer Affairs, Bureaus,
Programs, and Divisions Yes 11/20/98 1/31/99 12/4/98 4/15/99 12/31/99 6/30/99
Corrections, Board of 11-Corrections Standards and Services Yes Yes Yes Yes n/a Yes Yes
21-Standards and Training for Local Officers Yes Yes Yes Yes n/a Yes Yes
31-Administration Yes Yes Yes Yes n/a Yes Yes
Emergency Medical Services Authority 10-Emergency Medical Services Authority Yes Yes Yes Yes Yes 12/31/98 11/30/98
Fair Employment and Housing Commission 10-Fair Employment and Housing Commission n/a n/a Yes n/a n/a n/a Yes
Fair Employment and Housing, Department of 50-Administration of Civil Rights Law 6/30/99 6/30/99 6/30/99 6/30/99 12/15/98 6/30/99 2/1/99
Finance, Department of 10-Annual Financial Plan Yes Yes Yes Yes Yes n/a n/a
20-Program and Information System
Assessments Yes Yes Yes Yes Yes n/a n/a
30-Supportive Data Yes Yes Yes Yes Yes n/a n/a
40-Administration Yes Yes Yes Yes Yes n/a n/a
Health and Human Services Agency, Secretary for 10-Secretary for Health and Human Services n/a Yes 12/31/98 12/31/98 n/a Yes n/a
Horse Racing Board, California 10-California Horse Racing Board Yes Yes Yes Yes Yes Yes Yes
20.01-Administration Yes Yes Yes Yes Yes Yes Yes
Housing Finance Agency, California 10-Lending and Program Activity Yes 12/31/98 n/a 12/31/98 6/30/99 6/30/99 Yes
20-Insurance Activity Yes Yes n/a Yes Yes 6/30/99 Yes
Integrated Waste Management Board, California 10-Planning and Enforcement Yes Yes Yes n/a n/a Yes Yes
15-Disposal Site Cleanup and Maintenance Yes Yes Yes n/a n/a Yes Yes
20-Waste Reduction and Resource Recovery Yes Yes Yes n/a n/a Yes Yes
Judicial Performance, Commission on 10-Commission on Judicial Performance 6/30/99 6/30/99 6/30/99 6/30/99 6/30/99 6/30/99 6/30/99
Law Revision Commission, California 10-California Law Revision Commission n/a Yes Yes n/a n/a n/a n/a
Library, California State 10-State Library Services n/a n/a n/a 6/30/99 6/30/99 6/30/99 9/30/99
20-Library Development Services 6/30/99 6/30/99 6/30/99 6/30/99 6/30/99 6/30/99 9/30/99
30-Information Technology Services n/a Yes 6/30/99 6/30/99 Yes 6/30/99 9/30/99
40-Administration n/a n/a 6/30/99 6/30/99 6/30/99 6/30/99 9/30/99
Managed Risk Medical Insurance Board 10-Major Risk Medical Insurance Program 11/15/98 12/31/9812/31/98 12/31/98 12/31/98 12/31/98 12/31/98
20-Access for Infants and Mothers Program 2/1/99 2/1/99 2/1/99 2/1/99 2/1/99 2/1/99 2/1/99
30-Health Insurance Plan of California 7/30/99 7/30/99 7/30/99 7/30/99 7/30/99 7/30/99 7/30/99
40-Healthy Families Program 2/1/99 2/1/99 3/1/99 n/a 3/1/99 3/1/99 3/1/99
63
Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
Medical Assistance Commission, California 10-California Medical Assistance Commission n/a Yes Yes Yes n/a 1/31/99 1/31/99
Personnel Administration, Department of 20-Labor Relations 4/1/99 6/1/99 6/30/99 12/31/98 n/a 6/30/99 6/30/99
25-Legal n/a n/a 6/30/99 12/31/98 n/a 6/30/99 6/30/99
40-Administration n/a n/a 6/30/99 12/31/98 n/a 6/30/99 6/30/99
52-Classification and Compensation 3/1/99 6/1/99 6/30/99 12/31/98 6/1/99 6/30/99 6/30/99
54-Benefits Administration 6/1/99 6/1/99 6/30/99 12/31/98 6/1/99 6/30/99 6/30/99
56-Training and Continuous Development n/a 3/1/99 6/30/99 12/31/98 n/a 6/30/99 6/30/99
58-Merit Award Yes 12/31/98 6/30/99 12/31/98 n/a 6/30/99 6/30/99
Personnel Board, State 10-Merit System Administration 6/30/99 6/30/99 6/30/99 6/30/99 6/30/99 9/14/99 Yes
40-Local Government Services 6/30/99 6/30/99 6/30/99 6/30/99 6/30/99 n/a 6/30/99
50.01-Administrative Services 9/30/99 9/30/99 9/30/99 9/30/99 12/31/98 9/14/99 Yes
Public Employment Relations Board 11-Public Employment Relations Yes Yes Yes Yes n/a n/a Yes
Public Utilities Commission 10-Regulation of Utilities 2/1/99 5/1/99 6/1/99 5/1/99 10/1/99 n/a 10/1/99
20-Regulation of Transportation 5/1/99 7/1/99 10/1/99 7/1/99 n/a Yes Yes
30.01-Administration 7/1/99 7/1/99 9/1/99 7/1/99 7/1/99 Yes Yes
Real Estate Appraisers, Office of 10-Administration of Real Estate Appraisers
Program Yes Yes Yes 12/31/98 12/31/98 Yes 12/31/98
Secretary of State 05-Business Programs Yes Yes Yes Yes Yes Yes Yes
10-Elections n/a n/a n/a n/a n/a Yes Yes
15-Political Reform Yes Yes Yes Yes Yes Yes Yes
30-Archives n/a n/a n/a n/a n/a Yes Yes
35-Management Services Yes Yes Yes Yes Yes Yes Yes
38-Information Technology Yes Yes Yes Yes Yes Yes Yes
State Mandates, Commission on 10-Administration n/a 12/31/9812/31/9812/31/98 n/a 12/31/98 12/31/98
Tahoe Conservancy, California 10-Tahoe Conservancy Yes Yes Yes n/a n/a Yes n/a
Teacher Credentialing, Commission on 10.10-Certification, Assignment, and Waivers Yes Yes Yes Yes Yes Yes 3/1/99
10.30-Professional Practices 12/15/98 12/15/9812/15/9812/15/98 n/a 12/15/98 12/15/98
Trade and Commerce Agency 10-Economic Development 6/30/99 7/30/99 7/30/99 7/30/99 6/30/99 6/30/99 6/30/99
20-International Trade and Investment 6/30/99 7/30/99 7/30/99 7/30/99 n/a 6/30/99 6/30/99
25-Marketing and Communications n/a n/a n/a n/a n/a 6/30/99 n/a
30-Tourism n/a n/a n/a n/a n/a 6/30/99 6/30/99
40-Contract, Grants and Loans Yes Yes Yes 6/30/99 n/a 6/30/99 6/30/99
60-Economic Research and Strategic Planning n/a n/a n/a n/a n/a 6/30/99 n/a
70.01-Administration Yes Yes Yes 6/30/99 n/a 6/30/99 6/30/99
Traffic Safety, Office of 10-California Traffic Safety Program n/a Yes Yes Yes Yes 6/1/99 Yes
Youthful Offender Parole Board 10-Youthful Offender Parole Board n/a n/a n/a 6/30/99 6/30/99 6/30/99 11/30/99
Q 7 n / a n / a n / a n / a n / a n / a Y e s Y e s Y e s 3 / 1 / 9 9 n / a 7 / 1 / 9 9 7 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 n / a Y e s Y e s Y e s 7 / 1 / 9 9 6 / 3 0 / 9 9 7 / 3 1 / 9 9 7 / 3 1 / 9 9
Q 6 6 / 3 0 / 9 9 6 / 3 0 / 9 9 6 / 3 0 / 9 9 6 / 3 0 / 9 9 n / a n / a Y e s n / a n / a 1 / 1 / 9 9 n / a 2 / 1 9 / 9 9 2 / 1 9 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 Y e s 6 / 3 0 / 9 9 6 / 3 0 / 9 9 Y e s 7 / 1 / 9 9 6 / 3 0 / 9 9 5 / 1 / 9 9 1 2 / 3 1 / 9 9
n s e s Q 5 6 / 3 0 / 9 9 6 / 3 0 / 9 9 Y e s 6 / 3 0 / 9 9 Y e s n / a Y e s n / a n / a 1 / 1 / 9 9 n / a n / a n / a 1 2 / 1 / 9 9 n / a 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 n / a 3 / 3 1 / 9 9 1 / 3 0 / 9 9 1 2 / 3 1 / 9 8 Y e s n / a n / a n / a at e A u dit s.
e y R e s p o Q 4 n / a n / a n / a n / a Y e s n / a Y e s Y e s Y e s 1 / 1 / 9 9 / 1 / 0 0 n / a n / a 6 / 3 0 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 1 2 / 1 / 9 9 Y e s 3 / 3 1 / 9 9 1 / 3 0 / 9 9 1 2 / 3 1 / 9 8 Y e s n / a n / a n / a ur e a u of St
S u r v
A g e n c y N a m e
P r o g r a m N u m b e r / N a m e
Q 1
Q 2
Q 3
A g e n ci e s N o t R e q ui r e d t o R e p
o r t
t
o
t
h
e
D e p a r t m e n t o f I n f o r m a ti o n T e
c h n ol o
g
y
C alif or ni a C o m m u nit y C oll e g e s, B o ar d of
1
0- A p p orti o n m e nt s
6 / 3 0 / 9 9
6 / 3 0 / 9 9
6 / 3 0 / 9 9
G o v er n or s of t h e
2
0- S p e ci al S er vi c e s
6 / 3 0 / 9 9
6 / 3 0 / 9 9
6 / 3 0 / 9 9
3
0- A d mi ni str ati o n
6 / 3 0 / 9 9
6 / 3 0 / 9 9
Y e s
9
8- St at e- M a n d at e d L o c al Pr o gr a m s
6 / 3 0 / 9 9
6 / 3 0 / 9 9
6 / 3 0 / 9 9
C hil d D e v el o p m e nt P oli c y A d vi s or y C o m
mitt e e
1
0- C hil d D e v el o p m e nt P oli c y A d vi s or y C o m mitt e e
Y e s
Y e s
Y e s
C o a c h ell a V all e y M o u nt ai n s C o n s er v a n c y
1
0- C o a c h ell a V all e y M o u nt ai n s C o n s er v a n c y
n / a
Y e s
Y e s
C o n s er v ati o n C or p s, C alif or ni a
1
0- Tr ai ni n g a n d W or k Pr o gr a m
Y e s
Y e s
Y e s
D e bt a n d I n v e st m e nt A d vi s or y C o m mi s si o
n, C
alif
or
ni
a
1
0- C alif or ni a D e bt a n d I n v e st m e nt A d vi s or y C o m mi s si o n
Y e s
Y e s
1 2 / 3 1 / 9 8
D e bt Li mit All o c ati o n C o m mitt e e, C alif or ni
a
1
0- C alif or ni a D e bt Li mit All o c ati o n C o m mitt e
e n / a
n / a
Y e s
D elt a Pr ot e cti o n C o m mi s si o n
1
0- D elt a Pr ot e cti o n
1 / 1 / 9 9
1 / 1 / 9 9
1 / 1 / 9 9
D e v el o p m e nt al Di s a biliti e s, Ar e a B o ar d s o n
1
0- Ar e a B o ar d s S er vi c e s
n / a
n / a
n / a 1
D e v el o p m e nt al Di s a biliti e s, St at e C o u n cil o
n
1
0- St at e C o u n cil Pl a n ni n g a n d O p er ati o n s
n / a
n / a
n / a
2
0- C o m m u nit y Pr o gr a m D e v el o p m e nt
n / a
n / a
n / a
H a sti n g s C oll e g e of t h e L a w
1
0-I n str u cti o n Pr o gr a m
6 / 3 0 / 9 9
6 / 3 0 / 9 9
6 / 3 0 / 9 9
2
0- P u bli c a n d Pr of e s si o n al S er vi c e s Pr o gr a m
n / a
1 2 / 1 / 9 9
1 2 / 1 / 9 9
3
0- A c a d e mi c S u p p ort Pr o gr a m — L a w Li br ar y
1 2 / 1 / 9 9
1 2 / 1 / 9 9
1 2 / 1 / 9 9
4
0- St u d e nt S er vi c e s Pr o gr a m
1 2 / 1 / 9 9
1 2 / 1 / 9 9
1 2 / 1 / 9 9
5
0-I n stit uti o n al S u p p ort Pr o gr a m
1 2 / 1 / 9 9
1 2 / 1 / 9 9
1 2 / 1 / 9 9
5
5- O p er ati o n a n d M ai nt e n a n c e of Pl a nt
n / a
1 2 / 1 / 9 9
1 2 / 1 / 9 9
I n d u stri al D e v el o p m e nt Fi n a n ci n g A d vi s or y
1
0- C alif or ni a I n d u stri al D e v el o p m e nt Fi n a n ci n
g
C o m mi s si o n, C alif or ni a
A d vi s or y C o m mi s si o n
n / a
n / a
Y e s
J u di ci al
1
0- S u pr e m e C o urt
2 / 2 8 / 9 9
3 / 3 1 / 9 9
3 / 3 1 / 9 9
2
0- C o urt s of A p p e al
1 2 / 3 1 / 9 9
1 / 3 0 / 9 9
1 / 3 0 / 9 9
3
0-J u di ci al C o u n cil
Y e s
1 2 / 3 1 / 9 8
1 2 / 3 1 / 9 8
L e gi sl ati v e C o u n s el B ur e a u
L e
gi sl ati v e C o u n s el B ur e a u
Y e s
Y e s
Y e s
Li e ut e n a nt G o v er n or, Offi c e of t h e
1
0- G e n er al A cti viti e s
n / a
n / a
n / a
Milit ar y D e p art m e nt
1
0- Ar m y N ati o n al G u ar d
n / a
n / a
n / a
2
0- Air N ati o n al G u ar d
n / a
n / a
n / a
N
ot e: A g e n ci e s, d at a c e nt er s, a n d pr o gr a m s
li st e d
i
n
it
ali
c s
pr o vi d e criti c al s er vi c e s t o t h e p u bli c a n d w
er e vi sit e d
a
n
d r e vi e w e
d b y t h e B
64
65
Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
Military Department (continued) 30.01-Office of the Adjutant General n/a n/a n/a n/a n/a 5/1/99 7/31/99
35-Military Support to Civil Authority n/a n/a n/a n/a n/a 5/1/99 7/31/99
40-Military Retirement n/a n/a n/a n/a n/a 5/1/99 7/31/99
65-California National Guard Youth Programs n/a n/a n/a n/a n/a 5/1/99 7/31/99
Native American Heritage Commission 10-Native American Heritage Commission Yes Yes Yes Yes Yes Yes Yes
Organization and Economy, Milton Marks 10-Milton Marks Commission on State
Commission on State Government Government Organization and Economy n/a n/a n/a n/a n/a 6/30/98 n/a
Pilot Commissioners for the Bays of San Francisco,
San Pablo, and Suisun, Board of 10-Board of Pilot Commissioners n/a n/a Yes Yes n/a n/a Yes
Postsecondary Education Commission, California Postsecondary Education Commission Yes Yes Yes Yes Yes Yes Yes
Prison Terms, Board of 10-Board of Prison Terms 4/1/99 n/a 4/1/99 n/a n/a n/a Yes
Public Employees’ Retirement System 10-Retirement 2/16/99 6/22/99 6/22/99 6/22/99 12/18/98 12/31/98 Yes
30-Health Benefits Yes 4/15/99 4/15/99 4/15/99 12/18/98 12/31/98 n/a
40-Investment Operations 12/31/98 12/31/9812/31/9812/31/98 Yes n/a Yes
50-Administration Yes 12/31/9812/31/9812/31/98 Yes 3/30/99 Yes
San Francisco Bay Conservation and
Development Commission 10-Bay Conservation and Development n/a n/a n/a n/a n/a Yes n/a
Science Center, California 10-Education n/a n/a Yes Yes n/a n/a Yes
30-California African-American Museum n/a n/a Yes Yes n/a n/a n/a
40-Administration n/a n/a Yes Yes n/a n/a Yes
Seismic Safety Commission 10-Seismic Safety 12/31/99 12/31/9910/31/9910/31/99 n/a 12/31/99 10/31/99
State University,, California 01-Instruction 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99
02-Research 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99
03-Public Services 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99
04-Academic Support 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99
05-Student Services 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99
06-Institutional Support 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99
07-Operation and Maintenance of Plant 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99
08-Student Financial Aid 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99
09-Auxiliary Enterprises 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99 12/1/99
Student Aid Commission, California 15-Financial Aid Grants Program 2/1/99 6/1/99 1/1/99 Yes Yes Yes Yes
50-California Loan Program Yes Yes Yes Yes Yes Yes Yes
80.01-Administration and Support Services Yes Yes Yes Yes Yes Yes Yes
Tax Credit Allocation Committee, California 10-California Tax Credit Allocation Committee n/a n/a Yes Yes n/a Yes n/a
Note: Agencies, data centers, and programs listed in italics provide critical services to the public and were visited and reviewed by the Bureau of State Audits.
66 Survey Responses
Agency Name Program Number/Name Q1 Q2 Q3 Q4 Q5 Q6 Q7
University of California1 05-Instruction—General Campuses
05-Instruction—Health Sciences
05-Instruction—Summer Sessions
05-Instruction—University Extension
10-Research
15-Public Service
20-Academic Support
25-Teaching Hospitals
30-Student Services
35-Institutional Support
40-Operation and Maintenance of Plant
45-Student Financial Aid
50-Auxiliary Enterprises
55-Provisions for Allocation
60-Program Maintenance—Fixed Costs,
Economic Factors and Salary Increases
65-Special Regents Program
1The University of California (UC) did not complete our survey but provided alternative information. According to the university auditor, UC has established an overall year 2000
methodology and is monitoring the progress at each campus and medical center. UC provided us with its latest progress report for the campuses, headquarters, and medical
centers, and that information is contained in Tables 5 and 6. According to the information provided by UC, mission-critical systems at both the campuses and medical centers will be
year 2000 ready by June 30, 1999, and year 2000 remediation for any remaining systems will be completed by October 1, 1999.
Agency Name Program Number/Name
Agencies That Responded “n/a” to All Seven Survey Questions
Academic Content and Performance, Commission
for the Establishment of 10-Standards Commission
Aging, Commission on 10-Commission on Aging
Alcohol and Drug Programs, Department of 30-Administration
Arts Council, California 10-Arts in Residence
20-Organizational Support Group
25-Performing Arts Touring/Presenting Program
40-Statewide Projects
45-California Challenge Program
50-Administration
Note: Agencies, data centers, and programs listed in italics provide critical services to the public and were visited and reviewed by the Bureau of State Audits.
67
Agency Name Program Number/Name
Boating and Waterways, Department of 10-Boating Facilities
30-Beach Erosion
Child Development and Education, Secretary for 10-Secretary for Child Development and Education
11-California Commission on Improving Life Through Service
20-Academic Volunteer and Mentor Service Program
Chiropractic Examiners, Board of 10-Board of Chiropractic Examiners
Colorado River Board of California 10-Protection of California’s Colorado River
Rights and Interests
Conservation, Department of 30-Land Resources
40-Administration
50-Beverage Container Recycling and Litter
Reduction Program
Corrections, Board of 98-State Mandated Local Programs
Developmental Disabilities, State Council on 30-Allocation to Area Boards
Developmental Services, Department of 98-State Mandated Local Programs
Education, Department of 95-Categorical Growth and Cost-of-Living Adjustment
98-State Mandated Local Programs
Electricity Oversight Board 30-Administration
Employment Development Department 50-Employment Training Panel Program
Franchise Tax Board 00-Lease Revenue Bond Payments
30-Political Reform Audit
Governor’s Office 10.10-Governor’s Office
Health Services, Department of 98-State Mandated Local Programs
Independent Living Council, State 10-Statewide Council Services (Reimbursement)
Industrial Relations, Department of 20-Conciliation of Employer-Employee Disputes
36-Commission on Health and Safety and
Workers’ Compensation
70-Labor Force Research and Data
Dissemination
80-Payment of Claims, Wages and
Contingencies
98-State Mandated Local Programs
Occupational Information Coordinating Committee, 10-California Occupational Information
California Coordinating Committee
Osteopathic Board of Medicine 10-Osteopathic Medical Board
68
Agency Name Program Number/Name
Planning and Research, Office of 11-State Planning and Policy Development
Resources, Secretary for 10-Administration of Resources Agency
Santa Monica Mountains Conservancy 10-Santa Monica Mountains Conservancy
Secretary of State 98-State Mandated Local Programs
Statewide Health Planning and Development, 10-Health Policy and Analysis
Office of 30-Health Professions Development
45-Cal-Mortgage Loan Insurance
State and Consumer Services Agency, Secretary for 10-Administration of State and Consumer
Services Agency
State University, California 10-Provisions for Allocation
11-Reimbursed Activities
Status of Women, Commission on the 10-Administration—Legislation—Research
and Information
20-Displaced Homemaker Emergency Loan
Program
Student Aid Commission, California 30-Golden State Scholarship Trust Program
Summer School for the Arts, California State 10-California State Summer School for the Arts
Teacher Credentialing, Commission on 10.40-Administration
Toxic Substances Control, Department of 19-Administration
20-Science, Pollution Prevention and
Technology
Veterans Affairs, Department of 20-Veterans Claims and Rights
35-Veterans Home of Southern California
Preactivation
50-General Administration
Water Resources, Department of 40-Services
Wildlife Conservation Board 10-Wildlife Conservation Board
Youth and Adult Correctional Agency, Secretary for 10-Corrections Standards and Services
15-Commission on Peace Officer Standards and Testing
69
Agency Name Program Number/Name
Agencies That Did Not Respond for Some Programs
Coastal Conservancy, State 90.01-Administration
Judicial 50-Habeas Resource Center
Agencies That Did Not Respond to Our Survey
Environmental Protection, Secretary for
San Joaquin River Conservancy
Transportation Commission, California
Uniform State Laws, Commission on
Legend: n/a = Task not applicable to this program
Date = Projected completion date
Yes = Task complete
Below are listed Questions 1 through 7.
Question 1: Is program code remediated and unit-level testing complete?
Question 2: Is integrated testing of software units and applications complete?
Question 3: Have all application software and hardware been tested in a production environment and accepted by users?
Question 4: Have all systems that support this program been tested in an isolated environment where the hardware clock has been manually set to future dates?
Question 5: Have all external data exchange partners been identified, contacted, data format established, and shared data tested?
Question 6: Have embedded systems that support this program been surveyed, assessed, prioritized, and fixed?
Question 7: Are business continuation plans established to ensure uninterrupted services if supporting systems fail or are not fixed by January 1, 2000?
TABLE 5
Year 2000 Progress at University of California’s
Nine Campuses and Headquarters
Number
Estimated
to Be
Number of Number Completed
Mission-Critical Completed by November 1998
System Systems October 1998 Through June 1999
Financial
General Ledger 15 3 12
Accounts Payable 13 4 9
Billing and Accounts Receivable 7 2 5
Budget 12 4 8
Recharge Billing 10 6 3a
Purchasing 9 4 5
Other 25 8 17
Student
Admissions 15 1 14
Registration/Enrollment 26 5 21
Financial Aid 8 2 6
Loan Collections 10 3 7
Billing and Accounts Receivable 7 1 6
Other 10 0 10
Facilities
Housing 43 6 37
Storehouse 7 1 6
Equipment Inventory 7 1 6
Facilities Inventory 8 5 3
Planning
Data Warehouse 9 4 5
Human Resources 29 16 13
Development/Alumni 11 5 5a
Research Administration
Contracts and Grants 19 7 12
Effort Reporting 9 1 8
Total Administrative Systems 309 89 218a
Network/Communications
Telephone 34 22 12
Data 64 39 25
Video 2 0 2
Total Network/Communications 100 61 39
Operating Systems and Tools
Mainframe 158 97 61
Servers 87 23 64
Total Operating Systems
and Tools 245 120 125
TOTALS 654 270 382a
aThe number of systems completed by October 1998 plus the number of systems estimated to be completed
between November 1998 and June 1999 do not equal the total number of mission-critical systems. The
University of California did not explain why these figures do not agree.
70
TABLE 6
Year 2000 Progress at University of California’s
Four Hospitals
Number
Estimated
Number of Number to Be
Mission-Critical Completed by Completed
System Systems December 1998 January-June 1999
Financial
General Ledger 4 2 2
Accounts Payable 7 0 7
Billing and Accounts Receivable 32 18 14
Budget 4 3 1
Purchasing 5 1 4
Contracts 5 0 5
Patient Information
Admission, Discharge, Transfer 13 5 8
Medical Records 11 0 11
Results Reporting 8 3 5
Order Entry 4 0 4
Clinical Systems (e.g., Tracking
Systems) 23 1 22
Pharmacy Systems 7 0 7
Dictation Systems 11 2 9
Other 5 2 3
Miscellaneous
Physician Information (Including
Reference Manuals) 12 4 8
Scheduling Information 7 2 5
Hospital Departmental Systems 70 6 64
Human Resources 13 9 4
Other 31 1 30
Total Administrative Systems 272 59 213
Network/Communications
Telephone 50 8 42
Data 5 2 3
Video 1 0 1
Total Network/Communications 56 10 46
Operating Systems and Tools
Mainframe 6 3 3
Servers 49 16 33
Desktop 9 0 9
Total Operating Systems
and Tools 64 19 45
TOTALS 392 88 304
71
Blank page inserted for reproduction purposes only.
72
APPENDIX C
Year 2000 Planning at State
Agencies Not Required to Report
to the Department of Information
Technology
W
e identified 45 state agencies that do not report their
year 2000 progress to the Department of Information
Technology (DOIT). Some of these agencies are
exempted by law from reporting; for example, the University of
California, California State University, Board of Governors of the
California Community Colleges, and the Judicial branch (courts)
are exempt. We concluded that other agencies do not report to
DOIT because their names did not appear in DOIT’s July quar-
terly year 2000 progress report.
We surveyed these agencies to determine the extent of their
planning efforts for the year 2000. The main objective of our
survey, sent in October 1998, was to determine whether the
agencies have comprehensive plans for year 2000 compliance,
and if so, whether a designated manager was responsible for
implementing each plan. In addition, we inquired whether the
agencies periodically reported their year 2000 efforts, and if so,
to whom they reported.
As shown in Table 7, we received responses from 40 of the 45
agencies we identified. Of those responding, 39 indicated they
either had a plan or did not need a plan because they did not
have year 2000 problems. One agency, the Santa Monica
Mountains Conservancy, indicated that it did not have a year
2000 plan or a business continuation plan because it was a small
agency and did not have a budget for this purpose.
73
TABLE 7
Survey Results of 45 Agencies
Not Required to Report to DOIT
Have a
Have a Designated Make
Comprehensive Plan Periodic
Agency Name Plan Manager Reports
Academic Content and Performance
Standards, Commission for the
Establishment of Noa No No
Area Boards on Developmental Disabilities Noa No No
Board of Governors of the California
Community Colleges Yes Yes Yes
Child Development and Education,
Secretary for Noa Yes No
Child Development Policy Advisory
Committee Noa Yes Yes
Chiropractic Examiners, Board of Yes No No
Coachella Valley Mountain Conservancy Noa No Yes
Conservation Corps, California Yes Yes No
Debt and Investment Advisory
Commission, California Yes Yes Yes
Debt Limit Allocation Committee,
California Yes Yes Yes
Delta Protection Commission Yes Yes No
Developmental Disabilities, State
Council on Yes Yes Yes
Electricity Oversight Board Noa No No
Environmental Protection, Secretary for * * *
Governor’s Office Yes Yes No
Hastings College of the Law Yes Yes Yes
Industrial Development Financing
Advisory Commission, California Yes Yes Yes
Judicial * * *
Legislative Counsel Bureau Yes Yes Yes
Lieutenant Governor, Office of the Noa No No
Military Department Yes Yes Yes
Native American Heritage Commission Noa No No
Organization and Economy, Milton Marks
Commission on State Government Noa Yes No
Osteopathic Board of Medicine Yes Yes No
74
Have a
Have a Designated Make
Comprehensive Plan Periodic
Agency Name Plan Manager Reports
Pilot Commissioners for the Bays of
San Francisco, San Pablo, and Suisun,
Board of Yes Yes No
Planning and Research, Office of Yes Yes No
Postsecondary Education Commission,
California Yes Yes No
Prison Terms, Board of Yes Yes No
Public Employees’ Retirement System Yes Yes Yes
Resources, Secretary for Noa Yes No
San Francisco Bay Conservation
and Development Commission Noa No No
San Joaquin River Conservancy * * *
Santa Monica Mountains
Conservancy Nob Yes No
Science Center, California Noa Yes No
Seismic Safety Commission Yes Yes Yes
State Independent Living Council Noa No No
State University, California Yes Yes Yes
Student Aid Commission, California Yes Yes Yes
Summer School for the Arts,
California State Noa No No
Tax Credit Allocation Committee,
California Yes Yes Yes
Transportation Commission, California * * *
Uniform State Laws, Commission on * * *
University of California Yes Yes Yes
Wildlife Conservation Board Noa No No
Youth and Adult Correctional Agency,
Secretary for Yes Yes Yes
Yes 24 29 17
No 16 11 23
No Response 5 5 5
Total 45 45 45
Note:
*No Response.
aAgency indicated that a comprehensive year 2000 plan was unnecessary because its computers are being fixed by
another department, are used for word processing and spreadsheets, are Macintosh computers, have no
year 2000 problem, or the agency relies on commercial upgrades.
bAgency indicated that it was too small and had no budget for a Y2K plan.
75
Blank page inserted for reproduction purposes only.
76
Agency’s response to the report provided as text only:
OFFICE OF THE GOVERNOR
Governor Gray Davis
Sacramento, California 95814
(916) 445-2841
February 10, 1998
Kurt R. Sjoberg
California State Auditor
Bureau of State Audits
555 Capitol Mall, Suite 300
Sacramento, CA 95814
Dear Mr. Sjoberg:
Thank you for inviting the Davis Administration to review a draft copy of your report to the
Legislature entitled, Year 2000 Computer Problem: The State’s Agencies Are Progressing but
Key Steps Remain Incomplete.
In general, we find that the report’s findings are essentially consistent with the Department of
Information Technology’s assessment of the state’s progress in addressing the Year 2000
problem. The Bureau of State Audits continuing review of the Year 2000 situation serves a very
valuable purpose and complements the efforts of the Administration to maintain a focus on the
Year 2000 and its related issues in order to help assure a smooth transition for state government.
The Administration is also keenly aware of the challenges posed by the Year 2000 problem, and
appreciates the State Auditor’s recognition of the Governor’s commitment outlined in his fiscal
year 1999-2000 budget. Governor Davis will soon announce a comprehensive and assertive
program detailing his initiatives for managing and coordinating the State’s Year 2000
preparedness efforts. Our plan will address the issues identified by both the State Auditor and the
Department of Information Technology to ensure the State will be prepared for the millennium
change.
The Davis Administration remains committed to continue working with the Bureau of State
Audits to facilitate the state’s Year 2000 problem resolution effort and to provide you
information as requested. Again, thank you for the opportunity to review your draft report.
Please call Bob Dell’Agostino at the Department of Information Technology at 445-5900 if you
have any questions concerning our comments.
Sincerely,
SIGNED BY: VINCENT H. HALL
Vincent Hall
Staff Director
Office of the Governor
R-1
Blank page inserted for reproduction purposes only.
R-2
Agency’s response to the report provided as text only:
BUSINESS, TRANSPORTATION AND HOUSING AGENCY
980 9th Street, Suite 2450
Sacramento, California 95814-2719
(916) 323-5400
FAX (916) 323-5440
February 4, 1999
Kurt R. Sjoberg, State Auditor
Bureau of State Audits
555 Capitol Mall, Suite 300
Sacramento, CA 95814
Dear Mr. Sjoberg:
Thank you for the opportunity to comment on your draft audit report No. 98116
entitled “State of California Year 2000 Computer Problems,” of the Teale Data
Center. We welcome the input from the Bureau of State Audits (BSA).
Attached please find the Teale Data Center’s response to the findings and
recommendations in the draft report.
If you have any questions, please contact Glen Matsuoka, Acting Director of the Teale
Data Center at 263-1876.
Sincerely,
Original Signed by: MARIA CONTRERAS-SWEET/jm
MARIA CONTRERAS-SWEET
Secretary
R-3
State of California Business, Transportation and Housing Agency
M e m o r a n d u m
To: Kurt R. Sjoberg, State Auditor Date: February 4, 1999
Bureau of State Audits
555 Capitol Mall, Suite 300
Sacramento, CA 95814
From: Glen Matsuoka, Acting Director
Stephen P. Teale Data Center
2005 Evergreen Street
Sacramento, CA 95815-3831
Subject: Review of the Teale Data Center by the Bureau of State Audits
Thank you for the opportunity to respond to the State of California Year 2000 (Y2K)
Draft Audit Report of the Teale Data Center. Teale has played a leadership role in
addressing the Y2K issue within California State Government and, more specifically,
for the Business, Transportation and Housing Agency. The Data Center has taken
a proactive role in implementing their time machine environments, procuring software
tools for Y2K remediation and testing, and encouraging all of its customers to test
on the time machine. In addition, at the urging of the Teale Data Center, the Business,
Transportation and Housing Agency has required its departments to time-machine
test its applications, in the absence of a statewide mandate.
The issue of Y2K compliance is a challenge for the State of California as a whole.
We believe that Teale has aggressively pursued strategies to provide its clients with
the resources necessary to allow them to be Y2K-ready. While Teale is a provider of
services it has nonetheless gone beyond its normal boundaries to work with its
clients in this critical area. The Data Center is not a control agency and, consequently,
must rely on its informal influence and its technical expertise to convince its clients
to follow good practices to become Y2K-ready. As the far as the Teale Data Center
1*
is concerned, it is fully compliant for its mission critical software and equipment,
and has fully tested itssoftware on both simulation tests and time-machine tests. It
is our recommendation, therefore, that policy or oversight be established by the
Department of Information Technology to address departments that continue to
use unsupported software and hardware; or elect not to time-machine test their
mission-critical applications.
We welcome the input from the Bureau of State Audits; however, there are some
findings in the draft report we wish to clarify. Following are responses to the Draft
Audit Report:
*California State Auditor’s comments on this response begin on page R-9
R-4
Kurt R. Sjoberg
February 4, 1999
Bureau of State Audits
Teale lacks a successful strategy for its year 2000 remediation plan that addresses
services critical to its clients. Teale also has devoted few resources to year 2000
activities. Even though the data center serves about 250 agencies and local
governments it has assigned only two full-time staff to year 2000 remediation.
Comment/Response
With information technology processing platforms being Teale’s core function for
250+ departments, we believe that Teale has successfully followed through with
their strategy to ensure that Y2K-readiness was incorporated into its normal course
of business for upgrading hardware and software. Teale provided individual detailed
project task plans that were developed for each core business function of the Data
2
Center – operating systems, network, database, embedded systems, desktops,
external interfaces, etc. To the Data Center’s credit, accomplishments to date were
made through use of existing staff resources and with the assistance of a few
consultant contracts. In addition, to the maximum extent possible within staffing
and workload constraints, we have provided direct assistance to client conversion
efforts.
Bureau of State Audits
To its credit, Teale has created a time machine for its clients to test its MVS operating
system, and plans to use client testing to affirm that its own computers will operate
properly after January 1, 2000. However, Teale does not monitor what segments of
the system clients are testing. Unless Teale monitors these tests, it cannot ensure
it has successfully remediated its operating system and cannot support its clients’
business needs into the next millennium.
Comment/Response
Teale has performed many tests on the operating systems for Y2K compliancy and
3
all tests indicate system readiness. Teale is not aware of a standard industry process
that allows the type of testing cited by BSA. The Data Center is contacting several
vendors to assess if this specific function mentioned by BSA can be monitored,
and if so, how.
Teale has established time machine environments for customer testing. This includes
the control and management processes that support the customers’ selected test
dates, the monitoring of these environments, the appropriate readiness of software
and the coordination necessary to ensure the successful completion of their testing.
R-5
Kurt R. Sjoberg
February 4, 1999
Bureau of State Audits
For instance, one of Teale’s clients, the State Controller’s Office (SCO) which is
responsible for disbursing all state funds, is considering moving its mainframe
computer systems to Teale’s MVS mainframes. According to the SCO, the computer
it uses to support 24 mission-critical systems is outdated and almost in constant
use and cannot be used for time machine testing. By transferring its systems to
Teale’s more modern mainframes, the SCO has the option to use Teale’s time
machine. If the SCO does transfer its systems to Teale, it will rely upon Teale to
ensure that the mainframe operating system is year 2000 compliant. However, Teale’s
failure to track the portions of the MVS operating system its customers test will limit
its ability to measure the year 2000 readiness of the system and provide such
assurances.
Comment/Response
3
As indicated in the above response, Teale has performed its own testing. Should
our contacts with the vendors determine that a monitoring capability is available,
Teale will evaluate the viability of implementing that function. The reference that the
SCO computer cannot be used for time machine testing is in the context of “capacity”
which is almost fully consumed by their workload and not due to technical restriction
of the Data Center.
Bureau of State Audits
Additionally, Teale allowed six clients to use the time machine with an earlier Y2K-
ready version of MVS system software and failed to inform them of this fact. As of
November 1998, the clients had already tested ten of their computer systems with
the time machine. According to Teale staff, the center upgraded the MVS operating
system software on December 27, 1998; therefore, the software that will actually
be in use beginningJanuary 1, 2000, is a newer version than the one the six clients
tested.
We asked two independent experts, the Gartner Group and IBM, whether this
software upgrade would adversely affect the validity of the time machine tests
performed prior to December 27, 1998. According to these experts, the software
upgrade would probably not affect date calculations, and thus, not affect the validity
of the test; however, to be sure, Teale should give each client the opportunity to
investigate the potential impact on their individual systems. We suggested that Teale
notify the six clients affected by the software upgrade, and Teale indicated it would
do so.
R-6
Kurt R. Sjoberg
February 4, 1999
Comment/Response
Teale agrees with the Audit Report and believes the software upgrade would not
affect date calculations nor affect the validity of the test; however, Teale has notified
the six clients, as suggested by the Bureau of State Audits.
Bureau of State Audits
Finally, Teale is not requiring its clients to discontinue using non-compliant
commercial software products. Instead, Teale notified its clients on December 1,
1998, that certain software products are not year 2000-ready. However, it did not
identify when compliant software would be available, or set a date when the non-
compliant software would be removed from the data center computers. Instead,
Teale stated in the letter that it will not assume responsibility or accept any liability
arising from the functioning of agencies’ systems, applications or software after
December 31, 1999. Because of the potential risk that non-compliant software could
corrupt data or lead to an unstable processing environment, we believe that Teale
should be more aggressive and set a deadline for removing all non-compliant
software from its computers.
Comment/Response
All Teale customers have been informed that Y2K-readiness for their applications is
the responsibility of each department. Teale performed due diligence by
communicating and documenting Y2K information with all levels of their customer
departments, as well as the vendors and suppliers. Departments were also advised
to migrate to Y2K-ready products or risk the chance their business processes may
fail. Teale has also made Y2K computing environments available for departments to
4
test all critical processes. The Data Center has indeed set deadlines for the removal
of non-compliant Y2K software – i.e., customers were notified of the July 1, 1999,
deadline for the removal of non-compliant COBOL products.
Bureau of State Audits
Because many state agencies rely upon the data centers for their computer services,
it is critical that the data centers’ operations remain unhindered by year 2000
problems. Any interruption in computer services could be disastrous to state
agencies’ ability to provide critical services to Californians. Nevertheless, Teale Data
Center has not developed a business continuation plan to ensure it can deliver
services despite year 2000 problems. Teale acknowledges that it needs to develop
such a plan. Teale anticipates that its plan will be completed by June 1999.
R-7
Kurt R. Sjoberg
February 4, 1999
Comment/Response
Teale is currently focusing on its Business Continuation Plan which will be completed
by the second quarter of 1999.
Enclosed is the diskette, as requested, as well as copies of all appropriate
memoranda sent to customers by Teale Data Center regarding the Y2K issue. If
you have any questions, please contact Glen Matsuoka, Acting Director, Teale
Data Center, at (916) 263-1876.
In closing, please be assured that the Business, Transportation and Housing Agency
and the Teale Data Center are committed to a successful transition into the new
millennium with a minimum of disruptions.
R-8
COMMENTS
California State Auditor’s Comments
on the Response From the
Teale Data Center
T
o provide clarity and perspective, we are commenting
on the Teale Data Center’s (Teale) response to our
audit report. The numbers correspond with the numbers
we have placed in the response.
1
While Teale’s own critical software and equipment may be
compliant, as we state on page 33, Teale has not addressed
critical client services such as computer operations and telecom-
munications in its remediation plan and has yet to develop a
strategy to fully test these important systems.
2
The “individual detailed project task plans” Teale refers to are its
monthly update reports to the Department of Information
Technology. These reports do not constitute a year 2000 plan
that addresses the remediation of its computer processing and
telecommunication services critical to its clients.
3
As stated on page 36, Teale plans to use client testing to affirm
that its Multiple Virtual Storage (MVS) operating systems are
year 2000 ready. However, unlike the Health and Welfare Data
Center, it does not track what parts of the systems are tested by
clients so it cannot assess the systems’ readiness. Furthermore,
when asked, Teale could not provide us with any test plan or test
results for its MVS.
4
We are encouraged that after our fieldwork Teale is removing
two noncompliant compilers from access by its clients. However,
these noncompliant COBOL products are only 2 of at least 22
noncompliant mainframe software products Teale has identified
but has yet to preclude from use.
R-9
Blank page inserted for reproduction purposes only.
R-10