Attachment 003 - IPPS-A Technical Architecture Specification (v2.8 Redacted).pdf
PDF 975 KB Posted
- Attached to
- RFI IPPS-A TDS INC II Federal contract opportunity
- Solicitation number
- W91CRB-24-DRFI-002
About this file
This document is a Technical Architecture Specification (TAS) for the Integrated Personnel and Pay System - Army (IPPS-A) Increment II. It provides an overview of the software architecture, infrastructure, and technical components that support the IPPS-A system.
The document describes the IPPS-A infrastructure, including the hosting sites, network zones, enclaves, and application stacks. It details the core IPPS-A functionality, including the PeopleSoft applications for Human Capital Management, Payroll, Talent Management, and Self-Service. The TAS also covers system management capabilities such as monitoring, high availability, access management, and data management features like the Oracle database, replication, and reporting/analytics. Key technical components include Oracle WebLogic, Oracle Enterprise Manager, Oracle Identity Management, and the Gradkell digital signature solution. The TAS references applicable Army and DoD architectural guidance and standards the IPPS-A solution aligns to.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| IPPS-A RFI Response Template_20240417_Final.xlsx | XLSX spreadsheet | |
| Attachment 006 - IPPS-A Interface Diagrams (OV-5b A-0) - 21 NOV 2022.pdf | ||
| Attachment 001 - IPPS-A Functional Requirements List (Post R3) Bucketed dtd 17NOV22_Locked.xlsx | XLSX spreadsheet | |
| IPPS-A TDS_RFI_Final_04162024.pdf | ||
| Attachment 004 - IPPS-A Data Arcitecture - from TAS v2.8 (002).png | PNG image | |
| Attachment 005 - IPPS-A Interface Descriptions (OV-5b A-0 AV-2) - 21 NOV 2022_Locked.xlsx | XLSX spreadsheet | |
| Attachment 002 - IPPS-A Functional Baseline (version 4.0) Final 17 Sept 2020.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNCLASSIFIED
Integrated Personnel and Pay System – Army (IPPS-A)
Technical Architecture Specification (TAS)
Version 2.8
16 August 2022
. 16 August 2022 ii
REVISION HISTORY
Version Submitted Description Author
REMOVED
iii
Table of Contents 1 Introduction and Purpose .................................................................................................... A-1
1.1 Introduction ................................................................................................................. A-1
1.2 Document Purpose ...................................................................................................... A-1
1.3 Document Overview ................................................................................................... A-2
1.4 Reference Documents ................................................................................................. A-2
2 Intended Audience .............................................................................................................. A-4 3 Background ......................................................................................................................... A-5
3.1 Legacy Systems and IPPS-A ...................................................................................... A-5
3.2 Army Information Enterprise Architecture (IEA) ...................................................... A-5
Network Campaign Plan ..................................................................................... A-5 Common Operating Environment (COE) Architecture ...................................... A-5 Cloud Computing Initiative ................................................................................ A-6 Enterprise Cross-Domain Services and Solutions .............................................. A-6
3.3 Release 2 and 3 Challenges......................................................................................... A-6 Phire (Source Code Management) ...................................................................... A-6 IPPS-A Landing Zone (IALZ) ............................................................................ A-7 Canonicals Model, Inbound and Outbound Data Flows ..................................... A-8 Data Governance ................................................................................................. A-8
4 IPPS-A Increment II Software Architecture Overview .................................................... A-10
4.1 IPPS-A Infrastructure Software Framework ............................................................. A-11
IPPS-A Infrastructure Engineering ................................................................... A-11
4.1.1.1 Sites ................................................................................................................... A-13
4.1.1.2 Zones ................................................................................................................. A-13
4.1.1.3 Enclaves ............................................................................................................ A-14
4.1.1.4 SuperCluster ...................................................................................................... A-15
4.1.1.5 InfiniBand ......................................................................................................... A-16
4.1.1.6 ERP ................................................................................................................... A-16
4.1.1.7 Environments .................................................................................................... A-16
Application Stacks ............................................................................................ A-17
4.2 IPPS-A Software Layer Category: User Management ............................................. A-17
IPPS-A Core Functions ..................................................................................... A-17
4.2.1.1 PeopleSoft Human Capital Management (HCM) ............................................. A-18
PeopleSoft Global Payroll................................................................................. A-18 Oracle Talent Management ............................................................................... A-18 PeopleSoft Self-Service .................................................................................... A-19
4.2.1.2 PeopleSoft Customer Relationship Management (CRM) for HR Helpdesk .... A-19
4.2.1.3 PeopleSoft Enterprise Learning Management (ELM) ...................................... A-20
Training Tools ................................................................................................... A-20
4.2.2.1 PeopleSoft User Productivity Kit (UPK) .......................................................... A-20
Identity Management ........................................................................................ A-20 Digital Signature (Gradkell DBsign) ................................................................ A-20 Mobile Architecture .......................................................................................... A-21
4.3 IPPS-A Software Layer Category: Systems Management ........................................ A-21 System and Application Monitoring ................................................................. A-22
4.3.1.1 Oracle Enterprise Manager (OEM) ................................................................... A-22 iv
4.3.1.2 Logging Key Performance Indicators ............................................................... A-22
4.3.1.3 PeopleSoft Application Management Suite ...................................................... A-23
System High Availability (HA) ........................................................................ A-23 System Access Management............................................................................. A-24
4.3.3.1 Enterprise Access Management Service - Army (EAMS-A) ........................... A-24
4.3.3.2 Oracle Access Manager (OAM) ....................................................................... A-24
4.3.3.3 Oracle Identity Manager (OIM) ........................................................................ A-25
4.3.3.4 Oracle Unified Directory (OUD) ...................................................................... A-25
4.3.3.5 Oracle HTTP Server (OHS) .............................................................................. A-25
4.4 IPPS-A Software Layer Category: Data Management ............................................. A-26
Oracle RDBMS ................................................................................................. A-26
4.4.1.1 Advanced Security Option ................................................................................ A-26
Data Replication and High Availability (HA) .................................................. A-26
4.4.2.1 Oracle Multitenant ............................................................................................ A-26
4.4.2.2 Oracle Data Guard and Active Data Guard ...................................................... A-26
Database Vault and Label Security ................................................................... A-27 Gradkell DBsign ............................................................................................... A-27 Enterprise Reporting and Analytics/Data Warehouse ...................................... A-30
4.4.2.1 PeopleSoft Extensible Markup Language (XML)/BI Publisher ....................... A-30
4.4.2.2 HR Analytics ..................................................................................................... A-30
AngularJS and NodeJS ..................................................................................... A-31
4.5 IPPS-A Software Layer Category: Enterprise Application Integration .................... A-31
Ab Initio ............................................................................................................ A-31 Oracle GoldenGate (OGG) ............................................................................... A-32 Data Archiving .................................................................................................. A-32 Enterprise Service Bus (ESB) ........................................................................... A-32 PeopleSoft Integration Broker .......................................................................... A-33 Audit Vault........................................................................................................ A-34 Log Parsing Tool............................................................................................... A-34 Workflow Automation ...................................................................................... A-35
4.6 IPPS-A Software Layer Category: IPPS-A Software Tools Library ........................ A-35 IPPS-A Support Tools ...................................................................................... A-36
4.6.1.1 HP Agile Manager ............................................................................................ A-36
4.6.1.2 HP Application Lifecycle Management (ALM) ............................................... A-36
4.6.1.3 Cameo ............................................................................................................... A-36
4.6.1.4 Integrated Risk Information System (IRIS) Intelligence .................................. A-37
Content Management and Configuration Control Tools .................................. A-37
4.6.2.1 MS SharePoint .................................................................................................. A-37
Developer Tools ................................................................................................ A-37
4.6.3.1 PeopleTools....................................................................................................... A-37
4.6.3.2 SQL Developer ................................................................................................. A-38
4.6.3.3 PuTTY............................................................................................................... A-38
4.6.3.4 UltraEdit and UltraCompare ............................................................................. A-38
4.6.3.5 Common Business-Oriented Language (COBOL) Compiler for PeopleSoft ... A-38
4.6.3.6 JDeveloper Integrated Development Environment (IDE) ................................ A-38
4.6.3.7 Altova XML Spy............................................................................................... A-39 v
Training Tools – Adobe Captivate .................................................................... A-39 Test Tools.......................................................................................................... A-39
4.6.5.1 cFactory............................................................................................................. A-39
4.6.5.2 HP Performance Center .................................................................................... A-39
4.6.5.3 HP Unified Functional Testing (UFT) .............................................................. A-39
4.6.5.4 SnagIt ................................................................................................................ A-39
4.6.5.5 Simple Object Access Protocol UI (SoapUI) .................................................... A-40
Remote Access Tools ........................................................................................ A-40
4.6.6.1 Virtual Desktop Infrastructure (VDI) ............................................................... A-40
4.6.6.2 Exceed X Server Software ................................................................................ A-41
4.6.6.3 VMWare Horizon View .................................................................................... A-41
4.6.6.4 Windows Terminal Server (TS) 2012 ............................................................... A-41
5 IPPS-A Increment II System Architecture Overview ....................................................... A-42
5.1 IPPS-A Functional Architecture ............................................................................... A-42
Data Sources ..................................................................................................... A-43 Provisioning ...................................................................................................... A-43 Security ............................................................................................................. A-44
5.1.3.1 Hosting Site Security ........................................................................................ A-44
5.1.3.2 Software and Database Security ....................................................................... A-44
5.1.3.3 Vulnerability ..................................................................................................... A-45
5.1.3.4 IPPS-A Web Site Protection ............................................................................. A-45
5.1.3.5 Dual Persona Authorization Accommodations ................................................. A-47
IPPS-A Core Functionality ............................................................................... A-47 IPPS-A Training Environments Capabilities Vision ........................................ A-48
5.1.5.1 Army Training Objectives ................................................................................ A-49
5.1.5.2 Institutional/Self-Development/Qualification Training Environment .............. A-49
5.1.5.3 Operational Training Environment ................................................................... A-50
IPPS-A Auditing ............................................................................................... A-50
5.1.6.1 IPPS-A Oracle Audit Vault Server ................................................................... A-50
5.1.6.2 IPPS-A Splunk Enterprise Log Parsing ............................................................ A-51
5.2 IPPS-A Technical Architecture: High-Level Component Design ............................ A-52
REMOVED ....................................................................................................... A-56
5.2.1.1 REMOVED REMOVED Data Center (SDC) .................................................. A-56
Architecture Summary ...................................................................................... A-56 Zone B ............................................................................................................... A-57
5.2.1.1.2.1 Architecture Summary ............................................................................... A-57
5.2.1.1.2.2 Data Flow Diagram .................................................................................... A-57
5.2.1.1.2.3 Logical Architecture .................................................................................. A-57
5.2.1.1.2.4 Performance Standards .............................................................................. A-57
Zone A .............................................................................................................. A-57
5.2.1.1.3.1 Architecture Summary ............................................................................... A-58
5.2.1.1.3.2 Data Flow Diagram .................................................................................... A-58
5.2.1.1.3.3 Logical Architecture .................................................................................. A-58
5.2.1.1.3.4 Performance Standards .............................................................................. A-58
5.2.1.1.3.5 High Availability (HA) Applications ........................................................ A-58
REMOVED SDC Tools Enclave ...................................................................... A-58 vi
REMOVED COOP ........................................................................................... A-59
5.2.1.1.5.1 Architecture Summary ............................................................................... A-59
5.2.1.1.5.2 Data Flow Diagram .................................................................................... A-59
5.2.1.1.5.3 Logical Architecture .................................................................................. A-59
5.2.1.1.5.4 Performance Standards .............................................................................. A-59
5.2.1.1.5.5 High Availability (HA) Applications ........................................................ A-59
5.2.1.2 REMOVED REMOVED Data Center (PDC) .................................................. A-59
Architecture Summary ...................................................................................... A-60 Data Flow Diagram ........................................................................................... A-60 Logical Architecture ......................................................................................... A-60 Performance Standards ..................................................................................... A-60 High Availability (HA) Applications ................................................................ A-60
6 Business Information Component Architecture ................................................................ A-61 Appendix A: Acronyms and Abbreviations ........................................................................... A-62 Appendix B: Data Center Buildout ...........................................................................................B-1 Appendix C: REMOVED Network Diagrams ..........................................................................C-1 Appendix D: Requirements Traceability Matrix (RTM) INC II Release 2 .............................. D-1
List of Figures
Figure 3-1 IPPS-A Landing Zone ............................................................................................... A-7
Figure 3-2 Data Quality Process Flow ........................................................................................ A-8
Figure 4-1 IPPS-A Software Layer Categories ......................................................................... A-10
Figure 4-2 IPPS-A Software Architecture Overview ............................................................... A-11
Figure 4-3 IPPS-A Infrastructure High-Level Design .............................................................. A-12
Figure 4-4 PeopleSoft Functional Solution: IPPS-A Core Capability INC II, Release 3 ......... A-12
Figure 4-5 IPPS-A Infrastructure High-Level Application Flow Diagram .............................. A-12
Figure 4-6 IPPS-A Inbound Data Flow Diagram – Exploded for ESB .................................... A-12
Figure 4-7 IPPS-A Outbound Data Flow Diagram - Exploded for ESB .................................. A-13
Figure 4-8 IPPS-A INC II SuperClusters.................................................................................. A-15
Figure 4-9 Example: IPPS-A Infrastructure Application Stacks (Multiple Environments) ..... A-17
Figure 4-10 Oracle-Optimized Solution for PeopleSoft ........................................................... A-22
Figure 4-11 Infrastructure High-Level Gradkell Architecture .................................................. A-29
Figure 4-12 IPPS-A PeopleSoft HR and Self-Service Analytics Tiles ..................................... A-31
Figure 4-13 Implementation of VMWare Horizon View ......................................................... A-41
Figure 5-1 Overview of the IPPS-A Functional Architecture .................................................. A-42
Figure 5-2 Provisioning Diagram ............................................................................................. A-43
Figure 5-3 IPPS-A Access Control Layers ............................................................................... A-45
Figure 5-4 IPPS-A Authentication Flow Architecture .............................................................. A-46 vii
Figure 5-5 PeopleSoft Functional Solution: IPPS-A Core Capability - All Releases .............. A-47
Figure 5-6 Oracle Audit Vault Auditing ................................................................................... A-51
Figure 5-7 Splunk Enterprise Engine Architecture ................................................................... A-51
Figure 5-8 Splunk Enterprise Log Parsing Pipeline Segment Architecture ............................. A-52
Figure 5-9 Splunk Enterprise Architecture ............................................................................... A-52
Figure 5-10 IPPS-A Authentication Flow Architecture ............................................................ A-53
Figure 5-11 Infrastructure High-Level OAM OIM OUD Architecture .................................... A-53
Figure 5-12 Infrastructure High-Level HCM CRM ELM Architecture ................................... A-53
Figure 5-13 Infrastructure High-Level PeopleSoft Network Architecture ............................... A-53
Figure 5-14 Infrastructure High-Level OBIA ODI OBIEE Architecture ................................. A-54
Figure 5-15 Infrastructure High-Level UPK Architecture ........................................................ A-54
Figure 5-16 Infrastructure High-Level Stonebranch Architecture ............................................ A-54
Figure 5-17 Inbound Message Flow – Implementation Perspective w/ Segregation ............... A-55
Figure 5-18 Outbound Message Flow – Implementation Perspective w/ Segregation ............. A-55
Figure 5-19 Shared File System ................................................................................................ A-55
Figure 5-20 ESB SOA Application High-Level Architecture .................................................. A-55
Figure 5-21 ESB KafkaApplication High-Level Architecture ................................................. A-55
Figure 5-22 ESB DMZ High-Level Architecture ..................................................................... A-56
Figure 5-23 REMOVED REMOVED Data Center Zone B Design ......................................... A-57
Figure 5-24 REMOVED REMOVED Data Center Zone A Design ......................................... A-58
Figure 5-25 REMOVED REMOVED Data Center Tools Enclave Design .............................. A-58
Figure 5-26 REMOVED REMOVED Data Center SDC (COOP) Design............................... A-59
Figure 5-27 REMOVED REMOVED Data Center Production Design ................................... A-60
List of Tables
Table 1-1 Reference Documentation .......................................................................................... A-2
Table 4-1 IPPS-A INC II Release 3 Gradkell DBsign Features ............................................... A-28
A-1
1 INTRODUCTION AND PURPOSE
1.1 Introduction
The Army currently relies on more than 60 separate legacy information systems to provide personnel and pay management for all components (Active, Guard, and Reserve). These systems were designed at different times, reside on different hardware platforms, use a variety of in-house and commercial software, and vary widely in their functionality.
To consolidate these systems, the Army is developing and implementing the Integrated Personnel and Pay System – Army (IPPS-A), a Web-based tool, available 24 hours a day, accessible to Soldiers, Human Resources (HR) professionals, Combatant Commanders, personnel and pay managers, and other authorized users throughout the Army.
Team CACI has been selected as the System Integrator (SI) to ensure successful development and delivery of the envisioned IPPS-A.
1.2 Document Purpose
This document provides the specifications of servers and environments, functionality of the software components, and a complete list of hardware and software to support those capabilities for IPPS-A Increment (INC) II Production, Test, and Development enclaves. Note that the hardware and software list is complete at document delivery, but changes to these configuration items are expected and this document will be updated accordingly. This document describes the overall technical architecture of the IPPS-A INC II system, including:
• Logical views of environments
• Physical view of the servers, storage, and network
• Server and virtual machine (VM) specifications
• Application installation prerequisites
• Application overviews to provide a basis of functionality in the environments
• Hardware and software inventory lists
• References to the applicable Army (IPPS-A) Functional Baseline This Technical Architecture Specification (TAS) defines the Army’s accepted hardware and software portfolio as well as the system architecture for IPPS-A INC II. This specification contains:
• Descriptions for physical and logical architectures
• Network information
• Operating system (OS) and system software versions and patch levels
• Detailed configuration settings for all software and hardware
• Review of security, including hardware, software, personnel, and procedures
• Review of the use of Common Operating Environment (COE) technologies
A-2
• Support for cloud computing initiatives
• Cross-Domain Solution (classified Sensitive Products [SPs] CDRL REMOVED)
1.3 Document Overview
The TAS defines and describes the infrastructure components implemented as part of IPPS-A INC II activities to meet IPPS-A requirements. Infrastructure components discussed in this document may be used for future program releases as defined in TASs of future releases. This document will be revisited over the project lifecycle to confirm accuracy, adjust technical details, and build out new architecture.
The document’s primary sections:
• Section 2 identifies the intended audience.
• Section 3 provides background information, including legacy systems.
• Section 4 describes the IPPS-A INC II Software Architecture.
• Section 5 describes the IPPS-A INC II System Architecture.
• Section 6 describes the Business Information Component Architecture.
A detailed itemization of tasks to instantiate this environment is not in this document; it is in the IPPS-A INC II SI’s Integrated Master Schedule (IMS). Select diagrams in this document were delivered to the Government in standard engineering format using American National Standards Institute (ANSI) E size in Technical Architectural Drawings; all other diagrams are delivered in this document in standard A4 size.
Although this document is a Quality Assurance Surveillance Plan (QASP) deliverable, it is considered a living document that can be updated during post-analysis phase activities.
The Sensitive Activities (SA) Annex for this document is maintained on the Enterprise Access Management Service - Army (EAMS-A) – Secret Internet Protocol Router Network (SIPRNet)
(EAMS-A-S).
The process for Cyber Compliance Verification (which is shown as “CCV” in the diagrams found throughout this document) is now known as Final Production Connectivity, or “FPC”.
However, the content of the diagrams is not affected by this difference.
1.4 Reference Documents
Table 1-1 lists cited references and supporting material used in developing this document.
Table 1-1 Reference Documentation
Document Date AR 350-1, Army Training and Leader Development 19 AUG 14 Army Regulation (AR) 25-1 25 JUN 13 Committee for National Security Systems Instruction 4009 06 APR 15 Department of Defense (DoD) Information Enterprise Architecture (IEA) v2.0 , Volumes I and II 10 AUG 12
REMOVED 30 JUN 22
IPPS-A Enterprise Service Bus (ESB) Specification 06 SEP 16
A-3
Document Date IPPS-A Increment I TAS (Increment I, CDRL REMOVED) 15 MAY 15 National Institute of Standards and Technology (NIST) Special Publication 800-70, Rev. 3 12 DEC 15 Oracle Technical Manuals and White Papers N/A TRADOC Pamphlet 525-8-3 07 JAN 11 U.S. Army Training and Doctrine Command (TRADOC) Pamphlet 525-8-2, the U.S. Army Learning Concept for 2015 20 JAN 11
A-4
2 INTENDED AUDIENCE
This TAS is designed for the following audiences:
• Architects: Reference for implementing a specific architectural component in this document
• Managers: Reference to understand the technical approach
• Administrators: Reference to see the framework for the design approach and knowledge transfer
• Software Developers: Reference to better understand the environments, settings, and
Integrated Development Environment (IDE)
• Testers: Reference to better understand the environments, settings, and Integrated Test
Environment (ITE)
• IPPS-A Hosting Centers: Reference for building out the environments
A-5
3 BACKGROUND
3.1 Legacy Systems and IPPS-A
Army legacy personnel and pay systems vary greatly in design, technology, functionality and maintainability. The integration of those heterogeneous systems can oftentimes cause processing errors, requiring manual workarounds, and increasing processing costs. In addition, many are based on Army component-unique business practices that manage Army component-unique data.
Some interfaces have been operating for decades using antiquated software on obsolete hardware. The difficulty in integrating the Army’s component-unique data elements into meaningful information presents problems in monitoring deployments, responding to needs of family members, and implementing personnel and pay policies.
In order to modernize its personnel and pay systems, the Army has chosen to use an out-of-the-box Enterprise Resource Planning (ERP) software solution along with a hybrid Agile methodology to develop its IPPS-A application. This approach allows the program to develop and deploy integrated personnel and pay capabilities, building on the trusted database and PeopleSoft foundation delivered during INC I (see Increment I, CDRL REMOVED, Technical Architecture Specification Documentation). INC II uses PeopleSoft 9.2 (or higher) and Oracle RDMS 12c (or higher) database capabilities, with application technologies outside the core ERP, to meet user requirements for the total system. IPPS-A is being developed and deployed incrementally, delivering fully integrated personnel and pay management functionality gradually, over multiple releases.
IPPS-A combines Agile, Modular, and traditional engineering methodologies in development with the SI. The IPPS-A Program Management Office (PMO) and SI determine which methodology is the best fit for each activity. For example, Agile development lends itself to requirements and third-party applications development and design; modular development methodology lends itself to PeopleSoft Fits/Gaps, data management, design, and traditional engineering can best be used for the network and system design.
3.2 Army Information Enterprise Architecture (IEA)
The Army Information Enterprise Architecture (IEA) is a high-level representation of the LandWarNet (LWN) architecture, as it supports the Army’s Enterprise Information Environment, Warfighting, Business, and Defense Intelligence Mission Areas. The IEA is sub-divided into the LWN 2020 and Beyond Enterprise Architecture (EA), and a set of Enterprise Reference Architectures (RAs), all of which the Chief Information Officer (CIO)/G-6 develops.
Network Campaign Plan The Army Network Campaign Plan includes policy, principles and rules, constraints, technical guidance, standards and forecasts, implementation conventions, and criteria. Each of these documents has a unique role in the IEA by providing specific architecture-related information.
Common Operating Environment (COE) Architecture The Army has published guidance for a COE Architecture for the Army Enterprise Network that both CIO/G-6 and the Assistant Secretary of the Army (ASA) for Acquisition, Logistics, and Technology (ALT), approved.
A-6
The COE is a set of computing technologies and standards that enable secure and interoperable applications to be rapidly developed and executed across a variety of computing environments— server, client, mobile devices, sensors, and platforms.
Cloud Computing Initiative Army Enterprise Cloud Computing informs, guides, and constrains delivery of cloud computing environments in DoD and non-DoD data centers and application migrations to these environments in support of the Army’s transition to cloud computing. IPPS-A will use DoD data centers but will not implement cloud computing at this time.
Enterprise Cross-Domain Services and Solutions Another initiative of the Army IEA is to implement Enterprise Cross-Domain Services (ECDS).
ECDS is an automated set of capabilities available to multiple users, organizations, and/or hosted mission applications in an enterprise environment for information sharing across and among security domains using one or more cross-domain solutions (CDSs) (CNSSI 4009). CDSs support encrypted data transport between internal and external networks for information sharing.
Further information on the IPPS-A ECDS solution is in the classified annex to this document.
3.3 Release 2 and 3 Challenges
REMOVED
Phire (Source Code Management) Phire is an application Change Management Solution built using PeopleTools to better manage and control changes that are necessary for PeopleSoft and other large enterprise applications.
Phire runs on PeopleSoft Technical Architecture and has Incident Management Capabilities, Workflow Driven Change Request Tracking, PeopleTools Object Versioning and Migrations and custom reporting for configuration audit purposes. Phire tasks define the manual steps to migrate the software.
Phire application is configured for IPPS-A usage for development support, change request tracking, code repository and reporting purposes.
Phire for PeopleSoft and non-PeopleSoft Applications The IPPS-A needs a Change Management tool that works with Oracle PeopleSoft to replace Stat for PeopleSoft. An Alternatives of Analysis (AoA) was conducted that evaluates the change management tool performance, program suitability, provide cost alternatives and to mitigate the cyber risks of the DoD’s supply chain management. The AoA was completed 26 March 2021.
The IPPS-A Phire procurement process was completed on 15 October 2021. The SI CM proof of concepts testing was completed on the 23 November 2021.The administrative functions testing was completed in January 2022.
IPPS-A Phire usage:
There are two different classes of migrations supported by the Phire application. People Soft and Non- PeopleSoft applications which are essentially flat file based. There is a slight difference between the PeopleSoft and Non- PeopleSoft applications and each of the life cycle processes is demonstrated in the process diagrams in the Phire SOP.
A-7
SI CM is responsible for performing CM practices for IPPS-A Configuration Items (CIs), but does not manage the REMOVED environments in which select CIs reside. SI CM does have varied interest and influence in all IPPS-A environments, but to differing degrees. SI CM currently performs a verification and validation (V&V) audit on the PROD and TRAINING environments to ensure that the environments are CM controlled.
IPPS-A Landing Zone (IALZ) The IALZ is more than a SFTP server receiving and serving point to points (P2P). It includes the web service APIs, batch, and asynchronous content delivery to topics that enforces need-to-know. With a clearly delineated IPPS-A Landing Zone (IALZ) IPPS-A and its respective partners know where information came from, where it goes, where to find it, and how it is managed. The IALZ streamlines source profiling, using available tools to generate information and rules that users and other apps can leverage. This by no means replaces the requirement for data stewards to address the data nuances like effective dating and record duplication, which are essential to improving data quality. Additionally, this is a great opportunity to access what IPPS- A legacy investments to integrate them into the process. By storing information persistently, it enables additional analysis and/or replay of sources, which is an essential element for analytics, mashups, and incorporating new content. These concepts are essential Release 3 capabilities.
IALZ decreases the number of sources/sinks, which subsequently reduces complexity, costs, maintenance, and implementation timelines, while increasing system agility.
Figure 3-1 IPPS-A Landing Zone
Providing a centralized content repository, including raw inbounds, finished reports, logs, etc., enables content discovery and proactive responses for IPPS-A developers and soldiers. It provides a secure IPPS-A infrastructure boundary, where IPPS-A can run tests according to mission priorities and build standalone services, mitigating dependencies on external systems.
This landing zone standardizes repository containing raw materials and finished assets within an organizational taxonomy that is easy to use and discover. The infrastructure component provides enterprise scalability to capture and source information, where producers can drop off raw information, ETL processes can pick it up, analysts can leverage it in mashups, and applications can serve it to their producers. The landing zone is IPPS-A’s edge, insulating the system of record, storing it in a location that supports volume, velocity, veracity and variety, and managing asset change in a compatible way to enable its evolution in directions not yet envisioned – “Forward Integration”.
IALZ uses governance to keep it from becoming a morass and is the first step and the foundation for establishing canonical models and data quality, which are critical IPPS-A success factors. A fully featured and capable IALZ mitigates these feature costs and complexities. IALZ establishes governance via:
A-8
1. Consumer topic schemas – Consumer topics set the overall system content types for 42+ topics for the trading partners. Further, enhancements enable trading partners to alter both their shape and size. Combining both these concepts (i.e. forward compatible schema approach & content selectivity / filtering), mitigate change impacts to only the trading partners requiring them, reducing implementation costs and raising system agility.
2. Audit – The implementation of interceptors captures a massive amount of audit and aid in the enforcement of need-to-know (see PEP). This information gains significant insight for how IPPS-A’s trading partners leverage the application, which leads to proactive governance through alerting.
3. Policy Enforcement Point (PEP) – Leverages interceptors, defined consumer groups, and topic accessibility to govern test, PMO, FMD, and trading partner’s access to information based upon their need-to-know.
4. Checksum, Connector, & File Limits – These capabilities ensure the integrity of the information that IPPS-A provides and restricts the resources that the partners can employ within the IALZ.
5. File Movement – This capability provides for generic file movement provided that the file adheres to a standard naming convention.
Canonical Models, Inbound and Outbound Data Flows Building outbound canonical models and simplifying outbound data flows decrease complexity, cost, and maintenance, since it decouples IPPS-A external consumers and the system by segregating concerns. This decoupling substantially increases agility by creating reuse, allowing teams to focus on a specific function and work in parallel.
Figure 3-2 Data Quality Process Flow
Identifying and leveraging canonical models for inbound and outbound data flows mitigates point-to-point integrations that create individual end-to-end herculean efforts and situations where IPPS-A directly couples itself to external systems. Canonical models centralize business logic and transformation, creating a higher quality inputs and business object outputs. These enable the identification of rules and relationships, providing externalization and reuse. They create segregated roles and responsibilities where responsibilities may work in isolation:
Acquisition and Dissemination, Routing and Model, and Internal ETL. Canonical models and taxonomies identify a consistent, trusted, and valued standard sharing capability, creating an information clearing house for soldier and organization information that everyone wants to use.
Data Governance Asset governance leads to using appropriate tools, defining a roadmap in how IPPS-A plans to transition to their ultimate mission goals, reducing costs and management. Data governance leads to high quality information, which translates to total soldier confidence and a 360-degree soldier perspective. Profiling incoming information externalizes rules and business processes for reusability, reduces time to market, increases mission agility, enables adaptable interfaces providing the ability to pivot quickly and address evolving mission objectives.
A-9
Asset governance provides guidance on best practice use of tools to solve mission challenges mitigates the use of multiple competing products and establishes capabilities via a technical roadmap, providing a process to add new feature capabilities, and a plan identifying when feature capabilities become milestones and the SI ages off or enable products. Additionally, asset governance tracks Key Performance Indicators (KPIs) and where we need to track them.
Data governance identifies what versions of what interfaces and business objects work in conjunction with others. It tracks compatibility between versions mitigating service changes from rippling across infrastructure layers; it provides Policies, Rules, and Standards for our and external system compliance and Service Level Agreements (SLAs).
Governance of assets and products within the system is essential for its agility, maintainability, compliance, and reporting. Maintenance comprises more than 80% of any software implementation; and governance comprises tools, policies, and procedures to control whether that statistic is closer to 90% or much less. Compliance and reporting establishes trust with our information providers and end users. Governance provides the infrastructure to promote a mission’s growth, how it protects its information, and a plan for the future.
A-10
4 IPPS-A INCREMENT II SOFTWARE ARCHITECTURE OVERVIEW
This section provides an overview of the IPPS-A INC II software architecture. It contains the following sub-sections identifying the major software categories used in developing the IPPS-A application. Software categories are layers of software designed to perform a group of coordinated functions, tasks, or activities in support of the IPPS-A application.
• IPPS-A Infrastructure Software Framework (Section 4.1)
• IPPS-A Software Layer Category: User Management (Section 4.2)
• IPPS-A Software Layer Category: Systems Management, Applications (Section 4.3)
• IPPS-A Software Layer Category: Data Management (Section 4.4)
• IPPS-A Software Layer Category: Enterprise Application Integration (Section 4.5)
• IPPS-A Software Layer Category: IPPS-A Software Tools Library (Section 4.6) Figure 4-1 depicts the IPPS-A high-level software layer categories, features, functionality and supporting applications as shown from a vertical perspective. The collective nouns describing the categories of application software refers to all applications collectively.
Figure 4-1 IPPS-A Software Layer Categories
To view a larger version of Figure 4-1, click the PDF icon.
The software architecture overview in Figure 4-2 depicts both horizontal and vertical graphical hierarchies of the software acquired to support the major coordinated functions, software groupings and the software acquired in order to meet the requirements of the IPPS-A application.
It includes but is not limited to the following hierarchy software groupings and supporting applications:
• IPPS-A System
− Access Point − Enterprise User Authentication and Work Authorization Layer − IPPS-A CORE Function: Human Capital Management (HCM), Payroll, Talent
Management, Self-Service − Data Management − Backup, Data Archiving − Enterprise Reporting and Analytics/Data Warehouse − Enterprise Integration Layer − Governance and Audit Controls − High Availability, Replication − Training
A-11
− Customer/Case Management − Rules Engine − Digital Signature − Job Scheduler − System and Application Monitoring
• Support Tools and Local Install
− Requirements, Business Process Management, Archiving − Risk Management − Content Management and Configuration Control − Developer Tools − Training Tools − Test Tools − Remote Access and Tools
Figure 4-2 IPPS-A Software Architecture Overview
REMOVED
To retrieve the latest version of this document on SharePoint, click on the hyperlink below.
REMOVED
To view a larger version of Figure 4-2, click the PDF icon.
REMOVED
4.1 IPPS-A Infrastructure Software Framework
This section gives a high-level overview of the IPPS-A INC II technical architecture and components of the system located at the following hosting data centers:
• INC II Primary Data Center (PDC) at REMOVED
• INC II Secondary Data Center (SDC) is the REMOVED in the remainder of this document.
IPPS-A Infrastructure Engineering The organization of the IPPS-A environmental design is a tiered structure consisting of many distinct layers. The many layers include sites, zones, enclaves, application stacks, and environments. In addition, the existence of Non-secure Internet Protocol Router Network (NIPRNet)-connected and Secure Internet Protocol Router Network (SIPRNet)-connected networks could define an additional layer. However, as the SIPRNet-connected network mirrors the environmental design of the NIPRNet-connected network, this document represents both as a single structure. Please utilize the Table of Contents to locate specific parts and descriptions of the IPPS-A architecture. For more details on the architecture of an application, please reference the applicable vendor documentation.
A-12
Figure 4-3 shows the high-level technical infrastructure architecture for all INC II data centers.
The IPPS-A INC II PDC and SDC are shown.
Figure 4-3 IPPS-A Infrastructure High-Level Design
To view a larger version of Figure 4-3, click the PDF icon.
To retrieve the latest version of this diagram on SharePoint, click on the hyperlink below.
REMOVED
Figure 4-4 shows the high-level functional solution for INC II, Release 3.
Figure 4-4 PeopleSoft Functional Solution: IPPS-A Core Capability INC II, Release 3
To view a larger version of Figure 4-4, click the PDF icon.
Figure 4-5 shows the high-level data flows for INC II. A more detailed description of the functionality found in the diagram is located in Section 4.5 IPPS-A Software Layer Category:
Enterprise Application Integration.
Figure 4-5 IPPS-A Infrastructure High-Level Application Flow Diagram
To view a larger version of Figure 4-5, click the PDF icon.
Figure 4-6 shows the IPPS-A Inbound Data Flow Diagram – Exploded for ESB INC II Release
3. A more detailed description of the functionality found in the diagram is located in Section 3.3.3.
Figure 4-6 IPPS-A Inbound Data Flow Diagram – Exploded for ESB
REMOVED
To view a larger version of Figure 4-6, click the PDF icon.
A-13
Figure 4-7 shows the IPPS-A Outbound Data Flow Diagram - Exploded for ESB for INCII Release 3. A more detailed description of the functionality found in the diagram is located in Section 3.3.3.
Figure 4-7 IPPS-A Outbound Data Flow Diagram - Exploded for ESB
REMOVED
To view a larger version of Figure 4-7, click the PDF icon.
4.1.1.1 Sites
The first tier of the environmental design is the site level. The term sites refers to the hosting data center that fulfills specific requirements for phases of the Software Development Lifecycle (SDLC). Current sites include:
• REMOVED Data Center: The REMOVED infrastructure supports enclaves and environments for all development, testing, and secondary data center operations, including support, and sustainment activities.
• REMOVED Data Center: REMOVED infrastructure hosts enclaves and environments for primary data center operations and sustainment activities.
4.1.1.2 Zones
According to the REMOVED Test and Development Enclave Security Technical Implementation Guide (STIG) dated 22 January 2016, a zone breakdown has been developed to establish the security baselines, which must be in place for each test and development environment.
REMOVED has identified four zones for various activities. For IPPS-A INC II, two of these zones support the SDLC.
• Zone A: IPPS-A uses Zone A to support its Test enclave, environments in that enclave, and a
Support Tools Enclave to support those environments. According to the STIG:
“The Zone A environment is typically configured as a mirrored operational network for final end stage testing. This environment will have connectivity to the live operational network for final data testing prior to the product or application deployment into the operational network.”
“Since the Zone A environment mimics the operational network, the supporting infrastructure will comply with all applicable DoD policy and security requirements.
Prior to being granted connectivity, it will go through a risk assessment for the Connection Approval Process. The environment is required to hold at minimum, an Interim Authority to Operate (IATO) for connectivity to the Defense Information Systems Network (DISN) or other live operational network in the DoD. An Interim Authority to Test (IATT) may be obtained where the test environment requires testing of live operational data that cannot be mirrored or make use of sanitized data. The
A-14
Information System Security Manager (ISSM) will conduct a security risk assessment for the requested IATT approved by the Army Organization (AO).”
• Zone B: IPPS-A Development enclave, environments in that enclave, and a Support Tools Enclave to support those environments hosted by REMOVED in Zone B. According to the
STIG:
“Zone B follows and is similar to Zone A from a network connectivity perspective, but with much stricter control mechanisms in the infrastructure supporting the environment.”
“The Zone B environment is the designated zone permitting connectivity for moving sanitized data for testing along with developing applications destined for a live and operational DoD network.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .