Asset_Config_Management_Conops_Final.pdf
PDF 1022 KB Posted
- Attached to
- ServiceNow Federal contract opportunity
- Solicitation number
- HB0001-18-R-0012
- Issued by
- Department of Defense Cyber Command
About this file
Asset Config Management Conops Final
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CONCEPT OF OPERATIONS
FOR
IT Service Management
Version 0.2.5
21 March 2018
Requirement Sponsor/Org: J64
RMS #: RSF-098-17-616
Revision History
Version Date of
Change Changes Made
Name of Person/Office
Entering Change
0.1 03/28/2017 Initial Draft Initiation A. Hatfield
0.1.1 04/14/2017 Review and Polish N. Centafont/ E. Veeck
0.1.2 04/21/2017 Second Draft Initiation A. Hatfield
0.1.3 04/24/2017 Updated Section 2.4, 2.5, and 4.5 E. Veeck
0.1.4 04/24/2017 Added content under Knowledge
Management and Configuration
Management
N. Centafont
0.1.5 04/25/2017 Updated Section 2.2, 4.2, 4.3, E. Veeck
0.1.6 04/25/2017 Updated Tables and Section 5.1, 5.2, 5.3, and 6
A. Hatfield
0.1.7 04/25/2017 Updated Section 4.7 N. Centafont
0.1.8 04/26/2017 Reviewed and commented E. Wojciechowski
0.2.1 5/3/2017 Updated Section 3.1 and fixed feedback
A. Hatfield
0.2.2 5/9/2017 Updated Section 3.1 and 3.3 N. Centafont
0.2.3 5/25/2017 Revised based from feedback N. Centafont
0.2.4 5/25/2017 Added Signature Blocks/Altered formatting
A. Hatfield
0.25 3/20/2108 Added OV-1, ServiceNow
Process Diagram links; and high-level integrated process diagram
N. Centafont/E. Veeck/C.
Bowman
TABLE OF CONTENTS
1 SCOPE
1.1 System Overview and Identification
1.2 Security Considerations
1.3 System security
2 CURRENT SYSTEM AND STATE
2.1 Background, objectives, and scope
2.2 Operational policies and constraints
2.3 Current System Description
2.4 User Classes and affected personnel
2.5 Support Environment
3 ANALYSIS AND JUSTIFICATION OF THE PROPOSED SYSTEM
3.1 Summary of Advantages and Improvements
3.2 Summary of disadvantages and limitations
3.3 Alternatives and trade-offs considered
4 SYSTEM CONCEPT
4.1 Background, objectives, and scope
4.2 Operational policies and constraints
4.3 Technical Policies & Constraints
4.4 Description of the new or modified system
4.5 User Classes and affected personnel
4.6 Support concept
4.7 Operational scenarios
5 SUMMARY OF IMPACTS
5.1 Operational impacts
5.2 Organizational impacts
5.3 Impacts during development
6 REFERENCES
7 APPENDICES
7.1 Appendix A: Acronyms
INDEX OF FIGURES
Figure 1 - Service Management Processes Figure 2 - ITIL Framework
Figure 3– Implementation Environments with ServiceNow and Discovery Products
INDEX OF TABLES
Table 1-Roles and Responsibilities Table 2 - Operational Support Providers Table 3 - Acronym Appendix
1 SCOPE
1.1 System Overview and Identification
As USCYBERCOM continues to support the Cyber Mission Forces and Cryptologic Centers, the supporting information technology (IT) infrastructure continues to grow in complexity in terms of hardware and software deployed as well as the number of differing configurations associated with these components of the IT infrastructure. As part of the Clinger-Cohen Act of 1996, and the Department of Defense (DoD) Chief Information Officer (CIO) Policy1, the CIO is required to establish IT policies for managing the IT enterprise environment as well as tracking all IT assets within the organization. In order to meet these objectives, the commercial market provides a wide range of robust IT Service Management (ITSM) products providing management oversight, situational awareness, and structured change management processes for the IT operational environment, as well as, tracking all assets. The objective of this CONOPS is to justify an investment in an integrated commercial-off-the-shelf (COTS) ITSM solution so that
USCYBERCOM may leverage the solution to meet DoD and CIO requirements.
1.2 Security Considerations
This document is unclassified and for the use of official government business in accordance with records management policies and/or regulations.
1.3 System security
As an IT Service Management tool for USCYBERCOM, all security controls for the proposed system will be consistent with the Risk Management Framework (RMF) rating assigned by CDG
J65 Information Assurance Manager once the system is assessed.
In addition to complying with the RMF, the system will be required to comply with the Security
Technical Implementation Guides (STIGS) issued by the Defense Information Systems Agency
(DISA) as well as, vendor patches for both the application itself and any of the supporting prerequisite applications.
Single SignOn required utilizing either CAC or PKI enabled credentials in Unclassified, Secret and Top Secret domains.
2 CURRENT SYSTEM AND STATE
2.1 Background, objectives, and scope
No singular system currently exists for IT Service Management (ITSM) in USCYBERCOM.
Presently, Atlassian’s product suite, JIRA, provides Service Desk functionality along with Eagle
Alliance’s implementation of ServiceNow. No system at USCYBERCOM encompasses all
ITSM processes to include Asset Management, Change Management, Configuration
Management, Incident Management, Knowledge Management, Problem Management, Release
Management, Requirements Management, Service Catalog, Service Desk and Service Level
1 Department of Defense Directive 8000.01 March 17, 2016, Management of the Department of Defense
Information Enterprise (DoD IE).
Management. USCYBERCOM selected ServiceNow as the commercial off the shelf (COTS) product for meeting these requirements. The ServiceNow application suite, successfully implemented at NSA, will reduce resource requirements and administrative overhead enabling more time for mission-related tasks, provide situational awareness, and support management of
USCYBERCOM IT infrastructure.
2.2 Operational policies and constraints
USCYBERCOM is a joint command with representatives from all branches of the military, as well as, civilian staff. The following policies guide the content of this document:
DoD Directive 8115.01, “Information Technology Portfolio Management,” October 10, DoD Directive 8000.01, “Management of the Department of Defense Information
Enterprise,” February 10, 2009
Office of the Deputy Chief Management Officer Website, http://dcmo.defense.gov
DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended
DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information
Technology(IT),” March 12, 2014, Incorporating change 1, Effective May 24, 2016
DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,” January 7, DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007
DoD Manual 5200.01 – Volume 1, “DoD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012
Section 552a of Title 5, United States Code, (also known as “The Privacy Act of 1974,” as amended)
DoD 5400.11, “Department of Defense Privacy Program,” October 29, 2014
DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014
2.3 Current System Description
No integrated ITSM solution currently exists in USCYBERCOM. Currently, the command utilizes a disparate set of tools, processes, and procedures to perform the functions associated with each process area or not at all. Many of those processes and procedures are manually intensive (i.e. tracking assets via MS Excel spreadsheets) in nature and were developed under a narrow scope. The current practices lack the benefits of tools developed using a system of systems view where a common platform facilitates and enables information sharing across the process areas.
2.4 User Classes and affected personnel
User roles identified in Table 1 are currently performed by multiple personnel across one, more, or all of the USCYBERCOM Directorates. Titles associated with individuals performing these roles may vary across the command. Personnel performing these roles utilize isolated sets of tools, processes and procedures. Additional resources will be required to support these roles as the Command grows and becomes less dependent on external organizations for infrastructure, people, and processes. However, the need for additional resource can offset to a degree through realization of efficiencies gained from implementing a fully integrated enterprise-wide ITSM solution.
User Role Responsibilities
Asset Manager Manage USCYBERCOM assets and inventory records
License Manager Manage and audit USCYBERCOM software licenses
Configuration
Manager
Define and maintain a configuration management database for
USCYBERCOM IT infrastructure
Project Manager Plan, organize, and manage projects, tasks, and resources associated with USCYBERCOM capability requirements
Service Level
Manager
Ensure that a guaranteed level of service is provided for all
USCYBERCOM IT services
Release Manager Plan, build, and coordinate the release of new and improved
USCYBERCOM capabilities, services, and products
Incident Manager Manage USCYBERCOM service disruptions and restore to normal operations
Change Manager Minimize risk by controlling change to USCYBERCOM baselines
Problem Manager Perform root cause analysis to identify underlying cause of recurring incidents
Knowledge Manager Gather, store, and share knowledge across USCYBERCOM
Service Desk Provide basic service desk functions and provide a means for
USCYBERCOM to request IT services
Table 1-Roles and Responsibilities
2.5 Support Environment
Currently, in the absence of a fully integrated ITSM solution, the tools used to perform the functions associated with each of the defined roles are wide-ranging and are supported across many of the directorates, primarily CDG, J2, J3, and J6. Additionally, formally established training, user manuals, or standard operating procedures do not currently exist for many of the functions performed but will be developed for ITSM capabilities to be implemented.
3 ANALYSIS AND JUSTIFICATION OF THE PROPOSED SYSTEM
3.1 Summary of Advantages and Improvements
The new system will provide a centralized management location to maintain an audit ready posture of all IT assets within USCYBERCOM, as well as, manage and operate its infrastructure.
Once implemented, ServiceNow will help reduce administrative overhead for IT Service
Management enabling a more mission-focused workforce. Based on the evaluation criteria defined in Gartner’s analysis, ServiceNow was identified as a leader amongst ITSM tool providers alongside BMC. The application was successfully implemented at NSA, IC ITE, INTELINK, USCENTCOM, and Eagle Alliance to support mission efforts.
The ServiceNow platform is one of the few ITSM solutions on the market to receive the
FEDRamp certification from the U.S Government, which provides federal agencies with heightened confidence in moving to the Cloud for ITSM. This certification also ensures the tool meets the risk management specifications and security measures required for Government
Systems. The ServiceNow ITSM suite of tools is compliant with the ISO/IEC 20000 standard and conforms to ITIL Framework best practices. The total cost of ownership is reduced leveraging all the capabilities of the ServiceNow suite, such as generic workflow/task management processes for J1 in addition to the ITSM processes.
The implementation of the underlying service management technology provides technical benefits to USCYBERCOM. These technical benefits are comprised of the following:
1. Reduction in the overall time to implement solutions:
a. Built upon common work management platform. Implementation focused on configuration of specific business processes and not underlying enabling capabilities.
b. Reuse of business processes. Business processes can call other business processes. When a business process crosses an organizational boundary, if the called business process already implemented within the tool, does not need to be re-developed.
c. Reuse of interface applications, i.e. NSA has already integrated with PKI. The application selected should reuse the same integration across multiple applications if built upon the same work management platform.
2. Single work management platform available for implementation across all
USCYBERCOM.2
3. Increase in number of internal technical staff capabilities with implementation of standardized work management platform.
4. Increased availability of commercially available technical staff if COTS product procured.
5. Authority to Operate: reduced time to obtain with the standardization of an underlying work management platform. Similar to SharePoint, ATO only required for initial implementation. Additional implementations are configurations of existing system and not installation of new system, thus no additional ATO is required.
2 This is a recommendation from MITRE “Knowledge Management/Content Management” study of December
2016. See Mr. Paul Guevin (paul.guevin@cybercom.mil) for copy of this study and recommendation.
mailto:paul.guevin@cybercom.mil
6. Reduction in system maintenance: if COTS product selected, vendor provides regular maintenance updates to address identified deficiencies within product.
3.2 Summary of disadvantages and limitations
As ServiceNow is a COTS solution, the command will be limited to the amount of flexibility and control it has over the system. The tool known for its customizable features will still have limitations compared to if the command was to build its own solution. The various modules inside the ServiceNow solution allow for a wide range of customization and comply with the industry standard ITIL Framework. The platform has a slight learning curve requiring some training for all administrators and user of the system.
3.3 Alternatives and trade-offs considered
J64 leveraged access to Gartner’s “Magic Quadrant” to help facilitate the evaluation of available tools and ensure all known suitable options were considered during the assessment. The Magic
Quadrant consists of market research reports containing qualitative analyses conducted by the
Gartner research and advisory firm. According to Gartner’s Magic Quadrant for IT Service
Management Tools, 24 August 2016, more than 450 vendors offer ITSM products, but the majority are basic tools focusing on IT Service Desk and ticketing functions. Advanced ITSM tools have a full range of ITSM capabilities integrated with advanced third-party IT Operations
Managements solutions. The evaluation of the available ITSM tools was based on the following criteria: ability to execute the product/service, overall viability, sales execution/pricing, market responsiveness/record, marketing execution, customer experience, and operation.
In addition to the criteria used in the analyses provided by Gartner, consideration was also given to ITSM tool compliance with the ISO/IEC 20000 standard and conformity to ITIL Framework best practices.
ISO/IEC 20000 promotes the adoption of an integrated process approach effectively delivering managed services. Requirements for a management system include policies and a framework to enable the effective management and implementation of all IT Services. It specifies a number of closely related service management processes, as shown in Figure 1, ISO/IEC 20000-1 First edition 2005-12-15.
Figure 1 - Service Management Processes
The ITIL Framework in Figure 2 is a framework to enable the effective management and implementation of all IT Services and provides guidance to service providers on the provision of quality IT services, and on the processes, functions and other capabilities needed to support them as identified in ISO/IEC 20000 Service Management Processes.
Figure 2 - ITIL Framework
Lastly, HQ Operations Portfolio identified and described major alternatives considered for a system, the trade-offs among them, and rationale for the decisions reached for J1’s US Cyber
Command Human Resources Information System. During this analysis, the same solution identified for the ITSM requirement showed a significant cost savings across the Fiscal Year
Development Program.
The evaluation of the above tool was based on the following:
Relying on commercial research, online and vendor documentation and demonstrated success in NSA, NTOC, Eagle Alliance, and IC ITE.
Industry standards and frameworks
Costs--to include costs for software licenses, software maintenance, hardware implementation, lifecycle support. Consideration made the ability to use the tool for more than ITSM.
Product must meet the USCYBERCOM Business Domain and IT Infrastructure architecture demands, interacting seamlessly and with minimal risk with desktop environment.
Product easy to configure workflows with drag and drop functionality for building quick customizations. Makes good use of underlined platform to build tool functions specific to enhancing IT service support.
Analysis of Alternatives for Helpdesk Tool Suite V3, April 9, 2013 relying on commercial research, online and vendor documentation and demonstrated success in TD, TAO, EA and IAD environments, several products were evaluated for functionality, cost and risk. The recommendation for a helpdesk tool was ServiceNow.
4 SYSTEM CONCEPT
4.1 Background, objectives, and scope
USCYBERCOM plans to implement a COTS ITSM solution to utilize across the command in order to address the IT policy requirements defined within the Clinger-Cohen Act of 1996 and the DOD CIO Policy.
IT Service Management as defined by the IT industry is comprised of the following processes the Command would like to utilize:
Asset Management
Change Management
Configuration management
Incident Management
Knowledge Management
Problem Management
Release Management
Requirements Management
Service Catalog
Service Desk
Service Level Management
Based on extensive research, the ITSM definition provided above, and previous IC ITSM experiences, J64 decide to pursue ServiceNow as the COTS ITSM solution for USCYBERCOM.
4.2 Operational policies and constraints
USCYBERCOM is a joint command with representatives from all branches of the military, as well as, civilian staff. The policies of each respective military branch applies while members of each military branch stationed at USCYBERCOM. Civilian employees of USCYBERCOM follow the policies outlined by the Department of Defense Civilian Personnel Management. In addition to the policies of each military branch, the following policies guide the content of this document:
DoD Directive 8115.01, “Information Technology Portfolio Management,” October 10, DoD Directive 8000.01, “Management of the Department of Defense Information
Enterprise,” February 10, 2009
Office of the Deputy Chief Management Officer Website, http://dcmo.defense.gov
DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended
DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information
Technology(IT),” March 12, 2014, Incorporating change 1, Effective May 24, 2016
DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,” January 7, DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007
DoD Manual 5200.01 – Volume 1, “DoD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012
Section 552a of Title 5, United States Code, (also known as “The Privacy Act of 1974,” as amended)
DoD 5400.11, “Department of Defense Privacy Program,” October 29, 2014
DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014
4.3 Technical Policies & Constraints
The following technical policies have influenced the creation of this CONOPS and should shape any technical solution considered:
DoD Directive 8000-01, “Management of the Department of Defense Information
Enterprise (DoD IE)”, March 17, 2016
DoD Instruction 8500.01 “Cybersecurity,” March 14, 2014
DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information
Technology (IT),” March 12, 2014
DoD Directive 8140.01, “Cyberspace Workforce Management ,” August 11, 2015
DoD Instruction 8330.01, “Interoperability of Information Technology (IT), Including
National Security Systems (NSS),” May 21, 2014
DoD Instruction 8210.01, “Information Technology Standards in the DoD,” February 2, Section 508 Standard
Web Content Accessibility (WCAG) Guideline 2.0
4.4 Description of the new or modified system
ServiceNow is one of the leading COTS solutions for IT Service management. This solution manages and automates IT enterprise services, whether it is through change management, incident management, project portfolio management, configuration management, or resource management amongst other practices of the ITIL framework.
Network security classification portability: USCYBERCOM utilizes multiple network domains.
The work management tool should support developing a business application in one environment and then deploying in multiple network environments without requiring additional development coding or configuration efforts. See figure 3.
Figure 3– Implementation Environments with ServiceNow and Discovery Products
The features within these components include:
ServiceNow Reporting – reports of lists, charts, or calendar-based views of data in a particular table. The system offers a range of predefined reports for features like incident management and service catalog requests. If none of the predefined reports generated by
ServiceNow meet your needs, you are able to create your own.
ServiceNow Social IT – use of social media technology (such as instant messaging and microblogging) to enhance IT operations. Social IT helps improve communication throughout an organization and empowers IT and non-IT employees alike to answer IT related questions.
ServiceNow Chat – provides real-time communication through instant messaging between users in a ServiceNow instance. This provides end users the ability to access live support instantaneously.
ServiceNow Live Feed – a social IT application that provides a place to post and share content in the ServiceNow instance. This content forms a searchable knowledge source for sharing information within an organization.
ServiceNow Content Management System (CMS) – enables users to create a custom interface for the ServiceNow platform and applications. CMS generally requires a systems administrator or a web develop to set up and add features but any user can use the application as a website maintenance tool with ease.
ServiceNow Search – Find information quickly in ServiceNow by using any of the available searches. Searches are not cases sensitive and allow the use of advanced options such as wildcards or Boolean operations to generate specific queries.
ServiceNow Analytics – Enhances Event Management with alert data analysis and alert aggregation for technical services, manual services, and alert groups. It also provides root cause analysis for business services discovered by Service Mapping and for manual services.
ServiceNow Workflow – Automates mult-step processes and is used throughout the
ServiceNow system. Each workflow implemented in a ServiceNow instance has a sequence of activities, such as generating records, or notifying users of pending approvals. The transitions between these activities based on configurable conditions.
ServiceNow Integrations – Allows for integration with many third party applications and data sources. The most common integrations are with Incident Management, Problem
Management, Change Management, User Administration, and Single Sign-on.
ServiceNow Discovery – Enables you to create an accurate, up‑to‑date, single system of record for IT infrastructure, both on‑premises and in public clouds. It identifies
IP‑enabled configuration items (CIs), maps their interdependencies, and populates and maintains them in the ServiceNow Configuration Management Database (CMDB). When used with ServiceNow Service Mapping, it discovers services, too.
Process Descriptions, Flows, Roles and Responsibilities utilizing how ServiceNow automated
ITSM capabilities following the ITIL Framework:
ITSM
https://docs.servicenow.com/bundle/kingston-it-service-management/page/product/it-service-management/reference/r_ITServiceManagement.html
Software Asset Management https://docs.servicenow.com/bundle/kingston-software-asset-management/page/product/software-asset-management2/concept/software-asset-management.html
USCYBERCOM shall initiate the implementation of a command wide ITSM solution through a pilot focused on evaluating only the Asset Management and Configuration Management components in the ServiceNow and Discovery applications. This pilot will allow the command to evaluate some key features of the product and assess the tool’s value as it applies to the command. If the pilot is deemed successful and selected to be incorporated into the
USCYBERCOMMAND ITSM model, these other components will be implemented in a phased approach.
The ServiceNow Enterprise ITSM designed around the ITIL principles provides a single system of record for IT services, operations, and business management automating IT service applications and processes. All aspects of IT Service can potentially live in the ServiceNow ecosystem of modules, and thus provides a complete view of services and resources. This allows for broad control of how to best allocate resources and design the process flow of those services.
Applications will be implemented in the Cloud thus reducing infrastructure maintenance requirements. The efficiency of common IT processes is increased by adhering to ITIL principles and methods, as well as, enabling USCYBERCOM to report on performance and cost.
4.5 User Classes and affected personnel
User roles and responsibilities associated with the concept system will not change from those identified for the current situation in Section 2.4, Table 1. The concept system will allow users filling the defined roles to leverage information-sharing aspects that are inherent with the implementation of a fully integrated ITSM solution resulting in efficiencies gained across all affected process areas.
4.6 Support concept
The support of the new task management system is a cross organizational effort, requiring the expertise of multiple directorates to successfully implement.
The table below, Table 2, documents the proposed responsibilities of each directorate for supporting the development, implementation and maintenance of the task management system.
Support Task Performing Directorate(s) Description
Technical installation and maintenance of application
CDG/J6 – System
Administrators with Vendor support
Install software, apply patches and STIGS, and ensure security controls maintained per the system security plan. (Note anticipate https://docs.servicenow.com/bundle/kingston-it-service-management/page/product/it-service-management/reference/r_ITServiceManagement.html https://docs.servicenow.com/bundle/kingston-it-service-management/page/product/it-service-management/reference/r_ITServiceManagement.html https://docs.servicenow.com/bundle/kingston-software-asset-management/page/product/software-asset-management2/concept/software-asset-management.html https://docs.servicenow.com/bundle/kingston-software-asset-management/page/product/software-asset-management2/concept/software-asset-management.html https://docs.servicenow.com/bundle/kingston-software-asset-management/page/product/software-asset-management2/concept/software-asset-management.html
Support Task Performing Directorate(s) Description three (3) environments:
development, training, production). Upgrade application and underlying software as required
Monitor/Manage system performance
CDG/J6 – System
Administrators
Monitor application storage, database optimization, ensure adequate storage available.
Implementing new/changed business processes
Directorate with process area oversight
CDG/J6
Directorate is responsible for identifying the new and/or changed business processes.
CDG/J6 is responsible for working with Directorate to document changes and implement within the application.
Correcting defects within the application
Affected Directorate
CDG/J6
Directorate is responsible for confirming that identified discrepancy is a defect in the implementation. Once confirmed, the Directorate is responsible for prioritizing backlog and target implementation date for correction.
CDG/J6 will implement the correction per the prioritization and implementation of the backlog by the Directorate
End User Training/End User
Manual
Directorate with process area oversight
CDG/J6
Directorate is responsible for providing subject matter expertise relating to the business processes and their implementation within the system.
CDG/J6 is responsible for providing technical SME to answer questions related to how the system works.
Support Task Performing Directorate(s) Description
User Acceptance Testing Directorate with process area oversight
Directorate will define the criteria that will determine a successful implementation of the application as it pertains to their process area. Using the success criteria, the
Directorate will create, document and perform independent user acceptance testing of the developed application, prior to the application deployed in production environment.
Application Support System
Administrator
Training/System
Administrator Manual
CDG/J6
Vendor
CDG/J6 will be responsible for providing the system administrators with training on the maintenance of the application environment.
Additionally, the vendor does provide training tailored to system administrators.
Table 2 - Operational Support Providers
4.7 Operational scenarios
Asset Management
Control inventory purchased and used.
Reduce the cost of purchasing and managing assets.
Manage the asset life cycle from planning to disposal.
Achieve compliance with relevant standards and regulations.
Improve IT service to end users.
Change Management
Monitor and track the initiation, review, approval, and implementation of all proposed changes
Ensure standardized methods and procedures are used for efficient and prompt handling of all changes
Configuration Management
IT managed assets are identified, and controlled throughout their lifecycle working with
Change Management to ensure only authorized components are used and only authorized changes are made
Identify, control, record, report, audit and verify services and other CIs, including versions, baselines, constituent components, their attributes and relationships
Ensure integrity of CIs and configurations required to control the services by establishing and maintaining an accurate and complete Configuration Management
Database
Support efficient and effective service management processes by providing accurate configuration information for decision-making purposes.
Incident Management
Any user can create an incident within the system by default
After creating an incident alert, the incident alert administrator can process it through a set of predefined states to ensure efficient and consistent handling.
When an incident alert is resolved, the incident alert administrator can run a post incident review, and can generate a report for that review from within the incident alert.
If the cause of an incident cannot be fixed, the service desk can generate a problem from the incident. The problem evaluated through the problem management process.
If the incident creates the need for a change in IT services, the service desk can generate a change request to evaluate through the change management process.
Create a change request
Knowledge Management
Gather, analyze, store, share, use and maintain knowledge, information and data throughout the command
Maintain a Service Knowledge Management System that provides audience-appropriate and controlled access to knowledge, information, and data.
Improve the quality of decision-making by ensuring that reliable and secure knowledge, information, and data are available throughout the service life cycle.
Problem Management
An IT staff member can generate a problem manually.
An IT staff member can generate a problem from an incident.
A record producer created allows users to log problems in the service catalog.
If a user attempts to create a generic task, the task interceptor asks them to specify what type of task to create. In this way, tasks assigned a handling process.
Release Management
Release Management coordinates the planning of product and/or service releases. Once a release finalized, a change ticket generated allows the implementation and deployment of a release handled within the Change Management Process.
Requirements Management
Requirements Management is the process of documenting, analyzing, tracing, prioritizing and approving requirements and communicating to relevant stakeholders.
Once approved, new requirement is process through Change Management.
Service Catalog
Create a catalog item
Edit a catalog item
Copy a catalog item
Add a catalog item
Create item diagnostic report
Add an ordered item link
Create service catalog UI policy
Create service catalog client script
Accessibility of service to end users
Place an order for a service
Service Desk
Service Desk (SD) allows users to create a call record and quickly capture basic information from a customer contact. SD can then decide if the call is an incident, a problem, a change, or a service catalog request and appropriately handle through the right process flow to meet customer need.
Service Level Management
Service Level Managers area responsible for a set of agreements between a service provider and customer that define the scope, quality and speed of the services provided.
Service Level Management (SLM) provides the customer with an expectation of service within a known timescale and the ability to monitor when service levels not met. SLM used across the directorates to keep track of how internal and external teams are performing against their agreed service levels.
5 SUMMARY OF IMPACTS
5.1 Operational impacts
Addressing the post-deployment of the ITSM application, the operational impacts will primarily affect the resources across all of USCYBERCOM. The resources will be required to learn a new business application to receive support services from the ServiceNow tool. This automated tool will replace the current process of relying upon email to request support or manually update and track desired information. Additionally, USCYBERCOM will now be able to obtain real-time reports on either all USCYBERCOM systems or operations tracked.
5.2 Organizational impacts
Once implemented, there will be a significant impact across the USCYBERCOM community.
The procurement and implementation of a new COTS product will require each element within the USCYBERCOM receive training in the capabilities of this technology, the proper configuration and maintenance of the application as well as new application development techniques. CDG J6 will be responsible for developing and providing end-user training on the tool.
5.3 Impacts during development
The successful acquisition, installation, development and implementation of any new application requires support from a large cross section of the organization. This success will require commitment of resources to this endeavor, including supporting regular status meetings, detailed working sessions to flesh out and document the detail functionality and business rules as well supporting testing and end-user training. The periods and duration of when each type of resource will be required is mitigated through project planning. Please note the capability proposed in this document is a commercial off the shelf (COTS) solution and therefore shall require minimal development. The majority of impacts during implementation of the new application will be spent on system configuration and initial training.
6 REFERENCES
Below is a list of documents used as references to this documentation and/or can provide further detailed description of various aspects of ITSM and ServiceNow:
ITSM Pilot documentation such as ITSM Pilot Plan, Project charter, addendum, ConOps
Kickoff, CRIB RDP, COTS Selection, ITSM Requirements, ITSM Overview and Pilot
(https://uscybercom.sp.web.nsa.ic.gov/sites/Cybernet/j6/j64/cm/Pages/ITSMPilot.aspx
NSANET)
ServiceNow process guides (www.servicenow.com NIPR)
Gartner’s Magic Quadrant for IT Service Management Tools, 24 August 2016
Analysis of Alternatives for Helpdesk Tool Suite V. 3.0, April 9, 2013
DoD Directive 8115.01, “Information Technology Portfolio Management,” October 10, https://uscybercom.sp.web.nsa.ic.gov/sites/Cybernet/j6/j64/cm/Pages/ITSMPilot.aspx http://www.servicenow.com/
DoD Directive 8000.01, “Management of the Department of Defense Information
Enterprise,” February 10, 2009
Office of the Deputy Chief Management Officer Website, http://dcmo.defense.gov
DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended
DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information
Technology(IT),” March 12, 2014, Incorporating change 1, Effective May 24, 2016
DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,” January 7, DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007
DoD Manual 5200.01 – Volume 1, “DoD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012
Section 552a of Title 5, United States Code, (also known as “The Privacy Act of 1974,” as amended)
DoD 5400.11, “Department of Defense Privacy Program,” October 29, 2014
DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014
DoD Directive 8000-01, “Management of the Department of Defense Information
Enterprise (DoD IE)”, March 17, 2016
DoD Instruction 8500.01 “Cybersecurity,” March 14, 2014
DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information
Technology (IT),” March 12, 2014
DoD Directive 8140.01, “Cyberspace Workforce Management ,” August 11, 2015
DoD Instruction 8330.01, “Interoperability of Information Technology (IT), Including
National Security Systems (NSS),” May 21, 2014
DoD Instruction 8210.01, “Information Technology Standards in the DoD,” February 2, Section 508 Standard
Web Content Accessibility (WCAG) Guideline 2.0
DoD Directive 8115.01, “Information Technology Portfolio Management,” October 10, DoD Directive 8000.01, “Management of the Department of Defense Information
Enterprise,” February 10, 2009
Office of the Deputy Chief Management Officer Website, http://dcmo.defense.gov
DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended
DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information
Technology(IT),” March 12, 2014, Incorporating change 1, Effective May 24, 2016 http://dcmo.defense.gov/
DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,” January 7, DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007
DoD Manual 5200.01 – Volume 1, “DoD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012
Section 552a of Title 5, United States Code, (also known as “The Privacy Act of 1974,” as amended)
DoD 5400.11, “Department of Defense Privacy Program,” October 29, 2014
DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014
7 APPENDICES
7.1 Appendix A: Acronyms
Acronym Full Name
ATO Authority to Operate
CDG Capabilities Development Group
CI Controlled Interface
CIO Chief Information Officer
CONOPS Concept of Operations
COTS Commercial Off the Shelf
DISA Defense Information Systems Agency
DoD Department of Defense
EA Eagle Alliance
IAD Information Assurance Directorate
IEC International Electrotechnical Commission
ISO International Organization for Standardization
IT Information Technology
ITIL Information Technology Infrastructure Library
ITOM Information Technology Operations Management
ITSM Information Technology Service Management
MS Microsoft
NIPRNet Nonsecure Internet Protocol Router Network
NSA National Security Agency
NTOC National Threat Operations Center
RDP Remote Desktop Protocol
RMF Risk Management Framework
SD Service Desk
SLM Service Level Management
SME Subject Matter Expert
STIGS Security Technical Implementation Guides
TAO Tailored Access Operations
TD Technology Directorate
UI User Interface
USCYBERCOM United States Cyber Command Table 3 - Acronym Appendix
File details come from the government source that posted it. Updated .