Asset_Config_Management_Conops_Final.pdf

PDF 1022 KB Posted

Attached to
ServiceNow Federal contract opportunity
Solicitation number
HB0001-18-R-0012
Issued by
Department of Defense Cyber Command

About this file

Asset Config Management Conops Final

View the file

Other files for this federal contract opportunity

Other files attached to ServiceNow, newest first.
File Type Posted
HB0001-18-R-0012-P0002.pdf PDF
ServiceNow_RFP_Questions_V2.docx DOCX document
HB0001-18-R-0012-P0001.pdf PDF
RFP_Questions.pdf PDF
Religious_Mission_Trip_February_2015.pdf PDF
CS_050515_eform.pdf PDF
HB000118R0012.pdf PDF
SF312.pdf PDF
SSO_Toolkit_SOW_final.pdf PDF
SCI_ATTESTATION.pdf PDF
Questionaire_Response_Attachment_20180119.pdf PDF
ServiceNow_SOW_General_Provisions_final.pdf PDF
HR_Toolkit_Conops__Task_Management.pdf PDF
SCI_Pre_Screen_Questionaire_DEC_2017.pdf PDF
SCI_Reporting_Memo.pdf PDF
HR_Toolkit_Process_Flows_Final.pdf PDF
HR_Toolkit_SOW_FINAL.pdf PDF
Asset_Config_Management_SOW_Final.pdf PDF
10-SIP_Instructions.pdf PDF
ACS_050515_eform.pdf PDF
J6_forms.pdf PDF
SIP_050515_eform.pdf PDF
SSO_Toolkit_CONOPS_final.pdf PDF
Language_Immersion_Trip_February_2015.pdf PDF
Foreign_Travel_Questionnaire.pdf PDF
US_Cyber_Command_Pre_Screen_Notice_20180308.pdf PDF
FY18_Software_Order.pdf PDF
Source_Selection_Plan_-_Service_Now.pdf PDF
FORM_4414_Rev_12-2013_fillable_(Savable).pdf PDF
Show all 29

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CONCEPT OF OPERATIONS

FOR

IT Service Management

Version 0.2.5

21 March 2018

Requirement Sponsor/Org: J64

RMS #: RSF-098-17-616

Revision History

Version Date of

Change Changes Made

Name of Person/Office

Entering Change

0.1 03/28/2017 Initial Draft Initiation A. Hatfield

0.1.1 04/14/2017 Review and Polish N. Centafont/ E. Veeck

0.1.2 04/21/2017 Second Draft Initiation A. Hatfield

0.1.3 04/24/2017 Updated Section 2.4, 2.5, and 4.5 E. Veeck

0.1.4 04/24/2017 Added content under Knowledge

Management and Configuration

Management

N. Centafont

0.1.5 04/25/2017 Updated Section 2.2, 4.2, 4.3, E. Veeck

0.1.6 04/25/2017 Updated Tables and Section 5.1, 5.2, 5.3, and 6

A. Hatfield

0.1.7 04/25/2017 Updated Section 4.7 N. Centafont

0.1.8 04/26/2017 Reviewed and commented E. Wojciechowski

0.2.1 5/3/2017 Updated Section 3.1 and fixed feedback

A. Hatfield

0.2.2 5/9/2017 Updated Section 3.1 and 3.3 N. Centafont

0.2.3 5/25/2017 Revised based from feedback N. Centafont

0.2.4 5/25/2017 Added Signature Blocks/Altered formatting

A. Hatfield

0.25 3/20/2108 Added OV-1, ServiceNow

Process Diagram links; and high-level integrated process diagram

N. Centafont/E. Veeck/C.

Bowman

TABLE OF CONTENTS

1 SCOPE

1.1 System Overview and Identification

1.2 Security Considerations

1.3 System security

2 CURRENT SYSTEM AND STATE

2.1 Background, objectives, and scope

2.2 Operational policies and constraints

2.3 Current System Description

2.4 User Classes and affected personnel

2.5 Support Environment

3 ANALYSIS AND JUSTIFICATION OF THE PROPOSED SYSTEM

3.1 Summary of Advantages and Improvements

3.2 Summary of disadvantages and limitations

3.3 Alternatives and trade-offs considered

4 SYSTEM CONCEPT

4.1 Background, objectives, and scope

4.2 Operational policies and constraints

4.3 Technical Policies & Constraints

4.4 Description of the new or modified system

4.5 User Classes and affected personnel

4.6 Support concept

4.7 Operational scenarios

5 SUMMARY OF IMPACTS

5.1 Operational impacts

5.2 Organizational impacts

5.3 Impacts during development

6 REFERENCES

7 APPENDICES

7.1 Appendix A: Acronyms

INDEX OF FIGURES

Figure 1 - Service Management Processes Figure 2 - ITIL Framework

Figure 3– Implementation Environments with ServiceNow and Discovery Products

INDEX OF TABLES

Table 1-Roles and Responsibilities Table 2 - Operational Support Providers Table 3 - Acronym Appendix

1 SCOPE

1.1 System Overview and Identification

As USCYBERCOM continues to support the Cyber Mission Forces and Cryptologic Centers, the supporting information technology (IT) infrastructure continues to grow in complexity in terms of hardware and software deployed as well as the number of differing configurations associated with these components of the IT infrastructure. As part of the Clinger-Cohen Act of 1996, and the Department of Defense (DoD) Chief Information Officer (CIO) Policy1, the CIO is required to establish IT policies for managing the IT enterprise environment as well as tracking all IT assets within the organization. In order to meet these objectives, the commercial market provides a wide range of robust IT Service Management (ITSM) products providing management oversight, situational awareness, and structured change management processes for the IT operational environment, as well as, tracking all assets. The objective of this CONOPS is to justify an investment in an integrated commercial-off-the-shelf (COTS) ITSM solution so that

USCYBERCOM may leverage the solution to meet DoD and CIO requirements.

1.2 Security Considerations

This document is unclassified and for the use of official government business in accordance with records management policies and/or regulations.

1.3 System security

As an IT Service Management tool for USCYBERCOM, all security controls for the proposed system will be consistent with the Risk Management Framework (RMF) rating assigned by CDG

J65 Information Assurance Manager once the system is assessed.

In addition to complying with the RMF, the system will be required to comply with the Security

Technical Implementation Guides (STIGS) issued by the Defense Information Systems Agency

(DISA) as well as, vendor patches for both the application itself and any of the supporting prerequisite applications.

Single SignOn required utilizing either CAC or PKI enabled credentials in Unclassified, Secret and Top Secret domains.

2 CURRENT SYSTEM AND STATE

2.1 Background, objectives, and scope

No singular system currently exists for IT Service Management (ITSM) in USCYBERCOM.

Presently, Atlassian’s product suite, JIRA, provides Service Desk functionality along with Eagle

Alliance’s implementation of ServiceNow. No system at USCYBERCOM encompasses all

ITSM processes to include Asset Management, Change Management, Configuration

Management, Incident Management, Knowledge Management, Problem Management, Release

Management, Requirements Management, Service Catalog, Service Desk and Service Level

1 Department of Defense Directive 8000.01 March 17, 2016, Management of the Department of Defense

Information Enterprise (DoD IE).

Management. USCYBERCOM selected ServiceNow as the commercial off the shelf (COTS) product for meeting these requirements. The ServiceNow application suite, successfully implemented at NSA, will reduce resource requirements and administrative overhead enabling more time for mission-related tasks, provide situational awareness, and support management of

USCYBERCOM IT infrastructure.

2.2 Operational policies and constraints

USCYBERCOM is a joint command with representatives from all branches of the military, as well as, civilian staff. The following policies guide the content of this document:

DoD Directive 8115.01, “Information Technology Portfolio Management,” October 10, DoD Directive 8000.01, “Management of the Department of Defense Information

Enterprise,” February 10, 2009

Office of the Deputy Chief Management Officer Website, http://dcmo.defense.gov

DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended

DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information

Technology(IT),” March 12, 2014, Incorporating change 1, Effective May 24, 2016

DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,” January 7, DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007

DoD Manual 5200.01 – Volume 1, “DoD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012

Section 552a of Title 5, United States Code, (also known as “The Privacy Act of 1974,” as amended)

DoD 5400.11, “Department of Defense Privacy Program,” October 29, 2014

DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014

2.3 Current System Description

No integrated ITSM solution currently exists in USCYBERCOM. Currently, the command utilizes a disparate set of tools, processes, and procedures to perform the functions associated with each process area or not at all. Many of those processes and procedures are manually intensive (i.e. tracking assets via MS Excel spreadsheets) in nature and were developed under a narrow scope. The current practices lack the benefits of tools developed using a system of systems view where a common platform facilitates and enables information sharing across the process areas.

2.4 User Classes and affected personnel

User roles identified in Table 1 are currently performed by multiple personnel across one, more, or all of the USCYBERCOM Directorates. Titles associated with individuals performing these roles may vary across the command. Personnel performing these roles utilize isolated sets of tools, processes and procedures. Additional resources will be required to support these roles as the Command grows and becomes less dependent on external organizations for infrastructure, people, and processes. However, the need for additional resource can offset to a degree through realization of efficiencies gained from implementing a fully integrated enterprise-wide ITSM solution.

User Role Responsibilities

Asset Manager Manage USCYBERCOM assets and inventory records

License Manager Manage and audit USCYBERCOM software licenses

Configuration

Manager

Define and maintain a configuration management database for

USCYBERCOM IT infrastructure

Project Manager Plan, organize, and manage projects, tasks, and resources associated with USCYBERCOM capability requirements

Service Level

Manager

Ensure that a guaranteed level of service is provided for all

USCYBERCOM IT services

Release Manager Plan, build, and coordinate the release of new and improved

USCYBERCOM capabilities, services, and products

Incident Manager Manage USCYBERCOM service disruptions and restore to normal operations

Change Manager Minimize risk by controlling change to USCYBERCOM baselines

Problem Manager Perform root cause analysis to identify underlying cause of recurring incidents

Knowledge Manager Gather, store, and share knowledge across USCYBERCOM

Service Desk Provide basic service desk functions and provide a means for

USCYBERCOM to request IT services

Table 1-Roles and Responsibilities

2.5 Support Environment

Currently, in the absence of a fully integrated ITSM solution, the tools used to perform the functions associated with each of the defined roles are wide-ranging and are supported across many of the directorates, primarily CDG, J2, J3, and J6. Additionally, formally established training, user manuals, or standard operating procedures do not currently exist for many of the functions performed but will be developed for ITSM capabilities to be implemented.

3 ANALYSIS AND JUSTIFICATION OF THE PROPOSED SYSTEM

3.1 Summary of Advantages and Improvements

The new system will provide a centralized management location to maintain an audit ready posture of all IT assets within USCYBERCOM, as well as, manage and operate its infrastructure.

Once implemented, ServiceNow will help reduce administrative overhead for IT Service

Management enabling a more mission-focused workforce. Based on the evaluation criteria defined in Gartner’s analysis, ServiceNow was identified as a leader amongst ITSM tool providers alongside BMC. The application was successfully implemented at NSA, IC ITE, INTELINK, USCENTCOM, and Eagle Alliance to support mission efforts.

The ServiceNow platform is one of the few ITSM solutions on the market to receive the

FEDRamp certification from the U.S Government, which provides federal agencies with heightened confidence in moving to the Cloud for ITSM. This certification also ensures the tool meets the risk management specifications and security measures required for Government

Systems. The ServiceNow ITSM suite of tools is compliant with the ISO/IEC 20000 standard and conforms to ITIL Framework best practices. The total cost of ownership is reduced leveraging all the capabilities of the ServiceNow suite, such as generic workflow/task management processes for J1 in addition to the ITSM processes.

The implementation of the underlying service management technology provides technical benefits to USCYBERCOM. These technical benefits are comprised of the following:

1. Reduction in the overall time to implement solutions:

a. Built upon common work management platform. Implementation focused on configuration of specific business processes and not underlying enabling capabilities.

b. Reuse of business processes. Business processes can call other business processes. When a business process crosses an organizational boundary, if the called business process already implemented within the tool, does not need to be re-developed.

c. Reuse of interface applications, i.e. NSA has already integrated with PKI. The application selected should reuse the same integration across multiple applications if built upon the same work management platform.

2. Single work management platform available for implementation across all

USCYBERCOM.2

3. Increase in number of internal technical staff capabilities with implementation of standardized work management platform.

4. Increased availability of commercially available technical staff if COTS product procured.

5. Authority to Operate: reduced time to obtain with the standardization of an underlying work management platform. Similar to SharePoint, ATO only required for initial implementation. Additional implementations are configurations of existing system and not installation of new system, thus no additional ATO is required.

2 This is a recommendation from MITRE “Knowledge Management/Content Management” study of December

2016. See Mr. Paul Guevin (paul.guevin@cybercom.mil) for copy of this study and recommendation.

mailto:paul.guevin@cybercom.mil

6. Reduction in system maintenance: if COTS product selected, vendor provides regular maintenance updates to address identified deficiencies within product.

3.2 Summary of disadvantages and limitations

As ServiceNow is a COTS solution, the command will be limited to the amount of flexibility and control it has over the system. The tool known for its customizable features will still have limitations compared to if the command was to build its own solution. The various modules inside the ServiceNow solution allow for a wide range of customization and comply with the industry standard ITIL Framework. The platform has a slight learning curve requiring some training for all administrators and user of the system.

3.3 Alternatives and trade-offs considered

J64 leveraged access to Gartner’s “Magic Quadrant” to help facilitate the evaluation of available tools and ensure all known suitable options were considered during the assessment. The Magic

Quadrant consists of market research reports containing qualitative analyses conducted by the

Gartner research and advisory firm. According to Gartner’s Magic Quadrant for IT Service

Management Tools, 24 August 2016, more than 450 vendors offer ITSM products, but the majority are basic tools focusing on IT Service Desk and ticketing functions. Advanced ITSM tools have a full range of ITSM capabilities integrated with advanced third-party IT Operations

Managements solutions. The evaluation of the available ITSM tools was based on the following criteria: ability to execute the product/service, overall viability, sales execution/pricing, market responsiveness/record, marketing execution, customer experience, and operation.

In addition to the criteria used in the analyses provided by Gartner, consideration was also given to ITSM tool compliance with the ISO/IEC 20000 standard and conformity to ITIL Framework best practices.

ISO/IEC 20000 promotes the adoption of an integrated process approach effectively delivering managed services. Requirements for a management system include policies and a framework to enable the effective management and implementation of all IT Services. It specifies a number of closely related service management processes, as shown in Figure 1, ISO/IEC 20000-1 First edition 2005-12-15.

Figure 1 - Service Management Processes

The ITIL Framework in Figure 2 is a framework to enable the effective management and implementation of all IT Services and provides guidance to service providers on the provision of quality IT services, and on the processes, functions and other capabilities needed to support them as identified in ISO/IEC 20000 Service Management Processes.

Figure 2 - ITIL Framework

Lastly, HQ Operations Portfolio identified and described major alternatives considered for a system, the trade-offs among them, and rationale for the decisions reached for J1’s US Cyber

Command Human Resources Information System. During this analysis, the same solution identified for the ITSM requirement showed a significant cost savings across the Fiscal Year

Development Program.

The evaluation of the above tool was based on the following:

Relying on commercial research, online and vendor documentation and demonstrated success in NSA, NTOC, Eagle Alliance, and IC ITE.

Industry standards and frameworks

Costs--to include costs for software licenses, software maintenance, hardware implementation, lifecycle support. Consideration made the ability to use the tool for more than ITSM.

Product must meet the USCYBERCOM Business Domain and IT Infrastructure architecture demands, interacting seamlessly and with minimal risk with desktop environment.

Product easy to configure workflows with drag and drop functionality for building quick customizations. Makes good use of underlined platform to build tool functions specific to enhancing IT service support.

Analysis of Alternatives for Helpdesk Tool Suite V3, April 9, 2013 relying on commercial research, online and vendor documentation and demonstrated success in TD, TAO, EA and IAD environments, several products were evaluated for functionality, cost and risk. The recommendation for a helpdesk tool was ServiceNow.

4 SYSTEM CONCEPT

4.1 Background, objectives, and scope

USCYBERCOM plans to implement a COTS ITSM solution to utilize across the command in order to address the IT policy requirements defined within the Clinger-Cohen Act of 1996 and the DOD CIO Policy.

IT Service Management as defined by the IT industry is comprised of the following processes the Command would like to utilize:

Asset Management

Change Management

Configuration management

Incident Management

Knowledge Management

Problem Management

Release Management

Requirements Management

Service Catalog

Service Desk

Service Level Management

Based on extensive research, the ITSM definition provided above, and previous IC ITSM experiences, J64 decide to pursue ServiceNow as the COTS ITSM solution for USCYBERCOM.

4.2 Operational policies and constraints

USCYBERCOM is a joint command with representatives from all branches of the military, as well as, civilian staff. The policies of each respective military branch applies while members of each military branch stationed at USCYBERCOM. Civilian employees of USCYBERCOM follow the policies outlined by the Department of Defense Civilian Personnel Management. In addition to the policies of each military branch, the following policies guide the content of this document:

DoD Directive 8115.01, “Information Technology Portfolio Management,” October 10, DoD Directive 8000.01, “Management of the Department of Defense Information

Enterprise,” February 10, 2009

Office of the Deputy Chief Management Officer Website, http://dcmo.defense.gov

DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended

DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information

Technology(IT),” March 12, 2014, Incorporating change 1, Effective May 24, 2016

DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,” January 7, DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007

DoD Manual 5200.01 – Volume 1, “DoD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012

Section 552a of Title 5, United States Code, (also known as “The Privacy Act of 1974,” as amended)

DoD 5400.11, “Department of Defense Privacy Program,” October 29, 2014

DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014

4.3 Technical Policies & Constraints

The following technical policies have influenced the creation of this CONOPS and should shape any technical solution considered:

DoD Directive 8000-01, “Management of the Department of Defense Information

Enterprise (DoD IE)”, March 17, 2016

DoD Instruction 8500.01 “Cybersecurity,” March 14, 2014

DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information

Technology (IT),” March 12, 2014

DoD Directive 8140.01, “Cyberspace Workforce Management ,” August 11, 2015

DoD Instruction 8330.01, “Interoperability of Information Technology (IT), Including

National Security Systems (NSS),” May 21, 2014

DoD Instruction 8210.01, “Information Technology Standards in the DoD,” February 2, Section 508 Standard

Web Content Accessibility (WCAG) Guideline 2.0

4.4 Description of the new or modified system

ServiceNow is one of the leading COTS solutions for IT Service management. This solution manages and automates IT enterprise services, whether it is through change management, incident management, project portfolio management, configuration management, or resource management amongst other practices of the ITIL framework.

Network security classification portability: USCYBERCOM utilizes multiple network domains.

The work management tool should support developing a business application in one environment and then deploying in multiple network environments without requiring additional development coding or configuration efforts. See figure 3.

Figure 3– Implementation Environments with ServiceNow and Discovery Products

The features within these components include:

ServiceNow Reporting – reports of lists, charts, or calendar-based views of data in a particular table. The system offers a range of predefined reports for features like incident management and service catalog requests. If none of the predefined reports generated by

ServiceNow meet your needs, you are able to create your own.

ServiceNow Social IT – use of social media technology (such as instant messaging and microblogging) to enhance IT operations. Social IT helps improve communication throughout an organization and empowers IT and non-IT employees alike to answer IT related questions.

ServiceNow Chat – provides real-time communication through instant messaging between users in a ServiceNow instance. This provides end users the ability to access live support instantaneously.

ServiceNow Live Feed – a social IT application that provides a place to post and share content in the ServiceNow instance. This content forms a searchable knowledge source for sharing information within an organization.

ServiceNow Content Management System (CMS) – enables users to create a custom interface for the ServiceNow platform and applications. CMS generally requires a systems administrator or a web develop to set up and add features but any user can use the application as a website maintenance tool with ease.

ServiceNow Search – Find information quickly in ServiceNow by using any of the available searches. Searches are not cases sensitive and allow the use of advanced options such as wildcards or Boolean operations to generate specific queries.

ServiceNow Analytics – Enhances Event Management with alert data analysis and alert aggregation for technical services, manual services, and alert groups. It also provides root cause analysis for business services discovered by Service Mapping and for manual services.

ServiceNow Workflow – Automates mult-step processes and is used throughout the

ServiceNow system. Each workflow implemented in a ServiceNow instance has a sequence of activities, such as generating records, or notifying users of pending approvals. The transitions between these activities based on configurable conditions.

ServiceNow Integrations – Allows for integration with many third party applications and data sources. The most common integrations are with Incident Management, Problem

Management, Change Management, User Administration, and Single Sign-on.

ServiceNow Discovery – Enables you to create an accurate, up‑to‑date, single system of record for IT infrastructure, both on‑premises and in public clouds. It identifies

IP‑enabled configuration items (CIs), maps their interdependencies, and populates and maintains them in the ServiceNow Configuration Management Database (CMDB). When used with ServiceNow Service Mapping, it discovers services, too.

Process Descriptions, Flows, Roles and Responsibilities utilizing how ServiceNow automated

ITSM capabilities following the ITIL Framework:

ITSM

https://docs.servicenow.com/bundle/kingston-it-service-management/page/product/it-service-management/reference/r_ITServiceManagement.html

Software Asset Management https://docs.servicenow.com/bundle/kingston-software-asset-management/page/product/software-asset-management2/concept/software-asset-management.html

USCYBERCOM shall initiate the implementation of a command wide ITSM solution through a pilot focused on evaluating only the Asset Management and Configuration Management components in the ServiceNow and Discovery applications. This pilot will allow the command to evaluate some key features of the product and assess the tool’s value as it applies to the command. If the pilot is deemed successful and selected to be incorporated into the

USCYBERCOMMAND ITSM model, these other components will be implemented in a phased approach.

The ServiceNow Enterprise ITSM designed around the ITIL principles provides a single system of record for IT services, operations, and business management automating IT service applications and processes. All aspects of IT Service can potentially live in the ServiceNow ecosystem of modules, and thus provides a complete view of services and resources. This allows for broad control of how to best allocate resources and design the process flow of those services.

Applications will be implemented in the Cloud thus reducing infrastructure maintenance requirements. The efficiency of common IT processes is increased by adhering to ITIL principles and methods, as well as, enabling USCYBERCOM to report on performance and cost.

4.5 User Classes and affected personnel

User roles and responsibilities associated with the concept system will not change from those identified for the current situation in Section 2.4, Table 1. The concept system will allow users filling the defined roles to leverage information-sharing aspects that are inherent with the implementation of a fully integrated ITSM solution resulting in efficiencies gained across all affected process areas.

4.6 Support concept

The support of the new task management system is a cross organizational effort, requiring the expertise of multiple directorates to successfully implement.

The table below, Table 2, documents the proposed responsibilities of each directorate for supporting the development, implementation and maintenance of the task management system.

Support Task Performing Directorate(s) Description

Technical installation and maintenance of application

CDG/J6 – System

Administrators with Vendor support

Install software, apply patches and STIGS, and ensure security controls maintained per the system security plan. (Note anticipate https://docs.servicenow.com/bundle/kingston-it-service-management/page/product/it-service-management/reference/r_ITServiceManagement.html https://docs.servicenow.com/bundle/kingston-it-service-management/page/product/it-service-management/reference/r_ITServiceManagement.html https://docs.servicenow.com/bundle/kingston-software-asset-management/page/product/software-asset-management2/concept/software-asset-management.html https://docs.servicenow.com/bundle/kingston-software-asset-management/page/product/software-asset-management2/concept/software-asset-management.html https://docs.servicenow.com/bundle/kingston-software-asset-management/page/product/software-asset-management2/concept/software-asset-management.html

Support Task Performing Directorate(s) Description three (3) environments:

development, training, production). Upgrade application and underlying software as required

Monitor/Manage system performance

CDG/J6 – System

Administrators

Monitor application storage, database optimization, ensure adequate storage available.

Implementing new/changed business processes

Directorate with process area oversight

CDG/J6

Directorate is responsible for identifying the new and/or changed business processes.

CDG/J6 is responsible for working with Directorate to document changes and implement within the application.

Correcting defects within the application

Affected Directorate

CDG/J6

Directorate is responsible for confirming that identified discrepancy is a defect in the implementation. Once confirmed, the Directorate is responsible for prioritizing backlog and target implementation date for correction.

CDG/J6 will implement the correction per the prioritization and implementation of the backlog by the Directorate

End User Training/End User

Manual

Directorate with process area oversight

CDG/J6

Directorate is responsible for providing subject matter expertise relating to the business processes and their implementation within the system.

CDG/J6 is responsible for providing technical SME to answer questions related to how the system works.

Support Task Performing Directorate(s) Description

User Acceptance Testing Directorate with process area oversight

Directorate will define the criteria that will determine a successful implementation of the application as it pertains to their process area. Using the success criteria, the

Directorate will create, document and perform independent user acceptance testing of the developed application, prior to the application deployed in production environment.

Application Support System

Administrator

Training/System

Administrator Manual

CDG/J6

Vendor

CDG/J6 will be responsible for providing the system administrators with training on the maintenance of the application environment.

Additionally, the vendor does provide training tailored to system administrators.

Table 2 - Operational Support Providers

4.7 Operational scenarios

Asset Management

Control inventory purchased and used.

Reduce the cost of purchasing and managing assets.

Manage the asset life cycle from planning to disposal.

Achieve compliance with relevant standards and regulations.

Improve IT service to end users.

Change Management

Monitor and track the initiation, review, approval, and implementation of all proposed changes

Ensure standardized methods and procedures are used for efficient and prompt handling of all changes

Configuration Management

IT managed assets are identified, and controlled throughout their lifecycle working with

Change Management to ensure only authorized components are used and only authorized changes are made

Identify, control, record, report, audit and verify services and other CIs, including versions, baselines, constituent components, their attributes and relationships

Ensure integrity of CIs and configurations required to control the services by establishing and maintaining an accurate and complete Configuration Management

Database

Support efficient and effective service management processes by providing accurate configuration information for decision-making purposes.

Incident Management

Any user can create an incident within the system by default

After creating an incident alert, the incident alert administrator can process it through a set of predefined states to ensure efficient and consistent handling.

When an incident alert is resolved, the incident alert administrator can run a post incident review, and can generate a report for that review from within the incident alert.

If the cause of an incident cannot be fixed, the service desk can generate a problem from the incident. The problem evaluated through the problem management process.

If the incident creates the need for a change in IT services, the service desk can generate a change request to evaluate through the change management process.

Create a change request

Knowledge Management

Gather, analyze, store, share, use and maintain knowledge, information and data throughout the command

Maintain a Service Knowledge Management System that provides audience-appropriate and controlled access to knowledge, information, and data.

Improve the quality of decision-making by ensuring that reliable and secure knowledge, information, and data are available throughout the service life cycle.

Problem Management

An IT staff member can generate a problem manually.

An IT staff member can generate a problem from an incident.

A record producer created allows users to log problems in the service catalog.

If a user attempts to create a generic task, the task interceptor asks them to specify what type of task to create. In this way, tasks assigned a handling process.

Release Management

Release Management coordinates the planning of product and/or service releases. Once a release finalized, a change ticket generated allows the implementation and deployment of a release handled within the Change Management Process.

Requirements Management

Requirements Management is the process of documenting, analyzing, tracing, prioritizing and approving requirements and communicating to relevant stakeholders.

Once approved, new requirement is process through Change Management.

Service Catalog

Create a catalog item

Edit a catalog item

Copy a catalog item

Add a catalog item

Create item diagnostic report

Add an ordered item link

Create service catalog UI policy

Create service catalog client script

Accessibility of service to end users

Place an order for a service

Service Desk

Service Desk (SD) allows users to create a call record and quickly capture basic information from a customer contact. SD can then decide if the call is an incident, a problem, a change, or a service catalog request and appropriately handle through the right process flow to meet customer need.

Service Level Management

Service Level Managers area responsible for a set of agreements between a service provider and customer that define the scope, quality and speed of the services provided.

Service Level Management (SLM) provides the customer with an expectation of service within a known timescale and the ability to monitor when service levels not met. SLM used across the directorates to keep track of how internal and external teams are performing against their agreed service levels.

5 SUMMARY OF IMPACTS

5.1 Operational impacts

Addressing the post-deployment of the ITSM application, the operational impacts will primarily affect the resources across all of USCYBERCOM. The resources will be required to learn a new business application to receive support services from the ServiceNow tool. This automated tool will replace the current process of relying upon email to request support or manually update and track desired information. Additionally, USCYBERCOM will now be able to obtain real-time reports on either all USCYBERCOM systems or operations tracked.

5.2 Organizational impacts

Once implemented, there will be a significant impact across the USCYBERCOM community.

The procurement and implementation of a new COTS product will require each element within the USCYBERCOM receive training in the capabilities of this technology, the proper configuration and maintenance of the application as well as new application development techniques. CDG J6 will be responsible for developing and providing end-user training on the tool.

5.3 Impacts during development

The successful acquisition, installation, development and implementation of any new application requires support from a large cross section of the organization. This success will require commitment of resources to this endeavor, including supporting regular status meetings, detailed working sessions to flesh out and document the detail functionality and business rules as well supporting testing and end-user training. The periods and duration of when each type of resource will be required is mitigated through project planning. Please note the capability proposed in this document is a commercial off the shelf (COTS) solution and therefore shall require minimal development. The majority of impacts during implementation of the new application will be spent on system configuration and initial training.

6 REFERENCES

Below is a list of documents used as references to this documentation and/or can provide further detailed description of various aspects of ITSM and ServiceNow:

ITSM Pilot documentation such as ITSM Pilot Plan, Project charter, addendum, ConOps

Kickoff, CRIB RDP, COTS Selection, ITSM Requirements, ITSM Overview and Pilot

(https://uscybercom.sp.web.nsa.ic.gov/sites/Cybernet/j6/j64/cm/Pages/ITSMPilot.aspx

NSANET)

ServiceNow process guides (www.servicenow.com NIPR)

Gartner’s Magic Quadrant for IT Service Management Tools, 24 August 2016

Analysis of Alternatives for Helpdesk Tool Suite V. 3.0, April 9, 2013

DoD Directive 8115.01, “Information Technology Portfolio Management,” October 10, https://uscybercom.sp.web.nsa.ic.gov/sites/Cybernet/j6/j64/cm/Pages/ITSMPilot.aspx http://www.servicenow.com/

DoD Directive 8000.01, “Management of the Department of Defense Information

Enterprise,” February 10, 2009

Office of the Deputy Chief Management Officer Website, http://dcmo.defense.gov

DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended

DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information

Technology(IT),” March 12, 2014, Incorporating change 1, Effective May 24, 2016

DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,” January 7, DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007

DoD Manual 5200.01 – Volume 1, “DoD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012

Section 552a of Title 5, United States Code, (also known as “The Privacy Act of 1974,” as amended)

DoD 5400.11, “Department of Defense Privacy Program,” October 29, 2014

DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014

DoD Directive 8000-01, “Management of the Department of Defense Information

Enterprise (DoD IE)”, March 17, 2016

DoD Instruction 8500.01 “Cybersecurity,” March 14, 2014

DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information

Technology (IT),” March 12, 2014

DoD Directive 8140.01, “Cyberspace Workforce Management ,” August 11, 2015

DoD Instruction 8330.01, “Interoperability of Information Technology (IT), Including

National Security Systems (NSS),” May 21, 2014

DoD Instruction 8210.01, “Information Technology Standards in the DoD,” February 2, Section 508 Standard

Web Content Accessibility (WCAG) Guideline 2.0

DoD Directive 8115.01, “Information Technology Portfolio Management,” October 10, DoD Directive 8000.01, “Management of the Department of Defense Information

Enterprise,” February 10, 2009

Office of the Deputy Chief Management Officer Website, http://dcmo.defense.gov

DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended

DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information

Technology(IT),” March 12, 2014, Incorporating change 1, Effective May 24, 2016 http://dcmo.defense.gov/

DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,” January 7, DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007

DoD Manual 5200.01 – Volume 1, “DoD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012

Section 552a of Title 5, United States Code, (also known as “The Privacy Act of 1974,” as amended)

DoD 5400.11, “Department of Defense Privacy Program,” October 29, 2014

DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014

7 APPENDICES

7.1 Appendix A: Acronyms

Acronym Full Name

ATO Authority to Operate

CDG Capabilities Development Group

CI Controlled Interface

CIO Chief Information Officer

CONOPS Concept of Operations

COTS Commercial Off the Shelf

DISA Defense Information Systems Agency

DoD Department of Defense

EA Eagle Alliance

IAD Information Assurance Directorate

IEC International Electrotechnical Commission

ISO International Organization for Standardization

IT Information Technology

ITIL Information Technology Infrastructure Library

ITOM Information Technology Operations Management

ITSM Information Technology Service Management

MS Microsoft

NIPRNet Nonsecure Internet Protocol Router Network

NSA National Security Agency

NTOC National Threat Operations Center

RDP Remote Desktop Protocol

RMF Risk Management Framework

SD Service Desk

SLM Service Level Management

SME Subject Matter Expert

STIGS Security Technical Implementation Guides

TAO Tailored Access Operations

TD Technology Directorate

UI User Interface

USCYBERCOM United States Cyber Command Table 3 - Acronym Appendix

File details come from the government source that posted it. Updated .