HR_Toolkit_Conops__Task_Management.pdf

PDF 1 MB Posted

Attached to
ServiceNow Federal contract opportunity
Solicitation number
HB0001-18-R-0012
Issued by
Department of Defense Cyber Command

About this file

HR Toolkit Conops Task Management

View the file

Other files for this federal contract opportunity

Other files attached to ServiceNow, newest first.
File Type Posted
HB0001-18-R-0012-P0002.pdf PDF
ServiceNow_RFP_Questions_V2.docx DOCX document
HB0001-18-R-0012-P0001.pdf PDF
RFP_Questions.pdf PDF
Religious_Mission_Trip_February_2015.pdf PDF
CS_050515_eform.pdf PDF
HB000118R0012.pdf PDF
SF312.pdf PDF
SSO_Toolkit_SOW_final.pdf PDF
SCI_ATTESTATION.pdf PDF
Questionaire_Response_Attachment_20180119.pdf PDF
ServiceNow_SOW_General_Provisions_final.pdf PDF
Asset_Config_Management_SOW_Final.pdf PDF
10-SIP_Instructions.pdf PDF
ACS_050515_eform.pdf PDF
J6_forms.pdf PDF
SIP_050515_eform.pdf PDF
SSO_Toolkit_CONOPS_final.pdf PDF
Language_Immersion_Trip_February_2015.pdf PDF
Foreign_Travel_Questionnaire.pdf PDF
US_Cyber_Command_Pre_Screen_Notice_20180308.pdf PDF
FY18_Software_Order.pdf PDF
Source_Selection_Plan_-_Service_Now.pdf PDF
FORM_4414_Rev_12-2013_fillable_(Savable).pdf PDF
Asset_Config_Management_Conops_Final.pdf PDF
SCI_Pre_Screen_Questionaire_DEC_2017.pdf PDF
SCI_Reporting_Memo.pdf PDF
HR_Toolkit_Process_Flows_Final.pdf PDF
HR_Toolkit_SOW_FINAL.pdf PDF
Show all 29

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

UNCLASSIFIED//FOR OFFICIAL USE ONLY

CONCEPT OF OPERATIONS

FOR

US Cyber Command Human Resources Information System

Version 1.0

Ms. Amy Washburn Date:

Director (acting), J1 Manpower & Personnel

CAPT Greg Czerwonka, USCG Date:

Chief, Capabilities Development Group Mission Integration Division

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 2 of 48

Record of Reviews and Changes

Change ID or CI #

Date

Reviewed

Date

Approved Comments Signature

.1 12/20/2016 Initial draft version Earl Wojciechowski

.2 12/27/2016 Revised draft Joseph Mahr, Christine Costello, Dale Campbell

.3 02/07/17 Incorporate comments from J1

Ms. A. Washburn, Maj. N. Porcher, Mr.

K. Paul, Ms. H.

Donnelly

1.0 02/14/17 Approvals from Ms.

Washburn & Captain

Czerwonka

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 3 of 48

The J1 Personnel Management Internal Tool working group was comprised of the following individuals. This team met twice a week from October through December

2016 to identify and document the accompanying processes reflected in this document.

Title First Name Last Name SID Organization

Chief Christina Bledsoe cvbleds J12

Ms. Tracey Dooley tldool3 J12

Ms. Deborah Glenn dlglenn J14

Mr. Fred Humphry fehumph J64

Mr. Ken Marsh kamars2 J64

Mr. Ken Paul kjpaul J14

Maj Natasha Porcher nporche J12

MAJ Melody Robinson mdrobi8 J13

SSG Damico Ruiz druiz J12

Mr. Amar Valentine akvalen J14

Mr. Earl Wojciechowski emwojci CDG

Capabilities Development Group (CDG) Mission Integration (MI) also acknowledges the support provided by NSA Y4D32, especially Alex Joy and Ryan Dobbyn, providing invaluable information regarding the capabilities of ServiceNow as one commercial off the shelf (COTS) product that potentially meets the capabilities identified within the

CONOPS.

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 4 of 48

TABLE OF CONTENTS

1. (U//FOUO) Executive Summary

2. (U//FOUO) CONOPS Scope

2.1. (U//FOUO) Identification

2.2. (U//FOUO) Document security

2.3. (U//FOUO) System security

3. (U//FOUO) Current system or situation

3.1. (U//FOUO) Background, objectives, and scope

3.2. (U//FOUO) Operational policies and constraints

3.3. (U//FOUO) Description of current system or situation

3.3.1. (U//FOUO) Operational environment

3.3.2. (U//FOUO) System Components

3.3.3. (U//FOUO) Interfaces to external systems or procedures

3.3.4. (U//FOUO) Capabilities

3.3.5. (U//FOUO) Performance characteristics,

3.3.6. (U//FOUO) Quality

3.3.6.1. (U//FOUO) Reliability:

3.3.6.2. (U//FOUO) Maintainability:

3.3.6.2.1. (U//FOUO) Adaptive:

3.3.6.2.2. (U//FOUO) Perfective:

3.3.6.2.3. (U//FOUO) Corrective:

3.3.6.2.4. (U//FOUO) Preventative:

3.3.6.3. (U//FOUO) Availability:

3.3.6.4. (U//FOUO) Portability:

3.3.6.4.1. (U//FOUO) Multiple operating systems support:

3.3.6.4.2. (U//FOUO) Network security classification portability:

3.3.6.5. (U//FOUO) Usability:

3.3.7. (U//FOUO) Security:

3.3.8. (U//FOUO) Privacy:

3.3.9. (U//FOUO) Continuity of Operations:

3.4. (U//FOUO) Users or affected personnel

3.5. (U//FOUO) Support concept

4. (U//FOUO) Analysis of the proposed system

4.1. (U//FOUO) Summary of advantages

4.2. (U//FOUO) Summary of disadvantages or limitations

4.3. (U//FOUO) Alternatives and trade-offs considered

5. (U//FOUO) Concept for a new or modified system

5.1. (U//FOUO) Background, objectives, and scope

5.2. (U//FOUO) Operational policies and constraints

5.3. (U//FOUO) Technical Policies & Constraints

5.4. (U//FOUO) Description of the new or modified system

5.4.1. (U//FOUO) Operational environment

5.4.2. (U//FOUO) System Components

5.4.3. (U//FOUO) Interfaces to external systems or procedures

5.4.4. (U//FOUO) Capabilities

5.4.5. (U//FOUO) Performance characteristics, 2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 5 of 48

5.4.6. (U//FOUO) Quality

5.4.6.1. (U//FOUO) Reliability:

5.4.6.2. (U//FOUO) Maintainability:

5.4.6.2.1. (U//FOUO) Adaptive:

5.4.6.2.2. (U//FOUO) Perfective:

5.4.6.2.3. (U//FOUO) Corrective:

5.4.6.2.4. (U//FOUO) Preventative:

5.4.6.3. (U//FOUO) Availability:

5.4.6.4. (U//FOUO) Portability:

5.4.6.4.1. (U//FOUO) Multiple operating systems support:

5.4.6.4.2. (U//FOUO) Network layer portability:

5.4.6.5. (U//FOUO) Usability:

5.4.6.6. (U//FOUO) Privacy:

5.4.6.7. (U//FOUO) Continuity of Operations:

5.5. (U//FOUO) Users or affected personnel

5.6. Support concept

5.7. (U//FOUO) Operational scenarios

6. (U//FOUO) Summary of impacts

6.1. (U//FOUO) Operational impacts

6.2. (U//FOUO) Organizational impacts

6.3. (U//FOUO) Impacts during development

7. (U//FOUO) Notes

8. (U//FOUO) Appendices Appendix A: Functional Fixed Block Diagrams Appendix B: Acronyms

(U//FOUO) Figure 1 J1 Organizational Interactions (U//FOUO) Figure 2 J1 System Interactions (U//FOUO) Figure 3 J1 Personnel Management Task Tool

(U//FOUO) Figure 4 Existing Role Interactions (U//FOUO) Figure 5 Task Management Notional Architecture

(U//FOUO) Figure 6 Task Management Process Flow (U//FOUO) Figure 7 Task Management System User Roles

(U//FOUO) Table 1 Personnel Action Description (U//FOUO) Table 2 System Interactions (U//FOUO) Table 3 Volume Projections (U//FOUO) Table 4 User Role & Actions

(U//FOUO) Table 5 Notional Architecture Elements (U//FOUO) Table 6 Work Management Capabilities

(U//FOUO) Table 7 Volume Projections (U//FOUO) Table 8 Task Management User Roles (U//FOUO) Table 9 Operational Support Providers (U//FOUO) Table 10 Retirement Award Scenario (U//FOUO) Table 11 Organizational Impacts

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 6 of 48

1. (U//FOUO) Executive Summary

(U//FOUO) The execution of the J1 mission is currently dependent upon a combination of manual processes, reliance upon external data processing systems as well as emails, spreadsheets and MS Word documents in the execution of its mission. These manual processes are resource intensive, time consuming, and fail to provide time-relevant and actionable reporting on the status of on-going personnel actions. These manual processes are inherently error prone due to the manual data entry, manual routing and tracking and manual data manipulation required to provide the information required by leadership.

The current tools and processes prohibit the ability to provide timely meaningful data reporting on such critical activities as hiring civilians or onboarding military members into the USCYBERCOM organization.

(U//FOUO) This CONOPS identifies the IT capabilities required by J1 to provide a generic commercial off-the-shelf (COTS) task/workflow management tool that will automate many of the J1 personnel processes. Automation of these processes will provide greater transparency to the Command’s directorates regarding staffing actions, enable trending analysis in support of process improvement and provide actionable reporting to leadership.

(U//FOUO) Additionally, the capabilities identified in the CONOPS are generic and the

IT solution can be leveraged across the enterprise to provide a single task/workflow management tool across the enterprise as identified in a recent MITRE study1.

Implementation of a standard workflow tool within the enterprise reduces time to implementation while simultaneously building a skilled resource base to provide future support utilizing COTS technology while simultaneously reducing overall operations and maintenance costs.

2. (U//FOUO) CONOPS Scope

(U//FOUO) The execution of the J1 mission is currently dependent upon a combination of manual processes, reliance upon external, non-USCYBERCOM data processing systems as well as emails, spreadsheets and MS Word documents in the execution of its mission. These manual processes are resource intensive, time consuming, and fail to provide time-relevant and actionable reporting on the status of on-going personnel actions. These manual processes are inherently error prone due to the manual data entry, manual routing and tracking and manual data manipulation required to provide the information required by leadership. The current tools and processes prohibit the ability to provide timely meaningful data reporting on such critical activities as hiring civilians or onboarding military members into the USCYBERCOM organization.

(U//FOUO) The scope of this CONOPS is to document the current J1 Human Resource business processes with the objective of automating as many of these processes as possible with a technology solution that is logistically supportable. The technology solution is intended to support the current internal USCYBERCOM J1 user community

1 “Knowledge Management/Content Management Study” December 2016. Point of Contact is Paul Guevin

III (prguevi).

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 7 of 48 and the corresponding manpower personnel representatives (MPR) and leadership within each Directorates, CDG,CMF. The solution is intended to function in a complementary capacity to existing internal and external systems (such as Fourth Estate Manpower

Tracking System (FMTS), Department of Defense Civilian Personnel System (DCPDS) and others). The optimal solution will minimize manual data entry/manual data reporting while maximizing data integrity between these other systems. Integration with these other systems, while desirable, is not critical to the success of the implementation of a technology solution for an internal tool for J1.

2.1. (U//FOUO) Identification

(U//FOUO) USCYBERCOM’s J1 utilizes Excel spreadsheets, MS Word documents and email as its primary internal tools for tracking personnel actions within USCYBERCOM.

The creation and maintenance of these spreadsheets is a very manually intensive process with J1 staff interacting with multiple external personnel systems from other agencies and services as well as obtaining updates from multiple emails with which to update information in the spreadsheets.

2.2. (U//FOUO) Document security

(U//FOUO) All information documented herein shall be classified as “Unclassified, For

Official Use Only” (U/OFUO).

2.3. (U//FOUO) System security

(U//FOUO) As a personnel tool for USCYBERCOM’s J1, it is anticipated that the proposed system will contain Personally Identifiable Information (PII). It is not anticipated that any Personal Health Information (PHI) will be stored within the system.

Recognizing that the system will contain PII as well as other sensitive personnel information (such as specific assignments held and durations, performance reviews, awards and/or decorations received, as well as other personal information) it is anticipated that the system will be categorized under the Risk Management Framework

(RMF) as an Aisle of Assurance Level 2. All security controls will have to be implemented consistent with the RMF rating assigned by CDG J65 Information

Assurance Manager once the system is designed.

(U/FOUO) In addition to complying with the RMF, the system will be required to comply with the Security Technical Implementation Guides (STIGS) issued by the

Defense Information Systems Agency (DISA) as well as vendor patches for both the application itself and any of the supporting prerequisite applications.

(U/FOUO) Further, while the envisioned system may contain PII, the envisioned system will NOT be the authoritative source of information regarding personnel records for staff

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 8 of 48 assigned to USCYBERCOM. The existing authoritative personnel systems used by elements within USCYBERCOM, such as FMTS, DCPDS and others will continue to remain as the definitive source for all personnel actions. All documentation created and/or managed by the envisioned system will be forwarded to the appropriate corresponding authoritative personnel management system for inclusion in the individual’s personnel record as documented in the process flows in the appendix.

Working information created or maintained within the task management system, will be periodically purged from the system.

3. (U//FOUO) Current system or situation

3.1. (U//FOUO) Background, objectives, and scope

(U/FOUO) The mission of J1 is: “Deliver manpower, personnel, and readiness support to U.S. Cyber Command by developing human resource management strategies and providing organizational solutions in order to enable cyberspace operations for the U.S.

and our allies.”

(U/FOUO) The corresponding vision of J1 states: “Provide the command with the highest quality manpower, personnel, and readiness support by delivering fully qualified cyber-warriors to the right place, at the right time ready to execute full-spectrum cyberspace operations for our nation!”

(U//FOUO) J1 is currently hampered in its ability to fully meet the mission and vision as stated due to a reliance upon manual tools and processes. As USCYBERCOM continues to increase staffing levels, a reliance upon manual tools and processes will adversely impact J1’s ability to manage the anticipated staffing levels. Providing J0 with timely information regarding current staffing actions, is a manually intensive process.

Additionally, the production of both regular and ad hoc reports is a staff intensive, manual effort and represents data that is aged and often not actionable.

(U//FOUO) The scope of this CONOPS is to document the current J1 manual personnel processes with the objective of automating as many of these processes as possible with a technology solution that is logistically supportable. The technology solution is intended to support the current internal USCYBERCOM J1 user community and the corresponding manpower personnel representatives (MPR) and leadership within each

Directorates, CDG,CMF. The solution is intended to function in a complementary capacity to existing internal and external systems (such as FMTS, DCPDS and others).

The optimal solution will minimize manual data entry/manual data reporting while maximizing data integrity between these other systems. Integration with these other systems, while desirable, is not critical to the success of the implementation of a

3.2. (U//FOUO) Operational policies and constraints

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 9 of 48

(U//FOUO) USCYBERCOM is a joint command with representatives from all military services as well as civilian staff. . Civilian employees of USCYBERCOM follow the policies outlined by the Office of Personnel Management and United States Air Force. In addition to the policies of each military command, the following policies have been used in guiding the content of this document:

a) DoD Directive 5124.02 “Under Secretary of Defense for Personnel and Readiness

(USD(P&R)),” June 23, 2008

b) DoD Directive 1400.25, “DoD Civilian Personnel Management Systems,”

November 25, 1996, http://dtic.mil/whs/directives/corres/CPM_table2.html

c) Subtitle III of Title 40, United States Code

d) Title 10, United States Code

e) DoD Instruction 1400.25-V1100, “DoD Civilian Personnel Management

Systems,” January 3, 2014, http://dtic.mil/whs/directives/corres/CPM_table2.html

f) DoD Directive 8115.01, “Information Technology Portfolio Management,”

October 10, 2005

g) DoD Directive 8000.01, “Management of the Department of Defense Information

Enterprise,” February 10, 2009

h) Office of the Deputy Chief Management Officer Website, http://dcmo.defense.gov

i) DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended

j) DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD

Information Technology(IT),” March 12, 2014, Incorporating change 1, Effective

May 24, 2016

k) DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,”

January 7, 2015

l) DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007

m) DoD Manual 5200.01 – Volume 1, “DoD Information Security Program:

Overview, Classification, and Declassification,” February 24, 2012

n) Section 552a of Title 5, United States Code, (also known as “The Privacy Act of

1974,” as amended)

o) DoD 5400.11, Department of Defense Privacy Program,” October 29, 2014

p) DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014

3.3. (U//FOUO) Description of current system or situation

3.3.1. (U//FOUO) Operational environment http://dcmo.defense.gov/

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 10 of 48

(U//FOUO) The current operational environment is a patchwork of primarily manual processes coupled with a dependency upon a complex of external systems (as documented in (U//FOUO) Figure 2 J1 System Interactions on page 12). J1 currently relies upon MS Excel spreadsheets to track personnel actions and email to obtain status updates which are then manually entered into the Excel spreadsheet. This method does not capture elapsed time within any one action or within one individual or group.

Providing any type of meaningful reports, such as trend analysis, outstanding actions or number of priority actions as examples, is challenging and results, when possible, are often delayed due to the manual efforts required.

3.3.2. (U//FOUO) System Components

(U//FOUO) In its role as the source of manpower and personnel for the

USCYBERCOM, J1 has organizational interactions across the command of

USCYBERCOM as well as working with other external military services related to staffing. (U//FOUO) Figure 1 J1 Organizational Interactions on page 10 graphically presents the scope of J1’s interactions.

(U/FOUO) J1 Organizational Interactions

J1

SSOAFPC NSA

NAVY

AFDW

USCYBERCOM

J0-J8, CDG,CNMF,

PMRs

STRATCOM

USCG

MARINESUSAFARMY

JCS

(U//FOUO) Figure 1 J1 Organizational Interactions

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 11 of 48

(U//FOUO) The nature of these interactions revolve around the following types of staffing actions:

Personnel Selection - Civilian2

Personnel Inbound - Civilian

Annual Evaluations3

Awards and Decorations

Outbound – Civilian

Personnel Action Description

Personnel Selection -

Civilian

Process of selecting and offering job offer to selected civilian candidate for position

Personnel Onboarding -

Civilian

Once civilian candidate has accepted job offer, steps to be completed to convert individual from candidate to employee

Annual Evaluations Annual performance review and counseling for military personnel

Awards and Decorations Process for recognizing above average performance

Outbound - Civilian Process utilized when civilian staff member departs

USCYBERCOM

(U//FOUO) Table 1 Personnel Action Description

3.3.3. (U//FOUO) Interfaces to external systems or procedures

(U/FOUO) In the performance of its mission, J1 interacts with several data processing systems that are external to USCYBERCOM. These systems are the official personnel systems for either civilian employees of USCYBERCOM or the corresponding military services for military personnel. In almost all instances, data is manually copied from these external systems to a spreadsheet maintained by J1. This spreadsheet is utilized by

J1 for tracking and suspense dates. Additionally, J1 will email or physically send hardcopy documents (or send by both email and hardcopy) to points of contact at these external systems for data entry into these external systems and resulting actions. The results of these actions are communicated back to J1 via email, along with any attachments.

(U/FOUO) The graphic below documents the systems that J1 interacts with to complete its mission:

2 The military selection and inbound process were under review and changing during the time frame that the work group was developing the CONOPS. As result of these other processes, the military aspect was excluded from these processes in this CONOPS. Once these military processes are finalized, they can be incorporated within the task management tool as a separate effort.

3 “New Beginnings” is being implemented to address the civilian appraisal process. Based upon the deployment of “New Beginnings”, the civilian processes were not included.

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 12 of 48

(U/FOUO) J1 System Interactions

J1

DCPDS

(Air Force)

FMTS

vPC (Air Force)

Email

MS Excel

E-915

SIPR

NIPRNET

NIPRNET

NIPRNET

NSANET

Application

SIPR

NSANet

NIPRNET

BLSDM

(Air Force)

NIPRNET

ERS

(Army)

NavFit (Navy)

NIPRNET

NIPRNET

EES

(Army)

NIPRNET

SIPR

NIPRNET

NSANET

NSANET

(U//FOUO) Figure 2 J1 System Interactions

Application

Abbreviation

Application Name Business Purpose

BLSDM Base-Level Service Delivery Model Allows supervisors the capability to retrieve queries and perform actions on personnel records for personnel under supervisors command

DCPDS Department of Defense Civilian

Personnel System

Official system of record for all civilian personnel records

E915 E915 automated routing and tracking supporting the coordination and approval of documents

EER Army Evaluation Reporting System system used for evaluation process

EES Army Entry System system used for evaluation process

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 13 of 48

Application

Abbreviation

Application Name Business Purpose

Email Electronic mail Both NIPRNet and SIPRNet used. Navy primarily uses

SIPRNet

FMTS Fourth Estate Manpower Tracking

System

Manpower system of record for OSD

MS Excel Spreadsheet Currently used to track status of personnel activities

NavFit Navy Personnel Evaluation system used for evaluation process vPC Air Force Personnel Evaluation system used for evaluation process

(U//FOUO) Table 2 System Interactions

3.3.4. (U//FOUO) Capabilities

(U//FOUO) J1 along with the CDG MI and CDG System Engineering, jointly participated in a series of meetings from October through December 2016 with the objective of identifying core business functionalities of the J1 Personnel Management

Internal Automated Tool. The team identified the following mission areas requiring support by the automated tool, reference (U//FOUO) Table 1 Personnel Action

Description:

Personnel Selection - Civilian

Personnel Inbound - Civilian

Annual Evaluations - Military

Awards and Decorations

Outbound - Civilian

(U//FOUO) The team employed Fixed Functional Block Diagramming as the method to document the existing business processes. The underlying key requirements for the automated tool were developed by abstracting from these business processes. The business processes (and the fixed functional block diagram) which this tool must be capable of supporting are documented in attachments as a separate document: “J1

CONOPS Process Flows”, December 12, 2016 (PowerPoint file).

(U//FOUO) At the highest level of abstraction, J1 has identified a need for an automated task management tool that would:

support the capture and tracking of work requests, set prioritization of work requests through the application of business rules, give assignment of work requests to “qualified and available staff”; and, provide robust real-time reporting capabilities.

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 14 of 48

Inbounds Annual

Evaluation Awards and Decorations

Out-Bounds

Workflow/Task Management Processes

Selections

Work Queue

User Queue

Personnel Events

Work Item Completed

More Steps

No

Business Rules

User Assignment rules

Work Request

Routing Rules

Create/Update Work Item

Yes

Business

Application

Layer

API

Task

Management

Application

On Boarding (Future Process)

(U//FOUO) Figure 3 J1 Personnel Management Task Tool

(U//FOUO) Figure 3 J1 Personnel Management Task Tool on Page 14 illustrates a high level notional concept of a work management foundational tool. This tool provides generic work management capabilities that are configured based upon specific business rules. The key concept is that the deployment of this tool supporting the J1 processes and internal tracking is based upon configuration of native functionality within the COTS software application rather than creating a custom application. The commercial marketplace is replete with vendors4 providing this type of solution. Key features of this work management foundational tool include:

Work Queue – backlog of work requests that need to be completed

User Queue – listing of users and their associated profiles

Business rules – defines the attributes of a work item, logic for prioritizing work and expected timeframes for completion of work item or work step

User Assignment Rules – based upon user profile, matches available user to work item and assigns work item to either individual user or group of users

Routing Rule – defines the activities that must be accomplished and the sequence of steps to be performed based upon the type of work item.

4 Commercial vendors providing software solutions include, but not limited to, BMC Remedy, Microsoft

Dynamics, ServiceNow

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 15 of 48

3.3.5. (U//FOUO) Performance characteristics, (U//FOUO) The nature of the work that J1 performs is of a low-volume high-interaction nature. Low-volume in terms of the total number of personnel actions performed each year. High-interaction in that multiple individuals are required to complete any one personnel action. The table below provides estimated number of personnel actions required to be supported by the proposed tool each year. The table also includes the number of identified process steps within each mission.

Mission Annual

Projected

Transactions

Steps within each process

Number of

Divisions/Branch

Requiring action

Selection - Civilian 300 – 400 15 – 30 10 - 20

Inbound - Civilian 50 – 100 15 - 20 10 - 20

Annual Evaluations 300 – 400 10 -20 5 - 15

Awards/Decorations 100 – 150 10 - 20 5 - 15

Outbound 30 – 75 20 – 25 2 - 5

(U//FOUO) Table 3 Volume Projections5

3.3.6. (U//FOUO) Quality

Quality is a multidimensional aspect within the final solution. The following identifies the critical aspects that must be included within the delivery of the final solution.

3.3.6.1. (U//FOUO) Reliability:

defined as the ability of the software to consistently perform according to its specifications. J1 requires that the application perform according to the agreed upon specifications with no critical defects ( a defect for which there is no system work around).

3.3.6.2. (U//FOUO) Maintainability:

defined as the ease with which a system can be maintained and corrected. Software industry recognizes four different types of maintenance as noted below. Regardless of the types of maintenance, the implementation of these maintenance activities should not impact the production availability of the system to the user community and be able to be performed during routine maintenance times.

5 These volumes are the projected annual volumes exclusive of the initial data load. The initial data load is projected to be in the range of 1,000 – 1,500 initial records.

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 16 of 48

3.3.6.2.1. (U//FOUO) Adaptive:

modifying the system to cope with changes in the software environment (system patches, application of STIGs, application upgrades)

3.3.6.2.2. (U//FOUO) Perfective:

implementing new or changed user requirements which concern functional enhancements to the software

3.3.6.2.3. (U//FOUO) Corrective:

diagnosing and fixing errors

3.3.6.2.4. (U//FOUO) Preventative:

increasing software maintainability or reliability to prevent problems in the future

3.3.6.3. (U//FOUO) Availability:

defined as the percentage of time the application is available and functioning for the end user. J1 requires an availability time of

99% Monday through Friday, 06:00 – 21:00 EST.

3.3.6.4. (U//FOUO) Portability:

There are several aspects to the applicability of software portability.

3.3.6.4.1. (U//FOUO) Multiple operating systems support:

Ability to operate the software in different operating system environments. The Command requires that the workflow tool be able to be supported by current operating systems, including standard PC desktops and servers, as well as mobile computing platforms, such as Android, IOS and other standards6.

3.3.6.4.2. (U//FOUO) Network security classification portability:

USCYBERCOM utilizes multiple networks, NIPRNet, SIPRNet, NSANet, JWICS. The work management tool should support developing a business application in one environment and then deploying in multiple network environments without requiring additional development coding or configuration efforts.

6 (U//FOUO) While mobile computing platforms are not currently supported, the work management tool should not preclude supporting mobile computing when implemented in the USCYBERCOM environment.

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 17 of 48

3.3.6.5. (U//FOUO) Usability:

The work management tool shall comply with W3C usability standards for end user interface design and with section 508 standards. Response times for end user displays shall be in the range of page loading between 3 – 6 seconds.

3.3.7. (U//FOUO) Security:

The work management tool will comply with the Risk Management

Framework (RMF) 2.0 standards consistent with the RMF rating assigned by the CDG J65 Information Assurance Manager once the system design is finalized.

3.3.8. (U//FOUO) Privacy:

The work management tool will comply with the Privacy Act of 1974, as amended.

3.3.9. (U//FOUO) Continuity of Operations:

J1 recognizes that in the event that a Continuity of Operations Plan

(COOP) is required to be implemented, mission applications must be prioritized relative to the order in which specific missions are supported.

Accordingly, in order to continue the overall mission of USCYBERCOM, J1 requires that the task management application must be restored no later than two (2) calendar days after the initiation of a COOP.

3.4. (U//FOUO) Users or affected personnel

(U//FOUO) J1, in its role as the manpower and personnel directorate, acts as a liaison with other directorates within USCYBERCOM and with other federal and DoD agencies.

The current manual Excel/email based processes interacts with all these groups. The diagram below illustrates these interaction intersections.

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 18 of 48

Civilian Military

Roles

Civilian

Military

User Types

J1 Liaison

Staff

Security

Officer

(SSO)

User Roles

GOFO/

Executive

User Role Relationships Role Intra Relationships – Existing Processes

GOFO/

Executive J1 Liaison

Staff Security

Officer

(SSO)

JDIR

Manpower

Representative

JDIR

Manpower

Representat ive

External

Agencies

External

Agencies

Excel Tracking/Manual Processes

(U//FOUO) Figure 4 Existing Role Interactions

(U//FOUO) As a combined DoD and civilian agency, USCYBERCOM is supported by both civilians and military personnel. Either of these types of personnel can and does perform any of the user roles identified.

User Role User Actions

General Officer/Flag

Officer/Civilian

Executive

This group can initiate personnel actions, coordinate comments on all personnel actions as well as approve personnel actions

J1 Acts as the liaison with and between other GOFO/Senior

Executives, Directorates, CDG,CMF manpower representatives and external combatant commands.

Directorates, CDG,CMF

Manpower

Representatives

Initiates personnel actions. Coordinates feedback of personnel actions initiated outside of own specific

Directorates, CDG,CMF

Staff Security Officer Initiates security related activities related to personnel actions, such as initial and periodic security reviews.

External Agencies Depending on specific command, may approve staffing actions and/or provide staffing support such as maintaining official personnel records. These are external systems maintained by external agencies.

(U//FOUO) Table 4 User Role & Actions

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 19 of 48

3.5. (U//FOUO) Support concept

(U//FOUO) In the current manual process of utilizing Excel spreadsheets and email, J1 is providing all support for this process. There are multiple interactions with each of the

Directorates, CDG,CMFs, external agencies and the senior level, however it is J1’s responsibility to manage, track and report on the results of these processes.7

4. (U//FOUO) Analysis of the proposed system

4.1. (U//FOUO) Summary of advantages

(U//FOUO) The implementation of an automated work management tool as envisioned within this CONOPS delivers the following advantages to not only the J1, but to

USCYBERCOM overall.

1. Improved timeliness of military evaluations through tracking, reporting and automated notifications of due dates.

2. Reduced civilian hiring processes through process improvements identified through trend analysis.

3. Improved management work load balancing across staff through real time reporting of work backlogs.

4. Trend analysis identifying current organizational delays impacting personnel actions.

5. Real Time reporting on personnel actions.

6. Consistent implementation of identified J1 processes within this CONOPS across all USCYBERCOM.

7. Automatic tracking of durations each action remains within each step and/or organization for each process.

(U//FOUO) In addition to the benefits that J1 will achieve, the implementation of the underlying work management technology provides technical benefits to

USCYBERCOM. These technical benefits are comprised of the following:

1. Reduction in the overall time to implement solutions:

7 Previously, J1 was employing MS Access database for tracking purposes. However, when the resource who developed and supported this MS Access database was reassigned, J1 was unable to backfill with a resource knowledgeable with MS Access. As a contingency, J1 reverted to using MS Excel.

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 20 of 48

a. built upon common work management infrastructure. Implementation is focused on configuration of specific business processes and not underlying enabling capabilities.

b. Reuse of business processes. Business processes can call other business processes. When a business process crosses an organizational boundary, if the called business process is already implemented within the tool, it does not need to be redeveloped. For example, all new staff are required to undergo a security investigation. If the SSO has a process implemented within the tool, the J1 process can initiate a background investigation automatically.

c. Reuse of interface applications, i.e. NSA has already integrated with

CASPORT. The application selected should reuse the same integration across multiple applications if built upon the same work management tool.

2. Single work management tool available for implementation across all

USCYBERCOM.8

3. Increase in number of internal technical staff capabilities with implementation of standardized work management tool.

4. Increased availability of commercially available technical staff if COTS product is procured.

5. Authority to Operate: reduced time to obtain with the standardization of an underlying work management tool. Similar to SharePoint, ATO only required for initial implementation. Additional implementations are configurations of existing system and not installation of new system, thus no additional ATO is required.

6. Reduction in system maintenance: if COTS product selected, vendor provides regular maintenance updates to address identified deficiencies within product.

4.2. (U//FOUO) Summary of disadvantages or limitations

(U//FOUO) As noted in (U//FOUO) Figure 2 J1 System Interactions on Page 12, the majority of the J1 work is completed on the NIPRNet. However, there are required interactions on all the other network enclaves. As stated in the scope statement:

“The optimal solution will minimize manual data entry/manual data reporting while maximizing data integrity between these other systems. Integration with these other systems, while desirable, is not critical to the success of the implementation of a technology solution for an internal tool for J1”.

The solution proposed does not cross network boundaries. This means that J1 will continue to have to manually enter data into systems resident on other network enclaves or enter data into the J1 tool from other network enclaves.

8 This is a recommendation from MITRE “Knowledge Management/Content Management” study of

December 2016. See Mr. Paul Guevin (paul.guevin@cybercom.mil) for copy of this study and recommendation.

mailto:paul.guevin@cybercom.mil

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 21 of 48

4.3. (U//FOUO) Alternatives and trade-offs considered

(U) This section identifies and describes major alternatives considered for a system or its characteristics, the trade-offs among them, and rationale for the decisions reached.

(U//FOUO) With the conclusion of the J1 process documentation phase, the high level capabilities were abstracted. Based upon these abstracted capabilities, market research is being conducted on three different solutions:

a) Accenture TMT

b) Microsoft Dynamics

c) ServiceNow

(U) This analysis is still in progress. An independent assessment will be published documenting the basis for the selection of a COTS task/workflow management solution.

5. (U//FOUO) Concept for a new or modified system

5.1. (U//FOUO) Background, objectives, and scope

(U/FOUO) The mission of J1 is: “Deliver manpower, personnel, and readiness support to U.S. Cyber Command by developing human resource management strategies and providing organizational solutions in order to enable cyberspace operations for the U.S.

and our allies.”

(U/FOUO) The corresponding vision of J1 states: “Provide the command with the highest quality manpower, personnel, and readiness support by delivering fully qualified cyber-warriors to the right place, at the right time ready to execute full-spectrum cyberspace operations for our nation!”

(U//FOUO) J1 is currently hampered in its ability to fully meet the mission and vision as stated due to a reliance upon manual tools and processes. As USCYBERCOM continues to increase staffing levels, a reliance upon manual tools and processes will adversely impact J1’s ability to manage the anticipated staffing levels. Providing J0 with timely information regarding current staffing actions, is a manually intensive process.

Additionally, the production of both regular and ad hoc reports is a staff intensive effort and represents data that is aged and often not actionable.

(U//FOUO) The scope of this CONOPS is to document the current J1 manual personnel processes with the objective of automating as many of these processes as possible with a technology solution that is logistically supportable. The technology solution is intended to support the current internal USCYBERCOM J1 user community and the corresponding manpower personnel representatives (MPR) and supervisors within each

Directorates, CDG,CMF. The solution is intended to function in a complementary capacity to existing internal and external systems (such as FMTS, DCPDS and others).

The optimal solution will minimize manual data entry/manual data reporting while maximizing data integrity between these other systems. Integration with these other

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 22 of 48 systems, while desirable, is not critical to the success of the implementation of a

5.2. (U//FOUO) Operational policies and constraints

(U//FOUO) USCYBERCOM is a joint command with representatives from all branches of the military as well as civilian staff. The personnel policies of each respective military branch applies while members of each military branch is stationed at USCYBERCOM.

Civilian employees of USCYBERCOM follow the policies outlined by the Department of

Defense Civilian Personnel Management. In addition to the policies of each military branch, the following policies have been used in guiding the content of this document:

a) DoD Directive 5124.02 “Under Secretary of Defense for Personnel and Readiness

(USD(P&R)),” June 23, 2008

b) DoD Directive 1400.25, “DoD Civilian Personnel Management Systems,”

November 25, 1996, http://dtic.mil/whs/directives/corres/CPM_table2.html

c) Subtitle III of Title 40, United States Code

d) Title 10, United States Code

e) DoD Instruction 1400.25-V1100, “DoD Civilian Personnel Management

Systems,” January 3, 2014, http://dtic.mil/whs/directives/corres/CPM_table2.html

f) DoD Directive 8115.01, “Information Technology Portfolio Management,”

October 10, 2005

g) DoD Directive 8000.01, “Management of the Department of Defense Information

Enterprise,” February 10, 2009

h) Office of the Deputy Chief Management Officer Website, http://dcmo.defense.gov

i) DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended

j) DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD

Information Technology(IT),” March 12, 2014, Incorporating change 1, Effective

May 24, 2016

k) DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,”

January 7, 2015

l) DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007

m) DoD Manual 5200.01 – Volume 1, “DoD Information Security Program:

Overview, Classification, and Declassification,” February 24, 2012

n) Section 552a of Title 5, United States Code, (also known as “The Privacy Act of

1974,” as amended)

o) DoD 5400.11, “Department of Defense Privacy Program,” October 29, 2014 http://dcmo.defense.gov/

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 23 of 48

p) DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014

5.3. (U//FOUO) Technical Policies & Constraints

(U//FOUO) The following technical policies have influenced the creation of this

CONOPS and should shape any technical solution considered:

DoD Directive 8000-01, “Management of the Department of Defense Information

Enterprise (DoD IE)”, March 17, 2016

DoD Instruction 8500.01 “Cybersecurity,” March 14, 2014

DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD

Information Technology (IT),” March 12, 2014

DoD Directive 8140.01, “Cyberspace Workforce Management ,” August 11, 2015

DoD Instruction 8330.01, “Interoperability of Information Technology (IT), Including National Security Systems (NSS),” May 21, 2014

DoD Instruction 8210.01, “Information Technology Standards in the DoD,”

February 2, 2015

Section 508 Standard

Web Content Accessibility (WCAG) Guideline 2.0

5.4. (U//FOUO) Description of the new or modified system

(U//FOUO) The implementation of the J1’s Personnel Management Internal tool will significantly change and enhance the J1’s current business practices while improving the overall timeliness of the mission of the J1. The sections below document these envisioned changes.

5.4.1. (U//FOUO) Operational environment

(U//FOUO) With the implementation of J1’s Personnel Management internal tool, the operational environment will significantly change. J1 will no longer be dependent upon

MS Excel and email for tracking personnel actions and obtaining status from the different directorates. J1, as well as all users of the tool, will be able to obtain real-time updates on the status of personnel actions from this automated tool. All users will be able to see what actions have been completed, and what actions still remain to be done.

Additionally, users will be able to identify if the action is not being worked and will be prompted to follow up, accordingly. Because of this real-time insight into the status of personnel actions, requests for updates to J1 will significantly decrease, allowing resources to spend more time processing activities. Additionally, J1 will be able to

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 24 of 48 provide actionable real-time reports on personnel actions to J0. Time spent within each step of the process and by each directorate will be discretely captured, enabling detailed reporting. Historical trends will be automatically documented. This historical information can uncover potential slowdowns and/or stoppages in processes. Root cause analysis can be performed to remediate either through additional user training or process changes.

(U//FOUO) An additional aspect of the operational environment is the recommendation that the J1 internal tool be implemented on NIPRNet. This recommendation is based upon the interactions that J1 performs and the platform on which these interactions occur

(see (U//FOUO) Figure 2 J1 System Interactions on page 12.) As documented within this figure, the majority of J1’s interactions are currently performed on the NIPRNet. J1 does not foresee this changing in the future.

5.4.2. (U//FOUO) System Components

(U//FOUO) The capabilities, as documented in (U//FOUO) Table 6 Work Management

Capabilities on page 34 establishes a vision of a common enabling application that would support multiple business implementations built atop this same foundational framework.

The foundational framework is depicted in (U//FOUO) Figure 5 Task Management

Notional Architecture on page 24. The business application utilizing this foundational framework of utilizing an enabling application: Task Management is depicted in

(U//FOUO) Figure 6 Task Management Process Flow on Page 26.

Operating System

Database

Task Management Application SharePoint

Document collaboration

J1 HR

Application

CPC

Application (Notional)

SSO

Application (notional)

J8 Application (notional)

Business Application Layer

Enabling Applications

Database

Operating System

Email

Hardware layerHardware

E915 WMS

Business Application Layer

Applications built CONFIGURING using native features of underlying task management application . Minimal use of traditional development languages/tools required

Business Application Layer

Custom applications built utilizing a combination of SharePoint developer tools and traditional development languages/tools such as .NET, VB

Published Interfaces

API API API

(U//FOUO) Figure 5 Task Management Notional Architecture

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 25 of 48

(U//FOUO) The components of each layer of the above architecture are decomposed in the table that follows.

Component Description Notes

Business Application

Layer

Business rules specific to the business processes are implemented in this layer.

Published Interfaces These are the external interfaces that allow programmatic calling of specific functions within the enabling application from an another application.

Examples:

Task management API:

add work item to queue from another application

SharePoint: add document to a library from another application

Email: create and send email from another application

Enabling Application Provide foundational capabilities for use by other business applications.

For the J1 internal tool, provides the capabilities as documented in (U//FOUO)

Table 6 Work Management

Capabilities

Database Centralized capability to store either structured or unstructured data, provides data security

Operating System Interface between higher level applications and hardware level

Hardware Servers, data storage, network connectivity

(U//FOUO) Table 5 Notional Architecture Elements

(U//FOUO) The application of the foundational task management application is depicted in (U//FOUO) Figure 6 Task Management Process Flow on page 26. This process flow is decomposed in the section following the figure.

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 26 of 48

Inbounds Annual

Evaluation Awards and Decorations

Out-Bounds

Workflow/Task Management Processes

Selections

Work Queue

User Queue

Personnel Events

Work Item Completed

More Steps

No

Business Rules

User Assignment rules

Work Request

Routing Rules

Create/Update Work Item

Yes

Business

Application

Layer

API

Task

Management

Application

On Boarding (Future Process)

(U//FOUO) Figure 6 Task Management Process Flow

A. In this scenario, the business application layer contains specific business processes performed by J1. The initiation of any one of these processes would call the API layer to add a work request to the work queue.

B. Once an item is added to the work queue, the business rules are applied to the work request. These business rules might establish the initial priority of the item and an initial due date.

C. After the business rules have been applied, a “user” is assigned. This “user” could be either an individual specific user, or a general “user group”. The assignment of a user is based upon the specific user profile, which can include the type of work items the user is authorized to perform.

D. At the completion of the assignment of a user and the business rules, a work item is created. This work item is a unique instance of one work request associated with a user and routing rules.

E. The routing rules defines the activities that must be performed in order to complete the work.

F. A decision occurs next. If there are additional steps to complete the work item, the work item is sent back to the work queue for application of business rules and a potential reassignment, based upon the type of activity that must be performed next.

G. This process continues until all the activities that are required to complete a work item are performed. Once all activities have been performed, the work item is completed and the process ends.

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 27 of 48

5.4.3. (U//FOUO) Interfaces to external systems or procedures

(U//FOUO) As noted in (U//FOUO) Figure 2 J1 System Interactions on page 12, J1 interacts with multiple internal and external systems in the completion of its mission.

These interactions are currently performed manually, with J1 manually copying data between systems/networks. Referring back to the original scope statement:

(U//FOUO) The optimal solution will minimize manual data entry/manual data reporting while maximizing data integrity between these other systems. Integration with these other systems, while desirable, is not critical to the success of the implementation of a

(U//FOUO) Based upon this scope statement, no automated interfaces will be developed as part of the solution. These interfaces will not be automated due to the limitations of moving data between different network security levels.

(U//FOUO) The primary system that J1 does interact with and does currently manually copy data from is FMTS. It would be greatly beneficial to J1 if there was a way to minimize this data copying through a data import capability. This data import would require the data to be manually exported from FMTS, manually transferred to the

NIPRNet and then manually imported into the J1 automated internal tool. This capability falls into the category of a high value nice to have capability.

5.4.4. (U//FOUO) Capabilities

(U//FOUO) The table below presents the capabilities that have been abstracted from a review of the J1 personnel processes as documented in Appendix A as a separate document.

2/14/2017 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 28 of 48

Number Process Area Capability Note

1 Work Queue Add new items Either manually or systematically (via

API)

2 Work Queue Update items Either manually or systematically (via

API)

3 Work Queue Delete Items Either manually or systematically…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .