Comment on Governance by Dave Sun, 25 Apr 2010 16:46:50 +0000 see, now i’m confused. admittedly, I’d jumped straight in at the ‘archietcture’ section – and am now working my way back – but i think this really makes my point. under Things To Do (where not stepping on the cracks of the pavement is clearly a given) 3 and 4 are surely at odds. what is needed is not a simple renaming of CIOs, but CIOs who can do their job effectively, which negates the need for a 3 or a 5; but once you have such, i’d grant that such a senior role would be useful. not before though i’d wager…

Comment on Procurement by Amy Fri, 23 Apr 2010 19:10:34 +0000 1) Introduce Agile methodology as much as possible.

2) Decouple all civil servant bonus payments from introducing a specific system and link instead to measurable improvement in customer feedback.

3) For every project over £25 have a mandatory monthly teleconference / online presentation status update where any member of the public can attend (listen only). All sessions to be recorded (sound and slides) and provided in an archive for future “lessons learned” sessions.

Comment on Identity and Authentication by Phil Thu, 22 Apr 2010 05:41:08 +0000 I’d re-cast ‘An effective UK identity framework needs to ensure that it provides various levels of trust, identity and authentication’ as ‘Any effective identity assurance framework (in the UK or elsewhere) needs to ensure that it provides various levels of trust, identification and authentication’. Your wording implies a single framework, and – unlike every instance up to that point – I feel its use of the word ‘identity’ is a bit imprecise.

Similarly, I’d say principle 1 should read: ‘Government is just one potential *credential* provider of many: it does not, and should not have, a monopoly on citizens’ identity and authentication.’

Principle 2 is more problematic. Government’s role may be to ensure/enforce proper governance of any identity assurance framework(s) operating in the UK – though its record to date makes it a pretty poor candidate. It may even have a place in establishing standards – if it can get over its obsession with its own administrative convenience. But ‘an overall governance framework’ could easily be misinterpreted to mean ‘one ring to rule them all’…

Governments don’t issue identities. So, ‘credential-issuing and authentication functions’ or ‘identity assurance’ would be far preferable to ‘identity-issuance and authentication functions’.

Principle 3: why not ‘adopt’, rather than ‘support and promote’? A bit of ‘leadership by example’ might help rehabilitate trust…

Comment on Personal Data by Phil Thu, 22 Apr 2010 05:09:26 +0000 RE. your revised key principles:

1) Anonymity is not just ‘fine’, it could be (the/a) key to getting the public sector to realise it doesn’t need to collect (so much) data. Aim for the ‘high hanging fruit’, so your driving problem is sufficiently challenging to make people/organisations reconceive the whole way they do things – rather than just pare back bits of existing systems, or bolt other bits on – and embrace the fact that it’ll shake out some of the stickiest problems first. Success (i.e. anonymous delivery) then illustrates a deep principle, and successes along the way (e.g. permanently excising a field of data) build momentum rather than serve as end points in themselves. Agree with Iain that data minimisation, though sensible and necessary, is not as good as *proper* privacy by design. Indeed, as espoused by Home Office, I’ve heard dm used as a ‘justification’ for the National Identity Register!

2) If it’s truly a principle, you need something stronger than ‘may’. Sorry. Also think double use of ‘proof’ is problematic, though I can’t quite put my finger on why (tautologous? limits the case too much?). How about ‘Declaration/establishment of entitlement should *never* require proof of identity’? People should always be able to find out what they qualify for (and if they qualify for that, what else they might also qualify for) without having to identify themselves. Only at ‘transaction’ time should credentials/actual personal data come into play. If government wants to act like a shop (and I don’t agree that it should) it has to allow people to wander around and try things on for size/colour/whatever before going to the ’till’…

3) Please seperate ownership from management and control. Though tremendously problematic, in all sorts of ways, ‘ownership’ of personal data should be inviolable. An analogy: though their lives/bodies are almost completely managed and heavily controlled, no-one would argue (I hope) that prisoners are *owned* by the state that has detained them. Law enforcement agencies may be ‘priviledged’ (preferably by court-issued warrants – strict constraints and proper independent oversight) to act in certain ways that override the control or consent of the individual, but they don’t ‘own’ the suspect or even stuff/items gathered in evidence – and should NEVER be encouraged to think that they do. Or you get more obscenities like the million innocent people’s data on NDNAD. Just because, in the course of discharging its duties, an agency paid to process some data shouldn’t mean it gets to own it.

Comment on Personal Data by william Thu, 08 Apr 2010 17:30:41 +0000 from industry unConference

Personal Data
Principles of Personal Data:
Clear benefit statement – 2 way
Benefits realisation for the customer:
Tell us once
Know what your entitled to
Stop Queuing
Prevent fraudulent use
Lowered service cost and reduced tax
Subject Access Request
Rapid Response Holistic view
Minimal disclosure
People’s records should be accessible
Provide audit trail
Accepted and endorsed across government
Selective implementation
Explicit permission – citizen in control

Things to do (new)
Open up to receiving data streams from the individual – Rx rather than Tx
Monitor/control access to data streams

Things to stop doing
Stop breaking the law
Don’t build centralised databases

Things to continue doing
Get better on information assurance

Comment on Procurement by william Wed, 07 Apr 2010 15:28:04 +0000 Above comment was live from industry feedback session. Typed in haste (sorry for abundant typos)

Comment on Procurement by william Wed, 07 Apr 2010 15:27:09 +0000 Feedback on procureme

– constrained by existin contracts
– constrained by procuremnt regulations

* know what it is you want to buy
– ID the svce categories you want to buy in new world
* ensure you move away from bespoke reqts; ID what is genuinely unique.

Create envt where pub sector collaborates on proct is a world away – mechanisms for comms etc just not in place

Loops back into enabling business change – the bigger part of savings.

Standardised reqts conflict with “we work this way”: existing business processes inhibit change. So we need holistic view of entire piece. Where is the IT reinforcing inefficiencies.

IT suppliers not entirely happy with gov approach to proct. re the 4 principles:

i effective competition: YES
ii separation of complex v commodity. DOnt wrap up desktop with user-facing: agree in principle. But recognise it cd drive up cost of bespoke work (if commodity partis removed)
? is public sector ready to support multi vendor environment? Skills, manpower issue.
Bespoke only when necessary: doesnt require move away from proprietary; just means define tech arch standard and we have interopability so nothing is closed off.
4: breaking it up. We thought this was admirable, but is the problem statement fact or open to argument? Also: it points to importance of collaboration and partnership. Dont send suppliers into bunkers to solve problems.

Terms/key recs:
1. identify genuilnely unique reqts. Standardise and share the rest.
2. improve capability and skills for whole programme; proj, contr mgt as well as procurement. There are many causes of failure.
3. Big gap: how is risk priced into existing contracts? (ind cd help with this). Do they understad tradeoffs with cost savings etc.
4. Find ways to ease proct process. eg rolling centralised accreditation or pre PQQ stage, so it doesnt have to be done case by case. “This supplier is capable of supplyig these services, up to these sorts of standards or levels of risk” – gold/silver . Doesnt rul eout SMEs. Might drive cost of sale down, and length of procureent,

Things to stop:
overly flexible OGC frameworls focussed on PRICE of IT svces as opposed to the change it delivers. Driving magin out is not in long term interests of entire market.

Avoid ignoring businesss process change: focus on the larger prize.

Avoid process as blocker to change.

We DO sense change in envt in trying to have debate on difficult and entrenched issues. Persist with this

Comment on Information Assurance and Cybersecurity by william Wed, 07 Apr 2010 15:16:37 +0000 * How does one make the case: “what if I don’t spend the £10m?

* not all depts are equal. DWP non-issuing cash vs people not getting their tax discs

Things to stop:

Hard to work out. But perhaps there’s less oingon in govt than it supports through CPNI.

Comment on Saving Money by andy macleod Mon, 05 Apr 2010 10:37:53 +0000 William, ‘changing the way that Govt works’ should save money and time -and accelerate the digital literacy required for Govt to be a better buyer of IT services ( which in the future would start to include ‘cloud Services’.More to follow if you are interested .