Release Architecture Discussion December 1, 2011 OneVA Enterprise Architecture Services to Veterans Enterprise IT Governance and Architecture Guidance EA Vision / EA Development Guidance VA Core Process Governance / Governance Strategy EA Planning / ETP Architecture Tools VA Strategies Policies OMB EA Guidance EA / Services Repositories EA Comms Veterans Health Administration Veterans Benefits Administration National Cemeteries Administration Medical Care Compensation Burials Medical Research Pension Medical Education Memorials Education VR&E Loan Guaranty Enabling Capabilities Insurance Enterprise Business Capabilities & Services Corporate Finance Mgmt/ Processes Enterprise IT Services & Capabilities Information Networks & Security NetOps Human Resources Materiel Management Knowledge Management Platforms Application Standards Shared Services The “Release Architecture” is the consolidated compliance architecture for the Enterprise IT layer of the OneVA Enterprise Architecture Release Architecture Components Compliance guidance for the Enterprise IT Services & Capabilities layer of the OneVA EA consists of the following architecture products: Product: Responsibility: Application Design &Development Standards PD SD&E: OIT Release Architecture v.1.21 SD&E VA Security & Privacy Controls OIS VA IT Systems Inventory (Application Systems / Services / Interfaces) ASD Technical Reference Model ASD Integration of RA documents ASD Each of the above products exists today in some form and can be issued as collectively the first iteration of an IT compliance architecture. ASD will work with owners of release architecture components post-issuance to create more standardized methods / formats to facilitate more consistent, even and more easily navigable compliance guidance in future versions. VA CIO memo necessary to designate new / existing versions of these products collectively as the current release architecture to which all VA IT programs must conform. (This will become responsibility of EA governance body once chartered.) Backup Slides / Product Status 11/15/2011 RA v4 4 Release Architecture Components Application Design & Development Standards (PD) Purpose: Provides rules and criteria that define how new applications will be designed and developed to meet our goals of modular design and well-defined short term deliverables Status: Previously written draft IT Architecture Principles directive is being re-crafted as an application design & development standards EDM (link is to original draft directive). EDM should be available 12/15. Release Cycle: As needed. 11/15/2011 RA v4 5 Release Architecture Components SD&E OIT Release Architecture v.1.21 (SD&E) Purpose: Outlines the current operating environment at VA Data Centers and a summary of the specifications that should be used for any new, enhanced or replacement IT systems being planned. Development teams should use this reference to understand the target platforms to which they should develop and implement. Status: Ready for publication. While much of the content is more geared to those building out the infrastructure than those developing applications that sit on it, it provides the necessary guidance both communities need. As IT governance evolves, this architecture should also include details on enterprise services (e.g. identity mgmt, search & discovery) that are identified, provisioned and required / mandated for use in all enterprise solutions / applications. Release Cycle: Periodic release (annual?) anticipated; however, next release within 6 months to improve usability. 11/15/2011 RA v4 6 Release Architecture Components VA Security & Privacy Controls (OIS) Office of Cyber Security IA2 Certification & Accreditation Tool Purpose: Provides System Security Plan (SSP) and Risk Assessment (RA) using the IA2 tool. VA recently decided that it would be good to start leveraging more functionality in the IA2 application and begin using it to automate the C&A Process. Status: Exists today at link above. Currently the IA2 application can be used to automate the VA System Security Plan (SSP) and the VA Risk Assessment (RA). Release Cycle: Eventually the IA2 application may be used to automate additional parts of the C&A Process. 11/15/2011 RA v4 7 Release Architecture Components VA Systems Inventory (ASD) Application Systems / Services / Interfaces Purpose: Provides an inventory of all VA application systems. Designed to include system functional and system interface descriptions needed by developers to ensure interoperability of solutions. Status: Exists today at link above. Inventory largely complete, though new systems are always being discovered as we learn more about activities in the business units. All entered systems have full program functional descriptions. System interface descriptions typically do not yet exist. They are being adding incrementally with anticipation that all critical system interface descriptions will be available by June, 2012 Release Cycle: Updated constantly as new information is discovered 11/15/2011 RA v4 8 Release Architecture Components Technical Reference Model (ASD) Purpose: Reference model detailing the Standards Profile and Product List, collectively serve as a technology roadmap and as a forecasting tool for supporting product development and technology acquisition. Use of the TRM determines the technical alignment of projects/programs with all VA IT technical standards. Status: Exists today at link above. Release Cycle: Updated as new standards are approved 11/15/2011 RA v4 9 Release Architecture Components EA Architecture Website Purpose: Provides interface to all VA Enterprise Architecture information. The Release Architecture is presented as the Compliance Architecture for the Enterprise IT Services Layer of the OneVA EA. Status: Currently in development with release anticipated 12/8/11. The availability of the consolidated IT Compliance Architecture will be highlighted as soon as “released” Release Cycle: Updated constantly as architecture products are released 11/15/2011 RA v4 10