Information Security Strategy

advertisement
Office of the CIO
EITS
The University of Georgia

Phase 1:
 Identity Repository and Infrastructure
 Unique Identifier (UGAID)
 Translation Tools

Phase 2 EMT Priorities:
 SSN Removal/Mitigation in Distributed Systems—
estimated Dec 2011
 SSN Removal/Mitigation in CORE/Enterprise and
Mainframe Systems—estimated Dec 2012
12 Total Slides
1
2009
FEB
2010
MAR
APR
MAY
JUN
JUL
Single, consolidated
view of ALL Identities
SSN PHASE I
SEP
OCT
NOV
DEC
JAN
JUL
DEC
JAN
JUL
2012
DEC
2013
JAN JUL DEC JAN
7/31/09
(Estimated)
IdM Infrastructure and Process
Initial systems for SSN
Replacement chosen
SSN PHASE II
AUG
2011
SSN Replacement
Analysis & Planning
7/31/09
(Estimated)
SSN Replaced in Initial
Systems
SSN Replacement
(timeline to be determined by scope)
6/30/10
(Estimated)
SSN Replaced
in Remaining
Systems
12/31/11
(Estimated)
SSN Replacement
(timeline to be determined by scope)
Current Efforts
Ongoing SSN Replacement Efforts
Discovery
Complete
IMS/SSN
12/31/09
Implementation End
12/31/12
IMS to DB2/SSN Removal (convert IMS database to DB2 and
removeContract
SSN from Negotiations
core administrative systems)
DOAS
12 Total Slides
2
Original Total 12.6 M
Removed 5.5 M
12,000,000
8,000,000
11,000,000
7,000,000
10,000,000
9,000,000
6,000,000
8,000,000
SSN Records
5,000,000
7,000,000
4,000,000
6,000,000
5,000,000
3,000,000
4,000,000
2,000,000
3,000,000
1,000,000
2,000,000
0
1,000,000
Actuals
0
Goal
12 Total Slides
3
Unit
SSNs
Removed
Unit
SSNs
Removed
Parking Services
1,896,980
Student Affairs
35,000
Libraries
1,169,771
BigCard
35,000
EITS
1,034,315
Printing
10,000
UGA Card Services
1,000,040
Food Services
7,200
Arts & Sciences
266,999
Golf Course
3,000
Admissions
220,000
Political Science
1,500
Graduate School
73,000
Admin Services
1,100
School of Law
48,887
Regents Center
400
12 Total Slides
4
DOAS Procurement Delays -- IMS/DB2
Conversion RFP
2. Complexity of CORE/Distributed Processes and
Systems
3. Distributed Units Require Intensive EITS
Assistance
4. Data Discrepancies
5. Resources/Priority Conflicts
1.
If identified challenges are not addressed, original
timelines are likely to change
12 Total Slides
5
Student System Diagram
12 Total Slides
6

Lengthy DOAS procurement process

Complexity





3+ million lines of code
14,000 programs
5381 tables and views
348 major databases
Existing/potential institutional priorities requiring
IDM resources
 e.g., ADDM projects, SACS, next generation
administrative systems, new email system
12 Total Slides
7

Lack of resources in distributed units

Interdependent on CORE systems

EITS resources are needed for all projects

Data Discrepancies between Student, HR and BigCard
Systems

UGAID Assignment for Professional Schools not
available at application

Some unit technical staff unwilling to move forward or
causing delays because of disagreement with technical
aspects of the approach
12 Total Slides
8
In Process
225,955
Secure in “Fort Knox”
Required to
Keep
1,802,772
Known Barriers
1,759,060
12 Total Slides
Ready to
Execute
774,520
Potential
Barriers
2,587,941
9

Types of data discrepancies
 Historical
 New
▪ Some business/system processes continue to propagate
discrepancies

IDM has identified discrepancies/duplicates
 Initial number ~100,000
▪ Both historical and active
▪ Identified by IDM
 Reduced to 21,382
▪ Estimated 1,000 – 2,000 discrepancies in active records
12 Total Slides
10

Academic and Administrative unit heads confirm
targets
 Confirm or re-specify the dates their units have previously set for the
elimination of SSNs in their units

Accountability for progress
 Require progress reports from unit heads on quarterly basis

Complete process mapping and data error
identification
Continued…
12 Total Slides
11

Move forward without waiting for “perfection”
▪ Units should move forward without 100% discrepancies resolved
▪ Implement data discrepancy controls
▪ Units that are reliant on SSNs from Core Systems should assess
using IDM tools prior to the IMS/DB2 conversion

Resources/Priorities
 If additional resources are not available, then support is
needed for changes in priorities due to resource
reallocations required for IDM priorities
12 Total Slides
12
Download