Tuesday, 15 May 2012

Glow2—Managing Open Technologies in the Public Sector in Scotland

The need to reduce costs and improve services is bringing the use of free and open source software to the centre of discussions about strategies for ICT in Scotland. But it appears that Scotland isn’t about to change its ways.

Where are we now?

An article in the Spring edition[1] of the UK publication, Central Government says:

Free, Libre or ‘Open Source’ Software … has been the big success story of the IT world, taking the enterprise by storm and exposing proprietary software as over-priced, inflexible and insecure. Governments from Brazil to China have rushed to adopt the free GNU/Linux operating system (OS), to benefit from software that can be adapted to local needs. Held back by their cautious procurement policies and procedures, the UK Government and local authorities have so far just dipped the occasional toe in the water, then rushed to embrace the next special deal from proprietary software vendors.[1]

How true that is, and how relevant to the current process of developing a new ICT Strategy for the Public Sector in Scotland, and for the decisions being made now about the successor to Glow[2] (the Scottish “national online community for education”). Glow, when it launched for full in 2007[3], was “the world’s first national education intranet”[4]. Surely we don’t want to be overtaken by the rest of the world!

It is perhaps encouraging to note that soon after the above quote, the UK Office of Government commerce produced a report[5] on open source software trials in Government and concluded, amongst other things, that:

Open Source software is a viable and credible alternative to proprietary software for infrastructure implementations, and for meeting the requirements of the majority of desktop users[5]

But whilst it is great to know that the UK Government is behind the use of open source software, one might look at the very comprehensive report by the Institute of Infonomics for the European Union[6] (produced two years earlier) and ask why it has taken the UK government so long to get its own act together? Here’s a quote from that earlier report where it talks about the cost benefits of free and open source software:

Despite the possibly high costs of migration (which would also arise by migration to another proprietary technology) this shift should be gainful in any case. The situation after the migration to open source software will lead to lower life-cycle costs. Furthermore costs of service, support, and maintenance can now be contracted out to a range of suppliers, being placed in the competitive environment of a functioning market. The costs of this more service-oriented model of open source are then also normally spent within the economy of the governmental organization, and not necessary to large multinational companies. This has a positive feedback regarding employment, local investment base, tax revenue, etc.[6]

Back to reality

But I’m sad to say that I may have been a little misleading. The reports quoted above are not new reports. The first two quotes were published in 2004, and the European Union report on FLOSS (Free/Libre Open Source Software) was published in 2002—ten years ago and five years before Glow first launched.

So, when late last year (Sep 2011), Mike Russell (Cabinet Secretary for Education in Scotland) announced a move to using “the free tools and the open source services that already exist on the web”[4], this “new approach” was proposing something that had been recommended to the public sector in the UK at the beginning of the previous decade and long before the first version of Glow was even conceived.

But let’s give Scotland a chance to catch up, after all, the first reference I can find to the Scottish Government making a policy of using free and open source software was in 2007:

Next Steps

41. There is a need to maximise the returns on, and benefits from, investments in publicly funded software. The ability to freely share software which has been developed within the Scottish public sector or bespoke software funded by the Scottish public sector would be enhanced by making this available as FLOSS [Free/Libre and Open Source Software]. Copyright of software, documentation, design materials, manuals, user interface and source code should be released under an OSI-approved open source licence unless there is a compelling argument why this should not be the case and an alternative licensing model proposed.

42. Further consideration will be given to mechanisms for sharing ICT products and architectural components as part of the ICT transformation work which the Scottish Executive is taking forward under its public service reform agenda.[7]

I’ve carefully kept in the heading of this section of the policy statement because these two points represent the complete “next steps” of this report. But now in May 2012, I am not aware that these points have been taken forward at all in any area of the Public Sector in Scotland. Unaware of this, I had a very similar policy in my “Alternative ICT Strategy for the Public Sector in Scotland”[8]. Sadly the first in an unfulfilled policy and the second is just a dream.

So how do we escape from standing still for the next ten years?

Let’s be clear to start, that the use of free and open source software in the public sector would save money. It would also open up opportunities for the private sector in Scotland to provide services to the public sector that have previously been exclusively delivered by multinational companies headquartered outside of Scotland and the UK. In other words, it opens up ways of reducing public spending without cutting jobs. It would transfer the profits of multinationals taxed outside of the UK to those of smaller companies that are based in Scotland and taxed in the UK.

Let’s also be clear that this is not in dispute, it is not new, it is well known, it has been recommended to the public sector for years and has been an unimplemented policy in Scotland for the last five years.

But unfortunately, the public sector does not appear to have the skills and leadership to understandstand how to deliver on these policies. So it tries to outsource the management to the very companies that would loose money if they implementing them.

Look at the current situation with Glow 2 (explained in the blog post “Glow2: Intranet or Ecosystem?"[9]). Rather than having a skilled public sector team manage the delivery of free software to schools in Scotland, it appears that the government has decided to try and pass everything onto Google and Microsoft. It no-doubt feals more comfortable with the idea of a large company with seemingly limitless resources making the decisions rather than the Scottish Government. It’s also hard for central government to manage these things because they have progressively outsourced all the skills they would have needed to do it in-house. A situation that was recognised in Westminster last year[10] just as Scotland’s report on the delivery of ICT[11] was recommending greater outsourcing.

Discussions about procurement often focus on the lack of an “intelligent customer” function within Government to enable it to engage effectively with external suppliers and stakeholders. The Government’s inability to act as an intelligent customer seems to be a consequence of its decision to outsource a large amount of its IT operations to the private sector.[10]

“Shiny Granite”—a whole knew world leading school building infrastructure for Scotland

Let’s put this in more general terms for those less familiar with the technological issues. Let’s imagine for a moment that Glow isn’t an ICT infrastructure for schools but instead the actual physical school infrastructure for Scotland. Let’s call it “Shiny Granite”.

So re-writing history we find that Scotland has invested lots of public money in paying a private company to build new buildings for every school in Scotland. The work started in 2005 and by 2007 it was launched with school children gradually moving over to the new buildings. The management team said how wonderful and world-leading this was despite the fact that the schools were old refurbished buildings and weren’t designed for easy access. Some schools were without accommodation for 5 years.

Then, in this history re-write the government needed to decide what to do next, because the “Shiny Granite” buildings were owned by the private company, not the public. So in September 2012 there won’t be any school buildings in Scotland anymore and we’ll have to buy some new ones. Naturally, this makes the government a little nervous and they decide to rent from now on, which in changing times isn’t a bad idea. Indeed it’s a particularly good idea because the suppliers are offering the properties rent-free!

So, does the government compare the offerings and choose the best buildings? No, it tells the companies that they have to enter a competition to win the chance to rent their properties for free. Oh, and in addition they want the companies to promise to move and accommodate lots of the important property and equipment from the old buildings to the new but they can’t say what and how much. Oh, and they would like the companies to use a completely different security firm in Scotland to their own.

What could possibly go wrong?

Well, the company (Google) which already has well equiped tried and tested buildings ready and waiting to be used has decided that it should focus on doing what it does well[12]. It would seem that it feels that when it is giving something away for free it doesn’t really make sense to be spending time competing for the priviledge.


In reality I don’t know the details of what is actually going on right now. But it doesn’t take an expert to realise that the current situation is a mess and the clock is ticking.

How is it that in a country full of talent and expertise the Scottish Government can’t assemble a team of experts with the vision and leadership to take this mess and transform it into the success it can and should be?


  1. Richard Smedley, “The Price of freedom”, Central Government, Spring 2004(http://m.publicservice.co.uk/article.asp?publication=Central%20Government&id=125&content_name=IT%20and%20e-Government&article=2965).  ↩

  2. Glow (http://www.educationscotland.gov.uk/usingglowandict/glow/)—“Glow is the world’s first national online community for education”.  ↩

  3. Glow, “The story so far” (http://www.educationscotland.gov.uk/usingglowandict/glow/whatis/storysofar/index.asp).  ↩

  4. Cabinet Secretary for Education Michael Russell discusses the future of Glow. Video and transcript: http://www.engageforeducation.org/2011/09/the-future-of-glow/.  ↩

  5. “Open Source Software Trials in Government (Final Report)”, Office of Government Commerce, October 2004 (http://www.epractice.eu/files/media/media_540.pdf).  ↩

  6. “Free/Libre and Open Source Software: Survey and Study”, International Institute of Infonomics, University of Maastricht, The Netherlands, Section 2.2. (http://www.flossproject.org/report/Final-2b.htm).  ↩

  7. “Free/Libre/Open Source Software: Scottish Policy Statement: A Report by the Open Source Software Working Group”, March 2007. (http://www.scotland.gov.uk/Publications/2007/04/10104126/0).  ↩

  8. Stuart Roebuck, “The Alternative ICT Strategy for the Public Sector in Scotland”, April 2012 (http://stuartroebuck.blogspot.co.uk/2012/04/alternative-ict-strategy-for-public.html).  ↩

  9. Theo Kuechel, “Glow2: Intranet or Ecosystem?”, 11 May 2012 http://theok.typepad.com/digital_signposts/2012/05/there-is-a-fundamental-debate-taking-place-in-scotland-at-the-moment-with-regard-to-the-next-implementation-of-glow-scotland.html.  ↩

  10. “Government and IT — ‘a recipe for rip-offs’: time for a new approach, Twelth Report of Session 2010–12”, House of Commons Public Administration Select Committee, 27 July 2011. (http://www.parliament.uk/business/committees/committees-a-z/commons-select/public-administration-select-committee/publications/)  ↩

  11. John McClelland, “Review of ICT Infrastructure in the Public Sector in Scotland”, June 2011 (http://www.scotland.gov.uk/Publications/2011/06/15104329/0).  ↩

  12. Google’s letter, pulling out of the tendering process, 2 May 2012, http://mimanifesto.files.wordpress.com/2012/05/20120502-161203.jpg.  ↩

Monday, 23 April 2012

Open Sourcing the Public Sector in Scotland

If there was one decision that could have the greatest positive impact on the use of ICT In the Public Sector in Scotland, it would be the wholehearted open sourcing of public sector ICT. I don’t simply mean the use of open source software: I mean taking software produced for the public sector and making it unambiguously publically owned and publically accessible by default.

Unfortunately, there is such a wide range of opinions on this topic that it seems almost impossible to write a concise text that addresses the concerns and misunderstandings that still hold back progress in this area. I am therefore inclined to quote from text produced for the Consumer Financial Protection Bureau[1] of the US Government which (in April 2012) announced its intention to do exactly what the Scottish Government should do. Here is a portion of an article explaining the two halves of this policy: using open source and open sourcing their own software:

Source code that can be freely modified and redistributed is known as “open-source software,” and it has been instrumental to the CFPB’s innovation efforts for a few reasons:

  • It is usually very easy to acquire, as there are no ongoing licensing fees. Just pay once, and the product is yours.
  • It keeps our data open. If we decide one day to move our web site to another platform, we don’t have to worry about whether the current platform is going to keep us from exporting all of our data. (Only some proprietary software keeps its data open, but all open source software does so.)
  • It lets us use tailor-made tools without having to build those tools from scratch. This lets us do things that nobody else has ever done, and do them quickly. Until recently, the federal government was hesitant to adopt open-source software due to a perceived ambiguity around its legal status as a commercial good. In 2009, however, the Department of Defense[2] made it clear that open-source software products are on equal footing with their proprietary counterparts.

We agree, and the first section of our source code policy is unequivocal: We use open-source software, and we do so because it helps us fulfill our mission.

Open-source software works because it enables people from around the world to share their contributions with each other. The CFPB has benefited tremendously from other people’s efforts, so it’s only right that we give back to the community by sharing our work with others.

This brings us to the second part of our policy: When we build our own software or contract with a third party to build it for us, we will share the code with the public at no charge. Exceptions will be made when source code exposes sensitive details that would put the Bureau at risk for security breaches; but we believe that, in general, hiding source code does not make the software safer.

We’re sharing our code for a few reasons:

  • First, it is the right thing to do: the Bureau will use public dollars to create the source code, so the public should have access to that creation.
  • Second, it gives the public a window into how a government agency conducts its business. Our job is to protect consumers and to regulate financial institutions, and every citizen deserves to know exactly how we perform those missions.
  • Third, code sharing makes our products better. By letting the development community propose modifications , our software will become more stable, more secure, and more powerful with less time and expense from our team. Sharing our code positions us to maintain a technological pace that would otherwise be impossible for a government agency.

The CFPB is serious about building great technology. This policy will not necessarily make that an easy job, but it will make the goal achievable.

If you are left thinking that the United States is very different from the UK then you can also look at the UK Government in Westminster which has set up the Government Digital Service[3] which is now open sourcing the software it uses and produces, and even blogs about the many open source technologies that they rely on to make it all work[4].

 FAQ

So, here’s a pseudo FAQ (Frequently Asked Questions) covering some of the concerns and issues I’ve heard relating to the idea of the public sector adopting open source and open sourcing the software it produces.

How can open sourcing software save the government money?

Open sourcing government software makes it easy for other public sector bodies to identify and re-use software themselves, thus removing duplication: reducing development costs and development time. Well known open source software also benefits from free contributions from third parties who are able to find and fix bugs or contribute enhancements at no cost.

With traditional government approaches to tendering, the private company supplying the software is often the only organisation that understands the software and is able to support it in the future, this means that the government is ‘locked-in’ to using that supplier or starting all over again with a new supplier. The cost of starting again or the lack of competition act to increase the cost to government.

Finally, the large size of public sector contracts eliminates most nationally based suppliers from tendering for the work. Whilst these multinationals may well go on to employ staff from within Scotland, the profits are probably taxed elsewhere. Open sourcing the software creates an open system which can and should be modularised into smaller components that could be delivered by local suppliers. This would rely on some centrally based development team much like the model of the UK Government Digital Service[3].

The Government can’t open source public software—think about the security risks!

There is a misconception that open sourcing software makes it more vulnerable to security risks: the reality is quite different. The underlying security mechanism currently relied on by Banks and Governments connecting with the public over the internet is something called SSL/TLS[5]. This standard is open and it exists in many software libraries including OpenSSL—an open source version. The open nature of this standard has been critical to the identification and consequent elimination of security vulnerabilities in earlier versions of the standard. The Linux operating system, the Apache and Tomcat web servers and numerous other open-source technologies are relied upon across the world to drive countless high security web services.

Open Source is a nice idea but surely it’s no good for big government projects?

Open source is not some new idealistic approach to building software for academics. When governments contract large multinational companies to develop critical software they are typically paying for them to produce software which under the hood is made up of lots of open source components. Conceptually the government agency is not placing its trust in the open source software but in the company that uses it to produce the solution they require: in reality they are just paying a lot of money for something they could get for free.

How would open sourcing government software align with the McClelland report on ICT in the Public Sector?

The McClelland report makes it clear that there is a need for greater transparency in the use of ICT and its costs and that there is a need to increase reuse of software. Open sourcing government software is the ultimate form of transparency and opens up opportunities for re-use not just of complete software systems, but also of components that make them up. For example, within the GDS[3] open sources software for the DirectGov web site, there is a software library that will take a postcode, determine it’s location and generate a map showing the location. By open sourcing this software, any government department can reuse it for any purpose it sees fit.

How would open sourcing government software align with the Christie Commission on the future delivery of public services?

The Christie Commission report emphasises the importance of saving money by preventative actions and tailoring services to meet local needs. Open sourcing government software prevents huge and unnecessary costs around the commissioning and future decommissioning of large contracted software systems and the complex tendering processes around these. Open sourcing software enables iterative change and development that allows systems to adapt to needs rather than being locked into agreements sometimes lasting as long as eight years at a time. Because open sourcing software allows sharing and adaptation, it allows software to be both shared and adapted to local needs.


  1. Consumer Financial Protection Bureau: http://www.consumerfinance.gov/. The quoted article can be found here: http://www.consumerfinance.gov/blog/the-cfpbs-source-code-policy-open-and-shared/. They have also published their source code policy to help other organisations to do the same thing: https://gist.github.com/2343578. Finally, you can look at their open source software as it develops on their Github account here: https://github.com/cfpb.  ↩

  2. US Department of Defense policies around open source software: http://dodcio.defense.gov/Home/Topics/UseofFreeOpenSourceSoftwareFOSS.aspx  ↩

  3. The Government Digital Service: http://digital.cabinetoffice.gov.uk/. A document describing their software design principles: https://www.gov.uk/designprinciples. Their own software freely available on Github: https://github.com/alphagov.  ↩

  4. UK Government Digital Service blog entry describing the current technologies they are using: http://digital.cabinetoffice.gov.uk/colophon-beta/.  ↩

  5. Secure Sockets Layer: for a good overview and history see the Wikipedia article here: http://en.wikipedia.org/wiki/Secure_Sockets_Layer.  ↩

Tuesday, 6 March 2012

Big IT is past its sell by date, but Scotland is ripe for the picking

In Westminster the government has just woken up after decades of slumbers and realised that IT can be done efficiently and can be done well. But in so doing, it is re-writing the whole way it deals with the big IT suppliers that have lived off government contracts since the beginning of time.

So all those big name IT businesses realise that they need to restart some long contracts with the Scottish Government before Scotland realises what’s going on.

Here are some of the things they are likely to do that the Scottish government would do well to recognise:

  1. They will want to try to create as many long-term contracts now as possible so that the government is tied in to them when they realise what they should have done. This means that they will probably offer to exit from existing contracts on beneficial terms that seem surprisingly generous.
  1. Working off the back of the poorly thought out McClelland report, the big IT suppliers will find it easy to persuade the Scottish Government that it can save money by centralising procurement and enforcing standards. They will argue that government has to make the ‘hard’ decision of enforcing change across the board all at once in order to save money.
  1. They will encourage the importance of ‘governance’: because big bureaucracy encourages centralised decision making and big committees and boards can’t make decisions so they will end up ‘consulting’ industry.
  1. They will supportively help Scotland the create its own Public Sector Network. They will unreluctantly acknowledge that it is essential for security and reliability. It will be so complicated that only they will understand it but, in their embarrassment, government officials will pretend to understand it because they know that they should.
  1. They won’t use Open Source software, indeed they’ll try not to let it enter conversation, and if it does they will laugh it off as not a serious suggestion.
  1. They will insist that contracts are commercially confidential. How could industry survive if they weren’t!
  1. They will retain ownership of the technologies they use and make sure that they are tied to some proprietary systems that are ‘industry standards’.
  1. They will offer lots of stuff at such competitive rates in the short term that it seems like an offer that just can’t be turned down.

Scottish Government - be warned!

Tuesday, 18 October 2011

What is the Public Sector Network (PSN): a cloud of confusion?

Recent announcements on the ICT Infrastructure programme for the Scottish Government and press coverage have drawn my attention to the Public Sector Network programme. Read around the topic I have become increasingly concerned that this programme is seriously flawed.

In summary, the PSN programme is a programme for creating a single public sector network for all UK public sector organisations including Universities. It is a programme that appears to be driven by the need to save money and a recognition that the existing arrangements are often outdated and inefficient. However, the proposed solution is very complex and potentially costly despite being argued publicly as a mechanism for saving costs and introducing a level playing field for commercial suppliers.

But you can’t really explain this all in one paragraph, so here’s a more extended attempt to explain what this is all about, starting with a look at the background and the surprisingly ambiguous definition of what the programme really is.

Programme establishment

In early 2007, the CTO Council articulated a vision for a Public Sector Network described as a network of networks delivering the effect of a single network for the public sector. In July 2008, the Public Sector Network (PSN) programme was established by the UK Government, principally coordinated by the Cabinet Office. (PSN-OM p.10-11)

But what is it?

Below is a selection of definitions or visions of what the Public Sector Network is. These are mostly from programme documents and should give a flavour of how confusing this whole thing is.

  • A single, integrated infrastructure, delivered by multiple selected service providers
  • A ‘private network of networks’ for the public sector, addressing the various special; security, resilience, service and availability needs of public sector organisations
  • Global, including overseas posts and other international UK public bodies
  • A secure version of the Internet for the UK Public Sector

(PSN PowerPoint Presentation)


The PSN vision is one of creating the effect of a single network across the public sector, to be delivered through multiple service providers in order to ensure ongoing value and innovation. In some respects, this is similar to the Internet model, whereby “service consumers” experience flexibility and inter-working without much concern for underlying inter-network “plumbing”. However, the vision is also one of a “private network of networks” for the public sector, addressing the various special security, resilience, service and availability needs of public sector organisations. (PSN-OM, p.10)


The Public Sector Network (PSN) will change the approach to the acquisition of Information and Communications Technology by the UK Public Sector, allowing public sector customers and select partners to harness changing technology to better support their delivery of service and the transformational government agenda. This will be achieved through a commonality of standards, a customer-centric operational model and a flexible approach. (PSN-PM, p. 1)


PSN is not a physical entity.
PSN is

  • an industry standard
  • an enabler for network interoperability benefits
  • an enabler to deliver procurement effort benefits
  • a process that provides a commonality

(SG-Breakouts, p. 7)


PSN offers a vision of ICT services from many suppliers being shared across the Public Sector and delivered over a common network infrastructure, itself provided by several network operators. (PSN-Comp, p.7)


The PSN is a supply-side “network of networks”, making network-oriented services utility-like for the public sector. Hence, it is essentially an inter-working and standards framework for the suppliers of network-oriented services to the public sector, governing both interconnection of supplier services and the relevant key service characteristics/attributes that ensure inter-working and end-to-end service assurance across supplier portfolios. (PSN-GCN, p. 7)

These definitions tend to raise more questions than they answer:

  1. Is the PSN a separate physical network that duplicates the Internet but is intended just for the public sector?
  2. When the PSN documentation talks about open standards does this mean that this is technically just using Internet standards or is it actually a network running under a protocol unique to the UK public sector?
  3. Why can’t the public sector just use the Internet?
  4. If this is separate from the Internet does this mean that staff in the public sector won’t be able to access the Internet?
  5. What will this cost and how can it possibly save the government money?

Let’s try and tackle some of these.

So is the Public Sector Network a physical entity?

A breakout session of a joint Scottish Government, Socitm and Cabinet Office PSN workshop held in Edinburgh in January 2011 was clearly told that the Public Sector Network, “is not a physical entity”. But the extensive documentation around PSN includes description of the Government Conveyancing Network (GCN) - a part of PSN that “will be used to interconnect supplier data networks and other services in terms of network transport” (PSN-GCN, p. 8).

Similarly, the Operating Model document describes the PSN vision as “one of a ‘private network of networks’ for the public sector, addressing the various special security, resilience, service and availability needs of public sector organisations” (PSN-OM, p.10). If the PSN is not a physical entity then how can it possibly address issues of resilience and availability that are not ‘virtual’ concerns?

Looking at the various specification documents available on the Cabinet Office web site it is clear that the specifications include physical requirements like network timing and the implementation of domain name resolution across the network.

Ultimately the only way to make sense of all the documents and the conversations is to look at the terminology.

The truth, as far as I can tell, is that the PSN is the specification and not the network itself. Just like a car manual is not a car, the PSN is not a physical network but it does define the standards required to supply a physical network that is essential for it to run. To put this simply, whenever a document talks about the Public Sector Network you should probably insert the word “Specification” at the end. So, the phrase “The Public Sector Network is not a physical entity” should be read, “The Public Sector Network Specification is not a physical entity”, but parts of the actual network will be!

This is a very unfortunate and ambiguous choice of terminology.

What is the Public Sector Network Specification and what is the network it specifies?

So, the Public Sector Network (PSN) is the specification of a network that will deliver network services to users in a consistent manner throughout the country and even beyond the UK. These services will be physically delivered by private sector suppliers who have won contracts to deliver these services and who have met the compliance requirements set by government.

Third party private sector suppliers are providing something akin to an Internet connection, except it isn’t connecting directly to the Internet: it is connecting to a special public sector private network with what it terms, “segregated access” to the Internet (PSN-OM, p.21). This, the theory goes, allows the public sector to maintain a security separation from the Internet with communications running on networks which are provisioned to deliver higher resilience and availability standards than the Internet can provide.

So the idea is that the private sector will supply separate parts of this one single network and they will work together by virtue of adhering to the PSN specification. Hence, the PSN is not a physical network owned by the public sector: it is network that meets a specification and runs over networking hardware supplied to government by the private sector on a service contract.

Obvious!

So, why can’t the public sector use the Internet like everyone else?

This is a very good question. Indeed I would argue that this is ultimately the question that every government minister and civil servant should be asking repeatedly.

The proposed reasons why the public sector needs its own network appear to fall into the following headings:

  • For consistency across the public sector
  • For efficiency
  • For reliability and capacity
  • For security

Let’s take these one at a time.

Consistent networking across the public sector

The truth is that, to the present day, the public sector is a mish-mash of networks developed independently and often intended to be kept separate from each other. The need to bring these networks together to allow for sharing of information and intercommunication is hard to deny.

But given a choice does it makes sense to standardise on the networking standard of the world or create a unique one for the UK public sector?

Efficiency of delivery, procurement and maintenance

Maintaining the current range of networking services across government is undoubtedly more costly than it needs to be. It makes sense to standardise the platform so that procurement is less costly.

But what is the least costly option, servicing a network that is unique to the UK public sector or servicing a network like every other private sector business in the world?

Reliability and capacity

Enabling the public sector to share a common network that can balance the varying peaks and troughs of demand across services is a good way of dealing with capacity needs where individual and separate networks would be constrained by their individual capacities. Setting standards for the delivery of these networks can help to ensure that the networks are reliable.

But this concept of shared networking is the basis of the Internet. If capacity and reliability requirements genuinely demand more control there is no reason why the public sector couldn’t have a dedicated physical network running on the standards of the internet. In effect this is the model of the UK Joint Academic Network (JANET) used for many years by Universities and Colleges throughout the UK.

A secure network

Clearly the public sector deals with information of a private nature some of which concerns the security of the nation. So, do we need a separate network or unique networking standards in order to deliver the levels of security required?

It turns out that this question is answered by the specification of the PSN itself. It says quite clearly that it is possible to deliver all the security levels required over an “untrusted” network like the Internet.

Coupled with encryption technologies the authentication of individual devices will enable the sharing of information across the same PSN infrastructure from IL0 to IL4. (PSN-OM page 20)

(“IL0” (Impact Level 0) refers to “untrusted infrastructure” for example, the Internet. In other words, the PSN can operate over the Internet. So the special security needs of the public sector do not appear to mandate a PSN.)

The truth here is that much of the public sector has taken a “walled garden” approach to security. The idea is that you create a safe network within which public sector users can operate without worries of outside intrusion. Just like some secured government building, the security checks are made at the exits and entrances so that everyone inside feels safe to walk around with freedom and security. Unfortunately this isn’t really very secure at all. As soon as someone gets into the building they can access anything and everything.

So what do banks and security conscious companies do? They may provide a private network for employees but ultimately they make sure that data and systems that need to be secure are individually secured to the level commensurate with the data risks.

If the public sector took the same approach they could also operate on the standard internet like everyone else does.

So why are we doing this?

It is very hard to see any real justification for the Public Sector Network programme in its current form. So, how has it come into existence and why is it going ahead?

I can’t claim to know why the PSN programme happened but I can make some guesses:

  1. In the absence of technical guidance it is quite possible that the public sector decision makers didn’t realise that they might be able to make use of existing technologies to replace all the complex networking systems that are currently in use. From that standpoint the idea of setting up a programme to design a whole new public sector network specification may have made complete sense.
  2. Security always has a high profile and leads the public sector to demand the highest possible security standards in some things whilst completely failing to address the obvious issues like the unencrypted laptops, CDs and memory sticks that keep hitting the news. The security provisions in some parts of the public sector are so awkward that they practically force staff to ignore them in order to get their work done. Faced with pressures to be secure it is not surprising that non-technical decision makers probably ruled out the Internet as a viable option even despite then producing a specification that allows the Internet to be used!
  3. The need to cut costs has resulted in a massive focus on centralised purchasing and procurement as an apparently obvious way of gaining ‘economies of scale’. This principal is much more widely applied than it is understood. Consequently it doesn’t surprise that government decision makers might feel that it would be better value for money to procure a government specific system for the whole of the country, than let individual regions procure an internationally standard system locally. In reality the latter is almost certainly more cost effective than the former and a lot easier to organise as well.

Tuesday, 23 August 2011

COSLA Police Summit - 23 Aug 2011

Concerned by the way things appear to be going with plans for a single force in Scotland, I attended the COSLA organised “Police Summit” today in Edinburgh.

Here are some very brief notes:

  • It was reassuring to find that there were plenty of people there who were well informed about the limitations of the published reports presenting the various options. Colin Mair (Chief Executive, Improvement Service) did a particularly fine job of pointing out issues with the business case document.
  • I was shocked to discover that the leaders of Scotland’s main police bodies had seen nothing of the outline business case document. It put my failed attempt to see the document - as a member of the public - into perspective!
  • A running theme was that nobody knew what a proposed single force would mean in terms of accountability. Would it devolve power to local police or centralise it in the Scottish Police Board? Who would elect the members of the Police Board? How would the police interface at the local council level?
  • A number of people I spoke to one-to-one said that they recognised that we couldn’t stay with the eight forces model in the current economic climate. I asked why and discovered that they were just assuming that reducing the number of forces would reduce cost!
  • A number of the propositions and views seemed to suggest, more or less directly, that ACPOS (the Association of Chief Police Offices of Scotland) had historically acted as a barrier to change. There was a suggestion that, for some, the single force model had the attraction of bypassing the power of ACPOS. This provides a possible explanation why some may be pursuing a single forces model even if it doesn’t provide substantive cost savings over other options.
  • The consensus was that the SNP had decide to maintain its manifesto commitment to a single force and was unlikely to shift from this. However, there was also a suggestion that there might still be time to impact the government’s perspective on what a single force actually means.
 
Google Analytics Alternative