logo

NJP

Inside Software Factories: Government's Innovation Accelerators

Import · Dec 08, 2023 · video

hi everyone I'm Adam mazmanian executive editor at NEX FCW and your moderator for today's Tech Spotlight inside software factories government's Innovation accelerators underwritten by service n during today's program we'll explore the people processes and Technology required to run a successful software Factory and I'm joined by a great group of subject matter experts we have Lily ziki uh Deputy Chief Information officer for information Enterprise at the Department of Defense and gain Nazareth director solution Consulting Air Force and DOD forth estate at service now and I'm hoping to turn to each of you uh for some quick opening remarks on um you know your work and and how it maybe intersects with software factories and certainly with with Innovation and software um and Lily I'd like to start with you all right thank you so much uh for having me here I really appreciate this opportunity to talk about our work about software modernization and software Factory which is an integral part of it um as you know um we've had the software U modernization strategy since uh early uh 22 I think it might have even been signed out in 20 late 21 uh and then March 2023 uh we uh released our uh implementation plan for the for the strategy and really one of the fun foundational goals as you've noted um is the software Factory ecosystem and what that really means is a network of software factories that we would want to have and not just to have them but really ultimately our goal is to have software development delivery and update pipeline at speed of the mission need and really uh to have these software factories closer to the user um and where the needs are and really that was one of our um software modernization strategy initiatives that we've um been going uh down the road of and um so I'm I'm really glad and I'm honored to be here to discuss um have the opportunity to discuss it great thanks LLY and gain I'm going to ask you for some opening remarks as well yep absolutely and thanks for the intro Adam and thanks for having me uh and and super grateful to share the stage with Lily um I I'll say this I've I've been in the text Page for about 18 years now uh my first half uh I supported a lot of commercial customers uh you know some the Enterprise large large customers I've obviously always been in industry but over the last eight years I've focused primarily on the dod right Air Force and defense defense agencies purple purple estate or forth estate right um so I think I've got unique perspectives on both ends and I'm super excited to to hear what Lily has to say on that as well so grateful y let's just let's dive in um I I first became aware of the software factories as they as they were starting to launch a few years ago and uh from the point of view of a reporter software factories were great because they were highly entrepreneurial about press about getting attention and they had to thrive and one of the ways they wanted to I think build um uh build a kind of following or or or showcase their own importance was uh being getting out there doing events doing press so we love the softare factories we thought they were very very cool um but they're also you know part of the Department of Defense and they have to execute on the larger goals of the Department of Defense and so as the software strategy evolved these factories are be becoming a big part of it so I guess my first big question Lily is how do you get these sort of like some quasi independent freewheeling but mostly entrepreneurial you know shops to kind of work handin glove with the sort of command and control that that you know you expect from the Department of Defense I absolutely love how you couched it I think you sort of have alluded to some of the answers because one of the beauties of the software factories is that they are leaning forward uh they're Innovative uh this is a new way of doing software and new way of U you know innovating and bringing software at speed um on a continuous basis continuous deliveries what we call it a pipeline so we don't want that to stop and really the software factories brought forth um our ability to really see in real terms that it can be done um in at speed the Kastle runs were the F the first one but now we have up to 50 actually uh software factories and I'm sure we'll talk about you know how do you manage all that Etc but I think the balance is we are really uh through the our software modernization implementation plan as you know we've laid out some key aspects of it one is really laying out guidance and standards which we're working towards right now in some cases we've already brought forth the devops or the development Security operation really what these software Factories do is bring these um aspects together with the user input so we are already working um we've you know done reference designs St Cyclops reference designs activities tools everything that supports our ability to have sort of a consistent um um software Factory foundational software Factory uh implementation uh and adoption across the board they're all not going to be cookie cutters but at a minimum we're laying out these uh foundational guidance for for the software factories in addition we are also really focused on doing software Factory inventory because to your point uh we don't want a proliferation of software factories where you know 10 of software factories are doing the same exact thing I think you all hear us use the word rationalization a lot with cloud with systems networks everything just like anything if not managed if not metrics appropriately if not tracked and if not uh really um uh looked after in a real way um this has an opportunity to sort of get out of hand but I think everybody recognizes that so we're you know conducting a a good uh software inventory across the department to sort of establish what what is the Enterprise criteria so we are not there yet but that's one of the things that the strategy sets out and that we're going to do uh which will help us and appropriate metrics of course accountability is always imperative in this case and then um the other piece is really establishing sort of the right uh work roles for software because that's one of our biggest challenges is you know you can expand as much as you want the software factories but if we don't have the right skill sets and the right uh people at deployed across uh that's going to be a challenge so the you know our ability to have the right Work World r the right designation and this this is working across the department with the um you know our dodci Workforce team but as well as other uh organizations to make sure that we can you know hire train retain our you know the right work work skill uh for for this uh aspect so I think this is really the formal way that we're going about it through the strategy and through the software modernization SSG but as we are doing this and as we're sort of working on the formal guidance and structure Etc it at a Grassroots level the software factories recognize this as well and they're actually forming have formed a coalition of software factories and they're getting after the same kinds of things so it's really beautiful to see actually the top down and the bottom up are sort of thinking about the same exact thing and we're cold Lessing to make sure that we have a consistent um approach across the board and one of the things that the movement to the soft to the software strategy kind of represents and it's like the it's a defense metaphor doing something complicated they say it's like turning an aircraft carrier around and one of the aircraft carriers you're turning around is is going from a kind of like waterfall based delivery system to a more agile continuous delivery and so G I wanted to ask you what's that what is that a great signal to get on the industry side that this is really absolutely absolutely and amplify on that a little bit please oh absolutely and Lily spoke about structure consistency standardization ecosystem that's that's going to be extremely beneficial both to the dod as well as industry right so obviously DOD it's pretty obvious right if we can if the software factories can share code artifacts processes guidelines it it it will bring about a lot of efficiencies in cost savings and process savings and in levels of effort and all of that good stuff right but on the industry side it helps us too and and I'm speaking as an oem right original equipment manufacturer we build software we build software for the dod and and when we build software for the dod we intentionally build a generic because we know every DOD or that uses our software will configure it they'll customize it right now based on Lily's point if we kind of standardize right what we could do is just out of the box we can build build tailor made software Factory products right so we can just kind of plug and play it makes us sticky as industry right we we provide more value to the dod and then obviously all the other efficiencies that come about it so it's it's great it's definitely phenomenal I like to see more of that great and we touched on this a little bit um but I'm hoping Lily you can drill in a little bit more on the sort of um how what what's entailed in bringing the software factories um up to up to like a you know creating some minimum standards how does that communication process work you said there there's a lot coming from the bottom up but also you know can you talk a little bit more about what's coming from the top down uh yes so I think our foundational um governance and I always talk about you know I don't like to talk about governance forums but we do have um a forum the software modernization uh senior Steering group uh myself with uh my um RNE uh research and engineering and acquisition uh Community uh leaders that we we co we try chair this group uh but they have a an incredible group of folks from across the department that are experts that are part of this working group that includes uh representatives from the software factories and from the military departments and from the com all of the components that participate in this group so this sort of Keeps Us aligned and continue to walk this software modernization strategy plan that we've laid out which I spoke about um a few minutes ago to be able to for us to be able to go um Implement in a methodical way and have the right metrics and the right um criteria uh develop the right criteria together as the software Factory Coalition also on their own are cesing and developing some of these standards that they bring into this group so we we attack it from different uh perspectives not just a formal governance but we welcome the fact that they are coal lising together and we're going to funnel that information into um our formal process and ultimately we will surface policies official policies and guidance that will enable and ultimately it is the intent is to enable to continue to uh push forward this leaning forward kind of innovative agile process even I will even tell you our software modernization um implementation plan is only set for fiscal year 23 and 24 which we're already done with 23 and already begun 24 and we're in the process of developing our 2 5 and 26 um uh guidance or implementation plan which will include quite a bit of these things as you see we were doing uh the inventory right now and all of our work together with the software Factor so this is how we manage it's not a one-size fits all and we certainly don't want to curtail the incredible Innovation that's been going on and I wanted to follow up did The Innovation that was sort of took place independently at the software factories you know before the software strategy was finished did the efforts and activity of the software Factory kind of show you what was possible a little bit did it guide any of that sort of strategic development oh absolutely I mean it it's as we were forming the software modernization strategy as you know you know about seven years ago as the idea of software Factory sort of popped up with the kessle Run group um those two were sort of shaping together and cold bling so I I believe um that leaning forward and leaders actually uh going for it and and supporting it in a sense uh allowing um the software factories to do what they need to do to deliver uh products and and and continue to do what they're doing helped us actually form and formulate our implementation our strategy and implementation guidance to where uh it now solidifies um the fact that we really need to continue to flourish the uh the ecosystem as we call it uh you know the network of software factories because it's not like I said it's not a one-size fits all but again I think we've as we continue to grow the software factories we're learning and we're modifying right we're uh taking into account Lessons Learned and I really believe this is going to uh show up in some of the policies or guidance whatever form it's going to be ultimately it's going to uh translate into that but ultimately those folks that started the leaders that supported that helped us you know Run start this engine uh going and and we're you know we haven't stopped ever since then and gay I wanted to flip it to you for a sec this must be a familiar business challenge in the sense that you want things to come from the bottom up but you don't want chaos you still want standards and Enterprise govern so uh H how how do you balance you know in your organization in your work absolutely and and I'll say this right like we we always talk about standardization in Industry we talk about in government you know but to your point unless we have that strategy unless we have policy guidelines communication training uh and that comes from top that's not going to happen right so I love the approach Lily you're saying amazing things this is this is really really exciting I I feel like we we're on the right track to kind of standardizing okay great and I also wanted to I got one more one question about kessle run in particular it's been mentioned a few times kle run was kind of formed um kind of out of frustration with a system with a particular system that wasn't working and um they really went after a very large program and I wanted to ask you do you sort of see software factories going after these like really really big the big hairy problems as the as the software developers like to say or are you thinking of them as like app kind of factories like where do you how do you see them fitting in size it'sit all there multiple opportunities for them to contribute it's all of the above honestly uh we have complex uh software issues and we also have uh I mean the way I look at it I mean to to have a um you know easily accessible navigable uh websites for an increasingly mobile Workforce for for example uh but then now you have embedded you know weapon systems that have that are software machines basically so we are uh in a really highly softwar driven world and we really um believe that our intent is really to have software factories capable of handling both big programs and smaller projects it all depends on the spe specific needs and requirements because we are about delivering capability at the speed of need and you know it it's just it's that is really ultimately our mission um and uh that's going to drive that so to me again it's not one-size fitall it's not cookie cutter I think the thank God for the Kastle runs right they've set the way theyve really um they're they're they're the trend setters But ultimately now we want to make that common place right we want to have as many software factories as we need to meet the mission but also we don't want it to go off the rails where we're now everybody wants their own siloed software Factory that's that is really where uh the oversight and governance comes into play but we have really not seen that um yet and we're still in the learning and forming uh phase so um I really believe that you know the trend setters uh will continue to teach us more um as we you know as new ones come into play just that I think with Castle Run they were uh their their organizationally were based out of hanscum Air Force Base but they decided to locate I forget if it was in Kendall Square in Cambridge or in Boston but they wanted to be around the Hub where the talent was yeah and I wanted to sort of ask like is that still going to be a feature and I think there are others in Austin there are some others in other high-tech corridors is that going to continue to be a feature of soft factories as they uh the ecosystem proliferates to be honest with you I think it the need uh the requirement is going to dictate how software factories are going to formulate I I really I I believe the trend is that as you call it so sort of Co lising in a common place uh where the need is really where uh we're seeing and what we believe is going to be more useful where the user is very close and that you have the closer communication ultimately the software um uh modern software practices and Dev psyops all of these practices are about bringing the development the cyber security the operations the user feedback all of it sort of uh in the same environment and whatever helps us do that is really going to be what we're going to implement but again we have very different uh military departments with different missions uh across the board the department has various missions so it's hard to say like one way or another and that's why you have we have variations of uh formulation of software factories and ultimately I think we'll hone in what is at the Enterprise level what are the commonalities that we're going to standardize or we're going to you know put a stamp on as a policy matter but then what are the things that we're going to Fed and allow that growth and Innovation we don't want to curtail ultimately I continue to say like my job is to enable my job is to remove hurdles um so I think that's that's how we will approach it but again we're still rent learning so we'll have to see and and and G you know in the workforce piece you know people who do this kind of work they don't necessarily grow on trees you can train them up but uh in terms of in terms of trying to find your Workforce um any thoughts any thoughts from you there I mean it it's no secret right that the top Tech Talent they typically flock towards Tech hubs right you're talking about Boston and dcan Francisco right uh it's it's no secret they do that so uh but with actually adding software factories in a lot of those areas I think the software factories will have access to some of the the best talent out there right that's quick and easy access I think that's one as aspect of it and the other aspect is it helps partner with industry even more right um and I think that goes a long way as well yes we are we live in a virtual world we have access we can do things across the country no doubt about it um but but the close proximity can help a lot especially when we talking about piloting we talking about prototyping we talking about building uh applications that kind of we can test and try before we go to market or deliver value or or or or provide cap ility in in the hands of you know the warf fighter right so just the proximity will definitely help with some of the tech hubs for sure and and a quick comment uh Adam on the previous uh question about you know starting small and expanding the castle runs of the world and some of the other factories yes they can handle large ones but it's important to note that they started small right they they got those wins on the boat they got those runs on the board that's one aspect of it and the other one is just in doing that they were able to kind of formulate and get their processes their strategy their execution and their security in order right now you have that foundation so now they're able to take on some of the larger projects so I think that's an important uh piece to kind of acknowledge as well and that's a big challenge right where you know maturing an innovation driven organization um gain and I'm wondering if that's uh something you can speak to a little bit just how do you you know people say capturing lightning in a bottle I mean it's it's it's got to be hard to do to to and sustain those wins over time absolutely it's repetition it's process it's Foundation it's getting the basics right right again like starting small getting that foundation and Lily mentioned right having having those guidelines having uh policy having all that in place to kind of nurture that Foundation uh I think is key uh you don't do big things right from day one right it takes a while and and Lily I want to shift back to you and kind of shift gears a little bit towards the some other elements of the strategy um the software Factory ecosystem plan is listed just below the goal of accelerating adoption of Enterprise cloud in the in the soft in the strategy and can you speak to how the factories and the cloud adoption plan are linked do you want the factories to be early adopters or even evangelists for the Enterprise cloud and maybe I should uh caveat by saying to people who are don't know if anyone who would watch this uh doesn't know you know the dod is Fielding a large Enterprise cloud with four big vendors and they are actively trying to get um users uh in the services and DOD Central to shift their their Cloud workloads to the the new uh the new Enterprise Cloud thank you so much for that setup I I believe um you know initially when we started uh our uh Cloud Journey um everybody thought you know Cloud adoption and that's you know sort of the end all be all but really that was just the beginning cloud is an enabler that is going to fuel uh these modern software practices in you know as well as uh the software factories ultimately it's going to provide the global access uh the scalability the compute fabric that we need so that's really what what connects these two uh in a big way right without the the cloud um Foundation or backbone our ability to do the software uh modernization and the you know all the great things that we would want the software factories to do in a scalable and a very um basically continuous basis is is not going to happen so that's really the the connection and obviously with the jwcc The Joint War fighting Cloud capability which is the the uh Cloud capability that you me you mentioned jwcc absolutely we would want the software factories to uh utilize it to the maximum extent possible but not just the software factories it's our entire department as you know we've released our jwcc guidance and you know within a year the department has actually successfully um awarded uh several task orders uh beyond our expectations so it's been um it's been it's been great um but ultimately I think it's not about just moving to the cloud what does the cloud enable us to do and it is really what we're talking about here with the software modernization and the defc Ops uh practices uh and the software software factories being able to scale and automate and do the um sort of the um analysis and and uh AI ml capabilities that that they would need automation that they would need uh to continue to be uh doing and delivering in a continuous way and gain want to chime in on on on the cloud piece yeah um you know I think the whole purpose of software factories is to deliver at the speed of relevance right and in today's world there's no way we can do it without cloud right think about you know the benefits of just having the cloud out there right you you know you don't have to worry or software factories don't have to worry about Hardware installation operation and maintenance you know hatching sing Disaster Recovery data backups let the cloud vendors do that right that way the software factories can can focus on delivering Mission applications uh so I think that's a big thing and and I think everybody's agreement Cloud's the way to go right and I I get their different classification levels and I know we can build for that that's something that's coming I mean you see all the major Cloud vendors uh they are looking at impact level four impact level five impact level six and Beyond U so I think we're headed in the right direction with that and I guess um maybe jump ball here but it seems to me that once you have the software factories embracing the jwcc with it's only four vendors four Cloud ecosystems the work that they actually do will just be that much more sharable across the defense Enterprise is that is that correct and and is that seems like it would be like a like a big goal to have things that you can just kind of lift and shift to other environments without too much customization I that's absolutely I mean one of the goals is uh to have the uh diversity uh but also the ability to have optionality right um and and enable the software factories to have various options to you know to um depending on the the capability they're trying to field uh so I I really believe uh that one um the interoperability piece you talked about or you know sharability but also so it provides optionality uh for us just because of the vastness of the mission of the department okay well we're closing in on the end but I want to I got one more question that I'm hoping to uh get some uh discussion on uh one of the key security goals of the plan is validating the cyber security of DOD systems on a continuous basis The Continuous uh authority to operate and is this an area where you'd like to see the factories uh lead Lily oh absolutely they they already are um to be honest because they are they're sort of have to implement that right in order to deliver um approved products um that are authorized to operate um at the speed that they're moving they're working hard but the process right now is not um as fast as we would like it to be um that's really why the you know the continuous uh authorization to operate um issue is one that is really near and dear to our hearts and our cyber security um uh Deputy CIO the sizo is working with us as also um the software uh Team from from my team and the department uh because devop software development processes are part of enabling this so the integration of the development the security the operations so that SEC piece the security piece is really what we're talking about you know while M making sure that we maintain the Cyber risk management framework controls Etc we need to speed up our ability to get the approvals what are we doing towards that and we're still continuing to work it you know we're one we're uh developing through our um software initiatives uh the devs Ops criteria to make sure that we we don't deviate from the risk management framework uh requirements but also how do we speed it up monitoring is part of it um and then also uh reciprocity so if we've done a certain kind of approval once let's not do it a hundred times so uh we're really working in different ways to make sure that we speed up this um authorization process because ultimately to have a continuous pipeline of delivery you have to to have a continuous approval um environment cyber security environment but making sure the Cyber posture uh is maintained or improved every time but our it's our perspective you know as The Advocates of deite Ops and CTO uh really that actually doing it this way and integrating the development the security the Ops and you know having a continuous monitoring uh approach is actually going to make us even more resilient and more cyber uh secure uh so really we are uh very hard working hand inand with our sizo and the cyber security DCI um as both aspects sort of the two sides of the coin um are um working this hand inand to advance but this is this is imperative right to uh enable the uh uh software factories to be as effective as possible and really deliver in the way that we really would like them to at the speed we would like them to we need to get this moving and there's a reason we call it devs Ops as opposed to devops right I mean security needs to be ingrained to your point Lily needs to be ingrained in that and I I'll offer some of my experience both working with you know commercial customers as well as DOD obviously security is important on both sides but whether DOD has gotten it right and they've done a a job is they actually have security teams as a part of the process right so when you're doing requirements security requirements need to be a part of it when you're doing design of the system security needs to be taken in consideration design implementation testing everything everywhere security needs to be a part of right and if you do it that way you're able to kind of bring about a lot of efficiencies I'll give you guys one example let's say let's say a softw factory is working on a small application and and that small application doesn't have a database right we we we we maintain that the authentication is strong but doesn't need a database at this point maybe when we doing a security testing when we do pen testing or scanning or even SQL injection testing we may not need SQL injection testing because we don't have a database now security teams may not know that unless they are part of the process right so just security being a part of the process can bring about a lot of efficiencies we we still make maintain security we still maintain compliance uh but let's bring out software quicker while being a part of single team okay well I think we're going to have to wrap it up there that's all the time we have today but a big thanks to our expert speakers for today's conversation and a big thanks to service now for underwriting today's program uh if you miss part of the broadcast or want to share it with your colleagues keep an eye on your email we'll send you the link to the ond demand program and other resources shortly for next FCW I'm Adam mazmanian have a great day

View original source

https://www.youtube.com/watch?v=yExwpO38Fz4