* Required information |
Phase |
| |||
|---|---|---|---|---|
Status |
| |||
Start Date | Enter the starting date of your initiative, by clicking on the calendar icon bellow - when you started to work on different step of the initiative
| |||
Initiative name ID Provided by DT PMO | 12261: Labware Composite upgrade | |||
Description of the initiative | The upgrade of Labware Composite project is required in 2023 to be aligned with NIST/CMMC (The Cybersecurity Maturity Model Certification) standards. The current Composite Labware environment is running software that is outdated and does not meet the requirements put in place for CMMC.
The project will also include the assessment of a future upgrade of the Labware software from version 7 to version 8. 421K Pre-Cost Analysis | |||
Domain & Product | ||||
Requested Domain Journey / Platform |
| |||
| Involved Domain Journey/ Platform |
| |||
Initiative Ownership | ||||
Digital Technology Partner | Enter the Digital Technology Partner, using « @ » for user attribution (if not known refer to the DT Playbook in "Relation with GBU & BSA" chapter) @ | |||
Product Manager / Service Delivery | @Martina Gatti + @Jean-Pierre Genet (PM), @Pedro Falcao (SDM) | |||
Roadmap & Key objectives | ||||
Roadmap | Upgrade the Windows OS, SQL Server and Citrix versions to the latest versions supported within Solvay standards. Implement encryption from Citrix client to server that meets CMMS requirements. Stabilize environment by reducing the downtime caused by Citrix connectivity issues Improve performance of the Labware application and make key new features available for the business. | |||
2023 Digital Technology Key objective | ||||
Priority | P1 to required to be aligned with NIST/CMMC (The Cybersecurity Maturity Model Certification) standards. | |||
Understand: Why is this initiative proposed? What are the consequences if not done? What are the new capabilities expected?
|
|
* Why is this initiative proposed today?
Explain what are the motivations and the expected objective behind this initiative/ what are the consequences if not done?
| Currently the Composites Labware environment is running outdated and unsupported server software which creates a major risk and does not meet NIST/CMMC (The Cybersecurity Maturity Model Certification) standards. The goal is to upgrade the software to the latest and fully supported versions. |
What are the new capabilities expected?
| The Labware environment will be running on up to date and supported Windows OS, Citrix and SQL Server which is align with NIST/CMMC (The Cybersecurity Maturity Model Certification) standards, as well as improves the stability and performance of the servers. |
What will it replace? Is it a new solution or an existing one?
| This is an upgrade to an existing environment within the Solvay Landscape |
Who are the future users?
Identify the future users (BU, sites...) and population concerned
| The user population will stay the same which includes the Quality Labs and Shop floor across all sites of Composites GBU |
What is the number of users impacted?
| 900 Users across all sites of Composites GBU |
What about the Business Needs?
What is the value of the initiative?
Financial Business expectation (ROI, benefits, savings,...) + Qualitative Business expectation (business value, market fit, visibility,...)
Limit the exposure / risk of outdated non supported software. Alignment with NIST/CMMC standards |
How does the product / deliverable align with the business goals?
| Alignment with NIST/CMMC standards which is required by key customers (ITAR) |
Are there any challenges in developing the product?
| Resource availability and constraints based on conflicts with PO2 |
How will we measure success?
| Performance improvements, reduce server down time and aligned with NIST/CMMC standards. |
Please duplicate this template iand contact the SIP teaùm in order to get your corresponding folder. Then, for the envision phase, answer to the initiative card tab and to the 7 high-level questions in the "Security Scoring" tab. These questions will help the SIP team to determine the level of cybersecurity & compliance support you will need. Please contact the team by email: @SIP_team@solvay.com
If not able to answer yet, explain it at the Envision gate and it will be the DTLT to decide if green light or not considering with the high level of uncertainty
If your initiative is working with data, please select the domain which is impacted:
Estimated Delivery phase start date*
| Estimated Delivered end Quarter* Q4 2023 |
What is the coherent money to commit on the initiative?*
| 2023 (in K€)* | 2024 (in K€)* | 2025 (in K€) | |
|---|---|---|---|
Estimated size of investment (high level) | 391K |
What is the coherent run and build commit on the initiative?
Only run cost impact - TCO over 10Y will be finalized during the strategize phaseEstimated run costs (estimation high level) per year on xxYear (xx= duration of the contract if known) Current recurring cost for servers is $13.5K a month (162K annually). The new server environment will increase to $19.9K a month(238.8K annually). | Type of savings expected /year for DT (Ex: Contracts, FTE, ...) |
|
Please add here the required envelop needed to work on the strategize phase - if needed (maximum 40k€) :
What skills and talents do we need?
Here kind of skills required in order to start to fill the Capacity Planning. If name already available please write the name
| Jose Carreira (25%), Harrison Blackwelder (25%), Mark Reece (15%), Michael Manuelle (15%), Loic Romagny (10%), Cedric Armand (10%) |
1.12. Methodology to apply (refer for Accolade)
Do you think if your initiative is compatible with a waterfall approachor with an agile approach?
|
If the initiative will be done in Agile methodology, please contact during the strategize phase Nicolas LOVAGNINI
Understand: How this bring value? Which pain points will it removes? Will it be delivered in Agile or Waterfall?
|
|
Now, we can move on to the Solution space
What is your list of scope if waterfall initiatives (technical, functional & organizational) / deliverables foreseen? What are your list of Epics if Agile initiatives?
| Mandatory actions * (please contact them together if possible) | ||
|---|---|---|
Description of the action / task | Contact | Document & examples (please make your own copy and insert new link here) |
Contact each relevant pool lead to book resources in the capacity planning tool
| Complete Capacity planning tool | |
Complete Accolade
| Claire Bazin | Complete Accolade |
Review with Enterprise Architect the actual solution answering the objective
| Complete Architecture Impact Analysis (AIA) | |
Check you have confirmed the involvement of each platform | Revert to SDM of each Platform | |
Identify security needs (Confidentiality, Integrity, Availability) and define security measures to be implemented by the initiative team
| Complete the security questionnaire in “SIP Support tool” | |
Support for budget estimation (via the Workload & Cost), Financial evaluation (Total Cost of Ownership over 10Y), saving validation
| W&C: to be filled in to Accolade in preparation phase TCO over 10Y: | |
If Data Governance is required: identify the business objects
| Data Governance Strategise for Initiative Briefs | |
| Optional | ||
If any relation needed with a supplier
| ||
If it concerns a key supplier, a sourcing strategy has to be defined
| ||
If conformity by design is required
| GMP (pharma), ISO | |
What do users dislike about the current solution?
Applicable when a new solution is developed
| Not applicable - no product development |
What tools or features do your users wish to have?
| Not applicable - no product development |
What value will it add to the user´s lives?
| The upgrade of Labware Composite is required in 2023 to reduce security risk and vulnerabilities that comes with running unsupported server software and to be aligned with NIST/CMMC (The Cybersecurity Maturity Model Certification) standards. |
What alternative do we have?
| None |
A standardised process for creating and introducing services. It may sound basic, but Service Design and Introduction should be considered at the very beginning of the project.
Who is the service owner?
What is the target?
Which platform will maintain the new service?
What are the risks (refer to Risk analysis matrix in Accolade)?
Are there any internal / external constraints and what are the preventive actions associated?
Identify risks and mitigation plans
Possible Resource constraint of DT Project Team members based on conflicts with PO2 Business user availability during testing phases |
What is the qualitative assessment of Hardware/ Data processing/ Project’s contribution to Solvay One Planet?
- Is the business ambition you will support improving or not sustainability? - Will you increase or decrease the number of hardware we need to operate? How much ? - Will you generate or transfer an important amount of data, especially videos? How much? |