LA's Move To Google Apps Slows As "Apps For Gov't." Announced
Several readers noted Google's announcement yesterday of Google Apps for Government: "The new version is a variant of Google Apps Premier edition, and includes the same core apps: Gmail, Calendar, Docs, Sites, Groups, Video, and Postini. Pricing is the same as for Google Apps Premier: $50 per user per year. The certification says that Google Apps qualifies for is called a FISMA-Moderate rating, which means that it's authorized for use with data that's sensitive but unclassified. In addition, Google says that it's storing government Gmail and Google Calendar on servers that are isolated from those used for non-government customers, and which are located in the continental US." This service might be just what the city of Los Angeles needs (though the price may not be right). LA started migrating months ago to Google Apps, and the process is experiencing some delays, as pointed out by reader theodp. "In December, Google tooted its own horn as it celebrated edging out rival Microsoft to win a high-profile, ironically Microsoft-funded contract to supply email and collaboration software to the City of Los Angeles. Now comes word that the search giant has missed a June deadline for full implementation due to lingering security concerns. Google downplayed reports of the delay, saying it was 'very pleased with the progress to date' which has allowed 10,000+ of the City's 34,000 employees to use Google Apps."
Maybe it is because I'm an old hand (and I'm speaking for myself here), but there is something about having physical control of data in house, in a data center. This way, unless there is a network intrusion, one knows where critical information resides.
With a cloud provider, all I have is a promise of security.
This isn't to say that Google isn't secure, but I personally trust good locks on the doors and all people who have access to the data having signed contracts more than just a piece of paper with a promise that things are secure.
I work in a relatively small government organization - about 1200 people, only about 350 of which are office workers - and I can't imagine us even remotely considering this. Anything that involves storing ANY of our data on a server that doesn't reside in one of our 3 data centers is automatically nixed by IT. Heck, if you've got a decent IT staff, setting up basic stuff like webmail and the like isn't even that difficult or expensive. Apache, Horde, Postfix, and Dovecot will get you mostly there for nothing more than the cost of a decent server ($2k tops) and the time of a staff member to set it up (and that time, for full-time employees, is typically already paid for, so you might as well use it).
"People who think they know everything are very annoying to those of us who do."-Mark Twain
...and Google knows it. The government is flourishing, huzzah!
The Army reading list
This is what you get, and what - currently - only very few federal agencies can afford:
An independent third party auditor issued Google Apps an unqualified SAS70 Type II certification. Google is proud to provide Google Apps administrators the peace of mind knowing that their data is secure under the SAS70 auditing industry standard.
The independent third party auditor verified that Google Apps has the following controls and protocols in place:
http://www.google.com/apps/intl/en/government/trust.html
Sure, it comes with a risk (do you have multiple redundant and trunked high speed internet connections?) but also with enorous freeing of public funds.
In my view, a win.
They who would give up an essential liberty for temporary security, deserve neither liberty or security - Ben Franklin
Nobody seems to have mentioned this yet, but it looks like at least part of the reason for the delay are "unforeseen requirements" that weren't in the initial arrangement with the city that Google's had to deal with. For example:
http://techcrunch.com/2010/07/26/google-city-of-los-angeles-apps-delay-is-overblown/
As for the delay, Google says that they are working with with the City of LA to "address requirements that were not included in the original contract." One example of these possible requirements that came up is that the LAPD wants to conduct background checks on all Google employees that have access to Google Apps data in the cloud. Doing these checks of course add more time to the adminstrative clock.
LAPD background checks on Google employees may very well be a reasonable request, but things like this add time to the schedule and weren't part of the original contract.
Well, it is simple.
(Trust me I'm not MS fan-boi.)
For the time period 2007-2009, my department spent an estimated $1,100,928 developing and enhancing two primary systems. This included all development and hardware costs. These systems take in between $300M and $400M per year in taxes and fees and are the largest of the kind by number of transactions processed in the US.
Vendor systems in this range have been quoted to us as costing between $4M and $6M outright with $500K to $800K/year in maintenance.
(Our accounting system - which is crap IMO - runs on a shared server and cost $160M.)
Here's how I came up with the figures.
Development Costs for JEDI System November 2007 - January 2009
Software
MSDN $50,000.00
Team Foundation Server $10,000.00
Janis Controls $20,000.00
Atlasoft Controls $20,000.00
Analysts
Specifications $138,622
Documentation $110,856
Training $52,100
Testing $146,178
Programmers
Development: $523,172
Management
Oversight: $30,000.00
Total: $1,100,928.00
Now, you can add in the overhead costs for servers and the personnel to cover the servers. We currently have 89 servers on racks in our server room. These servers must be up 18/6 and are absolutely essential during certain time periods. We have four staff members running the servers and an additional six staff members maintaining our 800+ workstations, LAN and six remote locations.
I’m a taxpayer also, and cannot stand to see money wasted. If I were to move to the cloud – the ultimate in vaporware IMO – we’d be moving to a service level that is set by the vendor and not in our control. We already have some services moved to the cloud. IIRC, the department spent around $1M on a vendor-hosted system that has been less than reliable and very expensive to maintain.
The Kai's Semi-Updated Website Thingy
Give me just one example of sensitive data that gas escaped from a major cloud service (Google, Amazon, etc), and I'll give you 10 more examples of data that has escaped from an incompetent IT organization's in house systems. Do *your* in house systems allow you to configure ALL your user's desktops and laptops to be completely disposable, with no other software necessary than a recent version of Firefox or Chrome? Never had a DBA accidentally botch a transaction, do your users never accidentally delete email, never had a spearphishing attempt slip though your spamassassin filters? Never put off a software upgrade because your users were to busy for downtime? Never had a backup fail?
Let's just admit it's all the politics of control, which is fine. Personally, I'd rather not do the shit work of reading log files, restoring lost email and files, forgotten passwords, and cleaning up the mess when a user gets phished.
Give a man a fish and you have fed him for today. Teach a man to fish, and he'll say "WHERE'S MY FISH, YOU IDIOT?"
...and get those people to agree to a police background check. Imagine if you were an offshore developer in another country, and your line manager casually dropped into a conversation that the LAPD want to audit you. Now scale that up to the presumably hundreds/thousands of google personnel who potentially have access to that data.