Developing Guidelines for IRM: A Grassroots Process in a Decentralized Environment Copyright 1990 CAUSE From _CAUSE/EFFECT_ Volume 13, Number 2, Summer 1990. Permission to copy or disseminate all or part of this material is granted provided that the copies are not made or distributed for commercial advantage, the CAUSE copyright and its dateappear, and notice is given that copying is by permission of CAUSE, the association for managing and using information resources in higher education. To disseminate otherwise, or to republish, requires written permission. For further information, contact CAUSE, 4840 Pearl East Circle, Suite 302E, Boulder, CO 80301, 303-449-4430, e-mail info@CAUSE.colorado.edu DEVELOPING GUIDELINES FOR IRM: A GRASSROOTS PROCESS IN A DECENTRALIZED ENVIRONMENT by Lore Balkan and Philip Sheldon ************************************************************************ Lore Balkan, Database Analyst for Information Resource Management at Virginia Polytechnic Institute and State University in Blacksburg, Virginia, has worked in computing and information systems for thirteen years. She is the Chapter Association Director and Region Vice President of the Data Processing Management Association, and is a 1973 graduate of the University of North Dakota. Philip Sheldon is Assistant Director of Institutional Research and Planning Analysis at Virginia Polytechnic Institute and State University, where he has also served as a systems analyst and a member of the mathematics faculty. He currently chairs the Virginia Tech Administrative Systems Users' Group. He received his Ph.D. in mathematics from the University of Wisconsin. ************************************************************************ ABSTRACT: In response to internal and external pressures, the offices of Information Resource Management and Institutional Research at Virginia Tech developed a set of guidelines for information management that have been adopted as University policy. This article describes the historical evolution leading up to the present situation, the forces that motivated the development of the guidelines, and the consensus-building activities that led to the acceptance of the guidelines as University policy. Virginia Polytechnic Institute and State University (Virginia Tech) is the land-grant university of the Commonwealth of Virginia. With almost 25,000 students and over 1,500 full-time instructional faculty members, Virginia Tech is the largest university in the state. It ranks in the top fifty U.S. universities in research expenditures, which total almost $100 million annually. Virginia Tech's computing capability includes an IBM 3090 Model 200 supercomputer, an IBM 3084, and several smaller mainframes. Access to the mainframes is provided by 3,000 terminals and many of the 12,000 personal computers on campus. During the late 1960s and much of the 1970s, administrative information systems at Virginia Tech operated in a highly centralized environment, which offered the benefits of consistency across systems and the potential for large-scale integration. Essentially all major record-keeping systems were IMS systems developed in-house by the central Systems Development office. The technical expertise required to develop and maintain IMS applications, the need for integration and security across systems, and the sharing of limited mainframe computing resources encouraged a "build-on" approach to existing systems and assured the continued need for coordinated and centralized database management. Counterbalancing the forces promoting centralization were policies and decisions that led to the distribution of data management activities. Central operational data systems were never operated as a "job shop," nor was a central pool of programmers maintained to support administrative units that needed access to University data. Instead, as each new system was brought on line, the responsibility for its management and maintenance was generally turned over to the user office, usually accompanied by additional support-staff positions. While Systems Development personnel had no formal responsibility to provide continuing support for the systems that they had developed, they were available on an informal basis for assistance in trouble-shooting and making minor modifications. Ongoing central support for these systems was provided principally by the Data Administration office, which was responsible for administering the IMS database system and the UCC-10 data dictionary that supports IMS, coordinating and assisting with production implementation, managing security, controlling IMS space allocations, and maintaining a system of shared tables. During the 1980s, the move toward decentralization accelerated dramatically. Programming and systems-analysis staffs grew in administrative offices across the campus, especially in support of the student, personnel/payroll, and accounting record systems, but also on a smaller scale in a number of other offices. While the costs of mainframe computing were paid by user offices out of their allocations of computer dollars (which they perceive as "funny money"), the other costs associated with such staff growth -- salaries, equipment, supplies, professional development, etc. -- were direct costs paid for with real dollars in the budgets of the individual offices. This shift in dollars promoted a corresponding shift in the mindset of the managers of the administrative units, a shift toward a much more decentralized point of view: "If it's my money being spent, then I'd like more control on how it's spent." Software developments played a role in the move toward decentralization, as new, less- complicated data management systems and languages such as SPIRES(R), FOCUS(R), and SAS(R) allowed operating offices increased independence from central support systems. Fourth- generation languages were eagerly examined by both the central computing-support offices and by the operating offices as potential new tools for maintaining systems and providing services. For the first time, purchasing sophisticated off-the-shelf software packages became a serious alternative to developing all major systems in-house. Motivating Forces The development of guidelines for information resource management at Virginia Tech should be viewed against the background of a number of campus events, trends, and initiatives of the latter half of the 1980s. One major force was the rapid expansion in the number of personal computers on campus, including many that were bought by administrative units that had never been heavy users of mainframe computing. Suddenly, offices that had shown no previous capability for using administrative data in unprocessed form were displaying appetites for data commensurate with their rapidly developing skills in word processing, graphics packages, spreadsheets, and databases. Another major source of motivation was the report of the University Self-Study of 1986-88, which identified several concerns in the area of information resource management. Specifically, it contained the following points: * A recommendation for the development of procedures for consistent coding, complete documentation, user training, and system-wide integration of administrative databases. * A suggestion that the office of Data Administration -- which was later renamed Information Resource Management -- take a lead role in the coordination, integration, and dissemination of the new wave of information technology. * A recognition of Institutional Research as a major player in the process of gathering and analyzing data to support planning and decision-making functions. A concurrent campus initiative was the commitment to move toward a "single system image," a vision articulated by the University's vice president for information systems.[1] The single system image model accepts the increased pluralism of "native computing environments" -- both in hardware (mainframe, minicomputer, or microcomputer) and software (statistical analysis, spreadsheet, word processing, database, etc.) -- and develops a strategy for maintaining "coherency in computing and communications." In the context of administrative information systems, the single system image implies the capability of moving large amounts of diverse input and output to and from a variety of native environments. Essential to this transmission process is the establishment of standard interfaces, based on intelligent data management systems capable of doing the required translation. Other motivating factors included the emergence of external standards[2] and the growing acceptance of "standard electronic operating procedures" for particular business functions in the private sector.[3] For Virginia Tech to anticipate, plan, and be responsive to these initiatives and reap the accompanying benefits, new levels of conformance to standard practices for data management across the University's information resources were imperative. The self-study played another significant role in the move toward guidelines through its call -- together with the University's positive response to the call -- for the development of a strategic planning process. It was generally recognized that such a process could place significant new demands on administrative data systems to provide management information to support planning; however, the ability of the University's decentralized data systems to provide the integrated data that were needed was suspect. The problems inherent in one area of the administrative data systems -- but symptomatic of problems in a number of other areas -- were highlighted in the work of the Facilities Data Base Task Force, which completed its six-month study of all University facilities-related data sources in September 1988. The task force found a proliferation of special-purpose systems operating totally independently of one another, using imprecise or conflicting data definitions, and offering very few options for sharing of information. The task force's report identified several essential standards for data quality and usefulness including rigorous definitions, standardization of data items, uniform sets of codes, and documentation of data elements and structures. Another motivating factor in the development of guidelines, itself a consequence of some of the forces described above, was the start of planning for a data dictionary. The immediate goal was to provide a tool for the inventory and documentation of the entire administrative data resource, while the ultimate goal was the development of a "university database."[4] A final event worth noting was the 1986 decision to purchase an accounting system to replace the IMS-based accounting system that was nearly twenty years old. This decision sent shock waves throughout the University administration, both for being the first commercial software package to be used for a major operational system, and for not being an IMS system. Unforeseen problems, delays, and expense also created a few aftershocks. The magnitude of the effort needed to configure the new system to the University's computing environment raised the consciousness of executive leadership about the need for communication between and consistency across data systems and about the associated costs when consistency is lacking. The Development Process The process of developing guidelines for information resource management began with meetings of a core group consisting of two representatives each from the offices of Information Resource Management and Institutional Research. Each office approached these meetings with its own agenda. Institutional Research representatives wanted to develop their responses to the self-study recommendations. They were also anxious to discuss issues of consistency and communication among administrative databases, as a consequence of both their traditional responsibility for data-gathering and reporting projects involving multiple databases and their prospective new role in support of the planning process. The perspective of the Information Resource Management office was exemplified by its recent change in name from Data Administration. Its focus was shifting and broadening from the day-to-day management of IMS databases to more global issues of accessibility, integration, and security of the University's information resources. It, too, had a self- study charge as well as an assignment to implement a comprehensive data dictionary. In addition, Information Resource Management representatives wanted to define their office's long-term role in the development of the "university database." They specifically wanted to discuss the possibility of using Institutional Research's student census file as a prototype. Early in the core group's discussions, a common thread among all of the agenda items became evident: the need for guidelines and standards in the management of all of the University's administrative data systems. It also became clear that a fairly distinct division could be made between guidelines and standards, in the sense that guidelines indicate what should be done and standards indicate how it should be done. It was quickly recognized that the issue of standards, with its attendant enforcement questions and other political problems, had the potential for causing the entire process to founder. Everyone in the core group agreed to put aside standards for the moment and to focus first on guidelines. The core group recognized the need for input and support from the individuals who operate and maintain the individual administrative data systems. For this they turned to the Administrative Systems Users' Group (ASUG), a loosely-structured organization whose members come from a number of different offices, including information systems offices (Systems Programming, Systems Development, Information Resource Management, etc.), system coordinating offices (Financial Systems, Student Systems, etc.), and user offices (Institutional Research, Budget and Financial Planning, Extension Information Systems, etc.). The intent of ASUG is to provide an open forum for communication and discussion of topics of common concern. Despite its informal basis and its lack of any official status in the University administrative structure, ASUG has made productive contributions to the University beyond being a discussion forum. Since ASUG began meeting in 1986, one subgroup developed COBOL programming standards and another provided significant input on requirements for an access-control software package that was purchased in 1988. In both cases, the proposals from these ASUG committees were presented to ASUG as a whole where they were reviewed, modified, and endorsed. The core group formed an ad hoc committee to represent ASUG in the development of guidelines. Its membership consisted of four representatives of system coordinating offices -- generally senior programmer-analysts -- and the EDP auditing manager from Internal Auditing, along with two members from the core group who coordinated the group meetings. After a series of meetings over a period of three months, characterized by a lot of thought-provoking discussion and a considerable sense of give and take, a guidelines document was finished. The document contained many of the original ideas of the core group, refined by the operational perspective of the ASUG representatives. In the true spirit of compromise, no individual on the committee thought that the guidelines were exactly what he or she wanted; they all agreed, however, that they had been given the opportunity to be heard in the deliberations. Consequently, they were all willing to support the document, both in ASUG and within their own offices. Perhaps the greatest concern expressed by the committee members was that they might be perceived as telling their own managers how information systems should be managed. Prior to presenting the guidelines to ASUG as a whole, the document was presented at a meeting of the managers of the various administrative data systems, including the immediate supervisors of several of the committee members. These managers, basically the most senior among the ASUG members, were considered essential to building the consensus needed at the operational level. The group suggested some improvements in wording and other clarifying statements and, without a formal vote, generally endorsed the document. Later, when the guidelines were presented at ASUG, the group reached the following conclusions: * The guidelines must be viewed as a living document; revisions will continue to be made as consensus dictates. * Many upper-level administrators are not currently fully aware of the responsibilities that the guidelines assign to them. An important function that should not be overlooked is that of educating and assisting these individuals. * Information Resource Management must move toward standardized interfaces and security strategies for decentralized systems and provide tools such as a comprehensive data dictionary for information resource documentation and reference. * Some of the tasks implied by the guidelines are not currently being done. To accomplish them, additional resources (for example, documentation specialists) and/or new strategies will likely be required. * Clarifications of responsibility and authority may be needed to ensure that the guidelines are followed. In particular, there is a need for clear responsibilities for data-exchange interfaces in the evolving distributed environment. This ASUG discussion concluded with an endorsement of the guidelines. The core group also initiated discussions with the assistant vice president for administrative affairs, two of whose responsibilities are directly relevant to the guidelines project. One is the ADMINSYS system, an online repository and reference system for University policies and procedures. The second is the office of Records Management, which was in the process of developing local records management policies and procedures to conform with Virginia's state policy. Initial discussions focused on how electronic records fit into a policy which is definitely oriented to hard-copy records although it refers to "information in any recording medium ... including data processing devices and computers." While the endorsed guidelines do not specifically address procedural issues for electronic records management, they do provide a framework for determining such procedural issues. Since standards and procedures would be developed based on the guidelines, it was agreed that the guidelines belonged in the ADMINSYS system, with cross references to other sections of records management policy. Next, the guidelines document was presented to all those administrators who have responsibility for major operational data systems. Referred to in the guidelines as the "data custodians," they have titles like controller, associate provost for student systems, and associate vice president for facilities. Generally speaking, they hold positions just under the vice-presidential level and just above the level of the ASUG members. All of these individuals were provided with copies of the guidelines and invited to attend a meeting to discuss them. Again, after only minor modification, the data custodians endorsed the guidelines. It is worth noting that in each meeting with the various constituency groups, questions were raised about how the guidelines would be implemented or enforced. Although such questions are clearly relevant and important, the group was encouraged to focus only on the principles (the what) initially. It was made clear that the standards and procedures that would later be developed to implement the guidelines would again progress through consensus-building forums. It was encouraging that the concepts embodied in the guidelines were viewed as both reasonable and needed at all levels of the organization. In fact, in response to a question about auditing and compliance, a representative of Internal Auditing suggested that he would routinely use this policy in his review process. In the final step of this informal "approval" process, the director of institutional research and the vice president for information systems (the executive-level supervisors of the members of the core group and the two top-level individuals most directly responsible for carrying out the self-study mandates on data management) met and discussed the guidelines. These two agreed that the guidelines were appropriate and authorized their inclusion in the ADMINSYS system. Of course, this is not the end of the story. Much work lies ahead, most notably the development of standards. On the software side, the guidelines clearly identify the need for centrally-supported data management tools to help with issues of accessibility and compatibility, and they specifically mention the essential role of a central data dictionary. Development work is currently under way on a dictionary product which will run in a relational environment and which is based on the ANSI IRDS standard.[5] Acceptance of these guidelines is an important first step for successful implementation of this data dictionary. Strengths of the Guidelines Perhaps the most notable strength of the guidelines, and also a key to the broad base of the endorsement that they received, is their management focus, as opposed to a technical or operational focus. Nontechnical, nonthreatening terminology was used intentionally to promote shared understanding. A second important strength of the guidelines is that the criteria for including a database or data element under the guidelines are based on the University's usage of information and not on existing system structures. The guidelines introduce a concept called the Administrative University Data Base (AUDB), which is defined as the logical aggregate of those data critical to the administration of the University. The guidelines specify that the AUDB include all of the following classes of data: * data relevant to planning, managing, operating, or auditing major administrative functions; * data referenced by or required for use by more than one organizational unit; * data included in an official University administrative report; and * data used to derive an element that meets the above criteria. The guidelines are further strengthened by their definition of information management roles based on function, without regard to current or future organizational structure. This gives the guidelines general applicability which will not become obsolete in a changing environment of ever-widening distribution and ever-increasing use of administrative information. The role of data custodian is ascribed to those administrators who are ultimately responsible for the data created and referenced within their particular area of responsibility. The data custodians are assigned the responsibility for conformance to the guidelines. Data stewards are those delegated the responsibility for data maintenance and dissemination as directed by data custodians. Individuals who have need for University data are identified as data users. Virginia Tech is considered the data owner of all University administrative data. The function of applying formal guidelines and tools to manage the University's information resource is termed data administration; the guidelines emphasize that this role is overseen by data custodians but played by all participants. The recent reorganization and renaming of Information Resource Management underscores the leadership and support roles that this office provides for the distributed data administration activities. Another strength of the guidelines is their breadth. Following the introduction of the AUDB concept and the explanation of the information management roles, the guidelines deal independently with data capture; data storage; data validation and correction; data manipulation, modification, and reporting; data security; data documentation; and data availability. Finally, the guidelines document clearly acknowledges the necessity of continued work on policies and procedures for the management of the University's information resource. In recognition of the need for adaptability and periodic review, it assigns the responsibility for maintaining and revising the guidelines to the Information Resource Management office. In addition, it emphasizes the importance of developing a set of standards to accompany and implement the guidelines. Lessons Learned Perhaps the most important lesson learned and a primary point of success in the process was the use of informal groups in the absence of formal organizational structures in the University. Such groups generally brought to the process a set of diverse backgrounds and experiences, but they were always able to identify common purposes and needs. For example, three of the key groups in this process -- the core group, the system managers, and the data custodians -- had never previously met together formally. Even ASUG, the most structured of the participating groups, has no officially recognized role in the administration of the University. However, its choice as the first constituency group to work on the guidelines was particularly successful. ASUG had a history of working on common problems in an atmosphere of mutual trust. Moreover, its members were the people who would be affected by the guidelines daily, as well as the individuals whom the data custodians would consult about whether the guidelines were relevant and worthwhile. Getting this group's participation and endorsement as a first step turned out to be an excellent strategy. Also contributing to the success of the process was the riding of the tides that were surging in the University community. The case for guidelines was built on a broad base of forces and events: the self- study, the purchase of an accounting package, and the need for policy on records management, among others. By capitalizing on the diverse array of motivating factors, the core group was able to convince a number of groups and University officials at various levels in the organization of the value of these guidelines. Another lesson to be extracted from this process is the importance of creating focus as a means of avoiding unnecessary controversy and distraction. This was the reason why standards were put aside initially in order to build consensus on guidelines. Debate and discussion could be focused on a limited topic in order to build a foundation upon which to base further work and more attention to detail. As in so many projects, one of the keys was to maintain reasonable expectations. This was important in at least two areas. First, the core group recognized, and articulated to the constituency groups, that neither total agreement nor the perfect document were likely outcomes. Consensus, however, was attainable, even though no one who contributed to this process was likely to agree with every point in the final document. Second, it was evident at every step of the way that the process was and will continue to be an evolutionary one. The document is not "cast in bronze," but is expected to continue to evolve in response to technological and environmental change. The virtue of patience was yet another basic principle that was reinforced during the process of developing the guidelines. At each stage of the process, the guidelines changed slightly, as each new constituency group brought its new perspective into the discussion. From looking at the end result, it is evident that seemingly minor modifications all served to strengthen the final set of guidelines. In retrospect, it seems unlikely that a top-down approach (which was the core group's first impulse) or any other less patient course of action would have worked as well. By acknowledging and illustrating data management problems without laying blame, and by describing desired outcomes and suggesting a path for achieving those outcomes, the core group helped to expand thinking beyond the limits of individual turf boundaries or existing organizational structures. As a result, the Guidelines for University Administrative Information Resource Management are not the "rules according to xyz department," but rather a platform that will support the variety of missions, activities, and responsibilities of the offices that provide for the global information needs of the University. ************************************************************************ Note: Virginia Tech's Guidelines for University Administrative Information Resource Management document has been added to the CAUSE Exchange Library (CSD0371, 4 pages, $.60), as has a related Virginia Tech document, An Information Infrastructure for the Future (CSD0261, 24 pages, $3.60). CAUSE members may order these documents by mail, fax (303-440-0461), or e-mail (orders@CAUSE.colorado. edu). ============================================================= Footnotes 1 He articulated this vision in a paper published by CAUSE. See Robert C. Heterick, Jr., A Single System Image: An Information Systems Strategy, CAUSE Professional Paper Series #1 (Boulder, Colo.: CAUSE,1988). 2 For example, the International Standards Organization's Open Systems Interconnect (ISO/OSI) model for data communications. 3 For example, vendors were positioning themselves to accept purchase orders using Electronic Data Interchange (EDI) standards. 4 The concept of a "university database" had been articulated earlier in a position paper developed by Data Administration. In general terms, the university database is a logical database (not necessarily a physical database) which provides a stable information architecture within which the authorized users of university information can obtain what they need to perform their duties. 5 The Information Resource Dictionary Standard (IRDS) was developed by the National Institute of Standards and Technology and adopted in October 1988 as ANSI X3.138.1988. ============================================================= SPIRES(R) is a registered trademark of the Leland Stanford Junior University, Stanford, CA 94305. FOCUS(R) is a registered trademark of Information Builders Inc., New York, NY 10001. SAS(R) is a registered trademark of SAS Institute Inc., Cary, NC 27511. ************************************************************************ revised 3/16/95 (jar)