ITAC Internal Home Page

ITAC Agenda and Meeting -- February 10-12, 2004
Indiana District Office -- Indianapolis, IN
_____________________________________________

arrow icon Meeting Logistics    arrow icon Attendees
arrow icon Town Meeting
arrow icon Agenda and Meeting Minutes
arrow icon Tuesday Notes    arrow icon Wednesday Notes    arrow icon Thursday Notes
arrow icon Action Items

arrow icon Constituent Reports:

arrow icon Data Chiefs Report
arrow icon District Chiefs Report
arrow icon Study Chiefs Report (Sonya Jones)
arrow icon Administrative Officer's Report (Donna Hector-Sabin)

arrow icon Attendee Information

Following is a list of ITAC meeting attendees/invitees who attended (accepted invitation), were absent (declined invitation), or delegated an alternate:

Brian McCallum

Data Chief -- Atlanta, GA

Absent

Greg Allord

Chief, CAPP -- Madison, WI

Absent

Jessica Alvarez

NR Regional Computer Specialist -- Reston, VA

Attended

Margaret Bunch

Site Administrators Rep -- Carson City, NV

Attended

Steve Glodt

NWQL Representative -- Denver, CO

Absent

Joel Johnson

Data Base Management Systems -- Sacramento, CA

Attended

Sonya Jones, Chair

Studies Section Chief -- Austin, TX

Attended

Katherine Lins

Chief, OWI -- Reston, VA

Attended

Charlie Merk

Chief, WICAS -- Reston, VA

Attended

Jeff Stoner

District Chief -- MN

Attended

Susan Trapanese

Chief, NWIS -- Reston, VA

Attended

Sonja Sebree

World Wide Web Development -- Lincoln, NE

Absent

Sandy Williamson

WRD Technical Offices -- Tacoma, WA

Attended

Marilyn Billone

ITAC Executive Secretary -- Reston, VA

Attended

Jim Nicholas

District Chief, MI

Attended

Tim McElhone

Acting, NR Regional Computer Specialist -- Lansing Michigan

Attended

arrow icon Invited Guests:

Tom Wood

GIO, Computing Infrastructure Unit -- Reston, VA

Attended

Karen Klima

GIO, Enterprise Web -- Reston, VA

Attended her session by phone

Paul Exter

Lead IT Specialist -- Baltimore, MD

Attended his session by phone

Maryjon McAvery

GIO,Information Security Team -- Reston, VA

Attended her session by phone

Steve King

Regional GIO, Eastern Region -- Reston, VA

Attended

Scott McEwen

CR Regional Computer Specialist -- Lakewood, CO

Attended


News Items


Agenda and Meeting Notes

Audio Bridge Information:

Call 650-329-5199
Enter conference code 1419 (good for all conferences), followed by #

The conference has been set up for Tuesday through Thursday, 2/10/04 - 2/12/04, from 8:00 am to 5:00 pm EST, for five participants. If you have any problems accessing this conference, please call 650-329-4444 for assistance.


Monday, February 9, 2004     --     ITAC travels to Indiana District Office
Tuesday, February 10, 2004
Time Agenda Item, Presenter(s), & Expected Outcome
8:00 am Welcome and Introductions
Presented by: Sonya Jones
Roundtable introductions
8:30m District Chief Presentation
Presented by: Jim Stewart
  • Jim introduced Indiana
  • IN DO overview and its accomplishments
    • 50 employees and two study sections
    • Computer section - 1 full-time employee and 5 part-time employees
9:00 am Indiana District IT Overview
Presented by: Magello Gonzales
  • Excellent staff; all part-time. His task: UNIX and Windows administrator.
  • Four full-time (includes Magello); three work part-time for Magello.
  • Backup software: Arkeia 5.1.12 (Supports multiple clients.)
  • Magello presented backup stats.
  • They do have a COOP (Continuity of Operations Plan).
  • Keep physical security on laptops and desktops. Security cameras cost $936 each. They are on record all the time; records motion. Need especially for non-controlled property.
10:00 am Town Hall Meeting
  • ITAC Overview (Jones)

    • Introduction of ITAC members to District Office employees
  • IT Bureau Issues (Tom Wood)

    • Tom represented Kevin Gallagher. Explained GIO structure. New name: Information Technology Office
    • GISRA expired last fall. Replaced by Federal Information Security Act (FISMA).
    • Hord Tipton, DOI CIO (one level up from Karen Siderelis) - 2002 Secretarial Order issued; authority given to Tipton to approve all IT investments via the capital planning process.

      Information needs to be secure; all this may seem like it's getting in the way of doing "real" work, but it has to be protected. Our systems are at risk. We're trying to catch up with mandates that have already been out there.

    • Information Technology Security Operations Team (ITSOT) - Made up of volunteers. Lester North is the Lead (GD). Structure explained. [Discussion: Strong hope we'll save money by consolidation. Employees want to "get back to Science." 250 registered Web servers now, that should get onto NatWeb. CTO is committed to accountability. It's important that Water not lose structure that we had in place, because we need to be consistent across the Regions. Water has some of best practices, and we'll want to incorporate them into other Disciplines.]

    • Certification & Accreditation (C&A): A significant percentage of federal IT systems have not completed needed C&A.

      "The integrity, availability, and confidentiality of the USGS are critical to the mission."

    • Maryjon McAvery is full-time C&A coordinator.

      Federal Information Security Act (FISMA) - Background:
      DOI received a failing grade (weaknesses found in DOI's "security posture").
      [Discussion: We've come a long way. We're doing much better with security.]

    • MS Active Directory - Directory service that keeps track of all the MS computing equipment and their configuration. Designated 9/02. All USGS offices will migrate to this (Bureau Active Directory) by September 2005.

    • DOI Messaging (e-mail) - DOI CIO proposed migration to Micosoft Exchange. Mixed "feelings" about switching from Lotus Notes to this. (Discussion on this.) The decision has been made for all of DOI. Reference email thread of 2/11/2004 to 2/17/2004.

    • DOI Information Technology Management Council (ITMC) - Voted in January 2004 to migrate to Exchange over the next few years.

  • Office of Water Information (OWI) update

    • OWI structure explained, and the different offices and their functions.
    • Much of what OWI does is an example for what to apply across the Bureau (i.e. Publishing).
    • Katherine is matrixed to Karen Siderelis, GIO. Karen's goal - to integrate geographic information; make our data work better across systems.

    Question: Who is making these decisions on scanning of publications?
    A memo will go out to the Districts explaining what is being scanned, what to expect, and how to help.

    Question: Data linkage to STORET?
    Katherine said EPA and USGS are trying to address this. Goal is to make our data exchangeable.

  • NWIS Update (Susan Trapanese)

    • Continue to improve information technology "system development and management practices."
    • NWIS 4.4 will be released in Aug/Sept, preceded by user testing and formal acceptance testing.
    • NWISWeb: NWISWeb User Group getting established; top priority for development is serving all daily values.
    • Water Use: SWUDS - Major new release on "Windows" desktop & assist in district installation/transfer & support.

    Questions:

    How do you enter parameter codes into NWIS and when will the process be "easier" for Districts?

    New parameter codes are requested via the Office of Water Quality (see OWQ Technical Memorandum 2003.01). Yes, the NWIS parameter code "system" is archaic - its whole logic needs to be reworked. NWIS and Phoenix (QW user group) are still analyzing strategies for improving it.

    Will there be a 2005 compilation of water use?
    Yes, as far as we know.

    Is there a limit to how much data you can retrieve in NWISWeb?
    Yes, currently 20,000 records/rows.

    Registering sites to the NHD.
    Editing tools will be made available to Districts. Bob Pierce is working on this. We're going to use the 1:100K NHD. Is being tested now.

    When will the ground-water levels in ADAPS be made available via NWISWeb?
    NWIS has just begun the analysis and development efforts needed to provide the retrieval/display of all "historic" ADAPS daily values via NWISWeb, including ground-water levels. This is the NWISWeb team's highest new development priority. See also Knapp/Johnson email thread of 2/10/2004 and 2/20/2004 for detailed Townhall follow-up.

    Who is the audience for NWISWeb?
    Considered to be both public and internal. The core NWIS District database and software is for internal "data production" activities. NWISWeb is for disseminating data/info to larger audiences. For NWISWeb, things that benefit the public get precedence. NWISWeb is constrained by security issues associated with publicly available Web systems.

11:30 am LUNCH
12:45pm Review Town Hall Meeting
Presented by: Sonya Jones

Sonya caught "action item" - Completed: Susan helped inquirer about retrieving WQ data.

  • Announcement about Pubs Warehouse? Internal announcement suggested before public announcement is made.

  • action item iconFeb2004.IN.2 - Greg Allord - Greg will make sure Pubs Warehouse is highlighted as "New" on USGS Web sites. Another internal announcement should be made (via All Employee E-Mail?) to make USGS employees aware of this user-friendly capability to find and purchase over 13,000 USGS reports in one database to eliminate the need of Districts duplicating the effort of scanning reports for posting online. The schedule for CAPP's scanning of USGS publications should be made known.

  • action item icon Feb2004.IN.3 - Jessie Alvarez will distribute ITAC's organization chart to use to refer to during All Hands meeting. (Completed)

Discussion: Town Hall Meetings - We may not have provided enough time for District feedback. Need to stress that we're here to hear your concerns and issues. Sandy Williamson will send an e-mail to Indiana asking for any additional concerns we need to address.

  • Minutes from Rapid City, SD are approved.
  • Pending Action Items reviewed.
  • action item icon Feb2004.IN.4 - ITAC members will review revised ITAC charter -- specifically Marilyn Billone's revision distributed to members via e-mail on 1/13/04. Approved? Yes, as of 2/11/04, pending modification. (Completed)
2:45 pm IT Competitive Sourcing Update -
Presented by: Jessie Alvarez

Reference Jessie's email of 2/9/04 sent to ITAC and the field:

  • DOI took IT competitive sourcing off the list, with a caveat. USGS will have control of it. Inventory will be done every year. Not under the gun by DOI anymore...just to develop a strategy on how to handle competitive sourcing. USGS has to review our own IT Fair Act Inventory for consistency. Inherently governmental positions varied among the Districts.

  • GIO is working on network, directory services, e-mail, and Web server management. Dept. wants each bureau to do an inventory of each of these functions, of people involved in these areas, including hours.

3:00 pm GIO IT projects for FY04 - plan review
Presented by: Jessie Alvarez
  • Draft of 50-page plan - ITAC reviewed this and made comments. Jessie will compile comments made regarding 17+ projects.

  • ITAC can recommend an order for implementation to minimize impact to SAs; not priority, necessarily.

  • Steve King can take message to GIO; take ALL these topics to them, instead of prioritizing all of them. We can recommend the order; not priority, necessarily.

  • Tim said the best value of this document is that there's a checklist available to him of everything he has to do—from now until the foreseeable future.

  • ITAC commented on each item in "Contents" of Plan.

4:00 pm Resources/support for NatWeb
Presented by: Sandy Williamson
Lorna Schmid and Dan Winkless joined meeting via teleconference.
  • Request funding for a 24/7 staff for a Network Operation Center (NOC)
  • Lorna mentioned that NatWeb is dependent on functionality of our network
  • There is no mechanism in place to report a problem after hours. Lorna works after hours, with Dan, but nothing is really set in place as far as credit hours or comp time. Mission-critical programs deliver info after hours. When something is wrong with one of the systems, you can't report problem to get it fixed, during a holiday or weekend, especially.

Discussion:

  • This is not a new issue. It's not just NatWeb. There's also the Network Monitoring Group (Bob Wakelee). But many times, things can't be done over the weekend. It will be more of an issue as more things get replicated.

  • Dept.'s ESN NOC would be set up, 24/7. Should be presented by ITAC to GIO. Information about network monitoring; can issue something like a trouble ticket. Maybe RGIOs can put some of their weight behind this as well. Lorna needs a working dialog with whoever does this.

  • Don't have a real 24/7 operation. Propose setting up an interim deal (18/7), to be able to call vendors, etc. Other programs would benefit from this too.

  • action item icon Feb2004.IN.5 - Katherine Lins will write up request on providing at least 18/7 support to NatWeb and WAN, with the ultimate goal of 24/7 support. (Completed - Reference Katherine Lins e-mail to Karen Siderelis on 2/19/04.)

5:00 pm Adjourn for the day
Wednesday, February 11, 2004
Time Agenda Item, Presenter(s), & Expected Outcome
8:00 am

MS Active Directory (AD) Deployment
Presented by: Paul Exter

  • Steve King: Revisited "What is Active Directory?"

    "Microsoft's Active Directory® directory service is the distributed directory service that is included with Microsoft® Windows ServerTM 2003 and Microsoft Windows® 2000 Server operating systems. Active Directory enables centralized, secure management of an entire network, which might span a building, a city, or multiple locations throughout the world."

  • 1999-2000 offices had Windows NT for domain model. Around Windows 2000, model shifted toward management model. Became Windows Active Directory.

  • Directory Service is one store for all IT-related functions—one store for user credentials, one store for computers, one store for printers, etc. Allows applications, messaging, workflow processes—for everything it does. Won't have to keep using user ID and credentials (authentication).

  • Management of computers is the main function. Software-consistent security, across the board (Bureauwide).

  • Efficient administration of your network.

  • Controls access to e-mail.

  • Have to have Active Directory (AD) first, before you get another package (i.e. Microsoft software).

  • No option: We have to employ AD Bureauwide (USGS).

  • One "forest" for DOI, and each bureau will be in the forest.

  • SAs will be delegated "systems management."

  • Centralized management; complete delegated local management.

  • Will be able to take your laptop to any system and log on.

  • Availability - involves complete replication.

  • Cached areas were discussed. Computer and file server talk to each other. User experience is better and more efficient. Don't have to worry about making copies and backing up documents. Removes necessity to do laptop backups.

  • Works like "PC Anywhere" (reliability & availability).

  • Business drivers: OMB DOI mandates; security benefits; cost savings other benefits/

  • Will be able to see everything in your office--all the computers and printers within the USGS.

  • Servers talk to the clients.

  • What about UNIX servers? UNIX Macs can leverage AD, can be part of it; can't get policy from AD, however. Can't distribute software at a local level using AD; UNIX cannot be part of AD infrastructure. Won't see security benefits for UNIX with AD. Will have to authenticate a second time.

  • Will there be an option if UNIX wants to authenticate? Won't be "forced" to use/leverage AD. Will provide guidance how to use AD, if UNIX users do want to use it.

  • Security policy cannot be applied to UNIX machines using AD.

  • Makes it easier to install software; facilitates software deployment. [Machines can do this in a couple of hours.]

  • Impact to the field: minimum requirements for operating the system.

  • Machines not upgraded to 2000 or XP cannot join AD. But they will have functionality; will just have to authenticate.

  • Paul is working on memo that all USGS offices will have to be working on Windows 2000 or XP by end of 2004. There will be a requirement to use AD.

  • Not many are still working on Windows 98 desktops.

  • Office may consider mobile laptops to replace desktops, to cut down enterprise maintenance costs.

  • NT TAC - Working on "administrator rights" of users.

  • What about NWQL? They're assuming they won't be running XP. There will be some exceptions for systems not on the network. The AD team has an NWQL representative to comment on AD and how it could affect how the NWQL functions.

  • There are file tools to handle some exceptions. Virtual machines...

  • Lab machine can get to Windows 2000 or XP through modifications.

  • All machines have to be certified and accredited by a deadline (July 2004). They feel they can have AD in place by then.

  • Lower software costs. (This was questioned.)

  • Reduction of servers (from 400 to 100).

  • We'll need between 8-10 FTE on AD Team, to handle 100 servers. Their job would be back-ups, authentication...will be maintaining core infrastructure; not helping users so much.

  • Lotus servers now - around 40-60 servers.

  • Access has to be limited, to ensure security of the infrastructure; has to have controlled/locked access.

  • Scientific benefits: Administration will be reduced; the IT people won't have to install software; they'll have more time to do other things.

  • Costs: Procurement of servers for AD; new software; design and engineering; reconfiguration associated with workstations and resources that will be migrated to AD; and modifying requirements associated with AD.

  • Each SA will manage their own "bucket," provided they have a domain controller.

  • Applying AD is efficient for SAs.

  • We will have to "true up" our licensing with Microsoft. Account is Office Automation (Windows2000, Office Suite, XP) - Current count is 10,000 on this. We have 13,000 employees, most with computers. (Some employees have Macs and UNIX systems - less than 5%.) We can expect increased license costs.

  • Hardware & software maintenance.

  • Who will provide info to District management? Paul will take as action item to get it on GIO agenda.

  • Managers Meeting is in April.

  • Districts have to project costs. Paul does have cost of EA each year. Complete migration won't be done until the end of 2005.

  • Training: Comprehensive Training Program - Phased deployment of AD. Training for the SA.

  • Paul mentioned they hired a company through Microsoft to help set up AD.

  • USGS AD Architecture Development Process: Going through complete plan, where everything is documented. End of March - complete architechture and migration plans. Phase AD implementation by end of March 2004.

  • Discussed "Project Strategy - Delivery" (slide):
    - Deadline is by end of 2005.
    - Aggressive schedule.
    - Regional Teams - Need their support for 10 sites(?).

  • Certified project manager on this. Customer advocacy people are involved in this too (i.e. Nelson Williams and Gail Kalen).

  • Much info will be on their Web site

9:30 am

Information on future Network Design
Presented by: Paul Exter
Expected outcome: More information on future network design and opportunity for input

Need internal network for Active Directory.

  • We have to separate our Domain Name Server (DNS) space.
  • Have to totally restructure network design.
  • Paul Exter is not a DNS expert and will need assistance; design project is going slowly. Dan Winkless and Bob Wakelee provided feedback but they are not in support of this proposal. Need to get SunTAC on the line.
10:00 am

DOI messaging initiative and Bureau's help desk
Presented by: Sandy Williamson
Expected outcome: Announcement soon from DOI on messaging

Patty Damon, GIO, is present on the phone to discuss plans for replacing Enterprise e-mail system Lotus Notes with Microsoft Exchange. There is no project plan yet. There is no plan to run Lotus under Active Directory. The Lotus team plans to implement MIIS, a program, that feeds back to LotusNotes Dominoes Directory. MMS is being used now to populate Active Diretcory. MIIS can put everything into it and it forwards out to other directories. Active Directory has to be authoritative directory. Microsoft Exchange will not be deployed soon. The Lotus Team is in no real rush to deploy right now. The Lotus Team will work hard in abiding by initial requirements including a requirement to scale down the mail servers quite a bit and keep other collaborative tools. Microsoft Exchange is being mandated by the Department. The cyber tool in Lotus is being rewritten so the interface looks like RainDance.

  • Discussion: Security concerns regarding Microsoft Exchange have been raised and documented. Microsoft Exchange System is vulnerable to viruses.

  • Lotus support staff will support Microsoft Exchange.

  • POP and IMAC supported? Not exactly; if they are, it'll be secure POP and IMAC.

  • PDAs that run on POP won't be able to run on Exchange then... 3 years down the line... Blackberries will use Exchange.

  • Don't want to pay QA for licensing (software assurance). We shouldn't have to pay for something we're not using. We paid for all but 4,000 employees. FY05 - billing charge will come in for that. District Chiefs need to know if they'll be paying at all during FY05 for Microsoft Exchange.

  • Patti will be member of Exchange Team, at Bureau level. Greg McHendrie, Daphne Wall, and Valerie Walker will be her team mates.

Action Recommended: Official word needs to come out; not just via posted and distributed ITAC minutes. Communication needs to come from GIO. ITAC supports GIO's plan to notify USGS personnel of these important topics.

  • action item icon Feb2004.IN.6 - Scott McEwen will write a note to cost center managers addressing the following bullets for ITAC Minutes summary: (Reference email thread)
    • Background/definitions/plans of MS AD and messaging.
    • MS EA cost recovery may increase $200/employee in FY05.
    • One "office automation" machine (with MS Office and e-mail) per person will reduce cost recovery. All desktops and laptops need upgrade to Windows 2000 or XP by Winter 2005 for AD.
    • MS exchange messaging may result in new licensing costs in FY05 (or more likely FY06).
11:15 am

Overview of C&A process for high risk systems
Presented by: Maryjon McAvery
Expected outcome: Discussion and Q&A session on C&A process for high risk systems and how internal scans might affect our C&A

Enterprise Web Certification and Accreditation
Certification and Accreditation of IT Systems

Linda Peng present; she's Security Manager of everything that isn't NWIS.

  • Three enclaves: (Reference Jessie's email of 2/06/2004)
    -- E-Web
    -- Office Automation General
    -- Office Automation Specific

  • Blanket purchase agreement; in place sometime in March 2004. Will allow a 2-day turnaround for credit card purchase.

  • All IT systems must be accounted for in the C&A process.

  • Asset inventory and evaluation would be adopted - a common configuration management policy: All systems must be involved in C&A, in an IT inventory.

  • Every desktop must be accounted for in range of IPs. Accounted for individually or in a group, in some way.

  • Every piece of equipment will need an asset inventory. Only need to inventory that one server one time. Web site is GIO's Security Web site.

  • Need some way to streamline the process for the Districts. Shouldn't do through multiple data calls.

  • Garry Neverdon is coordinating three enclaves for C&A. We're going to need to form a C&A team. Contractors should help us find some shortcuts for all this documentation.

  • Maryjon did state that if there is a grouping of the same machines, you can do a type of C&A for that grouping. Always have to do an asset evaluation.

  • Discussion on possibility to have small team focusing on Water districts. (NWIS has done complete inventory.) Everything has to be C&A-ed by 7/31/05.

  • WRD's Mission-critical system has already been C&A-ed (NWIS). Can't get everything C&A-ed this year.

  • Need process to go out to Districts. But we have to do asset inventory now: by late Spring. This has to be done. C&A for E-Web will be finished this year. Kevin Gallagher is overseeing this asset inventory. Guidance will be coming out, probably next week. Field will be told to do this, fill in form

  • ITAC recommends that Tom Wood communicate to the CTO the need to coordinate data calls for C&A and server registration, etc., and ITAC volunteers to work with the CTO by establishing a team to develop and test a plan to capture this information. Steve King volunteered to coordinate this across the regions.

  • ITAC recommended that Tom Wood communicate to the CTO the need to coordinate one data call for all enclaves for C&A and server registration, etc.

  • We're not completely done with the high-risk systems. EWeb is a high-risk system as it's open to the public.

  • This asset inventory will help us with anything we do in the future. We've always struggled with asset inventory.

  • Members will work with the CTO by establishing a team to develop and test a plan to capture inventory information for enclave C&A.

  • Discussion: There is software that will do all this and keep it automated.

  • Sandy says to wait until next year, after AD is implemented, before starting a big database. But we can develop a spreadsheet for the inventory, in the meantime.

  • Discussion: Isabelle Halley and Richard Hollway worked on this for NWIS. Maryjon can go to Maryland District Office to test whatever is developed (but that district office is not "typical"). Can go to VA... PA...

  • Work on common denominator first.

  • Steve King has contacts in other bureaus, ones that are tackling asset inventory now. He can ask them what they're doing, and see if they'd share the form they're using.

  • The whole thing needs to be developed a bit more in GIO, before we try to put anything together.

  • action item icon Feb2004.IN.7 - Sonya Jones will ask CTO for update on C&A during ITAC teleconference call next month.

11:45 am LUNCH
12:10 pm

Serial Connections and non-DOI-standard Windows versions
Presented by: Scott McEwen

Paul Exter said NT TAC is working on documenting these solutions. Get people who've done research on this and include this information.

  • Serial connections not too good.

  • Ask people from water to coordinate hardware and software, and communicate with NTTAC.

  • Take guidance Paul had online and see what it works with.

  • action item icon Feb2004.IN.9 - ITAC members agreed to sponsor an ad hoc team tasked to investigate USB and Windows XP compatibility with field equipment, test alternative methods, resolve conflicts with vendors where possible, and prepare a report on findings/resolutions/outstanding issues. This report is to be shared with all WRD IT support staff and staff who use the "problem" hardware and software.

  • Endorse putting together a team. It would be clearly stated what this team will be doing.

1:30 pm

Do the Districts need public NWISWeb servers?
Presented by: Margaret Bunch

  • Every office used to have its own publically available Web server - in particular to provide cooperators easy access to real-time data. This was particularly important for redundancy since the initial release of the national NWISWeb system was a single-point of failure. Now the NWISWeb system provides redundancy for real-time data via NatWeb. District offices have not been told to shut down their local real-time data web server. Should districts still maintain their local Web servers?

  • Of the 14 districts that responded, the majority said even if they had a reliable network and could get hold of help at reliable hours, then they still want to strongly maintain their own server. Reasons are in Margaret's document. They want capability to craft own site. (Scott queried another District).

  • PA, KS, and SD were the districts used in Margaret's study.

  • Scott's example (MT) - They just want ability to maintain a site.

  • Jeff Stoner heard from the ND district, which wants the capability to serve real-time data for special projects, such as streamflow from the Ukrainian international project. Currently they serve that data for them.

  • WaterWatch is an example of a specialized Web application that uses data from NWISWeb, but then provides additional content. But WaterWatch has been integrated into NatWeb management framework to insure security.

  • NWISWeb has a feature that allows the Hydro-techs to "build-a-sequence" of graphs for real-time sites. Many use this as part of the real-time data review process. Districts want this local because if there are network problems, then it interrupts productivity.

  • If office does not rely on local/district NWISWeb Web server for real-time data review, then migrate completely to national NWISWeb server (many have).

  • OSW/SWUG recommends using Hydra, a routine available in ADAPS-NWIS, to review and edit real-time data instead of using the NWISWeb "build-a-sequence" graphing feature. Suggestions/scripts to "optimize" Hydra from quick data review are available from SWUG.

  • Conclusion: Start a plan phase. Can drop at least half of the Ultra 5s from Inventory. Let people know what other tools are available; help them.

  • action item icon Feb2004.IN.8 - Tim McElhone will forward Margaret Bunch's findings to NR SAs and RCSers stating pros and cons of maintaining NWISWeb server at District to help them decide if they should phase out the local servers. They can then make a decision whether to maintain their local NWIS server or not. Jessie will create document and send out to SAs and get feedback; in order to get a complete picture. <

  • Reference NWISWeb site page - District NWISWeb Web Server Installation

1:30 pm Enterprise Web Update
Presented by: Karen Klima
Expected outcome: ITAC briefing of Enterprise Web

On the phone - w/Judy Ferrier- Security Officer; PowerPoint presentation.

  • Referred to handout of PowerPoint presentation.

  • Enterprise Web is within GIO. Karen Klima works for Hedy Rossmeissl.

  • GIO Enterprise Web Team - Members are as follows: Karen Klima, Judy Ferrier, Carmelo Ferrigno, Dave Govoni, Kevin Laurent, Gerry Lebing, Sharon Moore, Nancy Spriggs, and Bettyanne Taylor.

  • USGS Enterprise Web Team - Members are as follows: Gregory Allord, Lance Everette, Ken Lanfear, Peter Schweitzer, Lorna Schmid, Kent Swanjord, Gail Wendt, Denise Wiltshire, and two onsite contractors (Raju Prasannappa and Pat Kelly).

  • The Enterprise Web Team works for Karen. Other team is a "matrix." Larger group.

  • Lorna Schmid now works full-time for the GIO Chief Technology Office. NatWeb is part of Enterprise Web.

  • Challenges: One Bureau, one Web presence (goal).

  • Consolidation & integration needed for USGS Web presence.

  • USGS has a very distributed system (250 servers; 80 cities); lacks customer focus and management controls.

  • DOI created a Web Council.

  • Barbara Wainman and Karen Siderelis have created Web Advisory Group...to make sure we are uniform across the Bureau. Still hearing about this group, meeting in March.

  • There's a proposed new template for USGS Web pages. (also reference the New USGS Homepage Design)

  • Anything on a public server has to be secure. Shouldn't mix public with private data on the same server

  • Tim Brown, GIO - IT Plan author- ITAC will ask Kevin to provide clarification on his role.

  • New Homepage goal: easier access; improve Web presence; support IG recommendations; reflect USGS 125th Anniversary.

  • Homepage improvement is incremental. Getting feedback from users.

  • Have a map on USGS homepage now. Not just search tools. New header and link to DOI. This is important to Secretary.

  • Ken Lanfear coded USGS Web sites according to terms to automate answers to the public when contacted (ASK USGS).

  • Greg Allord is working with Ken Lanfear to geocode publications. Katherine Lins has asked Greg to put together communication to Districts.

  • Overall strategy: 250 servers they know of serving Web sites. 68 of them secured in NatWeb. E-Web enclave would take care of all USGS Web servers. Karen Klima will encourage as many as possible to "join" NatWeb. Each set of owners outside NWISWeb will have to provide own set of C&A documents. The NWISWeb servers were addressed in the overall NWIS C&A.

  • Timeline: By 2/23/04, they'd have 6 weeks to get back to Lorna. Would have to secure servers.

  • URL supplied to everyone in memo from Chip Groat (January 30, 2004). Register all Web servers by 2/16/04. (Reference presentation slide)

  • C&A process for all Web servers by 7/31/04.

  • Maryjon offered C&A training; 2d week in March 9-11, 2004, in Reston; whole week.

  • NAWQA has not been C&A-ed yet; by 7/31/04, it should be.

  • Arc-IMS servers will go through C&A for Enterprise Web. Jacque Coles will help out.

  • NatWeb has 73 virtual hosts. (C&A will cover servers that may hold more than one Web site; i.e. NAWQA and Pubs Warehouse.)

  • Harry's server farm is part of this C&A.

  • Servers using NATWeb do not need to register separately.

  • DOI wants to reduce number of publicly available systems; reverse proxy helps in this endeavor. Reverse proxy servers sit in DMZs, which is a requirement.

  • Discussion: Should be new process if office wants to use ArcIMS server.

  • DOI is asking for contractor for end of fiscal year to develop long-term projects plan to reach C&A deadline (7/31/04).

  • Maryjon wants to do cyber seminar on all these changes. ITAC will be invited.

  • Discussion among ITAC: Consistency issues. District homepages should be revised, but a template will be coming out on that. Good idea to hold off on Districts revising their homepages to conform to new template of USGS Web pages? Review the content; not artwork.(See p. 12 in handout.)

  • USGS homepage template is not ready for distribution

3:30 pm

NWIS/operational issues and Status of RT depot
Presented by: Susan Trapanese

Note: NWISWeb and NatWeb have given several presentations/cyber seminars on this topic. The March 2003 cyber seminar provides a good overview.

Susan drew a diagram on the chalkboard - from the "gage to the page" identifying the flow of data from the Data Collection Platform (DCP), to LRGS, then through district NWIS, and "out to" the NWISWeb servers.

First, Susan discussed the "normal conditions" of NWIS data processing and NWISWeb Web serving.

  • Data transmission to NWISWeb is controlled by a set of routines on the Distict NWIS server (these routines are often called the NWIS-side of NWISWeb).

  • The NWIS server can transmit data to two places: the local/district NWISWeb Web server (ultra5) and the National NWISWeb "Data Hub".

  • Nomenclature: If District has local NWISWeb server, it's sometimes referred to as the "local NWISWeb Web server". This Web server is limited to the real-time data for the District.

  • The "Data Hub" service has built-in redundancy. When the District NWIS server transmits data to the "Data Hub", the data is actually received at one of the three NatWeb locations. For example, if it can't transfer to Reston, it automatically goes to either Sioux Falls or Menlo Park. It uses CISCO's "Distributed Director" software.

  • Next, the Data Hub routes the data to All four 'national' NWISWeb servers (two in Reston, and one in Sioux Falls and one in Menlo Park). NWIS developed the application that controls the routing and synchronization of the data in all the national NWISWeb servers. The real-time data are redundantly served from all four NWISWeb servers, but the "historic data" (historic streamflow daily values, QW data sample results, etc.) are available from one server, the nwis.waterdata Web server located in Reston. The public only needs to remember one URL in order to access any of the NWISWeb national Web servers (waterdata.usgs.gov). The Cisco Distributed Director then directs the public to one of the available NWISWeb servers.

Next, Susan discussed how NWIS-RT, the backup NWIS servers for real-time data processing (LRGS/SATIN/SENTRY/DECODES/ADAPS), fits into this "picture."

  • What happens if something goes wrong and the district is unable to process and/or send real-time data to NWISWeb? This could be a WAN outage, a district NWIS server failure, etc...

  • The NWIS-RT systems have their own LRGS for receiving all USGS GOES real-time data.

  • The NWIS-RT systems have the districts latest "ADAPS support data" (ratings, shifts, DECODEs configs, etc.), which it uses to process and compute real-time unit and daily values data from the LRGS transmissions. The NWIS-RT systems are "hot" backups that should always have up-to-date real-time data.

  • The NWIS-RT systems "resemble" the district NWIS-ADAPS setups. District users can log into their assigned NWIS-RT system and perform ADAPS functions, and control web displays via the nw_edit functions. However, the NWIS-RT systems will only send data to public/national NWISWeb servers for a district when that district "turns-on" this feature. Subsequently, the district can "turn-off" this feature when their regular operations are back to normal. As an aside, when the feature to send data to the nationa/public NWISWeb is turned-off, the NWIS-RT server sends the real-time data to an internal-only test Web server.

4:10 pm

Non-GOES: RT data not acquired through GOES telemetry

  • NWIS currently processe Non-GOES data; however, NWIS does not manage/support the applications and hardware used to provide the acquisition of Non-GOES data (modem/dialer programs, etc).

  • NWIS will provide redundant processing (not acquisition) of non-GOES real-time data via NWIS-RT.

  • Greg Shank has decided that districts must use secure copy to send non-GOES data to the NWIS-RT systems. The districts are responsible for modifying their non-GOES "acquisition" systems so that they can securely send data to NWIS-RT; Greg will assist districts with their connections to NWIS-RT.

  • SCP (secure copy) is part of SSH; supported in different platforms.

Additional Topic: (a Follow-up on Issue from last ITAC Meeting:) Susan provided an update on the problems that South Dakota (SD)were having with delays in real-time data transmission to NWISWeb. Dave Briar and Scott Bartholoma have been investigating. There have been intermittent NWIS database server locking problems that can interrupt the data transmission. Dave Briar also discovered a minor misconfiguration associated with their use of use of rt_www, the old Web system. SD fixed this, but SD's continued use of rt_www impacts NWISWeb transmission performance. Dave is working with SD to do furthering testing/experimenting with a more frequent data transmission interval (from every 5 minutes to every minute). Initial testing of the one-minute-interval shows that it now takes around 2 minutes for the real-time data to be extracted from the SD NWIS database and displayed in all 4 national NWISWeb systems. Under the old transmission scenario, this process could add an additional 4 minutes delay to the real-time data Web delivery. We/NWIS developers do have other concerns with using a one-minute data transmission interval: the frequent transmission may cause additional NWIS database server locking/deadlocks. The NWIS teams will continue to test this before making any recommendations to other NWIS sites.

4:20 pm

ITAC's comments on Shawn Noble's E-mail sent to ITAC from SunTAC on 2/9/04

  • There is no immediate need to replace the District NWIS Sun Servers. However, Districts should plan on replacing their "NWIS" Sun Servers before the end of FY 2007 since support ends in 11/2007.
  • All ITAC members are in agreement with this plan.
  • Discussion: Using UNIX and administering UNIX are two different things.
  • DOI is moving toward Microsoft environment.
5:00 pm

Action item follow-up

5:30 pm

Adjourn for the day

Thursday, February 12, 2004
Time Agenda Item, Presenter(s), & Expected Outcome
8:00 am

Security Issue associated with administrative privileges
Presented by: Sandy Williamson and Paul Exter (by phone)

  • Example: ability to install new software to fix a problem.
  • Perhaps certain users could be trained to be administrators on their computers
  • Site administrators should not have their ID with other user IDs

OPTION 1

  1. Alt. Login ID w/elevated rights
    1. Admin - SA's only
    2. Regular user x - for regular user
    3. User X w/elevated rights
  2. Add user to Power User group
    • User IDs should not also be admin IDs. - Directive
    • Issue - Hard to balance security with getting work done.
    • Paul's proposal: Users will have to switch user credentials in order to install software.

Discussion: District Chiefs, when asked, indicated that users begin with maximum security and then work to what security rights user really need.

Paul administered 120 users in the Maryland District but NONE had administrative rights. Laptop users need some privileges; Site Administrators can provide a user ID that will allow additional privileges.

  • Elevated Rights ID would allow users to install software.

  • With Active Directory, cached pages are in a special place.

  • Moving to a mail platform that will help improve security issues, including viruses.

  • Thanh Le will do initial draft (Paul). They will document all this. Paul's group will write Web pages to put in perspective issues about secure systems and grant power-user rights.

  • The user can login to a system with an elevated user ID and after installation is completed, login with a non-elevated user ID. Active Directory provides this functionality.

  • Discussion about setting of time: User never has to set the time; it's always fixed.

    • AD will replace that structure; Active Directory will set the system time for EVERY client because systems are contingent on time.

    • User can change the time zone, if necessary. Paul will check on this.

    • ITAC suggests that AD guidance is needed by WRD District offices - the sooner, the better.)

    • Scott McEwen would like recommendations on configuring laptops for fieldwork. The user can switch user credentials with a right click on the mouse.

    • A suggestion is made to use cyber seminar to impart this information.

  • In WRD, NT TAC provides guidance and should be used to support recommendations.

  • DOI policy maintains that user credentials be separated. ITAC recommends that the policy be circulated to all employees. There are certain situations where users will need elevated rights. Also, there are some applications that won't run without elevated rights.

  • action item icon Feb2004.IN.11 - Scott McEwen - RCS'ers, Sandy Williamson, a couple of selected IT'ers, and a couple of selected members of the regional data committees will work together to develop both a memo and a cyber seminar—both sponsored by ITAC and the Office of Water Information—to inform science center managers and Information Technology support staff of recommended ways to configure laptops for field work. (Reference Scott McEwen email of 2/11/2004.)

8:30 am

Understanding Hydra and Hydstra and its Relation to NWIS/ADAPS
Presented by: Susan Trapanese

  • Hydra is a part of the NWIS/ADAPS software system; used for unit and daily value editing.
  • Positive feedback from field: A hydrologist at this meeting told Susan, "I love Hydra."
  • Hydstra is a company (software product suite).
  • In January 2004, Hydstra merged with KISTERS; KISTERS has a competitive product.
  • The Hydstra Suite consists of several modules; we are specifically interested in the graphical rating editor modules.
  • USGS (NWIS and the OSW) have a CTA (Cooperative Technical Agreement) with Hydstra for graphical rating/shift applications.
  • Field personnel need to edit stage discharge ratings; the Hydrstra program helps field personnel graphically draw the rating curve.
  • Surface Water User Group using Hydstra software in a test in 4-5 District Offiices; report should be ready by February.

Discussion points:

  • NWIS wants to extend the CTA until June 30, 2004.
  • Feedback from Indiana attendees: Exciting! It can save fieldworker 2-4 person weeks! Great timesaver! (And 12 people work surface-water records with handplotting, just in the Indiana District Office alone.)
9:00 am

ADCP data archival issues
Presented by: Scott Morlock

Hydroacoustic Current Meter Archiving Issues

  • For 120 years, USGS using Price meters.
  • Hydroacoustic current meters - "new kid on block" (really since 1960's); sound used instead of a spinning cup; very reliable.
  • Gives QA/QC measure; can quantify instrument.
  • ADVs have a handheld controller.
  • Tethered boat and remote-controlled boat used (hard thrust-to-weight ratio); excellent tools Thelatter keeps field personnel out of the water).
  • Current meters "won't go away real fast."
  • In WRD, there are about 165 ADCPs; 250 flowtrackers; 10 new BoogieDopps = $6,000,000 - This amount represents a significant and worthwhile investment in the USGS WRD.
  • DART (Data Archive Tool) software archives hydroacoustic data.
  • Recommended: "Real-time" hydroacoustic discharge measurement data needs to be transferred quickly from the field to the server.
  • OFR 95-701: You have to archive all your data (national policy).
  • EVERYTHING these instruments generate you should archive.
  • OFR 03-460: IN Surface Water QA Plan (applies to everything) - It's online. "It's a living document."
  • Indiana has its own District policy for field archiving and office archiving. Can projections be made, as far as how long data will last? Things put on CD-ROM and put away?
  • How unique is IN DO as far as archival procedures and policy? (Scott Morlock hopes that other districts are doing this.) There is a team meeting this week in Tucson regarding storing of scientific records. Everyone in SW should have a plan for archiving data. There is an enforcement mechanism tied to this.

Discussion:
Current meter hydroacoustic technology is a highly competitive business. This technology needs to be available to scientists. There is a need to work with IT security to get discharge measurements into the office databases faster (wirelessly). District Chief, IN DO, is very proud of his Data Section staff.

9:30 am

Surface water inspection and measuring device (SWIM)
Presented by: Ron Knapp

Field computing -- Ron Knapp presented information on the handheld field computer project. Software for automating inspection sheets and discharge measurements was presented.

Future SWIM software enhancements include:

  • Field Training in the Districts.
  • Wireless between CMSP and PDA
  • Voice recognition, voice input to SWIM.
  • Update shifts and gage height corrections.
  • Import other measurement data.

DISCUSSION:
Priority of above enhancements: Training; Wireless; Update shifts, automatically (from NWIS side); import other measurement data, voice recognition.

  • Need funding for SWIM software enhancements; The concern about Charlie retiring is that someone needs to take the lead.
  • Project is a success!
  • It is critically important to have Bureau support for the handheld project. WRD is focusing on how to integrate among disciplines, by reviewing how the other disciplines are using PDAs, in order to present case for future funding.
  • Steve King was asked to keep this before Science Committee.
  • Security issue - Would be good to have wireless communication; need to keep in mind for the field. It was noted that security issues should be addressed, but these issues should not stop the work.)
  • Another selling point is safety: getting measurement w/o standing in water or taking off gloves in bitter cold.
  • It is noted that Eastern Region Data Conference - June 2004, Raleigh, NC Eastern Region Conference audience is field Techicians and hydrologists; ITAC suggested that some IT personnel people attend to learn about instrumentation in the field. It is expected that 250 personnel will attend.
  • Draft agenda is full, and is being finalized.
  • action item icon Feb2004.IN.11 - Scott, Tim, and Ron Knapp - Let SAs know what they can gain from attending Eastern Region Data Conference (CHIDER), June 2004, Raleigh, NC. Letter will be delivered to the CHIDER Committee for distribution.
10:30 am

Officially elect Vice Chair/AO replacement

  • Jeff Stoner volunteered for Vice Chair position
  • Majority of members voted "yes."
  • action item icon Feb2004.IN.12 - Charlie Merk will draft ITAC Secretary's tasks and steps, which will be reviewed by ITAC. Will give to Katherine and Sonya.
  • Push for Agenda items and getting them onto Web. Hotel info and carpool info.

Discussion:
action item icon Feb2004.IN.13 - Katherine Lins will check into AO replacement for ITAC membership. She will check with RHs and CAPP. (Completed) - Donna Hector-Sabin assigned for 3-year term. Reference Katherine's email to Greg Allord of 2/19/2004.

10:45 a.m.

Action Item Review
Presented by: Sonya Jones

  • Need in writing who will get back to those who replied in Town Meeting.
    action item icon Un-numbered AI - Joel will answer questions.

  • Next ITAC Conference call - March 12, 2004 (2d Friday); noon.

  • ITAC Conference calls will be scheduled for the second Friday of every month, noon, Eastern time (4/9; 5/14 - next two meetings).

  • ITAC should focus on issues that the committee can influence. Information sharing is a major ITAC goal. GIO presence at ITAC meetings is beneficial. Communication to the WRD office regarding GIO IT issues should be issued by the GIO office; ITAC will continue to be an intermediary.

11:20 am ADJOURN Meeting


[an error occurred while processing this directive]