Homeland Security Articles Data Insights

Embed Size (px)

Citation preview

  • 7/27/2019 Homeland Security Articles Data Insights

    1/9

    Marshaling Data for Enterprise InsightsA 10-Year Vision for the US Department of Homeland Security

  • 7/27/2019 Homeland Security Articles Data Insights

    2/9

    1

    As owners of one of the most comprehensive dataenvironments in the US federal system, the USDepartment of Homeland Security (DHS) has anasset like no other for conducting its basic missionof safeguarding Americas citizens, infrastructure,and borders. The information it collects is as diverseas the missions of the many agencies and officesunder its purview, ranging from the TransportationSecurity Administration (TSA) to the Federal Emergency Management Agency (FEMA), US Customs andBorder Protection (CPB), Immigration and CustomsEnforcement (ICE), the US Secret Service, and theCoast Guard.

    Because the mission of DHS is so broad and allconsuming, it is challenged with ushering in the kindsof changes that its data regime needs to render newinsights and drive down costs. Each of the extensivedata sets that DHS and its components maintainsupports specific mission needs and exists underestablished legal and regulatory authorities. Their

    owners naturally strive to improve the efficiency andeffectiveness of data analysis for their intendedpurposes. But even when users recognize the missionbenefits of sharing data and conducting analysisacross multiple data sets, they too often run intotechnical, procedural, legal, and cultural barriers toshared analysis.

    These barriers are preventing DHS from realizingthe full potential of the data it has as its disposal.Intelligence and law enforcement analysts searching forterrorists, and other threats, need the ability to paint acomprehensive picture that considers all kinds of dataat oncesuch as travel and entry and exit records,evidence that ties suspected terrorists or criminals toillicit shipments of cash or contraband, or involvement

    of specific individuals or groups in diverse criminalactivities, from weapons trafficking to cyber crime.The need to learn from and capitalize on multiplesources of data is no less urgent for DHS teamsresponsible for responding to emergencies, enforcingtrade agreements, combating transnational criminalorganizations, managing the flow of people throughUS borders, protecting intellectual property rights, andsafeguarding Americas critical infrastructure.

    Over the coming years, DHS will need to masterthe ability to marshal its tremendous repository of data while still living up to its manifold day-to-day responsibilities. These tasks are mutually dependentthe bridge must be rebuilt while remaining open totraffic. We believe it will be easier for DHS to manageits transformation into a data-enabled enterprise if it attacks the problem from a mission perspectiveand taps emerging cloud-based analytics to gain newinsights from the information it already has at itsdisposal. Through this effort, DHS can significantly

    elevate its role in the nations homeland security ecosystem, position itself as a valuable andinsight-driven partner to other crime enforcementagencies, and increase the efficiency of itsmission-support functions.

    Opening the ApertureWhen Michael Chertoff became the second secretary of homeland security in 2005, one of his first prioritieswas to change a departmental policy of only taking twofingerprints from each person either wanting a visa to

    come into the country or for those traveling withoutvisas. Chertoff reasoned that by only taking twofingerprintsone from each index fingerhomelandsecurity personnel were potentially missing scores of

    Marshaling Data for Enterprise InsightsA 10-Year Vision for the US Department of Homeland Security

  • 7/27/2019 Homeland Security Articles Data Insights

    3/9

    latent fingerprints, or the fingerprint residue collectedall over the world at crime scenes, in safehouseswhere terrorists plan, and even on battlefields. By expanding the information collected from travelers to

    10 fingerprints, Chertoff said that the DHS significantly enhanced its capability to identify those who werentincluded on watch lists but left a little piece of themselves somewhere and some place that suggestswe ought to take a closer look. 1

    Chertoffs policy change was predicated on the belief that information is power. By opening the departmentsaperture to collect more information, he reasoned thatthe department was strengthening its powers to detectbad actors before they performed bad deeds.

    This premise is at the heart of all homeland security efforts, and yet, there are real and significantconstraints to expanding the amount of pertinent datathat each DHS entity has at its disposal. The mostsignificant constraint is rooted in the departmentsoriginsbringing 22 different agencies under oneorganization necessarily meant bringing their legacy information technology systems with them. Whileconsiderable progress has been made in improvingthese systems over the last 10 years, too little hasbeen done to address the challenges of sharing data

    and conducting analysis across these systems. Asa result, DHS has limited the usefulness of its data.Users have to mine a number of databases to findanswers to problems identified at the policy levelor pursue particular cases, and these efforts havehistorically been susceptible to redundancy and lack of coordination. In addition, the people operating at thecollection end of those stovepipes have little incentiveto acquire information that isnt directly relevant totheir own priorities, even though it might be very important to others.

    But the issue also goes to a lack of awareness thatdata exist in the first place. In the homeland security setting, the real power of data is not limited tohelping you solve problems identified elsewhereits

    identifying new problems so you can get ahead of them. Information sharing relies on the owner of thatinformation to recognize its value to others, and this isvery seldom the case. As a result of this shortcoming,information just stays where it is, where it has no valueat all. Its as if 10 different DHS entities were eachcollecting a print sample from a different finger, butnobody could ever put them together because therewas no mechanism for matching them up.

    These organizational and other barriers are particularly problematic for homeland security leaders trying tosecure the nations borders, keep ahead of criminalorganizations, enforce and facilitate trade and travel,and plan for emergency response. For instance,Customs and Border Protection has developedreasonably effective processes for physically andvirtually screening cargo shipments by analyzing trade

    data supplied by shippers and other information on theflow of goods into and out of ports of entry. But it isdifficult to link that data to information on individualswho may be involved in those shipments, the past

    1 Remarks by Michael Chertoff, www.tsa.gov/press/happenings/2007_chertoff_remarks.shtm

    http://www.tsa.gov/press/happenings/2007_chertoff_remarks.shtmhttp://www.tsa.gov/press/happenings/2007_chertoff_remarks.shtmhttp://www.tsa.gov/press/happenings/2007_chertoff_remarks.shtmhttp://www.tsa.gov/press/happenings/2007_chertoff_remarks.shtm
  • 7/27/2019 Homeland Security Articles Data Insights

    4/9

    3

    histories of the conveyances used in the shipments,and the money and data flows that accompany allmovement of goodswhether legal or not.

    Part of this difficulty stems from the fact that differentagencies relying on different databases are responsiblefor different aspects of securing and facilitating themovement of people, goods, money, and data. A datapoint as plain as a phone number on a bill of ladingcould be associated with a known terrorist, but itwont be flagged for follow-up if nobody inside CBPunderstands its value and those outside of CBP remainunaware that this information is even being tracked.Only by revealing the presence of data in the first placecan DHS and its partners expect its analysts at theedge to make these critical connections.

    More Tooth, Less TailDHS faces the added challenge of evolving into a data-centric organization at a time when every cost is beingscrutinized. While mission challenges remain high, thedepartment is facing budget constraints unprecedentedin its 10-year history.

    As in the military, concern is growing that the tail of back-office functions has grown too big and unwieldy to support DHSs mission in a timely and cost-effective

    manner. One of the biggest complaints coming frominside the organization is that staffers have to supply the same data to five or six different entities. Thatlevel of duplication is expensive and ties up valuableresources. This spending seems particularly outof synch when analysts working at the edge of theenterprise have a limited view of the information theback-office support groups are helping to maintain.

    Our view is that DHS has the opportunity to becomea leaner, more productive organization in the future if it harnesses the power of the data it already collectstoday to support its many mission objectives. In10 years' time, we see DHS components thinkingof themselves as collective sources and sharers of information rather than separate parts of a largerbureaucracy. DHS must tap the potential of its data

    much in the way that retailers, banks, and healthcareproviders of today are tapping every available pieceof information about their customers to predicttheir behavior and help set strategy. Investigators,

    inspectors, and analysts in the field will knowwhat kinds of data are being collected across theorganization, so they know where to go to mine forinformation and learn more about the cases they arepursuing. Ultimately, this capability will be extendedfrom mission data to mission-support activities to helpDHS more efficiently manage its personnel, property,fixed assets, and finances.

    Mining Big Data for InsightsThe first step in developing this capability and

    transforming DHS into a data-enabled enterprise isto embrace a new method of keeping track of andaccessing informationone specifically designedfor big data that is distributed in a classified orlaw enforcement environment. The emergence of cloud computing technologies has paved the way for organizations to unlock new insights by couplingtechnological infrastructure with analytical tools togain better access to all of the data they have attheir disposal.

    To support this new capability, DHS must have afull and working knowledge of all the types of dataits many entities collect on a regular basis. As itstands now, a DHS analyst is only able to locate theinformation he or she needs if they know precisely where it is housedin one database or another. ButDHSs experience reveals that this is seldom the case;users move from database to database, searching forspecific information that may or may not be there. If users want to ask different kinds of questions, they often have to reengineer both the databases and theanalytics involveda process that can be prohibitively long and expensive. This tends to limit both thecomplexity of the questions that are asked and theutility of the results.

  • 7/27/2019 Homeland Security Articles Data Insights

    5/9

    What DHS needs to derive actionable insights fromits data is to evolve toward a platform where the datacan be staged for advanced analytics. Cloud-basedtechnology solutions now avail organizations with an

    effective and efficient way to load, store, and accessmultiple data sources to enable multivariate analyticsin a mission-specific setting. The evolution willsystematically convert the DHSs collection of individualdatabases into a consolidated and connected pool of informationor data lakemaking all of it readily accessible for all types of analysis.

    With the data lake, users can easily tap all of theavailable data in a variety of constantly changing ways.A key feature of the data lake is that information is nolonger defined strictly by its location. Specific piecesof supporting informationknown as meta-data, ordata about the dataare identified by embeddedtags that allow for sorting and identification. In theshipping container example illustrated above, theuser could find the phone number listed on the bill of lading simply by searching for it, regardless of whichDHS agency captured the information. The process of tagging information is not newit is commonly donewithin specific datasets or databases. What is new isusing the cloud in combination with the technique tomake it available to a wide array of users. This is animportant distinction, as an important advantage of thedata lake is there is no need to build, tear down, andrebuild rigid data structures.

    The most transformative aspect of a cloud analyticsreference architecture that incorporates a data lake isthat users do not need to have the possible answersin mind when they ask questions. Instead, they canlet the data talk to them. The ability to make complexinquiries, easily switching in and out any number of variables, allows users to look for patterns, and then

    follow them wherever they may lead. This is particularly important in predictive analytics, when people may notknow exactly what they are seeking. This capability strengthens the power of inquiry by empoweringdata to help reveal new or broader questions and

    correlations, expanding insight into scenarios andchallenges. Importantly, a data lake also helps drawfrom unstructured and streaming data, which existin forms that cannot be directly placed in structured

    databases and data sets.Our prior work with another intelligence-drivenorganization shows that a data lake can be employedeven when classified information is at issue by puttingappropriate levels of security and authorization inplace. The solution called for predictive analyticsto use existing data to forecast potential eventsand detect anomalies in order to extract potentially significant information and patterns. Our designfocused on keeping transactional-based queries in thecurrent relational databases, while doing the heavy lifting in the cloud and outputting the results intorelational data stores for quick access.

    The new cloud solution provided immediate andstriking improvements across the increasing volumeof structured and unstructured data using aggressiveindexing techniques, on-demand analytics, and pre-computed results for common analytics. By combiningsophistication with scalability, the solution helped movethe organization from a situation in which analystsstitched together sparse bits of data to a platform for

    distilling real-time, actionable information from the fullaggregation of data.

    Many such opportunities now exist in HomelandSecurity. For example, the National Cybersecurity andCommunications Integration Center (NCCIC) faces thechallenge of making full use of the numerous datafeeds it receives from a variety of government, private-sector, and other organizations. Because much of thedata is unstructured, or resides in discrete data setsthat are difficult to connect, NCCIC may get only apartial, delayed picture of cyber and communicationsincidents. Booz Allen Hamiltons Cloud-based Serviceswould enable NCCIC to consolidate all its availabledataof every type, from all sourcesand thenautomatically search through its entirety for importantcorrelations and patterns. With this ability to put all the

  • 7/27/2019 Homeland Security Articles Data Insights

    6/9

    5

    pieces together and see the full picture, NCCIC couldbetter respond to incidents in real time, and providemore accurate situational awareness to stakeholders.

    In another example, Cloud-based Services wouldenable DHS and the Department of Justice (DOJ) tointegrate the intelligence they gather in their sharedSouthwest border mission. Currently, the critical ability of the two agencies to gain a common operatingpicture is hampered not just by the wide range of structured and unstructured data collected, but alsoby the various restrictions, authorities and security issues around storing, managing and accessing thatdata. Through Cloud-based Services, DHS and DOJ cancreate a common operating picture while maintainingthe different sets of rules for the dataall in onesystem, rather than in many. This ultimately frees themission operators and the IT organizations supportingthem from the need for proprietary solutions, and fromthe resource-depleting operations and maintenancecosts tied to those solutions.

    Cloud-based Services would also allow DHS to breakthrough major cost barriers with a shared dataenvironment for the departments component agencies.Currently, agencies often share space at data centers.Cloud-based Services takes a major step forward by

    creating an environment in which the agencies sharea common data pool, as well as reusable analytic andvisualization software that taps into the pool. Whatoccurs is a decoupling of the data from the software,substantially driving down costs and creating previously unobtainable economies of scale.

    Oversight and Backing Of course, DHS will need to maintain adequategovernance of its data to help decide which informationis included in the data lake and who is authorized to

    access it. To this end, DHS will need a dedicated teamto provide this level of governance. Many commercialenterprises have turned to a chief data officer (CDO)to serve this function and increase the transparency

    of their data. This idea, or something like it, couldserve DHS well. The CDO and their staff should notbe confused with a chief information officer or chief technology officer. Where these other two functions

    provide general infrastructure support to the rest of theorganization in a commercial setting, CDOs work muchmore closely with the lines of business to tap data forspecific objectives.

    Financial services firms, among the first to create sucha position, have turned to CDOs to drive their datamanagement strategy and establish a data governancestructure to determine who owns and manages theinformation. Their experiences could be particularly instructive in a homeland security setting, given thevast array of data they collect, as well as their need tosafeguard sensitive information.

    Indeed, this last consideration has proved problematicfor DHS in the past; its easier to protect informationwhen security is at stake than risk exposing it tosomeone without the proper authorization. A criticalpart of the CDOs role would be to define theparameters for data ownership and stewardship. TheCDO would also help determine legal restrictions onthe use of data. When certain data are combined, itcan create a collision of legal authorities. On its own,

    one piece of information may not be classified or lawenforcement sensitive, but combining that informationwith other data may yield insights that need to beprotected for national security or prosecutorial reasons.

    A strong governance function may also be influentialin securing support from outside the organization.Whether the solution takes the form of a data lakeor some other vehicle, it likely wont go far withouta legislative mandate. The legacy structure of itsseven operating components and other agencies hassupported a view that information is a commodity that must be protected, and only disseminated ona need-to-know basis. The agency will also face thereality of convincing incoming political leaders to makeshort-term investments for long-term gains. Change

  • 7/27/2019 Homeland Security Articles Data Insights

    7/9

    management is tough enough for private companiesitis that much more difficult for federal agencies whosesenior leaders are in a state of constant flux. Eventhe best-laid plans can get disrupted or derailed when

    those who call the shots inevitably change.Without a legislative or statutory mandate to serve asa forcing event, DHS will not likely be able to fomentthe degree of change that is neededat least not atan acceptable rate. In some ways, the position DHSfinds itself in now is not dissimilar to that faced by the US Treasury Department in the aftermath of thecredit crisis. At the time, it was clear that the financialservices industry had major gaps in trying to get itshands around all of the risks being taken with theadvent of credit default swaps and other advancedfinancial derivatives. The Treasury Departmentneeded financial data that was actionable andwould support decision-making at the highestlevels within the department.

    To help fill these gaps, Congress created an Officeof Financial Research (OFR) within the Treasury Department through the Wall Street Reform andConsumer Protection Act of 2010 (Dodd-Frank).The law created two units within OFRa data centerand a research and analysis centerto continually

    gather up and analyze detailed financial informationcollected from a variety of banks and other financialfirms. One of its first steps was to issue a request forproposals on an industry utility to create and generateidentification codes to help it obtain more granulardata on counterparty risk, long and short positions,collateral and collateral calls, and derivative positions.

    Given the complexity involved with the effort, and thereliance on private sector contributions, OFR wouldnot have been possible were it not provided for instatute. It may be too early to judge whether OFR willbe a success or not, but it does show the power of a mandate to force organizational change where theavailability of information is restricted.

    Conclusion: A Data-Driven FutureThe political feasibility of winning such a mandate fora data-driven approach at DHS is an open question.To win support for such a mandate, it will be critical

    that DHS and its components present the opportunity to be more effective and cost-efficient in real terms.DHS will continue to collect and store data regardlessof whether such a mandate exists. The cost of thoseefforts will not go away. The question is whether DHSis empowered to make better use of those resourcesby increasing its awareness of the information thatexists. After all, you cant fight an enemy you dontknow. And, creating new channels to share informationonly works if you know what information you have atthe ready.

    The enterprise insights that come from these early efforts will likely produce some quick victories andattract the necessary buy-in to build incrementally from there and start developing a data repository withactual answersnot just questions. By thinking big,acting small, and going methodically step-by-step, DHShas the capability to lead where others continue tosquabble. Information is the key to this transformation.Treated as a commodity, it will continue to bestockpiled and stored away. Viewed as an asset,

    it will strengthen the nations homeland security enterprise and help DHS deliver on its many far-reaching mandates.

    Contacts Suzanne [email protected]

    Mike DelureyPrincipal

    [email protected]

  • 7/27/2019 Homeland Security Articles Data Insights

    8/9

    About Booz Allen

    To learn more about the firm and to download digital versions of this ar ticle and other Booz Allen Hamiltonpublications, visit www.boozallen.com .

    Booz Allen Hamilton has been at the forefront of strategy and technology consulting for nearly acentury. Today, Booz Allen is a leading provider of management and technology consulting servicesto the US government in defense, intelligence, andcivil markets, and to major corporations, institutions,

    and not-for-profit organizations. In the commercialsector, the firm focuses on leveraging its existingexpertise for clients in the financial services,healthcare, and energy markets, and to internationalclients in the Middle East. Booz Allen offers clientsdeep functional knowledge spanning strategy andorganization, engineering and operations, technology,and analyticswhich it combines with specializedexpertise in clients mission and domain areas tohelp solve their toughest problems.

    The firms management consulting heritage isthe basis for its unique collaborative culture andoperating model, enabling Booz Allen to anticipateneeds and opportunities, rapidly deploy talent and

    resources, and deliver enduring results. By combininga consultants problem-solving orientation with deeptechnical knowledge and strong execution, Booz Allenhelps clients achieve success in their most criticalmissionsas evidenced by the firms many clientrelationships that span decades. Booz Allen helps

    shape thinking and prepare for future developmentsin areas of national importance, includingcybersecurity, homeland security, healthcare,and information technology.

    Booz Allen is headquartered in McLean, Virginia,employs approximately 25,000 people, and hadrevenue of $5.86 billion for the 12 months endedMarch 31, 2012. Fortune has named Booz Allen oneof its 100 Best Companies to Work For for eightconsecutive years. Working Mother has ranked thefirm among its 100 Best Companies for WorkingMothers annually since 1999. More information isavailable at www.boozallen.com. (NYSE: BAH)

    http://www.boozallen.com/http://www.boozallen.com/
  • 7/27/2019 Homeland Security Articles Data Insights

    9/9

    www.boozallen.com

    The most complete, recent list of offices and their addresses and telephone numbers can be found onwww.boozallen.com

    Principal OfficesHuntsville, Alabama

    Sierra Vista, Arizona

    Los Angeles, California

    San Diego, California

    San Francisco, California

    Colorado Springs, Colorado

    Denver, Colorado

    District of Columbia

    Orlando, Florida

    Pensacola, Florida

    Sarasota, Florida

    Tampa, Florida

    Atlanta, Georgia

    Honolulu, Hawaii

    OFallon, Illinois

    Indianapolis, Indiana

    Leavenworth, Kansas

    Aberdeen, Maryland

    Annapolis Junction, Maryland

    Hanover, Maryland

    Lexington Park, Maryland

    Linthicum, Maryland

    Rockville, Maryland

    Troy, Michigan

    Kansas City, Missouri

    Omaha, Nebraska

    Red Bank, New Jersey

    New York, New York

    Rome, New York

    Dayton, Ohio

    Philadelphia, Pennsylvania

    Charleston, South Carolina

    Houston, Texas

    San Antonio, Texas

    Abu Dhabi, United Arab Emirates

    Alexandria, Virginia

    Arlington, Virginia

    Chantilly, Virginia

    Charlottesville, Virginia

    Falls Church, Virginia

    Herndon, Virginia

    McLean, Virginia

    Norfolk, Virginia

    Stafford, Virginia

    Seattle, Washington

    2012 Booz Allen Hamilton Inc.

    BA12 269Use of DoD imager does not constit te or impl endorsement