<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="stratml.xsl"?>
<StrategicPlan><id/><Name>U.S. Digital Services Playbook</Name><Description>The American people expect to interact with government through digital channels such as websites, email, and mobile applications. By building better digital services that meet the needs of the people that use our services, we can make the delivery of our policy and programs more effective.</Description><OtherInformation>Today, too many of our digital services projects do not work well, are delivered late, or are over budget. To increase the success rate of these projects, the U.S. Government needs a new approach. We created a playbook of 13 key “plays” drawn from successful best practices from the private sector and government that, if followed together, will help government build effective digital services.</OtherInformation><StrategicPlanCore><Organization><Name>U.S. CIO Council</Name><Acronym>CIOC</Acronym><Identifier>_6e3ed4bc-439d-11e4-a6a7-d9492e61dbbf</Identifier><Description/><Stakeholder><Name/><Description/></Stakeholder></Organization><Vision><Description/><Identifier>_6e3ed7d2-439d-11e4-a6a7-d9492e61dbbf</Identifier></Vision><Mission><Description>To help government build effective digital services</Description><Identifier>_6e3edb38-439d-11e4-a6a7-d9492e61dbbf</Identifier></Mission><Value><Name/><Description/></Value><Goal><Name>Needs</Name><Description>Understand what people need</Description><Identifier>_6e3edc50-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>We must begin digital projects by exploring and pinpointing the needs of the people who will use the service, and the ways in which the service will fit into their lives. Whether the users are members of the public or government employees, policy makers must include real people in their design process from the very beginning. The needs of people -- not constraints of government structures or silos -- should drive technical and design decisions. We need to continually test the products we build with real people to keep us honest about what is important...
key questions: 
What user needs will this service address?
Why does the user want or need this service?
Who are your key users?
Which people will have the most difficulty with your service?
What research methods were used?
What were the key findings from users’ current experience?
How were the findings documented? Where can future team members access the documentation?
How often are you testing with real people?</OtherInformation><Objective><Name>Consultation</Name><Description>Early in the project, spend time with current and prospective users of the service</Description><Identifier>_6e3edd22-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>User Research</Name><Description>Use a range of qualitative and quantitative user research methods to determine people’s goals, needs, and behaviors</Description><Identifier>_6e3eddf4-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>1.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>be thoughtful about the time spent</OtherInformation></Objective><Objective><Name>Prototypes</Name><Description>Test prototypes of possible solutions with real people, in the field if possible</Description><Identifier>_6e3edec6-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>1.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Documentation</Name><Description>Document the findings about user goals, needs, behaviors, and preferences</Description><Identifier>_6e3edfa2-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>1.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Findings</Name><Description>Share findings with the team and agency leadership</Description><Identifier>_6e3ee074-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>1.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Goals &amp; Priorities</Name><Description>Create a prioritized list of user stories, which are short descriptions of the goals the user is trying to accomplish</Description><Identifier>_6e3ee146-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>1.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Testing</Name><Description>As the digital service is being built, regularly test it with potential users to ensure it will meet peoples’ needs</Description><Identifier>_6e3ee218-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>1.7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Whole Experience</Name><Description>Address the whole experience, from start to finish</Description><Identifier>_6e3ee2f4-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>We must build digital services with an understanding of the range of ways a person might interact with our service, including the actions they take online, through a mobile application, on the phone, or in person. Every encounter should move the user closer towards the desired outcome, whether that encounter is online or offline...
key questions:
What are the different ways (both online and offline) that people currently accomplish the task the digital service is designed to help with?
Where are user pain points in the current way people accomplish the task?
Where does this specific project fit into the larger way people currently obtain the service being offered?
What metrics will best indicate how well the service is working for its users?</OtherInformation><Objective><Name>Interaction Points</Name><Description>Understand the different points at which people will interact with the service – both online and in person</Description><Identifier>_6e3ee3d0-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Pain Points</Name><Description>Identify pain points in the current way users interact with the service, and prioritize these according to user needs</Description><Identifier>_6e3ee4ac-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>2.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Digital Services</Name><Description>Design the digital parts of the service so that they are integrated with the offline touch points people use to interact with the service</Description><Identifier>_6e3ee57e-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>2.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Metrics</Name><Description>Develop metrics that will measure how well the service is meeting user needs, at each step of the service</Description><Identifier>_6e3ee65a-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>2.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Simplicity &amp; Intuitiveness</Name><Description>Make it simple and intuitive</Description><Identifier>_6e3ee72c-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Using a government service shouldn’t be stressful, confusing, or daunting -- it’s our job to build services that are simple and intuitive enough that users succeed the first time, unaided...
key questions:
What primary tasks are the user trying to accomplish?
What is the reading level of the language the service uses?
What languages is your service offered in?
If a user needs help while using the service how do they go about getting it?
How does the service’s design visually relate to other government services?</OtherInformation><Objective><Name>Style Guide</Name><Description>Create or use an existing, simple, and flexible design style guide for the service</Description><Identifier>_6e3ee812-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>3.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Cross-Service Style</Name><Description>Use the design style guide across related digital services</Description><Identifier>_6e3ee90c-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>3.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>User Process Information</Name><Description>Provide users with clear information about where they are in the process as they use the service</Description><Identifier>_6e3eea74-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>3.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Accessibility</Name><Description>Follow accessibility best practices to ensure all people can use the service</Description><Identifier>_6e3eeb64-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>3.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Exit &amp; Return</Name><Description>Provide users with a way to exit and return later to complete the process</Description><Identifier>_6e3eec4a-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>3.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Plain Language</Name><Description>Use language that is familiar to the user and is easy to understand</Description><Identifier>_6e3eed30-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>3.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Consistency</Name><Description>Use language and design consistently throughout the service, including in the online and offline (non-digital) touch points people use to interact with the service</Description><Identifier>_6e3eee20-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>3.7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Agility &amp; Iteration</Name><Description>Build the service using agile and iterative practices</Description><Identifier>_6e3eef1a-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>We should use an incremental, fast-paced style of software development to reduce the risk of failure by getting working software into users’ hands quickly, and by providing frequent opportunities for the delivery team members to adjust requirements and development plans based on watching people use prototypes and real software. A critical capability is being able to automatically test and deploy the service so that new features can be added often and easily put into production. Following agile methodologies is a proven best practice for building digital services, and will increase our ability to build services that effectively meet user needs...
key questions: 
How long did it take to ship the MVP? If it has not shipped yet, when will it?
How long does it take for a production deployment?
How long in days are the iterations/sprints?
Which source code version control system is being used?
What tool is being used to track bugs and issue tickets?
What tool is being used to manage the feature backlog?
How often do you review and reprioritize the items in your feature and bug backlog?
How do you collect user feedback during development and how is that feedback to improve the service?
At each stage of usability testing, what gaps were identified in addressing user needs?</OtherInformation><Objective><Name>Minimum Viable Product</Name><Description>Ship a functioning “minimum viable product” (MVP) that solves a core user need addressed by the service as soon as possible, and not longer than three months from the beginning of any new digital project, using a “beta” or “test” period if needed</Description><Identifier>_6e3ef01e-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>4.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Usability Testing</Name><Description>Run usability tests frequently to see how well the service works for users, and identify improvements that should be made</Description><Identifier>_6e3ef154-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>4.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Communication</Name><Description>Ensure the individuals building the service are in close communication using techniques such as war rooms, daily standups, and team chat tools</Description><Identifier>_6e3ef244-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>4.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Delivery Teams</Name><Description>Keep delivery teams small and focused</Description><Identifier>_6e3ef334-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>4.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>limit organizational layers that separate these teams from the business owners</OtherInformation></Objective><Objective><Name>Releases</Name><Description>Release features and improvements multiple times each month</Description><Identifier>_6e3ef532-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>4.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Features &amp; Bugs</Name><Description>Create a prioritized list of features and bugs, also known as the “feature backlog” and “bug backlog”</Description><Identifier>_6e3ef62c-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>4.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Issue Tracking</Name><Description>Use an “issue tracker” to catalog features and bugs</Description><Identifier>_6e3ef71c-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>4.7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Version Control</Name><Description>Use a source code version control system</Description><Identifier>_6e3ef83e-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>4.8</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Team Access</Name><Description>Ensure entire team has access to the issue tracker and version control system</Description><Identifier>_6e3ef9a6-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>4.9</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Code Reviews</Name><Description>Use code reviews to ensure quality</Description><Identifier>_6e3efaaa-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>4.10</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Budgets &amp; Contracts</Name><Description>Structure budgets and contracts to support delivery</Description><Identifier>_6e3efbb8-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>To improve our chances of success when contracting out development work, we need to work with experienced budgeting and contracting officers. In cases where we use third parties to help build a service, a well-defined contract can facilitate good development practices like conducting a research and prototyping phase, refining product requirements as the service is built, evaluating open source alternatives, ensuring frequent delivery milestones, and allowing the flexibility to purchase cloud computing resources.  
The TechFAR Handbook provides a detailed explanation of the flexibilities in the Federal Acquisition Regulation (FAR) that can help agencies implement this play...
key questions: 
How frequent are the delivery milestones?
What are the performance metrics defined in the contract? (i.e., response time, system uptime, time period to address priority issues, etc.)</OtherInformation><Objective><Name>Budget</Name><Description>Budget includes research, discovery, and prototyping activities</Description><Identifier>_6e3efcb2-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>5.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Deliverables</Name><Description>Contract is structured to request frequent deliverables and not multi-month milestones</Description><Identifier>_6e3efdac-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>5.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Accountability</Name><Description>Contract is structured to hold vendors accountable to deliverables</Description><Identifier>_6e3efec4-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>5.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Flexibility</Name><Description>Contract allows the government delivery team the flexibility to adjust feature prioritization as the project evolves</Description><Identifier>_6e3effe6-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>5.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Open Source &amp; COTS</Name><Description>Contract ensures open source solutions are evaluated alongside commercial solutions when technology choices are made</Description><Identifier>_6e3f00e0-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>5.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Public Domain</Name><Description>Contract specifies that software and data generated by third parties remains under our control, and can be reused and released to the public as appropriate and in accordance with the law</Description><Identifier>_6e3f0202-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>5.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Tools, Services &amp; Hosting</Name><Description>Contract allows us to use tools, services, and hosting from vendors with a variety of pricing models, including fixed fees and variable service-based models like “pay-for-what-you-use” services</Description><Identifier>_6e3f0324-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>5.7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Warranties</Name><Description>Contract specifies a warranty period where defects uncovered by the public are addressed by the vendor(s) at no additional cost to the government</Description><Identifier>_6e3f0432-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>5.8</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Transitioning</Name><Description>Contract includes a transition of services period and transition-out plan</Description><Identifier>_6e3f0554-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>5.9</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Leadership &amp; Accountability</Name><Description>Assign one leader and hold that person accountable</Description><Identifier>_6e3f0662-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>There must be a single product owner who has the authority and responsibility across teams to assign tasks and work elements; make business, product, and technical decisions; and is accountable for the success or failure of the overall service. This product owner is ultimately responsible for how well the service is meeting the needs of its users, which is how a service should be evaluated. The product owner is responsible for ensuring the features are built and managing the feature and bug backlogs...
key questions:  
Who is the product owner?
What organizational changes have been made to ensure the product owner has sufficient authority over and support for the project?
What does it take for the product owner to add or remove a feature from the service?</OtherInformation><Objective><Name>Product Owner</Name><Description>A product owner has been identified</Description><Identifier>_6e3f0770-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>6.1</SequenceIndicator><Stakeholder><Name>Product Owner</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Stakeholder Agreement</Name><Description>All stakeholders agree that the product owner has the authority to assign tasks and make decisions about features and technical implementation details</Description><Identifier>_6e3f089c-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>6.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Background &amp; Expertise</Name><Description>The product owner has a product management background with technical experience to assess alternatives and weigh tradeoffs</Description><Identifier>_6e3f09d2-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>6.3</SequenceIndicator><Stakeholder><Name>Product Owner</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Work Plan</Name><Description>The product owner has a work plan that includes budget estimates and identification of funding sources</Description><Identifier>_6e3f0b76-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>6.4</SequenceIndicator><Stakeholder><Name>Product Owner</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Relationships</Name><Description>The product owner has a strong relationship with his or her contracting officer</Description><Identifier>_6e3f0e3c-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>6.5</SequenceIndicator><Stakeholder><Name>Product Owner</Name><Description/></Stakeholder><Stakeholder><Name>Contracting Officer</Name><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Experience</Name><Description>Bring in experienced teams</Description><Identifier>_6e3f0f5e-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 7</SequenceIndicator><Stakeholder><Name>Product Managers</Name><Description/></Stakeholder><Stakeholder><Name>Product Engineers</Name><Description/></Stakeholder><Stakeholder><Name>Product Designers</Name><Description/></Stakeholder><OtherInformation>We need talented people working in government who have experience creating modern digital services. This includes bringing in seasoned product managers, engineers, and designers. When outside help is needed, our teams should work with contracting officers who understand how to evaluate third-party technical competency so our teams can be paired with contractors who are good at both building and delivering effective digital services. The makeup and experience requirements of the team will vary depending on the scope of the project.</OtherInformation><Objective><Name>Experience</Name><Description>Member(s) of the team have experience building popular, high-traffic digital services</Description><Identifier>_6e3f1076-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>7.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Mobile &amp; Web Apps</Name><Description>Member(s) of the team have experience designing mobile and web applications</Description><Identifier>_6e3f11d4-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>7.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Automated Testing</Name><Description>Member(s) of the team have experience using automated testing frameworks</Description><Identifier>_6e3f12f6-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>7.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Modern DevOps</Name><Description>Member(s) of the team have experience with modern development and operations (DevOps) techniques such as continuous integration and continuous deployment</Description><Identifier>_6e3f1490-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>7.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Service Security</Name><Description>Member(s) of the team have experience securing digital services</Description><Identifier>_6e3f1698-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>7.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Contracting Officer</Name><Description>A Federal contracting officer is on the internal team if a third party will be used for development work</Description><Identifier>_6e3f17ba-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>7.6</SequenceIndicator><Stakeholder><Name>Contracting Officer</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Budget Officer</Name><Description>A Federal budget officer is on the internal team or is a partner</Description><Identifier>_6e3f18e6-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>7.7</SequenceIndicator><Stakeholder><Name>Budget Officer</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Privacy, Civil Liberties &amp; Legal Advisor</Name><Description>The appropriate privacy, civil liberties, and/or legal advisor for the department or agency is a partner</Description><Identifier>_6e3f1a30-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>7.8</SequenceIndicator><Stakeholder><Name>Privacy Advisor</Name><Description/></Stakeholder><Stakeholder><Name>Civil Liberties Advisor</Name><Description/></Stakeholder><Stakeholder><Name>Legal Advisor</Name><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Technology Stack</Name><Description>Choose a modern technology stack</Description><Identifier>_6e3f1c2e-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 8</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>The technology decisions we make need to enable development teams to work efficiently and enable services to scale easily and cost-effectively. Our choices for hosting infrastructure, databases, software frameworks, programming languages and the rest of the technology stack should seek to avoid vendor lock-in and match what successful modern consumer and enterprise software companies would choose today. In particular, digital services teams should consider using open source, cloud based, and commodity solutions across the technology stack, as these solutions have seen widespread adoption and support by the most successful private-sector consumer and enterprise software technology companies...
key questions:  
What is your development stack and why did you choose it?
What database(s) are you using and why did you choose them?
How long does it take for a new team member to set up a local development environment?</OtherInformation><Objective><Name>Software Frameworks</Name><Description>Choose software frameworks that are commonly used by private-sector companies creating similar services</Description><Identifier>_6e3f1dbe-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>8.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Software Deployment</Name><Description>To the extent practical, ensure that software can be deployed on a variety of commodity hardware types</Description><Identifier>_6e3f1f12-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>8.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Instructions</Name><Description>Ensure that each project has easy to understand instructions for setting up a local development environment, and that team members can be quickly added or removed from projects</Description><Identifier>_6e3f203e-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>8.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Open Source Software</Name><Description>Consider open source software solutions at all layers of the stack</Description><Identifier>_6e3f219c-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>8.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Hosting Environment</Name><Description>Deploy in a flexible hosting environment</Description><Identifier>_6e3f2318-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 9</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Our services should be deployed on flexible infrastructure, where resources can be provisioned in real time to meet spikes in user demand. Our digital services are crippled when we host them in data centers which market themselves as “cloud hosting” but require us to manage and maintain hardware directly. This outdated practice wastes time, weakens our disaster recovery plans, and results in significantly higher costs...
key questions
Where is your service hosted?
What hardware does your service use to run?
What is the demand / usage pattern for your service?
What happens to your service when it experiences a surge in traffic or load?
How much capacity is available in your hosting environment?
How long does it take you to provision a new resource such as an application server?
How have you designed your service to scale based on demand?
How are you paying for your hosting infrastructure — i.e., by the minute, hourly, daily, monthly, fixed?
Is your service hosted in multiple regions / availability zones / data centers?
In the event of a catastrophic disaster to a datacenter, how long will it take to have the service operational?
What would be the impact of a prolonged downtime window?
What data redundancy do you have built into the system, and what would be the impact of a catastrophic data loss?
How often do you need to contact a person from your hosting provider to get resources or to fix an issue?</OtherInformation><Objective><Name>Provisioning</Name><Description>Resources are provisioned on demand</Description><Identifier>_6e3f244e-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>9.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Scaling</Name><Description>Resources scale based on real-time user demand</Description><Identifier>_6e3f261a-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>9.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>APIs</Name><Description>Resources are provisioned through an API</Description><Identifier>_6e3f2796-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>9.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Availability</Name><Description>Resources are available in multiple regions</Description><Identifier>_6e3f28d6-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>9.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Usage</Name><Description>We pay only for the resources we use</Description><Identifier>_6e3f2a34-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>9.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Static Assets</Name><Description>Static assets are served through a content delivery network</Description><Identifier>_6e3f2c50-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>9.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Hardware</Name><Description>Application is hosted on commodity hardware</Description><Identifier>_6e3f2e12-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>9.7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Testing &amp; Deployment</Name><Description>Automate testing and deployments</Description><Identifier>_6e3f302e-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 10</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Today, developers write automated scripts that can verify thousands of scenarios in minutes and then deploy updated code into production environments multiple times per day. They use automated performance tests which simulate surges in traffic to identify performance bottlenecks. While manual tests and quality assurance is still necessary, automated tests provide consistent and reliable protection against unintentional regressions, and make it possible for developers to confidently release frequent updates to the service...
key questions:  
What percentage of the code base is covered by automated tests?
How long does it take to build, test, and deploy a typical bug fix?
How long does it take to build, test, and deploy a new feature into production?
How frequently are builds created?
What test tools are used?
What deployment automation or continuous integration tools are used?
What is the estimated maximum number of concurrent users who will want to use the system?
How many simultaneous users could the system handle, according to the most recent capacity test?
How does the service perform when you exceed the expected target usage volume? Does the service degrade gracefully or catastrophically?
What is your scaling strategy when demand increases suddenly?</OtherInformation><Objective><Name>User-Facing Functionality</Name><Description>Create automated tests that verify all user-facing functionality</Description><Identifier>_6e3f31b4-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>10.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Unit &amp; Integration Tests</Name><Description>Create unit and integration tests to verify modules and components</Description><Identifier>_6e3f338a-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>10.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Test Automation</Name><Description>Run tests automatically as part of the build process</Description><Identifier>_6e3f34d4-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>10.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Deployments</Name><Description>Perform deployments automatically with deployment scripts, continuous delivery services, or similar techniques</Description><Identifier>_6e3f36a0-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>10.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Load &amp; Performance Testing</Name><Description>Conduct load and performance tests at regular intervals, including before public launch</Description><Identifier>_6e3f37f4-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>10.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Security &amp; Privacy</Name><Description>Manage security and privacy through reusable processes</Description><Identifier>_6e3f393e-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 11</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>It is critical that our digital services protect sensitive information and keep systems secure. This is typically a process of continuous review and improvement which should be built into the development and maintenance of the service. At the start of designing a new service or feature, the team lead should engage the appropriate privacy, security, and legal officer(s) to discuss the type of information collected, how it should be secured, and how it may be used and shared. The sustained engagement of a privacy specialist helps ensure that personal data is properly managed. In addition, a key process to building a secure service is comprehensively testing and certifying the components in each layer of the technology stack for security vulnerabilities, and then to re-use these same pre-certified components for multiple services.The following checklist provides a starting point, but teams should work closely with their privacy specialist and security engineer to meet the needs of the specific service...
PLAY 11

Manage security and privacy through reusable processesIt is critical that our digital services protect sensitive information and keep systems secure. This is typically a process of continuous review and improvement which should be built into the development and maintenance of the service. At the start of designing a new service or feature, the team lead should engage the appropriate privacy, security, and legal officer(s) to discuss the type of information collected, how it should be secured, and how it may be used and shared. The sustained engagement of a privacy specialist helps ensure that personal data is properly managed. In addition, a key process to building a secure service is comprehensively testing and certifying the components in each layer of the technology stack for security vulnerabilities, and then to re-use these same pre-certified components for multiple services.The following checklist provides a starting point, but teams should work closely with their privacy specialist and security engineer to meet the needs of the specific service...
key questions:
Does the service collect personal information from the user (whether government or public)? How is the user notified of this collection?
Does it collect more information than is needed to perform the requested task? Are there uses of the data that would not be expected by the average user?
How does a user contact a responsible person to seek access, correction, deletion, or removal of his or her personal information?
Will information stored in the system be shared with others?
How and how often is the service tested for security vulnerabilities?
How can someone from the public report a security issue?</OtherInformation><Objective><Name>SORN &amp; PIA</Name><Description>Contact the appropriate privacy or legal officer of the department or agency to determine whether a System of Records Notice (SORN), Privacy Impact Assessment, or other review should be conducted</Description><Identifier>_6e3f3ae2-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>11.1</SequenceIndicator><Stakeholder><Name>Privacy Officers</Name><Description/></Stakeholder><Stakeholder><Name>Legal Officers</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Data Collection &amp; Preservation</Name><Description>Determine, in consultation with a records officer, what data is collected and why, how it is used or shared, how it is stored and secured, and how long it is kept</Description><Identifier>_6e3f3c40-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>11.2</SequenceIndicator><Stakeholder><Name>Records Officers</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>PI Notices</Name><Description>Determine, in consultation with a privacy specialist, whether and how users are notified about how personal information is collected and used, including whether a privacy policy is needed and where it should appear, and how users will be notified in the event of a security breach</Description><Identifier>_6e3f3dbc-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>11.3</SequenceIndicator><Stakeholder><Name>Privacy Specialists</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>User Access</Name><Description>Consider whether the user should be able to access, delete, or remove their information from the service</Description><Identifier>_6e3f3f56-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>11.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Hosting Infrastructure</Name><Description>“Pre-certify” the hosting infrastructure used for the project using FedRAMP
Use deployment scripts to ensure configuration of production environment remains consistent and controllable</Description><Identifier>_6e3f40be-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>11.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Data &amp; Decisions</Name><Description>Use data to drive decisions</Description><Identifier>_6e3f42c6-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 12</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>At all stages of a digital project, we should measure how well our service is working for our users. This includes measuring how well a system performs and how people are interacting with the system in real time. Our teams and agency leadership should carefully watch these metrics to proactively spot issues and identify which improvements should be prioritized. In addition to monitoring tools, a feedback mechanism should be in place for people to report issues directly...
key questions:  
What are the key metrics for the service?
How have these key metrics performed over the life of the service?
What system monitoring tool(s) are in place?
What is the targeted average response time for your service? What percent of requests take more than 1 second, 2 seconds, 4 seconds, and 8 seconds?
What is the average response time and percentile breakdown (percent of requests taking more than 1s, 2s, 4s, and 8s) for your service’s top 10 transactions?
What is your service’s monthly uptime target?
What is your service’s monthly uptime percentage including scheduled maintenance? Excluding scheduled maintenance?
How does your team receive automated alarms when incidents occur?
What is the volume of each of your service’s top 10 transactions? What is the percentage of transactions started vs. completed?
What tool(s) are in place to measure user behavior?
What tool/technology is used for A/B testing?
How do you measure customer satisfaction?</OtherInformation><Objective><Name>Utilization</Name><Description>Monitor system-level resource utilization in real time</Description><Identifier>_6e3f449c-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>12.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>System Performance</Name><Description>Monitor system performance, measuring response time, latency, throughput, and error rates in real-time</Description><Identifier>_6e3f462c-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>12.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Performance Monitoring</Name><Description>Ensure monitoring in place can measure median, 95th percentile and 98th percentile performance</Description><Identifier>_6e3f47b2-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>12.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Alerts</Name><Description>Create automated alerts based on this monitoring</Description><Identifier>_6e3f4960-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>12.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Concurrent Users &amp; Behaviors</Name><Description>Track concurrent users in real time, and monitor user behaviors (in the aggregate) to determine how well the service is meeting user needs</Description><Identifier>_6e3f4ad2-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>12.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Internal Metrics</Name><Description>Publish metrics internally</Description><Identifier>_6e3f4d16-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>12.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>External Metrics</Name><Description>Publish metrics externally</Description><Identifier>_6e3f4ec4-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>12.7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Multivariate Testing</Name><Description>Use an experimentation tool that supports multivariate testing in production</Description><Identifier>_6e3f5040-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>12.8</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Openness</Name><Description>Default to open</Description><Identifier>_6e3f51bc-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>Play 13</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>When we collaborate in the open and publish our data publicly we can improve Government together. By building services more openly and publishing open data, we simplify the public’s access to government services and information, allow the public to easily provide fixes and contributions, and enable reuse by entrepreneurs, nonprofits, other agencies, and the public...
key questions:
How are you collecting user feedback for bugs and issues?
If there is an API, what capabilities does it provide? Who uses it? How is it documented?
If the codebase has not been released under an open source license, explain why.
What components are made available to the public as open source?
What datasets are made available to the public?</OtherInformation><Objective><Name>User Feedback</Name><Description>Offer users a mechanism to report bugs and issues, and be responsive to these reports</Description><Identifier>_6e3f53f6-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>13.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Datasets</Name><Description>Provide datasets to the public, in their entirety, through bulk downloads and APIs (application programming interfaces)</Description><Identifier>_6e3f56c6-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>13.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Public Domain</Name><Description>Ensure that data from the service is explicitly in the public domain, and that rights are waived globally via an international public domain dedication, such as the “Creative Commons Zero” waiver</Description><Identifier>_6e3f5838-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>13.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Data Catalog</Name><Description>Catalog data in the agency’s enterprise data inventory and add any public datasets to the agency’s public data listing</Description><Identifier>_6e3f59f0-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>13.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Data Rights</Name><Description>Ensure that we maintain the rights to all data developed by third parties in such a manner that is releasable and reusable at no cost to the public</Description><Identifier>_6e3f5b80-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>13.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Software Rights</Name><Description>Ensure that we maintain contractual rights to all custom software developed by third parties in such a manner that is publishable and reusable at no cost</Description><Identifier>_6e3f5d1a-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>13.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>APIs</Name><Description>When appropriate, create an API for third parties to interact with the service directly</Description><Identifier>_6e3f5f22-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>13.7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Source Code</Name><Description>When appropriate, publish source code of projects or components online</Description><Identifier>_6e3f61ca-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>13.8</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Publicity</Name><Description>When appropriate, share your development process and progress publicly</Description><Identifier>_6e3f6364-439d-11e4-a6a7-d9492e61dbbf</Identifier><SequenceIndicator>13.9</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal></StrategicPlanCore><AdministrativeInformation><StartDate/><EndDate/><PublicationDate>2014-09-23</PublicationDate><Source>https://playbook.cio.gov/</Source><Submitter><FirstName>Owen</FirstName><LastName>Ambur</LastName><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></StrategicPlan>