IT Governance | OCIO

​​​IT Governance is an integral part of enterprise governance and consists of the leadership and organizational structures and processes that ensure that the organization's IT sustains and extends the organization's strategies and objectives. (IT Governance Institute, ITGI)

NIH IT priorities are driven by scientific program needs as guided by NIH's governance and planning processes which include extensive input from key stakeholders through multi-layered advisory structures.

The NIH IT governance process provides for a high-level, trans-NIH strategic approach to IT management. It provides a structured decision-making process around IT investment decisions and promotes accountability, due diligence, and efficient and economic delivery of enterprise IT services.

The Clinger-Cohen Act of 1996 establishes a definitive framework for IT investment management that requires federal agencies to focus on the results they have achieved through IT initiatives and introduces more rigor and structure into how agencies select and manage IT projects.

The Federal Information Technology Acquisition Reform Act (FITARA) of 2014 
outlines specific requirements related to:

  • Agency Chief Information Officer (CIO) Authority Enhancements
  • Enhanced Transparency and Improved Risk Management in IT Investments
  • Portfolio Review
  • Federal Data Center Consolidation Initiative
  • Expansion of Training and Use of IT Cadres
  • Maximizing the Benefit of the Federal Strategic Sourcing Initiative
  • Governmentwide Software Purchasing Program


NIH OCIO is working collaboratively with the Department of Health and Human Services (HHS) to set up the structure for meeting FITARA requirements, ensuring that NIH has input into OMB and HHS policies, guidance, and IT management activities.

Likewise, the OCIO collaborates with NIH ICs to implement the requirements of FITARA and Clinger Cohen. NIH OCIO enables and supports the NIH mission by playing a crucial role in IT governance, helping the NIH ICs and OD align information technology investments with the organization’s mission.
 

NIH OCIO’s supportive role in IT governance at NIH includes the following:

  • Collaborates with NIH ICs to develop effective and appropriate IT governance for NIH investments, and IT capital planning and investment control activities
  • Assures critical support to the NIH IT community and its essential activities through development, implementation, and management of NIH IT policy and related guidance
  • Interprets and defines the NIH implementation of relevant laws, regulations, and HHS, Office of Management and Budget (OMB), and other Federal mandates
  • Reviews NIH investment assessments and reports from General Accounting Office (GAO), OMB and HHS and collaborates with investment managers to provide responses as appropriate
  • Develops IT management tools and training
  • Provides staff support to IT management committees, governance groups, and work groups
  • Conducts special projects and initiatives

IT Budget

Investments in Information Technology (IT) can dramatically enhance organizational performance. When carefully managed, IT becomes a critical enabler to improve business processes, make information widely available, and reduce the cost of providing essential Government services. Congress and the Office of Management and Budget (OMB) have clearly stated that each executive agency must actively manage its IT program to ensure that technology expenditures are necessary and will result in demonstrated improvements in mission effectiveness and customer service.

The HHS Policy for Information Technology Portfolio Management (PFM) policy provides an integrated, structured methodology for managing HHS IT investments, to ensure that IT investments align with HHS’ mission, support business needs, minimize risks, and maximize returns throughout the investment’s lifecycle. The Office of Management and Budget’s (OMB) Circular A-11 requires all agencies to report on their capital IT Investments through the Agency IT Portfolio Summary (formerly called the Exhibit 53), and to report additional information for major IT investments through the Major IT Investment Business Case (formerly the Exhibit 300).

The NIH Office of the CIO (OCIO) serves as the central coordinator for the collection of NIH IT Budget information for the OMB Agency IT Portfolio Summary and the Major IT Investment Business Case as required by HHS Policy.

OCIO’s supportive role in the NIH IT Budget process includes the following services:

  • Represents NIH interests and needs to the HHS CPIC program
  • Prepares and distributes guidance on budget reporting requirements for the NIH Institutes and Centers (ICs)
  • Provides assistance to NIH ICs as they develop their IT budgets
  • Conducts quality assurance reviews of submitted materials
  • Coordinates related IT data calls from HHS, OMB, and other Federal entities
  • Ensures timely reporting of NIH data per HHS requirements

References

IT Policy, Standards and Guidance

The OCIO provides the following services to the NIH community:

  • Educates and guides the NIH community on the federal, HHS and other high-level policies, regulations, and laws that drive NIH-level IT requirements
  • Collaborates with the IT and broader NIH communities to develop, vet, implement and administer NIH IT-related policy, standards and guidance
  • Ensures that NIH management and staff have the proper information they need to effectively and efficiently use and protect valuable NIH IT resources and data.

A list of the current IT-related policies, standards and guidance is provided by subject area below.

The Information Security policies are geared towards users inside the NIH network. If you need any information related to Information Security policies please contact: nihisaopolicy@mail.nih.gov. If you have questions about general IT policies please contact: nihciocommunications@mail.nih.gov.

More Information

IT policies, standards and guidance issued by external IT governance organizations and followed by NIH can be found at External IT Governance and Oversight under IT Governance & Policy.

Contact

General IT Policy
Email nihciocommunications@mail.nih.gov
Phone 301-496-1168

Information Security Policy
Email nihisaopolicy@mail.nih.gov 

Managing IT Projects and Investments

The Office of Management and Budget (OMB) and the Congress are setting ever higher standards for the management and performance of information technology investments within the Federal government. Those standards require a project management and accountability environment where IT projects and IT investments achieve consistently successful outcomes that maximize alignment with business objectives and meet key cost, schedule and performance objectives. In planning IT investments and projects, the following factors need to be considered: strategic and tactical planning, enterprise architecture, IT security, acquisition strategy, records management, CPIC, EPLC, and FITARA.

Capital Planning and Investment Control (CPIC)*

Capital Planning and Investment Control (CPIC) is the primary IT governance and management methodology at HHS for selecting, managing, and evaluating the performance of IT investments. Adherence to the CPIC Policy ensures that NIH IT investments are selected based on their support of NIH and HHS business needs and mission requirements; that selected investments meet approved cost, schedule, and performance milestones; and that they successfully achieve specified benefits and outcomes throughout the IT Investment life cycle. Appropriate level review boards provide timely oversight of IT investments.

NIH CPIC/IT Budgeting reporting is coordinated by the NIH Office of the CIO (OCIO) in conjunction with the ICs. For more information about the IT Budget, see the NIH OCIO IT Budget page.

The HHS Policy for Information Technology Portfolio Management (PFM)

Enterprise Performance Life Cycle (EPLC)*

The HHS Enterprise Performance Life Cycle (EPLC) Policy provides an enterprise-wide, standard methodology for planning, managing, and overseeing IT projects over their entire life cycle. It establishes ten standard life cycle phases and project and stage gate reviews for IT projects. This policy incorporates the EPLC as a partner to CPIC and HHS Enterprise Architecture.

For information about how EPLC is implemented at NIH, please see the NIH Project Management EPLC page.

HHS Policy for Information Technology Enterprise Performance Life Cycle (EPLC)

Federal IT Acquisition Reform Act (FITARA)

FITARA covers Chief Information Officer (CIO) authority enhancements, enhanced transparency and improved risk management in information technology investments, Portfolio review, Federal data center consolidation initiative, expansion of training and use of information technology cadres, and maximizing the benefit of the Federal strategic sourcing initiative and Governmentwide software purchasing program.

* Whereas the HHS IT EPLC Policy addresses IT project requirements, the HHS CPIC Policy addresses IT Investments (which may be comprised of one or more IT projects) and IT portfolio management requirements.

The Department of Health and Human Services (HHS)

HHS Office of the Chief Information Officer (OCIO)

The office reports to the Assistant Secretary for Administration and supports the HHS mission by leading the development and implementation of information technology infrastructure across the agency.

Selected HHS Policy and Standards