Technical Evaluation Process

Designing and introducing a structured Technical Evaluation process to provide a consistent approach to assessing new and changed solutions.

The Challenge

Technical changes came through a number of different routes, including projects, suppliers and operational teams. There was no consistent approach to assessing them or documenting what was planned. The amount and quality of information available varied considerably, making it difficult to get a clear picture of a proposed change and its impact on the existing environment.

The Issue

By the time a change reached CAB, the technical plan needed to be clear enough for the change to be properly understood and approved. In practice, important information could be spread across different documents or simply not recorded.

Ownership was not always clear, and areas such as integrations, dependencies, security, implementation, support and handover could be dealt with inconsistently. This also created a risk that a solution could be implemented without the documentation or agreed ownership needed by the teams expected to support it afterwards.

It was also often difficult to see whether local Digital policies had been followed, including adherence to DSPT requirements and National Cyber Security Centre (NCSC) and Center for Internet Security advice.

The Solution

I designed and introduced a structured Technical Assessment process for new and changed solutions. It provided a consistent way to record and review solution architecture, hosting, integrations and data flows, ownership, security controls, dependencies, implementation and support requirements.

The assessment brought the technical plan together in one place, identified risks and actions, and provided CAB with a clearer basis for deciding whether a change was ready to proceed. It also required ownership, handover and support documentation to be addressed before implementation.

The process was supported by Microsoft Forms, Sharepoint, Lists and Power Automate. Initial submissions automatically created the project structure and tracking record, while workflows managed approval requests to managers and technical approvers. Responses and progress were recorded centrally, with notifications issued at key stages. This provided a consistent submission and approval process, while giving teams better visibility of progress and outstanding actions.

Previous
Previous

Application Consolidation

Next
Next

ACME TLS on a private network