Changes

Jump to navigation Jump to search
7,185 bytes added ,  15:40, 6 July 2021
text version toggles
Line 12: Line 12:  
Sandbox below
 
Sandbox below
 
</h1>
 
</h1>
 
+
<h2 id="toc09">Annexe&nbsp;C – Architecture intégrée cible des services et du numérique du gouvernement du Canada</h2>
 +
  <p>L’architecture intégrée cible des services et du  numérique décrit l’état futur du gouvernement du Canada. Le diagramme est divisé en plusieurs parties, selon les pratiques exemplaires de l’industrie, notamment l’architecture opérationnelle, l’architecture de l’information et des données, l’architecture des applications, l’architecture des technologies et la sécurité. L’adoption et l’exécution de ce modèle sont abordées dans ce PSON sous le pilier stratégique&nbsp;3 (3.2. Planifier et gouverner en vue d’une gestion durable et intégrée des services, de l’information, des données, de la TI et de la cybersécurité).</p>
 +
 
[[File:Service and Digital Target State Architecture-vJun2021 fr.png|alt=Architecture intégrée cible des services et du numérique|center|frameless|800x800px|Architecture intégrée cible des services et du numérique]]
 
[[File:Service and Digital Target State Architecture-vJun2021 fr.png|alt=Architecture intégrée cible des services et du numérique|center|frameless|800x800px|Architecture intégrée cible des services et du numérique]]
   Line 137: Line 139:  
         <li>La sécurité à la conception&nbsp;: authentification, autorisation, cryptage, utilisation de jetons et accréditation.</li>
 
         <li>La sécurité à la conception&nbsp;: authentification, autorisation, cryptage, utilisation de jetons et accréditation.</li>
 
         <li>Renseignements personnels&nbsp;: collecte, utilisation, exactitude, conservation et élimination.</li>
 
         <li>Renseignements personnels&nbsp;: collecte, utilisation, exactitude, conservation et élimination.</li>
 +
      </ul>
 +
</td>
 +
     
 +
            </tr>
 +
          </table>
 +
</div>
 +
  </div><br><br>
 +
 +
<h2 id="toc09">Appendix C: Government of Canada service and digital target state enterprise architecture</h2>
 +
  <p>The Service and Digital Target‑State Enterprise  Architecture depicts the Government of Canada’s future state. The diagram is  divided into several parts, based on industry best practices, including  business architecture, information and data architecture, application  architecture, technology architecture and security. The adoption and execution  of this model are addressed in this DOSP under strategic pillar&nbsp;3 (3.2.  Plan and govern for the sustainable and integrated management of service,  information, data, IT and cybersecurity). </p>
 +
 +
[[File:Service and Digital Target State Architecture-vJun2021.png|alt=Architecture intégrée cible des services et du numérique|center|frameless|800x800px|Architecture intégrée cible des services et du numérique]]
 +
 +
<div class="mw-collapsible" data-expandtext="Text Version" data-collapsetext="Hide Text Version">
 +
    <div class="sidetable">
 +
    <table class="wikitable">
 +
<tr>
 +
<td>
 +
<h1>
 +
Service and Digital Target Enterprise Architecture - Text version
 +
</h1>
 +
</td>
 +
<tr>
 +
<td>
 +
<p>The top row of the diagram shows examples of business programs and services, divided into two categories: front-office and back-office. </p>
 +
      <p>Examples of front-office business programs and services:</p>
 +
      <ul>
 +
        <li>Pensions</li>
 +
        <li>Employment Insurance</li>
 +
        <li>Licensing</li>
 +
        <li>Payments</li>
 +
        <li>Grants and contributions</li>
 +
        <li>Tax filing</li>
 +
      </ul>
 +
      <p>Examples of back-office programs and services:</p>
 +
      <ul>
 +
        <li>Core finance (FMT)</li>
 +
        <li>Security screening</li>
 +
        <li>NextGen HR and Pay</li>
 +
        <li>Enterprise procurement</li>
 +
        <li>Cloud-brokering service</li>
 +
      </ul>
 +
      <p>The second row of the architecture shows the top‑level business capabilities:</p>
 +
      <ul>
 +
        <li>Legislation, regulation and policy management</li>
 +
        <li>Enterprise planning</li>
 +
        <li>Outcomes management </li>
 +
        <li>Relationship management </li>
 +
        <li>Compliance management</li>
 +
        <li>Program and service delivery</li>
 +
        <li>Information management </li>
 +
        <li>Government resources management</li>
 +
        <li>Corporate management </li>
 +
      </ul>
 +
      <p>The third row lists the DevSecOps principles: Continuous integration and continuous deployments, automation of testing for security and functionality, inclusion of stakeholders</p>
 +
      <p>The fourth row identifies the various stakeholders:&nbsp; </p>
 +
      <p>Externally, examples include:</p>
 +
      <ul>
 +
        <li>Citizens</li>
 +
        <li>Businesses</li>
 +
        <li>International</li>
 +
        <li>Partnerships</li>
 +
      </ul>
 +
      <p>Internally, examples include:</p>
 +
      <ul>
 +
        <li>Employees, delegates, elected officials </li>
 +
      </ul>
 +
      <p>Two examples of user authentication are presented under the external stakeholder:</p>
 +
      <ul>
 +
        <li>Identity management </li>
 +
        <li>Sign-in Canada</li>
 +
      </ul>
 +
      <p>A third example related to the internal stakeholders is GCPass. </p>
 +
      <p>The fifth row identifies channels and interfaces.</p>
 +
      <p>Externally accessible solution examples are:</p>
 +
      <ul>
 +
        <li>OneGC platform: providing a tell-us-once experience</li>
 +
        <li>Omni-channel </li>
 +
      </ul>
 +
      <p>The third example is related to internal users:</p>
 +
      <ul>
 +
        <li>Digital workspace: GCexchange, GCTools</li>
 +
      </ul>
 +
      <p>The next part of the graphic show the elements of the information architecture, application architecture and technology architecture. </p>
 +
      <p><strong>Information architecture</strong></p>
 +
      <ul>
 +
        <li>For example, master data management, privacy (protection of personal data)&nbsp;&nbsp; </li>
 +
      </ul>
 +
      <p>Canada’s Digital Exchange Platform offers the following capabilities:</p>
 +
      <ul>
 +
        <li>API store</li>
 +
        <li>Event broker </li>
 +
        <li>Bulk data </li>
 +
      </ul>
 +
      <p><strong>Application architecture </strong>is divided into two categories based on security requirements:</p>
 +
      <ul>
 +
        <li>SaaS subscription feature</li>
 +
        <li>PaaS serverless hosted feature</li>
 +
        <li>IaaS broken into three parts:
 +
          <ul>
 +
            <li>Feature: IaaS</li>
 +
            <li>Runtime: IaaS</li>
 +
            <li>Data store: IaaS</li>
 +
          </ul>
 +
        </li>
 +
        <li>Automations can be achieved through tools such as:
 +
          <ul>
 +
            <li>artificial intelligence</li>
 +
            <li>workflow engines</li>
 +
            <li>machine learning</li>
 +
            <li>low‐code platforms</li>
 +
          </ul>
 +
        </li>
 +
        <li>Open source: solutions listed on open resource exchange</li>
 +
      </ul>
 +
      <p>The information from these application architecture options is shared back to the <strong>Canada’s Digital Exchange Platform</strong> via APIs (application programming interfaces).</p>
 +
      <p>Secret and above Secret systems, features, data, and storage exposed and consumed via API plus exceptions to cloud-first policy.</p>
 +
      <p><strong>Technology architecture</strong></p>
 +
      <p>Public cloud is the recommended architecture for solutions that are considered Protected B or below from an identified security level.</p>
 +
      <p>Solutions above Protected B must use Enterprise Data Centres. </p>
 +
      <p>All the layers of the Service and Digital Target Enterprise Architecture rely on <strong>enterprise network connectivity</strong>.</p>
 +
      <p>Examples of enterprise network connectivity include:</p>
 +
      <ul>
 +
        <li>Cloud-to-ground connectivity</li>
 +
        <li>secure cloud enablement and defence </li>
 +
        <li>cloud guardrails</li>
 +
        <li>network and cybermonitoring</li>
 +
        <li>LAN/WAN </li>
 +
        <li>GCSI </li>
 +
        <li>Related business continuity infrastructure</li>
 +
      </ul>
 +
      <p>Along the right side of the graphic are two overarching principles:</p>
 +
      <ul>
 +
        <li>Security by design: zero-trust authentication, authorization, encryption, tokenization and accreditation</li>
 +
        <li>Privacy: collection, use, accuracy, retention, and disposition</li>
 
       </ul>
 
       </ul>
 
</td>
 
</td>
139

edits

Navigation menu

GCwiki