2015-07-19

A Strategic Approach for Cyber Defence part I

How, in duel of two long chains intertwined with each other and with environment, one may gain any advantage over the other?

Abstract

This paper is describing one approach for strategic analysis and planning to gain advantage in confrontations within Cyber Environment. A constructive research method is used where solution is built by combining systems thinking with variation of models from business strategy (Supply Chain Strategies and Enterprise Information Strategies) to classical decision making (Nash Equilibrium). Theoretical relevance is assessed by using ENISA’s method for assessing Cyber Strategies in EU.

Introduction

Extension to other strategic approaches
This paper extends the theory of usage or threat of use of organized force for political purposes  within man-made Cyber Environment. Besides Clarke & Knape’s (2010)  defensive triad of backbone network protection – power grid hardening – defence countermeasures and Granova & Slaviero’s (2013)  four perspectives of Offence – Defence – Technical – Legal, there are not many strategic approaches for confrontations in Cyber Environment among the numerous technical and tactical studies. This paper is not analysing cyberwar as there are no international policies  to define war in cyber environment solely. Confrontation and conflict  are used to describe the interaction between hostile parties within cyber Environment.

Cyber Space or Cyber Environment is understood in this paper as sum of Globe’s communication links and computational nodes where information is being processed and distributed benefitting both humans and machines.

There are no single or isolated strategies in Cyber Environment since strategy is combination of all forces in every dimension directed to deliver the effect to the opponent’s Center of Gravity in decisive point. Operations is cyber space are part of wider Information Operations, which should be a part of greater strategy to achieve political goals. Thus this paper uses phrase strategic approach.

Strategic options
Defence and offence are traditional strategic options in other dimensions of utilizing force. China has been one of the earliest adaptor in offensive cyber means since 1995 with their Information Warfare plan.  More recently there are for example USA, North Korea and Russia that have wielded their offensive force in cyber environment. USA has allegedly supressed the Uranium enrichment facilities in Iran by Stuxnet worm 2010. North Korea has allegedly frozen computers in South Korea by using DarkSeoul malware 2013. Russian has allegedly utilized Distributed Denial of Service attacks against Estonian government 2007, against Georgia 2008 and against Ukraine 2014.

There have been reactional defensive actions in all above mentioned situations and nations have been defining their cyber defence strategies since 2001 . Defence in cyber environment may consist of Deception, Separation, Diversity, Consistency, Depth, Discretion, Collection, Correlation, Awareness and Response.


Besides the traditional strategies Mattila (2014)  has defined also Isolation and Habituation as strategic approaches for confrontation in cyber environment. Isolation means that entity is trying to isolate its cyber structure from global network thus protecting it by filtration (Chinese Great Fire Wall) or isolation by air cap (most military and industry systems until recently).

Habituation is more networked method of accepting dependencies and vulnerabilities, but exposing all three bases of nation’s power to every day malevolent effects, thus habituating all instances to endure or shelter when facing attacks. It includes also building relationships to extend defensive network in all aspects of international co-operation. Mattila (2014) gives Sweden as an example for utilizing this strategy. There is also a military strategic approach which is claiming that preparation for everything is not feasible in postmodern conflicts but flexibility, adaptation, recovery and capability to continue after surprise is more valid line of strategy.  The four strategic options are depicted in figure 1.

Figure 1: Four strategic options defined in Cyber Environment

Assets and vulnerabilities in cyber environment
As information and communications technology has not yet stopped its invasion to all sectors of mankind, it has become both the greatest enabler and the most dangerous vulnerability. In military this was recognized by Milan Vego (2009) when he wrote that:

"This evolution in the [cyber] characteristics of the strategic center of gravity
will create quite an anomalous situation, in which one’s center of gravity will
be the single greatest source of both critical strength and critical weakness,
simultaneously. Thus, protection of one’s strategic center of gravity will be a
much more difficult task than it is today. At the same time, computer
networks … do not have the ability to physically destroy or neutralize the
enemy’s strategic center of gravity."
Information is the greatest asset to enable building trust between stake holders and a network of specialized nodes is always more effective than any monolithic structure. With further digitized and digitalized business, the ICT-systems (=cyber) become the biggest leverage that any organization or network may utilize. This system model is described in Figure 2 left hand side of drawing.

Figure 2: Center of Gravity and Systems analysis of Cyber Assets

Adversary sees this socio-technical structure as very potential waypoint to project different malevolent means to effect at political, economic, social or security areas. With classical Center of Gravity analysis method adversary may define that networks is the single source of power they should aim to eliminate. The right hand side of Figure 2 is showing the causality of flow in disintegrating networks by cutting the relationships with implementing distrust between people, information and connectivity. The disintegration means are available to offender since there are more malevolent software created than ever before.  Existing ICT-systems have known failures that take long time to remedy thus attackers have plenty of time to exploit them. Human being remains the most vulnerable part of socio-technical systems with his weaknesses. Offender has advantage over defence since the cyber system has so many vulnerabilities and it has disseminated to all parts of living, business and security.


THERE ARE NO CLEAR LINES OF CONFRONTATION IN CYBER ENVIRONMENT


Estonian situation 2007
Estonia had built its economy and civilian life accelerated with modern IC-technology after gaining independence when Soviet Union collapsed. It was a fresh member of NATO and one of the most wired nations when it was attacked with cyber means in April 2007. Three weeks it faced a massive Distributed Denial of Service attacks that were targeted to suppress the national network of governmental services, main political parties, biggest news organizations, biggest banks and telecommunications providers. Attack game from botnets (remotely controlled robot network of breached computers i.e. zombies) all over the Internet so there was no one source of attack to be defined.  

Since this event happened at same time as there was dispute between Estonia and Russia about II WW memorial displacement, Russia was approached. They claimed that it has nothing to do with Russian state, but may be initiated by some individuals and non-state connected groups. Estonian government requested help from NATO based on the Article 5 : “The Parties agree that an armed attack against one or more of them in Europe or North America shall be considered an attack against them all”.

Estonian defended their cyber environment by coordinated effort from other regional Internet Operators, private companies and public agencies by filtering out foreign IP-requests.  There were major concerns risen amongst the citizens and government of Estonia but no crucial loss of trust was observed. 

The other members of NATO did not see armed attack, anyone being hurt or major damages happening. Agreements and Legislation did not include bullying in cyber space. The NATO ended up sending some cyber experts to Estonia only after assessing the situation for few weeks.    NATO was surprised by Russia at strategic level as it has been since in Georgian 2008 and Ukrainian 2014 operations.

As of 2008 one person with Russian origins living in the capital of Estonia has been found guilty in attacking the web page of one of the Estonian Parties. Russian authorities have denied all investigation cooperation with Estonian law enforcements agencies. Later the Head of Russian Military Forecasting Center, Colonel Anatoly Tsyganok stated: "These attacks have been quite successful, and today the alliance had nothing to oppose Russia's virtual attacks". 

Ukrainian situation 2014
As political crisis in Ukraine heated up more infections of “Snake” virus was reported from Ukraine during fall 2014. BAE Systems had identified 22 infections from Ukrainian government and its embassies.  This is major part of total 56 reported infections worldwide mainly targeting former Soviet Union countries but not Russian. Snake is a platform that allows outsider to gain access to infected computer and it can also carry autonomous malevolent features to computer.  Snake is considered to be strategic “sleeping cell” that is injected to several high value targets and only activated when need occurs.

This malevolent software was traced back to 2008 discovered “Agent.BTZ” when it was used successfully breaching information systems in Pentagon. Later there has been findings of several variants of this family as “Uroburos”, “Sengoku” and “Snark”. Some features in programming are directing to Moscow and level of professionalism is telling of major resources behind the development.  The fact that it was so clearly found activated in Ukraine during the conflict in eastern parts of country, is pinpointing Russia as a source.

Generalization of features of conflict in cyber environment as based on these two scenarios
Some basic features of confrontation in cyber environment are illustrated in Figure 3 as:

Figure 3: Nature of conflict in Cyber Environment

  • There are national stake holders, non-national groups and millions of Internet connected computers that might be used in attack. States can hide behind anonymous groups. Individual people may join into conflict.
  • There are no frontlines in Cyber Environment. The adversary might be attacking abroad, within the country or within organization by using any breached computer or manipulated people to launch malevolent measures.
  • There is no affirmative way of identifying the actual adversary that initiates attacks. The source may be found only after re-engineering the means of attack.
  • There is no international legislation or agreements that include cyber-attacks and enables the cooperation of law enforcement.
  • Advanced Cyber Adversaries do inject malevolent software in the systems of their opponents and activate them if need arises.
  • Attacker seems to have advantage in current cyber environment as Defender is not able to prepare against all possible threats. It remains on Defenders reactional proficiency of how quickly he is able to recuperate.
  • Race in developing Advanced Persistent means of cyber-attack require skilled teams and professional resources otherwise they may remain the copycat level of usual malevolent software. 2014 these mass variants were produced about one million a day. 
  • Cooperation between many Service Providers both private and public ensures quickest recovery from massive attack. There is seldom situation that organization alone can effectively deter cyber-attack.
  • Air gap isolation has been breached various times with attack vectors using “sneaker network”, contractor network or individual compromised users.
  • It is an advantage for adversary if he is able to collect information from his opponent’s cyber structure and behaviour of end users as it makes easier to produce an Advanced Persistence attack or Spearhead Trojans.

STRATEGIC DECISION MAKING IN CYBER CONFLICTS

Explains strategic options of defensive, offensive, isolation and habituation in confrontation situation
Information has become a major enabler for any socio-technical system to gain further productivity, wealth and performance. Information used whether digitized or digitalized is strategic asset i.e. Center of Gravity. Information as a Center of Gravity is both major enabler and severe vulnerability in Global cyber environment.

Offensive is an aggressive approach in using forces as a whole, combining all resources available for effecting the Centers of Gravity in a way that would fundamentally alter the relational posture of confronting parties in information utilization. Offensive may appear as aggressive infiltration in cyber space, intelligence gathering, denial of service or destroying information assets. USA may be appearing in taking this option.

Defence a set of cyber activities used for the purpose of deterring, resisting and repelling a strategic offensive, conducted as either a cyber space invasion, or an isolation from global cyber space, or a destruction of information assets. Strategic defensive does not need to be passive in nature but may involve deception, propaganda and psychological warfare, as well as pre-emptive or retaliation attacks. Defence normally requires cooperation within wider group of stake holders than military only. European Union seems to be following these strategic lines.

Isolation is following more traditional methods of defining borders of sovereign space in all dimensions and building ability to shut all avenues from foreign force projection with filtering or protecting gateways like customs, monetary hubs, governmental monopolies, firewalls, etc. China seems to be following this strategy as their “Great Fire Wall” is isolating national cyber space from global.

Habituation is more networked method of accepting dependencies and vulnerabilities, but exposing Government agencies, Armed Forces and private citizens of a nation to every day effects of malevolent behaviour, thus habituating all stake holders to endure through attack and quickly recover from its effects. It includes also building relationships to extend defensive network in all aspects of international co-operation. Sweden seems to take steps towards this strategic option.

The four strategic options or their combinations are available to each side of confrontation. In order to study the strategic decision making, the game theory called “Nash Equilibrium” is used in modelling two scenarios in simultaneous decision making of mixed strategies between duelling parties.  As the confrontation in cyber environment is not fulfilling all the requirements of pure Nash equilibrium, the outcome of this study is only conceptual. Scenarios are 1. Nation against Nation and 2. Nation against non-Nation. 

Blue and Red are players with 4 equally available options: Offence, Isolation, Defence and Habituation. Gained value from conflict varies between 1-5, where 1 means total loss and 5 means total win. Rules for game are as follows:
  • Both parties are trying to optimize the value of their cyber space as it multiplies their other functions.
  • Defence beats Isolation since isolation means that one is not gaining the full value of networking with others.
  • Offence beats Isolation 5 to 1 as Isolation often leaves the cyber area within the “Wall” very vulnerable and attacker has many ways to infiltrate within the “Fortress”.
  • Offence beats Defence only 5 to 3 since advantage is on attackers side, but defender is able to protect some of its assets and possible quickly recuperate after attack.
  • Offence beats also Habituation 5 to 3 as surprise gives advantage to attacker, but habituation has hardened the other side to sustain under attack. The quick recovery is also on habituates advantage.
Nation against nation
As both sides are nations that are logically striving to improve their economics and living by utilizing information in cyber environment, the loss of cyber capability is counted as loss of value. This logic is applied when both Blue and Red choose to attack the other. Outcome will be lose-lose as both parties are assumed able to destroy the information capabilities of the other side.

Comparison matrix shows that isolation will not become preferred strategy to either of parties since it ends up losing value in all variations thus it is eliminated. Both Blue and Red are preferring Defence and Habituation options since they create equilibrium in all variations, if neither of parties are aware of what the other is going to choose. The whole comparison and equilibrium analysis is shown in Figure 4.

Figure 4: Cyber duelling between two national parties

Situation alters if there is a foresight of the doctrinal tendency.  RED might choose offensive since it will give total win if BLUE is known to withhold the defensive posture. Because of multitude of cyber weapons and vastness of the vulnerable surface of cyber space, there is always advantage for attacker. BLUE may compensate the advantage of attacker with means executed in other dimensions of struggle (air, land, sea, space, electromagnetic) or building a deterring capability for cyber-attack. USA has ongoing program for improving their cyber defence within HomeLand Defence Initiative but also is pursuing after cyber space dominance with offensive means.    Early 2000 Russia declared in their doctrine for defence that any tampering of their cyber space will be countered with nuclear retaliation. 

As with conventional and nuclear arms there is also possibility between nations to agree on armistice or non-offense. Russia and China agreed on May 2015 not to conduct cyber-attacks against each other. They also agreed to jointly counteract technology that may “destabilize the internal political and socio-economic atmosphere,” ”disturb public order” or “interfere with the internal affairs of the state.” 

There is a special situation with North Korea, who has been able to keep isolated from cyber space by denying digital communications and computing within country. They are using this strategic advantage and wielding cyber-attacks against other countries by using global cyber space. 

Nation against non-nation
When nation is confronted with non-nation, there might not be balanced motivation since non-nation does not necessarily have goal to improving its cyber based governance, economics and social living. RED might be using cyber environment for exploitation only and does not have to worry about investments. Also isolation is eliminated from RED’s options since non-nation does not necessary have control over any cyber structure. Confrontation between nation and non-nation is analysed in Figure 5.

Figure 5: Cyber duelling between nation and non-nation

Since RED is enjoying the advantage of non-value, it is logical for it to choose offensive strategy over other alternatives. Defence or habituation does not bring any value to non-nation without cyber infrastructure. BLUE nation chooses logical defence or habituation strategy since the outcome is always better than from isolation or plain offence. 

Because of anonymity techniques and vast network of stake holders, there is difficult in cyber space to identify your opponent. Thus many nations are using their non-nation networks, rented botnets or employed experts globally to attack their counterpart. This has been the case in Russian operations against Estonia 2007, Georgia 2008 and Ukraine 2014.  

Cyber confrontations between nations and non-nations as well as between numerous non-nation stake holders are normal in contemporary cyber environment. There are several on-line sensors that are providing information on attack vectors at IP-level and email level. Cyber threat analysis company Norse  for example is providing visual views.

Majority of the normal targets are domain names in USA or .mil and .gov. Attackers are using botnets or breached computers that are quite often in China, United States, India or Russia. Partially this is because the level of cyber literacy has not improved the same pace of proliferation of Internet and it is easier to breach the computers of novice users. Breached computers are injected with “zombie” malware that makes computer to obey orders of botnet commanders often without owner’s knowledge. Recently seized “Beebone” botnet in US and Europe was using polymorphic malware that changed its fingerprints about 19 times a day to avoid detection. 

TOGETHER OR ALONE

Defending BLUE might ask in their strategic analysis, is it better remain alone or create coalition against unavoidable cyber-attacks. The basic rules of value of connected nodes states that N nodes connected together will provide value of N x log N. This is also called Metcalfe’s law but it assumes that connection between all nodes is available and the quality of connection and nodes is about same level. Principle is depicted in Figure 6. 

Figure 6: Connected to other equally good one is more than just sum of nodes

Connected network of stake holders does provide more amber source for innovation together with more explicit and implicit knowledge. There is also a level of quality of transactions that is achieved when cultivated in working together. Connections provide different variations to be exploited so operational freedom might be better with network, especially for defence where both width and depth is required if dynamic defence is implemented.

Negative effect appears if some of the nodes or connections in network are lower level of quality. These weak links may be exploited by attacker. There is also human cognitive features that does not follow the linear behaviour expectations of technical nodes and connections. Or as Kevin Mitnick says, the most vulnerable piece of any information system is one credulous human being.  

This concludes part I of this draft article. Part II will be available later this month.

2015-04-18

MILITARY KNOWLEDGE MANAGEMENT: SENSE MAKING, DECISION MAKING AND KNOWLEDGE CREATION

Abstract: 

The paper studies evolution of military Knowledge Management from Command and Control perspective to support strategic planning and enterprise architecture of Command, Control, Communications, Computers and Information System of systems.

Military Command and Control is studied in framework of Knowledge Creation through Evolution Theory and Path Creation to find road maps for Military Knowledge Management. Study finds some causalities and dependencies that have effect of Military Enterprise Architecture.

The study finds several ways to support the cognitive level of Information Superiority with C4I systems. The strategy should first diagnose the three dimensions of Sense making, Decision making and Learning with support of defined road map before any solutions are introduced. There should also be room for development in C4I since inflexibility in military structures may end in strategic and operational surprise.

This study is extending the three level Information Superiority Reference Model by Perry 2004. The cognitive layer is further defined with three dimensions: Sense Making, Decision Making and Learning.

Keywords: knowledge creation, sense making, decision making, learning

Introduction

Military Knowledge Management has changed as societies have been evolving and now we are questioning the rules of knowledge management of industrial era as opposed to information era (Mattila 2013 Feb). In this paper, the military combat operations process called OODA-loop defined by John Boyd (1987) (Osinga 2007:189-200) is studied in the framework of knowing organisation defined by Chun Wei Choo (1998). Framework is tested by the evolution theory (Mokyr 1997) and its path creation (Garud&Karnoe 2000). By combining Boyd and Choo one is able to define three abilities of military command and control process (OODA-loop) from the point of knowledge management as described in figure 1:
  1. Sense making, consisting of observation (sensing) and orientation (making sense), is interpreting the equivocal data by passing interpretations.
  2. Decision making, which is searching and selecting alternatives according to projected results, preferences and constraints.
  3. Knowledge creating, which is creating new knowledge and improving the whole OODA-loop through learning and knowledge acquisition.

Figure 1: Orientation for military knowledge management from sense making, decision making and knowledge creating approach

This paper defines the major evolutionary paths of each level of Knowledge Management and describes also the short cuts or downshifts that some military organisations have faced when reaching for more revolutionary goals. Paper provides also tools for strategic diagnosis by describing possible paths on both separate and integrated road map where interrelations and challenges may be easier to identify. The goal is to support strategic planning of how Information and Communications Technology, ICT is to enable the knowledge management in military organisation.

Description of evolutionary paths in Military Sense making 

Sense making can be projected to observation and orientation of John Boyd’s (1987) (Observe, Orient, Decide and Act) OODA loop. OODA loop is analysed in relationship to environment modelled with Kurtz and Snowden (2003) Cynefin framework. Military may face the four different situations defined in this framework: 1. Known, 2. Knowable, 3. Complex and 4. Chaos. Sensing and Sense making is following different process in each of these situations.
Sensing needs to overcome the fog of battlefield (Clausewitz 1832: 217) and egocentricity (Elder & Paul 2011) of human being. Sense making needs to address the attempts of deception (Rothstein and Whaley 2013 p. 39) by adversary, biases of sense making teams and individual mental models. The four different sense making situations are described in following subchapters and in figure 2.

Sense – Categorise – Respond in known environment

In known environment cause and effect relations are repeatable, thus easily perceived and predicable. In this situation military is following their Standard or Standing Operating Procedures, SOP (US Army FM 100-9).

Both individual, team and organisation are observing an event. Event is being sorted with previously defined model like the assumed order of battle of adversary. Each category has a predetermined type of respond, which is being followed without orientation or decision making (Osinga 2007:192-194). A good example of this is firing based on predetermined targeting list.

Adversary is not normally behaving by the book (Rothstein & Whaley 2013:25-27). It is harmful if surveillance and reconnaissance systems are preprogramed with assumed standard patterns and fail to detect anything divertive.

This approach is realistic for the lower levels of conscript army, where time to train ISTAR capabilities is short. It is mistakenly followed in forces that believe in Information Superiority gained with sheer volume (Perry et al 2004:14). It is also followed in Armed Forces with access to resources overwhelming to its adversaries (Finkel 2011:58).

Sense – Analyse – Decide – Act in knowable environment

In knowable environment cause and effect are separated over time and space. It needs some scenario playing and systems thinking to create a possible model to describe the knowable environment. 
After detection the incoming data needs to be analysed to reveal all effective cause-effect relationships. The analysis needs several experts working together and the challenges of collective sense making will appear: cognitive diversity creates clashes of individual mental models, but in another hand cognitive diversity helps against homogeneity biases like myopia and egocentricity (Smart & Sycara 2013). Sense making is evolving the scenarios as new data is detected.  There is a need to create a bigger picture from smaller events and to recognise their interrelationships by systems thinking (Mattila 2014 Oct a). 

Current trends in Big Data and Business Intelligence are good example of organisation trying to use all information it controls (Berman 2013:130). By fusing and correlating data differently, organisation may create new knowledge and if succeeding in sharing it, may gain a competitive advantage.

Probe - Sense – Analyse – Decide – Act in complex environment

In complex environment cause and effect are only coherent in retrospect and similar events seldom repeat. Emergent patterns can be perceived but not predicted. 

It needs an initiative probe to make possible patterns more visible for observation. Understanding these emergent, new patterns needs multiple perspectives to be involved in sense making. It needs to create stories as base for understanding as they are simple and easy to communicate between team. General McChrystal (2011) has defined this as “Understand the operating environment and your organization while constantly adapting for purpose”.

This is the very base of military professional approach in sense making since situation almost always is at least complex in military environment according to lessons of Emptiness by Miyamoto Musashi (Lahdenpera 2007). 

Act - Sense – Analyse – Decide in chaotic environment

No cause and effect relationships are perceivable in chaotic environment. System is turbulent or there is no time to wait patterns to emerge. One might assume there is a potential pattern but it is not visible or reconstruction able. This has been the base in military operations for Douche, Guderian and Swartzkopf (Fuller 1961, Guderian 2001, US Army War College 2004)

It needs a quick and decisive intervention to reduce the turbulence and ability to sense immediately the reaction to the intervention. This deliberate action might create something that is either known or knowable and with effective observing and analysing it might make sense.

Fast and determined action was the main approach for German staff officers and key enabler against Allied officers who tried to approach situations as knowable (Muth 2011 p.191). General Guderian put this as “Es gibt keine verzweifelten Lagen, es gibt nur verzweifelte Menschen”, which roughly means there are no desperate situations only people.

Figure 2: A framework for military sense making from Knowledge Management approach

Leaps, downshifts and revolutionary paths on sense making map of possible roads

The sense making ability may collapse and only behavioural routines will continue in crises situation and under extreme stress (Weick 1993). An exercised process should be in place before utilising more agile methods in sense making (Mattila 2014 Oct b).

Sometimes the feeling of having information superiority may cause a downshift. A complex situation is assumed as knowable and collecting more data is expected bring in the clarity. This might have been the case in late ISAF operation, where the collected data reached 40 Exabyte (10^18) in a month according to General Gartwright (2008).

A need for near real-time recognised operational picture to provide targeting information for target acquisition process may constrain the time and method used for fusion and recognition (JASON 2008). Thus targeting may fall short at basic event categorising and both friendly fire and collateral damage may occur.

Description of evolutionary path for Military Decision Making 

Decision is a function of residual uncertainty and the risks associated with the available options as a function of time. This chapter explains one possible road map to military decision making starting from authoritarian commander centric and gradually exploring more unconstrained and shared decision making patterns (Alberts &Nissen 2009). This chapter also discusses why the maturity of decision making is not improving linearly but has seen many revolutionary leaps and downshifts. The entire road map for military decision making is described in following chapters and in figure 3.

Authoritarian decision making in classic command and control

Decisions are made at top, Commander-centric, orders are flowing down and reporting heads upwards by support of hierarchical knowledge management. Decision making is based on individual understanding and any support should be only assertive as De Jomini (1862) puts it: “…, councils of war are a deplorable resource, and can be useful only when concurring in opinion with the commander, in which case they may give him more confidence in his own judgement,…”.

Information flow is following line organisation to enable superiors to understand better situation than their subordinates. The levels of hierarchy and means of communications are delaying situational information which is relayed from bottom up and orders flowing back down. Information is shared “need to know basis only”.

Carrying out tasks is based on pretrained procedures and there is no need to change behaviour during the operation. Knowledge base is following the doctrine and managing issues following standard operating processes.

Shared strategic intention with synchronised operational execution

Unlike his adversaries Napoleon could delegate operational decision making to his generals, who were each heading a Army Corps, bataillon carré. Napoleon shared his battle intent with his commanders (Shamir 2011) and gave them some degree of freedom in execution. This enabled to achieve dominance in volume, time and space, deep strategic penetration or rapid concentration of force superior to more cumbersome adversaries. 

Ability to share strategic information by actively collaborating between Corps heads provides good strategic and operational level awareness, alignment and manoeuvrability even if the lower levels in organisation are rigidly following orders and informing superiors through line.

After being outmanoeuvred entirely by Napoleon in Jena 1806, Prussians renewed their officer education and created “auftragstaktik”, which was later translated to mission command (Van Creveld 1985:174).

Mission command

In mission command tactical freedom is delegated to combined arms force level by giving mission to forces including command intent of battle. Forces were expected to fulfil the mission in most suitable way adjusting their tactics as situation was unfolding before the eyes of their commanders. Higher command was controlling execution by defining end states rather than tasking detailed goals. 

Mission command needs continual dialogue with higher authorities and mission partners to better understand the changing environment and perspectives (Luck 2013). Collaboration helps in perceiving what shared awareness looks like. It also build trust between commanders. Trust enables commanders to empower their subordinates to make decisions even creativity as Commander-in-Chief of Reichswehr (Muth 2011) was demanding: “Rules are for fools”.

Mission command with peer level collaboration

New level of awareness enabled by force digitalisation has flattened previously hierarchical organisations because middle level commands are not needed for control and quick reaction. Peer level collaboration lacks strict command relationships and is based more on trust (Mattila 2014 March b). 

Whereas the recognised operational picture is presenting the current situation to everyone interested, there is need for continuous dialogue in building and preserving the trust between stakeholders. The shared understanding enables empowerment, cross-domain synergy and eventually improves effectiveness. It will consume time differently compared more line or functional approach. The study of J7 DTD U.S. Armed Forces (2013) proves that “collaboration releases the initiative of subordinates”

Self-synchronising with swarming tactics

Power to the Edge (Alberts&Hayes 2003) principle addresses the shift in relationships required to leverage shared awareness to foster self-synchronisation and achieve major improvements in mission effectiveness. Control is sustained with shared command intent and consciousness instead of tight line control.

Swarming is a way to manoeuvre forces to gain advantage in time and space. It enables asymmetric tactics with agility, focus and convergence. (Mattila 2014 Oct b)
General McChrystal (2013) could improve his Special Operations Task Force capabilities about 30 fold in Iraq Operation 2006. He did this by executing the vision: “If we’re going to win, we need to become a network”. He transformed task force from hierarchical command and control structure to the network of a swarming subunits. 


Figure 3: A Road map of Military decision making from Knowledge Management view

Leaps, downshifts and revolutionary paths on decision making map of possible roads

Attrition with dominant resources (Boot 2003) has been keeping the command culture centralised and highlighted the linear planning and management more than leadership.

Improved communications and ability to gather up-to-date information from battle is not necessarily leading to mission command or more loosely controlled battle management as described by Van Creveld (1985: 238-251). The hunger for information at the top may produce an information overload resulting even longer lead times to prepare and launch operation. 

It is far easier to return to more centralised command culture when returning to peacetime garrison, tight fiscal constraints, and increased competition for promotion (Hastings 2005). It is also following Taylors (1911) scientific management methods, when higher headquarters centralise the control over myriad of detailed management events during peacetime.

At last there is the human himself as a decision maker in stressful situation. Human decision making has tendency to use pattern recognition. First decision maker is trying to categorise unfolding situation with his previous experience and then utilising the decision used previously. If there is no previous model to be recognised then human goes for most familiar action. As last effort human is trying to lessen undesirable outcomes and maximise his own utility (Alberts 2002:62-66). Thus human being is easily manipulated in stressful situations.


Description of evolutionary paths in Military Knowledge acquisition and Learning 

Military training has to prepare individuals and collectives to enter harm's way and perform physically and mentally demanding tasks at the highest possible levels of competence. Military training has the tradition to be more like discipline than a process of creating competence. 

This chapter is describing the sub-road map for military learning in more detail. The hypothesis starts by combining the organisational knowledge conversion process by Nonaka and Takeuchi (1995) with classic education ideas of behavioural, cognitive, constructive and social cognitive explained by Hergenhahn and Olson (2008). The model with four different approaches to knowledge acquisition, training, education and learning is described in figure 4. It is tested by explaining existing military training and knowledge creation approaches with it.

Military skills and understanding are learned in different way. Military skills are learned mainly in team training with progressive challenges tailored to each team of arms. Repetition is a disciplined way to establish team’s behaviour as part of a bigger system. At battle technical level both individuals, troops and weapon systems are trained to be able to act at level of subconscious habit, motoric memory or preset programming. 

Military understanding has several learning approaches. A strong legacy forces military to operate according to the doctrine and thinking by the book. A new request for educating soldiers how to think rather than what to think. This means introducing a combination of three thinking methods: systems thinking, creative thinking and critical thinking. With increasing complexity also need to educate team and organisational learning is arisen. This chapter is focusing on learning military understanding.

Drilling what to do and think with behavioural drivers

Drilling has been a tool for military training as documented vividly in Sun Tzu’s Art of War (1910) or in Prussian army (Smith 1998) when soldier was made a standardised, predictable and reliable unit to operate the musket. This is the basic way of socialising tacit skills (Choo 1988) when instructor (master) shows how to do movement to soldiers (apprentices) and then drills it continually supervising proceedings and correcting mistakes. 

In behaviourism learner gets positive feedback when his behaviour and learning results are moving in right direction. This is especially effective, when standard of needed performance is gradually increased and award from right behaviour is direct and public.
Soldiers and troops need to exercise as part of bigger fighting system, to gain automation level of skill, to be able to sense cues (Duhigg 2013) of enemy action and to fulfil ones task routinely to be effective under stress.

This industrial (Smith 1998: 45-48) way to educating and training troops may not be the best way to produce sense and decision makers. If the doctrine being educated is not applicable in the situation confronted, then officers do not have means to adapt into it (Harford 2011: 37-79).

Understanding how to think with cognitive drivers

General James Gartwright (2008) called after learning how to think and improving the pace of learning to meet current speed of evolution of business (3 months), technology (18 months) and war fighting (30 days). This requires the ability to create knowledge by bringing together explicit information from several sources. Combining different explicit and tacit ideas (Nonaka et al 2015: 23) needs systems thinking, critical thinking and operational analyses in social space.

The cognitive learning follows more the human way of creating understanding and processing information in his brain. New things are learned within a familiar orientation model. Problem solving is using cognitive approach, where one learns a new way of thinking (schema) and may use this “tool” further in solving for other similar problems. After learning these schemas, there remains a challenge of mapping problem to a right pre-existing schema. This needs logical reasoning like systems thinking (Senge 1990) or operational analyses.

Skills are learned mainly by team training with progressive challenges tailored to each team. Repetition is a discipline as a part of bigger system, but use of skills in different situations and environment is a driver for successful execution in progressively challenging environment. 
Understanding is soldiers’ ability to realise their space of operation, teams and systems, other combat supporters, supported and adversary as huge system where different parts interact with one another and with environment (Joint Doctrine Publication 04, 2010). It needs leaders to achieve synthesis of action (Nonaka et al 2015:33) when processing towards understanding of this phenomena. Leaders should reach a certain level of insight and foresight to be able to innovate and create best ways to operate their force as interdependent part of fighting system of systems. 

Experimenting with constructive drivers

The knowledge conversion process by Nonaka and Takeuchi (1995) includes: Socialisation – Externalisation – Combination - Internationalisation. Individual shares some experiences of his trials (tacit knowledge) with peers and together they come up (socialisation) with hypothesis for causality model of their analysed experience. They publish (externalisation) their findings in lessons identified (explicit) board. Someone else faces a challenge, finds these lessons together with few more similar, and fuses (combination) these concepts (explicit) to fit into situation in hand. One learns (internalisation) from this successful trial and increases his (tacit) knowledge.

Constructivism means that new information is learned by social and cultural interaction. Information is understood in relation to prior knowledge, experience and skills. Constructivism is using sociocultural dimension to support learning. Interaction with more capable peers, skilful leaders or cognitive tools do create mental constructions that enables students to recall learned things longer. The support is provided according to students’ maturity and it is gradually withdrawn as subjects become more internalised. This is a coach or mentor approach, where instructor is supporting enough to have student over first fears, provides safe environment for student to experiment, fail and learn, and gradually allows student to have more room for independent action. This provided an obvious competitive edge to German officers over their allied counterparts during the II WW as analysed by Muth (2011: 190-191).

Military as knowledge creating organisation driven by social cognitive learning

The competitive edge may be gained from continuous organisational knowledge creation and learning by “start talking and get to work” as Weber (1993) says. Conversations are the way knowledge workers discover what they know, share it with their colleagues and in the process create new knowledge for the organisation (Davenport&Prusak 2000: 88-106). This is one way of mitigating the constraint of one man’s understanding.

“A man has no ears for that to which experience has given him no access.” Nietzsche.

Knowledge conversion is enforced by social cognitive learning (Denler et al 2014). It means that learner's behaviour changes because of seeing others' behaviour and its effects. There are several factors that decide whether watching a model will result behavioural or cognitive change. These factors include the learner's developmental status, the noticed prestige and competence of the model, the effects received by the model, the relevance of the model's behaviours and consequences to the learner's goals, and the learner's self-efficacy. Self-efficacy refers to the learner's belief in his or her ability to perform according the behaviour.

Machines and men are collaborating, sharing information, creating understanding, learning from experiences and continuing the asymmetric ability over the adversary. This calls for training early to need (Faris 2013). This also needs to include machines in to the process of continuous learning (Mattila 2014). 


Figure 4: A Road map for military learning from knowledge management approach

Leaps, downshifts and revolutionary paths on knowledge creation map of possible roads

When following the evolutionary road on the map of knowledge creation and training, there are two distinct leaps: 1. from what to think to how to think and 2. from team learning to organisational learning (Mattila 2014 Nov). 

As described earlier, U.S. Armed Forces have been trying to leap from what to think to how to think for decades, but they have this far downgraded back to behavioural basics because of the gravity of their doctrine, culture and C2 attitude (Finkel 2007).

Despite of U.S. Armed Forces tradition McChrystal (2014) achieved to take his Special Operations Task force from behavioural level 2003 direct to organisational learning within couple of years. 
From team learning to organisational learning there are four obstacles defined as follows:
  • First obstacle is the culture of information distribution by need to know basis only. With tactical level information management by push method, military will always face the dilemma of operational security and survivability. Single owner of information does not have full understanding of where information in his possession might be utilised. Military culture needs to be switched to need to share before anything happens (McChrystal 2014). 
  • Second obstacle is the autocratic culture of command and control if it is featured by “shut your big mouth and stop thinking above your rank” attitude (Harford 2011). This disables the systems thinking, critical thinking and creative thinking needed to try and error with badly needed critique. 
  • Third obstacle is technology. The building of information technology systems is still defined by the boundaries of a system (Doan et al 2012). Data is constrained by the system because of vendor attempts to preserve market with proprietary solutions. National policy is trying to keep technology dominance (US ITAR) by restraining system integration. Different branches in military are trying to sustain their independency and freedom of movement by abiding interoperability standards.
  • Fourth obstacle is information itself. Either information is unstructured so it is not searchable or understandable but by human. Or it is modelled in proprietary way that data transfer always needs interpretation. These problems may be managed with improving semantic structures that frame all pieces of information with standard metadata. Metadata explains data objects and their relationships (Allemang&Hendler 2011).  This way information is understandable both to humans and machines.
As military basic skills are trained in very repetition and behavioural way, there is a natural pull to simplify all training delivered in same way. This happens when training and real needs of operation are not linked to one another.

Consider the way to support knowledge management with information systems and automation

When military command and control is studied from knowledge management view, one recognises major opportunities but also challenges, when combining all three areas of C2 evolution: Sense making, Decision making and Learning as pictured in Figure 5.

Figure 5: Evolutionary roads of military knowledge management within Command and Control

From evolutionary map of paths in Figure 5 one may conclude that:
A. There is a possibility to use these maps of possible roads to create a linear strategy to improve C2 capabilities.

  1. Define the current C2 situation by admitting the typical features of each stage of C2. (Black even line in figure 5)
  2. Set goal stage for improved command and control in each sub feature. (Blue dotted line in figure 5)
  3. As gap between current and future capability is thus defined, there is possibility to analyse alternative roads leading from current stage towards future capabilities. Strategic courses of action are thus defined.
  4. As these roads are two-way, one should be aware of tendencies that keeps C2 from improving or reverse to starting position.
  5. Create the development programme based on strengths and resources and simulate it with social and cultural variables.

B. The classic OODA loop and military sense making are more complex than first impression may reveal. Since sense making is always a social event, there is a major impact by the relationships between people. Both individual and team mental models take time to be aligned and it takes even longer to educate whole organisation to follow the same logic. If, in the other hand, organisation is too homogeneous, there is a danger to have too narrow or blind sense making.

  • Military situation is normally more diverse than only one dimension of Cynefin framework at time. There might exist all four different stages of dynamics within the same area of operation: 


  1. Own force and their action might be known or knowable
  2. Regular parts of adversary force might fall into knowable category
  3. Irregular or militant parts of adversary might fall into complex
  4. Society, where operation is executed, may seem chaotic.


  • It needs all four means of sensing and sense making processing parallel information from each part of area of interest and more complex orientation and sense making process than any one of above defined.

C. Military organisations usually improve their culture for decision making with three alternative ways: by copying a successful organisation, by importing new culture, or by fostering a revolution.

  1. One might successfully copy new way of behaviour or best practice, but normally organisation needs to create its knowledge by trial and error, since mimicking does not stick for longer term.
  2. Importing new cultures is normal in military force when officers are rotated between different appointments spreading best in-house practices on way. This is possible is officers are provided room for initiative and change to ask WHY.
  3. Revolutionary transformation usually needs both strong outside threat and inside will. Corporate behaviour is slow to change especially within military organisations.

D. Road map for decision making does not state that swarming and self-synchronised way is better than hierarchical and information constraint way. Organisational culture and situation is dictating also the command and decision making style. Hierarchical culture does not support self-synchronising and conversely.

E. Most flexible structure of C2 culture is gained, if Sense making in complex situations, Decision making delegated within swarming network and Learning as organisation are combined.

F. Combining Mission command with Sense making in Chaos situations and learning together made German staff officers way better than their Allied counterparts in the II WW.

G. U.S. Officers have been struggling in their efforts of improving C2 as their Sense making is heavily fixed with Known approach and Learning is mainly by the Book. Efforts in delegating Decision making have been bouncing back since their command culture prefers heavy planning and management.

H. Delegating decision making to swarming level and being able to learn continuously as organisation requires solid base of trust and openness of communication.

I. If one finds his force to be at first level of sense making, there is need to change knowledge, competence and process before it is implemented heavily in information system. Even if one’s own force is known, there may rise challenges in changing the Order of Battle quickly.

J. It needs more heterogenic team than before to bring up all possible aspects when analysing situation before decision making. Effective teamwork needs building by practice and challengers rather than more information technology. Information technology should be applied first to enable virtual collaboration of ad hoc sense making teams.

K. Delegating decision making towards mission command needs continual dialogue with higher authorities and mission partners to better understand the changing environment and perspectives and what a shared understanding looks like.

L. When one reaches towards more agile, focused force that has convergence, there needs to happen a transformation alike McChrystal implemented 2006 in Iraq: McChrystal (2013) explains the transformation strategy of Special Operations Task Force in Iraq as follows: “We began as a network of people, then grew into a network of teams, then a network of organisations, and ultimately a network of nations. Throughout, we evaluated the health of our network by how well each node shared a common but ever-evolving understanding of our organisation, of our battlefield, of our enemy, and of our strategy to defeat them—what we called ‘shared consciousness and purpose.”

M. There is a tendency (or entropy) in organisation, which does not face pressure from outside, to gain excessive bureaucracy, create narrow functional silos, simplify skills and competence to be easier trained and withhold most freedom of initiative from lower levels. Command and control culture of this kind does not necessarily survive in situations of complex crises. Especially if information systems are constraining the change to more flexible culture.

N. Repetition and drilling are essential in learning skills that are needed under stress but building competence that brings advantage in crises situation needs combination of trial, error and social reflection.

  1. The powers of human pattern recognition are used when education does create several mind models for possible solutions in future situations. 
  2. Since time and resources are constraining instructed learning, there is a need to learn more how to think rather that what. This leads to continuous learning concept that carries over the whole career of military officers.
  3. Skills are usually learnt together within a section or platoon. This should be extended to thinking, understanding and staff working if there is demand for improved situational awareness.
  4. As situation becomes more complex also the learning should change towards social cognitive means over the whole organisation to ensure the flexibility of military doctrine and operations. 

O. There is a heavy cultural, doctrinal, technical and information management opposition for improving learning in military environment. There should be special means of transformation in use when fielding the change in Military Organisations.

P. One should not expect that C2 strategies are linear, but always approach military C2 system of systems as a complex structure that is constantly in motion.


Discussion

This paper is extending the Cognitive layer of Perry’s (2004) reference model for Information Superiority. The collaboration between individual understanding and shared understanding is replaced with Nonaka’s (1995) knowledge creation process. Process is further framed with Coo’s (1998) Knowing Organization and Boyd’s (1987) Command and Control loop as illustrated in figure 6.

Figure 6: The combination of approaches used in this study

The Combination opens three dimensions of Sense making, Decision making and Learning, where knowledge creation has major effect in military affairs. Evolutionary paths of these three dimensions are defined empirically based on case studies and literature survey. By combining evolutionary paths a Military Knowledge Creation road map of interrelated paths is defined.

The road map for Military Knowledge Creation is used in defining options and constraints for C4I development strategies. These strategies are used further in other studies that try to define model for development of C4I capabilities in Military Environment.

2015-03-28

There is more than one way to develop your ICT based capabilities in Military Environment


Abstract

This paper introduces several development models for ICT based capabilities. Paper recognizes both continuous and discrete development but concentrates mainly on latter. Development models are adjusted to situation and environment described by Cynefin model. Besides waterfall development utilized in known environment, there are also incremental development for knowable situation, spiral development for complex situation and experimental development for chaotic environment. Paper concludes in discussion of managing all development possibilities together.

Do not directly accept System Development Life-Cycle method as your only ICT capability development – Analyse the situation first

Information and Communications Technology is becoming even greater enabler to military force as their digitalization  is proceeding. There is a natural approach for ICT engineers to develop systems by utilising Systems Development Life Cycle  method sometimes also called waterfall  approach. This paper introduces an analysing method for choosing between different development models and provides a few examples of their use. There is more than one way to develop ICT enabled capabilities in military environment. See figure 1.


Figure 1: One development method does not fit to all situations and change approaches

In developing ICT enabled capabilities there are two main lines of business: Lean development and disruptive development. Lean development (continuous improvement, kaizen)  is systems continuous adaptation to changes by:

  • monitoring its performance and effect and 
  • altering its configuration and operation to match the changing needs. 

Normally this is done within operations expenditure, OPEX.

Disruptive development (radical improvement, kaikaku) calls separate organization to design and produce new parts for capability and then implement them in existing structure of people, processes and technology. Normally this is done within capital expenditure, CAPEX. This study is focused more on latter development and choosing applicable method from environment and object point of view.

First one should analyse the environment where developed capability will be implemented. To create understanding of different environments this paper uses Cynefin framework  of Known, Knowable, Complex and Chaos situations.

Second one should analyse the object that needs to be transformed in order to gain new capabilities. To elaborate understanding of different objects of change a Managing Successful Programmes  method might be used. It defines specification-led change, business transformation and societal migration.

This paper is focusing in analysing development from environment and situation point of view. The object of transformation view will be studied in other papers.

Apply development method according to situation and environment


This study is using Dave Snowden’s (2003) Cynefin  method to describe four different environments or situations possibly faced by a developer of ICT capabilities. These environments are Known, Knowable, Complex and Chaotic. Each environment calls for different development approach as illustrated in Figure 2.


Figure 2: Using different development approaches adjusted to each environment and situation

In known situation environment is unchanging. Information requirements may be stated unambiguously and comprehensively since they are very stable and recognisable. The risk management wants complete and precise descriptions of new capability. Formal, specification-driven development methods would provide them with whole documentation.

In knowable situation environment might be turbulent. Organisation may be in constant change thus needs are also changing.  Linear, requirement based, development might be too slow to cope with changes. Development needs to be faster, delivering smaller parts or reusing existing parts of capability.

In complex situation environment is uncertain. Needs for the capability are unknown or uncertain.  Requirements cannot be accurately defined since situation is new or system is innovative. The development must emphasise learning. One version of Spiral development has learning phase after each delivery.

In chaotic situation environment is adaptive and unknown. Environment may change in reaction to the introduced change. In developing capabilities for this environment adaptation is the key. Development method must enable a straightforward introduction of new rules as in experimental process models using prototyping and rapid development. Development process should be able to record the reaction created and adapt to situations as they unfold.

The following chapters are explaining the development case in each of these four environments. These development methods are as follows:
SITUATION
DEVELOPMENT METHOD
Known - unchanging
Waterfall, System Development Life Cycle
Knowable – turbulent
Incremental development
Complex - uncertain
Spiral development
Chaotic – adaptive and unknown
Exploratory development

ICT capability development in known and unchanging environment


In known environment cause and effect relations are repeatable, perceivable and predictable. Business processes are following “best” practices and cemented in standard operating procedures. Developer is able to gather all needed information of user requirements, their competence, relations to environment and other components. The pace of change in this environment is slow.


Models for development

All variations of the classic ‘Waterfall’ Development  model may be used successfully in this environment. One example for the steps of waterfall development approach is:


  1. System Conceptualisation includes consideration of all aspects of the targeted business function or process. It calls for discovering how each of those aspects relates with one another and setting goals accordingly. The intended capability should be analysed within its coming environment to define interrelationships. There should also be resolution of which aspects should be incorporated into the development and which remain untouched. 
  2. Systems Analysis includes gathering of system requirements. Each requirement needs to be studied and determined how it will be accommodated in the system.  Analysis is not possible without intensive communication between the customer and the developer.
  3. System Design includes identifying in detail how the system will be built to perform necessary tasks. Designing is a process where data requirements, software construction and interface construction are planned together as a balanced design to fulfil the model created in steps one and two. 
  4. Implementation or Coding in software development is creation of the system software. The System Design is translated into machine readable computer code. 
  5. Verification or Testing is performed to ensure that developed application is working correctly and efficiently. Testing is to validate both internal efficiency and external effectiveness. Testing the external effectiveness is to corroborate the software is functioning according to system design and that all necessary roles or sub-functions are performing.  Internal testing assures the computer code is efficient, standardised, and well documented.
  6. Maintenance occurs after the developed feature has been installed in live environment as one or more configuration item. It means continuous evaluating of running systems. It means providing services for example with ITIL processes , where configuration management, problem management, release management and performance management have effect on single configuration item. Besides continuous improvement there may be a need to have mid-live updates within extended life cycle of the system. 

One variation of waterfall development model is depicted in figure 3.

Figure 3: Waterfall development model with documentation and validation emphasis by V-variant

Improved variations of this linear and specifications driven development method are:


  • V-model where testing is emphasised and added into each level of delivery as depictured in figure 3. 
  • In the System Development Life Cycle, SDLC operations, maintenance and finally disposal of delivered system is bound into holistic life cycle approach. Open SDLC group  is preserving and improving Systems Engineering and Software Development Life Cycle Framework.
  • Systems and software engineering – Software life cycle processes standard preserved as IEEE/ISO/IEC 12207:2008 includes supporting life cycle and organisational processes. 
  • Systems engineering standard ISO/IEC 15288:2008 is including some programme and portfolio management features into development intent. This is the most generic model to build systems that include “hardware, software, data, humans, processes (e.g. processes for providing service to users), procedures (e.g. operator instructions), facilities, materials and naturally occurring entities” .

Waterfall approach has high level of success if utilised in producing complex systems on known design or replacing technology. It is less successful when delivering new technology to organisation. Least success is predicted when method is used in changing organisations or in implementation of unproven technology.

Examples

The Finnish Defence Forces, FINDEF was renewing transport network during 2004-2006  mainly following the waterfall development model. It was feasible since there were no big changes in network topology and the change remained mainly at technical level. Requirements were gathered from each Services  and merged with constraints of finance and military environment. Analysis of needed topology and number of nodes provided simple design that was straightforward to acquire from minimum three vendors by comparison of cost.  The telecommunications organisation of FINDEF installed the MPLS  nodes themselves, updated fibre optical connections and integrated new network to system management. Project did deliver required capability almost 2 years ahead of deadline  but failed to recognise the following issues:

  • As circuit switched SDH  network layer was replaced with packet switched MPLS network the Quality of Service, routing and performance would have provided unforeseen applications. Project did not recognise these opportunities but only carried out a Mid-Life Update.
  • As Information Technology at upper layers were changed parallel, network project failed to capture their emerging needs.
  • As network service transformed to be more than dedicated point-to-point circuits of 2 Mbps multiples, the network node management system provided by project was not able to managing these new end-to-end services.


The Enterprise Resource Management system (SAP)  implemented in the Finnish Defence Forces during 2003 – 2008 was following typical SDLC model. Process owner initiated the programme (MAHATA) with business improvement as a goal. Concept was defined as incremental consolidation of Enterprise Resource Management, ERM functions. Plan was created with programme and project organisations aiming to replace all legacy systems. Requirement analyses was straightforward since existing processes were planned to be replaced with SAP functions. SAP integrator was chosen to take care of design, development, integration, testing and implementation.  Same vendor was also assigned to provide both process and technical level support in operation phase. System delivery was achieved as planned but other issues occurred during the implementation:

  • Since the culture of Defence Forces was not supporting process driven approach, SAP did not provide original business benefits since programme did not change the culture of administration. 
  • SAP was implemented to consolidate all administrative functions and information. Programme was not integrating operative management and administration functions together as in normal ERM development. This left Defence Forces with a handicap.  

Development in knowable but possibly turbulent environment

In knowable but turbulent environment the relationship between cause and effect needs analysis to become understandable. The analysed cause may still be changed during development with pace that normal development project management faces difficulties to match. Development should follow shorter iterations of delivery, which allow Sense - Analyse - Respond process in presenting new capabilities.

Model for development

Development models fitting in knowable environment are iterative, prototyping or rapid. The Iterative Development model delivers new capability in small parts. This allows partial results to be displayed earlier on within live environment and earn feedback from users. Each iteration might be managed as mini-Waterfall project and feedback loop is linked to future phases of analysis, design or implementation. Iterative development needs users to be involved actively in process. Requirement management is needed throughout the delivery. Attention needs to be paid to control possible creep of the scope. Figure 4 is illustrating this development model.

Figure 4: Iterative Development model

The iterative development approach may be further extended with continuous integration approach that is coming from software development called extreme programming.  Continuous integration means that developed iterations are integrated and tested together within main system several times before launching them in operation. Using continuous integration to develop large System of systems helps to manage turbulence caused by vast number interrelationships within System. 

Example

The Finnish Defence Forces was implementing an Information Technology Service Management (ITSM) system following good practice of the ITIL/ISO/IEC 20 000:2007 standard 2006 – 2008 as it was changing also the organisation for providing ICT services.  An incremental development of ITSM capability was chosen as organisation was transforming and maturity of different processes was diverse. The FINDEF was implementing ITIL and defining Configuration Management Database (CMDB) within one of the first organisations in Finland, which increased the likelihood for extra turbulence. Iterations were mainly as follows:
  • Delivery 1: Transforming event management and change management from TMN  model to ITIL using existing management systems
  • Delivery 2: Implementation of ICT service production processes with Enterprise Resource Management processes
  • Delivery 3: Changing end-users processes and application.
Outcome was positive as system and processes were completed but the following lessons were identified: 
  • Process and tool training should be integrated otherwise trainees may not understand the context of the capability
  • Usability of application is imperative when trying to change the behaviour of over 14 000 people
  • Risk management is important even in incremental approach. Now both human behaviour, training and performance provided unforeseen challenges.

Development in complex environment

In complex and uncertain environment the relationship between cause and effect can only be perceived in retrospect. Training focused approach with Probe - Sense – Respond method should be applied when establishing development programme.

Development methods fitting in complex situation are more evolutionary in nature as the models of experimental and spiral development. 

Models for development

Spiral Development  model differs from other models in being more risk-driven than document-driven or code-driven. A new capability is developed in spiralling rounds which each create a prototype in achieving to balance better the interrelationship of requirements, solutions, risks and costs. A typical round of development spiral runs as described in figure 5:
  1. Identification of objectives (performance, functionality), alternative means of achieving objectives (Design, Reuse, Buy) and constraints imposed on the application of the alternatives (Cost, Schedule, Interfaces).
  2. Evaluate alternatives relative to the objectives and constraints. Find out the areas of uncertainty. 
  3. Formulation of cost-effective strategy for resolving the sources of risks with means as prototyping, simulation, benchmarking, reference checking or analytical modelling.
  4. Develop a prototype driven by risk management. Try to mitigate the sources of biggest risks first. Create a concept for future prototypes matching the assumed sources of risks sequentially.
  5. Test and field the developed iteration to gather feedback both from users, service providers and business owners
  6. Review products, plans and resources in accomplished round. Define and improve further measures to mitigate sources of risk in development.

Figure 5: Spiral development rounds as described by Barry Boehm 1988 

Spiral development is managed like a scientific research process: 
  • Create a hypothesis that operational capability can be achieved by system development
  • Carry out a series of tests defined by risk structure. If hypothesis fails the test, then spiral should be abandoned.
  • Usually each test creates more information and possible new hypothesis that requires to be tested.

Experimental Development model includes the acquiring, combining, shaping and using of existing scientific, technological, business and other relevant knowledge. It uses the skills for producing plans, arrangements or designs for new, altered or improved capabilities.  Experimental approach means: 
  • active user involvement throughout development process; 
  • prototyping experiments closely coupled to work-situations and use-scenarios;
  • transforming results from early cooperative analysis and design to targeted object-oriented design, specification, and realisation;
  • designing for tailorability. 

Example

Transferable Operations Centre (TOC) was developed in FINDEF during 2000-2003.  TOC programme was to build a prototype for new joint operational level command and control concept for Finnish Defence Forces. Since situation was analysed to be complex and unprecedented, Barry Boehm’s spiral development was selected as main development model. Risk driven approach was applied as depicted in figure 6 as follows:  
  • Since tradition for having fixed command posts was identified as biggest source of opposition, transferability was chosen the first feature to be achieved. Late 2001 a transferable command post using cloud computing applications as service was prototyped.
  • Second source of opposition was analysed coming from request of physical presence in staff working. This was achieved by 2002 when one command post was distributed to three places following shifts of 8 hours. It was proved that physical distance do not hinder staff work in planning, situation briefings and decision making.
  • Having several levels of confidentiality accessed through same network and terminal was estimated to be third biggest source for opposition. A technical solution to use unrestricted, restricted and secret content in same session was presented. Vulnerability analysis proofed that risk for security breach was within risk appetite of Operational Security.
  • Fourth source of opposition was assumed to come from staff processes. A Service Oriented Architecture was applied to implement operational planning and execution processes. It was proven that process driven approach to staff work is more productive but requires change in entire operational thinking and staff behaviour.

The TOC demonstration programme achieved its goals by 2013 but when doctrine and concept was implemented to whole Defence Forces in Integrated C4ISR  programme (ITVJ) it confronted the following challenges: 
  • Tradition of physical presence in staff work delayed effectively the distribution of any command post until it was achieved with persistent effort by 2012
  • Defined best practices in operational planning and execution processes failed mainly since culture was not ready to standardise any other staff work but templates for orders.
  • The pace of technical evolution outdated some solutions and same time presented number of opportunities that technical people were having challenges in keeping ICT stack together.

Figure 6: Transferable Operation Centre development rounds  

Development in chaotic and adaptive environment

In chaotic, adaptive and unknown environment there is no relationship between cause and effect. Act-Sense-Respond approach is needed to penetrate the Fog in this area of operation and overcome the unseen Friction in execution.  In developing capabilities for this environment, adaptation is the key. Development method must enable a straightforward introduction of new rules as in exploratory Development process models using for example prototyping and rapid development methods.

Models for development

An elaboration to experimental model is Exploratory Development model , which runs as follows: 
  1. All the information available is gathered together in an attempt to get an idea of what the new capability is expected to do, and how it can be done.
  2. A rudimentary first-generation solution is put together. It is based on best assumption but no way specified final requirements.
  3. The first-generation solution is fielded to see how it performs, what it can and cannot do, and what might be done to improve it.
  4. A second-generation system is developed based on lessons from first generation and information gathered from first users.
  5. The second-generation solution is fielded to replace the first. Its performance is evaluated, and possible needed improvements determined.
  6. The process is repeated as many times as necessary to obtain user satisfaction, or until it is decided that the project is unworkable.
  7. Routine maintenance is established to prevent large-scale failures and to minimize downtime.

There are no precise specifications defined with the Exploratory Development.  Validation is based on adequacy of the end benefits and not on its compliance to pre-defined requirements.

Each generation of capability may be developed by creating a series of working models before any real system development occurs. Each prototype , is a working model or intermediate version as defined in figure 7 that is not nearly complete but works in production environment mainly as intended even if only on temporary bases.  The user in turn provides feedback to the developer, who amends the system requirements and proceeds to implement the actual function. There is a possibility that user expectations may overextend with prototyping or pressure for rapid delivery may drive development into poor design and unnecessarily layered or patched construction.

Figure 7: Concept for exploratory development 

In Rapid Application Development model  the components are developed in parallel as if they were mini projects. The components are time boxed, delivered and then assembled into a working prototype.  The working prototype can quickly give the customer something to see and use and to provide feedback regarding the delivery and their requirements. This model of development is applicable when delivery time is less than 5 months and there are number of developers available.

Example

Unknown environment was faced when improving battle management capability for the Finnish Land Forces.  There was no feasible means to capture requirements since there was but different opinions of end state. An exploratory development model was chosen to probe the maturity of land forces culture and search for opportunities of approach. Since earlier attempts to automate land forces command and control were mainly failed there was additional opposition to computers in battle field. 

To mitigate risks and exploit all unfolding opportunities the exploratory method was applied as follows:
  • An end-to-end blue force tracking feature was introduced in existing battle management system and it was extended from HQ of Land Forces down to companies. As first field exercises started to show positive feedback it become clear that this feature was needed. But not in all areas of operation since early adaptation in Finnish ISAF task force it was not welcomed. These bad experiences delayed BMS implementation in international operations for 3 years.
  • Second probe of capability was done when land forces blue force tracking was integrated with police, civil defence and medical support blue force information for Civil-Military operations for home land defence area of operations. As land forces battle management system and other agencies field management system were integrated, it provided clear benefit to all complex home land operations from police lead searching operation to life fire exercises of Defence Forces. 
  • Third probe was done by extending legacy BMS to platoon and group level. This started the change of operational procedures in battle technical level. Gradually swarming tactics was applied and the opportunity to develop new land forces fighting doctrine was appearing more promising. 
  • Fourth probe was to introduce full 4th generation battle management system for international operations. This time driver for implementation was coming from other forces implementing similar capabilities as earlier experiments were keeping some officers doubtful. First BMS was introduced in exercises and training for operations. Gradually capability was rotated to actual peace keeping operations. With effort on usability it was welcomed especially by reservists who formed the main body of troops. This drove also enlisted soldiers to adapt new methods of planning, commanding and controlling peace keeping and enforcing operations.  
  • Fifth generation battle management system was developed using rapid application development model parallel to these earlier prototypes. In development all lessons from other lines of operation were carefully studied and risks were mitigated.  

An example to manage overall development of military ICT enabled capabilities


As Military Forces become more digitalized the complexity of C4ISTAR System of systems will increase but military functions become simpler since added information will take away some friction and fog from battlefield. The challenge to gain and sustain asymmetric advantage over potential adversaries becomes harder. Forces need to be more flexible  in operation than any time before. This calls for quick learning and adapting both when building forces and in operating them in surprising situations. There is a demand for hybrid model to improve one’s ICT enabled capabilities. Figure 8 illustrates one possible structure  to have agility in development but still maintain control over the whole life-cycle of System of systems.

Figure 8: An example to manage more agile development of ICT enabled military capabilities

The strategic portfolio is divided into three areas of development :
Keiretsu or LEAN development in Operations of ICT Service Production
Kaikaku or discrete development of ICT enabled capabilities
Recognising concepts and opportunities for longer term development.

Continuous or keiretsu improvement loop is taking place in ICT service production being mostly end-user requirement driven. Management may follow LEAN, Six Sigma or Deming loop within ITIL service management family of processes. Improvement pace may vary between once a year to daily delivery. Development process starts “Alpha” version testing in ICT reference environment. If passed increment is migrated to Pilot environment for “Beta” testing. After full assurance of integration increment is migrated to production environment.

Kaikaku development may use any fitting development model to deliver capability parts per situation or environment. One development program is needed to manage all developed changes. There might be several parallel projects and programs ongoing utilizing different development models, but they all will deliver their capability parts via Service Production Change management. Simple management of creating new capabilities may follow Define-Design-Build process.

Strategic level sense making includes recognizing new opportunities, modelling them and war gaming in simulated environment where adversaries, neutral, own forces and their systems interact. There should also be several different experimenting sessions to test the practicality of new opportunities.

This concludes the analysis of environment and situation where development is taken place. Analysis was done by using Cynefin method in explaining different situations. Each situation was faced with some existing development method and further explained with examples from the Finnish Defence Forces. Finally an overall developing management framework was introduced to control different development approaches, situations and goals.