Bulletproofing IT Contracts
- 06 September, 2002 11:00
- Comments
It was a story that gave pause for thought across the US, creating in IT buyers everywhere those uneasy, there-but-for-the-grace-of-God sensations that beset us all when a peer comes under attack and we know our turn could one day come.
In its version, US CIO described how Elias Cortez, director of California's Department of Information Technology (DOIT), had fought back tears as he sat before the bright lights of a state legislative investigative committee and tried to deflect blame over a disastrous $US95 million contract for 270,000 Oracle database software licences. Licences, it subsequently turned out, that relatively few state workers needed or wanted.
At issue was whether the Oracle contract would cost taxpayers $US41 million, as a state auditor's April report had suggested, or save the state more than $US100 million, as Oracle claimed. Either way, the politics of the matter meant Cortez's bacon was clearly cooked.
It is a story that resonates with any large organisation buying software. Big spending customers have been hostage to software vendors since the industry's genesis, typically bound not only by the vendor's payment structures but often also by their terms of engagement.
The auditor's report found state officials working on the no-bid contract had applied little or no due diligence. It was bad enough that few state agencies wanted or needed the software, and that the state had bought many more licences than it had employees to use them, the auditor found. Insult had been added to injury by significantly inflated savings projections provided by an Oracle partner who stood to make millions of dollars, and the $US25,000 political contribution an Oracle executive had given a representative of California governor Gray Davis shortly after the contract was signed. The auditor's findings forced the governor to announce plans to try to nullify the May 31, 2001 contract and move to set up stricter guidelines for purchasing contracts.
Heads had to roll. Not surprisingly Davis, under intense political pressure, forced the resignation of Cortez after earlier accepting the resignation of two other top officials. Meanwhile Oracle vehemently rejected the criticism, insisting the contract would save the state money and improve its technology operations.
With investigations under way to determine exactly how the state's contract with Oracle went off course, enterprise CIOs around the US are saying mistakes outlined in the auditor's report were easily avoidable had fundamental IT purchasing practices been followed. The same, of course, applies in Australia. "IT is a hard enough business to get right as it is, and so taking contracts too casually is a very dangerous place to be," says Laurie Turner, general manager IT at David Jones. "I'm not saying that a good contract can save you, but it can certainly get you into trouble if it's a weak contract."
The DOIT's fiasco serves as a powerful study in how not to deal with vendors in developing and executing an IT purchasing contract. Making IT contracts bulletproof may not be easy, but it can be done.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
10 Essential Steps to Email Security
Modern business is reliant on email. All organisations using email need to answer the following questions: How do we control spam volumes without the risk of trapping a business email? How do we prevent infections from email-borne viruses? How do we stop leakage of confidential information? Can we detect and stop exploitation from phishing attacks? How do we control brand damage from occurring due to employee misuse? How do we prevent inappropriate content from being circulated? -
Delivering Tomorrow's Backup and Recovery Infrastructure
The data protection market has changed considerably over the past decade. During this time, the market witnessed a fundamental shift away from relying solely on tape for backup and recovery to using disk-based backup solutions to address challenges including backup performance, reliability, and recovery time objectives. This paper highlights that firms evaluating next-generation data protection solutions must expect a greater degree of integration between the technology components in today's data protection path. -
Using Application Control to Reduce Risk with Endpoint Security
Unwanted applications, like games, result in productivity loss. This is often the primary consideration when applying application control. But unauthorized applications also increase your company’s risks of malware infection and data loss. This paper details how endpoint security solutions that incorporate application control provide the most efficient, comprehensive defense against unauthorized applications.
-
Degn Prum Digital Classroom
-
Ethics in Technical Communication
-
Mastering AutoCAD 2000 +CD
-
Learning to Program with Visual Basic 6.0 2E
-
Implementing Nap and Nac Security Technologies
-
Lean Architecture - for Agile Software Development
-
SQL for Dummies, 6th Edition
-
Teach Yourself Visually Drer
-
Software Engineering








Comments
Post new comment