CIS 500 Weeks 6, 7, 8,9,11 Discussion Questions
Week 6 * Mobile banking features have added several advantages for customers however; there are security risks that come with them. Determine the security risks with respect to phishing, smishing, vishing, cloning, and a lost or stolen smartphone that have been experienced by the financial services industry as a result of mobile banking.
Phishig – Is when malware is downloaded on to a device and it attempts to obtain personal information. It lies in wait and gathers information from apps such as a mobile banking app to gain your login and password. If you bank does not have proper security in place this can lead to your account getting hacked and loss of money.
Smishing- This is where fraudulent communication occurs in the form of a text message in order to obtain personal information.
Vishing – This is similar to smishing instead of getting information through text it is obtained through phone calls or voicemails.
Cloning- The transfer of information from one device to another device including the electronic serial number
When a smartphone is lost or stolen this can lead to a compromise to a person’s personal information since it may be on the phone. I bank with Bank of America and use the mobile app to manage my account transfer funds, pay bills, deposit checks and so on. The app does not store the password but it does store the user login. You are unable to just log in to it from a new device or location without verify your identity. This is the form of know the image chosen when you started the account as well as answering security question and entering a verification code that is texted to the phone number that was used to set up the account. I am not saying that this prevents any of the above threats from happening but it does make it much more difficult for your account to be hacked. Many mobile devices come with apps on them that will wipe the information on the device if it lost or stolen. You can also call you service provider to do this as well if the option is available.

* Personal data assistants (PDAs), iPads, and e-Readers have the capability to wirelessly connect to online stores so that their users can purchase books, music, games, read e-Books, read the news, and perform a myriad of other tasks. Describe and assess the impact of these devices on newspapers, paper books, music CDs, gamesDVDs, etc.
With devices such as PDAs, iPads and e-Reader becoming more popular they are impacting the sales of newspaper, paper books, music CDs and games DVDs in positive and negative ways. When it comes to music industry it has increased sales. Those sales may not be in cd sales but in digital downloads of songs and or albums. It gives the customer to download certain songs if they do not like the whole album. It also allows for quicker sales on release day since they can just log on to iTunes or what every app they are using to download the song the moment is available. This hold true for eBooks and games as well, no more waiting in lines at midnight to purchase an item you can get it from the comfort of your own home. I am sure that this has reduced the sale at small bookstores who probably already struggle to compete against large chains such as Barnes and Noble. Even though many people are buying more and more eBooks it doesn’t change the fact that some people buy both. There will still be a need for paper backs since you can’t go get your eBook autographed by the author. A lot of people enjoy reading the paperback book over the eBook. This is also true with games weather they are console of PC. Many people buy the actual game instead of the digital version because they get special items. Like with many PC games you can get the collector’s edition which offer special in game bonuses as well as books soundtracks and other things. I don’t think that the digital format will completely replace the paper or disk version but I do think it has helped increase the sales of books games and music and has allowed for the reintroduction of classics.
Week 7 * Just-in-time (JIT) software is unable to foresee delivery problems resulting from bad weather, labor strikes, etc. Assess how a company using JIT inventory management software should mitigate delivery problems.
There needs to be a manual override that can make adjustment in the event of bad weather, labor strikes or other unforeseeable issues. Mangers that use this software need to keep up on the weather and news involving the companies they receive parts from and the events that are happing around them. Normally bad storms do not come out of nowhere so you can order parts prior to its arrival to compensate if you are manufacturing or send out orders early. Have a backup suppliers set up in the event that for whatever reason you cannot get product from your primary supplier. Have an emergency plans set in place that take into account varies common scenarios.

* An increasing number of retailers have installed self-checkout machines. Justify the installation of these machines in terms of costs management, efficiency, productivity, and trustworthiness of customers.

In regard to cost managing store that are opened 24/7 have dead times where they do not have a lot of business and they would have loss money due to wages With self-checkout you cut cost of having to pay someone to stand there to ring someone up. It also helps keep traffic flow of customers moving at check out. They way most self-checkout lines work you scan the item and you pace it in the bagging area which is on a scan that keep track of item being scanned and bagged. There is also a person at the self-scan area in case there is a problem or id has to be checked for alcohol and tobacco products they also so keep an eye out to make sure no one is stealing things. There are also security tags on high risk items to ensure that they are not stolen measures such as this ensures that products are not stolen.

* Loyalty programs are programs that recognize customers who repeatedly use services or buy products offered by a company. Examples include BI-LO’s Bonus Card, Kroger’s VIP card, frequent flyers, etc. Determine the risks associated with loyalty programs and identify the risk that is of most concern to you and why.
Pretty much every store has a loyalty program and they all require you to hand over personal information such as address, cell and/or home phone number, email, birthday, age and other demographics. Concerns with this are how is the information being used for do the company’s sale the information to other companies. Are there proper security measures in place to ensure that this data is not stolen?

* From the e-Activity, imagine you are a CTO of a large enterprise and have been tasked with choosing an ERP system for your organization. Compare and contrast commercial ERP systems to open source ERP systems focusing on flexibility and extensibility, supported platforms, support, and intellectual property issues. Describe the one you would choose and why.
I would go with commercial ERP to ensure that I have flexibility, extendibility, platform support, technical support. With open source you may encounter compatibly issues across platforms and security issues related to each. Even with the most commonly known open source software there may not have the flexibility need to do what you to do as well as you need may not have the support you get with a commercial product.
Week 8
From the e-Activity, determine the strategic advantages and disadvantages of using Customer Relations Management (CRM), services provided by vendors, such as, with regard to analytics and forecasting, infrastructure maintenance, data mining, and availability for a business that cannot implement its own CRM system.
* Analytics and forecasting can be used to generate report on sales and services * Scalability to go up or down as needed * Real-time data * Easily deployed once application are chosen

Disadvantages * Startup cost * Time lost training staff to use the product * May be difficult to integrate with current systems * Upkeep cost and upgrades

Businesses that employ CRM, Supply Chain Management (SCM), and Enterprise Resource Planning (ERP) for better decision making have a competitive advantage over businesses that do not. Assume that you are CTO of a large retail company that doesn’t use these tools. As part of the company’s IT strategic plans, the CEO would like to implement them. Suggest to the CEO how to effectively integrate these tools into the company. I would suggest that this system be implemented so that the company can stay competitive with others in the industry. Using the system will increase operations and communication. Arrange a meeting to discuss the possible change with leadership and explain what is need on their part to make this successful transition if they decide to go this route. Show how it has helped and worked for other businesses and how it can work for our company.
Software development can be a considerable part of a company’s software budget. Software may be developed in-house or outsourced. Outsourced development may be on shore or offshore. There have been heated debates on the best strategy of developing software. Take a strategic position on this debate. Create an argument for which method (in-house, onshore, and offshore software development) is the best in terms of cost, security, reliability, and intellectual property protection. Support your response. Outsourcing would be the most cost and time efficient when it comes to software development. With advances in technology and communication security and reliability is no longer a problem the way it has been in the past. As for intellectual property protection this too has change over the years and more laws and regulations have been put into place to protect this.

IT governance is concerned with organizational investments in IT and to ensure that the IT strategy delivers full value. The avoidance or prevention of IT strategic failures is the biggest part of IT governance. Describe at least two issues that drive IT governance. 1. Lack of accountability There needs to be a clear understanding of the roles and responsibilities of everyone. 2. Disconnect between management and IT. Management may not fully understand what is needed to implement or secure certain security measures or how to manage them and that can cause all kinds of problems. There need to be clear lines of communication between IT departments and mangers to ensure everyone is on the same page and following procedures
Week 9
Service Oriented Architecture (SOA) is an architectural style for building software applications that use services available in a network such as the Web. SOA is based on standard protocols such as Hypertext Transfer Protocol (HTTP), Simple Object Access Protocol (SOAP), etc. SOA services are consumed by client applications over the Internet. SOA exposes business services to a wide range of service consumers. Assess SOA in terms of business integration, security, interoperability, and IT infrastructure.
Service-Oriented Architecture
SOA is an architectural style for building software applications that use services available in a network such as the web. It promotes loose coupling between software components so that they can be reused. Applications in SOA are built based on services. A service is an implementation of well-defined business functionality, and such services can then be consumed by clients in different applications or business processes.
SOA allows for the reuse of existing assets where new services can be created from an existing IT infrastructure of systems. In other words, it enables businesses to leverage existing investments by allowing them to reuse existing applications, and promises interoperability between heterogeneous applications and technologies. SOA provides a level of flexibility that wasn't possible before in the sense that: * Services are software components with well-defined interfaces that are implementation-independent. An important aspect of SOA is the separation of the service interface (the what) from its implementation (the how). Such services are consumed by clients that are not concerned with how these services will execute their requests. * Services are self-contained (perform predetermined tasks) and loosely coupled (for independence) * Services can be dynamically discovered * Composite services can be built from aggregates of other services From everything that I have read SOA can work with current systems and is secure and easily added to an existing system. It has many apps available to suit the needs of a business.
A Web service is a set of technologies used for exchanging data between applications. Web services allow businesses to connect their processes to their business partners. This form of business integration results in Business Process Management (BPM) mashups. Assess the benefits of BPM mashups in terms of ease of integration, composition of services, and information sharing.
As stated on the Paga websites these are just a few benefits to BPM
Understanding — Migrating your processes onto a BPM platform can serve as the impetus to deeper understanding of your operations and the strengths and weaknesses of your current processes.
Efficiency and effectiveness — By intelligently automating manual processes or sub-processes that are time-consuming and prone to error, and by providing a fast, powerful source of decision-making support for process personnel, business process management software increases the efficiency and effectiveness of your operations.
Consistency — When consistency across customer interactions or other types of processes is important, business process management software can deliver that consistency.
Scalability — Automated and semi-automated processes scale much better than manual processes, an important consideration for businesses on a growth trajectory or navigating economic ups and downs. BPM software can also help to facilitate business process integration for large enterprises whose operations span multiple locations, departments, and IT systems.
Agility — The right business process management software will empower you to quickly update your processes in response to developments in your operational environment. Across time, BPM software provides a dynamic foundation for business performance management and continuous business process improvement programs. –
When a company has a need for software, one option is to buy it from a software vendor or build it internally if the IT department can develop the software. This results in a build-or-buy debate.
Week 11
You have just completed 10 weeks of a CIS course. Imagine you have been asked to create a one-day training course highlighting the important elements of what you have just learned in the past 10 weeks.
Create a hierarchy of five (no more or no less) of the most important topics that you believe need to be addressed in this one-day course that best fits the course title of “Information Systems for Decision Making: The Essentials Presented in One Day.” Give a detailed rationale for each of the five topics.

1. IS Vulnerabilities and Threats-It is important to know the type of threats you will face from within your organization as well as from the outside. You need to know how to proper defend from them and ensure that everyone is trained in how to protect themselves and the company. 2. IT Infrastructure and Cloud Computing –This essential to know since you need to know how to setup IS with regards to you company. How to save money and still have everything you need to have your business function properly and dependable support and scalability at your fingertips. 3. E-Business and E-Commerce Challenges- it is important you know the risk and advantages to E- Business and how to successfully integrate it into your current business plan. 4. IT Governance-This is important because you need to know and follow guide lines to ensure not only the protection of your company but of your customers. 5. Mobile Computing and Social Networking – This is key to staying up on new technologies and being able to reach more potential customers as well as adding more convince to current customers. It also shows the importance of have more ways to advertise products and receive quick feedback.
Using140 characters or less (the length of a Tweet), summarize the importance of this class to someone unfamiliar with the concepts.
This class provides helpful information about the importance of IS and IT infrastructure. It helps to inform about how to best make sure you people are trained properly and the importance of know security risk and how to prevent them. It is also provides a wealth of knowledge that is important in the IT field and our personal lives not only about security but how business are affected by ne advances in technology and what they are looking for in future employees.…...

