Showing posts with label CERTIFICATE. Show all posts
Showing posts with label CERTIFICATE. Show all posts

Friday, May 19, 2017

Feasibility Study


FEASIBILITY STUDY


In simple terms, a feasibility study involves taking a judgment call on whether a project is within your capabilities (doable). A feasibility study evaluates the project's potential for success.

The two criteria to judge feasibility are cost required and value to be delivered. A well-designed study should offer a historical background of the business or project, a description of the product or service, accounting statements, details of operations and management, marketing research and policies, financial data, legal requirements and tax obligations. Generally, such studies precede technical development and project implementation.

1.       Technical Feasibility - assessment is centred on the technical resources available to the organization. It helps organizations asses if the technical resources meet capacity and whether the technical team is capable of converting the ideas into working systems. Technical feasibility also involves evaluation of the hardware and the software requirements of the proposed system.

2.       Economic Feasibility - helps organizations assess the viability, cost, and benefits associated with projects before financial resources are allocated. It also serves as an independent project assessment, and enhances project credibility, as a result. This assessment typically involves a cost/ benefits analysis of the project.

3.       Legal Feasibility - investigates if the proposed system conflicts with legal requirements like data protection acts or social media laws.

4.       Operational Feasibility - this involves undertaking a study to analyze and determine whether your business needs can be fulfilled by using the proposed solution. It also measures how well the proposed system solves problems and takes advantage of the opportunities identified during scope definition.
These include such design-dependent parameters such as reliability, maintainability, supportability, usability, disposability, sustainability, affordability, and others.

5.       Scheduling Feasibility is the most important for project success. A project will fail if not completed on time. In scheduling feasibility, we estimate how much time the system will take to complete, and with our technical skills we need to estimate the period to complete the project using various methods of estimation.

Conducting a feasibility study is always beneficial to the project as it gives you and other stakeholders a clear picture of your idea.

Below are the key benefits of conducting a feasibility study:

·         Gives project teams more focus and provides an alternative outline.
·         Narrows the business alternatives.
·         Identifies a valid reason to undertake the project.
·         Enhances the success rate by evaluating multiple parameters.
·         Aids decision-making on the project.



Friday, July 22, 2016

BCS/CER/IS/DIP/SE1/ Prototype Model

Prototype Model


Prototyping is a working model of a real system. There are two types of prototypes. The basic idea here is that instead of freezing the requirements before a design or coding can proceed, 
  • Throw-away prototype
  • Evolutionary Prototype 


Throw-away prototype
Model is use to gather requirements, after gathering requirements development start from the beginning. 
Evolutionary Prototype
Model is use to get the user feedback and finalize the model and deliver the system

Throwaway prototype is built to understand the requirements. This prototype is developed based on the currently known requirements. By using this prototype, the client can get a “what users really want” of the system, since the interactions with prototype can enable the client to better understand the requirements of the desired system.  Prototyping is an attractive idea for complicated and large systems.

Advantages of Prototype model:
  • Users are actively involved in the development
  • Since in this methodology a working model of the system is provided, the users get a better understanding of the system being developed.
  • Errors can be detected much earlier.
  • Quicker user feedback is available leading to better solutions.
  • Confusing or difficult functions can be identified
  • Requirements validation, Quick implementation of, incomplete, but functional, application.
Disadvantages of Prototype model:
  • Leads to implementing and then repairing way of building systems.
  • Increase the complexity of the system as scope of the system may expand beyond original plans.

Friday, July 10, 2015

BCS/CER/CNT/OSI 7 LAYERS


Definition: Learn what the Open Systems Interconnection (OSI) reference model is and how its seven layers of functions provide vendors and developers with a common language for discussing how messages should be transmitted between any two points in a telecommunication network


OSI (Open Systems Interconnection) is reference model for how applications can communicate over a network. A reference model is a conceptual framework for understanding relationships. 

The purpose of the OSI reference model is to guide vendors and developers so the digital communication products and software programs they create will Inter-operate, and to facilitate clear comparisons among communications tools. Most vendors involved in telecommunications make an attempt to describe their products and services in relation to the OSI model. And although useful for guiding discussion and evaluation, OSI is rarely actually implemented, as few network products or standard tools keep all related functions together in well-defined layers as related to the model. The TCP/IP protocols, which define the Internet, do not map cleanly to the OSI model.

The seven Open Systems Interconnection layers are:

Layer 7: The application layer. This is the layer at which communication partners are identified (Is there someone to talk to?), network capacity is assessed (Will the network let me talk to them right now?), and that creates a thing to send or opens the thing received.  (This layer is not the application itself, it is the set of services an application should be able to make use of directly, although some applications may perform application layer functions.)

Layer 6: The presentation layer. This layer is usually part of an operating system and converts incoming and outgoing data from one presentation format to another (for example, from clear text to encrypted text at one end and back to clear text at the other).

Layer 5: The session layer. This layer sets up, coordinates and terminates conversations. Services include authentication and reconnection after an interruption.

Layer 4: The transport layer. This layer manages packetization of data, then the delivery of the packets, including checking for errors in the data once it arrives. 

Layer 3: The network layer. This layer handles the addressing and routing of the data (sending it in the right direction to the right destination on outgoing transmissions and receiving incoming transmissions at the packet level). IP is the network layer for the Internet.

Layer 2: The data-link layer. This layer sets up links across the physical network, putting packets into network frames. This layer has two sub-layers, the Logical Link Control Layer and the Media Access Control Layer. Ethernet is the main data link layer in use.

Layer 1: The physical layer. This layer conveys the bit streamthrough the network at the electrical, optical or radio level. It provides the hardware means of sending and receiving data on a carrier network.


Monday, January 19, 2015

BCS/DIP/PGD/MIS,CSM,ITSM/PHYSICAL SECURITY

Physical Security
#1: Lock up the server room
Even before you lock down the servers, in fact, before you even turn them on for the first time, you should ensure that there are good locks on the server room door. Of course, the best lock in the world does no good if it isn't used, so you also need policies requiring that those doors be locked any time the room is unoccupied, and the policies should set out who has the key or keycode to get in.
The server room is the heart of your physical network, and someone with physical access to the servers, switches, routers, cables and other devices in that room can do enormous damage.
#2: Set up surveillance
Locking the door to the server room is a good first step, but someone could break in, or someone who has authorized access could misuse that authority. You need a way to know who goes in and out and when. A log book for signing in and out is the most elemental way to accomplish this, but it has a lot of drawbacks. A person with malicious intent is likely to just bypass it.
A better solution than the log book is an authentication system incorporated into the locking devices, so that a smart card, token, or biometric scan is required to unlock the doors, and a record is made of the identity of each person who enters.
A video surveillance camera, placed in a location that makes it difficult to tamper with or disable (or even to find) but gives a good view of persons entering and leaving should supplement the log book or electronic access system. Surveillance cams can monitor continuously, or they can use motion detection technology to record only when someone is moving about. They can even be set up to send e-mail or cell phone notification if motion is detected when it shouldn't be (such as after hours).
#3: Make sure the most vulnerable devices are in that locked room
Remember, it's not just the servers you have to worry about. A hacker can plug a laptop into a hub and use sniffer software to capture data traveling across the network. Make sure that as many of your network devices as possible are in that locked room, or if they need to be in a different area, in a locked closet elsewhere in the building.
#4: Don't forget the workstations
Hackers can use any unsecured computer that's connected to the network to access or delete information that's important to your business. Workstations at unoccupied desks or in empty offices (such as those used by employees who are on vacation or have left the company and not yet been replaced) or at locations easily accessible to outsiders, such as the front receptionist's desk, are particularly vulnerable.
Disconnect and/or remove computers that aren't being used and/or lock the doors of empty offices, including those that are temporarily empty while an employee is at lunch or out sick. Equip computers that must remain in open areas, sometimes out of view of employees, with smart card or biometric readers so that it's more difficult for unauthorized persons to log on.
#5: Protect the portables
Laptops and handheld computers pose special physical security risks. A thief can easily steal the entire computer, including any data stored on its disk as well as network logon passwords that may be saved. If employees use laptops at their desks, they should take them with them when they leave or secure them to a permanent fixture with a cable lock, such as the one at PC Guardian.
Handhelds can be locked in a drawer or safe or just slipped into a pocket and carried on your person when you leave the area. Motion sensing alarms such as the one at SecurityKit.com are also available to alert you if your portable is moved.
For portables that contain sensitive information, full disk encryption, biometric readers, and software that "phones home" if the stolen laptop connects to the Internet can supplement physical precautions.
#6: Pack up the backups
Backing up important data is an essential element in disaster recovery, but don't forget that the information on those backup tapes, disks, or discs can be stolen and used by someone outside the company. Many IT administrators keep the backups next to the server in the server room. They should be locked in a drawer or safe at the very least. Ideally, a set of backups should be kept off site, and you must take care to ensure that they are secured in that offsite location.
Don't overlook the fact that some workers may back up their work on floppy disks, USB keys, or external hard disks. If this practice is allowed or encouraged, be sure to have policies requiring that the backups be locked up at all times.
#7: Disable the drives
If you don't want employees copying company information to removable media, you can disable or remove floppy drives, USB ports, and other means of connecting external drives. Simply disconnecting the cables may not deter technically savvy workers. Some organizations go so far as to fill ports with glue or other substances to permanently prevent their use, although there are software mechanisms that disallow it. Disk locks, such as the one at SecurityKit.com, can be inserted into floppy drives on those computers that still have them to lock out other diskettes.
#8: Protect your printers
You might not think about printers posing a security risk, but many of today's printers store document contents in their own on-board memories. If a hacker steals the printer and accesses that memory, he or she may be able to make copies of recently printed documents. Printers, like servers and workstations that store important information, should be located in secure locations and bolted down so nobody can walk off with them.
Also think about the physical security of documents that workers print out, especially extra copies or copies that don't print perfectly and may be just abandoned at the printer or thrown intact into the trash can where they can be retrieved. It's best to implement a policy of immediately shredding any unwanted printed documents, even those that don't contain confidential information. This establishes a habit and frees the end user of the responsibility for determining whether a document should be shredded.


Wednesday, August 27, 2014

BCS/DIP/CER/PGD/ BCS CODE OF CONDUCT SUMMARY

BCS Code of Conduct

 As a professional body the British Computer Society (known as BCS, the Chartered Institute for IT), has a responsibility to set rules and professional standards to direct the behaviour of its members in professional matters. It is expected that these rules and professional standards will be higher than those established by the general law and that they will be enforced through disciplinary action which can result in expulsion from membership.
Members are expected to exercise their own judgement (which should be made in such a way as to be reasonably justified) to meet the requirements of the code and seek advice if in doubt.


  • ·         sets out the professional standards required by BCS as a condition of membership.
  •  ·         applies to all members, irrespective of their membership grade, the role they fulfil, or the jurisdiction where they are employed or discharge their contractual obligations.
  •  ·         governs the conduct of the individual, not the nature of the business or ethics of any Relevant Authority*.

1. Public Interest

You shall:
a. have due regard for public health, privacy, security and wellbeing of others and the environment.
b. have due regard for the legitimate rights of Third Parties*.
c. conduct your professional activities without discrimination on the grounds of sex, sexual orientation, marital status, nationality, colour, race, ethnic origin, religion, age or disability, or of any other condition or requirement
d. promote equal access to the benefits of IT and seek to promote the inclusion of all sectors in society wherever opportunities arise.

2. Professional Competence and Integrity

You shall:
a. only undertake to do work or provide a service that is within your professional competence.
b. NOT claim any level of competence that you do not possess.
c. develop your professional knowledge, skills and competence on a continuing basis, maintaining awareness of technological developments, procedures, and standards that are relevant to your field.
d. ensure that you have the knowledge and understanding of Legislation* and that you comply with such Legislation, in carrying out your professional responsibilities.
e. respect and value alternative viewpoints and, seek, accept and offer honest criticisms of work.
f. avoid injuring others, their property, reputation, or employment by false or malicious or negligent action or inaction.
g. reject and will not make any offer of bribery or unethical inducement.

3. Duty to Relevant Authority

You shall:
a. carry out your professional responsibilities with due care and diligence in accordance with the Relevant Authority’s requirements whilst exercising your professional judgement at all times.
b. seek to avoid any situation that may give rise to a conflict of interest between you and your Relevant Authority.
c. accept professional responsibility for your work and for the work of colleagues who are defined in a given context as working under your supervision.
d. NOT disclose or authorise to be disclosed, or use for personal gain or to benefit a third party, confidential information except with the permission of your Relevant Authority, or as required by Legislation.
e. NOT misrepresent or withhold information on the performance of products, systems or services (unless lawfully bound by a duty of confidentiality not to disclose such information), or take advantage of the lack of relevant knowledge or inexperience of others.

4. Duty to the Profession

You shall:
a. accept your personal duty to uphold the reputation of the profession and not take any action which could bring the profession into disrepute.
b. seek to improve professional standards through participation in their development, use and enforcement.
c. uphold the reputation and good standing of BCS, the Chartered Institute for IT.
d. act with integrity and respect in your professional relationships with all members of BCS and with members of other professions with whom you work in a professional capacity.
e. notify BCS if convicted of a criminal offence or upon becoming bankrupt or disqualified as a Company Director and in each case give details of the relevant jurisdiction.
f. encourage and support fellow members in their professional development.


BCS/ PGD /SE2/MIS/CSM OR BCS/DIP/ITPM / CAPABILITY MATURITY MODEL(CMM)


The Capability Maturity Model (CMM) is a methodology used to develop and refine an organization's software development process. The model describes a five-level evolutionary path of increasingly organized and systematically more mature processes. CMM was developed and is promoted by the Software Engineering Institute (SEI), a research and development center sponsored by the U.S. Department of Defense. 
The Software Capability Maturity Model describes the principles and practices underlying software process maturity and is intended to help software organizations improve the maturity of their software processes in terms of an evolutionary path from ad hoc, chaotic processes to mature, disciplined software processes.
It is important, as it is an objective assessment of an organization’s software capability with a proven approach to improvements.

SCMM has five levels:
Initial - The software process is characterised as ad hoc, and occasionally even chaotic. Few processes are defined and success depends on individual effort and heroics.
Repeatable - Basic project management processes are established to track cost, schedule and functionality. The necessary process discipline is in place to repeat earlier successes on projects with similar applications.
Defined - The software process for both management and engineering activities is documented, standardised and integrated into a standard software process for the organisation. All projects use an approved, tailored version of the organisation's standard software process for developing and maintaining software.
Managed - Detailed measures of the software process and product quality are collected. Both the software process and products are quantitatively understood and controlled.
Optimising - Continuous process improvement is enabled by quantitative feedback from the process and from piloting innovative ideas and technologies.

ISO Vs CMM
The CMM is similar to ISO 9001, one of the ISO 9000 series of standards specified by the International Organization for Standardization. The ISO 9000 standards specify an effective quality system for manufacturing and service industries; ISO 9001 deals specifically with software development and maintenance. The main difference between the two systems lies in their respective purposes: ISO 9001 specifies a minimal acceptable quality level for software processes, while the CMM establishes a framework for continuous process improvement and is more explicit than the ISO standard in defining the means to be employed to that end.


BCS/CER/IS/Hard System Methodology(SSADM)

Hard System methodology


Hard problems

In hard systems approaches (or Structured Systems Analysis and Design Methodology (SSADM)), rigid techniques and procedures are used to provide unambiguous solutions to well-defined data and processing problems. These focus on computer implementations.
·         Problems can be well defined
·         Assumption of definite goals & solutions
·         Can pre-define success criteria
·         Technologically-oriented
e.g. - SSADM

What is SSADM?

Stand for Structured Systems Analysis and Design Method, a set of standards developed in the early 1980s for systems analysis and application design widely used for government computing projects in the United Kingdom. SSADM uses a combination of text and diagrams throughout the whole life cycle of a system design, from the initial design idea to the actual physical design of the application.

Stage 0: Feasibility

The Feasibility stage is a short assessment of a proposed information system to determine if the system can meet the business requirements of an organization, assuming the business case exists for developing the system. The analyst considers possible problems faced by the organization and produces various options to resolve these issues. Either the organization or you must decide if the cost of resolving the problems is worth the likely benefit to the project.

Stage 1: Investigation of the Current Environment

Detailed requirements are collected and business models are built in the Investigation of the Current Environment stage. This stage is where you develop a business-activity model, investigate and define requirements, investigate current processing in the data flow model, investigate current data and derive the logical view of current services.

Stage 2: Business System Options

The Business Systems Options, or BSO, stage allows the analyst and you to choose between a number of business-system options that each describe the scope and functionality provided by a particular development and implementation approach. After you present these to management, the management then decides which BSO is the better option.

Stage 3: Definition of Requirements

This stage specifies the details in the processing and data requirements of the selected BSO option. In this stage you define the required system processing, develop the required data model, determine the systems for existing or new functions, develop the user job specifications, enhance the required data model, develop specific prototypes and confirm the system objectives.

Stage 4: Technical Systems Options

This stage allows you and the analyst to consider the technical options. Details such as the terms of cost, performance and impact on the organization is determined. You identify, define and select the possible technical system option in this stage.

Stage 5: Logical Design

This stage involves you specifying the new system through designing the menu structure and dialogues of the required system. The steps in this stage include defining the user dialogue, defining update processes and defining the inquiry processes.

Stage 6: Physical Design


This is the implementation phase of SSADM. The Physical Design stage is used to specify the physical data and process design use the language and features of the chosen environment and incorporate installation standards. This stage concentrates on the environment in which the new system will be running.

BCS/CER/IS/Soft System Methodology

Soft System Methodology

Soft problems
  • ·         Difficult to define - they are problem situations
  • ·         High social, political & human activity component
  • ·         Sometimes wicked!
  • ·         Soft systems thinking

Soft systems methodology is a qualitative methodology developed by Peter Checkland and his colleagues at Lancaster University.  It applies systems concepts to qualitative research (as does the Snyder process).

The 7-stage description

1   The problem situation unstructured

The problem situation is first experienced, as it is, by the researcher.  That is, the researcher makes as few presumptions about the nature of the situation as possible.

 2   The problem situation expressed

In this step the researcher develops a detailed description, a "rich picture", of the situation within which the problem occurs.  This is most often done diagrammatically.
Throughout the 7 stages, both and logic and the culture of the situation are taken into account.  These twin streams of enquiry, logic and culture, are incorporated into the rich picture.
Checkland puts it this way.  In addition to the logic of the situation, the rich picture also tries to capture the relationships, the value judgments people make, and the "feel" of the situation.

3   Root definitions of relevant systems (CATWOE)

Now the "root definitions", the essence of the relevant systems, are defined.
For the logical analysis, Checkland provides the mnemonic CATWOE as a checklist for ensuring that the important features of the root definitions are included:

·         Customers...................who are system beneficiaries
·         Actors......................who transform inputs to outputs
·         Transformation..............from inputs into outputs
·         Weltanschauung..............the relevant world views
·         Owner.......................the persons with power of veto
·         Environmental constraints...that need to be considered

 "transformation" element is one of the features that signal this as a "systems" approach.
The cultural analysis has three parts:
A role analysis, focusing on the intervention itself.  This seeks to identify the client, the would-be problem solver (the researcher), and the problem owner (roughly, stakeholders).  In the terms that we used in earlier sessions you could think of this as the diagnostic part of entry and contracting.
 A social system analysis.  This identifies, for the problem situation, three sets of elements: roles, norms, and values.
 A political system analysis.  This identifies the use of power in the problem situation.

4   Making and testing conceptual models

The researcher now draws upon her knowledge of systems concepts and models.  She develops descriptions, in system terms, of how the relevant parts of the situation might ideally function.
One of the important questions here is: ideals from whose point of view? If you adopt those who pay you as your client, you may well just help the organisation exploit its members more effectively.  If you adopt everyone in the system as a client, you will avoid this problem.  But perhaps people outside the system will bear some of the cost of this.  Here, as elsewhere, a careful identification of stakeholders can make a large difference to the outcomes.

 5   Comparing conceptual models with reality

The purpose is not to implement the conceptual models.  Rather, it is so that models and reality can be compared and contrasted.  The differences can be used as the basis for a discussion: how the relevant systems work, how they might work, and what the implication of that might be.

 6   Identify feasible and desirable changes

From the discussion at step 5, certain possible changes are identified.  They are likely to vary in desirability and feasibility:
desirable: is it technically an improvement?
feasible: especially, does it fit the culture?

 7   Action to improve the problem situation

The most desirable and feasible changes identified at step 6 are now put into practice.
 I would like now to offer a different description.  My hope is to do this in such a way that the cyclic nature of the process, and the use of dialectic comparisons, are made more evident. 

Monday, August 25, 2014

BCS/ CER / IS / FEASIBILITY STUDY

Feasibility Study (TELOS)

Feasibility study is carried out to select the best system that meets performance requirements.
The main aim of the feasibility study activity is to determine whether it would be financially and technically feasible to develop the product. The feasibility study activity involves the analysis of the problem and collection of all relevant information relating to the product such as the different data items which would be input to the system, the processing required to be carried out on these data, the output data required to be produced by the system as well as various constraints on the behavior of the system.

Technical Feasibility
This is concerned with specifying equipment and software that will successfully satisfy the user requirement. The technical needs of the system may vary considerably, but might include :
• The facility to produce outputs in a given time.
• Response time under certain conditions.
• Ability to process a certain volume of transaction at a particular speed.
• Facility to communicate data to distant locations.
In examining technical feasibility, configuration of the system is given more importance than the actual make of hardware. The configuration should give the complete picture about the system’s requirements:
How many workstations are required, how these units are interconnected so that they could operate and communicate smoothly. What speeds of input and output should be achieved at particular quality of printing.

Economic Feasibility

Economic analysis is the most frequently used technique for evaluating the effectiveness of a proposed system. More commonly known as Cost / Benefit analysis, the procedure is to determine the benefits and savings that are expected from a proposed system and compare them with costs. If benefits outweigh costs, a decision is taken to design and implement the system. Otherwise, further justification or alternative in the proposed system will have to be made if it is to have a chance of being approved. This is an outgoing effort that improves in accuracy at each phase of the system life cycle.


Operational Feasibility

This is mainly related to human organizational and political aspects. The points to be considered are
• What changes will be brought with the system?
• What organizational structure are disturbed?
• What new skills will be required? Do the existing staff members have these skills? If not, can they be trained in due course of time?

This feasibility study is carried out by a small group of people who are familiar with information system technique and are skilled in system analysis and design process.
Proposed projects are beneficial only if they can be turned into information system that will meet the operating requirements of the organization. This test of feasibility asks if the system will work when it is developed and installed.