Monday, January 26, 2015

BCS/PGD/MIS/SISP

Strategic Information System Planing 
The Ad Doc Approach
This approach towards development of information systems is the worst possible approach as people in the development process are in the process of perpetual fire fighting. There in no plan available and the development work is carried out as per wises of the developer based on his understanding of what the needs of the user should be. The outcome of this kind of approach is a set of systems that are not synchronized or synergized into one system but a host of systems that work in isolation.
The Data Collection Approach
In this approach, all possible data about the need for the system and about the system is collected. This approach assumes that information systems are best developed based on data from all quarters. This results in lack of focus and understanding as the systems development process gets mired unnecessarily into other issues, like projecting the future information requirement in granular detail by the user.
The Organization Chart Approach
In this approach the information system is developed with the organization structure in mind. It assumes that information strictly flows on the basis of organizational structures. Junctions of information exchange are made on an ad hoc basis which complicates the flow of information and brings in redundancy in the system.
Now that we know how not to approach IS development in an organization, let us discuss the appropriate approaches for IS development.
The Top-down Approach
The top-down approach is used to develop IS with the objectives in focus. The objectives of the IS become the most important priority. The objectives are clearly defined in the first step, followed by identification of the activities of the organization. This in turn is followed by the third step in which the decision-making needs of managers within the organization are analyzed and the necessary information flow for facilitating information delivery to managers for decision-making is understood in detail. Once all the details are available, the application is developed. In this type of system the objectives become the mainstay of the system. However, for this kind of system, the requirements from the systems have to be clearly understood upfront to avoid any problems in the development process. This is because the strategy of development is such that the design is not adequately dynamic.

The Bottom-up Approach

In the bottom-up approach, we find out the type of information that is produced in the operational subsystem and then work backward to integrate this with the entire IS structure to have an organization wide impact. In this design, there is more flexibility to change the information system deliverables even during the development process as the individual subsystems are not designed according to the demands of the upper layers as in the case of top-down approach. On the contrary, here the upper layers are integrated with the lower layer subsystems to create the IS. Thus, bottom-up systems can expand in response to real-world changes and needs of the organization.

Monday, January 19, 2015

BCS/DIP/PGD/MIS,CSM,ITSM/PHYSICAL SECURITY

Physical Security
#1: Lock up the server room
Even before you lock down the servers, in fact, before you even turn them on for the first time, you should ensure that there are good locks on the server room door. Of course, the best lock in the world does no good if it isn't used, so you also need policies requiring that those doors be locked any time the room is unoccupied, and the policies should set out who has the key or keycode to get in.
The server room is the heart of your physical network, and someone with physical access to the servers, switches, routers, cables and other devices in that room can do enormous damage.
#2: Set up surveillance
Locking the door to the server room is a good first step, but someone could break in, or someone who has authorized access could misuse that authority. You need a way to know who goes in and out and when. A log book for signing in and out is the most elemental way to accomplish this, but it has a lot of drawbacks. A person with malicious intent is likely to just bypass it.
A better solution than the log book is an authentication system incorporated into the locking devices, so that a smart card, token, or biometric scan is required to unlock the doors, and a record is made of the identity of each person who enters.
A video surveillance camera, placed in a location that makes it difficult to tamper with or disable (or even to find) but gives a good view of persons entering and leaving should supplement the log book or electronic access system. Surveillance cams can monitor continuously, or they can use motion detection technology to record only when someone is moving about. They can even be set up to send e-mail or cell phone notification if motion is detected when it shouldn't be (such as after hours).
#3: Make sure the most vulnerable devices are in that locked room
Remember, it's not just the servers you have to worry about. A hacker can plug a laptop into a hub and use sniffer software to capture data traveling across the network. Make sure that as many of your network devices as possible are in that locked room, or if they need to be in a different area, in a locked closet elsewhere in the building.
#4: Don't forget the workstations
Hackers can use any unsecured computer that's connected to the network to access or delete information that's important to your business. Workstations at unoccupied desks or in empty offices (such as those used by employees who are on vacation or have left the company and not yet been replaced) or at locations easily accessible to outsiders, such as the front receptionist's desk, are particularly vulnerable.
Disconnect and/or remove computers that aren't being used and/or lock the doors of empty offices, including those that are temporarily empty while an employee is at lunch or out sick. Equip computers that must remain in open areas, sometimes out of view of employees, with smart card or biometric readers so that it's more difficult for unauthorized persons to log on.
#5: Protect the portables
Laptops and handheld computers pose special physical security risks. A thief can easily steal the entire computer, including any data stored on its disk as well as network logon passwords that may be saved. If employees use laptops at their desks, they should take them with them when they leave or secure them to a permanent fixture with a cable lock, such as the one at PC Guardian.
Handhelds can be locked in a drawer or safe or just slipped into a pocket and carried on your person when you leave the area. Motion sensing alarms such as the one at SecurityKit.com are also available to alert you if your portable is moved.
For portables that contain sensitive information, full disk encryption, biometric readers, and software that "phones home" if the stolen laptop connects to the Internet can supplement physical precautions.
#6: Pack up the backups
Backing up important data is an essential element in disaster recovery, but don't forget that the information on those backup tapes, disks, or discs can be stolen and used by someone outside the company. Many IT administrators keep the backups next to the server in the server room. They should be locked in a drawer or safe at the very least. Ideally, a set of backups should be kept off site, and you must take care to ensure that they are secured in that offsite location.
Don't overlook the fact that some workers may back up their work on floppy disks, USB keys, or external hard disks. If this practice is allowed or encouraged, be sure to have policies requiring that the backups be locked up at all times.
#7: Disable the drives
If you don't want employees copying company information to removable media, you can disable or remove floppy drives, USB ports, and other means of connecting external drives. Simply disconnecting the cables may not deter technically savvy workers. Some organizations go so far as to fill ports with glue or other substances to permanently prevent their use, although there are software mechanisms that disallow it. Disk locks, such as the one at SecurityKit.com, can be inserted into floppy drives on those computers that still have them to lock out other diskettes.
#8: Protect your printers
You might not think about printers posing a security risk, but many of today's printers store document contents in their own on-board memories. If a hacker steals the printer and accesses that memory, he or she may be able to make copies of recently printed documents. Printers, like servers and workstations that store important information, should be located in secure locations and bolted down so nobody can walk off with them.
Also think about the physical security of documents that workers print out, especially extra copies or copies that don't print perfectly and may be just abandoned at the printer or thrown intact into the trash can where they can be retrieved. It's best to implement a policy of immediately shredding any unwanted printed documents, even those that don't contain confidential information. This establishes a habit and frees the end user of the responsibility for determining whether a document should be shredded.


Tuesday, October 7, 2014

BCS TIME TABLE (MORNING) - FOR APRIL 2015

Date
Subject(PGD)
27th Monday   9.00 a.m. – 10.30 a.m.
CSM
27th Monday   10.30 a.m. – 12.00 noon
MIS
28th Tuesday   9.00 a.m. – 10.30 a.m.
KBS
28th Tuesday   10.30 a.m. – 12.00 noon
RUID
28th Tuesday   1.30 p.m. – 3.30 p.m.
SE2
Date
Subject(Diploma)
29th Wednesday  9.00 a.m. – 10.30 a.m.
CORE
29th Wednesday  10.30 a.m. – 12.00 noon
ITPM
30th Thursday       9.00 a.m. – 10.30 a.m.
ITSM
30th Thursday       10.30 a.m. – 12.00 noon
PIT

BCS Class( EVENING) Time table for April 2015

Date
Subject(Diploma)
27th Monday    6.00 p.m. – 7.30 p.m.
CORE
27th Monday    7.30 p.m. – 9.00 p.m.
ITSM
28th Tuesday    6.00 p.m. – 7.30 p.m.
ITPM
28th Tuesday    7.30 p.m. - 9.00 p.m.
PIT
Date
Subject(PGD)
29th Wednesday  6.00  p.m. – 7.30 p.m.
CSM
29th Wednesday  7.30  p.m. – 9.00 p.m.
MIS
30th Thursday       6.00  p.m.- 7.30  p.m.
KBS
30th Thursday       7.30  p.m. – 9.00 p.m.
SE2


Monday, September 22, 2014

BCS/PGD/ITE/ REMOTE SENSING

  • LIDAR

LIDAR, which stands for Light Detection and Ranging, is a remote sensing method that uses light in the form of a pulsed laser to measure ranges (variable distances) to the Earth. These light pulses—combined with other data recorded by the airborne system— generate precise, three-dimensional information about the shape of the Earth and its surface characteristics.
A LIDAR instrument principally consists of a laser, a scanner, and a specialized GPS receiver. Airplanes and helicopters are the most commonly used platforms for acquiring LIDAR data over broad areas.
LIDAR systems allow scientists and mapping professionals to examine both natural and manmade environments with accuracy, precision, and flexibility. NOAA scientists are using LIDAR to produce more accurate shoreline maps, make digital elevation models for use in geographic information systems, to assist in emergency response operations, and in many other applications.

Extra Reading 

LIDAR (Light Detection and Ranging) is an optical remote sensing technology that measures properties of scattered light to find range and/or other information of a distant target.

LIDAR data is often collected by air, such as with this NOAA (National Oceanic and Atmospheric Administration) survey aircraft (top) over Bixby Bridge in Big Sur, Calif. Here, LIDAR data reveals a top-down (bottom left) and profile view of Bixby Bridge. NOAA scientists use LIDAR-generated products to examine both natural and manmade environments. LIDAR data supports activities such as inundation and storm surge modeling, hydrodynamic modeling, shoreline mapping, emergency response, hydrographical surveying, and coastal vulnerability analysis.

Radiometry & Photometry

An overview of the science of measuring light

Radiometry is the science of measuring light in any portion of the electromagnetic spectrum. In practice, the term is usually limited to the measurement of infrared, visible, and ultraviolet light using optical instruments. Irradiance is the intensity of light and is measured in watts per square meter.

Photometry is the science of measuring visible light in units that are weighted according to the sensitivity of the human eye. It is a quantitative science based on a statistical model of the human visual response to light - that is, our perception of light - under carefully controlled conditions. The photometric equivalent of Radiance is called Illuminance and is measured in Lumens per square meter (Lux)The human visual system responds to the light in the electromagnetic spectrum with wavelengths ranging from 380 to 770 nanometers (nm). We see light of different wavelengths as a continuum of colors ranging through the visible spectrum: 650 nm is red, 540 nm is green, 450 nm is blue, and so on.

Photographic interpretation is “the act of examining photographic images for the purpose of identifying objects and judging their significance” (Colwell, 1997). This mainly refers to its usage in military aerial reconnaissance using photographs taken from reconnaissance aircraft..

Thermal imaging is a method of improving visibility of objects in a dark environment by detecting the objects' infrared radiation and creating an image based on that information. 
Thermal imaging, near-infrared illumination, low-light imaging and are the three most commonly used night vision technologies. Unlike the other two methods, thermal imaging works in environments without any ambient light. Like near-infrared illumination, thermal imaging can penetrate obscurantist such as smoke, fog and haze.
Extra reading 
Here's a brief explanation of how thermal imaging works: All objects emit infrared energy (heat) as a function of their temperature. The infrared energy emitted by an object is known as its heat signature. In general, the hotter an object is, the more radiation it emits. A thermal imager (also known as a thermal camera) is essentially a heat sensor that is capable of detecting tiny differences in temperature. The device collects the infrared radiation from objects in the scene and creates an electronic image based on information about the temperature differences. Because objects are rarely precisely the same temperature as other objects around them, a thermal camera can detect them and they will appear as distinct in a thermal image. 

Thursday, August 28, 2014

BCS/DIP/ITPM/TUTORIAL 01

DEFINITION
A Project is a temporary endeavor undertaken to create a unique product, service or a result.

Project Management is about applying our knowledge, skills, tools and techniques to project activities to meet project requirements.

1.)    List and explain very briefly the four main criteria for assessing the success of a project.

Ø   
Ø   
Ø   
Ø   
2.)    For each of these factors above, describe at least TWO potential problems that might arise to jeopardize the eventual success of the project.




3.)    What is the purpose of a business Case ?



4.)    Describe the main sections to be found in a business case report.
a.        
b.       
c.        
d.       
e.       
f.         
5.)    Identify FOUR events which might lead to an updating of the business case.



6.)    What are the main project management Processes?
a.       Initiating Process: authorizing the project or phase
b.       Planning Process: define and verify requirements, objectives, goals and the way forward.
c.        Executing Process: coordinating people and other resources to carry out the plan
d.      Monitoring and  Controlling Process: measuring and monitoring progress regularly
e.       Closing Process: formalizing the completion of project

7.)    Define the word project Stakeholders?
Project stakeholders are individuals and organizations that are actively involved in the project, or whose interests may be affected as a result of project execution or completion.
Ø  Project Manager
Ø   Project Sponsor
Ø   Project team members
Ø   Project Steering committee
Ø  Customers
8.)    Identify the role and responsibility of each and every stakeholder in the above.










9.)    Nine knowledge Areas of Project Management.












10.)  Explain the project Development Life Cycle.














11.) Explain the advantages and disadvantages of In-house development, outsourcing and cloud-computing.

In-house development




Outsourcing




Cloud computing




Off-the-shelf packages






 Question A1
The Tyre-It Company sells and fits tyres from a number of different manufacturers to a wide variety of motor vehicles. This is a very competitive market and it is important that the company always has a ready stock of the most popular car tyre brands. It must also be able to answer immediately any telephone enquiry for the price and number of tyres of a specific type available at that time.
In addition, good management information and the strict control of costs are essential in order for the organisation to maintain its competitive position.
It has become clear that the existing computer-based stock system, which was developed by the in-house IT section, is no longer adequate and a decision has been made by the Tyre-It senior management to adopt a new more advanced stock recording and enquiry system.
Some major tyre manufacturers offer such systems as on off-the-shelf (OTS) package, but the Tyre-It management are concerned that such packages might be too restrictive and thus not suitable for the wide range of tyres that it sells. The alternative would be to design and develop a new in-house system. However, the IT section has no experience of on-line or cost-based systems.
                         
Write a memorandum to the Tyre-It management setting out the advantages and disadvantages of acquiring an ‘off-the-shelf’ system as opposed to developing a new application in-house using its own staff, bearing in mind the scenario outlines above

(15 marks)
                         
A decision has been made to acquire an off-the-shelf package. Describe the activities that would now be needed to select and acquire the software and to set up a fully operational stock system.

(10 marks)









 Question A3
a) Explain the main reasons for using:

i) change control and
ii) configuration management

when developing a new in-house computer system. Highlight at least TWO advantages and ONE disadvantage of each.
(12 marks)
b) List and explain briefly FIVE major stages in the change control process.
(7 marks)
c) List and explain briefly the THREE major elements of a configuration management system. (6 marks)



2011 –Sep
a) Costs and benefits are two essential sections within a business case. List FIVE other sections in a business case.(5 marks)

b) List FIVE categories or types of benefits that are associated with an IT project and provide an example for each one.(10 marks)

c) List FIVE estimating techniques that can be used to identify costs.(5 marks)

d) There are some projects that will be given approval even though the costs exceed the benefits in the business case. Describe ONE example of when this might be legitimate.(4 marks)

Question 1
a) Explain what is meant by a successful project, giving the four main criteria of success. (4 marks)

b) Identify and describe SIX of the major types of activity that would be carried out in a software development project, highlighting those in which the eventual users should be involved and explaining how.  (6 marks)

c) A large distribution company wishes to implement a new warehouse system, and is undecided whether to develop the system internally (i.e. an “in-house system”) or to acquire and adapt an “off-the-shelf” (OTS) package for this purpose.

For EACH of the six types of activity listed in part b, compare the work to be undertaken for each of these two possible methods of system development, highlighting the key differences.                 (12 marks)


d) Identify one significant risk specific to the “in-house” approach and one risk specific to the “OTS” approach. (3 marks)

BCS / DIP / PGD/ CORE /CSM / COMPUTER MISUSE ACT 1990

The Computer Misuse Act (1990)

Hacking has been around almost as long as the Internet; some people just love to try and break into a computer system.
The Computer Misuse Act of 1990 is a law in the United Kingdom that makes certain activities illegal, such as hacking into other people’s systems, misusing software, or helping a person to gain access to protected files of someone else's computer. So, in 1990, the Computer Misuse Act was passed.
The Computer Misuse Act (1990) recognised the following new offences:
  1. Unauthorised access to computer material
The first section in the act forbids a person to use someone else’s identification to access a computer, run a program, or obtain any data, even if no personal gain is involved in such access. Individuals also cannot change, copy, delete, or move a program. The Computer Misuse Act also outlaws any attempts to obtain someone else’s password. Obviously, if someone gives another person his identification and he may legally use the computer, these laws under unauthorized access do not apply.
  1. Unauthorised access with intent to commit or facilitate a crime
The second provision in the law is gaining access to a computer system in order to commit or facilitate a crime. An individual can’t use someone else’s system to send material that might be offensive or to start worms or viruses. He also can’t give someone his identification so that he can use a system for this purpose. This second part means that the individual would be facilitating someone else’s intent or crime.
  1. Unauthorised modification of computer material.
Unauthorized modification in the Computer Misuse Act means that a person can’t delete, change, or corrupt data. Again, if someone puts a virus into someone else’s system, he would be violating the act. Usually, committing unauthorized access only is thought a crime punishable by fine. Access with intent and unauthorized modification are considered more severe and may be punished by heavy fines and/or jail time.

3a. Making, supplying or obtaining anything which can be used in computer misuse offences.

Making: This includes the writing or creation of computer viruses, worms, trojans, malware, malicious scripts etc.
Supplying: This part covers the distribution of any of the above material whether you have created it yourself or obtained it from elsewhere. It is an offense to supply or distribute these files to others.
Obtaining: If you purposely obtain malicious files such as computer viruses or scripts that you know could be used to damage computer systems then you have committed an offence under the Computer Misuse Act.