Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users...

22
Chapter 15 Managing Information

Transcript of Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users...

Page 1: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Chapter 15

Managing Information

Page 2: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Agenda

• Chief Information Officer

• IS Department and End Users

• Control & Security

• Contingency Management

Page 3: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Chief Information Officer

• Align technology with business strategy

• Implement state-of-art solutions

• Provide and improve information access

Page 4: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Agenda

• Chief Information Officer

• IS Department and End Users

• Control & Security

• Contingency Management

Page 5: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

IS Department and End Users

• Let them sink or swim (do nothing or educating)

• Use the stick (policies and procedures)– Steering committee

• Use carrot ( incentives)• Offer support

– Information center– Help desk

Page 6: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Agenda

• Chief Information Officer

• IS Department and End Users

• Control & Security

• Contingency Management

Page 7: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Control and Security

• Logical control

• Physical control

• Data control

• Communication control

• Administration control

• Application control

Page 8: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Physical Control

• Location (traffic)

• Security (lock)

• Environmental (air)

• Fire

• Power

Page 9: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Logical Control

• Photo

• Fingerprints

• Voice

• Eye

• Signature

• Password

Page 10: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Data Control

• Minimal privilege

• Minimal exposure

Page 11: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Communication Control

• Firewall

• Decryption

• Encryption

• Private & public key

Page 12: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Administrative Control

• Policy

• Procedure

• Hardware

• Software

• Employee

• Data

Page 13: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Application Control

• Input control

• Processing control

• Output control

Page 14: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Agenda

• Chief Information Officer

• IS Department and End Users

• Control & Security

• Contingency Management

Page 15: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Contingency Mgmt

• NOT disaster recovery– Reactive, not proactive

• Worst case scenario– All our eggs in one basket– Natural disaster– Human error / sabotage

Page 16: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Contingency Mgmt. Methods

• Disaster Recovery firm– Outsource strategic function?

• Off-line storage

• Data redundancy– Replicated databases– Fragmented databases

Page 17: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Contingency Methods

• Back-up power generators

• “What if” scenarios– Military war games

• Scaled-down manual system

• Back-up / recovery procedures

Page 18: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Contingency Methods

• Parallel systems

• Processing backup facility– Cold, warm, hot site

Page 19: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Cardinal Health• Redundant systems for critical order

processing

• Redundant WAN trunks

• System data backed up daily– Backup media kept off-site

• Backup replica site– Different part of country– Switched on within 30 minutes

Page 20: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Points to Remember

• Chief Information Officer

• IS Department and End Users

• Control & Security

• Contingency Management

Page 21: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Discussion Questions

• What types of control do you have implemented in your organization?

• Tell us a Contingency Management war story– What happened?– How did the firm recover?– How could the situation have been

• Averted?• Mitigated?

Page 22: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management.

Assignment

• Review chapters 8-14

• Exam 2

• Group assignment

• Research paper & presentation