1.1 TYPES OF BUSINESS ORGANISATIONS.
Forms of Business Organization
From a legal point of view, there are four types of businesses:
- Sole proprietorships;
- Partnerships;
- Corporations; and
- Co-operatives.
A brief description of each type is followed by a summary of their advantages and disadvantages.
Sole Proprietorships
This is the simplest way to set up a business. A sole proprietor is fully responsible for all debts and obligations related to his or her business. A creditor with a claim against a sole proprietor has a right against all of his or her assets, whether business or personal. This is known as unlimited liability.
This type of business comes under provincial jurisdiction. If the proprietor chooses to carry on a business under a name other than his/her own, he/she must register with the province. Your business name registration, or renewal of registration, will be valid for a certain number of years. If a sole proprietor establishes a business in his/her own name, without adding any other words, it is not necessary to register the business.
Partnerships
A partnership is an agreement in which two or more persons combine their resources in a business. In order to establish the terms of the business and to protect partners/shareholders in the event of disagreement or dissolution of the business, a partnership/shareholders agreement should be drawn up with the assistance of a lawyer. Partners share in the profits according to the terms of their agreement.
General Partnership
All members share the management of the business and each is personally liable for all the debts and obligations of the business. This means that each partner is responsible for and must assume the consequences of the actions of the other partner(s).
Limited Partnership
Some members are general partners who control and manage the business and may be entitled to a greater share of the profits, while other partners are limited and contribute only capital. Limited partners take no part in control or management and are liable for debts to a specified extent only. A legal document, outlining specific requirements, must be drawn up for a limited partnership.
Corporations
A corporation is a legal entity that is separate from its owners, the shareholders. No shareholder of a corporation is personally liable for the debts, obligations or acts of the corporation. This type of business can be incorporated at either the federal or provincial level.
A corporation is identified by the terms “Limited”, “Ltd.”, “Incorporated”, “Inc.”, “Corporation”, or “Corp.”. Whatever the term, it must appear with the corporate name on all documents, stationery, and so on, as it appears on the incorporation document.
Private Corporation
A private corporation can be formed by one or more people. A majority of its directors must be Canadian residents. If none of the directors reside in the province in which it does business, the corporation must appoint a Power of Attorney who reside in the province. A private corporation cannot sell shares or securities to the general public.
Public Corporation
A “public corporation” is one that issues securities for public distribution. Besides filing incorporation documents, a public corporation must file a prospectus with the appropriate Securities Commission in the province, must employ outside auditors and must distribute semi-annual financial statements.
Cooperatives
A co-operative is a corporation organized and controlled by its members, who pool resources to provide themselves and their patrons with goods, services, or other benefits. A cooperative business structure provides:
- democratic control based on one member one vote;
- open and voluntary membership;
- patronage dividends.
ADVANTAGES AND DISADVANTAGES OF EACH FORM OF BUSINESS ORGANIZATION
Sole Proprietorship
|
Advantages · relatively low start-up costs; · greatest freedom from regulation; · owner in direct control of decision making; · minimal working capital required; · tax advantages to owner; · all profits to owner. |
Disadvantages · unlimited liability; · lack of continuity in business organization in absence of owner; · difficulty raising capital. |
Partnership
|
Advantages · ease of formation; · relatively low start-up costs; · additional sources of investment capital; · possible tax advantages; · limited regulation; · broader management base. |
Disadvantages · unlimited liability; · lack of continuity; · divided authority; · difficulty raising additional capital; · hard to find suitable partners; · possible development of conflict between partners. |
Corporation
|
Advantages · limited liability; · specialized management; · ownership is transferable; · continuous existence; · separate legal entity; · possible tax advantage; · easier to raise capital. |
Disadvantages · closely regulated; · most expensive form to organize; · charter restrictions; · extensive record keeping necessary; · double taxation of dividends; · possible development of conflict between shareholders and executives. |
Co-operatives
|
Advantages · owned and controlled by members; · democratic control (i.e. one member, one vote); · limited liability; · profit distribution (surplus earnings) to members in proportion to use of service; surplus may be allocated in shares or cash. |
Disadvantages · possibility development of conflict between members; · longer decision-making process; · participation of members required for success; · extensive record keeping necessary; · less incentive to invest additional capital. |
1.2 Common objectives within which businesses operate.
Increase Market Share
In order to grow a business needs to increase their share of competitive markets. Marketing plans start with the overall strategic business plan of a company, but explain further how specific aims will be carried out. Marketing plans address this through defining product or service offerings, researching target markets, analysis of competition, then strategically placing, pricing and promoting the company offering.
Strengthening Financial Resources
Included in the growth objectives of an organization is the availability of capital resources to invest in future expansion projects. If a company’s financial resources are strong, capital could conceivably come from cash reserves. For many organizations, strengthening financial resources means to build cash flow or increase assets in order to attract investors and court creditors to fund expansion.
Physical Resources
To companies that produce tangible products, physical resources could mean the plant, machinery and other equipment integral to producing a product. Service businesses could define physical resources as office space or computer equipment to enhance customer service and other business processes. In either respect, the goal of increasing physical resources deals with using equipment or machinery to better produce a product, or offer a service.
Productivity
Productivity for any organization means fine tuning a business process to achieve the best result for a customer while increasing profit. A manufacturing organization that fine tunes a process could reduce waste, reduce production time, and in the end, make a better product that gets to the customer faster. A service business that changes the way customers are handled can decrease call times and increase customer satisfaction and loyalty.
Innovation
Innovation is a goal that helps a business stay ahead of the competition. Placing resources into research and development to create a new product, or into offering a better service, can pay dividends by entering a new and unique product or service into the marketplace.
Action Planning
A business cannot move forward without defining specific action steps to take them toward their goals and identified business objectives. Action planning involves identifying the top objectives for an organization, then developing SMART goals — goals are specific, measurable, achievable, realistic and timely. By setting and meeting SMART goals, an organization will meet specific business objectives along the way.
1.3 Environment within which businesses operate..
Business Environment
Environment refers to all external forces, which have a bearing on the functioning of business. Environment factors “are largely if not totally, external and beyond the control of individual industrial enterprises and their managements. The business environment poses threats to a firm or offers immense opportunities for potential market exploitation. Environmental business solutions will give way to the environmental business opportunities.
- Internal environment
Internal environment includes all those factors which influence business and which are present within the business itself. These factors are usually under the control of business. The study of internal factors is really important for the study of internal environment. These factors are:
(i) Objectives of Business, (ii) Policies of Business, (iii) Production Capacity, (iv) Production Methods, (v) Management Information System, (vi) Participation in Management, (vii) Composition of Board of Directors, (viii) Managerial Attitude, (ix) Organisational Structure, (x) Features of Human Resource, etc.
Note:
All the above factors do influence the decisions of business, but since all these factors are usually under the control of business, they cannot be wholly included in the business environment.
- External Environment
External environment includes all those factors which influence business and exist outside the business. Business has no control over these factors. The information about these factors is important for the study of the external environment.
Some of these factors are those with which a particular company has very close relationship. However, there are some other factors which influence the entire business community.
Micro environment means that environment which includes those factors with which business is closely related. These factors influence every industrial unit differently. These factors are as under:
(i) Customers (ii) Suppliers (iii) Competitors (iv) Public (v) Marketing Intermediaries.
(i) Customers:
Customers of an industrial unit can be of different types. They include household, government, industry, commercial enterprises, etc. The number of different types of customers highly influences a firm.
For example, suppose a firm supplies goods only to the government. It means that firm has only one customer. If because of some reason their relations get soured, the supply of goods will stop and in that case the closure of that firm is certain.
This clearly indicates that the customers do influence business. Therefore, a firm should make efforts to have different kinds of customers,
(ii) Suppliers:
Like the customers, the suppliers also influence business. If a business has only one supplier and he gets annoyed because of some reason, the supply of goods can be stopped and the very existence of the business can be threatened or endangered. Hence, efforts should be made to have various suppliers.
(iii) Competitors:
The competing firms can influence business in a number of ways. They can do so by bringing new and cheap products in the market, by launching some sale promotion scheme or other similar methods.
(iv) Public:
Public has different constituents like the local public, press or media, etc. The attitude or behaviour of these constituents can affect business units. For example, the local population can oppose some established firm whose business is excessively noisy.
Similarly, if the media gives some favourable report about a particular company the price of its share can register an increase on this count.
(v) Marketing Intermediaries:
The marketing intermediaries play a significant role in developing any business unit. They are those persons who reduce the distance between the producers and agents.
For example, a company sells its goods with the help of agents and if because of some reason all the agents get annoyed with the company and refuse to sell its goods, there can be a crisis for the company.
Types of Business Environment
Environment includes such factors as socio-economic, technological, supplier, competitor and the government. There are two more factors, which exercise considerable influence on business. They are physical or natural environment and global environment.
Technological Environment
Technology is understood as the systematic application of scientific or other organized knowledge to practical tasks. Technology changes fast and to keep pace with it, businessmen should be ever alert to adopt changed technology in their businesses.
Economic Environment
There is close relationship between business and its economic environment.
Business obtains all its needed inputs from the economic environment and it absorbs the output of business units.
Political Environment
It refers to the influence exerted by the three political institutions viz., legislature executive and the judiciary in shaping, directing, developing and controlling business activities. A stable and dynamic political environment is indispensable for business growth.
Natural Environment
Business, an economic pursuit of man, continues to be dictated by nature. To what extend business depends on nature and what is the relationship between the two constitutes an interesting study.
Global or international Environment
Thanks to liberalization, Indian companies are forces to view business issues from a global perspective. Business responses and managerial practices must be fine-tuned to survive in the global environment.
Social and culture Environment
It refers to people’s attitude to work and wealth; role of family, marriage,
religion and education; ethical issues and social responsiveness of business.
|
Self-check |
|||
|
|
|||
|
OUTCOME |
Yes |
No |
I Need help |
|
· 1. The description distinguishes types of business organisations. |
|
|
|
|
· 2. The description outlines the common objectives within which businesses operate. |
|
|
|
|
SPECIFIC OUTCOME 2 : Describe systems theory with respect to information systems. |
|
ASSESEMENT CRITERIA |
|
v 1. The description defines the concept of a system. v 2. The description identifies theoretical components of a system. v 3. The description distinguishes types of information systems. |
2.1 Describe systems theory with respect to information systems.
Systems work is not as hard as you might think. However, we have a tendency in this business to complicate things by changing the vocabulary of systems work and introducing convoluted concepts and techniques, all of which makes it difficult to produce systems in a consistent manner. Consequently, there is a tendency to reinvent the wheel with each systems development project.
THERE ARE THREE INHERENT PROPERTIES TO ANY SYSTEM
Regardless of the type of system, be it an irrigation system, a communications relay system, an information system, or whatever, all systems have three basic properties:
- A system has a purpose– such as to distribute water to plant life, bouncing a communications signal around the country to consumers, or producing information for people to use in conducting business.
- A system is a grouping of two or more components which are held together through some common and cohesive bond.The bond may be water as in the irrigation system, a microwave signal as used in communications, or, as we will see, data in an information system.
- A system operates routinelyand, as such, it is predictable in terms of how it works and what it will produce.
All systems embrace these simple properties. Without any one of them, it is, by definition, not a system.
For our purposes, the remainder of this paper will focus on “information systems” as this is what we are normally trying to produce for business. In other words, the development of an orderly arrangement or grouping of components dedicated to producing information to support the actions and decisions of a particular business. Information Systems are used to pay employees, manage finances, manufacture products, monitor and control production, forecast trends, process customer orders, etc.
If the intent of the system is to produce information, we should have a good understanding of what it is…
- INFORMATION = DATA + PROCESSING
Information is not synonymous with data. Data is the raw material needed to produce information. Data by itself is meaningless. It is simply a single element used to identify, describe or quantify an object used in a business, such as a product, an order, an employee, a purchase, a shipment, etc. A data element can also be generated based on a formula as used in a calculation; for example:
Net-Pay = Gross-Pay – FICA – Insurance – City-Tax – Union-Dues – (etc.)
Only when data is presented in a specific arrangement for use by the human being does it become information. If the human being cannot act on it or base a decision from it, it is nothing more than raw data. This implies data is stored, and information is produced. It is also dependent on the wants and needs of the human being (the consumer of information). Information, therefore, can be defined as “the intelligence or insight gained from the processing and/or analysis of data.”
The other variable in our formula is “processing” which specifies how data is to be collected, as well as its retrieval in order to produce information. This is ultimately driven by when the human being needs to make certain actions and decisions. Information is not always needed “upon request” (aka “on demand”); sometimes it is needed once daily, weekly, monthly, quarterly, annually, etc. These timing nuances will ultimately dictate how data is collected, stored, and retrieved. To illustrate, assume we collect data once a week. No matter how many times during the week we make a query of the data base, the data will only be valid as of the last weekly update. In other words, we will see the same results every day for one week. However, if we were to collect the data more frequently, such as periodically throughout the day, our query will produce different results throughout the week.
Our formula of “I = D + P” makes an important point: if the data is changed, yet the processing remains the same, the information will change. Conversely, if the data remains the same, yet the processing changes, the information will also change. This leads to a compelling argument to manage data and processing as separate by equal resources which can be manipulated and reused to produce information as needed.
- SYSTEMS ARE LOGICAL IN NATURE AND CAN BE PHYSICALLY IMPLEMENTED MANY DIFFERENT WAYS
An information system is a collection of processes (aka, “sub-systems”) to either collect and store data, to retrieve data and produce information, or a combination of both. The cohesive bond between these components is the data which should be shared and reused throughout the system (as well as other systems). You will observe we have not yet discussed the most suitable way to physically implement the processes, such as through the use of manual processes, computer programs, or other office technology. In other words, at this stage, the sub-systems of the system simply define logically WHAT data must be processed, WHEN it must be processed, and who will consume the information (aka “end-users”), but it most definitely does not specify HOW the sub-system is to be implemented.
Following this, developers determine a suitable approach for physically implementing each sub-system. This decision should ultimately be based on practicality and cost effectiveness. Sub-systems can be implemented using manual procedures, computer procedures (software), office automation procedures, or combinations of all three. Depending on the complexity of the sub-system, several procedures may be involved. Regardless of the procedures selected, developers must establish the precedent relationships in the execution of the procedures, either sequentially, iteratively, of choice (thereby allowing divergent paths). By defining the procedures in this manner, from start to end, the developers are defining the “work flow” of the sub-system, which specifies HOW the data will be physically processed (including how it is to be created, updated, or referenced).
Defining information systems logically is beneficial for two reasons:
- It provides for the consideration of alternative physical implementations. How one developer designs it may very well be different than the next developer. It also provides the means to effectively determine how a purchased software package may satisfy the needs. Again, the decision to select a specific implementation should be based on practicality and cost justification.
- It provides independence from physical equipment, thereby simplifying the migration to a new computer platform. It also opens the door for system portability, for example; our consulting firm helped a large Fortune 500 conglomerate design a single logical payroll system which was implemented on at least three different computer platforms as used by their various operating units; although they physically worked differently, it was all the same basic system producing the same information.
These logical and physical considerations leads to our final concept…
- A SYSTEM IS A PRODUCT THAT CAN BE ENGINEERED AND MANUFACTURED LIKE ANY OTHER PRODUCT.
An information system can be depicted as a four level hierarchy (aka, “standard system structure”):
LEVEL 1 – System
LEVEL 2 – Sub-systems (aka “business processes”) – 2 or more
LEVEL 3 – Procedures (manual, computer, office automation) – 1 or more for each sub-system
LEVEL 4 – Programs (for computer procedures), and Steps (for all others) – 1 or more for each procedure
Each level represents a different level of abstraction of the system, from general to specific (aka, “Stepwise Refinement” as found in blueprinting). This means design is a top-down effort. As designers move down the hierarchy, they finalize design decisions. So much so, by the time they finish designing Level 4 for a computer procedure, they should be ready to write program source code based on thorough specifications, thereby taking the guesswork out of programming.
The hierarchical structure of an information system is essentially no different than any other common product; to illustrate:
LEVEL 1 – Product
LEVEL 2 – Assembly – 2 or more
LEVEL 3 – Sub-assembly – 1 or more for each assembly
LEVEL 4 – Operation – 1 or more for each sub-assembly
Again, the product is designed top-down and assembled bottom-up (as found in assembly lines). This process is commonly referred to as design by “explosion” (top-down), and implementation by “implosion” (bottom-up). An information system is no different in that it is designed top-down, and tested and installed bottom-up. In engineering terms, this concept of a system/product is commonly referred to as a “four level bill of materials” where the various components of the system/product are defined and related to each other in various levels of abstraction (from general to specific).
This approach also suggests parallel development. After the system has been designed into sub-systems, separate teams of developers can independently design the sub-systems into procedures, programs, and steps. This is made possible by the fact that all of the data requirements were identified as the system was logically subdivided into sub-systems. Data is the cohesive bond that holds the system together. From an engineering/manufacturing perspective it is the “parts” used in the “product.” As such, management of the data should be relegated to a separate group of people to control in the same manner as a “materials management” function (inventory) in a manufacturing company. This is commonly referred to as “data resource management.”
This process allows parallel development, which is a more effective use of human resources on project work as opposed to the bottleneck of a sequential development process. Whole sections of the system (sub-systems) can be tested and delivered before others, and, because data is being managed separately, we have the assurance it will all fit together cohesively in the end.
The standard system structure is also useful from a Project Management perspective. First, it is used to determine the Work Breakdown Structure (WBS) for a project complete with precedent relationships. The project network is then used to estimate and schedule the project in part and in full. For example, each sub-system can be separately priced and scheduled, thereby giving the project sponsors the ability to pick and chose which parts of the system they want early in the project.
The standard system structure also simplifies implementing modification/improvements to the system. Instead of redesigning and reconstructing whole systems, sections of the system hierarchy can be identified and redesigned, thereby saving considerable time and money.
This analogy between a system and a product is highly credible and truly remarkable. Here we can take a time-proven concept derived from engineering and manufacturing and apply it to the design and development of something much less tangible, namely, information systems.
Types of information systems.
Transaction Processing System (TPS), Knowledge Work System (KWS), Management Information Systems(MIS), Decision Support Systems(DSS), Management/Executive Support Systems(ESS) (any three types)
|
Self-check |
|||
|
|
|||
|
OUTCOME |
Yes |
No |
I Need help |
|
· 1. The description defines the concept of a system. |
|
|
|
|
· 2. The description identifies theoretical components of a system. |
|
|
|
|
3. The description distinguishes types of information systems. |
|
|
|
|
SPECIFIC OUTCOME 3: Explain how IT can be used in business. |
|
ASSESEMENT CRITERIA |
|
v 1. The explanation identifies the purpose of computer applications in business. v 2. The explanation outlines the functions of computer applications in business. v 3. The explanation illustrates the effects of IT on business systems. |
3.1 The purpose of computers in business
General
- The business use of computers depends on the organization. Many businesses use computers for creating and processing letters, reports, spreadsheets, presentations and other documents. Computers offer an effective tool for organizing and managing customer records and contacts. For a small business, a single computer, with a few software programs, provides sufficient computing power.
Firms with numerous employees, and large volumes of transactions, require faster computers that are more powerful and a wide range of software. Companies that have two or more computers, or a computer network, enable staff to share files or make changes to records. A network also allows authorized staff and other parties, such as customers or vendors, to gain access to the system.
Business Intelligence
- One of the most common uses of computers in business involves the accumulation of data about customers and clients for analysis. This technique entails developing a database to record, manage, retrieve or manipulate information. Most individuals associate this type of use with the marketing or sales function of businesses, but it also invlves using the data to construct predictive models.
Inventory Management
- Large, mid-size and small companies employ computers for inventory control and management. This includes the functions of manufacturing, warehousing, sales, orders and delivery. Computerized activities include recording incoming goods, details on items, distribution inventory and storage information. Generally, small retail operations rely on basic inventory management software to handle this area of the business. Many large enterprises whose normal operations require huge volumes of raw materials for manufacturing, or the distribution of significant quantities of goods, have highly sophisticated computerized inventory management applications at the core of their operations.
Enterprise Resource Planning
- Enterprise Resource Planning or ERP consist of implementing a comprehensive administrative software system that merges or replaces single software applications. ERP software contains modules for each business function, such as purchasing, accounting, payroll, human resources, inventory management and other aspects of an organization. Many large business organizations have executed ERP strategies to gain from the assimilation of information and department functions under a single umbrella.
Misconceptions
- Although companies receive many benefits from computers, a big misconception is that they are unreliable and unable to provide consistent results. Training employees to properly manage company software and back up essential information can limit these fears of computerized workplaces.
Internet
- Utilizing the Internet is a great aspect of computers in the workplace. Not only can companies reach customers through websites, they can also use company intranets to connect all company locations via computer software.
Explain the effects of IT on business systems
____________________________________________________________________________________________________________________________________
|
Self-check |
|||
|
|
|||
|
OUTCOME |
Yes |
No |
I Need help |
|
· 1. The explanation identifies the purpose of computer applications in business. |
|
|
|
|
· 2. The explanation outlines the functions of computer applications in business. |
|
|
|
|
· 3. The explanation illustrates the effects of IT on business systems. |
|
|
|
|
SPECIFIC OUTCOME 4: Explain the relationship between a business and its information needs. |
|
ASSESEMENT CRITERIA |
|
v 1. The explanation distinguishes data and information. v 2. The explanation outlines the role of information in decision making. v 3. The explanation identifies the main threats to data security and integrity. v 4. The explanation identifies the sub-systems that make up a business and the information needs associated with each sub-system. |
4.1 Data and information.
People often miss the subtle difference between data and information and use the words interchangeably.
Comparison chart
|
|
Data |
Information |
|
Meaning |
Data is raw, unorganized facts that need to be processed. Data can be something simple and seemingly random and useless until it is organized. |
When data is processed, organized, structured or presented in a given context so as to make it useful, it is called Information. |
|
Example |
Each student’s test score is one piece of data |
The class’ average score or the school’s average score is the information that can be concluded from the given data. |
|
Definition |
Latin ‘datum’ meaning “that which is given”. Data was the plural form of datum singular (M150 adopts the general use of data as singular. Not everyone agrees.) |
Information is in |
Data
- Facts, statistics used for reference or analysis.
- Numbers, characters, symbols, images etc., which can be processed by a computer.
- Data must be interpreted, by a human or machine, to derive meaning
- “Data is a representation of information” *
- Latin ‘datum’ meaning “that which is given”
- Data plural, datum singular (M150 adopts the general use of data as singular. Not everyone agrees.)
Information
- Knowledge derived from study, experience (by the senses), or instruction.
- Communication of intelligence.
- “Information is any kind of knowledge that is exchangeable amongst people, about things, facts, concepts, etc., in some context.” *
- “Information is interpreted data” *
4.2 Role of information in decision making
Management information systems can help you make valid decisions by providing accurate and up-to-date information and performing analytic functions. You have to make sure the management information system you choose can work with the information formats available in your company and has the features you need. Suitable management information systems can structure the basic data available from your company operations and records into reports to present you with guidance for your decisions.
Information
When you base your decisions on data available from management information systems, they reflect information that comes from the operations of your company. Management information systems take data generated by the working level and organize it into useful formats. Management information systems typically contain sales figures, expenses, investments and workforce data. If you need to know how much profit your company has made each year for the past five years to make a decision, management information systems can provide accurate reports giving you that information.
Scenarios
The capability to run scenarios is a key decision-making tool. Some management information systems have this feature built in, while others can provide the information required for running scenarios on other applications, such as spreadsheets. Your decision is influenced by what happens if you decide a certain way. What-if scenarios show you how different variables change when you make a decision. You can enter reduced staff levels or increased promotion budgets and see what happens to revenue, expenses and profit for different levels of cuts or increases. Management information systems systems play a critical role in making realistic scenarios possible.
Projections
Any decisions you make result in changes in the projected company results and may require modifications to your business strategy and overall goals. Management information systems either have trend analysis built in or can provide information that lets you carry out such an analysis. Typical business strategies include projections for all fundamental operating results. A trend analysis allows you to show what these results would be in the current situation and how they will change once you have implemented the decisions you have taken. The new values form the basis of your strategic approach going forward.
Implementation
While you make your decisions with specific goals in mind and have the documentation from management information systems and trend analysis to support your expectations, you have to track company results to make sure they develop as planned. Management information systems give you the data you need to determine whether your decisions have had the desired effect, or whether you have to take corrective action to reach your goals. If specific results are not on track, you can use management information systems to evaluate the situation and decide to take additional measures if necessary.
4.3 Data security and integrity.
Refers to the validity of data. Data integrity can be compromised in a number of ways:
- Human errors when data is entered
- Errors that occur when data is transmitted from one computer to another
- Software bugs or viruses
- Hardware malfunctions, such as disk crashes
- Natural disasters, such as fires and floods
Threats to Computer Security
Computer systems are vulnerable to many threats that can inflict various types of damage resulting in significant losses. This damage can range from errors harming database integrity to fires destroying entire computer centers. Losses can stem, for example, from the actions of supposedly trusted employees defrauding a system, from outside hackers, or from careless data entry clerks. Precision in estimating computer security-related losses is not possible because many losses are never discovered, and others are “swept under the carpet” to avoid unfavorable publicity. The effects of various threats varies considerably: some affect the confidentiality or integrity of data while others affect the availability of a system.
- Errors and Omissions
Errors and omissions are an important threat to data and system integrity. These errors are caused not only by data entry clerks processing hundreds of transactions per day, but also by all types of users who create and edit data. Many programs, especially those designed by users for personal computers, lack quality control measures. However, even the most sophisticated programs cannot detect all types of input errors or omissions. A sound awareness and training program can help an organization reduce the number and severity of errors and omissions.
Users, data entry clerks, system operators, and programmers frequently make errors that contribute directly or indirectly to security problems. In some cases, the error is the threat, such as a data entry error or a programming error that crashes a system. In other cases, the errors create vulnerabilities. Errors can occur during all phases of the systems life cycle.
- Fraud and Theft
Computer systems can be exploited for both fraud and theft both by “automating” traditional methods of fraud and by using new methods. For example, individuals may use a computer to skim small amounts of money from a large number of financial accounts, assuming that small discrepancies may not be investigated. Financial systems are not the only ones at risk. Systems that control access to any resource are targets (e.g., time and attendance systems, inventory systems, school grading systems, and long-distance telephone systems). Computer fraud and theft can be committed by insiders or outsiders. Insiders (i.e., authorized users of a system) are responsible for the majority of fraud.
Since insiders have both access to and familiarity with the victim computer system (including what resources it controls and its flaws), authorized system users are in a better position to commit crimes. Insiders can be both general users (such as clerks) or technical staff members. An organization’s former employees, with their knowledge of an organization’s operations, may also pose a threat, particularly if their access is not terminated promptly.
- Employee Sabotage
Employees are most familiar with their employer’s computers and applications, including knowing what actions might cause the most damage, mischief, or sabotage. The downsizing of organizations in both the public and private sectors has created a group of individuals with organizational knowledge, who may retain potential system access (e.g., if system accounts are not deleted in a timely manner). The number of incidents of employee sabotage is believed to be much smaller than the instances of theft, but the cost of such incidents can be quite high.
Common examples of computer-related employee sabotage include:
- destroying hardware or facilities,
- planting logic bombs that destroy
- programs or data,
- entering data incorrectly,
- “crashing” systems,
- deleting data,
- holding data hostage, and
- changing data.
- Loss of Physical and Infrastructure Support
The loss of supporting infrastructure includes power failures (outages, spikes, and brownouts), loss of communications, water outages and leaks, sewer problems, lack of transportation services, fire, flood, civil unrest, and strikes.
- Malicious Hackers
The term malicious hackers, sometimes called crackers, refers to those who break into computers without authorization. They can include both outsiders and insiders. Much of the rise of hacker activity is often attributed to increases in connectivity in both government and industry. One 1992 study of a particular Internet site (i.e., one computer system) found that hackers attempted to break in at least once every other day. The hacker threat should be considered in terms of past and potential future damage. Although current losses due to hacker attacks are significantly smaller than losses due to insider theft and sabotage, the hacker problem is widespread and serious.
- Industrial Espionage
Industrial espionage is the act of gathering proprietary data from private companies or the government for the purpose of aiding another company(ies). Industrial espionage can be perpetrated either by companies seeking to improve their competitive advantage or by governments seeking to aid their domestic industries. Foreign industrial espionage carried out by a government is often referred to as economic espionage. Since information is processed and stored on computer systems, computer security can help protect against such threats; it can do little, however, to reduce the threat of authorized employees selling that information.
- Malicious Code
Malicious code refers to viruses, worms, Trojan horses, logic bombs, and other “uninvited” software. Sometimes mistakenly associated only with personal computers, malicious code can attack other platforms. Actual costs attributed to the presence of malicious code have resulted primarily from system outages and staff time involved in repairing the systems. Nonetheless, these costs can be significant.
Malicious Software: A Few Key Terms
Virus: A code segment that replicates by attaching copies of itself to existing executables. The new copy of the virus is executed when a user executes the new host program. The virus may include an additional “payload” that triggers when specific conditions are met. For example, some viruses display a text string on a particular date. There are many types of viruses, including variants, overwriting, resident, stealth, and polymorphic.
Trojan Horse: A program that performs a desired task, but that also includes unexpected (and undesirable) functions. Consider as an example an editing program for a multiuser system. This program could be modified to randomly delete one of the users’ files each time they perform a useful function (editing), but the deletions are unexpected and definitely undesired!
Worm: A self-replicating program that is self-contained and does not require a host program. The program creates a copy of itself and causes it to execute; no user intervention is required. Worms commonly use network services to propagate to other host systems.
- Threats to Personal Privacy
The accumulation of vast amounts of electronic information about individuals by governments, credit bureaus, and private companies, combined with the ability of computers to monitor, process, and aggregate large amounts of information about individuals have created a threat to individual privacy. The possibility that all of this information and technology may be able to be linked together has arisen as a specter of the modern information age.
4.4 sub-systems that make up a business and the information needs associated with each sub-system.
The Systems View
This idea of looking outward, of looking beyond the walls of the company office building is not new. What is relatively new to many executives, is the idea of looking at the world as a collection of systems that create a whole and examining the relationships between those systems to determine how they affect the whole. Systems Theory, as applied to organizational management, puts forth the premise that all organizations are systems, and all systems are part of larger systems. How a subsystem fits the needs of the larger system ultimately determines if that subsystem prospers or is left to wither on the vine.
It’s this concept that the adept leader can use to get a more “holistic” view of his organization. Understanding how the company relates to the larger system in which it exists and operates, and then how the company’s internal systems contribute or detract from that larger relationship can provide a more relevant analysis.
It really isn’t as esoteric as it may sound. Once you grasp the concept it will be easy to see how it applies to your organization. Let’s spend a moment on a definition and then we can address application.
In Systems Theory, a system is defined in two ways:
- Externally, by its purpose. Each system has a role that it plays in the higher-level system in which it exists. Using the auto company example we can say that the auto company is a system whose role is to provide cars to the next higher-level system, the auto market. The auto market in turn has its multiple roles that it plays in the next higher-level systems of transportation and national economy and so on.
- Internally, by its subsystems and internal functions. Each system is made up of components and sub-systems that interrelate and contribute to the overall purpose of the parent system. In the auto company those components might consist of engineering, production, marketing, finance, human resources and sales all of which should be supporting the system’s purpose of providing cars to the higher system, the auto market.
Systems Theory in Managing Organizations
Defining the Higher-Level System and the Organization’s Role in It
So for a leader, the first step in developing a holistic view of the organization is to define the higher-level system in which it exists/operates, and its role/purpose in that higher-level system. Where does it fit? What kind of role does it play and what value does it bring to the purpose of the higher-level system? If a company does not have a role to play in the higher-level system, then it does not belong in that system; and if it cannot find a role in any higher-level system, it is in effect redundant and will ultimately die. Additionally, and sadly more common, if a company cannot accurately define what its role is in the higher-level system, even if it has something relevant to offer, it will be treated as if it had no role at all
|
Self-check |
|||
|
|
|||
|
OUTCOME |
Yes |
No |
I Need help |
|
· 1. The explanation distinguishes data and information. |
|
|
|
|
· 2. The explanation outlines the role of information in decision making. |
|
|
|
|
· 3. The explanation identifies the main threats to data security and integrity. |
|
|
|