chapter 15 managing information. agenda chief information officer is department and end users...

22
Chapter 15 Managing Information

Upload: anabel-kelley

Post on 19-Jan-2016

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Chapter 15

Managing Information

Page 2: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Agenda

• Chief Information Officer

• IS Department and End Users

• Control & Security

• Contingency Management

Page 3: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Chief Information Officer

• Align technology with business strategy

• Implement state-of-art solutions

• Provide and improve information access

Page 4: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Agenda

• Chief Information Officer

• IS Department and End Users

• Control & Security

• Contingency Management

Page 5: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

IS Department and End Users

• Let them sink or swim (do nothing or educating)

• Use the stick (policies and procedures)– Steering committee

• Use carrot ( incentives)• Offer support

– Information center– Help desk

Page 6: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Agenda

• Chief Information Officer

• IS Department and End Users

• Control & Security

• Contingency Management

Page 7: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Control and Security

• Logical control

• Physical control

• Data control

• Communication control

• Administration control

• Application control

Page 8: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Physical Control

• Location (traffic)

• Security (lock)

• Environmental (air)

• Fire

• Power

Page 9: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Logical Control

• Photo

• Fingerprints

• Voice

• Eye

• Signature

• Password

Page 10: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Data Control

• Minimal privilege

• Minimal exposure

Page 11: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Communication Control

• Firewall

• Decryption

• Encryption

• Private & public key

Page 12: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Administrative Control

• Policy

• Procedure

• Hardware

• Software

• Employee

• Data

Page 13: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Application Control

• Input control

• Processing control

• Output control

Page 14: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Agenda

• Chief Information Officer

• IS Department and End Users

• Control & Security

• Contingency Management

Page 15: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Contingency Mgmt

• NOT disaster recovery– Reactive, not proactive

• Worst case scenario– All our eggs in one basket– Natural disaster– Human error / sabotage

Page 16: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Contingency Mgmt. Methods

• Disaster Recovery firm– Outsource strategic function?

• Off-line storage

• Data redundancy– Replicated databases– Fragmented databases

Page 17: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Contingency Methods

• Back-up power generators

• “What if” scenarios– Military war games

• Scaled-down manual system

• Back-up / recovery procedures

Page 18: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Contingency Methods

• Parallel systems

• Processing backup facility– Cold, warm, hot site

Page 19: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Cardinal Health• Redundant systems for critical order

processing

• Redundant WAN trunks

• System data backed up daily– Backup media kept off-site

• Backup replica site– Different part of country– Switched on within 30 minutes

Page 20: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Points to Remember

• Chief Information Officer

• IS Department and End Users

• Control & Security

• Contingency Management

Page 21: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Discussion Questions

• What types of control do you have implemented in your organization?

• Tell us a Contingency Management war story– What happened?– How did the firm recover?– How could the situation have been

• Averted?• Mitigated?

Page 22: Chapter 15 Managing Information. Agenda Chief Information Officer IS Department and End Users Control & Security Contingency Management

Assignment

• Review chapters 8-14

• Exam 2

• Group assignment

• Research paper & presentation