wk 3
1594884 - Pearson Education Limited ©
frontier, land was “up for grabs,” and people rushed to stake claim to valuable land. Similarly, today’s digital resources are up for grabs. Companies are trying to stake claim to intellectual property, data streams, and bandwidth. Internet service providers (ISPs), for example, have little control over the amount, type, or origin of the content they deliver. Why is this a problem? Consider the fact that in roughly the past 5 years, Netflix’s streaming services have grown so rapidly that 30 percent of all Internet traffic in the United States during peak hours is associated with people watching movies and TV shows using Netflix.
As an ISP, you may feel that Netflix should pay you a fee for clogging up your fiber lines with the release of a new season of a popular TV show. On the other hand, consumers and content providers want net neutrality. This would mean that all users and content providers would be treated equally. There wouldn’t be “fast” and “slow” lanes on the Internet. ISPs wouldn’t be allowed to block, or even slow, content associated with competing ISPs. They also couldn’t charge heavy Internet users additional fees or taxes.
To address these issues, the Federal Communications Commission (FCC) recently made an important ruling on net neutrality and became the new sheriff in town!
Neutralizing Innovation? In early 2015, the FCC approved new regulations to ensure that ISPs cannot discriminate between different types of Internet traffic. In short, all consumers will have access to content on an equal basis. This ruling in many ways renders the Internet a utility. It would be governed much like standard utilities (e.g., water and electricity) are
4
5
1594884 - Pearson Education Limited ©
by comparable regulations. Many people applauded this ruling. They pointed to the benefits of an Internet free of “fast” lanes and “slow” lanes. However, while on its surface it seems that this ruling can only be a good thing, there may be downsides to net neutrality.
Source: bakhtiarzein/Fotolia
People against net neutrality argue that it is yet another instance of the government interfering with free markets. This argument is based on laissez-faire economics, which advocates for a marketplace in which government intervention is not allowed. According to this principle, if a company is going to fail, it should fail and the marketplace will correct itself.
In the case of net neutrality, ISPs want to have the freedom to oversee Internet traffic flowing through their infrastructure. They want to be able to throttle it up or down based on whether content providers are paying them for better access. Because this capability
1594884 - Pearson Education Limited ©
has been ruled out by the FCC, ISPs are arguing that the loss of this potential revenue stream will inhibit infrastructure development, limit growth, and stifle new innovation.
Will we ever know if this claim by the ISPs is true? Maybe or maybe not. ISPs are working on finding ways to overturn this ruling. So while this battle is over, the larger war on net neutrality may have only just begun!
Questions 1. The feature states that access to the Internet can be
compared to other utilities due to the regulations that government agencies are beginning to enforce. Do you agree or disagree with the notion that the Internet is a utility? Explain your reasoning.
2. Imagine if the Internet was not protected by net neutrality. If you were an entrepreneur starting a new e-commerce company, how could your business be hurt by ISPs creating “fast” and “slow” lanes on the Internet?
3. The Internet is a resource used by governments, universities, businesses, and people all around the world. Do you think any one country or organization should be in charge of it?
4. Some economists may frown on the FCC getting involved in the operations of telecommunications companies and ISPs. Think of some examples of other potential harmful effects of net neutrality (besides the potential of lost revenue and stifled innovation).
5. Netflix was used as an example of a company that is instigating large volumes of Internet traffic. In what ways will the enforcement of net neutrality benefit Netflix?
An organization like Falcon Security can reduce its storage costs by 50 percent if it moves its data to the cloud. If the move is successful, Falcon
1594884 - Pearson Education Limited ©
Security can increase profitability, have a more reliable infrastructure, and scale its operations much more quickly. Large companies gain the same advantages but on a larger scale. So, the cloud lifts all boats and should enable organizations to develop more information systems cheaply and quickly, and thus (you knew it was coming!) increase the demand for employees who know how to use and manage information systems!
But what else? The cloud will foster new categories of work. By 2026, everything will be connected to everything else, with most data stored in the cloud. Mobile systems will be the standard; desktops will be relegated to content creators. So what new opportunities might arise?
Consider remote action systems , IS that provide computer-based activity or action at a distance. By enabling action at a distance, remote action systems save time and travel expense and make the skills and abilities of an expert available in places where he or she is not physically located. They also enable experts to scale their expertise. Let’s look at a few examples.
Telediagnosis is a remote action system that healthcare professionals use to diagnose illness for patients in rural or remote areas. Telesurgery uses telecommunications to link surgeons to robotic equipment at distant locations. In 2001, Dr. Jacques Marescaux, located in New York City, performed the first trans-Atlantic surgery when he successfully operated on a patient in Strasbourg, France. Such examples, which are still rare, have problems that must be overcome, but they will become more common by 2026. In fact, the largest healthcare provider in the U.S., UnitedHealthcare, recently announced that all video-based doctor visits will be covered just like regular doctor visits.
Other uses for remote systems include telelaw enforcement , such as the RedFlex system that uses cameras and motion-sensing equipment to issue
6
7
1594884 - Pearson Education Limited ©
tickets for red-light and speeding violations. The RedFlex Group, headquartered in South Melbourne, Victoria, Australia, earns 87 percent of its revenue from traffic violations in the United States. It offers a turn-key traffic citation information system that includes all five components.
Many remote systems are designed to provide services in dangerous locations, such as robots that clean nuclear reactors or biologically contaminated sites. Drones and other unoccupied military equipment are examples of remote systems used in war zones. Private security and law enforcement will increasingly take advantage of remotely controlled flying drones and robots. You may see an upgraded form of Knightscope’s 300- pound robot, named K5, patrolling your neighborhood in 2026.
But, even with these new opportunities, the news isn’t all good. New York’s Metropolitan Opera is arguably the finest opera company in the world. To see a live performance, you can drive to Manhattan, park your car, taxi to Lincoln Center, and pay $300 per seat. Or you can watch the same opera, remotely broadcast via Met Live, at a local movie theater, park your car for free, pay $12, and take a seat in the fourth row, where via the magic of digital broadcasting you can see details like the stitching on the singers’ costumes. Details you just can’t see from the $300 seats at the Met. And the sound quality is better. Wonderful, but now, who will go to a local opera performance?
Teleaction reduces the value of local mediocrity. The claim “Well, I’m not the best, but at least I’m here” loses value in a teleaction world. In 1990, when former Secretary of Labor Robert Reich wrote The Work of Nations, he could sensibly claim that those who provide routine face-to-face services are exempt from the dangers of offshoring. That claim loses validity in the teleaction world.
8
9
1594884 - Pearson Education Limited ©
By 2026, the value of the top-notch performers increases, possibly exponentially. Four million people watch the average Met Live broadcast; agents for the artists who perform at that venue will negotiate a sizable part of that $120 million gate. A famous surgeon or skating coach can reach a bigger market, faster and better, and be much better paid. So, if you can be the world’s best at s omething, do it!
But what about the rest of us? If you’re not the world’s expert at something, then find a way to be indispensable to someone who is. Own the theaters that broadcast Met Live. Own the skating rink for the remote figure skating coach. Be the vendor of the food at some teleaction event.
Or become essential to the development, use, and management of information systems that support these new opportunities. A business background with IS expertise will serve you very well between now and 2026. The next six chapters discuss many existing and new IS applications. Keep reading!
Security Guide From Anthem to Anathema
Have you ever lost your smartphone, even just for an hour or two? If so, you probably recall the wave of panic that set in when you thought it might be gone forever. Losing any digital device can be extremely troubling for a number of reasons. First, mobile devices and laptops are not cheap. The thought of spending hundreds of dollars, or even a couple thousand dollars in the case of a laptop, to replace the lost device is distressing. However, what often creates the most panic is the thought of the person now possessing your device finding a way to access all of your data.
If you were to lose a digital device, what data would you be most concerned about—banking data, email archives, social media
1594884 - Pearson Education Limited ©
accounts, your collection of photos, or something else? There is no right or wrong answer to this question, and responses vary from person to person. However, what is certain is the likelihood that in the future someone will access your personal data. The frustrating part is that in most cases, the culprits will not even need physical access to your smartphone or laptop. Your data can be stolen just as easily from a company storing it in the cloud. Don’t believe it? Just ask anyone covered by Anthem health care in February 2015.
Cloudy with a Chance of Theft More and more data are being stored in the cloud. Why? Because data storage costs have plummeted and Internet access has become faster and cheaper. In 1990, 1 million transistors cost $527, a gigabyte of storage cost $569, and a gigabit per second of bandwidth cost $1,245. But today 1 million transistors cost $0.05, a gigabyte of storage costs $0.02, and a gigabit per second of bandwidth costs $15.
Internet users want easy access to more and more data. Unfortunately, the downside to greater accessibility is that it becomes more accessible to hackers too.
In early 2015, Anthem Insurance Companies, Inc. reported a security breach resulting in the loss of roughly 80 million customer accounts. Hackers stole sensitive account data like names, addresses, Social Security numbers, and salaries. While any nationally publicized security breach will cause concern, especially in light of the recent trend in breaches with the Target and Home Depot incidents, Anthem customers became more and more irate as details about the nature of the breach were reported. Anthem eventually disclosed that the account data stolen had been stored in plain text—not encrypted. This meant that hackers could
10
11
1594884 - Pearson Education Limited ©
immediately begin selling the data on the black market or using it for other nefarious purposes.
Source: BillionPhotos.com/Fotolia
Security experts criticized Anthem for not encrypting sensitive customer account data. Numerous clients considered Anthem’s failure to encrypt account records negligent, and they subsequently filed lawsuits.
Bad for Business or Business as Usual? How would you feel if your account data had been part of the Anthem breach? Would this incident make you want to switch to a different healthcare provider, or would you recognize that large corporate data breaches are just a fact of life in a digital world and
1594884 - Pearson Education Limited ©
that your new healthcare provider could be equally vulnerable? The reality is that data breaches are so pervasive that it is not a matter of if, but when, a company holding data about you will be hacked. In fact, about a month after the Anthem data breach, Premera Blue Cross announced the loss of 11 million customer records. The lost customer records were even more sensitive because they included bank-account and medical data.
Despite these threats, it is highly unlikely that companies will begin pulling data from the cloud. Consumers clearly want the ease of use that Web-based services provide. However, it is possible that corporations’ security practices could evolve from being a necessary evil to becoming a competitive advantage. In fact, there could come a time when a company’s reputation for information security could be more valuable than the very products or services it sells!
Discussion Questions 1. Think about all of the cloud services you use. How vulnerable
are you right now to having your data stolen? 2. What are some of the ways you can lower the chances of your
personal data being stolen? 3. The article explains how Anthem failed to encrypt sensitive
account data. Why would encrypting account data make it more secure?
4. Have prior data breaches, like those at Home Depot or Target, affected your behavior as a consumer? How?
5. How can a greater awareness of security best practices help you in your current job?
Guide
12
1594884 - Pearson Education Limited ©
Is It Spying or Just Good Management?
According to a 2007 survey by American Management Association, 66 percent of employers monitor employees’ Internet connections. They also monitor email (43 percent), keystrokes (45 percent), stored files (43 percent), blogs (12 percent), and social networking sites (10 percent). That survey is 8 years old, and it is likely that, if anything, employer monitoring of employee activities has increased. A number of different techniques are used:
Key loggers. A key logger is a program that records all of your keystrokes. Employers can install key loggers without a problem on any corporate computer. If you allow your employer to configure your personal mobile device as part of its BYOD policy, it can install a key logger on it as well.
Key loggers do just what their name implies; they record everything you key: user IDs, passwords, text messages, emails, documents, and so forth. They are agnostic about what they record. If you check your personal banking account on an employer-owned computer, your employer (and its IT personnel) has everything it needs to manage your banking account. If you write a love letter to your spouse, the key logger will record it. Log files. Computer systems are indefatigable diarists. Your employer-provided computer or mobile device and any employer server that you connect to with a personal device keep extensive logs of your activity. Those logs show, in part, when you start work, when you end work, how long your computer is idle at work, and possibly, if the device has GPS, where your device has been. Logs also show what files you process and much information about your activities over the employer-managed networks.
13
1594884 - Pearson Education Limited ©
Packet sniffers. A packet sniffer is a program that captures network traffic. Most operate on wireless networks, but they are readily installed to work on wired networks as well. Packet sniffers obtain the text of unsecured email (most email), text messages, and Internet sites visited. They also can obtain voice traffic processed over the Internet. Any traffic that passes through an organization’s networks, whether from your employer-provided device, your personal device, or your personal computer at home (if you’re using the corporate network), can be sniffed.
Your employer could also have video surveillance cameras, audio recorders, office spies, and numerous other ways of watching you, but let’s leave those aside.
Source: Image Source/Getty Images
As you think about the amount of data that key logging files, log files, and packet sniffing files contain, you may feel secure that out
1594884 - Pearson Education Limited ©
of the millions of messages sent and received, your employer is unlikely to find your problematic ones. Text mining is the application of statistical techniques on text streams for locating particular words or patterns of particular words and even correlating word counts and patterns with personality profiles. The results can be used to find undesirable employees such as thieves, sexual predators, those engaged in an illicit romance, and any other profiles the employer creates (disgruntled employee?). So hiding in the company data pile is little protection.
Aha, you’re thinking. What about the First Amendment? It protects me, no? Alas, no. The First Amendment preserves your free speech regarding laws Congress may enact, and while in some limited sense it does protect federal employees, it doesn’t protect anyone else at work.
Well, you think, they can’t fire me for just anything, can they? Alas, again, unless you have negotiated an employment contract, you are what the attorneys call an employee at will. That means the employer can fire you for any reason whatsoever. The only exceptions are that you cannot be fired because of your race, gender, religion, or disability. You also cannot be fired for performing a public service such as jury duty. But, if you write an email on a computer at work that says your boss’s spouse is a jerk, he or she can fire you (the boss, not the spouse).
Discussion Questions 1. List the types of data you think are appropriate for your
employer to gather about you: a. On employer-provided devices. b. On personal devices used at work or at home on
employer-provided networks.
14
1594884 - Pearson Education Limited ©
2. As a manager, list the types of data you would like to obtain on your employees.
3. If there are differences between your answers to questions 1 and 2, explain and justify the differences.
4. Under what circumstances do you think it is appropriate for your employer to install a key logger on your personal mobile device?
5. Suppose someone from your IT department informs you that the company has evidence that one of your married subordinates is conducting an affair with someone not his or her spouse:
a. What would you do if the affair involves two people who work at your employer?
b. What would you do if the affair involves someone not employed by your company?
c. Do you think obtaining such knowledge is appropriate?
�. Given what you have learned regarding electronic surveillance at work, state your own personal guidelines for computer use.
7. Reread the definition of job security in Chapter 1 . Using that definition as a foundation, state what you can do, as an employee at will, to avoid being fired for a frivolous reason.
1594884 - Pearson Education Limited ©
Active Review Use this Active Review to verify that you understand the ideas and concepts that answer the chapter’s study questions.
Q6-1 Why is the cloud the future for most organizations?
Define cloud and explain the three key terms in your definition. Using Figure 6-3 as a guide, compare and contrast cloud-based and in-house hosting. Explain three factors that make cloud computing possible today. When does it not make sense to use a cloud-based infrastructure?
Q6-2 What network technology supports the cloud?
Define computer network. Explain the differences among PANs, LANs, WANs, intranets, internets, and the Internet. Describe protocol and explain the purpose of protocols. Explain the key distinction of a LAN. Describe the purpose of each component in Figure 6-5 . Define IEEE 802.3 and 802.11 and explain how they differ. List three ways of connecting a LAN or computer to the Internet. Explain the nature of each.
1594884 - Pearson Education Limited ©
Q6-3 How does the cloud work?
Explain the statement, “The Internet is an internet.” Define IP address and explain the different ways that public and private IP addresses are used. Describe the purpose of a domain name and explain how such names are associated with public IP addresses. Explain the role for agencies like GoDaddy. Define URL.
Define three-tier architecture and name and describe the role of each tier. Explain the role of each tier in Figure 6-10 as well as how the pages in Figures 6-9 and 6-11 are processed. Using the department analogy, define SOA and explain why departments are encapsulated. Summarize the advantages of using SOA in the three-tier architecture.
Define TCP/IP protocol architecture and explain, in general terms, the purpose of http, https, smtp, and ftp. Define the purpose and role of WSDL, SOAP, XML, and JSON. State a key difference between XML and JSON.
Q6-4 How do organizations use the cloud?
Define SaaS, PaaS, and IaaS. Provide an example of each. For each, describe the business situation in which it would be the most appropriate option. Define CDN and explain the purpose and advantages of a CDN. Explain how Web services can be used internally.
1594884 - Pearson Education Limited ©
Q6-5 How can Falcon Security use the cloud?
First, state why Falcon is likely to use the cloud. Name and describe SaaS products that Falcon could use. Explain several ways that Falcon could use PaaS offerings. Summarize why it is unlikely that Falcon would use IaaS.
Q6-6 How can organizations use cloud services securely?
Explain the purpose of a VPN and describe, in broad terms, how a VPN works. Define the term virtual and explain how it relates to VPN. Define private cloud. Summarize why the benefits of a private cloud are questionable. What kind of organization might benefit from such a cloud? Explain why it is unlikely that even very large organizations can create private clouds that compete with public cloud utilities. Under what circumstance might a private cloud make sense for an organization? Define VPC and explain how and why an organization might use one.
Q6-7 2026?
What is the likely future for the cloud? Summarize the good and bad news the cloud brings. Explain why the photo in Figure 6-2 is disturbing. Explain the statement, “The cloud lifts all boats.” Describe three categories of remote action systems. Explain how remote systems will increase the value of super-experts but diminish local mediocrity. What can other-than-
1594884 - Pearson Education Limited ©
super-experts do? Summarize how this 2026 discussion pertains to your career hopes.
Using Your Knowledge with Falcon Security
Name the principal advantage of the cloud to Falcon Security. For hosting its data, which cloud offering—SaaS, PaaS, or IaaS—makes the most sense, given the size and nature of Falcon’s business? Explain how Falcon could use that offering. If Falcon were larger and employed a more sophisticated IT staff, name another alternative that would make sense. Explain why.
1594884 - Pearson Education Limited ©
Key Terms and Concepts 10/100/1000 Ethernet Bluetooth Cable line Carrier Cloud Commerce server Content delivery network (CDN) Database tier Digital subscriber line (DSL) Domain name Elastic Encapsulated Ethernet File Transfer Protocol (ftp) Hop https Hypertext Transfer Protocol (http) ICANN (Internet Corporation for Assigned Names and Numbers) IEEE 802.3 protocol IEEE 802.11 protocol Infrastructure as a service (IaaS) Internet Internet service provider (ISP) Intranet
1594884 - Pearson Education Limited ©
IP address IPv4 IPv6 Local area network (LAN) Net neutrality Network Over the Internet Packet Packet sniffers Peering Personal area network (PAN) Platform as a service (PaaS) Pooled Private cloud Private IP address Protocol Public IP address Remote action system Server tier Service-oriented architecture (SOA) Simple Mail Transfer Protocol (smtp) Small office/home office (SOHO) Software as a service (SaaS) TCP/IP protocol architecture Telediagnosis Telelaw enforcement Telesurgery Text mining The Internet Three-tier architecture Tunnel URL (Uniform Resource Locator)
1594884 - Pearson Education Limited ©
User tier Virtual private cloud (VPC) Virtual private network (VPN) WAN wireless Web page Web servers Wide area network (WAN)
MyMISLab™
To complete the problems with the , go to EOC
Discussion Questions in the MyLab.
1594884 - Pearson Education Limited ©
Using Your Knowledge 6-1. Define cloud and explain the three key terms in your
definition. Compare and contrast cloud-based and in-house hosting using the comparison presented in Q6-1 as a guide. In your opinion, explain the three most important factors that make cloud-based hosting preferable to in-house hosting.
6-2. Apple invested more than $1B in the North Carolina
data center mentioned in Q6-1. For Apple to spend such a sum, it must perceive the iCloud as being a key component of its future. Using the principles discussed in Q3-7 of Chapter 3 , explain all the ways you believe the iCloud will give Apple a competitive advantage over other mobile device vendors.
6-3. Suppose you manage a group of seven employees in
a small business. Each of your employees wants to be connected to the Internet. Consider two alternatives:
Alternative A: Each employee has his or her own device and connects individually to the Internet.
Alternative B: The employees’ computers are connected using a LAN, and the network uses a single device to connect to the Internet.
1594884 - Pearson Education Limited ©
a. Sketch the equipment and lines required for each alternative.
b. Explain the actions you need to take to create each alternative.
c. Which of these two alternatives would you recommend?
6-4. Go to http://aws.amazon.com and search for AWS database offerings. Explain the differences among Amazon’s RDS, DynamoDB, ElastiCache, and Redshift services. Which of these three would you recommend for storing Falcon Security’s data? (By the way, whenever you query the Internet for any AWS product, be sure to include the keyword AWS in your search. Otherwise, your search will result in Amazon’s lists of books about the item you’re searching for.) 6-5. Suppose Toshio wants Falcon Security to set up a private internet, and he justifies this request on the basis of better security. Explain why that is not a good decision, and rebut his claim about security by suggesting that Falcon use a VPC. Justify your suggestion. 6-6. In five sentences or fewer, explain how the cloud will affect job prospects for you between now and 2026.
1594884 - Pearson Education Limited ©
Collaboration Exercise 6 Using the collaboration IS you built in Chapter 2 (page 76), collaborate with a group of students to answer the following questions.
The cloud is causing monumental changes in the information systems services industry. In every city, you will still see the trucks of local independent software vendors (ISVs) driving to their clients to set up and maintain local area networks, servers, and software. You’ll know the trucks by the Microsoft, Oracle, and Cisco logos on their sides. For years, those small, local companies have survived, some very profitably, on their ability to set up and maintain LANs, connect user computers to the Internet, set up servers, sell Microsoft Exchange licenses, and install other software on both servers and user computers.
Once everything is installed, these companies continued to earn revenue by providing maintenance for problems that inevitably developed and support for new versions of software, connecting new user computers, and so forth. Their customers vary, but generally are smaller companies of, say, 3 to 50 employees—companies that are large enough to need email, Internet connections, and possibly some entry-level software applications such as QuickBooks.
6-7. Using the knowledge of this chapter and the intuition of the members of your team, summarize threats that cloud services present to such ISVs.
1594884 - Pearson Education Limited ©
6-8. Suppose your team owns and manages one of these ISVs. You learn that more and more of your clients are choosing SaaS cloud services like Google for email, rather than setting up local email servers.
a. What, if anything, can you do to prevent the encroachment of SaaS on your business?
b. Given your answer to question 6-8a question , identify three alternative ways you can respond.
c. Which of the three responses identified in your answer to question 6-8b would you choose? Justify your choice.
6-9. Even if SaaS eliminates the need for email and other local servers, there will still remain viable services that you can provide. Name and describe those services. 6-10. Suppose instead of attempting to adapt an existing ISV to the threat of cloud services, you and your teammates decide to set up an entirely new business, one that will succeed in the presence of SaaS and other cloud services. Looking at businesses in and around your campus, identify and describe the IS needs those businesses will have in the cloud services world. 6-11. Describe the IS services that your new business could provide for the business needs you identified in your answer to question 6- 10 . 6-12. Given your answers to question 6-7 through 6-11
, would you rather be an existing ISV attempting to adapt to this new world or an entirely new company? Compare and contrast the advantages and disadvantages of each alternative. 6-13. Changing technology has, for centuries, eliminated the need for certain products and services and created the
1594884 - Pearson Education Limited ©
need for new products and services. What is new, today, however, is the rapid pace at which new technology is created and adapted. Using cloud services as an example, create a statement of the posture that business professionals should take with regard to technology in order to thrive in this fast-changing environment. Notice the verb in this assignment is thrive, and not just survive.
1594884 - Pearson Education Limited ©
Case Study 6
FinQloud Forever . . . Well, at Least for the Required Interval . . .
In 1937, the Securities and Exchange Commission (SEC) set out rules that stipulated records retention requirements for securities brokers and dealers. The SEC’s concern was (and is) that records of financial transactions not be altered after the fact, that they be retained for a stipulated period of time, and that indexes be created so that the records can be readily searched.
In 1937, the rules assumed that such records were recorded on paper media. With the rise of information systems storage, in 1997 the SEC updated the rules by stating that such records can be kept electronically, provided that the storage devices are write once, read many times (WORM) devices. This rule was readily accepted by the financial services industry because the first CDs and DVDs were WORM devices.
However, as technology developed, broker-dealers and other financial institutions wanted to store records using regular disk storage and petitioned the SEC for guidance on how they might do that. In May 2003, the SEC interpreted the rule to enable the storage of such records on read-
1594884 - Pearson Education Limited ©
write media, provided that the storage mechanism included software that would prohibit data alteration:
A broker-dealer would not violate the requirement in paragraph (f)(2)(ii)(A) of the rule if it used an electronic storage system that prevents the overwriting, erasing or otherwise altering of a record during its required retention period through the use of integrated hardware and software control codes. Rule 17a-4 requires broker-dealers to retain records for specified lengths of time. Therefore, it follows that the non-erasable and non-rewriteable aspect of their storage need not continue beyond that period.
The Commission’s interpretation does not include storage systems that only mitigate the risk a record will be overwritten or erased. Such systems—which may use software applications to protect electronic records, such as authentication and approval policies, passwords or other extrinsic security controls—do not maintain the records in a manner that is non-rewriteable and non-erasable. The external measures used by these other systems do not prevent a record from being changed or deleted. For example, they might limit access to records through the use of passwords. Additionally, they might create a “finger print” of the record based on its content. If the record is changed, the fingerprint will indicate that it was altered (but the original record would not be preserved). The ability to overwrite or erase records stored on these systems makes them non-compliant with Rule 17a-4(f).
Notice the SEC specifically excludes extrinsic controls such as authentication, passwords, and manual procedures because it believes it would be possible for such systems to be readily misused to overwrite records. The SEC is striking a fine line in this ruling; if, for example, someone were to tamper with the storage systems’ software, it would be possible to overwrite data. Apparently, the SEC assumes such tampering would be illegal and so rare as to not be a concern.
15
1594884 - Pearson Education Limited ©
Given this ruling, organizations began to develop systems in compliance. The NASDAQ OMX Group, a multinational corporation that owns and operates the NASDAQ stock market as well as eight European exchanges, began to develop FinQloud, a cloud-based storage system that was developed to be compliant with the SEC’s (and other regulating organizations’) rulings. NASDAQ OMX operates in 70 different markets, in 50 countries worldwide, and claims that it processes one out of 10 stock transactions worldwide.
Figure 6-25 Components of the FinQloud System
Figure 6-25 shows the fundamental structure of the FinQloud system. On the back end, it uses Amazon’s S3 product to provide scalable, elastic storage. When financial institutions submit records to FinQloud for storage, FinQloud processes the data in such a way that it cannot be updated, encrypts the data, and transmits the processed, encrypted data to AWS, where it is encrypted yet again and stored on S3 devices. Data is indexed on S3 and can be readily read by authorized users. NASDAQ OMX then claimed that FinQloud’s processing and encryption is done is such a way that it meets the SEC requirement.
16
1594884 - Pearson Education Limited ©
Of course, NASDAQ OMX knew this statement would be perceived as self- serving, so it hired two independent companies to verify that claim: Jordan & Jordan, a securities industry consulting company, and Cohasset Associates, a document-processing consulting company. According to The Wall Street Journal, both organizations concluded that when properly configured, FinQloud meets the requirements of the SEC’s rule (Rule 17a-3) as well as a similar rule set out by the Commodities Futures Trading Commission.
Consequently, NASDAQ OMX customers can use FinQloud, and as long as they can demonstrate that they have properly configured it, their auditors will find this system to be in compliance with the SEC rulings.
Questions
17
6-14. In your own words, summarize the dealer-broker record retention requirements. 6-15. Reread the SEC’s 2003 interpretation. In your own words, explain the difference between “integrated hardware and software control codes” and software applications that use “authentication and approval policies, passwords, or other extrinsic controls.” Give an example of each. 6-16. Clearly, in the view of the SEC, the likelihood of compromise of an integrated system of hardware and software is considerably less than the likelihood of compromise of a system of authentication, passwords, and procedures. Justify this view. 6-17. Do you agree with the view in question 6-16 ? Why or why not?
1594884 - Pearson Education Limited ©
MyMISLab™
Go to the Assignments section of your MyLab to complete these writing exercises.
6-18. Investigate Jordan & Jordan (www.jandj.com) and Cohasset Associates (www.cohasset.com). If you were a consultant to a financial institution, to what extent would you rely on the statements of these organizations? 6-19. If you were a consultant to a financial institution, what else might you do to verify that FinQloud complies with the SEC ruling and its 2003 interpretation? 6-20. Explain how the knowledge you have gained so far in this course helps you to understand the SEC’s 2003 interpretation. Summarize how your knowledge would help you if you worked for a financial institution. Cast your answers to this question in a way that you could use in a job interview.
6-21. Suppose that you work at Falcon Security and Joni tells you that she doesn’t believe that cheap, elastic provisioning of data storage is possible. “There has to be a catch somewhere,” she says. Write a one- page memo to her explaining how the cloud works. In your memo, include the role of standards for cloud processing. 6-22. Suppose you manage a sales department that uses the SaaS product Salesforce.com. One of your key salespeople refuses to put his data into that system. “I just don’t believe that the competition can’t
1594884 - Pearson Education Limited ©
steal my data, and I’m not taking that risk.” How do you respond to him?