Project Deliverable 3: Database and Programming Design
Project Deliverable 2: Business Requirements Document
Table of Contents 1.0 Introduction 1 2.0 Project Scope 2 3.0 Potential Risks, Constraints and Assumptions 2 3.1 Potential Risks 2 3.2 Constraints 3 3.3 Assumptions 3 4.0 Integration with other Systems and Infrastructure 4 4.1 Database Design 5 4.2 Interface Design 6 4.3 System and Network Security 6 4.4 Networking 8 5.0 Definition of Terms 9 6.0 Conclusion 10 7.0 References 12
2
E-Commerce for a Startup Company Business Requirements Document
1.0 Introduction
Over the recent past there has been a significant growth in the ecommerce market. The business owners have taken advantage of the strengths of using ecommerce in running as well as expanding their businesses. One of the main strengths that users properly utilize is the wide coverage of the business as it can reach potential customers throughout the world with use of proper tools and efficient customization.
According to Appedology (2020) research, the estimated returns of businesses that have successfully implemented ecommerce is 9% in average higher compared to the traditional businesses. However, the development and implementation require the physical resources as well as the availability of the physical commodities to be sold. To get the best results all this can be integrated in an online system.
The proposed online system is a complete project and therefore requires the basic steps of a successful project implementation. It has to take the entire lifecycle of an IT related project such as planning and requirements analysis, defining the requirements, designing of the system, development of the system, testing and evaluation of the system, deployment as well as system maintenance and updating (Linatoc, 2020). The successful deployment of this project would mean it meets all the user requirements such as high functionality of the system, user-friendliness, ease of doing business, and limited charges of importing and exporting for merchants and customers will indeed prove to be the best e-commerce website in the market. The basic requirements of the project development and implementation are as discussed below;
2.0 Project Scope
This project development and implementation is intended to serve the users within the headquarters region which tends to expand to cover global later. The implementation covers website development and design and system integration.
The defined project scope needs to be maintenance so as to control the project baseline. To achieve that, it has to be controlled using the basic strategies such as controlling the inputs, tools, techniques and outputs as well as sticking to the project management plan (Dongshen, 2016).
3.0 Potential Risks, Constraints and Assumptions
Any project integration and success are associated with potential risks, defined constraints as well as predefined assumptions. This project is not different in this case as it is likely to face with the following risks, has defined constraints and operates on stated assumptions as stated below;
3.1 Potential Risks
This project is likely to be associated with the following potential risks, threats and vulnerabilities;
i) Online security. This includes data breaches and related cyber-attacks by the hackers such as phishing, malware infection, distributed denial of service (DDOS), man-in-the middle attack among many others (Brauch, 2016).
ii) Client disputes as well as refunds. Clients are likely to raise disputes especially when they are not satisfied with the goods and/or services. At extreme levels they would require refunds for the items already purchased.
iii) Intellectual property violation. The attackers can steal the ecommerce intellectual property such as the trademarks, the logo manipulation, violation of copyright among others (Linatoc, 2020).
iv) Poor customer services. This can result from unprofessional employees who will delivery poor services such as poor communication and timing during delivery.
v) Weak authentication. It involves the use of weak authentication methods that allows the third parties to access the user data.
3.2 Constraints
This project is likely to be associated with the following constraints;
i) Quality parameter.
ii) Time factor.
iii) Cost factor.
iv) Scope definition.
v) Potential risks.
3.3 Assumptions
The proposed system implementation project works under the following assumptions;
i) The users have basic knowledge on the use of computer devices such as desktop computers, laptops and smartphones.
ii) The proposed system is compatible with most devices and runs on all operating systems.
iii) Most of the users of the system are in areas with good network coverage.
iv) The system meets the minimum software and hardware requirements.
4.0 Integration with other Systems and Infrastructure
Integration of the proposed system with other related and key systems is important for extended functionalities. The integration process involves the use of API to connect to remote servers. The proposed online system requires integration to other external sites such as the payment service providers like PayPal and Pioneer, shipping sites such as the DHL among others for complete operation (Hooda & Chhillar, 2018). The integration is helpful especially in reducing the level of entering similar information in every site connected to the system.
The integration has two major parts, that is the front end and the backend. The front end will provide a friendly user interface that would enable the users to interact with the system that is managed by the system designer (Donshen, 2016). On the other end, the back end comprises of the key components of the system such as the database and linking to the external sources which is managed by the system developer. The back end of this system requires either the enterprise resource planning (ERP) system or the point of sale (POS) system. To achieve the complete integration, both the hardware and the software infrastructure must meet the basic minimal requirements.
The use of external servers would improve the performance of the system as each functionality would be directed to a specific server type such as DNS server, webserver, database server and many others as provided by the selected cloud service provider. This technique will offload the main server from most functionalities and therefore assured of great system functionality (Appedology, 2020).
The infrastructure implementation depends on correct system design. The key components of the design include; database design and interface design as discussed below;
4.1 Database Design
The proposed system requires a well-designed database for storing the user’s data. The database needs also to meet the user specifications so as to ensure their data is properly stored. Linatoc (2020) states that the database needs to be integrated well for easier data management. The proposed system would need a relational database as opposed to document database since it requires higher performance.
The database to be used needs to meet the following criteria;
To begin with, it should be accurate. The database design has to ensure that the user data stored is accurate and true so as to avoid further conflicts.
Furthermore, it should use a strong query language. This can be achieved through the use of a standard language in this case the Structured Query Language (SQL). To make data definition (DDL) and manipulation (DML) simpler, the database has to make use of MYSQL. Fortunately, the oracle database system preferred for this project supports the two languages.
Moreover, it should allow multi accessing of data. The database should allow multiple users to access the data at the same time.
In addition, it should facilitate data sharing. The proposed database design needs to allow data sharing between the users in the database.
Also, it should be secured. The proposed database design should ensure that the users’ data is safe from any form of unauthorized access or manipulation.
Based on the user specification, the best database for the system implementation is Oracle database.
4.2 Interface Design
According to Donshen (2016) the proposed system needs to have a good interface design that is appealing and user friendly. The proposed system user interface has to meet the following;
i) It should be clear.
ii) It should be familiar.
iii) It should be responsive.
iv) It should be attractive.
v) It should be efficient.
vi) It should be consistent.
vii) It should be simple to use.
4.3 System and Network Security
The proposed system makes use of the public internet for transactions and the complete working. The internet is not always secure as it is full of different groups of cyber attackers who perform the attacks depending on different intentions such as competition, financial gain, superiority among others (Kupp et la., 2017).
System and network security has to be extensive in this case as the proposed system is intended to serve a large number of users. The best security strategy has to consider both defense in depth and layered security techniques (Brauch, 2019). Defense in depth would ensure that each and every component of the system is properly secured using the latest mechanisms as per the COBIT 5 framework. On the other hand, layered security would ensure that the different layers of the network are protected using different techniques and therefore once an attacker is successful at one layer it does not guarantee success to other layers.
Based on the potential risks, threats and vulnerabilities, the following defenses and countermeasures would be helpful;
i) Use of virtual private networks (VPNs). VPNs provide a secure channel communication within and outside the network.
ii) Password management. The passwords to be used for accessing both the system and the network needs to be strong. The strength can be defined in terms of correct password length as well as regular changes of passwords within specified period, most probably within three months. Password management can be greatly achieved through development and implementation of the right policies (Brauch, 2019).
iii) Use of encryption. Data encryption has to be applied on both the data stored in the system as well as that on transit. This prevents
iv) Applying limit access technique. Limited access to the system and other resources definitely reduces the chances of being attacked as it will be easier to track the offender using the log files.
v) Applying least privilege technique. The administrator is responsible for assigning each user the exact privilege needed to perform the required task. This prevents privilege escalation and therefore the insider threat.
vi) Integrating with the cloud security. The renowned cloud service providers such as Microsoft Azure, Amazon among others have always the best security strategies in place. Transferring the security risk to them will guarantee higher security to the system (Kupp et al., 2017).
vii) Use of antimalware applications. The use of updated antimalware applications such as antivirus software will protect the system from virus and other malware infections such as worms, trojan horses, logic bomb among others.
4.4 Networking
Networking is very crucial in the proposed systems development and implementation. The main role of networking in the system is to facilitate communication within the system network and the outside world. It is through the network that the clients from other regions can access its services. This means that a huge investment in the network would greatly improve the sales and profit as a whole (Donshen, 2016).
A good network would be an advantage to the business through traffic generation so as to expand its market. A good network design needs to consider the following factors;
To begin with, a good network should have great performance. The proposed system performance can be measured in terms of the communication speed.
Furthermore, a good network should be secured. The proposed system network should be secured in all aspects based on the network security triad, that is confidentiality, integrity and availability (CIA). This protects it from all form of malicious attacks from the unauthorized third parties (Brauch, 2019).
Moreover, a good network should be reliable. The proposed system network should be reliable in a way that the resources can be accessed anytime they are needed by the intended users.
Also, a good network should be scalable. The proposed system network should allow addition of more devices and users in future for expansion and growth.
In addition, a good network should be cost effective. It should be designed and implemented according to the user budget. This include both components purchasing as well as the services should align the set budget.
Correct implementation of the network meeting the above discussed criteria would ensure that the users of the system for instance employees can share ideas for improved work performance as well as functionality (Donshen, 2016).
Also, good network would improve the storage efficiency and volume. The proposed system network takes advantage of the unlimited network storage which terms to be very effective.
For this particular project a good network implementation involves both development of local area network (LAN) and wide area network (WAN) that needs to be integrated to work as a whole. Also, it will be a hybrid wired-wireless network to accommodate all devices at the same time promoting network mobility and flexibility.
5.0 Definition of Terms
Some of the key terms in this research paper include the following;
i) Network. A computer network is a group of interconnected devices (computers) for the purpose of communication.
ii) COBIT 5 framework. It stands for Control Objectives for Information Technologies. It is a framework developed by ISACA for information technology (IT) governance and IT management.
iii) Database. Refers to a collection of related information which are properly organized.
iv) Local Area Network (LAN). Refers to a computer network that entails computers connected within a large geographical area.
v) Wide Area Network (WAN). Refers to a computer network that entails computers connected within a small geographical area.
vi) Data breach. Refers to exposure of sensitive personal information to unauthorized users or environment.
vii) Cyber-attack. Refers to the malicious activities that is conducted by the cybercriminals against a computer or a group of connected computers.
viii) Enterprise resource planning (ERP) system. This refers to a compete system for managing all the business functions through automation of activities.
ix) Point of sale (POS) system. This is a system placed at the far end of the business that facilitate online payment of goods and services at the same time keeping track of the records.
x) User requirements. The defined specifications of the system defined by the users of the system.
xi) CIA network security triad. Refers to a comprehensive security strategy that upholds data and information confidentiality (prevents unauthorized access), integrity (prevents unauthorized modification) and availability (ensures data is available to intended users each time it is requested).
6.0 Conclusion
In conclusion, the proposed online system effectiveness can be evaluated through proper testing to ensure that it meets the user requirements. The main goal of the system is to link the buyers to the business through the internet and all other functionalities done remotely such as transportation and delivery of goods (Donshen, 2016).
To determine if the goal is met, the system is exposed to a number of tests that target the key aspects of the system such as performance, speed, accuracy, security, diagnostic as well as reliability among others. This includes; testing of the system functionalities, testing the system integration with third parties, testing the bandwidth usage, testing the system processing speed and testing the system security through data security test and system penetration testing (Hooda & Chhillar, 2018).
After the extensive testing all the bugs and errors and bugs are to be documented and possible solutions provided before the system is deployed. Also, deploying the system to the end users does jot mean it is now the end of everything. The system still requires maintenance, updates and upgrades to the latest versions for improved performance and security.
7.0 References
Appedology. 2020. Hardware and Software Requirements for E-Commerce Websites. Retrieved from https://appedology.com/hardware-and-software-requirements-for-e-commerce-websites/#:~:text=Hardware%20For%20E-Commerce%3A,CPU%3A%20Quad%202GHz%2B%20CPU.
Brauch, H. G. 2019. Security threats, challenges, vulnerabilities and risks in US national security documents (1990–2010). In Coping with Global Environmental Change, Disasters and Security (pp. 249-274). Springer, Berlin, Heidelberg.
Dongshen, Z. 2016. Computer network design and Implementation Based on relational database technology. Automation & Instrumentation, (4), 93.
Hooda, I., & Chhillar, R.S. 2018. Software test process, testing types and techniques. International Journal of Computer Applications, 111(13).
John Linatoc 2020. Build an Ecommerce Database Schema. Retrieved from https://medium.com/@johnwadelinatoc/build-an-ecommerce-database-schema-3b5e04b4f8b6
Kupp, M., Anderson, J., & Reckhenrich, J. 2017. Why design thinking in business needs a rethink. MIT sloan management review. 59(1), 42.