1 / 16100%
The Information System (IS) of an organization is fundamentally the use of information and
technology communications by a business so that people can use the technology for
supporting the business processes. The core components of an ‘IS’ of a business encompass
telecommunications, computer hardware, computer software, databases and data warehouses
and human resource and procedures. Each of these Information System components has a
cardinal role to play and they function in an interlinked manner so that the business can use
the technology for the intended purpose .The computer hardware is the physical technology
that functions with the information. It works along with the computer software. The software
tells the hardware what to do and thus it manages the operations that are performed by the
hardware. Telecommunications is required to connect the hardware so that a network can be
.A network is required in an Information System to tie together computer systems in a
specific area. The databases and data warehouses store the materials that the other IS
components work with. The data available in this section acts as the foundation of the IS of
an organization. The final component encompasses the human resource and procedures that
are responsible for running the system. They are related to cyber domain as they work in
close loop with other cyberspace elements. The organization I am choosing to discuss is the
financial institution USAA. USAA operates one of the most complex and successful
information systems in the world. It communicates with its broadly disperse customers,
mostly military officers and their families, primarily by phone, email, and its Web site. In
previous years, USAA made a calculated choice to become one of the more technology-
concentrated organizations in the world. It views IT as a calculated weapon and uses it in
multiple ways. For example, when customers call form their cell phones, offices, or homes,
the personnel over at USAA greets them personally by name. Unlike many diversified
companies, a customer representative can handle inquires and transactions about all of
USAA’s products using a highly integrated database. USAA utilizes its immeasurable
database to keep track of minute details, such as which auto parts are repaired most
regularly. It also uses its database to discover ways to lower claims costs. USAA spent
immensely to develop an image-processing system that digitizes all paper documents mailed
in by applicants. It takes only a few strokes of the computer keys for a policy service
representative to recover photos of all the documents in a client’s file. The system can sort
and prioritize so that workers are always focusing on the most urgent and important tasks.
USAA provides its customers with online deposit capture using scanning technology. USAA
was the first U.S. bank to administer a remote deposit capture application for the iPhone.
USAA's iPhone application allows clients to take photos of both the front and back of each
check and submit them for deposit electronically. The company I decided to use is Medicaid
for the state im currently located in. They have to use HIPPA to ensure that they don’t give
out patients information such as social security numbers, telephone numbers, addresses, and
Medical records. They also have to make sure that nobody gets hospital documents or any
type of doctor that accepts Medicaid because that contains providers information which
includes doctors account numbers, staff information and doctors social security numbers as
well. Medicaid collects a lot of information from doctors and patients and the information is
being kept on computers. I believe that they need to crack down on security a little bit more
because the system has been breached before. This all connects to the cyber domain because
everything that you use to look up patients information is through a website on the internet
and when I was working for Medicaid everyone was connected to one WiFi. Also people
used to connect their personal belongings to the same WiFi at the office so it was easy
access for a hacker to gain. I do know that they use VPN now that people are working from
home and using their own WiFi. Also they would have to make sure people stop connecting
their personal phones to the work computer because that can also spread around information
that the employees won’t even know they are doing. The organization that I choose was one
that I am intimately familiar with, which is the United States Army. The Army has a number
or protocols that must be followed in order to access even the most rudimentary of their
computer systems. The most basic of which would be Army Knowledge Online (AKO). This
is a system that allows you to quickly access any number or other military websites such as
MyPay (military website that allows access to things like your pay-stubs and tax
information), and iPERMS (Interactive Personnel Electronics Management System) which
allows soldiers to access their Army Military Human Resource Record (AHMRR). In order
to begin this process the soldier must be briefed and take multiple classes and pass exams
about ComSec (Communications Security). They are also issued a Common Access Card
(CAC), which not only serves as their official Military Identification, but is also preloaded
with "Permissions" for the various programs and websites that these soldiers are allowed to
access.
This card is typically locked with a numerical code chosen by the soldier, which must be
input whenever a soldier accesses a government computer, website, or in some cases secure
areas of buildings. On top of this, many sites are only accessible from a SIPR (Secure
Internet Protocol Router) line as opposed to utilizing a NIPR (Non-Secure Internet Protocol
Router) Access Point.
While it is necessary for the security of the military, I will be the first to say that at times the
systems in place do tend to run slightly behind the civilian world due to the difficulties and
expense in upgrading such a large system. In fact, their are still military websites such as
ones focusing on distance learning classes for rank progression, that require the use of
Internet Explorer as opposed to web browsers such as Microsoft Edge, FireFox, or Chrome.
Another key component is of information system is Data, if data is incorrect, then IT system
would collapse. I have worked for a non profit organization and my contract was thorough
FEMA, I was working as a Data Analyst where I ran reports for users and make sure Data is
entered correctly in the system for clients by case managers. we found numerous
discrepancies where data was entered incorrectly therefore these reports were very helpful. It
was web portal where I ran reports from, it was new system and we had many errors as we
ran reports, there were many glitches in the system, Data would change then I would have to
run the report again and sometimes many times which was not quite easy to work with and
so sometimes it was embarrassing in front of users cuz they know their clients and their
information and they were complaining that Data I sent them is incorrect. I often tried to
contact them and they say its a new system and it has glitches and we just have to bare with
it. It was quite annoying specially when we need the reports for meetings or create a report
to send the correct data to higher ups. The retail store that I choose will be Walmart. I
choose Walmart becasue for number one its walking distance from my house. My children
like to get out and walk from time to time. I can speak on their system becasue they have a
check system that will not let me let me cash any checks and I have asked several of times
why they will not and they gave me a number to call. The software and that they have will
not let you check go through the system if there is no funds. There was a time when I saw
people go in the store with checks and it went through and the check just bounced. The key
components of an information system is the hardware, software, data, and security. The
organization that I choose to discuss is this doctors office I used to work for. I thought that
they would be a perfect example to use because there is a certain level of confidentiality that
one has to abide by so you must assume that there is a some sort of security in place. Well
all of the patient information is stored on a computer program called an EMR electronic
medical record and if the company does pay for top notch security then a bunch of patients
information becomes available for hackers so it is very important to make sure you have
excellent software to protect the company from malware and hackers trying to steal the
patients information. People also are the cause for a lot of lost data, which is also important
because there should Be someone that is also monitoring cyber attacks and not just a
software that way there will be extra security protecting the patient information. The
company I chose to research is American Eagle Outfitters. They are a large retail clothing
company based in Pennsylvania. I worked for them for five years as a retail manager. At
American Eagle we had rewards programs where we would store shopper’s personal
information such as, email, address, and phone number. They also offer a credit card which
you can apply for on their site, so they have your social security number as well. With that,
they have databases and servers to store that information on. I recall our systems going down
one day for a couple hours and we couldn’t do any transactions or look up rewards
information. We found out later on there was a threat to the company, but they claimed that
they weren’t able to retrieve any customer information, so we didn’t need to worry. These
relate to the cyber domain because there is important information stored that needs to be
protected. The company I am choosing to profile is my current employer. We have many
key components in place to help us preserve our information security. One measure we have
in place is a form of physical security. Each employee must enter and exit through the main
entrance using a security badge. Any visitors are also routed through the main entrance
where they have to check in with reception and security. Once they’ve checked in with
security they are given a visitors badge. By doing this my employer is ensuring only
authorized personnel enter the building. This is important to our informational security
because it limits the availability to our hardware and infrastructure. It also verifies visitors
authenticity.
a a a a a a a a Another key component our IT department has in place is only allowing authorized
user accounts onto our network. If you try to access our internal network via an Ethernet
cable or WiFi without having an authorized account you will be locked out. In addition to
that they also have levels of confidentiality. A good example of this is the network drive that
human resources uses to store PII, personal identifiable information. Only account listed
within the user group of “Human Resources” and IT management can access this drive
because of the confidentiality level established by our accounts. The organization I will be
discussing about is my current employer. I currently work with the Bureau of Automotive
Repair. Our organization help consumers retire or repair their vehicles based off of
eligibility. It is extremely important that we hold the utmost confidentiality for our
consumers because we keep a track record of their private information such as their vehicle
information, mailing address, and income documents into our database. The physical copies
that we get are confidentially shredded and disposed of properly. Lately, we've been
receiving emails from the California Cyber Security Integration Center about employees
reporting multiple phishing emails from outside sources. During this pandemic, we are
receiving a lot of emails from third parties discussing about overdue invoices, COVID, and
the 2020 election. An email was sent to warn all employees because a few have opened the
emails from these outside sources and caused security to breach it. Since we are receiving
multiple phishing emails at this time, our cyber security has created a way for us to report
phishing emails through outlook in a timely manner. The organization I have chosen to
discuss about is the organization I work for. I am employed by the Defense Health Agency
supporting medical health care systems as a tier 1 desktop support specialist. The key
components in our information systems that correlates with this weeks video would be our
database is where we store user information along with patient health information. It is
stored on multiple servers for redundancy and availability to end clients on site and across
multiple military installations. Security is a top priority for my employer and we are
constantly receiving audits and training from our security team to ensure we following best
practices. Despite following best practices we still have threat events also known as attacks
happen in our enterprise. The most recent attack we received was actually a phishing attack
that affected a lot of our medical providers, The bases of the attack seemed to be targeted as
a denial of service because a lot of the medical providers received magnitude of junk email
out of nowhere and maxed out their 4gb mailbox capacity which caused a lot of our end
users to lose email functionality temporarily. Luckily it had minimal impact on our
enterprise and resolved quickly. The company I have chose to research their information
systems is Walmart. Walmart is one of the largest retailers in its industry. Walmart uses in
store shopping as well as online shopping in which it collects and secures data from possible
threats Walmart develop a supply chain management system that communicates with
customers, suppliers, and distributors and also built its own data centers and developed
supporting cloud-based commerce applications using open source tools. Walmart also has an
app that stores data used on the app such as location information, banking information,
search, and order information. In attempts to prevent customer information leaks Walmart
uses operational system components of PCI DSS that include maintaining a secure network
via use of firewalls to protect sensitive data, encrypting cardholder data that is transmitted
across public networks, regularly updating anti-virus software as well as tracking and
monitoring all access to network resources and cardholder data. Wal-Mart maintains
redundant primary and secondary information systems to mitigate the risks of operational
downtime and/or significant loss of information. The organization keeps primary and
secondary information systems physically separated. The company I chose is a company I
work for, Kaiser Permanente Hospital. I’ve been working here for almost 2 years now. I
work in the pharmacy department, we handle a large amount of patient information. We
constantly get these updates to better protect this information. We constantly get these
phishing emails, these emails are mostly not real, kaiser will send out these fake phishing
emails to try to train us into not opening emails that are sent from the outside. Kaiser
Permanente also requires a password change every three months, and require a finger scan
for every task that is being done in the pharmacy. Along with that, you also need a badge
scan to make your through certain department, no badge, no entry.
Along with medical and medication information that is displayed in a Patients chart is also
their personal information, address, phone number, email, social security number, and many
times they’ll also have credit card information. I really enjoyed this weeks reading
assignment, and video, it gave me a bigger outlook on information security, as well as a
different outlook on kaiser Permanente’s procedures to protect patient information. I have
worked for a couple of very large companies one was Verizon Online and the other was BP.
I worked as a Software Test Engineer and QA manager at Verizon, and a Senior Business
Analyst at BP. Both companies have complex information systems, but I have decided to go
with Verizon Online since I worked there the longest. Verizon Online is the internet and
landline side of Verizon, and really has nothing to do with the cell phone side of Verizon.
The servers that house all the information needed for various software projects are located
all over the country. There are servers for customer information that include names,
addresses, billing information, which services a customer has subscribed to, etc. There are
also servers that are used for hosting various Verizon websites including production,
development, and testing environments. There are servers for Online Help and databases as
well. There are multiple development teams, test teams (hardware and software), project
management teams, legal teams, design teams, artists, and business owners. We worked on a
local area network for our office, but we also had connections to other networks throughout
Verizon and sometimes 3rd party vendors. We even had access to some Microsoft servers
when we did a joint project with them. Since Verizon is a telecommunications company the
company had to worry about a wide variety of threats and areas that could be exploited.
Verizon provides consumer and business services so if there was a security breach it could
potentially affect numerous individuals and businesses. There is a dedicated security team
but really everyone was responsible for doing their part to ensure our data stayed secure.
Verizon is a part of the cyber domain. The services, data, hardware, people, and procedures
all make up aspects of the cyber domain. The key component of the information system I am
stuck between is the database and software. Databases relate to the cyber domain because
Data is often the most valuable asset of an organization and therefore is the main target of
intentional attacks. Systems developed in recent years are likely to make use of database
management systems. Backing up all data periodically will increase redundancy and will
make sure all sensitive data is not lost or compromised after a security breach. Attacks such
as injections and ransomware, compromise the integrity and availability of data. Backups
can help protect in such cases. Software is related to the cyber domain because Information
security is all too often implemented as an afterthought rather than developed as an integral
component from the beginning. And refactoring software and adding security measures later
on is far greater than building in security from the start. Security designed applications help
reduce the threats and ensure that when software/networks fail, they fail safely. Strong input
validation is often the first line of defense against various types of injection attacks.
Software and applications are designed to accept user input which opens it up to attacks and
here is where strong input validation helps filter out malicious input payloads that the
application would process. Information systems is a set of components to collect, store, and
process data from consisted data. Information systems consist of different types such as
executive support, management information, decision support, knowledge management,
transaction and office automation. As far as organizations Google would be the one I choose
as they use information systems for the search engine. This is how data is transmitted as
being the most used by users. For example from the given components, transaction
processing systems are included in the form of google pay as well as their online stores.
Information systems are related to cyber domain as they play a role for many world wide
systems, they are used from a global scale as it is everywhere. Cyber domain is a global
domain that is made of different networks of information, as being a infrastructure is counts
computer systems and networks as a whole. So being a whole domain this includes
information systems availability on the same scale. Cyber domain also consists of
information security to manage it with computer, data, and network security the 3 main
aspects to information security's architecture. I have chosen System76 as the company I
want to research. System76 may not be well known, but it is a small computer retailer based
out Colorado. They sell Linux based computer systems and have created their own flavor of
Linux called PopOS!. I have been a fan of this company for several years now, and I
currently run their OS on my system. I want to focus on them because not only are they a
retailer but also have an operating system that has a large community based support system,
so they have PI and in the community often screenshots are shared that could clue a threat
source in, and the bigger threat is if you are like me, you could possibly open yourself up to
potential malicious code when you update your system. I hope this is a good research and
hope that I find the faith I have in System76 is well placed. The organization that I will be
using is CACI International which is an American company headquartered In Arlington,
VA. “CACI provides expertise and technology to enterprise and mission customers in
support of national security missions and government transformation for defense,
intelligence, and civilian customers.” (CACI, 2020). These types of organizations have many
assets that if they fell into the wrong hands could compromise not only the company’s
interests but that of national security as well due the nature of the defense and intelligence
customer’s they work with. For example, they develop electronic warfare systems for the
Department of Defense to combat the enemy’s surveillance and reconnaissance systems. If
the plans for this asset where to fall into the wrong hands then that would cripple the
integrity and usefulness of those systems. There are many attacks that they have to thwart
every day from many different attackers, which could include other companies which are
competitors or foreign entities that are against some of their customers. The company has to
have many security measures set into place to counter attacks by always looking to improve
their security measures within the organization. Some of the ways to mitigate these risks
include always keeping the workforce aware of the latest threats through security training
which includes educating the workforce on the different threats they face, strict password
policies, and two factor authentications using things like tokens during logins. The company
has to keep their security team sharp as well, as threats are always evolving as new software
will come with new vulnerabilities that others will be looking to compromise for their
personal gain. I researched quite a few different organizations so far this week for ideas. It
came down to a few select organizations with enough public key components relating to the
cyber domain to make my choice but I ultimately want with Microsoft. I have always used
Microsoft products and learning a little more about their key components of an information
system was an interesting internet adventure. My original idea was to go with Amazon but
after much consideration I decided to go with Microsoft defining the cyber domain could be
accomplished multiple ways. I think it could easily be described as a domain occupied by
anything that deals with cyber technology or cyber space. While it appears some definitions
go more into depth this is the definition I will be sticking too for my assignments and future
discussion posts surrounding this topic. Key components of the information system I choose
relate to the cyber domain in multiple ways but more so Important is how the information
systems key components directly relate to how the cyber domain is established. Amazon is
the company I choose to write because of it’s size and capabilities it provides to customers
across the cyber domain. Amazon is a huge online corporation with physical logistical hubs
growing at an increasing rate every year. Due to this company size and client based I would
think they have many defenses in place to protect the customers data the adversaries would
love to exploit. They have many severs with their customer personal identification
information and financial information as well. Not only do they contain and protect personal
information they must safeguard many linked accounts like amazon prime that has users
account with information that must protect against threats that could result in loss of
information. Amazon will have to protect against threat of sabotaging servers or data.
Adversary threats are present daily with no warning to Amazons data base customers
information from exploitation to be downloaded and sold to sites. Advisories will create
ways or design their own ways to use a exploit on the assets data base to be resold. Amazon
takes measures to safeguard physical attacks as well to prevent loss of data bases physical of
exploiting data. The company I chose is a third-party help desk that provides support for a
much larger earth moving company. It has an information system that consists of physical
hardware and software that the computers run, the procedures the company uses and
enforces for troubleshooting or software licensing and much more. It also consists of the
people actively who work on the help desk or onsite at the warehouses, or even behind the
scenes that employees of the company never interact with. Another core component is the
large amounts of data stored on servers that is accessed by employees of the service desk or
by the employees who work for the company itself. Most employees must access or connect
to the cyber domain in order to do their jobs. Whether it be to access data or input data in a
certain database or share it with someone else who works in the company. On the service
desk we access a ticketing system where we input details of the customer and the issue.
There are still some forms of physical data is onsite locked away but for the most part all
information exists in the cyber domain and needs to be secured to keep the data safe. Apple
is the company I am going to write about since its a big growing industry and I know a lot
about it. When creating a Apple ID you started your information Asset. Adding your Credit
or debit cards to the wallet app and using keychain to save it to the iCloud when you backup
your device which is a Physical Asset. Apple has made it to where you can use Apple Pay in
a lot of places along with different websites. Doing so opens a door to Adversary's that
would want to gain access to this type of information. Using Phishing attempts like emails,
phone, text and pop-ups to pretend they are apple support and gain Information Assets.
Apple developed a way to make your information more secure by creating Two factor
authentication. Where you would need to either have a Trusted device or a Trusted Phone to
gain access to your Apple ID. Using this method makes it harder for Adversary's to gain
access to your Information Assets with just inputting your apple Id and password. Two
factor uses a method where when you log into your apple ID it sends a Verification code to
either your Trusted device or Trusted phone number. Without that verification code you are
unable to gain access to your apple ID. Now if you end up clicking the attachments from a
phishing email then it opens a door to where they can have access to information or if you
call the number on the phishing email your giving the Adversary the next step to gain access
to your Information Asset. The company I chose to do my research on is the company that I
work for Northrop Grumman. Northrop is a global aerospace and defense technology
company they have multiple locations throughout the country and worldwide. I currently
work in their logistics department but have dealt with their information systems department
when we have security concerns or hiccups. Their key components for information system
would be to monitor, control, and protect communications (transmitted or received by
organizational systems) at the external boundaries and key internal boundaries of
organizational systems. Protects the authenticity of communications sessions and prevents
unauthorized and unintended information transfer via shared system resources. My company
can relate to cyber domain because of how tight their security is. Once a month we get a
phishing email to help us understand that even though the company may appear to have high
security a hacker can still easily slip in and hack our systems if we are not careful when it
comes to opening the right or wrong emails and links. Prevent remote devices from
simultaneously establishing non-remote connections with organizational systems and
communicating via some other connections to resources in external networks. The
organization I chose to research their Information System is Advanced1, a drafting company
I previously worked for who is contracted by Spectrum, their main client, and other
companies. They have locations in Central Texas with 3 separate office locations in San
Antonio, Waco, and Georgetown as their main office. They design the layout for fiber optic,
coaxial cables, and equipment to be used when building subdivisions as well as providing
service to existing areas. The drafter must remotely log in to the client’s servers and use the
design software they use, most commonly v8i. In order to maintain security for their client’s
privacy the offices are interlinked by an EPN (Enterprise Private Network) allowing email
communication amongst each other only and no access to outside emails or internet, only
Google Earth for drafting purposes. Upper management are the only ones granted access to
outside emails to be able to communicate with clients on any issues that may come up on
designs. I feel their information security relates to the cyber domain in the way they
approach security for their network to help keep their client’s information confidential. By
limiting access to outside networks, it helps keep the possibility of hackers and viruses
down. Every drafter needs to log in to the servers with their own credentials daily with
maximum of 12 hours allowed to be in the server before needing to enter their credentials
again. Even though they keep security as the utmost priority there is still room for
improvement. I work for a rather large company that is on the global 500 list. This is BP
Lubricants. While I have been working for this company in a general IT role I have seen
many different types of attacks come across. Most common are the email phishing. While I
am not in security, I do not see most of the infrastructure that needs to be secured and I do
not deal with all of the different type of threats on a daily basis, I have seen quite a few
different types of attacks and attempts. Most of our infrastructure includes databases with
information assets and networking technology to connect all of the different sites together.
While I have been working there, i have only seen 1 notable attack that caused large scale
company wide issues. I am not sure exactly what it was but rumors said that it was a DDoS
type of attack on the corporate office. I remember this specifically because the company
internet was knocked out for about 3 days and many people were unable to work. Since then
they have implemented many different layers more of security including the Mimecast email
security for better scanning and filtering of emails. Before this system was introduced we
would get phishing emails once every six or so months. This would always come across as a
company email to just about everyone in the company and we would soon after get an email
from the security manager saying not to open it or click on any links in it and if you had to
contact the security team. The company I chose to highlight in the week one discussion is
the fortune 500 company, Sherwin-Williams Paint Company. I currently work for his
company in a management level position and have experienced many degrees of a lack of
information security. The Sherwin-Williams company has thousands of assets, which need
protection from adversaries. These assets include information assets as well as physical
assets. In the current world we live in people are constantly trying to get your information,
so you need to have a certain level of protection to threat sources. Sometimes, I do not see a
high level of security within this company. There have not been many threat events that I
have witnessed myself, but anything could happen. There has been an increased risk of
threats lately because of COVID-19. Sherwin-Williams was strictly curbside for a period,
and during this time they were taking all information over the phone or written information.
There were occasions where people’s personal information was written down, including
their financial information, and was left out for days. Luckily, even during a vulnerable time,
the company and the employees did a great job at reducing the exploits in our systems. The
Sherwin-Williams company needs to do a better job at securing clients information on short
notice. The computer systems Sherwin-Williams uses has great security, but when you are
forced to improvise, without the computers, you are more likely to have hiccups in the
structure. Overall, they have a solid foundation of information security, but their needs to be
improvement.
Students also viewed