ITM303 CASE, SLP and TD

profilelilkittingurl
home_itm.docx

Module 4 - Home

Electronic Commerce and Information Security and Ethics

Modular Learning Outcomes

Upon successful completion of this module, the student will be able to satisfy the following outcomes:

•Case ◦Describe the tools and skills needed to implement electronic commerce in businesses.

◦Identify the policies and procedures that organizations should implement to protect information systems.

•SLP ◦Identify best practices in electronic and mobile commerce.

◦Describe information security threats and their risks.

•Discussion ◦Identify the challenges associated with electronic and mobile commerce and monitoring technologies.

◦Reflect upon course concepts.

Module Overview

Internet and communication technologies have revolutionized the way businesses operate introducing new opportunities to create competitive advantages and at the same time improve traditional business activities such as develop and maintain customer relationships, supplier relationships and even employee relationships. These opportunities created by electronic and mobile commerce can enhance productivity, maximize convenience, and improve communications within and outside the company.

Let’s go over some definitions related to the topic of electronic and mobile commerce:

Following the definition given by Andrew Mitchell (2009) electronic commerce is conceived as conducting or facilitating business via electronic communications networks and computer systems. This includes buying and selling online, electronic funds transfer, business communications (including by telephone, facsimile, and internal data networks), and using computers to access business information resources.

Mobile commerce (or mbusiness, mcommerce), is defined as the ability to conducting or facilitatince business through a wireless Internet-enabled device.

An e-business model is a plan that details how a company creates, delivers, and generates revenues on the Internet. Ebusiness models fall into one of the four categories: (1) business to business or B2B, (2) Business to Consumer (B2C), Consumer to Business (C2B) and Consumer to Consumer (C2C).

Currently, about one third of the world population have Internet access (http://www.internetworldstats.com/stats.htm). This creates new ways of making business and we are at the stage where more opportunities can and should be discovered!

Along with Internet topics, ethics and security are two fundaments building blocks for all organizations. When the behavior of a few individuals can destroy billion-dollar organizations, the value of ethics and security should be evident. In the last decades and due to expansion of the Internet, individuals, organizations and the whole society began to explore the richness and all the potentials that the new service has to offer and have been using it in all kinds of activities. Opening the world to the internet was a great opportunity for people and business; however, it is also an opportunity for thieves and hackers to get access to the information in organizations in an unauthorized way.

It is hard to quantify the effects of cyber criminal activity because most of the costs are soft and are related to not being able to be in business; a recent survey by the Yankee Group indicates that more than half of companies rate their Internet downtime costs at more than $1,000 per hour.

There is an extensive variety of information security risks such as viruses, worms, denial-of-service attacks, spoofing, stolen passwords, social engineering, software exploitation, trojan horses, and authority and authorization violations that can have a very negative impact on the regular operations of an organization. As security threats have grown, the need to protect organizational data has became a corporate crucial need. Although some of these attacks can be originated externally, most of them are directly or indirectly originated by internal employees.

In this module we will evaluate the business opportunities created by electronic and mobile commerce for businesses. Additonally, we will discuss policies and procedures that companies should implement to protect themselves of security threats. We will also discuss the actual information security threats that are out there and their risks.