Replies and Critical analysis needed
Replies needed 1
John,
You make a very valid point when addressing the failure to establish set laws and repercussions for cybercrime. Naturally, no threat encourages wrong doing. I seems the conviction and penalty is attached the results of the cyber-attack rather that the attack. For instance, if a hacker attacks or attempts to hack a system to no avail, there’s may not be judicial punishment imposed. If the same hacker’s attacks results in $5 million monetary gain then he/she is subject to repercussion associated with theft, money laundering etc. I think a known attempt, even if failed should carry a harsh penalty for the attempt. If I attempt to rob a bank but make it away with no money, I still go to jail.
R,
E.W.
Replies Needed 2
Dmitriy,
After reviewing your reference from fireye.com I've learned that cyber attacks on infrastructures have become so widespread that National Security has literally categorized the chances of an attack as a guarantee rather than a potential. Cyber attacks on infrastructures has seemingly become a new cyber war strategy, along side traditional computer attacks
Within your response you mentioned states aren't active enough on the war against cyber attacks on infrastructure. Alike the Nation's ongoing struggle with other categories of cyber attacks, as long as hackers are motivated, a percentage of attacks will be successful; at best, we can lower the success rate. With that being said, as long as attacks are successful, I don't think we'll every feel like business', States, that Nation is being active enough.
Brasso, B. (2016). Cyber attacks against critical infrastructure are no longer just theories. Retrieved from https://www.fireeye.com/blog/executive-perspective/2016/04/cyber_attacks_agains.
R,
E.W.
Brasso, B. (2016). Cyber attacks against critical infrastructure are no longer just theories. Retrieved from https://www.fireeye.com/blog/executive-perspective/2016/04/cyber_attacks_agains.
Reply 3 needed
1. a) From a risk management and project management point of view, in what situation(s) should a system be more robustly tested?
You have to remember that in any type of project, there are going to be some level of risk involved, whether it is minor or low risk or even major with high risk. In my opinion, a brand new system should always be robustly tested. All levels are systems should be tested to ensure everything or every feature is working as required or designed. That would also include testing the customer or user interface to ensure it also works as the user expects it to. There are major differences between the back-end server type work and testing and the front-end user interface operability and testing. Robust testing also helps to flesh out user training as well as ensure security protocols are functioning properly.
1. b) In what situation(s) might less testing be acceptable?
There are many different situations and scenario that would be acceptable for only performing less testing. If you are simply performing a system upgrade or implementing some minor changes in the programming, then performing a total robust test of the system may not be at all necessary. You may be able to just test the particular parts that were affected by the changes made.
1. c) Suppose you were the project manager facing pressure from your customer or executive sponsor to reduce testing time when you believe more robust testing was needed. What approach would you use to try to convince the executive manager to follow your advice?
I of course would take the very upfront and direct approach to convincing him/her of following my advice. I would let them know that if proper testing in my professional opinion is to be performed on their system that it needs to be a full scale total test of the system. I would give lots of examples of what I’ve seen go wrong in similar situations when robust testing wasn’t performed, but needed. I would also detail how much I charged them to come back and fix what would have been caught had a full test of the system been accomplished. When you start talking money, bottom lines and down-time, businesses seem to pay more attention.
Darnall, R., & Preston, J. (2010). Project Management from Simple to Complex.
Reply 4 needed
a) From a risk management and project management point of view, in what situation(s) should a system be more robustly tested
A system should be more robustly tested during the testing phase of the SDLC. Any time a system, or product is about to be initiated for use, it needs to be checked for accuracies and performance in order to detect early signs of vulnerabilities and future issues. This will provide the development team and the PM enough insight to understand what process, or portion of a system, that needs to be reconsidered/ redesigned in order to prevent such huge or minor failures that would result in the loss of intellectual property, or profits.
b) In what situation(s) might less testing be acceptable?
c) Suppose you were the project manager facing pressure from your customer or executive sponsor to reduce testing time when you believe more robust testing was needed. What approach would you use to try to convince the executive manager to follow your advice?
The approach I would resort to is, taking the time with the customer or executive sponsor, and display to them in detail with hard facts, as to why more robust testing is needed. No one wants a faulty system, especially if it results in monetary losses, data loss, and especially if it hurts customer base. So therefore, a detailed meeting with key personnel will have to take place to explain as to why I know exactly why more robust testing needs to be conducted.
Darnall, R. Preston, J. (2014). Project Management from Simple to Complex. Saylor Foundation.
Reply 5 needed
A) From a risk management and project management point of view, in what situation(s) should a system be more robustly tested?
It depends on the type of testing that needs to be done. For example, a system may need to be more robustly tested if it is a brand new system undergoing acceptance testing, or if a system is undergoing beta testing, component, compliance or compatibility testing, or if defects were found during a previous test.
B) In what situation(s) might less testing be acceptable?
Situations were less testing might be acceptable is if the system is already in place and is only undergoing minor upgrades, such as a software update. It will still need to be tested, but not quite as rigorously as if it were being implemented for the very first time.
C) Suppose you were the project manager facing pressure from your customer or executive sponsor to reduce testing time when you believe more robust testing was needed. What approach would you use to try to convince the executive manager to follow your advice?
I think the best approach would be to use data to convince them, and show them previous projects that have failed due to inadequate testing. Having a detailed test plan laid out for them to review would also be helpful. That way the manager knows what you are thinking, exactly how the testing will go, and they can follow along with it as it happens.
Reference:
Parker, J. (2013, February 25). Types of system testing. Retrieved from http://enfocussolutions.com/types-of-system-testing/
Reply 6 needed
Many companies are outsourcing their businesses offshore to gain cost advantage and focus on new revenue streams. organizations are tempted to invest in offshore outsourcing because when they compare their own countries, they are able to get more accessible resources that can be exploited to gain competitive advantage.
GREAT POST
Reply 7 needed
John,
Great discussion. Nowadays most companies out source to some type of business that can run things smoothly with out them having to have a department or manage personnel to do whatever service. Most of the times it is very cost effective and beneficial that a company like Rusty Rims do outsource some of the systems that needs a bigger department for example. If this makes sense for the company to take advantage of a certain service, then I would highly recommend it myself.
Reply 8 needed
Hello,
I really hate asking this, did you consider outsourcing RR's customer service? In RR's situation with tight competition and a slow economy, coupled with poor help desk service, it may be worth outsourcing.
A glaring issue, in my opinion, is the fact that RR operates 24/7 and they only have one helpdesk person per terminal. Kinda putting that crew in a no-win situation. I think outsourcing the helpdesk/customer service can give Carol the ability to hire more folks for critical positions.
Good post,
Stephen
https://www.entrepreneur.com/article/225510