Information Assurance Framework for Web Services
Information Assurance Framework for Web Services 12
Information Assurance Framework for Web Services
Running head: Information Assurance Framework for Web Services 1
Table of Contents
Proposal 14 Visual Representation 16 Iteration -1 16 Understanding IA Challenges Plan 16 Action 17 Observation 20 Reflection 21 Iteration -2 Conducting Survey 22 Plan 22 Action 23 Observation 25 Reflection 27 Iteration -3 Structuring the Information 28 Plan 28 Action 29 Observation 30 Reflection 32 Iteration-4 Developing Framework 33 Plan 33 Action 34 Observation 35 Reflection 36 Summary of Learning 37 References 39
List of Tables
Table 1 Elements Considered in Quesionnaire 23
Table 2 Standard Security Features 24
List of Figures
Figure 1 Web Security Compromises 3
Figure 2 Information Assurance Model 5
Figure 3 Key Components of IA Implementation 6
Figure 4 Action Research Process 8
Figure.5 IA Reference Model Framework 10
Figure 7 Visual Representation 14
Figure 8 IA for Web Applications Search 16
Figure 9 Keyword Search Results 18
Introduction
Internet based solutions, and web based services that are offered to the customers has become a common practice in the businesses. Right from B2B segment, to B2c and C2C, there are many web services and web based applications that are predominantly used in the business environment (Kahonge, 2013).
Adaptation and implementation of web based application systems has certainly supported the stakeholders of business in improving the ease of business communication, transaction processing and other such key business functions. However, one of the critical challenges that are envisaged in the business process are about issues pertaining to the information assurance issues in the web based application systems and processes that are adapted by the organizations (Al-hamami & et.al, 2012).
Globally, web based applications systems has become an integral part of the organizational requirements that could support in managing the business process in more effective ways. With the emergence of contemporary web technologies like Web 2.0, cloud based solutions and many other such developments emerging, there are potential developments that are taking place in the environment (DAN J KIM & et.al, 2004).
An organizational website that is poorly designed security features can open the door to security vulnerabilities. IT professionals may be put in a compromising position to prioritize system administrative tasks that are beneficial to a company’s bottom line over evaluating and proactively defending against security risks.
According to a research report that is published in the recent past on website security solutions and features, the study emphasize the key elements that impact the web security solutions and the need for companies to focus on improving the performance and security of the web solutions.
Figure 1 Web Security Compromises
The figure above depicts the broad outlook of how various companies are considering the issues and challenges that are envisaged in the business environment for managing the web applications, the issues and scope for development that is to be considered by the organizations.
For instance, in the case of some of the web application systems, the data and transaction management is highly secured and there are potential solutions that are managed by the organizations. In the case of some web application systems, despite the robust solutions that are managed by the companies, still the impact in terms of information security breach, data availability issues, identity and access control issues and many other such factors has been more prevalent (DAN J KIM & et.al, 2004).
In the case of information assurance problems, both the technical and non-technical issues to impact the efficacy of the system and could lead to more complexities of information assurance.
The key elements of information assurance problems that are encountered by the companies in the web application solutions are depicted in the following figure, and it is very important that the organizations focus on addressing such issues in an effective manner (DAN J KIM & et.al, 2004).
Source: http://docs.oasis-open.org/wsqm/WS-Quality-Factors/v1.0/WS-Quality-Factors-v1.0.html
Figure 2 Information Assurance Model
In the case of any of the web services irrespective of the category, and the system, if the factors that are depicted in the figure are addressed, the outcome from the solutions could be more effective for the organizations. The scope of interoperability has become a significant factor and with the emerging practices of collaborated information management issues, it is very important that the companies focus on having robust systems and practices in place (DAN J KIM & et.al, 2004).
Despite the fact that there are certain frameworks that are developed for information assurance management, still in terms of impacts that are envisaged in the process, it can be stated that there is need for more effective frameworks that could be adapted, and some kind of common parameters of CSFs that could be considered by the companies in terms of handling the information assurance in the web systems (Al-hamami & et.al, 2012).
In the figure-3 detailed below, inputs pertaining to how the information assurance systems should focus upon improving the systems and practices that has to be adapted in the business process is clearly depicted and if right kind of measures and solutions are adapted and the systems are monitored regularly, the outcome shall be more effective.
Figure 3 Key Components of IA Implementation
Considering such factors and the scope for the study, the objective for the study is about evaluating the CSFs that are important for the services and the kind of fundamental framework that is essential in the development of a good web information system (Al-hamami & et.al, 2012).
For the chosen project study, the focus is upon practicing the action research method of research process that shall support in gaining quality insights, practical experience in the process and towards developing solutions that shall support in implementation.
Action Research
Research methodologies play a vital role in the successful outcome of a project study. Considering the objectives of the study and the scope for the study, the method of action research process has been chosen for the proposed study (Brydon-Miller, 2003).
The Action Research process which is also called as Participatory Research is the process of conducting the research in which the emphasis is more about understanding the subject of the study by being part of the subject environment. This kind of research methodology is more commonly used in the on-job training and towards educational programs with intensive structure of practical learning and development (Young & et.al).
The process of conducting the action research method could be attributed to the process of four key steps which are very important in the process of conducting the action research.
· Plan
· Action
· Observation
· Reflection
Action research method involves no structured practices or timelines, and is more about the iterations way of conducting the scope of research. For instance, depending on the subject of the study, and the scope for research a specific iteration shall be planned in the study.
Using the four key steps discussed above, for iteration, the plan, action, observation and reflection is carried out, and the process of iteration planning and learning is continued till the desired outcome and the objective of the study is achieved (Brydon-Miller, 2003).
The following figure represents the kind of cyclic approach followed in the process of conducting the iterations as a part of action research process.
Figure 4 Action Research Process
Taking in to account the scope of work, the feasibility for being part of the work environment and gaining insights about the information assurance issues and towards developing the framework, the method of action research process is adapted in the study to focus on the developments that could support in achieving successful outcome for the study (Schruijer, 2006).
The process of iterations shall be followed with the requisite framework that can support in gathering as many insights possible about the organizational practices in terms of information assurance management, and the iterations shall be adapted till the right kind of outcome for the proposed objective is achieved from the system (Brydon-Miller, 2003).
Literature Review
Information Assurance is one of the integral factors that impact the success for an organizational information systems network. In the case of the web applications, the intensity and the impact of information assurance issues are much higher, as the systems are open to the external environment (Aazadnia & Fasanghari, 2008).
Information Assurance has become a wide scope subject for research among the researchers, as there are numerous factors pertaining to information assurance that is impacting the web applications in terms of information security factors. The studies emphasize the fact that in the absence of right kind of information assurance solutions, vulnerability of the systems is turning out to be high (Feruza & Kim, 2007).
Cherdantseva and Hilton (2013) define Information Assurance as “a multidisciplinary area of study and professional activity which aims to protect business by reducing risks associated with information and information systems by means of a comprehensive and systematic management of security countermeasures, which is driven by risk analysis and cost-effectiveness” (Cherdantseva & Hilton, 2013).
Many other definitions from the researchers also quote the information assurance as the combination of various factors right from functional, to technical, design and structural approach that shall support the application systems to be managed in more effective manner (Scalet, 2015). However, the key challenge that is considered in the process could be attributed to the issues pertaining to how the vulnerabilities and process related issues in the application services management shall be impacting the security outcome in the web services (Murphy, 2015).
Alongside the positive developments that are taking place for the companies, even the kind of complexities and challenges that are envisaged by the companies from the process is also turning out to be a major challenge to be addressed (Google, 2012; Murphy, 2015), and the solution towards improving the organizational information security could be considered as one of the significant developments that has to be considered by the organization (McDonald, 2008).
Cherdantseva and Hilton (2013) in their study on the information security and information assurance issues, depict the following Reference Model framework for information assurance that could be very resourceful for the holistic management of information security and application performance (Cherdantseva & Hilton, 2013). The figure below indicates the RM model of the information assurance solution in the business process.
Figure.5 IA Reference Model Framework
The process of making an effective system that has the IA in integral manner, focused at every stage of the application development and management cycle, shall improve the kind of outcome from the systems (Scalet, 2015).
The scope and need for completeness, focusing on risk analysis and ensuring the consistency of the system along with more cost efficient ways of managing the system that is proposed in the system is certainly a productive process that can make significant impact to the system success (Sinjilawi & et.al, 2014).
Taking stock of the factors, from the varied studies that have been carried out on information assurance issues, it is imperative that in the case of many of the web applications, the issues of information assurance prevails due to some of the following intrinsic factors (Aazadnia & Fasanghari, 2008).
· As the developers do not focus on improving the information assurance factors whilst of designing the system (Kashyap, 2015)
· During the process of implementing the system, if the application is not managed in an effective ways by focusing on the system, it shall have adverse impact on the information security issues in the system (Cherdantseva & Hilton, 2013)
· Not conducting the risk audits which are critically important to evaluate the kind of issues that shall be impacting the business process, and focus on addressing the vulnerable issues identified with the system (DAN J KIM & et.al, 2004).
Many kinds of web frameworks has evolved in the market, and depending on the organizational requirements and focusing on the trends that could impact, there are vivid range of solutions that are implemented by the organizations. In the figure depicted below, some of the popular frameworks that are adapted in the web application systems development have been focused upon. Depending on the process requirements, outcome expected from the web solution, if right kind of framework is adapted, it can lead to potential developments.
Figure 6 Web Frameworks
Varied range of web frameworks that are detailed above has significant importance in the development of contemporary web application solutions. The key challenge that has to be taken in to consideration is about focusing on information assurance factors which could make big impact on the system efficacy.
Considering factors that could impact quality of services from the web applications and focusing on developing an effective framework of information assurance schema which can be resourceful for developing a robust web application system, the proposal towards working on a framework of information assurance that could support the companies in managing the systems more effectively, is depicted with certain iterations that shall be considered for handling the process (Knapp & et.al, 2006).
Proposal
Iteration -1 Understanding IA challenges
IA challenges might vary for the companies, depending upon the contexts and the model of web application systems. For instance in the case of web applications that have financial transaction processing systems shall have different kind of complexities in information security while compared to the information security and assurance issues in social networking mobile applications.
By conducting an empirical study of various cases of information assurance, using the extensive online research, the focus is upon gathering more effective insights in to understanding IA challenges from varied conditions.
Iteration -2 Conduct Surveys
By developing a questionnaire on the various kinds of information assurance issues that could be envisaged by the stakeholders of an web application system, the emphasis is on gathering insights pertaining to how various kinds of issues could be impacting the quality of web application system. Using the online forums and the other such professional networking forums, the survey is conducted and the insights are gathered, which shall help in improving the systems more effectively.
Iteration -3 Structuring the Information
The objective for the proposed iteration is to focus on structuring the information from the earlier iterations and from the inputs that are gathered from the literature review. The inputs that are gathered from the process shall be structured and classified as the issues pertaining to application design level factors, functional and operational factors, which shall help in structuring and developing a comprehensive framework for information assurance.
Iteration -4 Developing the Framework
The focus in developing the framework is about creating a comprehensive framework that can support in improving the information security for the solutions in an effective manner. By focusing on the information structured from the earlier iterations, an effective framework is developed.
Visual Representation
Figure 7 Visual Representation
Iteration -1
Understanding IA Challenges Plan
The plan for the proposed iteration is to gain insights in to the process of Information Assurance in the web application services and the kind of challenges that are involved in the process for various stakeholders’ part of such web application services. The following is the key plan that is adapted in terms of gaining insights in to the process.
An online search process shall be carried out to identify the journal articles on the information assurance issues in the web application services.
Using the filtering criteria in the search engines, some of the recent articles pertaining to generic web information applications, transaction management applications, social networking applications and the financial transaction management related applications related journal articles are gathered.
On the basis of detailed review of inputs presented in various journal articles, a detailed list of IA challenges specific to the kind of web services are noted.
Secondarily a search process shall be carried out to identify the related news articles like the incidents reported in specific to the IA challenges identified for various categories. For instance, gathering information on breach of security in online banking applications, or privacy issues identified in the social networking sites.
Depending on the contextual inputs gathered, the IA challenges pertaining to each of the segment are more classified in terms of probability, impact and the kind of solutions that are feasible to overcome such challenges.
Action
· The plan proposed for gathering information on the IA challenges that are envisaged in the web services, are gathered from the process.
· Using the Google search engine, online search process is carried out to identify the journal articles on the information assurance issues in the web application services.
· The key words that are used for gathering information on the IA challenges in web applications are :
· Journal Articles on information assurance issues in web applications
· Journal articles on information assurance planning for web applications
· How the information assurance framework can be implemented in the web applications
· Usage of information assurance framework in web applications
· The figure below indicates that inputs pertaining to the search process that is carried out using one of the keyword chosen for the search.
Figure 8 IA for Web Applications Search
· Applying the filtering criteria in the search engines, some of the recent journal and peer reviewed articles pertaining to information assurance issues has been identified in the system.
· Some of the key topics in which the articles has been shortlisted for review are generic web information applications, transaction management applications, social networking applications and the financial transaction management related applications related journal articles are gathered.
· Articles that are published in some of the reputed journals and the ones that are published only in the recent past have been chosen for review.
· From the key points drawn in the review of journal articles, some of the significant inputs presented in various journal articles, a detailed list of IA challenges specific to the kind of web services are noted as a draft
In the next phase of search process, the emphasis was to identify the related news articles like the incidents reported in specific to the IA challenges identified for various categories. For the inputs that are to be gathered for IA challenges, much relative information has been identified from the search process.
Review of the inputs in the system has provided good amount of inputs on various reported incidents, and how the companies have overcome the challenges has been detailed in the process, which was reviewed and the key inputs has been noted from the process. The figure detailed below indicates the kind of keyword search and the information that has been gathered from the process.
Figure 9 Keyword Search Results
From the inputs that are gathered, the IA challenges pertaining to each of the segment are more classified in terms of probability, impact and the kind of solutions that are feasible to overcome such challenges has been noted for further process towards achieving the objective of the study.
Observation
From the inputs that are gathered in the process, it is evident that in majority of the cases of information assurance issues that are envisaged by the companies, some of the key issues that are gathered from the review of systems are:
In the case scenario of financial transaction management systems, the scope of physical intrusion and the phishing attacks are very high. There are numerous such incidents that are reported across the world, for the breach of security in web applications of financial management solutions.
Social networking apps have significant traffic and there are many such websites, in which the reliability in terms of performance, availability of the solutions has become a major challenge for the organizations.
Identity theft and access control issues are one of the most commonly reported conditions across the range of web services. Irrespective of whether the application is related to transaction processing or only informative site or the social networking solution etc., the key challenge that is facing the stakeholders is about information security issues.
The other prevalent factor of IA challenges for the web services is about the interoperability of the system. Despite the fact that some of the web applications are being effective in terms of interoperability, still there are significant issues that have to be addressed in the process.
The other key insight from the review of journal articles and other such related information is that, across the range of web services, the issue of IA is more a challenge for the companies, as information security related problems that are integral part of the system security is an subsection of IA, and if information assurance process is designed effectively, such issues could be overcome.
Reflection
· The plan proposed for gathering information on the IA challenges that are envisaged in the web services, has been effectively implemented. Though initially choosing the keywords for collecting the information pertaining to various web-services has taken some time, still the process has been very insightful.
· One of the key challenges envisaged in the process, is that for every keyword used for gathering information, there was plethora of results from the search criteria, and short listing the relevant information which can be resourceful for the study and gathering information had taken considerable time.
· Applying the filtering criteria in the search engines, some of the recent journal and peer reviewed articles pertaining to information assurance issues, has been adapted as it could present us the inputs from the recent developments. This approach has been very effective and has yielded good results in terms of gathering insights in to the process.
· The review processes and gathering information in a structured manner and working a draft note has helped in capturing all the key points that are identified from the journal articles.
· From the key points drawn in the review of journal articles, some of the significant inputs presented in various journal articles, a detailed list of IA challenges has given good insights in to the process and the path for further tasks that could be adapted towards achieving the objective of the study.
Iteration -2 Conducting Survey Plan
The plan in the proposed iteration is to focus on conducting surveys with the key stakeholders of the web application system management. Right from the end users to the developers and the service providers (for the cloud based web applications) there are many stakeholders who face challenges in terms of the management of web application systems in an effective manner.
Following is the key plan that is considered in the process of conducting the survey with the stakeholders.
Questionnaire Preparation
· Preparing a varied set of questionnaire based on the inputs gathered from the earlier iterations.
· Questionnaire should be more suitable to the kind of process and challenges faced at every stakeholder level.
· Questionnaire have to be prepared for web developers, companies offering cloud services for web applications and the end users accessing such web application.
Participants Identification
· Selecting the target group for conducting the interviews
· To choose the right kind of platform for conducting the surveys
· Schedule the survey and gather inputs from the survey participants.
Collating Information and Analysis
· All the respondent inputs shall be collated for structuring the data
· Analyze the data and generate insights from the business process.
Action
The process of conducting the surveys and gathering the information from the respondents has been conducted as planned. On the basis of the data gathered from the earlier iterations, questionnaires have been prepared for conducting survey to various stakeholders.
The following table depicts the inputs pertaining to various elements that are considered in planning the questionnaire for various stakeholders.
|
Stakeholder |
Elements Considered in Questionnaire |
Target group |
|
Web Application Developers |
Security factors in web technologies Application level security features Features essential for improving the user experience System reliability |
Web developers working on developing varied range of web application solutions are chosen for getting the questionnaire and gathering information about IA related developments faced in the development of applications |
|
Cloud Service Providers |
Reliability of the systems Interoperability Issues Network Infrastructure Issues Network Security Challenges Intrusions |
Some of the cloud service providers offering IaaS and SaaS services for the companies, are chosen for conducting the surveys. |
|
End Users |
· Identity control issues · Phishing attacks · User Interface · Navigation · Reliability of the Solution · Payment Gateway solutions |
Customers using the web applications pertaining to various business process. |
Table 1 Elements Considered in Quesionnaire
On the basis of elements considered, a questionnaire has been prepared and using the online survey portals, contacting the stakeholders and conducting the survey has been performed. Though in the survey participation, more respondents were from the end user base, still adequate level of sample was gathered even from the other stakeholders too.
Inputs gathered from the process has been compiled for generating insights about the perceptions and the challenges faced by the stakeholders in the web application systems and how effective solutions could be developed for improving the system and process.
Information provided by the respondents for all the three different set of questionnaires has been analyzed independently, and on the basis of the key issues that are mentioned by the respondents, some of the significant factors that has to be addressed in the web application systems development has been compiled for ensuring more insightful inputs.
Observation
The focus in this iteration was to collect information pertaining to how the web development companies, end users and the cloud service provider kind of companies might be facing challenges in terms of offering quality services to the customers.
From the inputs that are compiled from the analysis there are certain key factors that are highlighted which could be very important for developing more effective framework.
One of the key challenges that are faced by the web developers is about the kind of changes that are taking place in the technology front. Regularly updating the applications for security solutions is the other significant issue that has to be considered.
Identity and access control issues are predominantly faced by the stakeholders of the industry. There is significant need for the organizations to focus on improving the security features and solutions, as more and more phishing attacks takes place and the identity of the users are compromised.
The other key factor that has to be taken in to consideration is the user expectations and requirements miss-management are some of the other key issues that has to be addressed. From the survey inputs gathered from the stakeholders, one of the common issues that have been identified with the people around is about how the companies are facing the challenges.
The figure below indicates some of the other key challenges that are envisaged by the stakeholders in the development, deployment and usage of web application solutions.
Table 2 Standard Security Features
There are many insightful inputs that are gathered from the process, which could be very resourceful for developing the framework. Some of the key issues that are depicted by the participants emphasize that there are some problems which is due to the lack of integration in the systems and process.
Reflection
The process of conducting the surveys has been conducted as intended. Though it is the first time I have conducted such surveys, still the kind of planning and structured approach that is adapted for conducting the surveys has been very resourceful in completing the project iteration;
Some of the key challenges that are faced in the process of conducting in the survey is about identifying the stakeholders who could be interviewed and right inputs are gathered. Choosing an online survey portal for conducting the interviews certainly has some kind of limitation in the process.
Firstly the authenticity of the profiles that have been part of the survey process is not verified personally and it could be one of the major impact factor. But considering the time limitation and the challenges of reaching out to so many stakeholders personally shall be significant issue.
Considering such limitations, it can be stated that the process of conducting the survey online has certainly been a more effective method that has provided quality results from the process.
Compiling information provided by the different set of participants has been a complex process. One of the key challenges has been lack of understanding of how the qualitative and quantitative analysis techniques have to be implemented.
The process of collating and compiling information from varied sources and working on gathering collective inputs that could support in planning the framework has been a very effective solution. Though there were certain limitations and challenges in the process, in overall the process has been completed in successful manner and the outcome from the solutions is also very effective.
Iteration -3 Structuring the Information Plan
The plan in the iteration is to focus on structuring the information that is essential for the process of developing the framework. It is very important to ensure that all the key factors that are essential for developing the framework are gathered properly and any of the points that are necessary for the process is missed.
Following are the key processes that are adapted in the process of structuring the information that is essential for developing the framework.
The process of structuring the information shall be carried out in the form of a structured table, with classification of the key components of a web application solution. Following are the key components to which the data shall be structured.
· User Interface
· Improved Database Systems
· Database Level Security factors
· Application Security Solutions
· Network Security Solutions
· Improving the Accessibility to the application system
· Compatibility of the web application system to varied computing devices
· Ease of Access
For the above set of factors that key challenges that are envisaged at every level along with the feasible solutions that are detailed in various sources shall be gathered for developing a detailed structure.
Action
To ensure that there is right kind of information is gathered on the various elements that have to be considered for a robust web application, initially a table of elements that are considered and the related challenges/features and the critical success factor elements that are essential in the system are compiled in to a table.
|
Elements |
Key Factors |
|
User Interface |
Identity and Login Controls Improving the authentication features Simple and easy to navigate features |
|
Improved Database systems |
Distributed data base requirements Importing and Export of data from third party application systems Data Integrity Data Assurance |
|
Database Level Security Factors |
Data validation Data stored in secured manner |
|
Application Security |
Focusing on improving the application security Resilience and Reliability |
|
Network Security |
Network Intrusions DoS attacks Network breach |
|
Improving Accessibility |
Improve the features of access Validations and features enhancement |
|
Compatibility |
Should be able to access from any kind of web application solutions |
Taking in to account the key factors that have to be addressed, an online search has been carried out to find effective solutions, techniques or practices that could be adapted for improving the overall performance, robustness and efficiency of the system. There are many solutions that have been discussed in various journals and articles, and key solutions that make significant have also been noted.
Observation
From the detailed search that is carried out and the kind of insights that are gathered in the process, there are very insightful inputs generated from the process. Some of the key observations that are carried out in the process are:
· There are numerous academic and industrial researches that are taking place in improving the efficacy and efficiency of the web application systems development
· Globally many companies are focused on updating the systems and network in order to ensure that their web applications are very secured
· Many of the websites are prone to risks and challenges, due to lack of preparedness and vulnerabilities that are part of the organizational systems and network.
· From one of the articles on web application operations and efficiency, it is also evaluated that usability and reliability of the systems has to be given significant attention and periodically the systems audit has to be carried out to ensure that right kind of system inputs are gathered.
· In the case of transactional processing systems and the applications that has payment gateway integrations, the scope of phishing attacks are very high and the companies have to be very careful in ensuring that right kind of system procedures are adapted.
· Irrespective of the kind of application system, unless the stakeholders focus on their roles of handling the systems, securing the system in an effective manner might turn out to be a challenge.
· With the rising trends of security breaches, it is very essential that contemporary tools and techniques that could support in improving the system security , scalability and reliability has to be adapted.
· In the process of deploying web applications, cloud based solutions are turning out to be a potential solution as many companies that are using the web applications.
· If the companies can choose right kind of cloud based services, the cost of managing the IT infrastructure goes down drastically for the organizations and it shall be a significant advantage for the organizations.
· However, if the right kind of cloud service provider is not chosen, there could be significant impact on the organizational outcome from the process.
Reflection
The process of conducting the structuring of information has been very resourceful. Despite the fact that scope in the proposed work is more of gathering and collating information from the process, still the task more intrinsic process to the framework that has to be developed.
From the process that is adapted in the iteration, the task of finding the solutions for the key elements that play a vital role in the efficiency of the web application systems.
One of the major advantages that has been achieved from the process, finding the solutions for varied complex conditions and factors that has to be considered in the process of developing a robust web application system
Though the process that has been adapted for the iteration has been very complex, still the quantum of solutions that are gathered and the insights that are reviewed shall be very resourceful in developing a good framework which can be a checklist for the organizational process.
One of the key challenges faced in the process is about reviewing exhaustive list of solutions that could be adapted for improving the efficacy of the web application, but the process chosen is one of the effective medium that is adapted for achieving the desired outcome.
In overall, it can be stated that the process adapted and the outcome that is achieved from the proposed process has been very resourceful in achieving quality outcome and deliverables from the process and shall be very resourceful for conducting the further set of iterations and achieving the objective of the study.
Iteration-4 Developing Framework
Plan
The plan in the proposed iteration is to develop a framework that can be resourceful for developing a checklist of information for the web developers about using varied kind of tools, techniques, benchmark practices and solutions that could be implemented.
The plan for developing the framework is implemented as follows:
· A detailed planning of the key elements that shall be incorporated in to framework structure shall be developed.
· Once the key elements are listed, for every stakeholder the classification of issues based on the key elements shall be developed.
· Solutions, techniques, tools and bench mark practices that are very essential for completing a good web application system is identified.
· Developing a matrix of key solutions that has to be adapted for improving the web application system shall be worked
· The developed framework shall be a common and elementary framework, without any customization to any of the specific kind of web applications.
· The framework developed shall be reviewed for any kind of gaps in the process, by reviewing the entire matrix.
· A checklist form of critical success factors that shall support in improvement of the system shall also be developed
· The final checklist, and the framework shall be a combined system that can help the stakeholders work towards developing, deploying and usage of a robust web application system.
Action
The process of developing the framework is planned in a structured manner and the process has been implemented as planned. Though there were some minor deviations in terms of execution of the plan, still the process has been implemented with focused approach.
As planned, in the first step, the focus was on improving the system and its outcome. Firstly the key elements that are identified in the earlier iteration of forming an information structure, has been used for classifying the varied factors that shall be taken up in a web application system.
Some of the key-aspects that are addressed in the process are
· User Interface
· Data Assurance
· Application Security Solutions
· Network Security Solutions
· Compatibility
· System Integration
· Ease of Access
· By depicting the above elements in to grid for ensuring that all the key stakeholder issues are addressed in the framework, a matrix comprising the list of stakeholders, key elements and the solutions has been developed.
· Ensuring that all the key factors that are to be addressed in the system are structured in to a matrix, detailed flow and analysis of the system has been carried out as a review of the system.
· Once the prime level of review is completed, the emphasis was on developing a checklist of information source that shall support in improving the process more effectively.
· The system of common framework and checklist of critical success factors has been combined as a unit to be offered, which can be very resourceful for reviewing the efficiency, design and development of an application system.
Observation
One of the key factors that have been considered in the process is about evaluating the varied kind of best practices, solutions, techniques and methods that could be adapted for improving the operational efficiency of a web application system. It is imperative from the process of matrix development that, despite of having numerous challenges, the researchers have focused on identifying many novel solutions that could be counter measures for addressing risks and challenges.
Some of the contemporary solutions that has been incorporated in to the system are
· End-end encryption methods
· Network intrusion detection techniques
· Digital and Network monitoring practices
· Ease of using Web 2.0 Technologies
· Practices of improving application reliability
· Distributed database management systems
· Implementing SLAs and rigid framework of solutions.
By focusing on the above range of techniques, solutions and practices that could be implemented, the focus is more about developing range of solutions, practices and developments that could be implemented by the web developers, whilst developing the solutions more effectively and the process has been achieved from the development of framework
Reflection
The whole process of developing a framework is first of its kind experience for me, as I have never had the opportunity towards working on such complex process. From the process that has been undertaken, it is imperative that there are varied set of issues that has to be taken in to consideration in the development of a framework.
If any minor mistakes or skipping of some intrinsic factors take place, it might have significant impact. Though some of the processes that have been adapted in the iteration action is found to be repetitive of some of the steps in earlier iteration, still the desired outcome has been achieved.
From the process of conducting this iteration, apart from achieving the desired outcome of getting good project insights, I could even achieve the confidence of focusing on system analysis and design process related progress.
Despite the fact that there are many frameworks that are published earlier, still by focusing on the process of developing my own set of framework has given me the opportunity to explore the possible features, right kind of solutions to be implemented and the key solutions that could be derived from the process.
In the whole process, the quality of the solutions, processes, and solutions that are achieved is phenomenal and has supported in accomplishing the objective of the study.
Summary of Learning
Globally, web based applications systems has become an integral part of the organizational requirements that could support in managing the business process in more effective ways. An organizational website that is not effectively and without appropriately designed security features can open the door to security vulnerabilities. IT professionals may be put in a compromising position to prioritize system administrative tasks that are beneficial to a company’s bottom line over evaluating and proactively defending against security risks.
In the case of some web application systems, despite the robust solutions that are managed by the companies, still the impact in terms of information security breach, data availability issues, identity and access control issues and many other such factors has been more prevalent.
One of the major issue that leads to many challenges in the web application systems are about the information assurance related factors. The key elements of information assurance problems that are encountered by the companies in the web application solutions are many and it is very important that the organizations focus on addressing such issues in an effective manner Despite the fact that there are certain frameworks that are developed for information assurance management, still in terms of impacts that are envisaged in the process, it can be stated that there is need for more effective frameworks that could be adapted, and some kind of common parameters of CSFs that could be considered by the companies in terms of handling the information assurance in the web systems
Information Assurance has become a wide scope subject for research among the researchers, as there are numerous factors pertaining to information assurance that is impacting the web applications in terms of information security factors. The scope and need for completeness, focusing on risk analysis and ensuring the consistency of the system along with more cost efficient ways of managing the system that is proposed in the system is certainly a productive process that can make significant impact to the system success.
Many kinds of web frameworks has evolved in the market, and depending on the organizational requirements and focusing on the trends that could impact, there are vivid range of solutions that are implemented by the organizations. From the process of conducting the iterations, the detailed analysis of IA implementation aspects and conducting the user surveys to gather insights from the process has certainly helped in gaining more insightful outlook in to process and gathering data, which could be resourceful in successful implementation, and in overall the final objective of developing a good framework has been achieved with valuable insights and good learning experience.
References
Aazadnia, M., &Fasanghari, M. (2008).Improving the Information Technology Service Management with Six. IJCSNS International Journal of Computer Science and Network Security, VOL.8 No.3,, 144-151.
Al-hamami, A. H., & et.al.(2012). Web Application Security of Money Transfer Systems.Journal of Emerging Trends in Computing and Information Sciences VOL. 3, NO.3 , 365-372.
Brydon-Miller, M. (2003). Why action research? Action Research Volume 1(1) , 9-28.
Cherdantseva, Y., & Hilton, J. (2013).A Reference Model of Information Assurance & Security.EEE proceedings of ARES 2013, 1-10.
DAN J KIM, D., & et.al. (2004). Information Assurance in B2C Websites for Information Goods/Services. Electronic Markets Vol. 14 No 4 .
Feruza, S., & Kim, T.-h. (2007). IT Security Review: Privacy, Protection, Access Control, Assurance and System Security. International Journal of Multimedia and Ubiquitous Engineering Vol. 2, No. 2, 17-32.
Google.(2012). Google’s Approach to IT Security.Google.
Kahonge, A. M. (2013). Web Security and Log Management: An Application Centric Perspective. Scientific Research Vol.4 No.3, .
Kashyap, P. (2015, Aug 26). Technology Trends and its Challenges to IAM Systems. Retrieved Sep 26, 2016, from Security Community.TCS: https://securitycommunity.tcs.com/infosecsoapbox/articles/2015/08/26/technology-trends-and-its-challenges-iam-systems
Knapp, K. J., & et.al. (2006). The Top Information Security Issues Facing Organizations: What Can Government Do to Help? INFORMATION SECURITY AND RISK MANAGEMENT.
McDonald, M. (2008).Securitization and the Construction of Security. European Journal of International Relations vol. 14 no. 4, 563-587.
Murphy, K. (2015, Apr 03). Cyber Security vs. Information Assurance: Which One is Right for You? Retrieved Sep 27, 2016, from AIU Blog: http://www.aiuniv.edu/blog/april-2015/cyber-security-vs-information-assurance
Scalet, S. D. (2015, Mar 31). How to build physical security into a data center. Retrieved Sep 29, 2016, from CSO Online.Com: http://www.csoonline.com/article/2112402/physical-security/physical-security-19-ways-to-build-physical-security-into-a-data-center.html
Schruijer, S. G. (2006). Research on Collaboration in Action . International Journal of Action Research Vol.2 Issue: 2 , 222-242.
Sinjilawi, Y. K., & et.al. (2014). Addressing Security and Privacy Issues in Cloud Computing. Journal of Emerging Technologies in Web Intelligence, Vol 6, No 2, 192-199.
Young, M. R., & et.al.(n.d.). Action research: enhancing classroom practice and fulfilling educational responsibilities. Journal of Instructional Pedagogies , 1-19.