Showing posts with label Management Information Systems. Show all posts
Showing posts with label Management Information Systems. Show all posts

Tuesday, 18 February 2020

Functional Information System


Functional business systems Support a variety of operational and managerial applications of the basic business functions of a company. Examples: information systems that support applications in accounting, finance, marketing, operations management, and human resource management.




Accounting information systems help record business transactions, produce periodic financial statements, and create reports required by law, such as balance sheets and profit-and-loss statements.
The purpose of financial systems is to facilitate financial planning and business transactions.
In finance, information systems help organize budgets, manage cash flow, analyze investments, and make decisions that could reduce interest payments and increase revenues from financial transactions.

Marketing IS provide information that helps management decide how many sales representatives to assign to specific products in specific geographical areas.
The systems identify trends in the demand for the company’s products and services.

Human resource (HR) management systems help mainly in record-keeping, employee evaluation, and employee benefits.
Every organization must maintain accurate employee records. Human resource management systems maintain such records, including employees’ pictures, marital status, tax information, and other data that other systems, such as payroll, might use.


Another way of Classifying Information Systems is by which level of organisation it serves.Three main levels of Organisation information systems serve are as follows:

Operational-level systems: support operational managers, keeping track of the elementary activities and transactions

Management-level systems: serve the monitoring, controlling, decision-making, and administrative activities

Strategic-level systems: help senior management tackle and address strategic issues

To learn more about Functional Information Systems click the links below
Financial Information Systems
Manufacturing Information System
Marketing Information System

Saturday, 1 February 2020

Risks to Information Systems

What are the risks to Information Systems? When data is in physical form, the common risk might theft or damage from the physical location, but when data is converted in electronic form data is vulnerable from many sources this is illustrated from the diagram below

  There are threats from people, malware , virus, worms etc.. we shall see some of the most common risks to Information Systems. Most Information systems are web based, we can classify the threats from various points of access like 
  • Client Side
  • Communication Network
  • Corporate Servers
  • Corporate Systems




Risk 1: Unauthorized Access
One big security issue is people who are not authorised to access a system getting access to it, it can be due to bad or no password or even theft of password or devices

Risk 2: Internet Vulnerabilities

Due to current practices of having 24/7 internet for all devices, hackers find it easier to target a corporate network, also file sharing and multiple personal devices connected means more unregulated downloads and more unauthorized applications are installed. these cause even more vulnerabilities.

Risk 3: Wireless Security Challanges:

The prevalance of wireless networks made illegal access of networks much easier, with a simple SSID or public WiFi networks hackers can inject malicious codes into secure devices. So companies always advice their personnel never to use public WiFi networks.

    Risk 4: Malicious Software:
Malicious software can be called in various names
  • Virus - self replicating malicious code
  • Worms - self replicating and self spreading malicious codes
  • Trojan - malicious code hidden under a different application
  • Spyware - software designed to spy on the users systems
  • Keylogger- software used to record all keyboard strokes
  • SQL Injection Attacks - adding malicious codes into the network using websites poor coding.
Risk 5: Hackers and Crimes

  •  Spoofing and Sniffing
  •  Denial Of Service
  • Identity Theft
  •  Cyber terrorism and Warfare
Risk 6: Internal Threats
  •  Software Vulnerability
  •  Employees
Most ignored threat is the internal Threats by employees and software vulnerability, most companies use obsolete software and this gives many opportunity for hackers. also employees who have a grudge sometimes keep Logic Bombs or deactivate security system or steal and sell data.

These are some of the major risks to Information systems



Monday, 11 March 2019

MIS - Short Answers 1

How are information systems transforming business, and what is their relationship to globalization?

E-mail, online conferencing, smartphones, and tablet computers have become essential tools for
conducting business. Information systems are the foundation of fast-paced supply chains. The Internet allows many businesses to buy, sell, advertise, and solicit customer feedback online. Organizations are trying to become more competitive and efficient by digitally enabling their core business processes and evolving into digital firms. The Internet has stimulated globalization by dramatically reducing the costs of producing, buying, and selling goods on a global scale. New information system trends include the emerging mobile digital platform, online software as a service, and cloud computing.

Why are information systems so essential for running and managing a business today?


Information systems are a foundation for conducting business today. In many industries, survival
and the ability to achieve strategic business goals are difficult without extensive use of information
technology. Businesses today use information systems to achieve six major objectives: operational
excellence; new products, services, and business models; customer/supplier intimacy; improved
 decision making; competitive advantage; and day-to-day survival.


What exactly is an information system? How does it work? What are its management, organization,
and technology components?


From a technical perspective, an information system collects, stores, and disseminates information
from an organization’s environment and internal operations to support organizational functions and
decision making, communication, coordination, control, analysis, and visualization. Information
 systems transform raw data into useful information through three basic activities: input, processing,
and output.
From a business perspective, an information system provides a solution to a problem or challenge
facing a firm and represents a combination of management, organization, and technology elements.
The management dimension of information systems involves issues such as leadership, strategy, and
management behaviour. The technology dimension consists of computer hardware, software, data
 management technology, and networking/telecommunications technology (including the Internet).
The organization dimension of information systems involves issues such as the organization’s
 hierarchy, functional specialties, business processes, culture, and political interest groups.


What is the role of the information systems function in a business?


The information systems department is the formal organizational unit responsible for information
technology services. It is responsible for maintaining the hardware, software, data storage, and
 networks that comprise the firm’s IT infrastructure. The department consists of specialists, such as
programmers, systems analysts, project leaders, and information systems managers, and is often
headed by a CIO.




Monday, 3 December 2018

Information Systems controls - facility control and procedural control

Facility CONTROLS and Procedural Controls

Controls are constraints and other restrictions imposed on a user or a system, and they can
be used to secure systems against the risks just discussed or to reduce damage caused to systems,
applications, and data.
 Controls are implemented not only for access but also to implement policies and ensure that nonsensical data is not entered into corporate databases.

Application Reliability and Data Entry Controls

 The most reliable programs consider every possible misuse or abuse. A highly reliable program includes code that promptly produces a clear message if a user either makes an error or tries to circumvent a process.

For example, a Web site invites users to select a username and password, and the operators demand passwords that are not easy to guess. The application should be programmed to reject any password that has fewer than a certain number of characters or does not include numerals. A clear message then must be presented, inviting the user to follow the guidelines.

Controls also translate business policies into system features. For example, Blockbuster Video uses its IS to implement a policy limiting debt for each customer to a certain level. When a renter reaches the debt limit and tries to rent another DVD, a message appears on the cash register screen: “Do not rent!” Thus, the policy is implemented by using a control at the point of sale. Similar systems do not allow any expenditures to be committed unless a certain budgetary item is first checked to ensure
sufficient allocation. A spending policy has been implemented through the proper software.

Access Controls

Unauthorised access to information systems, usually via public networks such as the Internet,
does not always damage IT resources. However, it is regarded as one of the most serious threats
to security because it is often the prelude to the destruction of Web sites, databases, and other
resources, or theft of valuable information.

Access controls are measures taken to ensure that only those who are authorised have
access to a computer or network, or to certain applications or data. One way to block access to
a computer is by physically locking it in a facility to which only authorised users have a key or
by locking the computer itself with a physical key. However, in the age of networked computers,
this solution is practical only for a limited number of servers and other computers. Therefore,
these organisations must use other access controls, most of which rely on software.

Experts like to classify access controls into three groups: what you know, what you have, and
who you are.
1. “What you know” includes access codes such as user IDs, account numbers, and
passwords.
2. “What you have” is some kind of a device, such as a security card, which you use
directly or which continuously changes coordinated access codes and displays them for you.
3. “Who you are” includes your unique physical characteristics.

The most common way to control access is through the combination of a user ID and a
password. While user IDs are usually not secret, passwords are. IS managers encourage users to
change their passwords frequently, which most systems easily allow, so that others do not have
time to figure them out and to limit the usefulness of stolen passwords.
Some organisations have systems that force users to change their passwords at preset intervals, such as once a month or once every three months. Some systems also prevent users from selecting a password that they have used in the past, to minimise the chance that someone else might guess it, and many require a minimum length and mix of characters and numerals.

Access codes and their related passwords are maintained either in a special list that becomes part of the operating system or in a database that the system searches to determine whether a user is authorised to access the requested resource.

A more secure measure than passwords is security cards, such as RSA’s SecureID. The device
is distributed to employees who need access to confidential databases, usually remotely. Employees
receive a small device that displays a 6-digit number. Special circuitry changes the number
both at the server and the device to the same new number every minute. To gain access,
employees enter at least one access code and the current number. The device is small enough to
be carried on a key chain or in a wallet. This two-factor access control increases the probability
that only authorised people gain access. This is an example of using both what you know and
what you have.

In recent years, some companies have adopted physical access controls called bio-metrics. A
bio-metric characteristic is a unique physical, measurable characteristic of a human being that
is used to identify a person. Characteristics such as fingerprints, retinal scans, or voice prints can
be used in bio-metrics. They are in the class of “who you are.” When a fingerprint is used, the user
presses a finger on a scanner or puts it before a digital camera. The fingerprint is compared
against a database of digitised fingerprints of people with authorised access. A growing number
of laptop computers have a built-in fingerprint scanner for the same purpose. The procedure is
similar when the image of a person’s retina is scanned. With voice recognition, the user is
instructed to utter a word or several words. The intonation and accent are digitised and
compared with a list of digitised voice samples.

Decision Making Process


Decisions are classified as structured, semi-structured, and unstructured.

Unstructured decisions are those in which the decision maker must provide judgment, evaluation, and insight to solve the problem. Each of these decisions is novel, important, and nonroutine, and there is no well-understood or agreed-on procedure for making them.

Structured decisions, by contrast, are repetitive and routine, and they involve a definite procedure for handling them so that they do not have to be treated each time as if they were new.

Many decisions have elements of both types of decisions and are semi-structured, where only part of the problem has a clear-cut answer provided by an accepted procedure.

In general, structured decisions are more prevalent at lower organizational levels, whereas unstructured problems are more common at higher levels of the firm.


Simon (1960) described four different stages in decision making: intelligence, design, choice, and implementation
Intelligence consists of discovering, identifying, and understanding the problems occurring in the organization—why a problem exists, where, and what effects it is having on the firm.

Design involves identifying and exploring various solutions to the problem.

Choice consists of choosing among solution alternatives.

Implementation involves making the chosen alternative work and continuing to monitor how well the solution is working.