1/129
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is IS
collect, store, analyze, and output data and information
data vs information vs knowledge
data: raw facts, numbers, stats
information: data given context
knowledge: application of information
knowledge > information > data in context
knowledge < information < data in volume
the six major roles of IS: operations management
functions to deliver goods/services: inventory/supply chain, accounting, payroll
compliance: US and other countries it is a part of keeping the business running
enterprise resource planning: big part of managing operations
the six major roles of IS: customer interactions
CRM systems, often bundled into ERP systems, build and maintain relationships
includes web-based front offices and online self-service
support tickets are a big part of this
also includes interactions inside a company
the six major roles of IS: making decisions
data driven decision making: many companies are terrible at this, let what’s actually going on in the business drive high-level decisions
business intelligence
process managers should use to make decisions, drawn from the company’s own information systems or external factors
combines data gathering, data storage, knowledge management, and analysis
involves data visualization and data analysis
the six major roles of IS: collaborating on teams
social networks: used in a business context (facebook marketplace) or also be used to engage customers (Wendy’s X)
workplace communication software: designed specifically for professional communication; allows for real time integration of multiple information channels
collaborating on teams: software development
allows for software development/storage/testing/deployment from multiple locations
Github is by far the biggest platform for this
collaborating on teams: file sharing
originally used by pirates in the 00’s for sharing music and such illegally with P2P sharing
companies now have professional platforms to allow their employees to share files with each other
the six major roles of IS: competitive advantage
valuable: has to deliver real value
rare: has to be something your competitors don’t have
inimitable: can’t easily be copied just by studying your business model and reverse engineering
non-substitutable: can’t get around using your product
the four components of IS
people: leaders, managers, and staff IT team
technology: hardware, software, networks
data: digital data can be integrated and shared across systems
processes: set of activities to achieve tasks, business process management
the four components of IS: people
by far the hardest part of dealing with an IS
people > processes > data > technology
don’t underestimate the importance of people and processes in an IS, new software is not a silver bullet
information value: timeliness
is the data real time, or is there a delay?
if delayed, is the information still valuable?
information value: accuracy
is the data showing what’s actually going on, or is it distorted
information value: completeness
is the data complete or fragmented
if fragmented, is it complete enough to be usable
information value: context
has the data been given the proper context, or could someone get a wrong idea about what’s really going on
Porter’s 5 competitive forces: threat of new entrants
many IS companies often do not have a big threat of new entrants compared to other industries
scale, network effects and switching costs often prevent people from switching software/products
network effects: product value increases because more people use it
switching costs: costs that customers incur when they change suppliers
amount of capital needed to even enter the market is substantial in some instances
Porter’s 5 competitive forces: power of buyers
depending on the segment of the IS field, buyers may have a little or a lot of power based on their ability to substitute
because of the concentration of firms, buyers often have few options
switching costs are higher than average for the IS industry
IS products are often marketed to the masses, so there are many buyers
backwards integration is usually not a problem
Porter’s 5 competitive forces: power of suppliers
IS products tend to have fewer suppliers the higher up you go, the power of their suppliers tends to be very strong at multiple levels
nothing has been found to replace silicon semiconductors and market segments are seeing further concentration
chinese firms have been trying to break out of this chain
Porter’s 5 competitive forces: threat of substitution
IS products tend to have a smaller # of companies in the market and are highly sophisticated, there are not many substitutes due to concentration and sophistication
high switching costs and very high network effects lower the threat
Porter’s 5 competitive forces: competitive rivalry
IS companies sometimes use each other’s services
oftentimes companies will use the services of more than one company
market shares in many categories have been stable for years
sometimes there is a degree of cooperation between IS companies
external factors that affect 5 forces: disruptive innovations
radical and unexpected
transform industry and change 5 forces
creative destruction: fail to respond to disruptive innovation that capitalizes on new technologies
ex: Gen AI
external factors that affect 5 forces: govt. policies
affect how industries operate and evolve
ogranizations lobby for govt. action
judges and courts affect industry structure
govt. can also make unexpected policy changes
external factors that affect 5 forces: complementary products and services
industries are interrelated → innovation can require many players in many roles
visionaires lead to new beneficial directions
companies embedded in ecosystem
core companies: google, apple, microsoft
complementary products/services: app store, google play
partner: microsoft partnering with LinkedIn
govt: establish regulations and standards
companies nowadays try to build platforms/ecosystems so they can see you a host of complementary goods
these goods can also come from unrelated manufacturers
external factors that affect 5 forces: environmental events
major effects without warning (ex: BP oil spill)
energy costs and emissions (ex: china banned bitcoin mining due to energy cost)
leaders must consider industry and forces
includes accounting for events that may be only a remote possibility
value chain
primary activities = direct materials + direct labor
what are actually needed to make a product (ex: dell buys computer parts, assembles a computer, markets it, and ships it out)
secondary activities = overhead
things you have to do to enable primary activities but aren’t “strictly necessary” for a product (ex: HR and management)
extended value chain
you have to consider other companies as a part of your value chain
why? disruption due to policy, new tech, or vertical integration opportunities
policy can cause your suppliers/buyers to disappear overnight
new tech can allow your buyers to substitute your good/service
everyone’s favorite: need to know who supplies you so you can buy them or whose space you want to move into (vertical integration)
IT benchmarking
IT spending varies by industry and region
managers can use benchmarks to assess extended value chain
EVC (extended value chain) model necessary for comparison
benchmarking - run, grow, and transform
organization just starting → little to none of your budget will be for running
organization is mature and in decline → more will go towards running
74% of IT spending to run organization
16% to grow business
9% to transform business model
competitive strategies in business: low cost strategy
competing on price by being the lowest-cost producer in the industry
you get to offer the lowest prices in order to reach the most people
many companies start in a low-cost strategy, before transitioning to a different strategy once they have enough market share/recognition
competition will likely be high, as you will compete with many
competitive strategies in business: product differentiation strategy
offering unique products/services that stand out from competitors
cost is still considered, but the ultimate focus is on maximum marginal profit
brand recognition matters way more
downside: it’s impossible to reach everybody, because you will turn off some people by how you differentiate yourself
competitive strategies in business: focused niche strategy
targeting a specific, narrow market segment with tailored offerings
ideally will serve a market that isn’t being served by anyone else, big focus on who is being served
ex: GoPro
competitive strategies in business: hybrid strategy
exactly what it sounds like; just combining the best of multiple types of strategies
ex: amazon offers competitive prices while providing a vast selection of products
role of IS in strategy
enhance operational efficiency
automate: eliminate low-value tasks → task is repetitive and rule-based; maek the customer experience as fast as possible
streamline: enable more/faster high-valued work → reduce complexity of the customer experience in order to drive customer satisfaction; enable employees to make more high-level decisions that matter
ethics
system of moral principles that human beings use to judge right and wrong and to develop rules of conduct
virtue ethics
that which makes us a better person is the right thing to do
influenced natural law
deontology
we should follow the rules/our duties to determine what’s right
what we do is more important than the outcomes or meaning behind it
utilitarianism
actions are ethical or unethical based on their consequences or outcomes
the needs of the many outweight the needs of the few
do the most good for the most people
care-based ethics
we should do what cares for others the most
rights-based ethics
we should do what preserves fundamental human rights the most
natural law and rights
certain moral values are universally apparent, inherent in, and applicable to all people and can be discovered using reason
ex: ten commandments, US declaration of independence
divine command theory
that which God commands must be right
moral relativism
morality is relative to the time and place in which someone lives
ethical nihilism
there is no objective source of morality
ethics and law
laws are oftened grounded in ethical principles
political pressure
legailty vs ethics
lying might be legal but, is it ethical
actions are “legal” if they do not violate the laws or codes of the local govt., state, or fed
actions are “ethical” or “moral” if they meet an individual's personal code of conduct, which may be based on a particular social, religous, or other group norms
amplification of consequences/effect
web-based technologies can turn minor mistakes into significant issues due to their viral nature
ex: a single tweet can reach millions within minutes, amplifying both positive and negative impacts
disinhibition effect
sometimes your brain doesn’t work the same way online
psychological distance
when we aren’t at risk of getting punched in the face, we get braver!
our minds we have more “distance” with people online
intellectual property (IP)
intangible assets such as music, written works, software, art, designs, movies, creative ideas, discoveries, inventions, and other expressions of the human mind
fair use (education) is a big exception
copyright, patent, trademark
copyright: protects authored works for 70 years + author’s life
patent: protects inventions for 20 years
trademark: protects marketing materials, potentially indefinitely
digital right management (DRM)
technologies that software developers, publishers, media companies, and other IP holders use to control access to their digital content
applied to movie through cryptographic keys
applied to games through software embedded inside
copy left
preserving one’s copyright or software while using that to ensure free software
license allows anyone to take, modify, sell, or otherwise use code
code is made publicly available on the internet
idea is to try and make software transparent/ethical for all
piracy
the practice of downloading and / or distributing digital content on the interent
abandonware
software that is no longer distributed or supported by the copyright user
privacy
fundamental aspect of human rights and personal freedom
involves the right to control personal information and how it is used
importance of privacy
protects individuals from misues of their personal data
ensurse personal autonomy and freedom from surveillance
impact of tech on privacy
IT has transformed how personal data is collected, stored, and shared
digital age has introduced new challenges and ethical considerations for maintaining privacy
cookies
little files that are stored by your browser that save login details, preferences, and allow companies to track behavior
third party cookies
those on the website that are not created by the website itself
google analytics
full service analytics platform which tracks users across multiple websites
facebook pixel
piece of javascript code that sits on many websites and tracks your movements for analytics
laws/rights to privacy
right to anonymity
protection from unwarranted searches or seizures
right to view and correct personal information
right to control use of personal information by third parties
right to be left alone
protection against intrusion
convenience and discounts
people often share personal data for convenience or discounts
ex: allowing cookies for personalized promotions
proxy servers
act as an intermediary
pass requests from you and the server back and forth without revealing your IP address or even your country
VPN (virtual private networks): work similarly, but they also encrypt the traffic between you and the proxy server
pro/con of anonymity online
pro: protects individuals in online support groups; allows sharing of sensitive information without fear of disclosure
con: shields terrorists, criminals, spammers, and vengeful posters; online identity can be obscured using fake names, nicknames, free email, and public computers; erasing digital tracks is challenging
surveillance technology
orgs use tech to monitor email, texting, web surfing, etc.
pro: addressing concerns like “cyberslacking”; concern from liability; need to protect security and confidentiality
con: potential drop in productivity; increased stress and lower productivity among monitored employees
information security
the protection of an organization’s information assets against misues, disclosure, unauthorized access, or destruction
can arise both inside and outside organizations
can be natural events or human-made, accidental or deliberate
insider threat: someone inside a company who compromises the information security of the company they work for, typically from inside the network
much of the time, it’s phishing attack from outside the company
hacking
accessing information systems in an unauthorized way, often for nefarious purposes
parasitic computing
accessing/using the computing power of someone else’s machine without permission
malware
malicious software designed to attack computer systems
ex: viruses, worms, trojans, keyloggers
botnets
networks of compromised computers controlled by criminal gangs
used to capture sensitive information like user IDs, passwords, and credit cards
distributed denial of service attacks (DDoS)
zombie computers (usually in a botnet) flood a site wtih quick bogus page requests
causes the sit to slow down or crash
impact: financial losses due to downtime, lost business, and damaged reputation
phishing attacks (social engineering)
mechanism: botnets often mask the source of phishing emails
recipients are lured to fake websites/login pages to enter personal information
ransomware
malware that encrypts files and demands a ransom for decryption codes
payment: often demanded in bitcoins due to their untraceable nature
impact on healthcare: disrupts access to patient records and critical data
information leaks
cybercriminals, lost devices, misplaced backup media, and unshredded documents
legal implications: govt. impose fines on companies that lose customer data
market impact: oversupply of leaked data drives prices in underground markets
multifactor authentication
prevents a criminal from accessing your account/network if they only stole a password
patching
being able to quickly deploy security fixes prevents them from exploitation
backups
if your system is compromised, being able to wipe it clean and use a back up to restore it is crucial to a quick recovery
principle of least privledge
every user should only have as much system access as they need at any one time
awareness
training employees on looking for threats like phishing or ransomware prevents them from becoming a network access point
incident response
need a cybersecurity team who actively surveys network logs and responds immediately upon detecting an attack
why do we need a formal process of system development
minimize failure
avoid creating an intuition-based system
avoid late, over budget projects
deliver values as promised
provide accountability
system development life cycle: planning
assessing business needs
ROI, BEP
risk management
competitive advantage
ideally most of your bad projects should fail here
system development life cycle: analysis
understand business processes/requirements → process diagram/flowchart
requirement definition (RDD): includes all of the outputs of this step, including the diagram
want to understand what the process is currently at a more detailed level so you can figure out how the system changes things or fits in
that is what drives your requirements in the document
second most common place for your project to fail
functional requirement
a process the system shoud perform as a part of supporting a user task
information the system should provide as the user performs a task
ex: system shall allow users to select the category of their order
non-functional requirement
characteristics that the system should have that do not directly contribute to the business process
usability (screen attractiveness), accessibility (accessible for people with disablity), performance (response time), interface (user navigation), security (authentication), compliance, integration, language
system development life cycle: design
where we specify techincal details to satisfy RDD/PDD like architectural design
“divide and conquer” is one of the primary strategies used in system/software development in general
model how users will be using the system
need to model how the data is used/created/stored including database design
SDD (solution design document) is first created here
system development life cycle: development
version control: usually using Git or Gifthub; keeps track of changes made across different software versions
project and issue tracking: usually integrated with version control; intended to keep track of all bugs and work to be done
code review: designed to make sure the code being put out by one person is reviewed by someone else to ensure maintainability
system development life cycle: testing
test small subsytems first, the once those are correct, test their integration at the larger system level
need to test the new system with any outside systems it integrates with
ensure performance is acceptable
have your business user test your system and sign off saying they approve (UAT = user acceptance test)
system development life cycle: implementation
your software has been tested and found worthy
parallel: launch new when old is still running
phased: launches modules in phases instead of all at once
pilot: launch to a small subset of users or locations first
direct: stops old system and launches new on the go-live date
parallel is usually the best, although phased can make sense with larger systems
direct can make sense but is more situational (better for smaller systems)
system development life cycle: maintenance
bug fixes - includes functionality and security
can be due to preexisting issues
can be due to new issues caused by other systems/software changing
end of life plan should be considered
keeping personnel who can maintan the systems is usually the largest challenge
also the issue of adding new features later, which is sometimes considered a new project depending on the scope
vibe coding: AI coding with no human experience will produce a maintenance crisis
What goes into buying?
RFI → RFP → evaluation → contract
RFP: your requirements from the RDD, timeline expectations, budget parameters, vendor qualification criteria
total cost of ownership: license/subscription fees, implementation cost, training, integrations, ongoing maintenance
key contract terms to watch: SLAs, data ownership, exit clauses, price escalation caps
buying: planning phase
define project scope, objectives, and feasibility
buying: analysis phase
gather detailed requirements and analyze stakeholder needs
buying: design phase
determine the technical architecture of the solution needed to fulfill analyzed business needs
buying: development phase
actual coding and building of the system
buying: testing phase
test the system to identify and fix defects
buying: implementation phase
deploy the system to the production environment
waterfall
strengths
requirements are defined long before programming begins. inspired by engineering/construction methodologies
requirements changes are limited as the project progresses
weaknesses
must wait a long time before there is evidence of the new system
take a long time from start to finish
requirements may be overlooked at the beginning and you can’t go back to previous phases
assumes build is the right decision
iterating vs incrementing
incrementing: get a portion done then adding it on to the big project
iterating: repeating a process, refining through a set of steps to improve something