Sunday, November 3, 2019
Mergers and Acquisitions Essay Example | Topics and Well Written Essays - 2500 words
Mergers and Acquisitions - Essay Example Before this governments believed this was a nascent industry that needed its protection. However, over the last three decades the industry has become highly competitive forcing many carriers to operate on thin margins. In fact, four of the six legacy carriers filed for Chapter 11 bankruptcy over the last ten years. American Airlines and Continental were the only two that did require bankruptcy protection (Harrison, 2010). US Airways is experiencing aggressive growth which is a consequence of its recent negotiations with other firms within the market. Specifically the Delta Slot Transaction whereby US Airways entered into a mutual asset purchase and sale agreement with Delta (Esterl, 2010). Pursuant to the agreement, US Airways would transfer to Delta certain assets related to flight operations at LaGuardia Airport in New York, consisting of 125 pairs of slots currently used to provide US Airways Express service at LaGuardia. Delta is expected to transfer to US Airways certain assets related to flight operations at Washington National Airport, including 42 pairs of slots, and the authority to serve Sao Paulo, Brazil and Tokyo, Japan. The agreement is structured as asset sales and is anticipated to be cash neutral to US Airways. The net benefit to the transaction is the restructuring of U.S Airways to focus its strategy and meet the growing demand. The agreement must be approved by the U.S.à Department of Justice, the DOT, the FAA and The Port Authority of New York and New Jersey. If approved, this transaction will significantly increase US Airwaysââ¬â¢ capacity in the Washington,à D.C. market and improve profitability(Gibbons, 2007). US Airways is experiencing slow growth coupled with an improving competitive market position. This means that US Airways is going through a phase of concentrated growth. The Frequent Traveler Program is a great method for the company to focus on their local hubs and create loyal consumers in those markets. This will undermine the low transfer cost and incentivize ticket purchasing through their company. This program helps generate a loyal consumer base and helps differentiate between airline services. Focusing on this program is key to brand development for US Airways. The Dividend Miles program credits passengers who fly on US Airways and Star Alliance carriers. Credits can be redeemed for travel on US Airways or other participating partner airlines, whereby US Airways assumes the fee. The incremental cost method is used to account for the portion of frequent traveler program liability related to mileage credits earned by Dividend Miles members. This creates an obligation to provide future travel when credits are redeemed (Gross, 2007). II. Company Strategy The possibility for a merger between US Airways and American Airlines have been stifled twice before, but renewed interest in the merger possibility has been created as a result of economic re-stabilization. But the two companies are currently in me rger talks that would make US Airways the second largest airline. The industry reported a $60 billion dollar loss since 2000 which has spurred interest in consolidation. Even with the dramatic declines in capacity by airlines collectively, in recent years, experts believe that there are too many airlines and a shortage in travelers. A merger could help both increase the earnings per share in a smaller timeframe than either company can accomplish alone. The industry is
Friday, November 1, 2019
Ask ls week 2 Essay Example | Topics and Well Written Essays - 250 words
Ask ls week 2 - Essay Example These include a person, as a researcher, and other stakeholders. What are some of the things one ought to have or consider when conducting such a research? One of the most common challenges when conduction a research is personal bias which might for example in this case be attributed to the fact that the researcher had participated in previous financial services projects. In this regard, what are some ways of ensuring such bias does not affect the outcome of your research? One of the key considerations to have when conducting a research is knowledge of your chosen area of research. According to you, do you think such previous knowledge and involvement in your area of research could be of any advantage when conducting a research? If yes why and how? In order to have effective research outcomes, the researcher has to have some research skills (Coghlan and Brannick 2010). What are some of the skills that are required to have, and especially in relation to the current study? It is evident that your AR research would be faced by many challenges, more so because it involves your organization as an, AR manager and that the people to incorporate in your research are your junior officers (Greenwood and Levin 2007). In this regard, what are some of the challenges that you may encounter during your research? And how would you overcome such challenges? Having indentified the problem of women officers not progressing to management ranks at KNBS may draw some mixed reactions and especially from male counterparts. In fact, your research may be influenced by some bias and especially when dealing with gender issues (Coghlan and Brannick 2010). What are some of the research techniques required in order to avoid such bias? Before one initialises a research, there must be a motive behind the research. What are some of the issues that instigate a research? What are some of the things to consider when starting a research
Wednesday, October 30, 2019
Marketing For Non-profit Organizations Case Study
Marketing For Non-profit Organizations - Case Study Example Coming to the Political factors which can influence the museum, it was identified that the Mayor's commission on the inclusion of Asian and African settlers in London into the Heritage could play an instrumental role in deciding if the museum would get the required support from the Greater London Association (GLA) for its further needs. It could also play a role in making a political impression, which could go a long way in the museum's growth. The 2012 Olympics and its preparations were also taken into consideration while formulating the political factors. At this juncture when the Government of UK was looking forward to make rapid changes to the city of London in a big way and also promote tourism, it is an undisputable fact that the museums would directly be impacted from this move. The 2012 Olympics and the Government's preparations for it and also the modernization agenda of London would really help the museum sector in the long run. Likewise, the social factors were identified to be the literacy rate of the city, country and the constitution of the population. Around 28% of the population consisted of the Asians and Africans and it was clearly identified that there was a need to include and appreciate their services too. Hence, extensive SWOT and PEST analyses on the British museum and the museum sector as a whole and suggestions were made. Since the marketing audit is essentially divided into Internal and External m arket analyses, we classify strengths, weaknesses as the internal analysis of the museum. Likewise, we classify political, economic, social and technological factors as the external environmental condition for any organization. It is obvious that the external environment for the museum too plays a crucial role in the growth of the organization in the long run. Marketing Audit and Recommendations It is a well-known fact that the British museum in London is one of the world's greatest museums of human history and culture. Its collections, which number more than 13 million objects from all continents, illustrate and document the story of human culture from its beginning to the present. is a point of controversy whether museums should be allowed to possess artefacts taken from other countries, and the British Museum is notable target for criticism (Albert Gunther, 2003).The Elgin marbles and the Benin Bonzes are among the most disputed objects in its collections, and organisations have been formed demanding the return of both sets of artefacts to their native countries of Greece and Nigeria respectively. The British Museum has refused to return either set, or any of its other disputed items, stating that the "restitutionist premise, that whatever was made in a country must return to an original geographical site, would empty both the British Museum. The Museum has also argued th at the British Museum Act of 1963 legally prevents it from selling any of its valuable artefacts, even the ones not on display. Internal Environment Analysis The Weaknesses Lack of funds, has clearly paralyzed the prospects of development of the museum in a real big way. Under funding has clearly caused discontent among the employees of the organization. In fact there were instances when the employees had gone off their duties in order to protest the government's attitude towards the museum. At a time when
Monday, October 28, 2019
Fitts and Posners Phases of Learning Essay Example for Free
Fitts and Posners Phases of Learning Essay Describe Fitts and Posners phases of learning and explain how you would structure practises to enhance a performance In this essay I will explain Fitts and Posners phases of learning and how I would structure practises to enhance performance. By practising a skill we can become better. Fitts and Posner theories were that everyone has to go through stages of learning, known as the cognitive, associative and autonomous stages of learning. Depending how good a person is at a particular sport, they will fall into a certain category. An example of this is Wayne Rooney. At a young age he was introduced to football and played amateur football from a young age, becoming one of the youngest strikers in football history. However by learning a skill in sport involves the development of skills by practice. An example of this is shooting practise you can only become good by practising to kick the ball in between goalposts. Until a person becomes confident enough that they score a goal, they will naturally fall into the next category. The three stages of learning can be divided into two main categories; associationists and cognitivists. Associationists views learning of a sport as the link of particular stimulus and particular responses. Cognitivists see it as a function of the brain, where we learn through the understanding and knowledge of the sport. There are 3 stages of learning according to Fitts and Posner. They are: Cognitive v Associative v Autonomous Cognitive This is the initial stage of learning and is essential if the learner is to process successful through the other stages and is to move a stage where the skill can be performed. The cognitive stage involves formation of a mental picture of a skill. The most efficient way is from a demonstration, which allows them to see the key requirements and to work through the performance mentally. Visual guidance is one of the best ways to make others understand, and so that the person learning can see the correct method to perform the skill. They will then attempt to perform. Success rate is usually 2/3 out of 10. The cognitive stage initially concentrates more on the skill, rather than the game. There is a lack of control and consistency. Trial and error is also a key way to learn. Reinforcement of this can be by giving positive feedback. Questions will arise when learning skills of a sport if the skill is not correctly learnt. The learner will be confronted with some very specific, cognitively oriented problems. Examples of this are, How do I score? What is the aim of this game? If so, where are the positions for players? If the mental picture is not correct the skill will not develop. It is important that the coach explains very thoroughly what is required of each athlete. Associative Learning at the associative stage means that the skill is becoming more consistent, but there are still some errors. The simple element of the skill has been grasped however the performer still refers back to the mental picture. The performer can begin to detect errors and begin to realise his/her mistakes. Feedback should encourage a feeling of a well performed skill. This means that the performer will begin to enjoy the sport. Success rate is 5/7 out of 10. Verbal guidance is essential as it is used in the associative stage. Some people never exceed this phase. An example of this is a semi-professional shot-put thrower. Some performers return to the cognitive stage to refer to the mental image of the skill. Also, some professional players return from autonomous stage to the associative stage if they have an injury they need to work hard and rise up to the expected standard of an autonomous performer. Autonomous Learning at the autonomous stage is where the skill is done without conscious thought. The movements of the performer are fluent, consistent and athletically pleasing. There is an advanced stage of learning where the elements of the skill have become part of long term memory and are automatically produced in response to a an appropriate stimulus. The skill is automatic. The attention of the performer focuses on the next movement, for example tactics. Consistent practise is required to reinforce being at the autonomous stage. Success rate is 9/10 out of 10. In tennis for example a player would be able to perform a serve whilst contemplating what their opponent will do next, rather than being focusing on the technical side of the serve. Not all performers reach the autonomous stage in all skills. For those who do, if practise is not maintained revision to the associative stage will occur. Closed skills such as throwing events can be finely tuned so that a high level of performance can be produced. Learning in its simplest form is the development of a position where we cant perform a skill to a stage where we can perform it. Knapp, 1973 The quote means that learning is a more or less permanent change in performance brought about by experience. Knapp is suggesting that once something is learnt, it remains with us, thus supporting the statement: Once you learn to ride a bike, you never forget. Learning in sport involves the development of skills through practice, hence the saying: Practice makes perfect. Fitts Posner recognised that as we learn, we do not move directly from cant to can. They suggest that the learning process is sequential we move through specific stages/phases as we learn. These stages are hierarchal, in other words each stage must be passed through before the next one is achieved. Ivan Pavlov was a scientist who conducted experiments on the response of dogs. He taught them that when a bell was rung, the dogs would learn to understand that it was time to eat. These findings link into Fitts and Posners phases of learning because a particular response with a stimulus can give a great benefit to sports performances. This approach can be used to mentally prepare the athlete for the sport. The player may be taught switching into the zone whilst walking onto the pitch. However in order to achieve this, the player would need to gradually progress to that level of conditioned stimulus. In order to teach and improve somebodys skills at a sport, I would structure a 6 week Personal Exercise Programme (or PEP). A PEP would help improve the skill of the performer, and help the learner to enhance their performance. This way the performer can test to see how long it takes him to master one specific skill. As a trainer I would encourage the performer and give feedback and give a clear understanding to the performer what they are doing right and wrong. Doing something wrong doesnt mean its negative feedback it would just acknowledge the performer on how to improve, becoming more successful. I would ensure that the performer practices the skill consistently and monitor any improvements in their ability. In a professional football match I would help keep the players to the standard that is required by making them do drills as a team. Warm-ups are essential as they prevent muscles getting damaged. I would also make sure that the stamina of the players is always high; this can be achieved by the Cooper run. In a tennis match the athlete must be able to complete a full match. There are no substitutions so the athletes stamina must be high. By hitting a ball for a long period of time every other turn there must be a large amount of upper body strength. In order to help the athlete achieve this, the coach should set the athlete physical training such as sprints, press-up, sit-ups and bicep curls. Technique is needed when serving, volleying; as being able to retain balance quickly is essential. An example of this is Andre Agassi. he focused more on physical conditioning than in the past and became one of the fittest players on the tour. His upper-body strength allowed him to bench press 350 lb (159 kg), which helped him retain pace on his shots late into a match, as well as adding to his serve power. He had remarkable endurance and rarely appeared tired on court. Golf is a sport where the athlete has to be very concentrated on the game. Having a perfect technique allows one to compete to a high level. In order to help raise concentration levels the coach must remove all apprehension and put the athlete in a confident frame of mind. To help an athlete raise concentration before a game the coach could give the athlete a structured diet. Junk food will slow down the concentration rate. Tiger Woods had a bad putting strike so he went home and perfected it. Well, thats one of the worst putting weeks Ive had in a long time, very frustrating. When I get home I am going to practise until I get it right. References: * Advanced P.E for Edexcel Heinemann * http://nobelprize.org/educational_games/medicine/pavlov/readmore.html. * http://www.answers.com/topic/andre-agassi * http://www.asapsports.com/show_interview.php?id=410149
Saturday, October 26, 2019
Cunstract, Intirnel, end Extirnel Velodoty :: dete, ivodinci, stady
Cunstract velodoty hes tu du woth istebloshong currict upiretounel miesaris fur thi cuncipts biong stadoid (Yon 2009, p. 40). Yon (2009), wrotis thet risierchirs cen ompruvi cunstract velodoty cunstract velodoty cen bi of maltopli suarcis uf dete os impluyid (troengaletoun uf dete), istebloshong cheon uf ivodinci, end rivoiwong thi ripurt woth thior onfurments (p. 41). In mekong sari thet uni cen drew e mienong end asifal onfirincis frum scuris un pertocaler onstramints uf dete cullictoun end tu dimunstreti thi eccarecy uf thior fondongs, Criswill (2013) elsu edvoci thi asi uf mimbir chickong end troengaletong dete (p. 201). Qaerm (2009) end Serqaeh (2008) buth asid sivirel dete suarcis (ontirvoiws, ducamints, midoe, end ontirnit) on thior stadois. Thi troengaletoun uf dete suarcis on thior stadois elluw fur sivirel ivodinci tu bi cullictid un thior cesis andir stady, cuncipts ur veroeblis wiri clierly end pricosily ixpleonid end upiretounelozid. Thos privintid oneccarecois end embo gaotois darong thi foild stady end elluwid fur lergi vulami uf dete tu bi cullictid end asid by buth onqaorirs. Bat buth ergaid thet dai tu tomi end fonencoel cunstreonts, thiy cuald nut rivoiw thi dete cullictid woth kiy onfurments tu currict eny mosteki, oneccarecois, clerofocetouns whoch tu sumi ixtint thrietinid thi velodoty uf thior stadois. 8.2 Intirnel Velodoty Thos rifirs tu istebloshong e ceasel riletounshop, whiriby cirteon cundotouns eri shuwn tu lied tu uthir cundotouns (Yon, 2009, p.40). Thi guel uf siikong tu isteblosh ceaseloty os muri ivodint on ixplenetury ur ceasel stadois rethir then discroptovi ur ixpluretury stadois (obod). Thos os dai tu thi lomotid cuntrul risierchirs hevi uvir ixtreniuas ur andisorebli veroeblis thet onflainci thi riletounshop bitwiin thi veroeblis. Estebloshong ceaseloty cen bi ompruvi darong thi dete enelysos stegi whiri thi risierchir niid tu du pettirn metchong, ixplenetoun baoldong, eddriss rovel thiurois end thi asi uf lugoc mudils (p.41). Buth Qaerm (2009) end Serqaeh (2008) stadois dod nut siik tu isteblosh ceaseloty bitwiin thior ondipindint end dipindint veroeblis. Buth stadois eri seod tu bi ixpluretury on netari. Fur ixempli, Qaerm (2009) stady siik tu discrobi thi meon ecturs end thi stretigois thiy impluyid tu pash thi dumistoc voulinci boll untu thi guvirnmint eginde fur ettintoun whiries Ser qaeh (2008) stady siik tu discrobi thi meon fecturs effictong thi omplimintetoun uf thi foscel dicintrelozetoun pulocy on Akaepim Suath dostroct uf Ghene. 8.3 Extirnel Velodoty Yon (2009) difonis ixtirnel velodoty es istebloshong thi dumeon tu whoch e stadyââ¬â¢s fondongs cen bi ginirelozid biyund thi ommidoeti cesi stady (p.
Thursday, October 24, 2019
Access Control Proposal Essay
Access control: type of access control by which the operating system constrains the ability of a subject or initiator to access or generally perform some sort of operation on an object or target. In practice, a subject is usually a process or thread; objects are constructs such as files, directories, TCP/UDP ports, shared memory segments, IO devices etc. Subjects and objects each have a set of security attributes. Whenever a subject attempts to access an object, an authorization rule enforced by the operating system kernel examines these security attributes and decides whether the access can take place. Any operation by any subject on any object will be tested against the set of authorization rules (aka policy) to determine if the operation is allowed. A database management system, in its access control mechanism, can also apply mandatory access control; in this case, the objects are tables, views, procedures, etc. With mandatory access control, this security policy is centrally controlled by a secu rity policy administrator; users do not have the ability to override the policy and, for example, grant access to files that would otherwise be restricted. By contrast, discretionary access control (DAC), which also governs the ability of subjects to access objects, allows users the ability to make policy decisions and/or assign security attributes. (The traditional UNIX system of users, groups, and read-write-execute permissions is an example of DAC.) MAC-enabled systems allow policy administrators to implement organization-wide security policies. Unlike with DAC, users cannot override or modify this policy, either accidentally or intentionally. This allows security administrators to define a central policy that is guaranteed (in principle) to be enforced for all users. Historically and traditionally, MAC has been closely associated with multi-level secure (MLS) systems. The Trusted Computer System Evaluation Criteria[1] (TCSEC), the seminal work on the subject, defines MAC as ââ¬Å"a means of restricting access to objects based on the sensitivity (as represented by a label) of the information containedà in the objects and the formal authorization (i.e., clearance) of subjects to access information of such sensitivityâ⬠. Early implementations of MAC such as Honeywellââ¬â¢s SCOMP, USAF SACDIN, NSA Blacker, and Boeingââ¬â¢s MLS LAN focused on MLS to protect military-oriented security classification levels with robust enforcement. Originally, the term MAC denoted that the access controls were not only guaranteed in principle, but in fact. Early security strategies enabled enforcement guarantees that were dependable in the face of national lab level attacks. Data classification awareness: For any IT initiative to succeed, particularly a security-centric one such as data classification, it needs to be understood and adopted by management and the employees using the system. Changing a staffââ¬â¢s data handling activities, particularly regarding sensitive data, will probably entail a change of culture across the organization. This type of movement requires sponsorship by senior management and its endorsement of the need to change current practices and ensure the necessary cooperation and accountability. The safest approach to this type of project is to begin with a pilot. Introducing substantial procedural changes all at once invariably creates frustration and confusion. I would pick one domain, such as HR or R&D, and conduct an information audit, incorporating interviews with the domainââ¬â¢s users about their business and regulatory requirements. The research will give you insight into whether the data is business or personal, and whether it is business-critical. This type of dialogue can fill in gaps in understanding between users and system designers, as well as ensure business and regulatory requirements are mapped appropriately to classification and storage requirements. Issues of quality and data duplication should also be covered during your audit. Categorizing and storing everything may seem an obvious approach, but data centers have notoriously high maintenance costs, and there are other hidden expenses; backup processes, archive retrieval and searches of unstructured and duplicated data all take longer to carry out, for example. Furthermore, too great a degree of granularity in classification levels can quickly become too complex and expensive. There are several dimensions by which data can be valued, including financial orà business, regulatory, legal and privacy. A useful exercise to help determine the value of data, and to which risks it is vulnerable, is to create a data flow diagram. The diagram shows how data flows through your organization and beyond so you can see how it is created, amended, stored, accessed and used. Donââ¬â¢t, however, just classify data based on the application that creates it, such as CRM or Accounts. This type of distinction may avoid many of the complexities of data classification, but it is too blunt an approach to achieve suitable levels of security and access. One consequence of data classification is the need for a tiered storage architecture, which will provide different levels of security within each type of storage, such as primary, backup, disaster recovery and archive ââ¬â increasingly confidential and valuable data protected by increasingly robust security. The tiered architecture also reduces costs, with access to current data kept quick and efficient, and archived or compliance data moved to cheaper offline storage. Security controls Organizations need to protect their information assets and must decide the level of risk they are willing to accept when determining the cost of security controls. According to the National Institute of Standards and Technology (NIST), ââ¬Å"Security should be appropriate and proportionate to the value of and degree of reliance on the computer system and to the severity, probability and extent of potential harm. Requirements for security will vary depending on the particular organization and computer system.â⬠1 To provide a common body of knowledge and define terms for information security professionals, the International Information Systems Security Certification Consortium (ISC2) created 10 security domains. The following domains provide the foundation for security practices and principles in all industries, not just healthcare: Security management practices Access control systems and methodology Telecommunications and networking security Cryptography Security architecture and models Operations security Application and systems development security Physical security Business continuity and disaster recovery planning Laws, investigation, and ethics In order to maintain information confidentiality, integrity, and availability, it is important to control access to information. Access controls prevent unauthorized users from retrieving, using, or altering information. They are determined by an organizationââ¬â¢s risks, threats, and vulnerabilities. Appropriate access controls are categorized in three ways: preventive, detective, or corrective. Preventive controls try to stop harmful events from occurring, while detective controls identify if a harmful event has occurred. Corrective controls are used after a harmful event to restore the system. Risk mitigation Assume/Accept: Acknowledge the existence of a particular risk, and make a deliberate decision to accept it without engaging in special efforts to control it. Approval of project or program leaders is required. Avoid: Adjust program requirements or constraints to eliminate or reduce the risk. This adjustment could be accommodated by a change in funding, schedule, or technical requirements. Control: Implement actions to minimize the impact or likelihood of the risk. Transfer: Reassign organizational accountability, responsibility, and authority to another stakeholder willing to accept the risk Watch/Monitor: Monitor the environment for changes that affect the nature and/or the impact of the risk Access control policy framework consisting of best practices for policies, standards, procedures, Guidelines to mitigate unauthorized access : IT application or program controls are fully automated (i.e., performed automatically by the systems) designed to ensure the complete and accurate processing of data, from input through output. These controls vary based on the business purpose of the specific application. These controls may also help ensure the privacy and security of data transmitted between applications. Categories of IT application controls may include: Completeness checks ââ¬â controls that ensure all records were processed from initiation to completion. Validity checks ââ¬â controls that ensure only valid data is input or processed. Identification ââ¬â controls that ensure all users are uniquely and irrefutably identified. Authentication ââ¬â controls that provide an authentication mechanism in the application system. Authorization ââ¬â controls that ensure only approved business users have access to the application system. Input controls ââ¬â controls that ensure data integrity fed from upstream sources into the application system. Forensic controls ââ¬â control that ensure data is scientifically correct and mathematically correct based on inputs and outputs Specific application (transaction processing) control procedures that directly mitigate identified financial reporting risks. There are typically a few such controls within major applications in each financial process, such as accounts payable, payroll, general ledger, etc. The focus is on ââ¬Å"keyâ⬠controls (those that specifically address risks), not on the entire application. IT general controls that support the assertions that programs function as intended and that key financial reports are reliable, primarily change control and security controls; IT operations controls, which ensure that problems with processing are identified and corrected. Specific activities that may occur to support the assessment of the key controls above include: Understanding the organizationââ¬â¢s internal control program and its financial reporting processes. Identifying the IT systems involved in the initiation, authorization, processing, summarization and reporting of financial data; Identifying the key controls that address specific financial risks; Designing and implementing controls designed to mitigate the identified risks and monitoring them for continued effectiveness; Documenting and testing IT controls; Ensuring that IT controls are updated and changed, as necessary, to correspond with changes in internal control or financial reporting processes; and Monitoring IT controls for effective operation over time. References : http://hokiepokie.org/docs/acl22003/security-policy.pdf Coe, Martin J. ââ¬Å"Trust services: a better way to evaluate I.T. controls: fulfilling the requirements of section 404.â⬠Journal of Accountancy 199.3 (2005): 69(7). Chan, Sally, and Stan Lepeak. ââ¬Å"IT and Sarbanes-Oxley.â⬠CMA Management 78.4 (2004): 33(4). P. A. Loscocco, S. D. Smalley, P. A. Muckelbauer, R. C. Taylor, S. J. Turner, and J. F. Farrell. The Inevitability of Failure: The Flawed Assumption of Security in Modern Computing Environments. In Proceedings of the 21st National Information Systems Security Conference, pages 303ââ¬â314, Oct. 1998. Access Control Proposal Essay Proposal Statement Integrated Distributors Incorporated (IDI) will establish specific requirements for protecting information and information systems against unauthorised access. IDI will effectively communicate the need for information and information system access control. Purpose Information security is the protection of information against accidental or malicious disclosure, modification or destruction. Information is an important, valuable asset of IDI which must be managed with care. All information has a value to IDI. However, not all of this information has an equal value or requires the same level of protection. Access controls are put in place to protect information by controlling who has the rights to use different information resources and by guarding against unauthorised use. Formal procedures must control how access to information is granted and how such access is changed. This policy also mandates a standard for the creation of strong passwords, their protection and frequency of change. See more:à Perseverance essay Scope This policy applies to all IDI Stakeholders, Committees, Departments, Partners, Employees of IDI (including system support staff with access to privileged administrative passwords), contractual third parties and agents of the Council with any form of access to IDIââ¬â¢s information and information systems. Definition Access control rules and procedures are required to regulate who can access IDI information resources or systems and the associated access privileges. This policy applies at all times and should be adhered to whenever accessing IDI information in any format, and on any device. Risks On occasion business information may be disclosed or accessed prematurely, accidentally or unlawfully. Individuals or companies, without the correct authorisation and clearance may intentionally or accidentally gain unauthorised access to business information which may adversely affect day to day business. This policy is intended to mitigate that risk. Non-compliance with this policy could have a significant effect on the efficient operation of the Council and may result in financial loss and an inability to provide necessary services to our customers. Applying the Policy ââ¬â Passwords / Choosing Passwords Passwords are the first line of defence for our ICT systems and together with the user ID help to establish that people are who they claim to be. A poorly chosen or misused password is a security risk and may impact upon the confidentiality, integrity or availability of our computers and systems. Weak and strong passwords A weak password is one which is easily discovered, or detected, by people who are not supposed to know it. Examples of weak passwords include words picked out of a dictionary, names of children and pets, car registration numbers and simple patterns of letters from a computer keyboard. A strong password is a password that is designed in such a way that it is unlikely to be detected by people who are not supposed to know it, and difficult to work out even with the help of a Protecting Passwords It is of utmost importance that the password remains protected at all times. Do not use the same password for systems inside and outside of work. Changing Passwords All user-level passwords must be changed at a maximum of every 90 days, or whenever a system prompts you to change it. Default passwords must also be changed immediately. If you become aware, or suspect, that your password has become known to someone else, you must change it immediately and report your concern to IDI Technical Support. Users must not reuse the same password within 20 password changes. System Administration Standards The password administration process for individual IDI systems is well-documented and available to designated individuals. All IDI IT systems will be configured to enforce the following: Authentication of individual users, not groups of users ââ¬â i.e. no generic accounts. Protection with regards to the retrieval of passwords and security details. System access monitoring and logging ââ¬â at a user level. Role management so that functions can be performed without sharing passwords. Password admin processes must be properly controlled, secure and auditable. User Access Management Formal user access control procedures must be documented, implemented and kept up to date for each application and information system to ensure authorised user access and to prevent unauthorised access. They must cover all stages of the lifecycle of user access, from the initial registration of new users to the final de-registration of users who no longer require access. These must be agreed by IDI. User access rights must be reviewed at regular intervals to ensure that the appropriate rights are still allocated. System administration accounts must only be provided to users that are required to perform system administration tasks. User Registration A request for access to IDIââ¬â¢s computer systems must first be submitted to the Information Services Helpdesk for approval. Applications for access must only be submitted if approval has been gained from Department Heads. When an employee leaves IDI, their access to computer systems and data must be suspended at the close of business on the employeeââ¬â¢s last working day. It is the responsibility of the Department Head to request the suspension of the access rights via the Information Services Helpdesk. User Responsibilities It is a userââ¬â¢s responsibility to prevent their userID and password being used to gain unauthorised access to IDI systems. Network Access Control The use of modems on non- IDI owned PCââ¬â¢s connected to the IDIââ¬â¢s network can seriously compromise the security of the network. The normal operation of the network must not be interfered with. User Authentication for External Connections Where remote access to the IDI network is required, an application must be made via IT Helpdesk. Remote access to the network must be secured by two factor authentication. Supplierââ¬â¢s Remote Access to the Council Network Partner agencies or 3rd party suppliers must not be given details of how to access IDI ââ¬â¢s network without permission. All permissions and access methods must be controlled by IT Helpdesk. Operating System Access Control Access to operating systems is controlled by a secure login process. The access control defined in the User Access Management section and the Password section above must be applied. All access to operating systems is via a unique login id that will be audited and can be traced back to each individual user. The login id must not give any indication of the level of access that it provides to the system (e.g. administration rights). System administrators must have individual administrator accounts that will be logged and audited. The administrator account must not be used by individuals for normal day to day activities. Application and Information Access Access within software applications must be restricted using the security features built into the individual product. The IT Helpdesk is responsible for granting access to the information within the system. Policy Compliance If any user is found to have breached this policy, they may be subject to IDIââ¬â¢s disciplinary procedure. If a criminal offence is considered to have been committed further action may be taken to assist in the prosecution of the offender(s). If you do not understand the implications of this policy or how it may apply to you, seek advice from IT Helpdesk. Policy Governance The following table identifies who within [Council Name] is Accountable, Responsible, Informed or Consulted with regards to this policy. The following definitions apply: Responsible Head of Information Services, Head of Human Resources Accountable Director of Finance etc. Consulted Policy Department Informed All IDI Employees, All Temporary Staff, All Contractors. Review and Revision This policy will be reviewed as it is deemed appropriate, but no less frequently than every 12 months. Key Messages All users must use strong passwords. Passwords must be protected at all times and must be changed at least every 90 days. User access rights must be reviewed at regular intervals.à It is a userââ¬â¢s responsibility to prevent their userID and password being used to gain unauthorised access to IDI systems. Partner agencies or 3rd party suppliers must not be given details of how to access the IDI network without permission from IT Helpdesk. Partners or 3rd party suppliers must contact the IT Helpdesk before connecting to the IDI network. Access Control Proposal Essay 1 INTRODUCTION 1.1 Title of the project Access Control Proposal Project for IDI 1.2 Project schedule summary The project will be a multi-year phased approach to have all sites (except JV and SA) on the same hardware and software platforms. 1.3 Project deliverables â⬠¢ Solutions to the issues that specifies location of IDI is facing â⬠¢ Plans to implement corporate-wide information access methods to ensure confidentiality, integrity, and availability â⬠¢ Assessment of strengths and weaknesses in current IDI systems â⬠¢ Address remote user and Web site userââ¬â¢s secure access requirements â⬠¢ Proposed budget for the projectââ¬âHardware only â⬠¢ Prepare detailed network and configuration diagrams outlining the proposed change 1.4 Project Guides Course Project Access Control Proposal Guide Juniper Networks Campus LAN Reference Architecture 1.5 Project Members David Crenshaw, IT Architect and IT Security Specialist Members of the IT Staff 1.6 Purpose A proposal for improving IDIââ¬â¢s computer network infrastructure is the purpose for this proposal. This project is intended to be used by IDIââ¬â¢s information security team to developing a plan to improve IDIââ¬â¢s computer network infrastructure at multiple locations. 1.7 Goals and Objectives Objective 1 To assess the aging infrastructure and then develop a multi-year phased approach to have all sites (except for JV and SA) on the same hardware and software platforms. Objective 2 The core infrastructure (switches, routers, firewalls, servers and etc.) must capable of withstanding 10 ââ¬â 15% growth every year for the next seven years with a three-to-four year phased technology refresh cycle. Objective 3 Solutions to the issues that the specifies location of IDI is facing Objective 4 Assessment of strengths and weaknesses in current IDI systems Objective 5 Address remote user and Web site userââ¬â¢s secure access requirements Objective 6 Prepare detailed network and configuration diagrams outlining the proposed change Objective 7 Prepare a 5 to 10 minute PowerPoint assisted presentation on important access control infrastructure, and management aspects from each location. Objective 8 A comprehensive network design that will incorporate all submitted requirements and allow for projected growth. Objective 9 Final testing of all installed hardware, software, and network connectivity. Objective 10 Initialization of the entire network and any last minute configuration adjustments to have the network up and operating within all specified ranges. 2 Current Environment 2.1 Overall: There are a variety of servers, switches, routers, and internal hardware firewalls. Each of the organizationââ¬â¢s locations is operating with different information technologies and infrastructureââ¬âIT systems, applications, and databases. Various levels of IT security and access management have been implemented and embedded within their respective locations. The information technology infrastructure is old and many locations are running on outdated hardware and software. Also, the infrastructure is out dated in terms ofà patches and upgrades which greatly increase the risk to the network in terms of confidentiality, integrity, and availability. 2.2 Data Center: Logisuite 4.2.2 has not been upgraded in almost 10 years. Also, numerous modifications have been made to the core engine and the license agreement has expired. Progressive upgrading to the current version will be required. As a result, renewing this product will be extremely cost and time-prohibitive. RouteSim is a destination delivery program used to simulate routes, costs, and profits. It is not integrated into Logisuite or Oracle financials to take advantage of the databases for real-time currency evaluation and profit or loss projections. IDIââ¬â¢s office automation hardware and software has not been standardized. Managers have too much liberty to buy what they want according to personal preferences. Other software problems include early versions of MS Office 5, WordPerfect 7.0, and PC-Write that are not compatible. Telecommunications has not been since the company moved its current headquarters 15 years ago. This has left many of the new features for telecommunications lacking and not integrated with the customer service database to improve call management efficiency. The generic system was acquired from a service provider who is now out of business. Policies for personal devices are being ignored by many of the executives who have local administrators install the clients on their unsupported, non-standard personal laptop computers and workstations that interface with the internet. The original WAN was designed in the early 2000ââ¬â¢s and has not been upgraded. During peak periods, usually between September and March, the capacity is insufficient for the organization resulting in lost internet customers whichà further reduces growth and revenue. Telecommunications works through a limited Mitel SX-2000 private automatic branch exchange (PABX) that only provides voice mail and call forwarding. 2.3 Warsaw, Poland This is the largest office based on number of employees, strategically located to assist IDI for major growth in the Middle East and Asia, and the home portal for expansion and geographical client development, yet there is insufficient computing power to stay afloat on a day-to-day basis. The primary freight forwarding application is almost 10 years old and does not interface with the McCormack dodge accounting and finance system There are 6 Web servers (4 are primary and 2 fail during clustered load balancing) The cafeteria sponsors a public wireless network running WPA (Wi-Fi Protected Access) with no password protection. Telecommunications is an 8 year old Siemens Saturn series PBX, some of whose features have become faulty. The desktop phones have not been replaced or upgraded during this time. There is a lack of separation of duties between the network operations and the accounts receivable department and there is evidence of nepotism and embezzlement. 2.3 Sao Paulo, Brazil Vendors are unwilling to sign a service agreements.
Wednesday, October 23, 2019
Arthur Miller Essay
An important theme in Arthur Millerââ¬â¢s play ââ¬Å"All My Sonsâ⬠is the responsibility a man has for another man. Miller stressed that people must be held accountable for their actions to society and they will be held accountable by the inevitable justice found in the universe: karma. This theme is expressed through action as well as characters throughout the entire play; it is subtle at first but slowly becomes more prominent until Joe Keller finally realizes exactly how his actions affected people outside of his family. To begin, Kellerââ¬â¢s character is important to the theme because he represents the opposite of being responsible for his actions and being held accountable to society. Joe Keller seems like a simple kind of man. His greatest wishes are to obtain the American dream for his wife and to create a legacy to pass on to his son. However, he harbors a dark secret that explains how he achieved those dreams for his family- he knowingly shipped out faulty airplane parts during wartime. Up until the time of the play, Keller did not believe he did a terrible thing by shipping those parts out. As he explains, when he came home from jail he was like an expert on the ââ¬Å"whole jail thingâ⬠and, over time, the children ââ¬Å"got it confused andâ⬠¦ [he] ended up a detectiveâ⬠(29). Or, more clearly, he went from being the bad guy to being the good guy. In Kellerââ¬â¢s mind, he was the good guy because he saved his family from being poor and having their reputations in the gutter. He says to his wife, ââ¬Å"you wanted money, so I made moneyâ⬠(76). To him, he simply did what he had to do to protect and take care of his family. At that point in his life he was not able to see the big picture of things; he was only able to see one little contour, just one small piece, of what makes up the universe. Furthermore, it is evident that Kellerââ¬â¢s small piece of the universe, his family, is what is most important to him. Throughout the play he tells Chris that everything he has done with the business , including sending out cracked gear heads, was for Chris: ââ¬Å"it was a chance and I took it for youâ⬠(70). Keller believed that he had to send out those parts so that he would still have a business to pass on to his son. Chris replies ââ¬Å"what is that, the world- the business?â⬠(70). He is asking his father if the whole world is the business. And the answer in Kellerââ¬â¢s mind is, as long as it takes care of his family, yes it is the world. Slowly, though, Keller begins to see just what his actions have caused to happen to other people. Take, for example, when he speaks to Ann about her father, Steve. He finds out that Ann and George never visit Steve in jail and that they donââ¬â¢t even write to him. Keller is unable to understand why the children would ââ¬Å"crucifyâ⬠their father and he pleads with Ann to not ââ¬Å"make a murderer out of himâ⬠(32). He realizes that Steveââ¬â¢s life was ruined and his relationships with his children, something that Keller gives very high value to, are ruined as well. It is also easy to believe that Keller doesnââ¬â¢t want to see Steve crucified because if he is, that means that Keller should be too. And if Keller was punished for his actions, that means there is ââ¬Å"something biggerâ⬠in the world than the relationship between father and son. The whole ordeal with Steve and Steveââ¬â¢s children gives Keller a clue that there may be bigger things in the world than familial relationships and also that there may be consequences to wrongful actions. Finally, Chris and Larry (posthumously) work to enlighten Keller that ââ¬Å"thereââ¬â¢s a universe of people outside and that [heââ¬â¢s] responsible to itâ⬠(84). Chrisââ¬â¢ character alone serves as a guidepost to this revelation. He is the epitome of the idea of responsibility and accountability to society because he is the person that reaches for something he wants but pulls ââ¬Å"back because other people will sufferâ⬠(16). Chris takes other peopleââ¬â¢s feelings and well-being into account before he acts. He learned to be so self-less in the war, as he watched his men kill themselves for each other. He describes it as ââ¬Å"a kind ofâ⬠¦ responsibility. Man for manâ⬠(35-36). He learned that you cannot only look out for yourself in this world, but you have to help other people out as well. And Larry, whom Keller thought shared his ideas on the way the world was made (with a ââ¬Å"forty-foot frontâ⬠), had a good sense that people must consider the good of the many before they act for the few. It is his letter to Ann, in which he states he ââ¬Å"canââ¬â¢t bear to live anymoreâ⬠(83) because of what his father did, that brings everything crashing down around Keller. In the same way Larryââ¬â¢s memorial tree came crashing down and allowed more light to shine into the arbor, his letter shined light onto the true ways of the universe. Everything that Keller stood for, everything he believed in was wrong. He finally realized that he did a terrible thing that killed not only strangers, but people who were fathers, brothers, and sons. In essence, he killed the thing he lives for; he killed family. This revelation drives home the idea that justice will inevitably be brought to the wrong-doers. Kellerââ¬â¢s karma comes back and makes him not only set everything right in the universe again but pay the ultimate price for his actions: death by his own hand. Chris, Ann, and Kate can now move forward, not bogged down by shame and guilt, and they can ââ¬Å"live.ââ¬
Subscribe to:
Posts (Atom)