
An investigation into current system development trends, including a summary of projects, platforms, and tools. The majority of projects get completed on time and within budget, but 14 percent still present problems. The choice of tools appears to be changing to represent the demand for new projects on new platforms—particularly the Internet. CASE tools are used sparingly, and Java is beginning to replace C++ in many projects. Database management systems are critical to almost all projects.
Top management support has long been conceivable as an important factor for the success of IS projects. Due to the hierarchical nature of an organization, a cross-level interaction can occur among nested levels. Thus, using inappropriate statistical analysis can cause misleading results and lost of information. This study provides two contributions to the IS research. First, Hierarchical Linear Modeling (HLM) was used to explain the cross-level interaction between organizational level and industry level. Second, unlike other studies focusing on an organizational level, this study considers top management support at the industry level and examines the mediating role of top management support between the two levels.
This study explores factors associated with the acceptance of Wireless Internet via Mobile Technology (WIMT) in China. The results indicate that the acceptance of WIMT is related to the factors of perceived usefulness, perceived ease of use, social influences, wireless trust environment, and facilitating conditions. It provides diagnostic insight into how different factors influence user intention to accept WIMT in China, and thus help business develop strategy to prompt WIMT communications and mobile commerce there.
Both industry leaders and government officials around the globe are struggling with how to address online privacy. One solution suggested by both groups within the United States is for companies to voluntarily comply with the fair information practices of Notice, Choice, Access, and Security. A content analysis of the online privacy policies of the firms in the Fortune Global 100 was conducted to determine the extent to which the most successful global companies comply with fair information practices. The results indicate that 1.2% fully complies, 87.2% partially comply and 11.6% fail to comply with one or more fair information practice.
The growing use of the Web for business-to-business transactions means corporate Web sites could be used to communicate with diverse suppliers. This study compares the Web-based supplier diversity content on Fortune 500 public sites with the content of off-line minority supplier programs. Web sites are underused for communicating with diverse suppliers, as the content appears on only 12.5% of the sites. They emphasize information publishing because the most common Web-based supplier diversity items are contact information, such as a title and name, and third-party certification. Web-based supplier diversity content, however, is very similar to off-line diversity program content.
Home healthcare industry is facing increasing pressure to change business processes and manage information flow electronically. With the help of a case example, this paper describes how a web- based system could improve the workflow communication problems in home healthcare companies. Every department of the case company has its own software to assist in everyday operations but is unable to communicate with one another electronically. All documents necessary in the coordination of care have to move physically between departments. The proposed solution is a web-based electronic form management system that would improve regulatory compliance and operating efficiency.
Due to the increasing service component of information technology, service quality measurement has become increasingly important as IS practitioners attempt to increase service quality to customers. The measurement of service quality in IS evolved from the research done in the marketing literature. The SERVQUAL instrument has evolved to become the most commonly used measurement instrument in both IS and marketing. Although commonly used, the SERVQUAL instrument is not without criticism. This paper describes the SERVQUAL instrument, its criticisms and support, and finally the SERVPERF instrument, a variation of the SERVQUAL instrument which is an attempt at improving upon the SERVQUAL instrument.
Knowledge Management (KM) has become a key business strategy. KM involves the systematic mapping, harvesting, storing, sharing, maintaining, and refreshing knowledge from many sources. An Electronic Performance Support System (EPSS) can perform an essential role of encapsulating and delivering knowledge at the time needed. Expanding globalization and reliance on distributed knowledge means that the EPSS delivered via networks should have a high priority. We present an argument to show the linkage between components of a KM system and EPSS. The approach involves the creation of software that is designed to assist decision makers and performers while they accomplish organizational processes.
Trade journals and magazines define three categories of computer certification: "professional, " industry, " and "vendor. " The purpose of this study was to compare Information Systems fIS) professionals' value of professional and vendor certification types in relation to technical and management positions in IS. It appears that IS professionals value both certification types equally when not considering job position. Findings suggest technical and managerial IS professionals value the two types of certifications differently when job position is considered. Future research is warranted to determine why the respondents considered these two certifications differently for both technical (programmers and analysts) and managerial positions. With the emergence of new computer teehnology, certification programs have become pievalent in the Information Technology (IT) profession. There appears to be three major categories of computer certification: professional, industrial, and vendor. Professional certifieation means the confirmation by an organization or profession that a person has the knov/ledge and experienee neeessary to work in that profession (Long and Kishchuk, 1997). An example is the designation of Certified Computer Professional (CCP), awarded by the Institute of Certified Computer Professionals (ICCP). Topics covered in the CCP are: human and oi:g£uii2;ation framework, systems eoneepts, data and information, systems development, technology, and associated disciplines. Renewal of the CCP requires 120 continuing education hours every three years. Such an increase in education increases computer usage (Igbaria, M and Zinatelli, N and Cavaye, A., 1998). The second category is vendor certification. Certifications of technical skills are vendors]]ecific (Filipczak, 1995; MeGrath, 1998). Examples are Novell's CNE, Microsoft's MSCE, and Cisco's CCNA. Some of the topies covered are: technical procedures, administration of the sy stem, and the management of users. Renewal of these eertifications generally is required when INTRODUCTION 73 1 White and Cook: Vendor and Professional Certification Where is it Headed? Published by CSUSB ScholarWorks, 2003 Journal of International Technoloev & Information Manaeement Volume 12. Number 2 a new version of the product comes out. Certificate holders must pass an upgrade exam every two or three years. A third category is industry certification. This is a generic certification for computer trade/technical skills that is sponsored by a not-for-profit organization. Examples are the A+ and i-Net+ certifications &om the Computing Technology Industry Association (CompTIA). These certifications focus on generic skills for hardware/operating systems. No specific vendor is stressed. This category was not considered for this study because it is similar to the technical skills found in vendor certifications. The attitude of clients and employers is the major piece of information that is missing for a rational decision on certification (Long and Kishchuk, 1997). It is the clients who -will increase the demand for evaluation in general, and it is the employers who will decide how much preference they will give to someone with the designation (Long and Kishchuk, 1997). Past literature from industry has focused on the value for vendor certification. However, such literature is primarily opinions. A preliminary study, using 29 respondents from industry, showed vendor certifications were valued strongly for technical positions, and both certifications were valued equally, when a specific job position, such as a technical IT position or a managerial position, was not considered (White, 2002). This limited pilot survey by the authors indicated that there was potential for some interesting findings related to the two types of certifications, since there was no evidence in the literature of any prior empirical research in this area. The purpose of this study is to compare technical and managerial IS professionals' value of these two certification types in relation to technical and management positions. Four questions this paper will answer are: (1) Do IS professionals value each type of certification, professional and vendor, equally when not considering job position? (2) Do IS professionals value all certification types equally when hiring IS managers versus IS technicians (programmers and analysts)? (3) Do IS professionals value each type of certification equally when hiring IS technicians (programmers and analysts)? (4) Do IS professionals value professional and vendor certifications equally when hiring IS managers? The decision to hire an applicant with a certification is generally made by managers with input from the technical staff. For this reason, the technical and managerial professionals surveyed are considered as employers in this paper. 74 2 Journal of International Information Management, Vol. 12 [2003], Iss. 2, Art. 6 http://scholarworks.lib.csusb.edu/jiim/vol12/iss2/6 Prnfps>:innal Certifirntinn Journal of International Technolosv & Information Management
This study presents findings about perceptions and use of Electronic Data Inter change (EDI) in Taiwan. It was undertaken to help build a framework within which to better understand EDI in a global setting. Findings indicate that there are differences and similarities between perceptions and use of EDI in Taiwan and what we know about EDI use in Western cultures. Possible explanations are offered for these findings. Several re search questions arise out of the findings that can guide future research about EDI in a variety of cultures, and sets of propositions for each research question are suggested.
During the e-Commerce boom of the late 1990s it was predicted that the Internet would have a significant impact on prices of various goods and services. Whether the net impact would he p ositive or negative was harder to forecast, there being opposing effects. We develop a model that describes some of those effects, including information asymmetry, search costs, price dispersion, trust premiums, and convenience premiums. The model is discussed, and a major portion is statistically tested with empirical data. As an exploratory gesture, the model is extended to consider product quality effects of online shopping. The final section concludes with direction for future research.
It is a rare day when the Wall Street Journal does not include an announcement that a company is taking a restructuring charge. Nowadays it is often assumed that this charge is being taken for the purpose of managing earnings. The problems associated with earnings management are not limited to Wall Street but can be found throughout the world's financial markets. Ongoing developments in artificial intelligence technology hold considerable promise for helping monitor and detect financial fraud and abuse. The objective of this paper is twofold: first, to illustrate how neural nets, a branch of artificial intelligence, can be used to analyze the impact of corporate restructuring announcements on stock performance and second, to propose the need for a balanced approach using both tighter accounting standards and ex-post analysis for better control of excessive earnings management practices. A company taking a restructuring charge will record an expense, generally an estimate, and will set up a reserve for a like amount. A classic example is the technique used by a firm when it sells an operating unit. It is very likely that the sale will result in a one-time gain that could cause a spike in earnings. To avoid this, the firm will record a restructuring charge in an amount that approximates the gain. The charge will be an estimate of future expenses that could be incurred as a result of the restructuring action. In the short term earnings will go down. However, the firm may be engaging in earnings management, which is designed to increase earnings in the future and thus drive up the stock price. This timing has been linked to when ClTO's sitock options can be exercised (Safder, 2003). In this regard, the primary legacy of former SEC Chairman Arthur Levitt is the war he wag(;d on earnings management. Recent developments at Enron, Worldcom and Arthur Andierson underscore the fact that the earnings management war is not over. The market losses for the top ten firms re-issuing earning statements in 2000 exceed $25 billion (Wu, 2001). Seven ou t of ten of these restatements were directly linked to problems involving revenue recognition. Fuirthennore, the number of public companies having to make earnings restatements increased nearly 50% from 1998 to 2000 (O'Connor, 2002). The SEC has issued Staff Bulletin No. lOI (Hi^ffes,, 2001) that is designed to tighten accounting standards regarding revenue recognition. A INTRODUCTION 29 1 Hall and McPeak: Using Neural Net Technology to Analyze Corporate Restructuring An Published by CSUSB ScholarWorks, 2003 Journal of International Technoloev & Information Manasement Volume 12. Number 2 basic principle of the new guidelines is that revenue should not be recognized until it is "realized and earned" (Griffin, 2001). Obtaining insight into how the market reacts to corporate restructuring announcements can directly impact current public watchdog operations as well as help in the formulation of new accounting guidelines and policies. Neural net technology, a branch of artificial intelligence, is seeing increased usage in a variety of fmancial applications (Baesens, 2003;Young, 1999). Recent survey data indicates that over one-half of these applications involved stock market forecasting (Fadlalla, 2001). Neural nets are well suited for detecting the presence of earnings management via stock price fluctuations since they do not require prior assumptions about possible relationships between the firm and the market. This paper consists of three parts: 1) a review of the relevant literature; 2) a brief review of neural nets; and 3) a neural net analysis of a database gleaned from corporate restructuring announcements. BACKGROUND AND LITERATURE The literature is rich regarding earnings management, in general, and restructuring announcements, in particular, as a corporate strategy (Chai, 2002; Dechow, 2000; Grant, 2000: Payne, 2000). In broad terms, earnings management is defined as the judgmental actions taken by the corporate leadership regarding fmancial transactions with the intent of misleading stockholders and markets as to the actual economic state of the firm. The pressures to manage earnings are usually not in response to a single condition but to a variety of internal and extemal forces. Specific examples are access to debt markets, management compensation, poor planning and competition. For example, many firms use debt for funding both short term and long term investments. Typically, in setting a firm's credit worthiness the debt rating agencies utilize performance data including earnings reports. Accordingly, a decline in earnings or negative future earnings expectations could result in a drop in the firm's debt rating. Such occurrences in turn could increase the firm's cost of capital and thus reduce the prospects for new debt issues. The primary strategies used to manage earnings are revenue recognition and restructuring charges (Healy, 1999). Other techniques used to manage earnings are: • Realizing one-time gains and one-time losses in the same period Suppose that a company has a one-time gain from a settlement with the IRS. The company might record pending one-time losses in the same period. • Matching Principle This accounting principle requires that revenue be recorded in the same period with all costs incurred to generate that revenue. A company might capitalize expenses, thus putting them on the balance sheet, claiming that the expenses are related to future earnings. The capitalized expenses will thus be delayed until future periods. • Big Bath Accounting If a company faces a period with poor operating income, or if it faces the need to do a write-off, the company may consider that period to be a lost cause and take substantial write-offs in several areas. This technique might be used to disguise operating expenses, or it might be used to pull operating expenses from future periods into the current period, thus boosting future earnings.
The proliferation of unsolicited commercial electronic mail (UCE) or spam is becoming a global concern for many organizations. This chapter explores issues of unsolicited email, the cost and loss of productivity, the impact of UCE and computer viruses, privacy concerns, electronic mail filters, attempts to control spam, and legislative action. A strengths, weaknesses, opportunities, and threats (SWOT) analysis was also applied in this study. The results of a survey concerning the perceptions of UCE are presented. The results clearly show that while the respondents find spam annoying, they spend very little time in dealing with it. Although the respondents express the need to control spam, they do not believe that governmental control is the solution, but rather that Internet Service Providers and organizations should take the responsibility for controlling unsolicited email. Lastly, the respondents are very unlikely to open, let alone read and respond to unsolicited email. The results of this study will be useful for guiding organizational, university, and public policies.
Simulation methodology is considered an effective decision making tool in the pro cess of patient scheduling in healthcare centers. In spite of the large number of simulation software packages that are commercially available, operation researches still are facing difficulties to implement simulation models in healthcare centers. In many cases, healthcare schedulers must spend extra efforts trying to mold scheduling requirements to conform to the features of the package. In this paper, we offer a systematic approach that can be used by practitioners to successfully adopt the available software simulation packages, develop simulation models, and transform their findings into practical scheduling rules. A radiology center in a Midwestern Hospital is used to illustrate the proposed methodol ogy. INTRODUCTION V^^hen compared to other alternatives, simulation methodology offers several advantages to the decision-making process in the area of scheduling. Simulation is easily understood by decision-mcikers and aids discussion of different options that may be used to improve the system. Tliese jDiroperties are very important in healthcare, since decision-making in this environment is often a matter of negotiations between medical, administrative and nursing disciplines. Simula tion allows the medical staff to ask what-if questions and review the implications and consequence:s of alternatives without altering the present situation. Ftecently, computer simulation packages have become more sophisticated and visual. Most simulation-based applications focused on patient scheduling use the minimization of the waiting time as the objective function (Advice, 1991; Mahachek, 1992; Benneyan et al., 1994; and Benneyan, 1997). Other applications include nurse scheduling (Arthur and Ravindran, 1981), staffing and operations improvement (Allen et al., 1997), and critical care operations manage ment ( Lowery and Martin, 1992). Scheduling of the radiology center is found to be rare (Coffin
The Internet has changed significantly business operation across national borders. However, existing literature about its impacts on export channels remains limited. This inductive study explored the Internet's impacts on the relations between 13 Chinese manufacturers and their export intermediaries in Canada. Findings from this study suggest that export intermediaries that provide financing and credit, intensive after-sales services, and important distribution infrastructure survive the Internet while those that offer traditional market-sensing and customer-linking services can hardly survive the Internet.
This paper describes middleware for n-tier architecture, describes how this middleware is meeting the unique demands of Internet applications and e-commerce, and suggests selection guidelines to assist business managers in choosing appropriate types of middleware for n-tier systems that will meet their internet needs. Different types of middleware provide the functionality for addressing many distinct and disparate problems arising from the distributed processing associated with n-tier systems. This paper associates the type of middleware with the nature of the system being developed. Thie Internet has grown at pace so rapid that technology has struggled to keep up. A communications medium that not long ago was read-only, text based-advertising has blossomed into full-scale client-server transaction processing. The conventional technologies that make client-S£;rver computing possible are limited in meeting the needs of the Internet. The purpose of this piapfjr is to describe the enabling technologies of n-tier architecture, describe how middleware is meeting the unique demands of Internet applications and e-commerce, and suggest selection guid(;lii].es that can assist business managers in choosing the correct mix of building blocks for nlier systems that meet their internet needs. Middleware is the enabling technology that has allowed web architects to develop threeitier Etnd n-tier systems, overcoming many problems and limitations inherent in two-tier systems. Many definitions of middleware have been published. It has been defined as, a vague term that covers all the distributed software needed to support interactions between clients and servers (Edwards, Harkey, and Orfali, 1999, p. 44), and, as a layer of software that enables communi cations between software components regardless of the programming language in which the INTRODUCTION MIDDLEWARE THE ENABLING TECHNOLOGY
Many Just-In-Time (JIT) manufacturing environments generate operational data reflecting both efficient and inefficient factory performance. Frequently data for inefficient performance is lost or discarded for fear of replicating poor performance. The purpose of this paper is two fold. First, historical JIT shop data is analyzed using a genetic algorithm (GA) to determine which shop factors are important determinants offactory performance. Second, subsequent to these important factors being identified by a GA, an artificial neural network (ANN) is used to learn the relationships between these factors and factory performance. The ANN can then be used to predict factory performance for future shop conditions and enhance shop performance. While ANN learning techniques have previously been applied to JIT production systems (Wray, Rakes, and Rees, 1997) (Markham, Mathieu, and Wray, 2000), these techniques have only been trained on data sets that reflect an efficient factory. Mathieu, Wray, and Markham (2002) investigated inefficient and efficient JIT factory performance but did not deploy either ANNs or a GA. In this paper an example application is presented using a GA to specify important shop factors and to predict saturated, starved or efficient factory performance based on dynamic shop floor data. INTRODUCTION Inhere have been many benefits for firms that have employed the Just-In-Time vfith Kanban philosophy. Some of these benefits are the reduction of work-in-progress inventories, level production schedules, manual control systems, and high levels of quality. A kanban (Jap£ine:se for sign) is a manual/visual cue that is used to signal the replenishment of goods at eacfi stage in the production process. The number of circulating kanbans is a critical issue for elfectiv e operation of a JIT production system. Too many kanbans result in excess work-inprogress inventory, while too few lead to production-floor stoppages. Excessive inventories, storage problems, machine idle times, long lead times, and output shortages can be caused by inappropriate levels of kanbans in a shop. 1 Wray et al.: An Artificial Neural Network Approach to Learning from Factory Pe Published by CSUSB ScholarWorks, 2003 Journal of International Technology & Information Manasement Volume 12. Number 2 The purpose of this paper is two fold. First, both efficient and inefficient historical JIT shop data is analyzed using a genetic algorithm (GA) to determine which shop factors are important determinants of factory performance. Second, once the GA identifies these important factors an artificial neural network (ANN) learns the relationships between these factors and factory performance. The ANN is then used to determine how to adjust shop factors to ensure efficient factory performance for future shop conditions. A computer-based approach is presented that supports learning in a JIT manufacturing environment to improve factory performance. While it is possible for an ANN to learn from successes (positive data) and failures (negative data), conventional modeling dictates that negative information be eliminated from the training data set. However, in many environments it may be desirable to learn from an archived history of data that contains negative information (Triantaphyllou and Soyster, 1996) (Hall, Hansen and Lang, 1997). Markham et al. (2000) compare artificial neural networks and CART on the kanban setting problem. The approach presented in this paper advances prior research by demonstrating a technique that can identify the importance of relationships between shop factors in determining good or bad factory performance. Dynamic factors (over two production periods) both endogenous and exogenous to the production function are examined. A methodology is presented that will allow a shop floor manager to identify relationships between shop factors that need to be monitored closely to operate a JIT factory at peak production performance. The identification of important relationships between shop factors in determining good or bad factory performance in a dynamic setting is sometimes difficult when less than optimal shop conditions exist. As a result of this difficulty, an inefficient number of kanbans may exist during normal operations, causing sub-optimal performance. The development of a model for the JIT system must ensure that such sub-optimal performance is not repeated if possible. Traditional wisdom is to discard any data representing poor shop performance (negative information). However, there are a wide variety of reasons for wanting to learn from data representing less than optimal conditions. First, there is knowledge to be gained from each mistake so that the mistake is not repeated. The precise conditions that caused poor performance can be identified and steps can be taken to rectify the situation in the future (Minsky, 1994). Second, by combining negative data with positive data the number of observations in the training and validation data sets is increased. As a result, the sometimes data hungry artificial neural network can be successfully applied in cases where the quantity of only positive data was insufficient. Finally, by analyzing both good and poor performance it is possible for the model to uncover predictive structures that would otherwise be hidden. This learned information can reveal relationships causing poor (negative) performance so that measures to assure good (positive) performance can be taken. LITERATURE REVIEW The necessary internal and external conditions to the production function that must be met for a successful application of JIT have been identified as a constant (or near-constant) 86 2 Journal of International Information Management, Vol. 12 [2003], Iss. 2, Art. 7 https://scholarworks.lib.csusb.edu/jiim/vol12/iss2/7 A.tSfl-inl MPiiral Network Journal of International Technology & Information Managemeni product demand, production process, and vendor supply (Fukukawa and Hong, 1993) (Huang, Rees and Taylor, 1983) (Price, Gravel and Nsakanda, 1994). Wray et al. (1997) found that even w i th constant distribution means for demand, machine processing, and vendor supply a dynamic variance could cause disruptions and inefficiencies in a JIT shop. They also found that certain comlainations of 2-period dynamic factors are important for efficient factory performance. Marldiam, Mathieu, and Wray (1998) used a classification tree based approach to identify critical dynamiic shop factors and then predicted the number of kanbans necessary for efficient factory pe:rformance. While the potential for genetic algorithm (OA) to find optimal or near optimal solutions to large, complex problems has been demonstrated by researchers, and real-world a]?plicatiions of OA are becoming increasingly common (Davis, 1991) (Goldberg, 1994), little research has been conducted in applying GA to the study of dynamic JIT factory perfoimance. 4i.rtifici.al neural networks have been applied to JIT production systems (Wray et al., 1997) (Markliam et al., 2000), but these techniques are typically used to learn by training on data sets thait contain only efficient factory data. The classification tree based approach developed by Mailcham et al. (1998) was extended by Mathieu et al. (2002) to investigate inefficient and efficient factory conditions. The performance of kanban-based production systems is a topic of continued interest in the academic community. Both Tardif and Maaseidvaag (2001) and Shahabudeen, Gopinath, and Krislmaiah (2002) present JIT production models which vary the number of kanbans in an atteiiflpt to improve factory performance. Haslett and Osborne (2000) modeled the local rules used bv managers in the operation of a kanban system and report on the success as well as the unintended consequences of applying these decision rules. Takahashi and Nakamura (2002) develo ped and tested a decentralized reactive kanban system that improves factory performance hi periods of unstable product demand. RESEARCH DESIGN: AN OVERVIEW OF GENETIC ALGORITHMS AND ARTIFICIAL NEURAL NETWORKS Genetic Algorithm During the process of natural evolution individuals of a species are created by decoding infc'imation stored in sequential codes called chromosomes. These individuals are evaluated by the enviromnent, with the fittest having a higher probability of surviving long enough to successlully reproduce. Reproduction, in essence, combines the existing chromosomes to create a new set of chromosomes. New chromosomes are also created as a result of mutation. Mutation occurs vvith a small probability. The success of the evolutionary process prompted John Holland (1986) to develop the genetic algorithm. In the GA, every solution is represented as a chromosome, or string of values. Each value on the chromosome, or token, is restricted to a set of legal values. The set of problem solutions, or popul ation, available at any point in time is the current generation. The fitness of each member of a generation is evaluated through a mathematical function. A new set of chromosomes is formed by operating on members of the current population. Although the chromosomes selected 87 3 Wray et al.: An Artificial Neural Network Approach to Learning from Factory Pe Published by CSUSB ScholarWorks, 2003 Journal of International Technolosv & Information Manasement Volume 12. Number 2 for use in forming the next generation are selected stochastically, those which are most fit have the highest probability of being selected. Implementation of the genetic algorithm includes several specific decisions. The representation scheme for the chromosome should allow problem solutions to be represented as a fixed-length, string of tokens. The selection of an initial population of solutions and the determination of the size of the initial population are important. A method for evaluating the fitness of each member of the population must be determined. This evaluation must be efficien
Security issues and threats in the e-commerce environment are varied and can be caused intentionally and unintentionally by insiders and outsiders. Many experts believe that insiders create the majority of the security threats and issues. Security issues and threats related to ecommerce environment can be categorized as controllable, partially controllable and uncontrollable. This article presents an integrated model that identifies various security issues and threats in the e-commerce environment and then offers a comprehensive e-commerce security plan. The integrated model includes six steps: identification of basic e-commerce security safeguards, identification of e-commerce general security threats, identification of intentional e-commerce threats, identification of e-commerce security measures and enforcements, identification of computer emergency response team services and formation of a comprehensive e-commerce security plan. The integrated model, if carefully followed, should significantly improve the chances of success in keeping the e-commerce hackers and crackers at bay (Bidgoli, 2002). INTRODUCTION Security issues and threats in the e-commerce environment are varied and can be caused intentionally and unintentionally by insiders and outsiders. Security issues and threats related to e-commerce environment can be categorized as controllable, partially controllable and uncontrollable. This article presents an integrated model that identifies various security issues and thieats in the e-commerce environment and then offers a comprehensive e-commerce S'Scurity plan. STEP 1: IDENTIFICATION OF BASIC E-COMMERCE SECURITY SAFEGUARDS Computer hackers and criminals are making national and international news. It's no v/onder that executives in private and public organizations are taking computer and e-commerce security very seriously. A comprehensive e-commerce security system protects customers, buildings, terminals, printers, CPUs, cables, and other hardware and software in an organization. ^/Ioreover, an e-commerce security plan protects data resources, the second most important 119 1 Bidgoli: All Integrated Model for Improving Security Management in the E-C Published by CSUSB ScholarWorks, 2003 Journal of International Techttoloey & Information Management Volume 12, Number 2 resource (after human resources) in an organization. The data resources can be an e-mail message from a division supervisor to the CEO, an invoice being transferred using EDI, the blueprint for a new product design, the outline of a new advertising strategy, the credit card number of a customer or financial statements. Security threats exceed merely stealing data; they include everything from sharing passwords with a co-worker, leaving the system unattended while logged onto the network, to spilling coffee on a keyboard. A comprehensive e-commerce security system includes hardware, software, procedures, customers, and personnel that collectively protect the e-commerce resources and keep intruders and hackers at bay. E-commerce security is broken down into three important aspects: secrecy, accuracy, and availability (Sanders, 1996). Let's briefly explain each aspect. A secret system must not allow information to be disclosed to anyone who is not authorized to access it. In highly secure government agencies (Department of Defense, the CIA, and the IRS) secrecy ensures that only the users who are supposed to have access are granted that access. In business organizations, confidentiality ensures the protection of private information (payroll, personnel, and corporate data). In the e-commerce world, confidentiality ensures that customers' data is protected and will be used only for the intended purpose. Accuracy ensures the integrity of data resources within the organization. This means that the security system must not allow the data to be corrupted or allow any unauthorized changes to the corporate database. Database administrators and webmasters must establish comprehensive security systems for corporate databases. Authorized users must be identified and they must be given proper access privileges. Just imagine that the addition or elimination of a zero would be the difference between $100,000 and $10,000. In e-commerce transactions accuracy and secrecy are important aspects of a security system and they are the prerequisite for any data quality implementation throughout the system. Availability ensures the efficient and effective operation of an e-commerce site and a computer system. In the e-commerce environment availability ensures that the virtual storefront is always available and accessible. A secure e-commerce system must make information available to authorized users. It should also ensure quick recovery of the system to its normal operation in case of a disaster. In many cases, availability is the baseline security need for all authorized users. If the system is not accessible to its authorized users, the secrecy and accuracy objectives of the system cannot be properly assessed. A comprehensive security system in the e-commerce environment must provide three levels of security: • Front-end servers must be protected against unauthorized access. (Level 1) • Back-end systems must be protected to ensure privacy, confidentiality, accuracy and integrity of data. (Level 2) • The corporate network must be protected against intrusion and unauthorized accesses. (Level 3) 120 2 Journal of International Information Management, Vol. 12 [2003], Iss. 2, Art. 9 http://scholarworks.lib.csusb.edu/jiim/vol12/iss2/9 Imvrovine Security Management Journal of Iniernational Technotosv & Information Manaeement I'he goal in designing a comprehensive e-commerce security system is first to design a f au lt tolerance system and then take all the possible measures for protecting the e-commerce data resources (Garfield, 1997). A fault tolerance system is a combination of hardware and software techniques that improves the reliability of an e-commerce site. There are several techniques and tools that can improve the fault tolerance of an e-commerce site. The following are among the po]3u].iir techniques: «i Unint(;rruptible power supply (UPS) Redundant arrays of independent disks (RAID) Mirror disks STEP 2: IDENTIFICATION OF E-COMMERCE GENERAL SECURITY THREATS K-commerce security is concerned with the unauthorized access to important data res our ces Some e-commerce threats are controllable, some are partially controllable, and some are. com]3]etely uncontrollable. Some are intentional while others are made unintentionally (Bidgoli, 2002 and Marion, 1995). Table 1 summarizes several potential e-commerce disasters. Natural Disasters Other Disasters Cold weather Blackouts Earthquakes Fires Floods Gas leaks Hot weather Neighborhood hazards Hurricanes Nuclear attacks Ice storms Oil leaks Ocean waves Power failure Severe dust Power fluctuations Snow Radioactive fallout Tornadoes Structural failure Table 1: Potential E-commerce Disasters Insiders or outsiders intentionally create certain security threats such as the spreading of a computer virus by a hacker or a disgruntled Webmaster. Certain security threats are unintentional, such as, th e eraser of a computer fde or formatting a data disk unintentionally by an employee. Some security Ihieats such as earthquakes are natural and are not controllable (or are partially controllable). A comprehensive e-commerce security system should allow only authorized employees to have access to ecornrnerce facilities. Table 2 summarizes the threats posed by insiders and outsiders.
During the economic boom of the last decade, companies and organizations have to offer lucrative salaries and a wide variety of incentive programs to attract and to retain highly skilled IT workers. While it is true that the economic downturn has affected the dramatic rise in salary trends, determining the worth of an employee as measured by wages will always remain a critical management issue. History has shown that irrespec tive of economic conditions, salaries will continue to rise. As the economy recovers and given the projected mass exodus of governmental information technology workers in the coming years, managers will need to be ready to deal with the difficult issue of high salary again. This study examines national and regional salary trends of IT managers. Specifi cally, the salaries examined are for the years 1991 through 2000, the period where sala ries were often adjusted because of the imbalance between the supply of and the demand for IT professionals. From the employee who is looking for a reasonable salary package to the employer who must determine a sufficient pay raise to retain an IT manager, the findings and trends reported in this study should be useful and interesting.