Wednesday, 2 May 2012

Case Study : Chapter 3


Questions to consider

1. Peter Gumble, European editor for Fortune magazine, comments, "Kerviel is a stunning example of a trader breaking the rules, but he's by no means alone. One of the dirty little secrets of trading floors around the world is that every so often, somebody is caught concealing a position and is quickly - and quietly - dismissed... [This] might be shocking for people unfamiliar with the macho, high-risk, high-reward culture of most trading floors, but consider this: the only way banks can tell who will turn into a good trader and who even the most junior traders to take aggressive positions. This leeway is supposed to be matched by careful controls, but clearly they aren't foolproof." What is your reaction to this statement by Mr. Gumble?
-I agree with Peter Gumble, because the only way banks can tell who will turn into a good trader and who won’t by giving every youngster it hires a chance to show his mettle.

2. What explanation can there be for the failure of SocGen's internal control system to detect Kerviel's transactions while Eurex detected many suspicious transactions?
-SocGen is failure because he thought that his internal control system is perfect. He didn't know that his system needs more security.

Discussion Questions

1. Do you think that Mike Lynn acted in a responsible manner? Why or why not?
-Yes, because Mike Lynn wants to be fair on their jobs.

2. Do you think that Cisco and ISS were right to pull the plug on Lynn's presentation at the Black Hat conference? Why or why not?
-Black Hat have to face the Issue about Mike Lynn because it is a disrespect for him.

3. Outline a more reasonable approach toward communicating the flaw in the Cisco routers that would have a led to the problem being promptly addressed without stiring up animosity among the parties involved.
-I guess we can wrap up the Cisco and ISS vs. Mike Lynn and Black Hat saga by mentioning the new Cisco security advisory released today: IPv6 Crafted Packet Vulnerability, which states: "(IOS) Software is vulnerable to a Denial of Service (DoS) and potentially an arbitrary code execution attack from a specifically crafted IPv6 packet. The packet must be sent from a local network segment. Only devices that have been explicitly configured to process IPv6 traffic are affected. Upon successful exploitation, the device may reload or be open to further exploitation."Assuming these details is correct and who knows now?  This is not an earth-shattering discovery. However, this may have been a sample vulnerability Mike demonstrated to explain his technique. He may have picked this vulnerability because he thought it would not affect much of the Internet, but he needed to let people know that his technique was already in use by malicious parties.


reference : http://www.cisco.com/en/US/products/csa/cisco-sa-20050729-ipv6.html

Monday, 16 April 2012

Case Study : Chapter 2

Discussion Questions(Page 64)


1. How can organizations and vendors change their certification programs to test for skills as well as core knowledge? What issues might this introduce?
-Organizations and vendors must conduct seminars for employees so that they can help boost the employees skills and knowledge.


2. What are the primary arguments against certification, and how can certifying bodies change their programs to overcome these shortcomings?
-IT workers argued that testable IT knowledge does not necessarily translate into quality IT work. This problem can be overcome by conducting a proper training.


3. What are the benefits of certification? How might certification programs need to change in the future to better serve the needs of the IT community?
-The benefit of certification is to help you to find a job. If you have many certifications you will have a higher chance to be hired.  Certification programs need to change in the future to better serve the needs of the IT community like changing IT certification examination.

Case Study : Chapter 1

Discussion Questions


1. Discuss how a CIO might handle Schrage's Scenarios using the suggested process for ethical decision making presented in this chapter.
-The CIO can handle Schrage's Scenario using the suggested process for ethical decision making by enhancing/modifying the suggested process.


2. Discuss the possible short-term losses and long-term gains in implementing ethical solutions for each of Schrage's scenarios.
-As what I have red from our photocopy, There are some readers argued that CIO's must consider a company's long-term needs rather than just the current needs of a specific project.

3. Must businesses choose between good ethics and financial benefits? explain your answer using Schrage's scenarios as example. 
-No, because both of them are useful in the business world.

Friday, 13 April 2012

What takes to be an IT professional ?


To be an IT professional you need to have the SHHKLEFF  values:

* Self-Confidence - To be an IT professional you must believe on yourself and on what you are doing.

* Humble - To be an IT professional you must have the quality or state of being humble and modest opinion of one's own importance or rank.

* Honesty - To be an IT professional you should be truthful, sincere in any situations that you are in.

* Knowledge - To be an IT professional you have to be familiar with  facts, information, description, or skill acquired through experience or education.

* Learning - To be an IT professional you must aquire something new or you must modify your existing knowledge, behavior, skills, values, or preferences.

* Exploration - To be an IT professional you must explore new informations.

* Fairness -To be an IT professional you must be free from bias or injustice, you should treat everyone equal.

* Focus - To be an IT professional you must Focus on what you are doing specially at work.