Phân Tích và Thiết Kế Hệ Thống Thông Tin Doanh Nghiệp: Kiểm Soát và Trách Nhiệm

Khám phá phần 2 của ebook về phân tích, thiết kế và thực hành hệ thống thông tin doanh nghiệp, cung cấp kiến thức chuyên sâu và ứng dụng thực tiễn.

Trường đại học

Trường Đại Học

Chuyên ngành

Phân Tích và Thiết Kế Hệ Thống Thông Tin Doanh Nghiệp

Người đăng

Ẩn danh

Thể loại

bài luận

2008

326
3
0

Phí lưu trữ

75 Point

Mục lục chi tiết

9. Chapter 9: Information systems: control and responsibility

9.1. Feedback control systems

9.2. Feedforward control system

9.3. Preventive control systems

9.3.1. Documentation

9.3.2. Procedures manual

9.3.3. Separation of functions

Tóm tắt

I. Tổng Quan Về Phân Tích và Thiết Kế Hệ Thống Thông Tin Doanh Nghiệp

Phân tích và thiết kế hệ thống thông tin doanh nghiệp là một quá trình quan trọng giúp tổ chức tối ưu hóa hoạt động và quản lý thông tin hiệu quả. Hệ thống thông tin doanh nghiệp không chỉ đơn thuần là công nghệ mà còn là một phần không thể thiếu trong chiến lược phát triển của doanh nghiệp. Việc hiểu rõ các khái niệm cơ bản và quy trình thiết kế sẽ giúp doanh nghiệp nâng cao khả năng cạnh tranh và đáp ứng nhanh chóng với các thay đổi trong môi trường kinh doanh.

1.1. Khái Niệm Cơ Bản Về Hệ Thống Thông Tin Doanh Nghiệp

Hệ thống thông tin doanh nghiệp bao gồm các phần mềm, phần cứng và quy trình nhằm thu thập, lưu trữ và phân tích dữ liệu. Điều này giúp doanh nghiệp đưa ra quyết định chính xác và kịp thời.

1.2. Vai Trò Của Hệ Thống Thông Tin Trong Doanh Nghiệp

Hệ thống thông tin đóng vai trò quan trọng trong việc quản lý dữ liệu, cải thiện quy trình làm việc và tăng cường khả năng ra quyết định. Nó giúp doanh nghiệp theo dõi hiệu suất và tối ưu hóa hoạt động.

II. Những Thách Thức Trong Phân Tích Hệ Thống Thông Tin Doanh Nghiệp

Trong quá trình phân tích hệ thống thông tin, doanh nghiệp thường gặp phải nhiều thách thức như việc xác định yêu cầu chính xác, quản lý dữ liệu lớn và đảm bảo tính bảo mật thông tin. Những thách thức này có thể ảnh hưởng đến hiệu quả của hệ thống và sự hài lòng của người dùng.

2.1. Xác Định Yêu Cầu Hệ Thống Thông Tin

Việc xác định yêu cầu hệ thống là một bước quan trọng nhưng cũng đầy khó khăn. Doanh nghiệp cần phải thu thập thông tin từ nhiều bên liên quan để đảm bảo rằng hệ thống đáp ứng được nhu cầu thực tế.

2.2. Quản Lý Dữ Liệu Lớn Trong Hệ Thống

Quản lý dữ liệu lớn là một thách thức lớn trong thiết kế hệ thống thông tin. Doanh nghiệp cần có các công cụ và phương pháp hiệu quả để xử lý và phân tích dữ liệu một cách nhanh chóng và chính xác.

III. Phương Pháp Phân Tích Hệ Thống Thông Tin Doanh Nghiệp Hiệu Quả

Để phân tích hệ thống thông tin doanh nghiệp một cách hiệu quả, cần áp dụng các phương pháp như phân tích yêu cầu, mô hình hóa quy trình và kiểm thử hệ thống. Những phương pháp này giúp đảm bảo rằng hệ thống được thiết kế phù hợp với nhu cầu thực tế của doanh nghiệp.

3.1. Phân Tích Yêu Cầu Hệ Thống

Phân tích yêu cầu là bước đầu tiên trong quá trình thiết kế hệ thống. Nó bao gồm việc thu thập và phân tích thông tin từ người dùng và các bên liên quan để xác định các tính năng cần thiết.

3.2. Mô Hình Hóa Quy Trình Kinh Doanh

Mô hình hóa quy trình giúp doanh nghiệp hình dung rõ ràng các bước trong quy trình làm việc. Điều này giúp xác định các điểm cần cải thiện và tối ưu hóa quy trình.

IV. Ứng Dụng Thực Tiễn Của Hệ Thống Thông Tin Doanh Nghiệp

Hệ thống thông tin doanh nghiệp có thể được ứng dụng trong nhiều lĩnh vực khác nhau như quản lý khách hàng, quản lý tài chính và quản lý chuỗi cung ứng. Những ứng dụng này giúp doanh nghiệp nâng cao hiệu quả hoạt động và cải thiện dịch vụ khách hàng.

4.1. Quản Lý Khách Hàng Bằng Hệ Thống Thông Tin

Hệ thống thông tin giúp doanh nghiệp theo dõi và quản lý thông tin khách hàng một cách hiệu quả. Điều này giúp cải thiện mối quan hệ với khách hàng và tăng cường sự hài lòng.

4.2. Quản Lý Tài Chính Với Hệ Thống Thông Tin

Hệ thống thông tin tài chính giúp doanh nghiệp theo dõi chi phí, doanh thu và lợi nhuận. Điều này giúp đưa ra quyết định tài chính chính xác và kịp thời.

V. Kết Luận Về Phân Tích và Thiết Kế Hệ Thống Thông Tin Doanh Nghiệp

Phân tích và thiết kế hệ thống thông tin doanh nghiệp là một quá trình phức tạp nhưng cần thiết để đảm bảo rằng doanh nghiệp hoạt động hiệu quả. Việc áp dụng các phương pháp và công nghệ hiện đại sẽ giúp doanh nghiệp tối ưu hóa quy trình và nâng cao khả năng cạnh tranh.

5.1. Tương Lai Của Hệ Thống Thông Tin Doanh Nghiệp

Tương lai của hệ thống thông tin doanh nghiệp sẽ tiếp tục phát triển với sự xuất hiện của công nghệ mới như trí tuệ nhân tạo và phân tích dữ liệu lớn. Những công nghệ này sẽ giúp doanh nghiệp cải thiện khả năng ra quyết định và tối ưu hóa quy trình.

5.2. Tầm Quan Trọng Của Bảo Mật Thông Tin

Bảo mật thông tin là một yếu tố quan trọng trong thiết kế hệ thống thông tin. Doanh nghiệp cần phải đảm bảo rằng dữ liệu được bảo vệ an toàn trước các mối đe dọa từ bên ngoài.

17/07/2025
Ebook business information systems analysis design and practice part 2

Trích đoạn nội dung tài liệu

qxd 1/31/08 1:29 PM Page 339 Chapter 9 Information systems: control and responsibility Learning outcomes On completion of this chapter, you should be able to: n Describe the controlling effect of feedback and feedforward in an information system n Evaluate the preventive measures necessary to effect control in an information system n Describe controls that can be applied to data in transmission n Evaluate a range of organizational controls that should be considered in the design and operation of an information system n Discuss the rights and responsibilities of individuals, organizations and society in the development, implementation and use of information systems n Apply principles of data protection legislation. Introduction This chapter introduces the general principles behind control and security in systems. These are then applied to computerized information systems. The increasing depend- ence of business on the reliable, complete and accurate processing of data by computers, often without manual checks, indicates that controls must be planned and designed.

This occurs before the development of computer systems and their surrounding manual procedures. Security and control should therefore be considered prior to systems design and certainly feature in the design process itself, not as afterthoughts. The increasing use of computers in the processing and transmission of confidential data and funds has also made computer systems attractive targets for fraud. The need to take steps to guard against this possibility has been a powerful stimulus to an emphasis on security in the process of systems analysis and design.

In the early part of this chapter, the basic concepts of control systems are developed by considering the general ideas behind feedback, feedforward and preventive controls. These are explained and applied to manual business systems. Controls over computer- ized information systems are introduced by identifying the various goals and levels of control that are applicable. Controls over data movement into, through and out of the computer system are covered, together with controls over the transmission of data 339 BIS_C09.qxd 1/31/08 1:29 PM Page 340 Chapter 9 · Information systems: control and responsibility between computers or through the public telecommunications network.

Some of the ways that fraud may be prevented are by restricting access to the computer system or to the data in it, or by scrambling the data prior to storage or transmission so that it is useless to any unauthorized person. The methods of achieving these ends are also explained. Computer systems always lie within and interface with a surrounding manual system. Not only should computer aspects of this combined socio-technical system be the subject of control but also the organizational and personnel elements.

To aid security, it is important that the system be structured in a way that facilitates this. The way that functions are separated as a means of control is developed in later sections of this chapter. The reliability of controls and security procedures operating over a working transaction- and information-processing system can be established by means of an audit. Although auditing is a large area in itself, the overall strategy adopted and the aid given by computer-assisted tools in the auditing of computer-based sys- tems is outlined.

The chapter also considers the relationship between information sys- tems, organizations and individuals. Issues such as crime, privacy and acceptability of behaviour raise questions of responsibility. Who should ensure that certain practices or activities are restrained or even prevented? Is it the duty of an individual, an orga- nization or society as a whole? There may be a collective belief amongst members of a community that there is a social responsibility in resolving a particular problem. In other situations the responsibility may rest on an organization.

In this case the reso- lution may be in corporate governance and how the organization manages its own affairs. Also, the form of action taken may vary greatly. Checks, controls and balances take many forms. They can be imposed by legislation, they can be adopted voluntarily by individuals or organizations or they can just become custom and practice with no for- mal agreement.

Judgments of the courses of actions taken are ethical considerations. Once a framework of policies, rules and legislation is in place, the ethics of actions taken can be considered. One example given extended treatment is that of privacy, in particular as enshrined by data protection legislation. Data on persons is the subject of data protection legislation.

This has implications both for security and for the design of systems holding data on persons. The reasons for the rise of this legislation and the general principles behind the Data Protection Act in the UK are explained, together with the effects of the legislation on personal data security and access. Finally, the need for a methodology for the identification of risk and the design of controls is stressed. Controls are an integral part of systems design, which is covered in Chapter 14 on systems design and Chapter 15 on detailed design.1 Control systems Controls, if they are to be effective, must operate in a systematic way.

This section considers the general principles behind control systems before applying these to business systems. Some controls work by sensing or predicting the state of a system, comparing that state with a desired standard and then carrying out some correcting action if the state does not meet favourably with the standard. Other controls prevent (or attempt to prevent) a system moving away from a desired state. They do this by preventing abnormal but possible occurrences that would have this effect.

Feedback and feedforward are examples of the first type of control. Preventive controls are examples of the second. Feedback and feedforward controls involve the 340 BIS_C09.qxd 1/31/08 1:29 PM Page 341 Control systems collection and processing of data and so operate within the business information system. Preventive controls prevent inaccurate and unreliable data processing, damage to data-processing equipment and unauthorized access to data, and so too are within this environment.

It is one of the responsibilities of management to ensure that adequate and effect- ive controls are present at all levels in a business organization. There is always a cost–benefit dimension to the existence of any control – it is insufficient to consider the control outside this context. All controls have some cost associated with their instal- lation and also a probability/possibility that they will fail in their control function. On the benefit side, there is the prevention or correction of the undesired state of affairs.

It may be possible to assign a money value to this benefit, but it is important to bear in mind that this undesired state of affairs might not have happened in the absence of the control (this is particularly true with preventive controls), so probability factors also have to be taken into account here. Cost–benefit considerations surrounding a strat- egy for control in a business are covered in a later section of this chapter, but it should be made clear from the outset that the major question surrounding a control is not ‘does it work?’ but ‘is it cost–benefit effective?’ 9.1 Feedback control systems The general nature of a feedback control system is shown in Figure 9. It consists of: n A process, which accepts inputs and converts these into outputs. n A sensor, which monitors the state of the process.

n A controller, which accepts data from the sensor and accepts standards given exter- nally. The controller then generates adjustments or decisions, which are fed into and affect the process.1 Feedback control 341 BIS_C09.qxd 1/31/08 1:29 PM Page 342 Chapter 9 · Information systems: control and responsibility n A comparator in the controller, which compares the sensed data with the standard and passes an indication of the deviation of the standard from the monitored data to the effector. n An effector in the controller, which on the basis of the output of the comparator makes an adjustment to the output from the controller. The example often given of a controller in a feedback control system is a thermostat.

It accepts data about temperature from a sensor, compares it with a standard that is set by the householder and if the temperature is below or above this standard (by a certain amount) makes an adjustment to the boiler, turning it either on or off. Feedback control enables a dynamic self-regulating system to function. Movements of the system from equilibrium lead to a self-correcting adjustment, implying that the combination of process and controller can be left over long periods of time and will continue to produce a guaranteed output that meets standards. Automated controller–process pairs are seldom encountered in business (although they often are in production engineering).

However, it is common for a person to be the controller. That is, an individual will monitor a process, compare it against given standards and take the necessary action in adjustment. This is one of the roles of management. In an organization, it is usual for control to be applied at several levels.

The con- troller of a process at level 1 supplies information on the process and adjustments to a higher-level controller (who also receives information from other level 1 controllers). The information supplied may be an exceptional deviation of the process from the stand- ard (exception reporting) or perhaps a summary (summary reporting). The higher- level controller can make adjustments to the functioning and structure of the system containing the level 1 controllers with their processes. The higher-level controller will also be given standards and will supply information to an even higher-level controller.

The nesting of control may be many levels deep. At the highest level, the controllers are given standards externally or they set their own. These levels of control correspond to levels of management. Above the lowest levels of control are the various layers of middle management.

Top management responds to standards expected of it by exter- nal bodies, such as shareholders, as well as setting its own standards. The study of feedback control is called cybernetics. Cybernetics ideas and principles have been applied to the study of management control of organizations (see for example Beer, 1994). Although real organizations are never so simple and clear-cut that they fit neatly into the feedback model, the idea of feedback provides a useful perspective on modelling management decision making and control.

In order to be useful, feedback controls, as well as satisfying the cost–benefit con- straint, should also be designed in accordance with the following principles: n Data and information fed to the controller should be simple and straightforward to understand. It must be designed to fit in with the intellectual capabilities of the con- troller, require no longer to digest than the time allowed for an adjustment to be made, and be directed to the task set for the controller. It is a common mistake for computerized systems that are responsible for generating this data to generate pages of reports that are quickly consigned to the rubbish bin. For example, a person in charge of debtor control (where the process is one of debtor-account book-keeping) may only need information on debtor accounts that have amounts outstanding over a set number of days, not information on all 342 BIS_C09.qxd 1/31/08 1:29 PM Page 343 Control systems accounts.

On these debtor accounts the controller probably initially needs only sum- mary information, such as the amount of debt, its age profile and the average turnover with the debtor, but not the delivery address or a complete list of past invoices. n Data and information fed to the controller should be timely. Two possibilities are regular reports on deviations from standards or immediate reports where corrective action must be taken quickly. It is important that the standards set and the data provided to the controller are restricted within these limitations.

The manager is in the best position in the organization to understand the workings of the process and may often be expected to take some responsibility for the setting of realistic standards.

Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ

Tài liệu Phân Tích và Thiết Kế Hệ Thống Thông Tin Doanh Nghiệp - Phần 2 cung cấp cái nhìn sâu sắc về quy trình phân tích và thiết kế hệ thống thông tin trong doanh nghiệp. Nó nhấn mạnh tầm quan trọng của việc hiểu rõ yêu cầu của người dùng và cách thức thiết kế hệ thống để đáp ứng những yêu cầu đó một cách hiệu quả. Độc giả sẽ tìm thấy các phương pháp và công cụ hữu ích để tối ưu hóa quy trình làm việc, từ đó nâng cao hiệu suất và khả năng cạnh tranh của doanh nghiệp.

Ngoài ra, tài liệu này còn mở ra cơ hội cho người đọc khám phá thêm các khía cạnh liên quan đến lập trình web và xây dựng trang báo điện tử. Một tài liệu đáng chú ý khác là Báo cáo bài tập lớn môn lập trình web tên đề tài xây dựng trang báo điện tử các thành viên nhóm it15, nơi bạn có thể tìm hiểu thêm về cách xây dựng trang web và ứng dụng thực tiễn trong lĩnh vực này. Những tài liệu này không chỉ giúp bạn mở rộng kiến thức mà còn cung cấp những góc nhìn mới mẻ về thiết kế và phát triển hệ thống thông tin trong doanh nghiệp.