Blogger news

Showing posts with label systems integration. Show all posts
Showing posts with label systems integration. Show all posts

Wednesday, 26 December 2012

Systems Integration: Usability, Navigation, Customization

Systems Integration: Usability, Navigation, Customization... Amazon.com and Aquarelle

Amazon.com, Inc., hereafter referred to as Amazon, was started in 1994. It has its headquarters in United States. Amazon grew from a bookstore to an online marketplace that sells just about anything a consumer can want, and is considered as one of the largest online retailers of the world. Many times, Amazon has made a great company for researchers concerned with ecommerce and web systems.

On the other hand, Aquarelle.com was founded in 1987 as a flower retailer, creating bouquets by hand in several of its shops. It also sells artificial flowers and fruit confections. Its headquarters are in France, and it also operates an online system. The online system was established in the year 2000.

For a systems integrators the main task In determining issues of system integration would be to investigate on the usability and interoperability of the two systems. In this report, A customer’s point of view has been adopted in the evaluation. Usability is taken to be the ease of use of the system to the customer in accessing the services of the system. Interoperability is the possibility of accessibility of the services across various systems.

Pearson and Pearson (2007), state that usability of a website can be assessed using five criteria: Navigation, Ease of Use, Customization, Download Speed, and Accessibility. In the following part, this paper compares the two systems, basing on the experience of the writer in the two systems.

 Systems Integration: Usability

Jacob Nielson (2005) says that Amazon used to be a leader in terms of usability, but not any more. In the article, he points out that Amazon’s pages are all scattered, and every page has so many links and buttons. This in a way can lead to confusion among customers for there’s lack of a clear organization. On the other hand, Amazon’s suggestions in the form of Customers who bought this also bought… are a feature that enhances its usability and customer satisfaction.
Looking at Aquarelle website, the main thing that strikes one’s mind is the simplicity, afforded by the fact that aquarelle has not cluttered so many products on the same website. Its large home page provides an instantaneous acquaintance with the products. This is contrasted with Amazon’s thousands of products, which can confuse the customer.

Systems Integration: Navigation

Aquarelle, just as we’d said above, has a home page that displays most of the products. There’s therefore little need for elaborate navigation systems. This is advantageous to Aquarell.
When one looks at Amazon, things are so different. There is multiplicity of products, ranging from books, to clothing, electronics and so many other products. This complicates Amazon making their site more difficult to navigate. In addition, Amazon has links to other websites, including a search box leading out of the site. This is quite confusing.

Having had a desire to register and attempt to make purchases in the two web systems, one thing that surprised me was the absence of any link to login in aquarelle. Amazon has a prompt for the customer to login or register, but not so for Aquarell. Whatever the reason, this makes aquarelle more impersonal than Amazon.

Systems Integration: Customization

Customization for Amazon is unique. The system is able to offer suggestions to the customers, based on what others have purchased in relation to what the customer is viewing. In addition, the system remembers what the customer’s history in the website. A customer is therefore taken directly to products they may be interested in.
For Aquarelle, customers can select the colour and size of the bouquet. Customers also decide whether to send a photo, chocolates etc with the orders.

Amazon vs Aquarelle: Download Speed, Accessibility and Interoperability

Amazon vs Aquarelle: Download Speed, Accessibility and Interoperability

Download Speed and Accessibility

It has been impossible to measure in accurate terms the download speeds of the two websites. However, through general experience, it appears that Aquarelle opens a little faster than amazon. The explanation for this may be the fact that Amazon website seems loaded with so many products far higher than Aquarelle. This means that it is easier and faster to use Aquarelle than it is to use Amazon.

Interoperability

Interoperability was defined as the possibility of accessibility of the services across various systems. For instance both e-commerce systems consist of different websites based in different countries. For instance, Amazon will have a website based in France, United States, U.K, etc. Similarly, Aquarelle has such websites. So the question is how do all these websites interoperate?

For Amazon, it is quite easy, for instance, an account in amazon.com still operates in amazon.co.uk. However, it is not so for Aquarelle. A customer has to create different accounts making it a frustrating experience for a customer. For instance, a customer will not understand why he/she has no account if they opened one in aquarelle.co.uk, and accidentally goes to aquarelle.com.

Obstacles that Face Systems Integration

Obstacles that Face Systems Integration

The following Identifies several obstacles that face systems integration
  • Lack of cooperation from the collaborating departments. In essence, such a problem could occur during systems integration. This is because many people fear change and definitely integration would mean change in the job description of some persons, while others may be laid off. Such possible opposition may make it impossible to carry out the work of integrating the systems.
  • The other area pointed out by Zaitun is the participating departments’ requirements and regulations. Though she was talking of departments in the same organization, the point applies even in our case, only at a larger degree. We realize that Amazon and Aquarelle are totally different systems, governed by different rules. This would not make it any easy for systems integrators. There would be need to re-design the rules and such is likely to consume a lot of time and financial resources, and be met with a lot of opposition.
  • Software and technological issues is another area of focus. It is quite possible that the systems be built in different programming languages and employing different software. This does not make integration any easier. If anything, it makes it harder as there would need to be a compromise on the side of either system.
  • Another potential difficulty arises because of the nature of the two businesses. Whereas Amazon deals with long lasting products such as books and electronics, Aquarelle deals with flowers

All About Amazon.com: Founders, Core Business and Risk Assessment

All About Amazon.com: Founders, Core Business and Risk Assessment

Amazon.com, Inc. is a prestigious business founded by Jeff Bezos in 1994 and launched online in 1995. It started off as a small online bookstore raising eyebrows world over. Since then, it has grown and expanded its portfolio and horizons.  It has its headquarters in Seattle, Washington and has separate websites across the world that services various countries such as Canada, Japan, and France etc.

Amazon’s growth from a bookstore to an online marketplace that sells just about anything a consumer can want has made it responsible for approximately one third of all E-Commerce in the United States and has America’s largest online retailer. In addition, Amazon is seen to have an edge in modern technology, noting that its system is one of the most innovative especially in the area of e-book development. For instance, they have developed The Kindle, a revolutionary e-book system. With this kind of profile and the responsibility it has to so many consumers, Amazon makes a great company to research.

The growth of the internet and online shopping has become a target ground for criminals to attempt to exploit.  There’s need for companies to consider the threats of online criminals and be adequately armed to deal with the possible occurrences of hacking, stolen identity, information theft among other risks facing ecommerce websites world over, such as a possibility of a virus getting into the system and deleting vital data.   Amazon is one such a company that has a major task at hand in securing its online marketplace and averting the dangers.

This research performs a risk assessment report regarding Amazon.com, identifying and evaluating threats and vulnerabilities that Amazon.com faces along with providing security controls to mitigate the threats and vulnerabilities. The major components evaluated are Amazon’s online transaction system; Amazons customer profile which can have sensitive information saved in it such as credit card information, bank account information, address information, etc.

Information to perform this risk assessment is gathered from a variety of online resources and books, along with the National Institute of Standards and Technology (NIST) Special Publication 800-30; Risk Management Guide for Information Technology Systems.

Risk Assessment on Amazon.com

Risk Assessment on Amazon.com

This risk assessment is meant to identify threats and vulnerabilities of Amazon, the largest online book store and a fast growing ecommerce platform. The findings of this research can be used as the base while considering measures to ensure security in Amazon. Further, it can be used by upcoming entrepreneurs as a source of information about possible and present risks and uncertainties in the ecommerce world.

According to Darshanand and R. McKegney, A secure system accomplishes its task with no unintended side effects. According to them, security has three main concepts: confidentiality, integrity, and availability. Confidentiality allows only authorized parties to read protected information. This assessment report focuses on the three main concepts, checks them against Amazon and attempts to determine the level of risk in which Amazon is operating.

This risk assessment is based on research. Information has been collected from public domains and from journals are used as the bases for the identification. Attempt has also been made to get first hand customer experience in order to report more accurately.
  
Overview of Amazon
Just as mentioned above, Amazon is a major ecommerce player, having started as a bookstore and grown to become a major all-item shop. In addition, Amazon has intimate connections with other ecommerce service providers such as shopping cart software providers, payment companies such as PayPal, and credit and debit card firms e.g. Visa, American Express among others. Such a complex structure means that there are several areas through which hackers, employees and customers can find loopholes and exploit to the detriment of Amazon.

<h2>Amazon System</h2>
Amazon operates as a fully online system. The following diagrams attempts a graphical representation of the system

3.2    Amazon’s Assets
Amazon business system has various assets, which form the basis of its success. These assets can be categorized into:
Personnel
Information
System Facilities
System Infrastructure
Software

3.3 Users
There are four types of users who have been identified to interact in the Amazon system. These can be presented in the form of a table as shown below. Each of the user has different levels of privileges determined in the design of Amazon business structure.

User    Description
Buyer     Customer who bid and buy goods from the Amazon system
Seller     Customer who sell goods on the trading platform
Employee     Employees who administer the system, providing customer services and do help desks.
payment Systems     These utilize Amazon’s system information for financial transactions. These includes transfer of funds from buyers to sellers or the Amazon system

Types of Threats among Ecommerce Systems

Possible Threats among Ecommerce Systems

1.    There may be risk to firm’s data, classified information and intellectual property through employees and other trading partners. Some firms do not have structures on how to control handling of sensitive by third parties or contract workers. Few organizations have systems that ensure common standards in human resource and provision of security mechanisms between partners.
2.    Hackers may exploit errors in application software, implementation or systems operation. In addition, there may be vulnerabilities in security mechanisms and operating systems which are now widely published and can be accesses by anyone to read or experiment with.
3.    Website defacement – Under certain circumstances, the corporate image or messages on the website may be changed through virus attacks thereby leading to commercial embarrassment and damage to the business image portrayed to its partners and the public.
4.    Denial-of-service attacks – This threat comprises of a flood of false messages aimed at crashing a business’ systems – can have an overwhelming impact upon a business, especially if it depends on its e-commerce system. The growth of the internet means that there are more possibilities of such an attack, especially with the anonymity one can adopt in the internet meaning that it is harder to trace attacker. Such attackers are increasingly using botnets – a group of computers infected with malevolent software and controlled remotely – to cause these attacks.

List of System Risks and Recommended ways to Control Them

List of System Risks and Recommended ways to Control Them

  1. Sensitive Account Information can be Lost to Hackers Using spoofing and spamming
  2. Recommended controls
    •    Enforce customers’ use of secure web connections (HTTPS)
    •    Help customer to develop and configure filters using such technologies as “black list” and Microsoft Intelligent Message Filter to prevent phishing and pharming sites and spoofed-emails (E-mail Spoofing, 2009) from reaching customers.
    •    Implement new filter technologies such as “white-list”, which automatically record legitimate website based on URL address, page features, and DNS-IP
  3.   Application Servers are Subject to PHP Remote File Include
    Use PHP versions that has secured register_globals, allow_url_fopen (Remote File Inclusion, 2009).
    • Enforce PHP program security, e.g. input check to filter out executable remote file include as passed parameter from client web browsers to web and application servers.
  4. The Database Systems are Vulnerable to SQL Injection.
  5. The system can be affected by worms, viruses, spyware and other malicious code
    Recommended Control
    Deploy new techniques, such as Vigilante, that can  pose Contain Internet Worm Epidemics
    • Use up to date anti-virus and anti-spyware software
    • Enable TCP Wrapper/libwrap service deaemons. Khusial, D., McKegney(2005)
    • Deploy Intrusion detection system and ACLs
  6. Stealing of  User Data and Account Information
    Recommended Control
    •    Implement RDBMS vendor’s new security technologies, such as Oracle Transparent Data Encryption and column labeling (Oracle, 2009) to enforce database security at different gratuity level (e.g. database, table, column level).
    •    Proactive action to prevent suspicious and malicious SQL queries to access
  7. User account/password can Subject to Dictionary Attacks
    Enforce strong password policy to ensure it has certain complexity, length and mix of cases and numbers.
    Use incremental delay response after each failed login. Pinkas, B., Sander, T. (2002)

All About Amazon.com: Founders, Core Business and Risk Assessment

All About Amazon.com: Founders, Core Business and Risk Assessment

Amazon.com, Inc. is a prestigious business founded by Jeff Bezos in 1994 and launched online in 1995. It started off as a small online bookstore raising eyebrows world over. Since then, it has grown and expanded its portfolio and horizons.  It has its headquarters in Seattle, Washington and has separate websites across the world that services various countries such as Canada, Japan, and France etc.

Amazon’s growth from a bookstore to an online marketplace that sells just about anything a consumer can want has made it responsible for approximately one third of all E-Commerce in the United States and has America’s largest online retailer. In addition, Amazon is seen to have an edge in modern technology, noting that its system is one of the most innovative especially in the area of e-book development. For instance, they have developed The Kindle, a revolutionary e-book system. With this kind of profile and the responsibility it has to so many consumers, Amazon makes a great company to research.

The growth of the internet and online shopping has become a target ground for criminals to attempt to exploit.  There’s need for companies to consider the threats of online criminals and be adequately armed to deal with the possible occurrences of hacking, stolen identity, information theft among other risks facing ecommerce websites world over, such as a possibility of a virus getting into the system and deleting vital data.   Amazon is one such a company that has a major task at hand in securing its online marketplace and averting the dangers.

This research performs a risk assessment report regarding Amazon.com, identifying and evaluating threats and vulnerabilities that Amazon.com faces along with providing security controls to mitigate the threats and vulnerabilities. The major components evaluated are Amazon’s online transaction system; Amazons customer profile which can have sensitive information saved in it such as credit card information, bank account information, address information, etc.

Information to perform this risk assessment is gathered from a variety of online resources and books, along with the National Institute of Standards and Technology (NIST) Special Publication 800-30; Risk Management Guide for Information Technology Systems.