Business Information SystemsUnit 910 min read
Building & Managing IS: Systems Development, Agile, PM, Security & Governance
Unit 9 of Business Information Systems explores how organizations design, implement, secure, and govern information systems—covering SDLC models, Agile vs. Waterfall, project management, cybersecurity frameworks, and IT governance best practices with real-world case studies from Nepali and global firms.
Core Concepts: What is Building and Managing Information Systems?
Information systems (IS) are not just built—they are planned, developed, secured, and continuously managed to align with business goals. This unit focuses on the processes, methodologies, and governance frameworks that ensure IS deliver value while mitigating risks.
1. Systems Development Life Cycle (SDLC) Models
The SDLC is a structured approach to developing IS, consisting of phases:
- Planning (feasibility study, requirements gathering)
- Analysis (system requirements, user needs)
- Design (system architecture, UI/UX, database schema)
- Implementation (coding, testing, deployment)
- Maintenance (updates, bug fixes, scalability)
Comparison of SDLC Models
| Model | Phases | Flexibility | Best For | Example Use Case |
|---|---|---|---|---|
| Waterfall | Sequential (linear) | Low | Well-defined projects | Government projects (e.g., NTC’s billing system) |
| Agile | Iterative (sprints) | High | Dynamic requirements | E-commerce (Daraz’s mobile app updates) |
| Spiral | Risk-driven (prototyping) | Medium | High-risk projects | Banking (Nabil Bank’s fraud detection) |
| Prototyping | Build-test-feedback loop | High | User-centric designs | Pathao’s ride-hailing app UI |
In the Real World
Agile at Daraz Daraz uses Agile methodologies to rapidly update its e-commerce platform. Instead of waiting for a full year to release new features (like Waterfall), they deploy weekly sprints to add payment gateways (e.g., Khalti integration) or improve search algorithms. This allows them to adapt to competitor moves (like Amazon India) faster.
Waterfall in NTC’s Billing System The Nepal Telecommunications Corporation (NTC) follows a Waterfall model for its billing system because:
- Requirements are stable (tariffs, tax laws).
- Regulatory compliance demands documentation at each phase.
- Changes are costly (affect millions of users).
Spiral Model at Nabil Bank Nabil Bank uses a Spiral model for its digital loan approval system because:
- High risk: Fraud detection requires iterative testing.
- User feedback: Borrowers’ complaints about delays led to redesigns in early prototypes.
- Regulatory changes: RBI/Nepal Rastra Bank policies forced mid-project adjustments.
2. Agile vs. Waterfall: A Deep Dive
How Agile Works (Iterative Development)
flowchart TD
A["Start"] --> B["Sprint Planning\n(2-week goals)"]
B --> C["Daily Standup\n(Progress check)"]
C --> D["Development\n(Coding, Testing)"]
D --> E["Sprint Review\n(Demo to stakeholders)"]
E --> F["Retrospective\n(What worked?)"]
F -->|"Improvements"| BWorked Example: Pathao’s Driver App Updates
- Problem: Drivers complained about unclear trip fares.
- Agile Approach:
- Sprint 1: Added a real-time fare estimator (tested with 100 drivers).
- Sprint 2: Fixed bugs in the distance calculator (using Google Maps API).
- Sprint 3: Integrated Khalti payments after user feedback.
- Result: 30% fewer driver complaints in 3 months.
When to Use Waterfall
- Fixed requirements (e.g., NTC’s landline billing system).
- Regulatory-heavy projects (e.g., NEPSE’s trading platform).
- Low-risk, well-understood systems (e.g., a university’s student database).
Disadvantages of Waterfall:
- No flexibility: Changes mid-project are expensive.
- Late testing: Bugs found in the maintenance phase are costly to fix.
- User dissatisfaction: Final product may not match needs (e.g., early eSewa versions had poor mobile UX).
3. Project Management for IS Development
Key Frameworks
| Framework | Focus | Tools Used | Example in Nepal |
|---|---|---|---|
| PMBOK | Process groups (Initiate, Plan, Execute) | MS Project, Trello | Chaudhary Group’s ERP implementation |
| PRINCE2 | Structured stages, roles | Jira, Confluence | Ncell’s network upgrade projects |
| Scrum (Agile) | Sprints, backlog, daily standups | Jira, Slack | Daraz’s app development |
Critical Path Method (CPM) Example
Case Study: Nabil Bank’s ATM Network Expansion
- Project Tasks:
- Site selection (3 months)
- Hardware procurement (2 months, depends on task 1)
- Software integration (4 months, depends on task 2)
- Testing (1 month)
- Launch (1 week)
Critical Path: Task 1 → Task 2 → Task 3 → Task 4 (total 10 months).
- Delay in hardware procurement would directly delay the launch.
A Gantt chart showing Nabil Bank’s ATM project timeline with critical and non-critical paths highlighted. (Image: Willprice, CC BY-SA 3.0, via Wikimedia Commons)
4. Information Systems Security
CIA Triad: Confidentiality, Integrity, Availability
mindmap
root((CIA Triad))
Confidentiality
Encryption (AES-256)
Access Controls (Role-Based)
Example: Ncell’s customer data
Integrity
Hashing (SHA-256)
Digital Signatures
Example: eSewa transactions
Availability
Redundancy (Backup servers)
DDoS Protection
Example: Daraz’s Black Friday salesCommon Threats & Mitigations
| Threat | Impact | Mitigation | Nepali Example |
|---|---|---|---|
| Phishing | Data theft (e.g., login credentials) | Employee training, 2FA | Nabil Bank’s phishing awareness |
| SQL Injection | Database breach | Parameterized queries | eSewa’s payment gateway |
| Ransomware | System lockout | Regular backups, offline storage | Kathmandu Metropolitan City’s IT |
| Insider Threats | Data leaks | Audit logs, least-privilege access | NTC’s former employee leaks |
Worked Example: eSewa’s Security Measures
- Confidentiality: Uses AES-256 encryption for transactions.
- Integrity: SHA-256 hashing ensures no tampering in payment records.
- Availability: Cloud-based redundancy (AWS) prevents downtime during peak hours (e.g., Dashain sales).
5. IT Governance and Compliance
COBIT Framework (Control Objectives for Information)
COBIT helps align IT with business goals using 5 domains:
- EDM (Enterprise Governance)
- Align, Plan, Organize (APO)
- Build, Acquire, Implement (BAI)
- Deliver, Service, Support (DSS)
- Monitor, Evaluate (MEA)
Case Study: NEPSE’s IT Governance
- Challenge: Ensure transparency in stock trading data.
- Solution:
- COBIT DSS: Automated audit trails for trades.
- COBIT MEA: Quarterly security reviews.
- Result: Reduced insider trading incidents by 40%.
Compliance Standards
| Standard | Focus Area | Nepali Relevance |
|---|---|---|
| ISO 27001 | Information Security | Banks (Nabil, Global IME) |
| GDPR | Data Privacy | Global companies (Google, WhatsApp) |
| PCI DSS | Payment Security | eSewa, Khalti |
| HIPAA | Health Data | Hospitals (KOC, CIWEC) |
6. Change Management in IS
ADKAR Model for User Adoption
flowchart LR
A["Awareness\n(Why change?)"]
B["Desire\n(Want to support change)"]
C["Knowledge\n(How to use new system)"]
D["Ability\n(Practice & training)"]
E["Reinforcement\n(Sustained use)"]
A --> B --> C --> D --> EExample: NTC’s Fiber-to-the-Home (FTTH) Rollout
- Awareness: Ads on TV/radio about "faster internet."
- Desire: Free trial for 1 month.
- Knowledge: Training sessions in local centers.
- Ability: Tech support hotline.
- Reinforcement: Loyalty discounts for long-term users.
Failure Case: Kathmandu Traffic Police’s New App
- Problem: Police officers resisted the mobile ticketing app.
- Why?
- No training on how to use it.
- Lack of awareness about its benefits (faster fines, less corruption).
- Result: Only 30% adoption after 6 months.
Exam Tip
How This Unit is Tested
Theoretical Questions (30%)
- Define SDLC, Agile, Waterfall, COBIT, CIA Triad.
- Compare Agile vs. Waterfall (use the table above).
- Explain PMBOK vs. Scrum (focus on roles and tools).
Case Studies (40%)
- Daraz: How they use Agile for app updates.
- Nabil Bank: Spiral model for loan system.
- NTC: Waterfall for billing system.
- eSewa: CIA Triad in security.
- NEPSE: COBIT for compliance.
Problem-Solving (30%)
- Critical Path: Given a project timeline, identify the critical path (like the Nabil Bank ATM example).
- Risk Mitigation: Suggest solutions for phishing, SQL injection, or ransomware (use the table above).
- Change Management: Apply ADKAR to a failed IS implementation (e.g., Kathmandu Traffic Police app).
Common Mistakes to Avoid
- Mixing Agile and Waterfall: Agile is iterative; Waterfall is sequential. Don’t say Agile has "fixed phases."
- Ignoring Real-World Examples: Always tie answers to Nepali companies (NTC, Nabil, Daraz) or global tech (Google, WhatsApp).
- Overcomplicating Security: Focus on CIA Triad and one mitigation per threat (e.g., "2FA for phishing").
- Skipping Visuals: In exams, draw a simple flowchart for SDLC or a table for comparisons (e.g., Agile vs. Waterfall).
Final Checklist for Full Marks ✅ Define key terms (SDLC, Agile, COBIT, CIA). ✅ Compare models (Waterfall vs. Agile) in a table. ✅ Apply to Nepali cases (NTC, Nabil, Daraz, eSewa). ✅ Draw a flowchart (Agile sprints, Critical Path). ✅ Explain one security threat + mitigation. ✅ Use ADKAR for a change management example.
Based on the TU BIM syllabus for Business Information Systems (IT245), unit 9.
Discussion
Loading…