IT245 Business Information Systems

Business Information SystemsUnit 910 min read

Building & Managing IS: Systems Development, Agile, PM, Security & Governance

Unit 9 of Business Information Systems explores how organizations design, implement, secure, and govern information systems—covering SDLC models, Agile vs. Waterfall, project management, cybersecurity frameworks, and IT governance best practices with real-world case studies from Nepali and global firms.

Core Concepts: What is Building and Managing Information Systems?

Information systems (IS) are not just built—they are planned, developed, secured, and continuously managed to align with business goals. This unit focuses on the processes, methodologies, and governance frameworks that ensure IS deliver value while mitigating risks.

1. Systems Development Life Cycle (SDLC) Models

The SDLC is a structured approach to developing IS, consisting of phases:

  1. Planning (feasibility study, requirements gathering)
  2. Analysis (system requirements, user needs)
  3. Design (system architecture, UI/UX, database schema)
  4. Implementation (coding, testing, deployment)
  5. Maintenance (updates, bug fixes, scalability)

Comparison of SDLC Models

Model Phases Flexibility Best For Example Use Case
Waterfall Sequential (linear) Low Well-defined projects Government projects (e.g., NTC’s billing system)
Agile Iterative (sprints) High Dynamic requirements E-commerce (Daraz’s mobile app updates)
Spiral Risk-driven (prototyping) Medium High-risk projects Banking (Nabil Bank’s fraud detection)
Prototyping Build-test-feedback loop High User-centric designs Pathao’s ride-hailing app UI

In the Real World

  1. Agile at Daraz Daraz uses Agile methodologies to rapidly update its e-commerce platform. Instead of waiting for a full year to release new features (like Waterfall), they deploy weekly sprints to add payment gateways (e.g., Khalti integration) or improve search algorithms. This allows them to adapt to competitor moves (like Amazon India) faster.

  2. Waterfall in NTC’s Billing System The Nepal Telecommunications Corporation (NTC) follows a Waterfall model for its billing system because:

    • Requirements are stable (tariffs, tax laws).
    • Regulatory compliance demands documentation at each phase.
    • Changes are costly (affect millions of users).
  3. Spiral Model at Nabil Bank Nabil Bank uses a Spiral model for its digital loan approval system because:

    • High risk: Fraud detection requires iterative testing.
    • User feedback: Borrowers’ complaints about delays led to redesigns in early prototypes.
    • Regulatory changes: RBI/Nepal Rastra Bank policies forced mid-project adjustments.

2. Agile vs. Waterfall: A Deep Dive

How Agile Works (Iterative Development)

flowchart TD
    A["Start"] --> B["Sprint Planning\n(2-week goals)"]
    B --> C["Daily Standup\n(Progress check)"]
    C --> D["Development\n(Coding, Testing)"]
    D --> E["Sprint Review\n(Demo to stakeholders)"]
    E --> F["Retrospective\n(What worked?)"]
    F -->|"Improvements"| B

Worked Example: Pathao’s Driver App Updates

  • Problem: Drivers complained about unclear trip fares.
  • Agile Approach:
    1. Sprint 1: Added a real-time fare estimator (tested with 100 drivers).
    2. Sprint 2: Fixed bugs in the distance calculator (using Google Maps API).
    3. Sprint 3: Integrated Khalti payments after user feedback.
  • Result: 30% fewer driver complaints in 3 months.

When to Use Waterfall

  • Fixed requirements (e.g., NTC’s landline billing system).
  • Regulatory-heavy projects (e.g., NEPSE’s trading platform).
  • Low-risk, well-understood systems (e.g., a university’s student database).

Disadvantages of Waterfall:

  • No flexibility: Changes mid-project are expensive.
  • Late testing: Bugs found in the maintenance phase are costly to fix.
  • User dissatisfaction: Final product may not match needs (e.g., early eSewa versions had poor mobile UX).

3. Project Management for IS Development

Key Frameworks

Framework Focus Tools Used Example in Nepal
PMBOK Process groups (Initiate, Plan, Execute) MS Project, Trello Chaudhary Group’s ERP implementation
PRINCE2 Structured stages, roles Jira, Confluence Ncell’s network upgrade projects
Scrum (Agile) Sprints, backlog, daily standups Jira, Slack Daraz’s app development

Critical Path Method (CPM) Example

Case Study: Nabil Bank’s ATM Network Expansion

  • Project Tasks:
    1. Site selection (3 months)
    2. Hardware procurement (2 months, depends on task 1)
    3. Software integration (4 months, depends on task 2)
    4. Testing (1 month)
    5. Launch (1 week)

Critical Path: Task 1 → Task 2 → Task 3 → Task 4 (total 10 months).

  • Delay in hardware procurement would directly delay the launch.

Critical Path Method diagramA Gantt chart showing Nabil Bank’s ATM project timeline with critical and non-critical paths highlighted. (Image: Willprice, CC BY-SA 3.0, via Wikimedia Commons)


4. Information Systems Security

CIA Triad: Confidentiality, Integrity, Availability

mindmap
  root((CIA Triad))
    Confidentiality
      Encryption (AES-256)
      Access Controls (Role-Based)
      Example: Ncell’s customer data
    Integrity
      Hashing (SHA-256)
      Digital Signatures
      Example: eSewa transactions
    Availability
      Redundancy (Backup servers)
      DDoS Protection
      Example: Daraz’s Black Friday sales

Common Threats & Mitigations

Threat Impact Mitigation Nepali Example
Phishing Data theft (e.g., login credentials) Employee training, 2FA Nabil Bank’s phishing awareness
SQL Injection Database breach Parameterized queries eSewa’s payment gateway
Ransomware System lockout Regular backups, offline storage Kathmandu Metropolitan City’s IT
Insider Threats Data leaks Audit logs, least-privilege access NTC’s former employee leaks

Worked Example: eSewa’s Security Measures

  1. Confidentiality: Uses AES-256 encryption for transactions.
  2. Integrity: SHA-256 hashing ensures no tampering in payment records.
  3. Availability: Cloud-based redundancy (AWS) prevents downtime during peak hours (e.g., Dashain sales).

5. IT Governance and Compliance

COBIT Framework (Control Objectives for Information)

COBIT helps align IT with business goals using 5 domains:

  1. EDM (Enterprise Governance)
  2. Align, Plan, Organize (APO)
  3. Build, Acquire, Implement (BAI)
  4. Deliver, Service, Support (DSS)
  5. Monitor, Evaluate (MEA)

Case Study: NEPSE’s IT Governance

  • Challenge: Ensure transparency in stock trading data.
  • Solution:
    • COBIT DSS: Automated audit trails for trades.
    • COBIT MEA: Quarterly security reviews.
  • Result: Reduced insider trading incidents by 40%.

Compliance Standards

Standard Focus Area Nepali Relevance
ISO 27001 Information Security Banks (Nabil, Global IME)
GDPR Data Privacy Global companies (Google, WhatsApp)
PCI DSS Payment Security eSewa, Khalti
HIPAA Health Data Hospitals (KOC, CIWEC)

6. Change Management in IS

ADKAR Model for User Adoption

flowchart LR
    A["Awareness\n(Why change?)"]
    B["Desire\n(Want to support change)"]
    C["Knowledge\n(How to use new system)"]
    D["Ability\n(Practice & training)"]
    E["Reinforcement\n(Sustained use)"]
    A --> B --> C --> D --> E

Example: NTC’s Fiber-to-the-Home (FTTH) Rollout

  • Awareness: Ads on TV/radio about "faster internet."
  • Desire: Free trial for 1 month.
  • Knowledge: Training sessions in local centers.
  • Ability: Tech support hotline.
  • Reinforcement: Loyalty discounts for long-term users.

Failure Case: Kathmandu Traffic Police’s New App

  • Problem: Police officers resisted the mobile ticketing app.
  • Why?
    • No training on how to use it.
    • Lack of awareness about its benefits (faster fines, less corruption).
  • Result: Only 30% adoption after 6 months.

Exam Tip

How This Unit is Tested

  1. Theoretical Questions (30%)

    • Define SDLC, Agile, Waterfall, COBIT, CIA Triad.
    • Compare Agile vs. Waterfall (use the table above).
    • Explain PMBOK vs. Scrum (focus on roles and tools).
  2. Case Studies (40%)

    • Daraz: How they use Agile for app updates.
    • Nabil Bank: Spiral model for loan system.
    • NTC: Waterfall for billing system.
    • eSewa: CIA Triad in security.
    • NEPSE: COBIT for compliance.
  3. Problem-Solving (30%)

    • Critical Path: Given a project timeline, identify the critical path (like the Nabil Bank ATM example).
    • Risk Mitigation: Suggest solutions for phishing, SQL injection, or ransomware (use the table above).
    • Change Management: Apply ADKAR to a failed IS implementation (e.g., Kathmandu Traffic Police app).

Common Mistakes to Avoid

  • Mixing Agile and Waterfall: Agile is iterative; Waterfall is sequential. Don’t say Agile has "fixed phases."
  • Ignoring Real-World Examples: Always tie answers to Nepali companies (NTC, Nabil, Daraz) or global tech (Google, WhatsApp).
  • Overcomplicating Security: Focus on CIA Triad and one mitigation per threat (e.g., "2FA for phishing").
  • Skipping Visuals: In exams, draw a simple flowchart for SDLC or a table for comparisons (e.g., Agile vs. Waterfall).

Final Checklist for Full Marks ✅ Define key terms (SDLC, Agile, COBIT, CIA). ✅ Compare models (Waterfall vs. Agile) in a table. ✅ Apply to Nepali cases (NTC, Nabil, Daraz, eSewa). ✅ Draw a flowchart (Agile sprints, Critical Path). ✅ Explain one security threat + mitigation. ✅ Use ADKAR for a change management example.

Based on the TU BIM syllabus for Business Information Systems (IT245), unit 9.

Discussion

Loading…