What types of information are exchanged and with whom

Assignment Help Computer Engineering
Reference no: EM133337748

Rotation assignment takes you to the Office of the Chief Financial Officer (CFO).

An external audit of the company's financial operations has just been completed. Last week, an "early look" copy of the audit was sent to the CFO with a request for a formal written response for each of the findings. Some of the problem areas were known to the CFO's staff and they were already working on the required responses. But, there is one set of findings that came as a complete surprise -- Shadow IT -- the unauthorized / unapproved use of cashless payment technologies by certain locations and offices within the company. These technologies included:

1. Micro payments using a payment card issued by guest services to hotel guests and via unattended vending machines to visitors. These payment cards are loaded with a cash value deposited to the card's account via a credit card charge. Guest services also credits some of these payment card accounts with "reward dollars" for guests who belong to the hotel's affinity program. The payment cards are used at service locations which do not have a cashier station. e.g. game arcade, self-service laundry or sales kiosk, etc. The payments are processed by a third party service provider which then uses an electronic funds transfer to pay the hotel its share of the income.

2. Mobile Payments for services booked through the concierge desk with an authorized but independent provider (not a hotel employee). These services include: private lessons with a tennis or golf pro, childcare, tours and tour guides, interpreters, etc. These payments are made by cell phone either as a mobile payment using a contactless payment system such as Apple Pay or by swiping a credit card through a magnetic stripe reader connected to the provider's cell phone. The payment accounts which receive the guests' payments are connected to the hotel's merchant card accounts. The hotel pays the providers monthly via electronic deposit and issues an IRS Form 1099 to record the income.

The CFO must make a presentation to the IT Governance board about these payment systems as a first step towards either getting approval for continued use or issuing a "cease and desist" directive to force the rogue offices and locations to stop using the unapproved payment systems. The presentation must include information about known or suspected compliance issues for PCI-DSS. The IT Governance board has previously asked project sponsors for information about potential privacy and security issues.

Due to the size and complexity of the problem, the CFO has split the available staff into two teams. Team #1 will focus on the micro payment cards. Team #2 will focus on the mobile payment systems. You have been asked to join one of these two teams and assist with their research. (Note: you *must* pick one and only one of the two technologies to focus on for your discussion paper this week.)

Your team leader has asked you to read the provided background information (see the Week 7 readings) and then put together a concise (approximately 300 word) summary of the important points from your readings. You have also been asked to help identify and describe / explain 3 or more privacy and security issues that could arise in conjunction with the use of the technology being studied by your team. Remember to keep your focus on the financial aspects of the technology implementation since you are contributing to the CFO's effort. (Financial aspects include how payments are made, what types of information are exchanged and with whom, how that information is protected, etc.)

Provide in-text citations and a reference list at the end of your summary paper (APA format recommended).

Reference no: EM133337748

Questions Cloud

Does action solve the issue of the unapplied device : CIST 2411 Central Georgia Technical College device profile and notice that the Include list has the profile assigned to All Users. You change the assignment
How should cybersecurity act of 2015 be updated to reflect : How should the Cybersecurity Act of 2015 be updated to reflect better and more value-added for the public-private partnership regarding Cybersecurity?
Discuss the deontology and utilitarianism moral stances : Did the HR staff that should have reported to the hiring manager the candidate's conviction and parole commit an ethical lapse, or was it just a clerical error?
Cybersecurity life cycle and cybersecurity framework : Explain how you would apply the cybersecurity life cycle, cybersecurity framework, and methodologies to establish a cybersecurity program
What types of information are exchanged and with whom : CSIA 300 University of Maryland Rotation assignment takes you to the Office of the Chief Financial Officer (CFO) - Provide in-text citations and a reference
Experience of forensics-incident response in organization : Based on your experience of forensics and incident response in an organization
Explain a rootkit hides : Explain how a rootkit "hides" and what can be done to find and remove them. Share one breach that was the result of a rootkit.
Recommends the use of wireless controllers : detailed description for the WAN connections to the distribution centers that includes backup connectivity or an alternate access method if the main connection
Easiest items to extract during investigation : What are some of the easiest items to extract during an investigation?

Reviews

Write a Review

Computer Engineering Questions & Answers

  Mathematics in computing

Binary search tree, and postorder and preorder traversal Determine the shortest path in Graph

  Ict governance

ICT is defined as the term of Information and communication technologies, it is diverse set of technical tools and resources used by the government agencies to communicate and produce, circulate, store, and manage all information.

  Implementation of memory management

Assignment covers the following eight topics and explore the implementation of memory management, processes and threads.

  Realize business and organizational data storage

Realize business and organizational data storage and fast access times are much more important than they have ever been. Compare and contrast magnetic tapes, magnetic disks, optical discs

  What is the protocol overhead

What are the advantages of using a compiled language over an interpreted one? Under what circumstances would you select to use an interpreted language?

  Implementation of memory management

Paper describes about memory management. How memory is used in executing programs and its critical support for applications.

  Define open and closed loop control systems

Define open and closed loop cotrol systems.Explain difference between time varying and time invariant control system wth suitable example.

  Prepare a proposal to deploy windows server

Prepare a proposal to deploy Windows Server onto an existing network based on the provided scenario.

  Security policy document project

Analyze security requirements and develop a security policy

  Write a procedure that produces independent stack objects

Write a procedure (make-stack) that produces independent stack objects, using a message-passing style, e.g.

  Define a suitable functional unit

Define a suitable functional unit for a comparative study between two different types of paint.

  Calculate yield to maturity and bond prices

Calculate yield to maturity (YTM) and bond prices

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd