PRJ300 – Quick update – 22/08/08
Had a meeting with Mary today @ 2pm to discuss my progress on the project. She made a few suggestions:
- Research methods will be the discussion of the survey, such as why I am using a web-based survey, not a random sample but a planned sample. Aim at least 100 businesses to get 10 results back. The number of results is not important as long as the process is carried through.
- I can use some of the questions from the security survey by otago university but have to acknowledge the fact that the survey is based on questions from the otago survey.
- Start the literature review of the report, report on the research of the data security technologies. I will have to analyse what I have, and get the data security technologies from that.
- Write in the report on each of the data security technologies.
- For the meeting on 27th of Wednesday @ 2pm, bring the plan of the survey design including, why I am using a survey instead of other research methods, a list of businesses I will be sending the survey to (including manager names, and e-mail address). How I will be conducting the survey, other possible sites to host the survey, how will I get the the results back.
- In conjunction with the survey design research for this week, I should be working on the literature review as well. 25 questions is fine for a survey as long as the questions are simple. Bring a sample of example questions to the meeting on Wednesday.
- Read the Questionnaire Design paper which Mary gave to me.
Thats all I can think of at this stage,
You will hear from me soon,
Cheers,
Herb
PRJ300 – Update from the week – 16/08/08
As you know it has been a week since I last posted on this blog, but I have been busy with my literature research, researching survey design, and research methods. I got a couple of resources from the NMIT Library Learning Center. These were “How To Design Surveys” by Arlene Fink, “How To Ask Survey Questions” by Arlene Fink, “The Survey Methods Workbook” by Alan Buckingham, and Peter Saunders; and “Introduction to Network Security” by Neal Krawetz.
On top of this I have found vast amounts of knowledge from the Internet, which includes resources such as case studies of New Zealand E-Commerce businesses, research on data security methods, whitepapers relating to data security, and alot of references, which I will be looking at (these are mainly books relating to the data security field). Also I have got out from the library a couple of previous research reports by various students, the one I am notably looking at, at the moment is a research report by “Abiot A.S. Mathetha”, “Information Technology Infrastructure Library”. The reasons I am looking at this particular report was that I found the general layout of the report very professional, and it had an example survey with an analysis of the results. I would like to design my report very similar to his, so for me it was a very good resource of information.
That is all I can report back at the moment, but will report back on any progress I have made in relation to my research topic.
Cheers,
Herb
PRJ300 – 08/08/08 – Confirmation of proposal
The last date for the project proposal was last Friday being the 1st of August. On Friday 29th of July I handed in my proposal to the project co-ordinator Mary Proctors pigeon hole. And on August the 4th, Monday, Mary Claire wrote back:
“The project committee met on Friday and your proposal has been approved. The committee made the following comments:
- Rather than determining what current best practice is for e-commerce data security, it may be better to focus on finding out what is the current state of e-commerce data security in NZ.
- Unfortunately, Clare Atkins does not have any supervision hours available this semester, so I will be taking the role of your supervisor. This, of course, does not mean that you cannot approach Clare for advice throughout your project.
I would like to setup a weekly meeting time with you. The best times for me are Monday, Wednesday or Friday at 1:00pm. Please let me know if any of these suit you.”
I wrote back to Mary, that 1:00pm Monday would be fine with me, as Monday is the only day I come into Polytech, which means that I can spend the rest of my time spending time with my baby daughter
.
Mary wrote back:
“Mondays sound good. I will see you next Monday – until then just carry on with what you are doing and we can make a plan from there.”
I am not too sure if she meant carry on with project work, or generally just carry on with the rest of my studies, so this week the only work I have done on my project, is the work on this post. Hopefully on Monday I can understand more clearly what I should be doing.
Cheers,
Herb Hesketh
RES300 – Ideas on Project Proposal – 07/06/08
I prepared a draft project proposal for claire atkins to review on Friday. After reviewing the proposal on Friday claire told me a couple of hints which will give the proposal a more finished look. One of these suggestions was that: I should include a draft survey in the back of the document, as well as signing the ethical considerations form, however after doing some research on the Internet I came by quite an interesting survey. The survey can be found here: http://www.hkcert.org/english/nan/articles/sec2004_report.pdf.
RES300 – Information from Journal I researched – 27/05/08
I recently I had to review and document a Journal about “Web Security for E-Commerce” by Robert J. Boncella in the Communications of the Association for Information Systems Volume 4, Article 11, November 2000; for my RES300 class. There was some interesting information I found for my project, this was:
“Client-side security is concerned with the techniques and practices that protect a user’s privacy and the integrity of the user’s computing system. The purpose of client-security is to prevent malicious destruction of a user’s computer system, and to prevent unauthorized use of a user’s private information, such as use of a user’s credit card number for fraudulent purposes.”
“Server-side security is concerned with the techniques and practices that protect the Web server and its associated hardware from break-ins, Web site vandalism and denial of service attacks. The purpose of server-side security is to prevent modification of a Web site’s contents, prevent use of the server’s hardware, software, or databases for malicious purposes and to ensure reasonable access to a Web site’s services, i.e., to avoid or minimise denial of service attacks.”
“Secure transmission is concerned with the techniques and practices that will guarantee protection from eavesdropping and intentional message modification. The purpose of these security measures is to maintain the confidentiality and integrity of user and server information as it is exchanged through the communication channel.”
“With respect to e-commerce, Web security has as its main focus Web server security and secure transmission. There is some concern with client-side security. However the client can be mostly assured that the client’s security expectations will be met if the Web server and transmission channel are secure in the sense suggested above.”
RES300 – Reply to comment – 23/05/08
The question asked, was: ‘So are you thinking of doing a case study of one or more companies or are you thinking of doing a survey of as many companies as you can?’
Answer: I was thinking of doing a case study of one particular company but believe in my case it would be better, doing a survey of as many companies as I can, and preparing the results of the findings into a written report. It is my intention to look at North Island companies rather than South Island companies, as I believe the findings from the North Island will return more valuable results; compared to the South Island.
RES300 – Case Study Information – 14/05/08
In class last week, I was unsure as to what a case study was (as this might be what my project is termed under), so to refresh my memory I did a search on google and found an interesting Website. The article on the Website was called “How to Write a Case Study?, the first paragraphy reminded me, what a case study is all about:
“Case studies can be used in any academic discipline. The purpose of a case study is to provide a more thorough analysis of a situation or “case” which might reveal interesting information about that classification of things. For the business student, a case study could be done on a particular company; for the political science student a case study might concern a particular country or government/administration. Case studies could be written about individuals, such as how kids learn to read, for example, about organizations and their management practices, or the results of applying a computer science program or process to a problem. You might be trying to figure out how to solve the problem of illiteracy or environmental degradation. The sky is the limit. The key is to take your large problem and bring it down to the level of the individual or single unit.”
The Website where this information was from: ‘http://www.essayforum.com/10_366_0.html’
Also another interesting document was: “How to Write a Case Study” from: ‘http://www.gttp.org/docs/HowToWriteAGoodCase.pdf’
Cheers,
Herb
RES300 – Research Methods – 10/05/08
RES300 Research Methods
- Choosing a Research Approach -
-
What is the area/issue/problem that I am doing my research about? (we call this the research question)
Answer: Data security in E-commerce
- What is the purpose of the research I will do (this includes the question, what is your expected outcome from your research)?
Answer: To show businesses how important Data security in E-commerce is, and how this technology can benefit them.
-
Do I want to confirm something or explore something or build something?
Answer: Explore the current situation of Data security in E-commerce in New Zealand, aimed more at the North Island than the South Island.
-
Do I want the results of my research to be ‘generalisable’?
Answer: No
-
What do I think would be a good research approach?
Answer: Empirical research approach
-
Would it be a good idea to combine different approaches? If so, why?
Answer: No, could get confusing, the only other two research approaches which could be combined are: Theoretical (building a theory, which does not apply to my problem), and Constructive (which is building something, which does not apply to my problem) both research approaches do not provide any advantages to my problem.
-
How do I do this type of research?
Answer: Perform observations, measurements, and to get results back which will usually be numbers; in this case perhaps I might write a survey. Also research what a case study is, and get sample case studies to find out how to write one.
-
What are my skills and what do I need to learn to do this research?
Answer: Computer skills, research skills, I will need to learn to be more familiar with analytical skills (analysing numbers, and interpreting results). And get sample surveys to research what makes an effective survey.
-
What are the deadlines?
Answer: Whatever NMIT sets for the Project.
-
What resources will I need?
Answer: Research papers, journals, the Internet, and case studies.
RES300 – 06/05/08 – Holidays, Bloody Holidays
Hi,
After a long delay of my two week term holiday, clearing out the shed, and the getting the study room sorted for my new baby girl coming in july; I am now ready to report back on my findings I found over the term break.
During the break I typed “data security in e-commerce” into Google, and found an interesting link which led me to a Google electronic book called “Electronic Commerce” by Michael Erbschloe; in the book I found an interesting article:
“To secure information assets, organizations must open availability to legitimate users while barring unauthorized access. In general, secure systems must provide the following protections:
Accountability: Detect attacks in progress or trace any damage from successful attacks. Prevent system users from later denying completed transactions.
Availability: Ensure uninterrupted service to authorized users. Service interruptions can either be accidental or maliciously caused by denial-of-service attacks.
Confidentiality: Safeguard user privacy and prevent the theft of information both stored and in transit.
Integrity: Ensure that electronic transactions and data resources are not tampered with at any point, either accidentally or maliciously.“
Later on the author describes in one sentence “Simply put, the more accessible data is, the harder it is to protect“.
I thought this was all very interesting, and will try and find a copy in the library as it might contain more valuable information for my project. The book this information was from was:
Loshin, P and Vacca, J. (2004) Electronic Business, Fourth Edition. Boston, MA: Charles River Media, Inc.
RES300 – 18/04/08 – Proposal Preparation Work
Hi, today I was ask to prepare a number of questions for the preparation of the proposal, and this is what I came up with
1. Identify and describe at least one area of IT that you are interested in as an area in which you could do research. I am particularly interested in the area that you might choose as the basis of your project next semester.
- Data security in E-commerce; I have found out so far that E-commerce is basically electronic commerce (using the Internet as a marketplace), and data security can be a number of things, like: monitoring traffic, privacy, firewalls, digital signatures, digital certificates, transmission security, etc.
2. For the area (or one of the areas if you have described more than one) identify and describe at least 3 questions that you think would be interesting to research or investigate.
- Q1 – How advanced is data security in E-commerce?
- Q2 – What would be the problems of using data security in E-commerce? Is it hard to setup? What is the cost?
- Q3 – Why would you use data security in E-commerce?
3. For each of those 3 questions, identify and describe how you might go about finding the answers (in other words what kind of research approach might you use).
- Q1 – Review the literature on:
a) Data security in the past/now.
b) Comparison of data security benefits/problems.
c) People’s previous work in relation to data security.
- Q2 – a) Send a survey to businesses.
b) Find research papers relating to the problems associated with data security in E-commerce.
c) Use an Empirical research approach to back the question up with quantitative results.
- Q3 – a) Ask people from businesses (interview).
b) Use graphs to show the percentage of people who do use data security, the percentage of people who don’t, and the percentage of people who don’t even know that there is data security in E-commerce.