Case Study, Stage 1: Business Environment Analysis

Case Study, Stage 1: Business Environment Analysis

Before you begin this assignment, be sure you have read the “UR UMUC Healthy Fitness Center Case Study.”

Purpose of this Assignment

This assignment gives you the opportunity to apply the concepts of the Porter Five Forces model to a specific business, develop a strategic direction for your Fitness Center, and identify a process that could be improved with the use of technology.  This assignment specifically addresses the following course outcomes to enable you to:

  • analyze business strategy to recognize how technology solutions enable strategic outcomes
  • analyze internal and external business processes to identify information systems requirements.

Business Environment Analysis for UR UMUC Healthy Fitness Center

The UR UMUC Healthy Fitness Center has been in business since 1980 and has seen an increase in competition from small fitness centers, Cable TV and Internet Exercise channels and sites, Wii and other TV Game Console, various exercise equipment infomercials and increasing supply of Exercise DVD’s . One of your fitness instructors told you that she saw a sign announcing the construction of Gold’s Gym (a well-known national fitness franchise) a few blocks away.  Your staff is worried and is looking to you to provide reassurance that the competition will not affect the business.  In addition, you have decided to develop your strategic direction for bringing the UR UMUC Healthy Fitness Center into the 21st century.

You know that Michael Porter’s Five Forces Model is a useful tool for analyzing a business, understanding the importance of the five competitive forces and helping to develop its Generic Strategy.  It is also used to aid organizations facing the challenging decisions of dealing with changes made by existing competitors, entering a new industry or industry segment, or developing a strategy for dealing with new competition.  The Five Forces Model helps determine the relative importance of the forces affecting competitive position that could affect the future success of a business.  The Five Forces are:

  • Buyer Power
  • Supplier power
  • Threat of substitute products or services
  • Threat of new entrants
  • Rivalry among existing competitors

The Five Forces and the Generic Strategy are fully described and discussed in the textbook, and the Business Model and Competitive Advantage are covered in Module 1.  In order to analyze the Fitness Center’s current competitive position and develop a Generic Strategic direction, you have decided to use the Five Forces Model to analyze your Fitness Center business.

Assignment

 

Using the textbook and external resources, write a short paper 2-3  pages in length, not including References page and cover sheet, responding to the bulleted items below.  Remember to use the APA formatting rules and correctly cite and reference your sources with APA format.  Use the Grading Rubric to be sure you have covered everything.  Submit your paper via your Assignment Folder as a Microsoft Word document with your last name included in the filename.

 

Create a document that includes the following:

  • Brief introduction providing the background of the case, why you are writing and what is to come in your paper.  This should only be 3-5 sentences.

·         Perform a Porter’s Five Forces analysis for your UR UMUC Healthy Fitness Center, addressing each force in one or two sentences and defining the force, its impact (Positive, Negative or Neutral) on the Fitness Center and whether it should affect your strategy (Yes/No).  (See  Textbook, pp. 18-21 and Course Module 1.)  Do not identify solutions or things that you are doing that would affect the factor. (The idea is to identify how the different forces affect the UR UMUC Healthy Fitness Center and how much.) This provides you with a view of the business that will allow you to select a Generic Strategy and a Strategic Business Area on which to focus your efforts.

  • Determine which of Porter’s Three Generic Strategies (see textbook page 22) that you will use to improve your UR UMUC Healthy Fitness Center for the 21st century and explain why you selected it and tie it into the significant forces that you have identified.

·         Using your analysis of the Fitness Center’s Business Model (based on what you learned in Module 1), identify an important Strategic Business Area that needs to be improved.  The Strategic Business Area is to be selected from the direct variables (explained in Module 1 and illustrated in the Walmart Example Case Study, page 3).  The Direct Variables are:  suppliers, competition, employees, location, organizational components, owners and customers.  The Walmart Example demonstrates use of this concept, so you should review it and make sure that you are on the right track.  Explain why you have selected that Strategic Business Area and how improving it will improve operation of the Center, including how it relates to the Generic Strategy you selected.

  • Within the selected Strategic Business Area, identify and select a single daily process that is within and supports the Strategic Business Area that needs improvement.  Note:  A process is defined in your textbook as “a standardized set of activities that accomplish a specific task, such as processing a customer’s order.” (Baltzan, 2013, p. 23)   (In Stage 2 you will model the AS IS process and the TO BE Process, and propose a technology solution to improve the process you identify here, so select a process that is appropriate for a technology solution.)
  • At the end of your report with your References enter the following headings and complete the information using one concise phrase for each.  You will be starting each subsequent stage by including this information as a method to keep us focused on the objectives.

GENERIC STRATEGY:

STRATEGIC BUSINESS AREA:

PROCESS TO BE IMPROVED:

In determining which process you select for improvement, be sure to keep in mind the remaining projects within this Case Study.  You should review Stages 2-5 to get an understanding of the future projects that build on this initial stage and to aid you in selecting a process (and later proposing a technology solution) that can support the requirements of the follow-on assignments.

Do not start on Stage 2 until you receive feedback on this Stage as the Process that you select is crucial and your instructor may recommend that you change processes so that you can successfully complete the case.  You MUST incorporate the recommended changes in all subsequent Stages.

The “right” and “wrong” answers have to do with whether or not you correctly incorporated the course concepts from the textbook and addressed all parts of the assignment. You need to do some external research on at least one aspect of the assignment – your choice – and incorporate it and cite/reference it in APA format in your response. The specific strategic area you select for a technology solution is not as important as that it makes sense in light of the course content and the Case Study and is well supported with your application of the course concepts and your external research.   Use the Rubric below to be sure you have covered all aspects.

UR UMUC Healthy Fitness Center Case Study

In 1980, the UR UMUC Healthy Fitness Center was opened in a growing area of a bedroom community, by Tom Ellington, a UMUC Business Management graduate after he retired from the US Marine Corps. It has an exercise room with many different kinds of specialized equipment, rooms for various exercise and martial arts classes, and locker rooms with showers for men and women. In addition, there is a small snack area where members can buy bottled water, soda, fruit juices and snacks, with tables and chairs where people can relax. There are several part time staff members that man the counter where people check in; they also sell memberships and collect payments. There are trained exercise room attendants to assist members, and a maintenance staff to ensure cleanliness of the facility and minor maintenance of the equipment. Recently you were hired by the owner and founder as the manager, and you are very excited about this opportunity!

UR UMUC Healthy is a for-profit Fitness Center and must cover its variable costs, fund future improvements and produce a reasonable profit for the owners. Unfortunately, business has been steadily declining over the last five years. Although your predecessor did a good job at the Center, it has become out-dated. You recognize that some of the equipment really needs to be replaced, but you are not sure which equipment should be replaced first. The classes and exercise programs available have also become out-dated. There is little known about the makeup of the membership (age, sex, goals, interests, problems, complaints, etc.). You don’t know if there are long waits for particular equipment. If you had more information in these areas you feel that you could increase membership and income. For instance, if you knew which equipment was most heavily used, perhaps you would opt to replace that first, or add more similar equipment. The membership fee structure has not been reviewed in many years, and your contracts with outside firms that perform preventative and major maintenance, and those that provide cleaning supplies, vending machines, and towels have not been reviewed in a number of years. Recently, there have been weeks when the Center has run out of clean towels and the vending machines were out of the most popular items. In addition, customers have been requesting WiFi reception in the Center as well as cardio monitoring features on the cardio equipment.

The Center is open from 5 AM to 10 PM and is busy most of the day; however, the make-up of the people differs over the course of the day and each group has its own characteristics. The early group, 5 – 8 AM are the heavy workout members who speed through their exercises and head out for work or school. The next group, 8 AM -2 PM are older and take their time exercising and attending classes and spend a lot of time in social interaction; they are generally either retired or moms with their kids in school. The period from 2 – 4 PM is the least busy and is made up largely of high school students and others who like a less crowded environment. From 4 – 7 PM the group is made up of workers on their way home who want to get their workout in before dinner. The last group, 7 – 10 PM, is young single people who want show themselves off and attract the opposite sex, while exercising or taking classes.

One problem that you notice immediately is that you do not know which employees are scheduled to work each day, and there is no way to quickly get a substitute if one is needed. All employees require annual training and certifications in CPR, Safety, First Aid and the use of AED Defibrillators, while the contract trainers require various additional certifications periodically based on their specialty. All of the membership records, orders for towels and snack bar items, and financial and payroll accounts are kept on paper. The Center does not have a Web site, and uses very little marketing except word-of-mouth, and essentially still operates the same as it did in 1980.

Throughout this course you will manage the UR UMUC Healthy Fitness Center, taking advantage of business practices discussed in the class, the Course Modules and the textbook to increase revenue, keep the business running, and bring the Center into the 21st century. You will identify one area that is in need of improvement and that can be improved through the use of technology. You are not expected to solve all of the problems identified or address all improvements that could be made at the UR UMUC Healthy Fitness Center. Note: We’re looking for a technology solution. While installing a handball court may attract new customers, it is not a technology solution.

The following is an example of how you will identify a business need and a technology solution: Last year, the Fitness Center had no effective way to check its members in when they arrived. Sign-sheets were used at the front desk, and employees had to check that against their printed list of members. This caused members to have to wait at the front desk, and several had complained about this situation. To address the business need of quickly checking members in, a small system was acquired that allowed the Fitness Center to issue membership cards with a bar code; then, members swiped their card upon entry to the Center and if the card read successfully, the member would be admitted.

Note: As you approach the case study assignments, you will find it helpful to think about your own experiences with a fitness center or gym. Making a trip to a local fitness center may help you think about the processes, challenges, and opportunities.

STAGED ASSIGNMENTS

The case study and assignments address the Course Outcomes to enable you to:

· analyze business strategy to recognize how technology solutions enable strategic outcomes

· analyze internal and external business processes to identify information systems requirements

· identify and plan IT solutions that meet business objectives.

Upon completion of these assignments you will have performed an array of activities to demonstrate your ability to apply the course content to a “real world situation” to:

· Analyze the business environment and identify a strategic area for improvement  (Stage 1)

· Propose an appropriate technology solution to improve a selected business process (Stage 2)

· Evaluate various IT considerations of the proposed technology solution (Stage 3)

· Communicate your solution and the IT considerations to stakeholders using a presentation format (Stage 4)

· Identify and explain the next steps in implementing the solution (Stage 5)

The staged assignments are designed to follow the relevant course modules and chapters of the textbook in the class schedule, and are due on the dates shown in the Syllabus.

Stage 1 Project: Business Environment Analysis (Word document with analysis)

Stage 2 Project:  Business Process Models and Technology-Supported Solution Proposal (Word document with proposed solution and process diagrams)

Stage 3 Project:  Template for IT Considerations (Word table)

Stage 4 Project:  Executive Briefing Presentation (PowerPoint Presentation on proposed solution)

Stage 5 Project:  Outline of Next Steps (Word document in outline format)

The weight of the assignments is shown in the Course Syllabus. The due dates are shown in the Course Schedule.

Assignments for stages 1, 2 and 5 require external research, outside of the textbook and course modules.  The grading rubric is included with each assignment.

These assignments are designed to help you identify how to effectively analyze and interpret information to improve the business.  This is an opportunity for you to apply critical thinking skills and think like a business professional.  When you are writing a paper or developing a presentation, prepare it as if it is going to the owner, Mr. Ellington, whom you want to impress with your knowledge and abilities.  Don’t just go through the mechanics of pulling together information — think about what you are doing, why you’re doing it, whether it make sense, whether the information seems realistic, and what the results show.  Support your recommendations with your research. It’s important that you identify relevant, timely resources that specifically support the points or information you provide in your assignment. You should read the source and assimilate the information first, and then put it into your own words and incorporate it into the flow of your writing (with an appropriate in-text APA citation and a list of references at the end of your paper). Direct quotes should be used very sparingly—only when the author’s own words uniquely present a concept that would be lost if paraphrased by you.

One of the prerequisites for this course is that you have a fundamental working knowledge of word processing and presentation software. Detailed instructions for each Staged Project, 1 through 5, are posted in the designated area of the classroom. You are to prepare each assignment in the indicated format (i.e., table, outline, report, presentation or other specified format) and submit it as an attachment through your individual Assignments Folder in WebTycho.  No credit will be given for assignments submitted in file formats other than those stated in the assignment instructions.

Because these assignments require you to use Microsoft Word and PowerPoint (as indicated in the instructions), you may need to “brush up” on your familiarity with these or use functions that perhaps are new to you.  Therefore, do not wait until the last minute to begin an activity.  You should read through all the assignments in advance to ensure you (1) understand what is expected, and (2) allow enough time to effectively create the information being requested.

Additional Information 

There is a significant amount of information available to you to assist in developing your skills in using the Microsoft Office Products.  MS Word and PowerPoint are required for these exercises.  The textbook comes with access to the publisher’s website ( http://www.mhhe.com/baltzan) where there are a number of resources, including Tech Plug-Ins for Office 2003, 2007 and 2010.  Don’t hesitate to use the on-line help and wizard tools built into the MS Office applications for help as you work with the software tools.  There are also other web sites, such as www.eHow.com , and www.microsoft.com that provide tips.  Even YouTube has some useful videos demonstrating various techniques.

 

 

03/08/2013 3

Distinguish between vulnerability, threat, and control.

1.8 Exercises

1. Distinguish between vulnerability, threat, and control.

2. Theft usually results in some kind of harm. For example, if someone steals

your car, you may suffer financial loss, inconvenience (by losing your mode of

transportation), and emotional upset (because of invasion of your personal

property and space). List three kinds of harm a company might experience from

theft of computer equipment.

3. List at least three kinds of harm a company could experience from electronic

espionage or unauthorized viewing of confidential company materials.

4. List at least three kinds of damage a company could suffer when the integrity

of a program or company data is compromised.

5. List at least three kinds of harm a company could encounter from loss of

service, that is, failure of availability. List the product or capability to which

access is lost, and explain how this loss hurts the company.

6. Describe a situation in which you have experienced harm as a consequence of

a failure of computer security. Was the failure malicious or not? Did the attack

target you specifically or was it general and you were the unfortunate victim?

7. Describe two examples of vulnerabilities in automobiles for which auto

manufacturers have instituted controls. Tell why you think these controls are

effective, somewhat effective, or ineffective.

8. One control against accidental software deletion is to save all old versions of

a program. Of course, this control is prohibitively expensive in terms of cost of

storage. Suggest a less costly control against accidental software deletion. Is

your control effective against all possible causes of software deletion? If not,

what threats does it not cover?

9. On your personal computer, who can install programs? Who can change

operating system data? Who can replace portions of the operating system? Can

any of these actions be performed remotely?

10. Suppose a program to print paychecks secretly leaks a list of names of employees

earning more than a certain amount each month. What controls could be instituted to

limit the vulnerability of this leakage?

11. Preserving confidentiality, integrity, and availability of data is a restatement of the

concern over interruption, interception, modification, and fabrication. How do the

first three concepts relate to the last four? That is, is any of the four equivalent to one

or more of the three? Is one of the three encompassed by one or more of the four?

12. Do you think attempting to break in to (that is, obtain access to or use of) a

computing system without authorization should be illegal? Why or why not?

13. Describe an example (other than the ones mentioned in this chapter) of data

whose confidentiality has a short timeliness, say, a day or less. Describe an example

of data whose confidentiality has a timeliness of more than a year.

14. Do you currently use any computer security control measures? If so, what?

Against what attacks are you trying to protect?

15. Describe an example in which absolute denial of service to a user (that is, the user

gets no response from the computer) is a serious problem to that user. Describe

another example where 10 percent denial of service to a user (that is, the user’s

computation progresses, but at a rate 10 percent slower than normal) is a serious

problem to that user. Could access by unauthorized people to a computing system

result in a 10 percent denial of service to the legitimate users? How?

16. When you say that software is of high quality, what do you mean? How does

security fit in your definition of quality? For example, can an application be insecure

and still be “good”?

17. Developers often think of software quality in terms of faults and failures. Faults

are problems (for example, loops that never terminate or misplaced commas in

statements) that developers can see by looking at the code. Failures are problems,

such as a system crash or the invocation of the wrong function, that are visible to the

user. Thus, faults can exist in programs but never become failures, because the

conditions under which a fault becomes a failure are never reached. How do software

vulnerabilities fit into this scheme of faults and failures? Is every fault a

vulnerability? Is every vulnerability a fault?

18. Consider a program to display on your website your city’s current time and

temperature. Who might want to attack your program? What types of harm might

they want to cause? What kinds of vulnerabilities might they exploit to cause harm?

19. Consider a program that allows consumers to order products from the web. Who

might want to attack the program? What types of harm might they want to cause?

What kinds of vulnerabilities might they exploit to cause harm?

20. Consider a program to accept and tabulate votes in an election. Who might want

to attack the program? What types of harm might they want to cause? What kinds of

vulnerabilities might they exploit to cause harm?

21. Consider a program that allows a surgeon in one city to assist in an operation on a

patient in another city via an Internet connection. Who might want to attack the

program? What types of harm might they want to cause? What kinds of

vulnerabilities might they exploit to cause harm?

1. Describe each of the following four kinds of access control mechanisms in

terms of (a) ease of determining authorized access during execution, (b) ease of

adding access for a new subject, (c) ease of deleting access by a subject, and (d)

ease of creating a new object to which all subjects by default have access.

• per-subject access control list (that is, one list for each subject tells

all the objects to which that subject has access)

• per-object access control list (that is, one list for each object tells all

the subjects who have access to that object)

• access control matrix

• capability

2. Suppose a per-subject access control list is used. Deleting an object in such a

system is inconvenient because all changes must be made to the control lists of

all subjects who did have access to the object. Suggest an alternative, less costly

means of handling deletion.

3. File access control relates largely to the secrecy dimension of security. What

is the relationship between an access control matrix and the integrity of the

objects to which access is being controlled?

4. One feature of a capability-based protection system is the ability of one

process to transfer a copy of a capability to another process. Describe a situation

in which one process should be able to transfer a capability to another.

5. Suggest an efficient scheme for maintaining a per-user protection scheme.

That is, the system maintains one directory per user, and that directory lists all

the objects to which the user is allowed access. Your design should address the

needs of a system with 1000 users, of whom no more than 20 are active at any

time. Each user has an average of 200 permitted objects; there are 50,000 total

objects in the system.

6. Calculate the timing of password-guessing attacks:

(a) If passwords are three uppercase alphabetic characters long, how much

time would it take to determine a particular password, assuming that testing

an individual password requires 5 seconds? How much time if testing

requires 0.001 seconds?

(b) Argue for a particular amount of time as the starting point for “secure.”

That is, suppose an attacker plans to use a brute-force attack to determine a

password. For what value of x (the total amount of time to try as many

passwords as necessary) would the attacker find this attack prohibitively

long?

(c) If the cutoff between “insecure” and “secure” were x amount of time,

how long would a secure password have to be? State and justify your

assumptions regarding the character set from which the password is

selected and the amount of time required to test a single password.

7. Design a protocol by which two mutually suspicious parties can authenticate

each other. Your protocol should be usable the first time these parties try to

authenticate each other.

8. List three reasons people might be reluctant to use biometrics for

authentication. Can you think of ways to counter those objections?

9. False positive and false negative rates can be adjusted, and they are often

complementary: Lowering one raises the other. List two situations in which false

negatives are significantly more serious than false positives.

10. In a typical office, biometric authentication might be used to control access to

employees and registered visitors only. We know the system will have some false

negatives, some employees falsely denied access, so we need a human override,

someone who can examine the employee and allow access in spite of the failed

authentication. Thus, we need a human guard at the door to handle problems, as well

as the authentication device; without biometrics we would have had just the guard.

Consequently, we have the same number of personnel with or without biometrics,

plus we have the added cost to acquire and maintain the biometrics system. Explain

the security advantage in this situation that justifies the extra expense.

11. Outline the design of an authentication scheme that “learns.” The authentication

scheme would start with certain primitive information about a user, such as name and

password. As the use of the computing system continued, the authentication system

would gather such information as commonly used programming languages; dates,

times, and lengths of computing sessions; and use of distinctive resources. The

authentication challenges would become more individualized as the system learned

more information about the user.

• Your design should include a list of many pieces of information

about a user that the system could collect. It is permissible for the

system to ask an authenticated user for certain additional information,

such as a favorite book, to use in subsequent challenges.

• Your design should also consider the problem of presenting and

validating these challenges: Does the would-be user answer a truefalse

or a multiple-choice question? Does the system interpret natural

language prose?

12. How are passwords stored on your personal computer?

13. Describe a situation in which a weak but easy-to-use password may be adequate.

14. List three authentication questions (but not the answers) your credit card

company could ask to authenticate you over the phone. Your questions should be

ones to which an imposter could not readily obtain the answers. How difficult would

it be for you to provide the correct answer (for example, you would have to look

something up or you would have to do a quick arithmetical calculation)?

15. If you forget your password for a website and you click [Forgot my password],

sometimes the company sends you a new password by email but sometimes it sends

you your old password by email. Compare these two cases in terms of vulnerability

of the website owner.

16. Defeating authentication follows the method–opportunity–motive paradigm

described in Chapter 1. Discuss how these three factors apply to an attack on

authentication.

17. Suggest a source of some very long unpredictable numbers. Your source must be

something that both the sender and receiver can readily access but that is not obvious

to outsiders and not transmitted directly from sender to receiver.

18. What are the risks of having the United States government select a cryptosystem

for widespread commercial use (both inside and outside the United States). How

could users from outside the United States overcome some or all of these risks?

19. If the useful life of DES was about 20 years (1977–1999), how long do you

predict the useful life of AES will be? Justify your answer.

20. Humans are said to be the weakest link in any security system. Give an example

for each of the following:

(a) a situation in which human failure could lead to a compromise of

encrypted data

(b) a situation in which human failure could lead to a compromise of

identification and authentication

(c) a situation in which human failure could lead to a compromise of access

control

21. Why do cryptologists recommend changing the encryption key from time to

time? Is it the same reason security experts recommend changing a password from

time to time? How can one determine how frequently to change keys or passwords?

22. Explain why hash collisions occur. That is, why must there always be two

different plaintexts that have the same hash value?

23. What property of a hash function means that collisions are not a security

problem? That is, why can an attacker not capitalize on collisions and change the

underlying plaintext to another form whose value collides with the hash value of the

original plaintext?

24. Does a PKI perform encryption? Explain your answer.

25. Does a PKI use symmetric or asymmetric encryption? Explain your answer.

26. Should a PKI be supported on a firewall (meaning that the certificates would be

stored on the firewall and the firewall would distribute certificates on demand)?

Explain your answer.

27. Why does a PKI need a means to cancel or invalidate certificates? Why is it not

sufficient for the PKI to stop distributing a certificate after it becomes invalid?

28. Some people think the certificate authority for a PKI should be the government,

but others think certificate authorities should be private entities, such as banks,

corporations, or schools. What are the advantages and disadvantages of each

approach?

29. If you live in country A and receive a certificate signed by a government

certificate authority in country B, what conditions would cause you to trust that

signature as authentic?

30. A certificate contains an identity, a public key, and signatures attesting that the

public key belongs to the identity. Other fields that may be present include the

organization (for example, university, company, or government) to which that

identity belongs and perhaps suborganizations (college, department, program, branch,

office). What security purpose do these other fields serve, if any? Explain your

answer.

MySQL and MySQL Workbench install

1.1 MySQL and MySQL Workbench install

1. Go to www.mysql.com and download and install the Community Edition of MySQL.  Note that you do not have to register to complete the download.

2. Go to www.mysql.com and download and install MySQL Workbench. Both of these software products are available for Windows and Mac OS X.

3. Start up the database using the MySQL Workbench tool.

4. To show that you have completed these steps, perform a screen capture and upload it to this drop box.

5. Download the create_databases.sql script from the create_databases.sql.zip file and then open up the script in MySQL Workbench using the second icon from the left.

6. Then execute the script using the lightning bolt icon. This will create many of the tables that you will need for the rest of the course.

7. Complete the following chapter 2 exercises:

 

1. Make sure the MySQL Workbench and open a connection for the root user.

1. Check whether the MySQL server is running.  If it isn’t, start it.  When you’re done, close the Startup/Shutdown window.

 

2. Use MySQL Workbench to review the Account Payable (AP) database

1. In the Navigator window, expand the node for the AP database so you can see all of the database objects it contains.

2. View the data for the Vendors and Invoices tables.

3. Navigate through the database objects and view the column definitions for at least the Vendors and Invoices tables.

 

3. Use MySQL Workbench to enter and run SQL statements

1. Double-click the AP database to select it.  When you do that, MySQL Workbench should display the database in bold.

2. Open a SQL Editor tab. Then, enter and run this SQL statement: SELECT vendor_name FROM vendors

3. Delete the e at the end of vendor_name and run the statement again.  Note the error number and the description of the error.

4. Open another SQL Editor tab.  Then enter and run this statement:

SELECT COUNT(*) AS number_of_invoices,

SUM(invoice_total) AS grad_invoice_total

FROM invoices

 

 

 

 

2.1 Chapter 4 Exercises

Submit proof of completion of the following Chapter 4 exercises to the dropbox:

4. Write SELECT statement that returns these five columns:

vendor_name The vendor_name column from the Vendors table
invoice_date The invoice_date column from the Invoices table
invoice_number The invoice_number column from the Invoices table
li_sequence The invoice_sequence column from the Invoice_Line_Items table
li_amount The line_item_amount column from the Invoice_Line_Items table

 

Use aliases for the tables.  This should return 118 rows

Sort the final result set by vendor_name, invoice_date, invoice_number and invoice_sequence.

5. Write SELECT statement that returns three columns:

vendor_id The vendor_id column from the Vendors table
vendor_name The vendor_name column from the Vendors table
contact_name A concatenation of the vendor_contact_first_name and vendor_contact_last_name columns with a space between

 

Return one row for each vendor whose contact has the same last name as another vendor’s contact.  This should return 2 rows.  Hint: Use a self-join to check that the vendor_id columns aren’t equal but the vendor_contact_last_name columns are equal.

Sort the result set by vendor_contact_last_name.

6. Write a SELECT statement that returns these three columns:

account_number The account_number column from the General_Ledger_Accounts table
account_description The account_description column from the General_Ledger_Accounts table
invoice_id The invoice_id column from the Invoice_Line_Items table

 

Return one row for each account number that has never been used. This should return 54 rows.  Hint: Use an outer join and only return rows where the invoice_id column contains a null value.

Remove the invoice_id column from the SELECT clause.

Sort the final result set by the account_number column.

 

 

3.1 Chapter 5 and 6 Exercises

Submit proof of completion of the following exercises from Chapter 5 to the dropbox.

To test whether a table has been modified correctly as you do these exercises, you can write and run an appropriate SELECT statement. Or, when you’re usingMySQL Workbench, you can right-click on a table name in the Object Browser window and select the Select Rows – Limit 1000 command to display the data for the table in a Result tab.  To refresh the data in this tab after modifying the table data, click the Refresh button in the toolbar at the top of the tab.

1. Write an INSERT statement that adds this row to the Terms table:

terms_id: 6
terms_description: Net due 120 days
terms_due_days: 120

 

Use MySQL Workbench to review the column definitions for the Terms table, and include a column list with the required columns in the INSERT statement.

2. Write an UPDATE statement that modifies the row you just added to the Terms table.  This statement should change the terms_description column to “Net due 125 days”, and it should change the terms_due_days column to 125.

3. Write a DELETE statement that deletes the row you added to the Terms table in exercise 1.

Submit proof of completion of the following exercises from Chapter 6 to the dropbox:

1. Write a SELECT statement that returns one row for each vendor in the Invoices table that contains these columns:

The vendor_id column from the Vendors table The sum of the invoice_total columns in the Invoices table for that vendor

This should return 34 rows.

3. Write a SELECT statement that returns one row for each vendor that contains three columns:

The vendor_name column from the Vendors table The count of the invoices in the Invoices table for each vendor The sum of the invoice_total columns in the Invoices table for each vendor

6. Write a SELECT statement that answers this questions: What is the total amount invoiced for each general ledger account number? Return these columns:

The account number from the Invoice_Line_Items table The sum of the line item amounts from the Invoice_Line_Items table

Use the WITH ROLLUP operator to include a row that gives the grand total. This should return 22 rows.

Note: Once you add the WITH ROLLUP operator, you may need to use MySQL Workbench’s Execute SQL Script button instead of its Execute Current Statement button to execute this statement.

 

 

 

4.1 Code of Ethics

Submit a 2 page paper responding to this article:

http://www.dba-oracle.com/t_oracle_dba_code_of_ethics.htm

Address the adequacy of this code of ethics.  What ethical framework drives this proposed code of ethics?  (Recall the various ethical approaches from your CSC  510 or 810 class).  To what extent does each of the following ethical theories inform this proposed code?

· moral relativism

· utilitarianism

· deontological ethics

· virtue ethics

 

Are there additional dimensions that the doctrine of vocation brings into the discussion?  See http://blogs.lcms.org/2011/technology-vocation-2-2011

 

 

 

 

5.1 Chapter 9 and 12 Exercises

Submit proof of completion of the following exercises from Chapter 9 to the dropbox.

1. Write a SELECT statement that returns these columns from the Invoices table:

The invoice_total column A column that uses the ROUND function to return the  invoice_total column with 1 decimal digit A column that uses the ROUND function to return the invoice_total column with no decimal digits

2. Write a SELECT statement that returns these columns from the Date_Sample table in the EX database:

The start_date column A column that uses the DATE_FORMAT function to return the start_date column with its month name abbreviated and its month, day, and two-digit year separated by slashes A column that uses the DATE_FORMAT function to return the start_date column with its month and day returned as integers with no leading zeros, a two-digit year, and all date parts separated by slashes A column that uses the DATE_FORMAT function to return the start_date column with only the hours and minutes on a 12-hour clock with an am/pm indicator A column that uses the DATE_FORMAT function to return the start_date column with its month returned as an integer with no leading zeros, its month, day and two-digit year separated by slashes and its hours and minutes on a 12-hour clock with an am/pm indicator

3. Write a SELECT statement that returns these columns from the Vendors table:

The vendor_name column The vendor_name column in all capital letters The vendor_phone column A column that displays the last four digits of each phone number

When you get that working right, add the columns that follow to the result set.  This is more difficult because these columns require the use of functions within functions.

The vendor_phone column with the parts of the number separated by dots, as in 555.555.5555 A column that displays the second word in each vendor name if there is one and blanks if there isn’t

Submit proof of completion of the following exercises from Chapter 12 to the dropbox.

1. Create a view named open_items that shows the invoices that haven’t been paid.

This view should return four columns from the Vendors and Invoices tables:

vendor_name, invoice_number, invoice_total, and balance_due (invoice_total – payment_total – credit_total).

A row should only be returned when the balance due is greater than zero, and the rows should be in sequence by vendor_name.

3. Create a view named open_items_summary that returns one summary row for each vendor that has invoices that haven’t been paid.

Each row should include vendor_name, open_item_count (the number of invoices with a balance due), and open_item_total (the total of the balance due amounts)

The rows should be sorted by the open item totals in the descending sequence.

6. Write an UPDATE statement that changes the address for the row with a vendor ID of 4 so the suite number (Ste 260) is stored in the vendor_address2 column instead of the vendor_address1 column.

 

6.1 Chapter 13 and 14 Exercises

Submit proof of completion of the following exercise from Chapter 13 to the dropbox.

1. Write a script following the same structure as figure 13-1 that creates and calls a stored procedure named test.  This stored procedure should declare a variable and set it to the count of all rows in the Invoices table that have a balance due that’s greater than or equal to $5,000.  Then, the stored procedure should display a result set that displays the variable in a message like this:

3 invoices exceed $5,000.

Submit proof of completion of the following exercise from Chapter 14 to the dropbox.

1. Write a script that creates and calls a stored procedure named test.  This procedure should include a set of three SQL statements coded as a transaction to reflect the following change: United Parcel Service has been purchased by Federal Express Corporation and the new company is named FedUP.  Rename one of the vendors and delete the other after updating the vendor_id column in the Invoices table.

If these statements execute successfully, commit the changes.  Otherwise, roll back the changes.

 

 

 

 

7.1 Chapter 15 and 16 Exercises

Submit proof of completion of the following exercise from Chapter 15 to the dropbox.

1. Write a script that creates and calls a stored procedure named insert_glaccount.  First, code a statement that creates a procedure that adds a new row to the General_Ledger_Accounts table in the AP schema.  To do that, this procedure should have two parameters, one for each of the two columns in this table.  Then, code a CALL statement that tests this procedure.  (Note that this table doesn’t allow duplicate account descriptions.)

 

Submit proof of completion of the following exercise from Chapter 16 to the dropbox.

2. Create a trigger named invoices_after_update.  This trigger should insert the old data about the invoice into the  Invoices_Audit table after the row is updated.  Then, test this trigger with an appropriate UPDATE statement.  If the Invoices_Audit table doesn’t exist, you can use the code shown in figure 16-3 to create it.

 

 

 

 

 

8.1 Summary of learning

Submit a 3-page course summary describing and summarizing what you have learned in this course. Your paper should include two paragraphs on ethical use of databases and administrative rights.

Case Study: Appliance Warehouse – Analysis & Planning

Assignment Content

 

Overview

The Appliance Warehouse case study is designed to practice systems analysis and design skills using a life-like scenario. Appliance Warehouse is facing a big business change: create a Service Department as one of their product offerings.

They need you, the new systems analyst, to help them. You have been tasked to help develop a technological solution to help schedule service appointments and integrate it with existing systems. As a newly hired analyst, you report to Carlie Davis, the IT manager, who will guide you through the steps of this project.

In the MindTap simulation environment, you will see email examples to your (simulated) Appliance Warehouse email inbox. These simulated emails will contain instructions for each session, and you will consult the Appliance Warehouse’s resource libraries and website for additional information.

For this week’s assignment, be sure to refer to the Appliance Warehouse Resources: Organizational Staffing Document, Appliance Warehouse website, Historical Analysis Phase Durations spreadsheet.

Directions

In MindTap, review the Appliance Warehouse Case, and do the following:

o Read the Before You Begin Message and the Module 1-3 Appliance Warehouse Webmail Client Emails. Read the messages to help determine the tasks you must complete.

o Review and analyze the weekly Appliance Warehouse case study content and resources.

Create a 2- to 3-page document that includes the following:

o An Organization Chart to support the Appliance Warehouse case study

o The SWOT Analysis diagram you performed and created to support the Appliance Warehouse case study

o The Mission Statement to support the Appliance Warehouse case study

o The Problem/Opportunity Statement to support the Appliance Warehouse case study

Submit your document.

Resources will be provided upon request if a resources has been omitted and is required to complete the assignment.

Sheet1

Costs for in-house development Standard Development Times
As standard practice, use these costs for all in-house development. As standard practice, use these guidelines (assume 8 hours of work per day).
Cost per hour (for first year) Duration
Database Development $ 60 Database design 5 days
Web developers $ 75 Database build 10 days
App developers $ 75 Design of a report (web or app) 2 days
UX designers $ 60 Design of data entry page (web or app) 2 days
Business Analyst $ 50 Design of static text page (web or app) 1 day
Trainers $ 50 Build of a report (web or app) 1 day
Cybersecurity specialists $ 90 Build of data entry page (web or app) 1 day
System Admin $ 70 Build of static text page (web or app) 1 day
Connection to separate system or database (sys admin) 8 days
Analysis work (both web and app combined) 20 days
Training 5 days
Equipment: Cybersecurity work 10 days
Servers $ 2,500
Routers $ 200
Expected Monthly Maintenance:
Development (web or app) 2 days
System Admin 3 days
Training 1 day
Key:
Web or app = activity must be done for both web and app. Same amount of time required for each deliverable.
Both web and app = time given includes development for both of the web and app deliverables.

Resource Library/historical-analysis-phase-durations.xlsx