Answer To: Page 1 of 4 SBM4304 IS Security and Risk Management Semester 2, 2018 Assignment 2: Essay Due date:...
Sanchita answered on Aug 10 2020
Assignment 1
Information System at Starbucks
Introduction
Starbucks is the biggest coffee-chains in the world. It is headquartered in America and has outlets in more than 60+ countries in the world. Though, Starbucks has not been too successful in Australia, nevertheless, it is an organisation that handles millions of transactions everyday across the globe and hence it is of prime significance for the organisation to have a proper and well integrated Information System (IS) in place. It is a known fact that irrespective of the size of the organisation, it needed to have a security plan so that it can well ensure the safety and security of their valuable information, confidential data and other ancillary aspects of transaction-handling; if compromised with can prove detrimental for the business. Thus, it is pivotal to have a security plan in place. A security plan ensures the safety of their assets, personnel and facilities.
Starbucks Corporation is a famous coffee-chain and it offers its customers man varieties of coffee, snacks and similar consumables. On an average day, a single outlet handles more than 5000+ customers a day. And as Starbucks operates in many different parts of the world, the number of customers that it handles it magnanimous, thus Information system is used to handle and aid in the transaction process. It is imperative to note that as an organisation, it does not form working and business relationship with just its long list of customers but also its wide network and range of vendors, suppliers and even investors. Starbucks uses Information System to handle all these transactions in an organised, safe and secure manner.
There are two types of the internal control in the world of computer audit, one is General management control (GMCs) and another is Application Control (AC). As now, almost in every sphere of business, computers and digitisation of data have become an indispensible part of the business, it has become increasingly easier to collect, organise, process and disseminate data. Such rapid explosion and adoption of technology has expanded the ambit of business and has made such large-scale expansion of business possible. However, it has also posed some great risks and dangers for the organisations. With rapid exchange and flow of data digitally, there is consistent possibility of security threat and risks. Such security threats can generate tremendous badwill and bad reputation for the organisation, This report aims to analyse and assess the IS used by Starbucks to handle such large transition traffic and how it safeguards such large pool of confidential and valuable data.
Outline and GMC of Starbucks
At Starbucks, General Management Control constitutes of transforming data into meaningful information and making it available for employee serving different department who use it as per their needs and requirements. At starbucks, there is huge interdependence between different departments for information, data and directions of flow of operations. At times, information is collected from different departments in order to make decisions. Hence, Starbucks takes it very seriously to establish a good communication channel for all the different departments of the organisation (Corp, 2016). Starbucks has curated a web portal that has two ways of access; the store portal and the partner portal. The store portal is used by workers who are employed at the store to gather information primarily about the customers and the partner portal is used by higher executives and managers to oversee other operations of the company such as expansion, investment, disinvestment, partnership, diversification etc. This system was implemented by Starbucks in the year 2003 and since then, it has turned out to be the primary tool of information dissemination at different organisational level. Over the years, the paper work has been drastically reduced and has been substituted by digital means of information storage (Perfil, 2013).
In the recent years, the GMC has moved towards building of Enterprise Security...