scieee AI-readable full text Open interactive document viewer

Business Informatics

Füzesi, István; Kovács, Tamás; Lengyel, Péter; Péntek, Ádám; Szilágyi, Róbert; Takács, Viktor; Várallyai, László

Abstract

Business Informatics is an interdisciplinary field that has evolved from the fusion of economics, information technology and management. It aims to effec tively use modern information tools and technologies to optimise and increase the efficiency of economic and business processes. Business Informatics includes business intelligence, database management, decision support sys tems, project management, IT strategy planning and other related areas. Business IT professionals play a key role in modern organisations, building bridges between business and IT. They can identify business needs and design and implement effective IT solutions. It is a dynamic field that is constantly adapting to technological advances and changing business needs. Business IT professionals are in high demand in the job market and have excellent career pros pects.

Full text

BUSINESS INFORMATICS ISBN 978-963-615-180-5 BUSINESS INFORMATICS Authors: ISTVÁN FÜZESI (CHAPTER 7) TAMÁS KOVÁCS (CHAPTER 1) PÉTER LENGYEL (CHAPTER 3) ÁDÁM PÉNTEK (CHAPTER 2) RÓBERT SZILÁGYI (CHAPTER 4) VIKTOR TAKÁCS (CHAPTER 5) LÁSZLÓ VÁRALLYAI (CHAPTER 6) Professional readers: ISTVÁN FÜZESI (CHAPTER 1) TAMÁS KOVÁCS (CHAPTER 2) PÉTER LENGYEL (CHAPTER 4) ÁDÁM PÉNTEK (CHAPTER 3) RÓBERT SZILÁGYI (CHAPTER 5) VIKTOR TAKÁCS (CHAPTER 6) LÁSZLÓ VÁRALLYAI (CHAPTER 7) © Debreceni Egyetemi Kiadó • Debrecen University Press, beleértve az egyetemi hálózaton belüli elektronikus terjesztés jogát is ISBN 978-963-615-180-5 ISBN (PDF) 978-963-615-181-2 Kiadta: aDebreceni Egyetemi Kiadó, az 1795-ben alapított Magyar Könyvkiadók és Könyvterjesztők Egyesülésének atagja dupress.unideb.hu Felelős kiadó: Karácsony Gyöngyi Készült a Debreceni Egyetemi Kiadó nyomdájában, 2024-ben Debreceni Egyetemi Kiadó Debrecen University Press 2024 BUSINESS INFORMATICS (AcAdemic Lecture notes) editor: Péter LengyeL Table of Contents Chapter 1: IntroductIon to BusIness InformatIcs (tamás Kovács) ........................................................................................... 7 1. Introduction .................................................................................. 7 2. Basic concepts .............................................................................. 8 3. Objectives of business informatics ............................................... 13 4. IT risks and opportunities ............................................................... 14 5. Skills and competencies required for jobs in the business ............... 16 References ....................................................................................... 19 Chapter 2: dataBase systems (ádám PénteK) ............................................................................................ 21 1. Introduction to databases .............................................................. 21 2. Database Management System (DBMS) ........................................... 23 3. Relational database management system (RDBMS) ......................... 24 4. Structured Query Language (SQL ) ................................................... 28 5. Conceptual Data Modeling ............................................................. 30 6. Database security .......................................................................... 32 References ........................................................................................ 33 Chapter 3: InformatIon systems (Péter LengyeL) ........................................................................................... 35 1. Introduction to Information Systems ............................................... 35 2. Fundamental components of Information Systems .......................... 39 3. Types and applications of Information Systems................................ 43 4. Security and ethical issues in Information Systems .......................... 45 5. Trends in Information Systems ........................................................ 47 References ........................................................................................ 50 Chapter 4: BusIness anaLysIs (róBert szILágyI) ......................................................................................... 53 1. Data, information, and knowledge .................................................. 53 2. Quantitative versus qualitative data analysis ................................... 56 3. Data storytelling ............................................................................. 58 4. Machine Learning and Business Intelligence .................................... 62 References ........................................................................................ 69 Chapter 5: BusIness Process management (BPm) (vIKtor taKács) ........................................................................................... 73 1. What is a Business Process? ........................................................... 75 2. Types of Business Processes ........................................................... 75 3. Business Process Improvement ...................................................... 77 4. Business Process Modeling ............................................................. 79 5. Business Process Modeling Notation (BPMN) ................................... 80 6. ARIS – eEPC (extended Event-driven Process Chain) ........................ 83 7. Workflow applications .................................................................... 87 References ........................................................................................ 88 Chapter 6: data securIty, data ProtectIon (LászLó váraLLyaI) ........................................................................................ 89 1. Basic safety concepts ..................................................................... 89 2. Threats and attacks ........................................................................ 93 3. Typical forms of attack and methods ............................................... 98 4. Defending against malicious attacks ............................................. 100 References ...................................................................................... 107 Chapter 7: BLocKchaIn technoLogy and cryPtocurrencIes (István füzesI) ........................................................................................... 109 1. Overview of blockchain technology ............................................... 109 2. Cryptocurrencies ......................................................................... 117 References ...................................................................................... 120 CHAPTER 1: INTRODUCTION TO BUSINESS INFORMATICS (tamás Kovács) 1. Introduction IT as a discipline is relatively young, but its roots go back to antiquity. The Ancient Greeks and Romans already used mechanical calculators, such as the abacus and the mechanical computer of ancient Cyrene. In the Middle Ages, scientists such as Al-Khwarizmi further developed computing techniques and introduced the decimal number system. The development of modern computer science began in the 17th century with the work of Blaise Pascal and Gottfried Wilhelm Leibniz, who developed mechanical calculators capable of more complex operations. In the 19th century, Charles Babbage created the analytical calculating machine, the first programmable computer. The 20th century brought the real revolution in computing. In 1937, John Atanasoff and Clifford Berry created the first electronic digital computer, the ABC. During the Second World War, Alan Turing used a computer called Colossus to decipher the Enigma code, which was instrumental in winning the war. After the war, electronic computers developed rapidly. The 1950s saw the first transistor computers, which were much smaller and faster than their predecessors. In the 1960s, integrated circuits were developed, allowing computers to be miniaturised and mass-produced. In the 1970s, the first microprocessors appeared, enabling the development of personal computers (PCs). The spread of the IBM PC in the 1980s brought a real revolution in computing. In the 1990s, Internet-connected computers spread into a global network. In the 21st century, the rapid development of information technology continues. The rise of artificial intelligence, big data, cloud computing and mobile phones is revolutionising computing. This discipline is con- 8BUSINESS INFORMATICS stantly evolving and permeates every aspect of modern life. Business Informatics can, therefore, be seen as an application area. Business Informatics is an interdisciplinary field that has evolved from the fusion of economics, information technology and management. It aims to effectively use modern information tools and techno logies to optimise and increase the efficiency of economic and business processes. Business Informatics includes business intelligence, database management, decision support systems, project management, IT strategy planning and other related areas. Business IT professionals play a key role in modern organisations, building bridges between business and IT. They can identify business needs and design and implement effective IT solutions. It is a dynamic field that is constantly adapting to technological advances and changing business needs. Business IT professionals are in high demand in the job market and have excellent career prospects. By learning Business Informatics: • You can learn to use IT tools effectively to optimise business processes. • You will be able to identify and analyse business needs. • Learn to design and implement effective IT solutions. • You will have excellent career prospects in the labour market. 2. Basic concepts Information systems (IS): these are software applications, databases, hardware and networks that work together to collect, store, process, analyse and disseminate information within an organisation. Data management involves effective organisation, storage, provision and retrieval of data to support informed decision-making. Business Process Management (BPM): focuses on mapping, analysing and improving the flow of activities within a business to optimise efficiency and effectiveness. Decision Support Systems (DSS): These computer-based tools provide managers with information, analysis and modelling capabilities to help them make data-driven decisions. 15 CHAPTER 1: INTRODUCTION TO BUSINESS INFORMATICS IT risks: Data security risks: The systems store sensitive data that can be stolen or manipulated by hackers or other malicious actors. Data security risks can cause severe financial losses and reputational damage to businesses. Data quality risks: poor quality data can lead to misleading analytical results, which can lead to poor decision-making. Data stored in systems must be accurate, complete and up-to-date. System failures: hardware and software failures can lead to downtime and data loss. Business IT systems must be reliable and available to businesses. Human error: human error, such as incorrect data entry or poor configurations, can have serious consequences. It is important to design and use IT systems in a way that minimises the risk of human error. Legal and compliance risks. Non-compliance can lead to financial penalties and legal consequences. IT opportunities: Improving efficiency: can help businesses by improving business processes, reducing costs and increasing productivity. It can help businesses develop new products and services, enter new markets and better serve existing customers. Reduce risks: This can help businesses identify and manage risks by providing insight into market trends, competitor activity, and operational efficiency. Facilitate better decision-making: This can help managers make better decisions by providing them with accurate and timely information on business performance. Gaining a competitive advantage: Businesses can gain a competitive advantage by making them more efficient and effective. Managing IT risks in business: Implement data security measures – Data security measures such as firewalls, encryption and access controls can help protect data from unauthorised access. Data quality controls can help ensure that data stored in business IT systems is accurate, complete and up-to-date. 16 BUSINESS INFORMATICS 5. Skills and competencies required for jobs in the business The IT sector is growing fast, and businesses are constantly looking for talented IT professionals. The skills and competencies required for a successful IT career are varied, but the most important include technical knowledge, problem-solving skills, communication and teamwork. This chapter reviews the key skills and competencies required for IT business positions, including technical and soft skills. In addition, some IT jobs may require additional specific skills and competencies. For example, a web developer must be familiar with web development languages and frameworks, while a data scientist will need statistical and machine-learning skills. The following are the most common skills required to fill a job in business IT. Technical skills: • Security: understanding cyber security threats and solutions is key to protecting business data and systems. • Programming: while not all IT roles require coding, some level of programming skills is beneficial, especially for tasks such as automation and customisation. Some jobs require at least a working knowledge of a programming language such as Python, Java, C++ or JavaScript. • Systems and networks: Managing and troubleshooting computer systems, networks and devices is essential. This includes knowledge of different operating systems (Windows, Linux, Mac). • Cloud computing: Cloud technology is now widely used by businesses. Expertise in cloud platforms such as AWS, Azure or GCP is valuable. • Data analytics: Many IT jobs involve working with data. The ability to analyse, interpret and visualise data is a sought-after skill. Soft Skills: • Communication: excellent written and verbal communication is essential to convey technical information to technical and non-technical audiences. • Problem-solving: IT professionals routinely troubleshoot and solve complex problems. Strong analytical and logical thinking is key. • Organisation and time management: prioritising tasks, managing deadlines and staying organised is essential in a fast-paced IT environment. 17 CHAPTER 1: INTRODUCTION TO BUSINESS INFORMATICS In addition, some business IT jobs may require specific skills, depending on the field. Business analysts, for example, may need business acumen, while IT security professionals may need a thorough understanding of security protocols and tools. In addition to having mixed knowledge, some roles may require a more generalist approach: e.g., DataAnalysts may already have a working knowledge of Python programming language, alongside strong business and analytical skills. Business IT professionals can work in both research and commerce. In business, there are different uses, which vary depending on professional experience. The most commonly employed areas are: • Management consultancy • IT consultancy • IT account manager • Systems analysis and organisation • Business analyst • IT project manager • IT auditor • Solution Designer • Enterprise Architect • Information Technology Management There are many ways to develop, but the most important ones include continuous training, obtaining certificates, gaining practical experience, networking and self-learning: • Continuous training: a range of courses, online courses, and boot camps are available to help you learn the latest technologies. These programmes are flexible and fit different learning styles and schedules. • Earn certifications: industry-recognised certifications demonstrate expertise and make your CV more attractive to prospective employers. There are many certifications in various IT fields, so everyone can find the right one for them. • Gaining experience: practical experience is essential to reinforce the theoretical knowledge you have learned. There are many ways to gain experience, including volunteering, participating in side projects, or contributing to open-source projects. • Networking: networking with other IT professionals is an excellent way to learn, develop your career and keep up with the latest trends. There 18 BUSINESS INFORMATICS are many industry events and conferences where you can meet other professionals, expand your network and build valuable contacts. • Self-learning: Many online resources, blogs and professional journals help you stay current. Continuous learning and development is essential for IT professionals to succeed. By applying these strategies, they can expand their knowledge, acquire new skills and remain competitive. Key-works, tasks and job opportunities Business Information Technology (BIT) is a dynamic field that offers many exciting job opportunities for professionals with different skills and experience. Business IT professionals collect, analyse and visualise data to provide businesses with valuable insights that can lead to better decision-making and more efficient operations. The most common job opportunities for business IT professionals Unsurprisingly, due to the traineeship orientation, jobs have been created in each company that are linked or partially linked to the tasks. These range from creating the simplest queries to building executive dashboards, complex system design, and data mining. Thus, it can be said that the field is constantly evolving and very diverse. Data Analyst: Data Analysts focus on collecting, analysing and visualising data to provide business insights. Report Writer: Report writers are responsible for producing reports on the analysis results. Business Intelligence (BI) Developer: BI developers develop and maintain business IT software and systems. Data Scientist: Data Scientists use advanced statistical and machinelearning techniques to extract insights from data. Data Architect: Data architects are responsible for designing and developing databases and data warehouses. 19 CHAPTER 1: INTRODUCTION TO BUSINESS INFORMATICS REFERENCES Bach, M. P., Praničević, D. G., Šebalj, D., & Pihir, I. (2018). Employment of business informatics graduates: Preliminary results. In Central European Conference on Information and Intelligent Systems (pp. 55–60). Faculty of Organization and Informatics Varazdin. Beynon-Davies, P. (2019). Business information systems. Bloomsbury Publishing. ISBN 978-1352009998 Helfert, M. (2008). Business informatics: An engineering perspective on information systems. Journal of Information Technology Education: Research, 7(1), 223–245. ISSN 1539-3585 Helfert, M. (2010). Business informatics. In Encyclopedia of Library and Information Sciences (Vol. 1, pp. 687–692). DOI: 10.1081/E-ELIS3-120043478 Herdon, M., Bakó, M., Lengyel, P., Nagyné, P. I., Rózsa, T., Szilágyi, R., & Várallyai, L. (2011). Üzleti informatika jegyzet. Debreceni Egyetem AGTC GVK. ISBN 978-963318-158-2 Pedersen, M. K., & Larsen, M. H. (2000). The efficiency opportunity impact of information systems in an organizational economics framework of informatics. Copenhagen Business School. Stair, R. M., & Reynolds, G. (2008). Fundamentals of business information systems. Thomson Learning. ISBN 978-0324406271 Wigand, R. T., Mertens, P., Bodendorf, F., König, W., & Schumann, M. (2003). Introduction to business information systems. Springer Science & Business Media. ISBN 978-3540001584 Zając, D., Nycz, M., & Pólkowski, Z. (2018). The graduate profile in the field of informatics and business informatics in the context of labour market needs. CHAPTER 2: DATABASE SYSTEMS (ádám PénteK) 1. Introduction to databases A database is a structured collection of data organized to facilitate the efficient storage, retrieval and management of information. It is a central repository for storing and managing data, allowing users to store, retrieve and update information as required. The database is made up of tables organized in rows and columns. Each row represents a record or entry, while each column represents a particular attribute or field within that record. These tables are linked through relationships, forming a relational database model that helps maintain data integrity and consistency. Databases are used in various applications and industries, including business, finance, healthcare and education. Their role in supporting the functioning of organizations is indispensable. They store a wide range of information, including customer data, data related to financial records, inventory data, employee information, and data essential for production and other operations. Because data is now a core business asset, in addition to storage, databases provide features such as data security, data integrity, concurrency control, and backup and recovery procedures to ensure the reliability and availability of the information they hold. 1.1. The database of related concepts 1. Data structure: data are organized in a structured format. It typically consists of tables, rows and columns. This format allows efficient storage and retrieval of data and the creation of relationships between individuals. 22 BUSINESS INFORMATICS 2. Data integrity: integrity rules and constraints are enforced to ensure that data remain accurate, consistent and reliable. Integrity constraints, such as primary keys, foreign keys and unique constraints, help prevent data inconsistencies and ensure that data meet defined criteria. 3. Data independence: changing the structure (schema) of the database does not necessarily require changing the applications that use the data. The separation between the logical and physical aspects of the database allows for greater flexibility and adaptability. 4. Data security: a critical issue for databases. Sensitive and confidential information is stored in them, so procedures are needed to protect against data breaches, such as user authentication, aut horization, encryption, protection against unauthorized access, etc. 5. Data consistency: data must comply with predefined rules and restrictions. 6. Queries: databases provide powerful tools that allow users to retrieve specific information from the database using structured query language (SQL) or other query languages. Queries can filter, sort, and aggregate data based on specific criteria, allowing users to extract meaningful insights from the database. 7. Data recovery: tools that can efficiently recover databases in the event of data loss due to hardware failures, software errors or other unforeseen events. Backup and recovery strategies ensure that data can be restored consistently during a disaster or system failure. 1.2. Types of databases Relational databases: relational databases are the most widely used type of database management system (DBMS). Data is organized in tables of rows and columns, where each row represents a record, and each column represents an attribute. Relational databases use a structured query language (SQL) to manipulate and query data. Examples of relational databases include MySQL, PostgreSQL, Oracle Database, Microsoft SQL Server and MsAccess, which is used in classroom exercises. NoSQL databases. Unlike relational databases, NoSQL databases do not use a table schema and support flexible data models such as key-value pairs, document-oriented, column-oriented and graph databases. NoSQL databases are highly scalable and can efficiently handle different data types. Examples of NoSQL databases include MongoDB, Cassandra, Couchbase and Redis. 23 CHAPTER 2: DATABASE SYSTEMS Document databases. Each document contains key-value pairs and can have a variable schema for dynamic data structures. Document databases suit applications with variable data requirements and complex data models. Examples of document databases are MongoDB, Couchbase, CouchDB and RavenDB. 2. Database Management System (DBMS) 2.1. Definition of DBMS A database management system (DBMS) is a software application that facilitates database creation, management and administration. It acts as an intermediary between users and the underlying database and provides an interface for users to interact with the data stored in the database. In principle, a DBMS offers several vital functions: Data definition: the DBMS allows users to define the database structure, including creating tables, defining data types, defining relationships between tables, and enforcing integrity constraints. This ensures meaningful and consistent organization and structuring of data. Data manipulation: the DBMS allows users to perform various operations on the data stored in the database. These include inserting new records, updating existing records, deleting obsolete records and querying the database to retrieve specific information. Database management systems usually support a query language, such as SQL (Structured Query Language), which allows users to interact with the database using standardized commands. Data security and access control: DBMS provide mechanisms to control access to the database and ensure data security. It allows administrators to define user roles and privileges, restrict access to sensitive data, and enforce authentication and authorization policies to prevent unauthorized access and data breaches. Data integrity and consistency: the DBMS applies integrity constraints and enforcement policies to maintain data integrity and consistency. It ensures that data stored in the database conforms to predefined rules and constraints, preventing inconsistencies, errors and data corruption. DBMS also supports transactions, allowing users to perform multiple database operations as a single atomic unit, ensuring that data remains consistent even during errors or interruptions. 24 BUSINESS INFORMATICS Data recovery and backup: the DBMS provides data recovery and backup mechanisms to protect against data loss caused by hardware failures, software errors or other unforeseen events. It allows administrators to perform regular database backups, perform incremental backups, and implement disaster recovery plans to ensure that data can be restored consistently during a disaster or system failure. 2.2. Database management systems Different database management systems (DBMS) are tailored to specific data storage and management requirements. These include relational database management systems covering 95% of all systems. A relational DBMS (RDBMS) is the most common type of DBMS, which organizes data into tables with rows and columns. Each table represents an entity, and the relationships between entities are created using keys. RDBMS follows the relational model and uses the SQL (Structured Query Language) language to manipulate and query data. Examples of RDBMS include MySQL, PostgreSQL, Oracle Database, SQL Server and SQLite. An object-oriented DBMS (OODBMS) stores data as objects consisting of attributes and methods. It is well-suited for applications with complex data structures and relationships. OODBMS supports encapsulation, inheritance and polymorphism, making it suitable for modelling real entities and their behaviour. Examples of OODBMS include db4o and ObjectDB. NoSQL (Not Only SQL) DBMS is a non-relational database management system designed to handle large amounts of unstructured and semi-structured data. NoSQL databases offer flexibility, scalability and performance advantages over traditional RDBMS, especially for web-scale applications and big data analytics. NoSQL databases can be categorized into different types, including document-oriented, key-value, column-family and graph databases. Examples of NoSQL databases include MongoDB, Cassandra, Redis, Couchbase and Neo4j. 3. Relational database management system (RDBMS) A relational database management system (RDBMS) is a software system that enables the creation, maintenance and management of relational databases. RDBMS is based on a relational model of data, which organizes data into tables of rows and columns. The RDBMS provides a structured and efficient mech- 31 business analysts, data engineers and end users, to ensure a common understanding of data elements and their relationships. Modelling is an iterative process that involves continuous refinement and validation of the model based on stakeholder feedback. To gather requirements and refine the model, you can use interviews, workshops, and documentation reviews. Entity-relationship (ER) modelling: Entity-relationship modelling is the most commonly used approach in conceptual data modelling. It represents key entities (objects or concepts) within an organization and the relationships between them. Entities represent an organisation’s key objects or concepts, such as customers, products, orders, employees, etc. Relationships define the relationships and interactions between entities, such as “is-a”, “has-a” or “belongs-to” relationships. Attributes describe properties or characteristics of entities. They provide additional details and information about the entities and are typically represented as columns in a database table. Attributes can be simple (atomic) or complex (composed of several sub-attributes), and their data type can be text, numeric, date, etc. The nature and extent of relationships between entities in the conceptual data model are determined by cardinality and multiplicity. Cardinality describes the number of instances of an entity that can be associated with another entity. It is expressed in terms such as ‘one to one’, ‘one to many’ or ‘many to many’. Multiplicity specifies an entity’s minimum and maximum number of occurrences within a relationship. It is often represented graphically using entity-relationship diagrams (ERDs) for ease of understanding. ERDs provide a visual representation of entities, relationships, attributes, and their cardinality and multiplicity limits. Boxes represent entities, lines represent relationships, and diamonds represent relationship types. Attributes are listed in boxes representing entities. 5.1. Logical Data Modeling Logical data modelling is an essential phase of the database design process that focuses on transforming the conceptual data model into a more detailed and structured representation that reflects the logical organization of data in a relational database management system (RDBMS). The logical data model builds on the conceptual data model developed in the conceptual data modelling phase. While the conceptual data model focuses on the definition of high-level entities, attributes and relationships, the logical data model adds additional details, including data types, constraints and normalization. As with conceptual data modelling, logical data modelling often uses entity-relationship diagrams (ERDs) to represent entities, relationships and attributes. However, in CHAPTER 2: DATABASE SYSTEMS 32 BUSINESS INFORMATICS the logical data model, entities are transformed into database tables, attributes become columns of tables, and foreign keys represent relationships. Normalization is one of the most important aspects of logical data modelling, which aims to organize data efficiently and reduce data redundancy. In which large tables are broken down into smaller, related tables to eliminate data anomalies and ensure data integrity. Normal forms such as the first normal form (1NF), the second normal form (2NF), the third normal form (3NF) and the Boyce-Codd normal form (BCNF) are used to ensure proper normalization of each table. Logical data modelling defines the data types and constraints for each column in the table. Data types, such as integer, character, date, etc., define the data type stored in each column. Constraints enforce rules and conditions on the data stored in the database, such as primary key constraints, foreign key constraints, unique constraints, and control constraints. In addition, the process involves defining each table’s primary and foreign keys to create relationships between tables. If necessary, indexes can be defined to optimize query performance. Enabling faster data retrieval based on specific columns. 6. Database security Database security is a critical aspect of information security that focuses on protecting the data stored in databases from unauthorized access, disclosure, modification or destruction. Since databases contain sensitive and valuable information, their protection is essential to maintain the data’s confidentiality, integrity and availability. Access control mechanisms regulate who can access the database and what operations can be performed on the data. Role-based access control (RBAC) allocates rights and privileges to users based on their organizational roles and responsibilities. User authentication mechanisms such as passwords, biometrics and multi-factor authentication verify the identity of users accessing the database. Encryption techniques protect data stored in databases from unauthorized access by converting it into ciphertext using encryption algorithms. Transparent Data Encryption (TDE) encrypts data at the storage level, ensuring that data remains encrypted while stored on disk. Column-level encryption selectively encrypts sensitive columns of database tables, allowing finer control over data protection. Control mechanisms monitor and record database activity, including login attempts, data modifications and access control changes. Database audit logs record who accessed the database, what operations were performed and when 33 they were performed. Real-time monitoring tools analyze database activity in real-time and detect suspicious or anomalous behaviour that may indicate security incidents. Data masking techniques hide sensitive information in databases by replacing actual data with fictitious or obfuscated data. Reduction techniques selectively hide or anonymize sensitive data in query results, reports or application interfaces, preventing unauthorized disclosure. Patch management includes the application of software patches, updates and security patches to the database management system (DBMS) and related software components. Regular patching helps mitigate security vulnerabilities and protect against known exploits and malicious attacks. Backup and recovery mechanisms protect databases from data loss and corruption caused by hardware failures, software errors or malicious attacks. Regular backups ensure that data can be restored to its previous state during a disaster or security incident. Database activity monitoring solutions analyze database traffic and user activity to identify potential security threats, policy violations and data breaches. DAM solutions provide real-time alerts, reports, and forensic analytics so organizations can immediately detect and respond to security incidents. Database security measures must be consistent with industry regulations, data protection laws and organizational security policies. Compliance frameworks such as GDPR, HIPAA, PCI DSS and SOX have requirements for protecting sensitive data, controlling access and maintaining audit trails. REFERENCES Ardeleanu, S. (2016). Relational database programming. ISBN 978-1-484220-79-5. Churcher, C. (2012). Beginning database design: From novice to professional. ISBN 978-1-4302-4210-9. Date, C. J. (2019). Database design and relational theory. ISBN 978-1484255391. Gajdos, S. (2016). Adatbázisok. ISBN 978-963-313-195-4. Garcia-Molina, H., Ullman, J. D., & Widom, J. (2009). Database systems: The complete book. ISBN 0-13-606701-6. Kovács, L. (2004). Adatbázisok tervezésének és kezelésének módszertana. Budapest: ComputerBooks. ISBN 963618321X. Negi, M. (2019). Fundamentals of database management system: Learn essential concepts of database systems. ISBN 978-9388176620. Taylor, A. G. (2000). Database development for dummies (1st ed.). ISBN 0-7645-0752-9. CHAPTER 2: DATABASE SYSTEMS CHAPTER 3: INFORMATION SYSTEMS (Péter LengyeL) 1. Introduction to Information Systems 1.1. Definition and basic concepts of information systems In today’s digital age, Information Systems (IS) are the backbone of almost every organization, driving operational excellence, fostering innovation, and enabling informed decision-making. Understanding the fundamental concepts of information systems is crucial for students aspiring to excel in the modern business environment. What is an Information System? An information system is an integrated ensemble of people, processes, data, and technology that supports an organisation’s operations, management, and decision-making functions. Unlike mere data, the output of an information system is information that has been processed to provide value to its users. Key Concepts in Information Systems: • Interdisciplinary Nature: Information Systems is a field that intersects business, technology, and management. It emphasizes not only the technological components but also their application in solving business problems and supporting strategic goals. • Socio-technical Systems: This concept highlights that an information system comprises social and technical elements. It includes the technology (hardware, software, databases, and networks), the people (users and IT professionals), and the processes that make the system functional and useful. 36 BUSINESS INFORMATICS • Data vs. Information: It’s vital to differentiate between these two concepts. Data represents raw facts and figures, while information is data that has been processed and organized to add value for its users. This transformation is at the heart of what information systems do. Components of Information Systems: • People: From IT professionals who develop and manage these systems to end-users who interact with them, people are crucial. • Processes: These are the methods and procedures that outline how business activities are conducted using the system. • Technology: This includes: o Hardware: Physical devices and equipment. o Software: The programs and applications. o Databases: Organized collections of data. o Networks: The infrastructure that supports communication between system components. Objectives of Information Systems: • Enhance Operational Efficiency: Streamlining business processes to increase productivity and reduce costs. • Foster Innovation: Developing new products, services, and business models through technological capabilities. • Build Customer and Supplier Intimacy: Strengthening relationships through efficient and responsive operations. • Support Informed Decision Making: Providing timely and relevant information to enable better business decisions. • Gain Competitive Advantage: Achieving superior performance in the marketplace through distinctive capabilities. • Ensure Survival: Meeting basic regulatory requirements and adapting to the changing business environment. Discussion Points and Activities: • Case Study Analysis: Review how a specific company leveraged information systems to solve a business problem or gain a competitive advantage. • Group Discussion: What are some everyday examples of information systems you interact with? Discuss their components and what makes them effective or ineffective. • Research Assignment: Investigate a failed information system project. Identify the factors that led to its failure and propose solutions. 37 CHAPTER 3: INFORMATION SYSTEMS Understanding the definition and basic concepts of information systems is the first step toward appreciating their strategic role in today’s businesses. As we delve deeper into each component and explore various information systems, we will understand how these systems are designed, implemented, and managed to achieve organizational goals. 1.2. Historical development of information systems The evolution of information systems (IS) is a fascinating journey that mirrors the advancements in technology and the changing needs of businesses. Information systems have undergone significant transformations from simple manual systems to today’s complex digital solutions. This section explores the key milestones in developing information systems and their impact on businesses and society. The Genesis and Evolution: • Pre-computer era (Before the 1950s): Early information systems were manual and paper-based. Businesses use ledgers, filing systems, and manual processes to collect, process, and store information. The main challenge was the time-consuming nature of processing large volumes of data. • The advent of computers (1950s–1960s): The introduction of mainframe computers marked the beginning of the digital information system era. These early computers were large and expensive and primarily used by big corporations to process vast data. Languages like COBOL and FORTRAN emerged, facilitating business and scientific computing. • Personal computers and databases (1970s–1980s): The invention of personal computers (PCs) and the development of database management systems (DBMS) democratized computing. Information storage and retrieval became more efficient, paving the way for more sophisticated information systems. • The Internet and World Wide Web (1990s): The Internet revolutionized information systems by enabling unprecedented connectivity and access to information. The development of the World Wide Web and browsers in the early 1990s made sharing and accessing information globally easier. • Enterprise Resource Planning (ERP) Systems (Late 1990s): ERP systems integrated all facets of an enterprise into a unified information 38 BUSINESS INFORMATICS system. Companies could manage their operations through a single system, from production to human resources. • The age of Big Data and Cloud Computing (2000s-Present): The explosion of digital data and the advent of cloud computing have transformed information systems. Big data analytics, cloud-based services, and mobile computing have enabled more agile, scalable, and data-driven information systems. Impact on Businesses and Society: • Efficiency and productivity: The evolution of information systems has significantly increased businesses’ efficiency and productivity by automating processes and enabling faster decision-making. • Globalization: Information systems have made it easier for businesses to operate globally, connecting markets and people worldwide. • Innovation: The advancements in information systems have fostered innovation, leading to new products, services, and business models. 1.3. The role of information systems in modern enterprises In the digital landscape of modern business, information systems (IS) have emerged as critical tools for achieving strategic goals, enhancing operational efficiency, and fostering innovation. As enterprises face the complexities of globalization and technological evolution, the adept use of IS is a key determinant of success. Strategic and Operational Impact Information systems enable businesses to carve out competitive advantages by providing insights that inform decision-making and improve operational efficiencies. By automating routine tasks, IS increases productivity and reduces errors, contributing to operational excellence. Additionally, real-time data monitoring allows for swift adjustments to business strategies in response to market changes. The strategic deployment of IS in supply chain management and customer relationship management (CRM) has revolutionized these areas. By streamlining processes and enhancing communication, businesses can optimize costs and build stronger relationships with customers and suppliers. 39 Innovation and Growth IS are foundational to data-driven innovation, opening new avenues for exploring business models, products, and services. They support the creation and delivery of digital products, facilitating traditional business model transformation and market expansion. Moreover, IS plays a crucial role in enabling global operations, breaking down geographical barriers and fostering international growth. Challenges and Adaptation Implementing and managing information systems comes with challenges, including data security and privacy concerns, keeping pace with technological advancements, and aligning IS with business strategies. Overcoming these obstacles requires effective leadership, a culture of continuous learning, and an openness to change. The role of information systems in modern enterprises is multifaceted, driving strategic initiatives, operational efficiencies, and innovation. As technology evolves, the importance of IS in shaping the future of business in the digital era continues to grow. Organisations that successfully integrate and leverage these systems will find themselves well-positioned to thrive in an increasingly competitive and complex business environment. 2. Fundamental components of Information Systems Information systems are integral to the modern business landscape, enabling organisations to operate efficiently, make informed decisions, and compete in a global market. At the core of any information system are five fundamental components: hardware, software, data, people, and processes. Understanding these components’ roles and interplay is crucial for effectively leveraging IS. 2.1. Hardware and software The physical devices and equipment constitute any information system’s technological backbone. Hardware includes computers, servers, data centres, switches, routers, and other devices essential for operations. The choice of hardware impacts the system’s performance, scalability, and reliability. Software refers to the programs and applications that run on the hardware, instructing it on performing tasks. This includes operating systems, enterprise CHAPTER 3: INFORMATION SYSTEMS 40 BUSINESS INFORMATICS software, application software, and databases. The software determines the functionalities available in an information system, from data processing and analysis to user interface design and interaction. 2.2. Data and information In information systems, the terms ‘data’ and ‘information’ are foundational yet distinct concepts that play pivotal roles. Understanding the nuances between data and information is essential for anyone looking to master information systems, as it lays the groundwork for grasping how these systems transform raw data into actionable insights. Data refers to raw facts and figures that, on their own, may not carry significant meaning to the untrained eye. These can be numbers, characters, images, or other measurements collected through observation. In information systems, data is the raw input that needs to be processed and analyzed to become functional. For example, the daily sales figures across different regions, the number of clicks on a website, or the temperatures recorded by a weather station all constitute data. Data is indispensable because it is the fundamental building block of information systems used to produce information. Transforming data into information In information systems, the transition from data to information is a cri - tical process that involves several steps, including data collection, storage, processing, and analysis. Modern information systems utilize sophisticated CHAPTER 3: INFORMATION SYSTEMS Figure 3.1. Fundamental Components of Information Systems Source: Pham & Desai-Naik, 2024 2.1. Hardware and software The physical devices and equipment constitute any information system's technological backbone. Hardware includes computers, servers, data centres, switches, routers, and other devices essential for operations. The choice of hardware impacts the system's performance, scalability, and reliability. Software refers to the programs and applications that run on the hardware, instructing it on performing tasks. This includes operating systems, enterprise software, application software, and databases. The software determines the functionalities available in an information system, from data processing and analysis to user interface design and interaction. 2.2. Data and information In information systems, the terms 'data' and 'information' are foundational yet distinct concepts that play pivotal roles. Understanding the nuances between data and information is essential for anyone looking to master information systems, as it lays the groundwork for grasping how these systems transform raw data into actionable insights. Data refers to raw facts and figures that, on their own, may not carry significant meaning to the untrained eye. These can be numbers, characters, images, or other measurements collected through observation. In information systems, data is the raw input that needs to be processed and analyzed to become functional. For example, the daily sales figures Figure 3.1. Fundamental Components of Information Systems Source: Pham & Desai-Naik, 2024 47 Challenges: • Sophisticated Cyberattacks: Hackers employ advanced techniques to exploit vulnerabilities, necessitating equally sophisticated defence mechanisms. • Big Data and IoT: The explosion of data from various sources, including IoT devices, complicates data management and protection. • Cloud Computing: While offering scalability and efficiency, cloud environments present unique security concerns, especially regarding data sovereignty and third-party risks. • Compliance with Multiple Regulations: Organizations operating globally must navigate a labyrinth of data protection regulations, making compliance increasingly complex. Solutions: • Advanced Security Technologies: Utilizing AI and machine learning can help predict and mitigate cyber threats more effectively. • Privacy by Design: Integrating data protection measures from the initial design phase of products and services. • Enhanced Encryption: Applying robust encryption standards for data at rest and in transit. • Regular Audits and Training: Conduct security audits and train employees on data protection best practices. • Data Protection Officers (DPOs): Appointing DPOs to oversee data protection strategies and ensure regulatory compliance. Implementing these solutions requires a commitment to continuous improvement and adaptation to evolving threats and regulatory landscapes. By proactively addressing these modern challenges, organizations can protect their data assets and maintain trust with stakeholders. 5. Trends in Information Systems The landscape of information systems is continuously evolving, shaped by technological advancements, changing organizational needs, and societal shifts. Several future trends are set to redefine how information systems are developed, deployed, and utilized, offering new opportunities and challenges. CHAPTER 3: INFORMATION SYSTEMS 48 BUSINESS INFORMATICS Artificial Intelligence and Machine Learning: AI and machine learning are increasingly integrated into information systems, enhancing decision-making, automating routine tasks, and providing personalized user experiences. These technologies are becoming more sophisticated, enabling systems to learn from data, predict outcomes, and make intelligent decisions in real-time. Internet of Things (IoT): The expansion of IoT devices is transforming information systems, enabling the collection and analysis of data from a myriad of connected devices. This trend facilitates more responsive and context-aware systems, impacting everything from smart homes and cities to advanced manufacturing processes. Blockchain Technology: Originally known for underpinning cryptocurrencies, blockchain is gaining traction in various sectors for its ability to provide secure, transparent, and tamper-proof record-keeping. Its applications in information systems range from enhancing data security and integrity to facilitating smart contracts and decentralized applications. Cloud Computing and Edge Computing: The cloud continues to be a significant trend, offering scalability, flexibility, and cost-efficiency. Edge computing, which processes data closer to where it is generated, is increasingly important, especially for IoT and mobile applications, reducing latency and bandwidth use. Cybersecurity Mesh: As cyber threats become more sophisticated, a more integrated approach to cybersecurity is emerging. Cybersecurity mesh is a flexible, modular architecture connecting disparate security services for a more cohesive and responsive defence strategy. Privacy-Enhancing Computation: In response to growing data privacy concerns, privacy-enhancing computation techniques that allow data to be processed securely without compromising privacy are being developed. This trend is critical for maintaining user trust and complying with stringent data protection regulations. Quantum Computing: Although still in its early stages, quantum computing has the potential to revolutionize information systems by solving complex problems much faster than traditional computers. Its impact could be game-changing in cryptography, drug discovery, and climate modelling. 49 The future of information systems is poised at the intersection of innovation and complexity. These trends highlight the field’s dynamic nature, emphasizing the need for ongoing learning and adaptation. As these technologies continue to develop, they promise more efficient, secure, and intelligent information systems that can address both current challenges and future opportunities, reshaping the digital landscape. In concluding our exploration of information systems, we’ve traversed from foundational concepts to the brink of tomorrow’s innovations, uncovering the integral role these systems play in the tapestry of modern life. Our journey illuminated the complexities of designing, implementing, and securing these systems while forecasting emerging technologies’ transformative potential. As we’ve seen, information systems are much more than mere conduits for data; they are the engines of innovation, the backbone of enterprises, and the facilitators of global connectivity. As we stand on the cusp of a future rich with possibilities—from AI-driven analytics to quantum computing breakthroughs— the promise of information systems to enhance, innovate, and transform our world is unmistakable. Yet, this journey also underscores the importance of ethical stewardship and vigilant security in an era where data is both a valuable asset and a vulnerable target. The delicate balance between leveraging technology for advancement and safeguarding our digital and societal fabric demands careful attention. As we look ahead, the information systems landscape will undoubtedly continue to evolve, shaped by the ingenuity of those who navigate its challenges and harness its potential. The journey through the world of information systems is not solitary. Still, a shared voyage that calls on us to contribute to a future where technology amplifies our capabilities, enriches our lives and fosters a more connected, informed, and ethical world. In essence, the horizon of information systems is vast and promising, filled with opportunities for innovation, growth, and profound societal impact. As we move forward, let us do so with curiosity, responsibility, and an unwavering commitment to using technology as a force for good, steering towards a future where information systems continue transforming and elevating our collective human experience. CHAPTER 3: INFORMATION SYSTEMS 50 BUSINESS INFORMATICS REFERENCES Acquisti, A., Dinev, T., & Keil, M. (2019). Editorial: Special issue on cyber security, privacy and ethics of information systems. Information Systems Frontiers. https:// doi.org/10.1007/S10796-019-09971-5 Behara, R. S., Gundersen, D. E., & Capozzoli, E. A. (1995). Trends in information systems outsourcing. Journal of Purchasing and Materials Management, 31(2), 45–53. https://doi.org/10.1111/J.1745-493X.1995.TB00202.X Ceccarelli, A., Bondavalli, A., Froemel, B., Hoeftberger, O., & Kopetz, H. (2016). Basic Concepts on Systems of Systems. In Springer. https://doi.org/10.1007/978-3-31947590-5_1 Dantas dos Santos, W. (2019). The entropic and symbolic components of information. BioSystems, 177, 63–71. https://doi.org/10.1016/J.BIOSYSTEMS.2019.05.003 Evangelista Silva, S., Ribeiro, F. N., Camarda, R. F., & Amorim, V. J. P. (2018). Lifecycle Information Systems: The concept, principles, and an approach. iSys. https://doi. org/10.5753/ISYS.2018.370 Galinkin, E. (2022). Towards a Responsible AI Development Lifecycle: Lessons From Information Security. arXiv.org. https://doi.org/10.48550/arXiv.2203.02958 Kapur, N. K. (2023). Information Lifecycle Management. Forschung zur Digitalisierung der Wirtschaft. https://doi.org/10.1007/978-3-658-40304-1_3 Milchev, G., & Miltchev, R. (2018). Development of Information Technologies, Planned Obsolescence and Modification of the Life-Cycle of the CAD/CAM/CAE Systems. European Journal of Sustainable Development, 7(3), 217. https://doi.org/10.14207/ EJSD.2018.V7N3P217 Nold, E. G. (1997). Trends in health information systems technology. American Journal of Health-System Pharmacy, 54(3), 269–274. https://doi.org/10.1093/AJHP/54.3.269 Safronov, V. V., Barabanov, V. F., Nuzhnyy, A. M., & Grebennikova, N. I. (2021). Integrated information system of lifecycle support of networks and electrical network equipment. Journal of Physics: Conference Series. https://doi.org/10.1088/1757899X/1035/1/012037 Saha, S., Das, A., Kumar, A., Biswas, D., & Saha, S. (2019). Ethical hacking: Redefining security in information system. In Book Title. https://doi.org/10.1007/978-981-150361-0_16 Taherdoost, H. (2022). An overview of trends in information systems: Emerging technologies that transform the information technology industry. Cloud Computing and Data Science, 4(1). https://doi.org/10.37256/ccds.4120231653 Pham, L. – H. T., & Desai-Naik, T. (2024). Using information systems for competitive advantage. In Information systems for business 2e. Workforce LibreTexts. Retrieved from https://workforce.libretexts.org/Courses/Evergreen_Valley_College/Information_Systems_for_Business_2e/07%3A_Leveraging_Information_Systems_for_ Strategic_Advantage/7.04%3A_Using_Information_Systems_for_Competitive_ Advantage [Accessed: 30.05.2024] Zelinska, O., Potapova, N., & Yemelianova, A. O. (2023). Information system for maintaining the register of clients of the bank. Visnik Khmelnytskyi National University, 2307–5732. https://doi.org/10.31891/2307-5732-2023-317-1-94-99 Zemmouchi-Ghomari, L. (2021). Basic Concepts of Information Systems. In InTechOpen. https://doi.org/10.5772/INTECHOPEN.97644 51 CHAPTER 3: INFORMATION SYSTEMS CHAPTER 4: BUSINESS ANALYSIS (róBert szILágyI) 1. Data, information, and knowledge Data are facts of the world. For example, financial transactions, age, temperature, number of steps from my house to my office are simply numbers. The information appears when we work with those numbers, and we can find value and meaning. The information can help us to make informed decisions. We can talk about knowledge when the data and the information turn into rules to assist the decisions. We can’t store knowledge because it implies a theoretical or practical understanding of a subject. However, using predictive analytics, we can simulate intelligent behaviour and provide a good approximation. An example of data information: How much? – not detailed question 20 – a numerical data What is 20? – question to understand the data What was the question? – another question to find the answer to the original question The nature of data We can find data in all the situations of the world around us, in all the structured or unstructured, in continuous or discrete conditions, in weather records, and in stock market logs. Data can be seen as the essential raw material of any kind of human activity. As shown in the following figure, we can see Data in two distinct ways: Categorical and Numerical. 54 BUSINESS INFORMATICS Categorical data are values or observations that can be sorted into groups or categories. There are two types of categorical values: nominal and ordinal. A nominal variable has no intrinsic ordering to its categories. For example, housing is a categorical variable having two categories (own and rent). An ordinal variable has an established ordering. For example, age as a variable with three orderly categories (young, adult, and elder). Numerical data are values or observations that can be measured. There are two kinds of numerical values: discrete and continuous. Discrete data are values or observations that can be counted and are distinct and separate. For example, the number of lines in a code. Continuous data are values or observations that may take on any value within a finite or infinite interval. For example, an economic time series such as historic gold prices. 1.1. The data analysis process Data analysis helps us to make this possible through exploring the past and creating predictive models. The data analysis process is composed of the following steps: • The statement of problem • Obtain your data • Clean the data • Normalize the data • Transform the data • Exploratory statistics • Exploratory visualization • Predictive modeling • Validate your model • Visualize and interpret your results • Deploy your solution All these activities can be grouped as shown in the following figure: Figure 4.1. Data analysis process activities Source: Cuesta, 2013 CHAPTER 4: BUSINESS ANALYSIS ordering. For example, age as a variable with three orderly categories (young, adult, and elder). Numerical data are values or observations that can be measured. There are two kinds of numerical values: discrete and continuous. Discrete data are values or observations that can be counted and are distinct and separate. For example, the number of lines in a code. Continuous data are values or observations that may take on any value within a finite or infinite interval. For example, an economic time series such as historic gold prices. 1.1. The data analysis process Data analysis helps us to make this possible through exploring the past and creating predictive models. The data analysis process is composed of the following steps: • The statement of problem • Obtain your data • Clean the data • Normalize the data • Transform the data • Exploratory statistics • Exploratory visualization • Predictive modeling • Validate your model • Visualize and interpret your results • Deploy your solution All these activities can be grouped as shown in the following figure: Figure 4.1. Data analysis process activities Source: Cuesta, 2013 The problem The problem definition starts with high-level questions such as how to track differences in behaviour between groups of customers or what's going to be the gold price 55 CHAPTER 4: BUSINESS ANALYSIS The problem The problem definition starts with high-level questions such as how to track differences in behaviour between groups of customers or what’s going to be the gold price in the next month. Understanding the objectives and requirements from a domain perspective is the key to a successful data analysis project. Types of data analysis questions are listed as follows: • Inferential • Predictive • Descriptive • Exploratory • Causal • Correlational Data preparation Data preparation is about obtaining, cleaning, normalising, and transforming the data into an optimal dataset, trying to avoid any possible data quality issues such as invalid, ambiguous, out-of-range, or missing values. This process can take a lot of your time. Analyzing data that has not been carefully prepared can lead you to highly misleading results. The characteristics of good data are listed as follows: • Complete • Coherent • Unambiguous • Countable • Correct • Standardized • Non-redundant Data analysis is the process in which raw data is ordered and organized, which is used in methods that help to explain the past and predict the future. Data analysis is not about the numbers. It is about making/asking questions, developing explanations, and testing hypotheses. Data Analysis is a multidisciplinary field which combines Computer Science, Artificial Intelligence and Machine Learning, Statistics and Mathematics, and Knowledge Domain as shown in the following figure. 56 BUSINESS INFORMATICS What about big data? Big data is a term used when the data exceeds the processing capacity of a typical database. We need big data analytics when the data grows quickly, and we need to uncover hidden patterns, unknown correlations, and other useful information. There are three main features of big data: • Volume: Large amounts of data (GB, TB, PB) • Variety: Different types of structured, unstructured, and multi-structured data (e.g. Database, photo, web, video, mobile, social, unstructured) • Velocity: Needs to be analyzed quickly (periodic, near real-time, realtime) Big data is an opportunity for any company to gain advantages from data aggregation, data exhaust, and metadata. This makes big data a useful business analytic tool, but there is a common misunderstanding about what big data is. Apache Hadoop is the most popular implementation for solving large-scale distributed data storage, analysis, and retrieval tasks. The NoSQL and massively parallel processing (MPP) data stores are also useable for large-scale data storage. One of the main challenges for big data is how to store, protect, backup, organize, and catalogue the data on a petabyte scale. Another main challenge of big data is the concept of data ubiquity. Figure 4.2. The algorithm vs data Source: Cuesta, 2013 2. Quantitative versus qualitative data analysis Quantitative and qualitative analysis can be defined as follows: • Quantitative data: It is numerical measurements expressed in terms of numbers. • Qualitative data: It is categorical measurements expressed in terms of natural language descriptions. CHAPTER 4: BUSINESS ANALYSIS Big data is a term used when the data exceeds the processing capacity of a typical database. We need big data analytics when the data grows quickly, and we need to uncover hidden patterns, unknown correlations, and other useful information. There are three main features of big data: • Volume: Large amounts of data (GB, TB, PB) • Variety: Different types of structured, unstructured, and multi-structured data (e.g. Database, photo, web, video, mobile, social, unstructured) • Velocity: Needs to be analyzed quickly (periodic, near real-time, real-time) Big data is an opportunity for any company to gain advantages from data aggregation, data exhaust, and metadata. This makes big data a useful business analytic tool, but there is a common misunderstanding about what big data is. Apache Hadoop is the most popular implementation for solving large-scale distributed data storage, analysis, and retrieval tasks. The NoSQL and massively parallel processing (MPP) data stores are also useable for large-scale data storage. One of the main challenges for big data is how to store, protect, backup, organize, and catalogue the data on a petabyte scale. Another main challenge of big data is the concept of data ubiquity. Figure 4.2. The algorithm vs data Source: Cuesta, 2013 Quantitative versus qualitative data analysis Quantitative and qualitative analysis can be defined as follows: • Quantitative data: It is numerical measurements expressed in terms of numbers. • Qualitative data: It is categorical measurements expressed in terms of natural language descriptions. Quantitative analytics involves the analysis of numerical data. The type of the analysis will depend on the level of measurement. There are four kinds of measurements: 63 ML has a large amount of algorithms generally split into three groups, given how the algorithm is training: • Supervised learning • Unsupervised learning • Reinforcement learning Data-driven research has been energized by the growth of Big Data analytics and developments in machine learning. Therefore, the machine learning method is one of the possible approaches for creating a Big Data decision support tool. Tsolaki et al. (2022) grouped data mining and machine learning methods by application area. AI visualisation is one of the distinctive features of Power BI. Key-influencer visualisation, decomposition tree, and anomaly detection are the three different types of AI visualisation in Power BI. In this research, we will use decomposition trees. Implementing machine learning techniques often requires a thorough understanding of mathematics and computer science; however, ML is difficult to use due to the high level of expertise required. A self-service framework ML can, therefore, be used by analysts with less technical knowledge. Numerous research papers have addressed the self-service deployment of machine learning for business intelligence using Microsoft Power BI. Decomposition Tree Visual: Self-Service Decision Tree The concept of a decision tree is used by decomposition tree visualisation to represent data in multiple dimensions. In the visualisation, the data is summarised in a graph, allowing the user to dive into the data dimensions in any order. The decomposition tree in Power BI allows the user to visualise data across multiple dimensions. It automatically aggregates the data and allows the user to drill down into the dimensions in any order. In addition, it is a visualisation with artificial intelligence, so the user can prompt it to find the next dimension and break it down according to the user’s criteria. Thank you for this tool. It is possible to perform root cause analysis and ad hoc investigations with it. The gradient boosting algorithm uses statistical regression and classification as primary methods for predictive data mining. The idea behind the gradient boosting procedure is to train a system using a mathematical model to maximize a differentiable loss function from a set of random “inputs” and “outputs”. The procedure automatically aggregates data and allows drilling down into selected dimensions in any order. It is an artificial intelligence (AI) visualisation, which makes it a valuable tool for ad hoc investigations. There is an “AI Splits” or “AutoAI” to figure out where to look next in the data. CHAPTER 4: BUSINESS ANALYSIS 64 BUSINESS INFORMATICS 4.1. Data-Driven Business Analysis In today’s data-rich world, businesses are generating and collecting information at an unprecedented rate. But data alone isn’t enough. Turning that data into actionable insights and driving informed decisions is where data-driven business analysis comes in. What is data-driven business analysis? It’s an approach to business analysis that leverages data analytics and visualization techniques to understand business problems, assess potential solutions, and measure their effectiveness. It’s about: • Asking the right questions: Identifying key business issues and opportunities that can be addressed with data. • Collecting and cleansing data: Gathering relevant data from various sources and ensuring its accuracy and completeness. • Applying analytical techniques: Using statistical analysis, data mining, and machine learning to uncover patterns, trends, and relationships within the data. • Visualizing insights: Creating clear and compelling visualizations to communicate data-driven findings to stakeholders. • Recommending informed solutions: Drawing conclusions and proposing data-backed solutions to improve business performance. • Key Performance Indicators (KPIs) are the main instruments of Business Performance Management. KPIs are the measures that are translated to both the strategy and the business process. These measures are often designed for an industry sector with assumptions about business processes in organizations. Benefits of data-driven business analysis: • Improved decision-making: Data-driven insights lead to more informed decisions, reducing the risk of guesswork and gut feeling. • Enhanced efficiency and cost savings: Identifying inefficiencies and optimizing processes based on data leads to improved resource utilization and cost reduction. • Better customer understanding: Analyzing customer data helps you better understand their needs, preferences, and behavior, allowing for targeted marketing and improved customer experience. 65 • Increased innovation: Data can reveal hidden patterns and opportunities, paving the way for innovative solutions and competitive advantage. • Stronger communication and collaboration: Data-driven insights provide a common ground for discussion and collaboration across different teams within an organization. Getting started with data-driven business analysis: • Develop your data literacy: Understand basic data analysis concepts and techniques. • Identify your business problems: What are the key challenges facing your organization? • Choose the right tools: There are various data analysis and visualization tools available depending on your needs and budget. • Focus on high-quality data: Ensure data accuracy and completeness for reliable insights. • Collaborate with stakeholders: Involve data scientists, business leaders, and other stakeholders in the process. • Tell a compelling story: Use data visualizations and storytelling to communicate insights effectively. Remember, data-driven business analysis is an ongoing journey. By continuously learning, adapting, and integrating data into your analysis, you can unlock its full potential to drive meaningful improvements in your business. 4.2. Large Language Models in business analysis Before discussing this topic, some key concepts about LLM should be clarified. Chatbot: a computer program designed to simulate a conversation with human users, especially over the Internet. Generative Model: a model that creates new data, not only classifies, but predicts based on the input data. Generative Pre-Trained Transformer (GPT): is a machine-learning model that uses unsupervised and supervised learning techniques to understand and generate human-like language. Language Model: a type of artificial intelligence model that is trained to generate text that resembles human language. Natural Language Processing (NLP): NLP is an area of artificial intelligence that involves the use of algorithms to analyze human language, such as text and speech, to extract meaning and useful information. CHAPTER 4: BUSINESS ANALYSIS 66 BUSINESS INFORMATICS Neural Network: a machine learning model consisting of connected processing nodes trained on data to perform a specific task based on their connections. Supervised Fine-Tuning: a machine learning technique in which a pre-trained model is further trained on a smaller, labelled data set to improve performance on a specific task. Transfer Learning: the ability of tools like ChatGPT to use the knowledge gained from one task to improve performance in another related task. Unsupervised Pre-Training: a machine learning technique in which a mo del is trained on a large dataset without labelled examples, allowing it to learn the underlying structure and patterns in the data. Security challenges of GPT-4 Although GPT-4 shows increased performance in areas such as reasoning, knowledge retention, and encoding compared to earlier models such as GPT-2 (Radford et al., 2019) and GPT-3, during its development based on the analyses carried out, specific risks can be observed. Hallucination: GPT-4 is prone to “hallucinating,” i.e., “producing meaningless or untrue content from certain sources.” This can be particularly harmful as users increasingly trust the information provided by the model. Harmful content, biased content: Language models can create different types of harmful content. These may be content that may violate development guidelines and may cause harm on an individual or social level. Language models can amplify biases and perpetuate stereotypes. Disinformation and (user) influencing activities: GPT-4 can create believable, realistic, and targeted content, including news articles, messages, conversations, and emails. Data protection: GPT-4 learned from several previously established and publicly available data sources that may contain publicly available personal data. Because of the above, the model can know people who are highly present on public Internet interfaces. Cyber security: In the case of vulnerability discovery and exploitation, external cyber security experts tested whether GPT-4 can help discover, assess, and exploit vulnerabilities in computer systems. They found that GPT-4 can explain certain vulnerabilities, but it no longer performs well when exploiting known vulnerabilities. Large Language Models in business Large Language Models (LLM) are already making waves in various industries, and business analysis is no exception. Here’s how LLMs are transforming the role of business analysts: 67 Improved Communication and Collaboration: • Generating Reports and Summaries: LLMs can automatically generate reports and summaries of complex data sets, making information easily digestible for different stakeholders. This improves communication and collaboration between analysts and other business units. • Personalized Insights: LLMs can tailor reports and recommendations based on individual needs and preferences. This ensures that stakeholders receive the information most relevant to them. Additional Benefits: • Reduced Costs: Automating tasks and improving efficiency thro ugh LLMs can lead to business cost savings. • Increased Productivity: Analysts can focus on higher-level tasks and strategic thinking, increasing productivity and value creation. • Democratization of Data Insights: LLMs can make data analysis more accessible to non-technical users, fostering a data-driven culture within the organization. Overall, LLMs are powerful tools that can significantly enhance the role of business analysts. By leveraging their strengths while addressing their limitations, businesses can gain a competitive edge through data-driven decision-making and insightful business analysis. 4.3. What new skills may be needed in businesses? Prompt design and prompt engineering: Prompts are input instructions or questions that we give to AI systems to generate responses. Prompts are critical because they determine what results you get. For GPT or other language models to provide accurate and useful answers, it is important to create appropriate prompts. Prompt engineering is the process of creating questions or instructions that help the model achieve the desired results. In prompt engineering, users must learn how to create efficient and accurate prompts so that the model provides the desired results. This is key to the application of AI, as good questions can be critical to success. Knowing and using MI art: GPT and similar models can also be used in creative fields, such as art and design. DALL-E, for example, is a model that generates images based on textual descriptions. Proficiency in AI art enables the creation of new and exciting works. CHAPTER 4: BUSINESS ANALYSIS 68 BUSINESS INFORMATICS Acquiring programming basics: Although it is not necessary to be a professional programmer when using GPT and other AI models, basic programming knowledge can be an advantage. These skills allow us to customize and integrate the models into our applications or projects. For example, if a company is developing its GPT-based chatbot, programming fundamentals can help finetune how the chatbot works. API (Programming Interface) use: APIs allow applications to communicate with other services and systems. There are a growing number of APIs in the field of AI that allow developers and companies to easily access AI systems and integrate them into their applications. For example, an e-commerce company can use APIs to offer customized recommendations and a personalized shopping experience to its customers, increasing purchase conversion. These skills and approaches can help companies take advantage of the opportunities offered by AI and large language models. AI is an increasingly widespread technology, and those who properly prepare and apply it can gain a competitive advantage in the age of digitization and automation. ICT related suggested skills for employees: • Marketing department: May require proficiency in digital marketing tools, social media management platforms, and content creation software. • Sales department: Needs skills like customer relationship management (CRM) systems, email marketing platforms, and data visualization tools. • Non-technical roles: Even basic computer literacy, effective communication, and problem-solving skills are crucial for navigating daily tasks and utilizing various software efficiently. Additionally, also related skills that companies have to consider: • Emerging technologies: Skills related to artificial intelligence, blockchain, and cloud-based solutions are increasingly sought after. • Data literacy: The ability to understand, analyze, and interpret data is becoming essential across all job roles. • Soft skills: Communication, collaboration, and problem-solving are crucial for leveraging technology effectively. 69 REFERENCES Aspin, A. (2021). Miscellaneous visual styles. In Pro Power BI theme creation (pp. 213– 230). Apress, Berkeley, CA. https://doi.org/10.1007/978-1-4842-7068-4_11 Aspin, A. (2022). Third-party visuals. In Pro Power BI dashboard creation (pp. 185-202). Apress, Berkeley, CA. https://doi.org/10.1007/978-1-4842-8227-4_10 Azamfirei, R., Kudchadkar, S. R., & Fackler, J. (2023). Large language models and the perils of their hallucinations. Critical Care, 27(1). https://doi.org/10.1186/s13054023-04393-x Bishop, C. M. (1994). Neural networks and their applications. Review of Scientific Instruments, 65(6), 1803-1832. https://doi.org/10.1063/1.1144830 Burkov, A. (2019). The hundred-page machine learning book. ISBN 978-1999579500 Cole, N. K. (2015). Storytelling with data: A data visualization guide for business professionals. John Wiley & Sons. Retrieved from ProQuest Ebook Central. Cuesta, H. (2013). Practical data analysis. Packt Publishing. Retrieved from ProQuest Ebook Central. Dwivedi, Y. K., Kshetri, N., Hughes, L., Slade, E. L., Jeyaraj, A., Kar, A. K., Baabdullah, A. M., Koohang, A., Raghavan, V., Ahuja, M., Wirtz, J., & Wright, R. (2023). “So what if ChatGPT wrote it?” Multidisciplinary perspectives on opportunities, challenges and implications of generative conversational AI for research, practice and policy. International Journal of Information Management, 71. https://doi.org/10.1016/j. ijinfomgt.2023.102642 Ehrenmueller-Jensen, M. (2020). Adding smart visualizations. In Self-service AI with Power BI desktop (pp. 89-106). Apress, Berkeley, CA. https://doi.org/10.1007/9781-4842-6231-3_5 Fleischhacker, A. J. (2023). A business analyst’s introduction to business analytics: Coding in R for fast, easy, and visual Bayesian inference. ISBN 979-8857923412 Forbes. (2023). The current state of LLMs in business intelligence and what needs to change. Retrieved from https://www.forbes.com/sites/forrester/ 2023/04/28/the-current-state-of-llms-in-business-intelligence-and-what-needsto-change/?sh=3bf4d32247d8 ] Accessed 2024.02.05.] Fortino, A. (2020). Data visualization for business decisions: A laboratory manual. Mercury Learning & Information. Retrieved from ProQuest Ebook Central. Friedman, J. H. (2001). Greedy function approximation: A gradient boosting machine. The Annals of Statistics, 29(5), 1189-1232. http://www.jstor.org/stable/2699986 Gualo, F., Rodriguez, M., Verdugo, J., & Caballero, I., Piattini, M. (2021). Data quality certification using ISO/IEC 25012: Industrial experiences. Journal of Systems and Software, 176, 110938. https://doi.org/10.1016/j.jss.2021.110938 CHAPTER 4: BUSINESS ANALYSIS 70 BUSINESS INFORMATICS Harvard Business Review (HBR). (2024). Why becoming a data-driven organization is so hard. Retrieved from https://hbr.org/2022/02/why-becoming-a-data-driven-organization-is-so-hard Heer, J., Bostock, M., & Ogievetsky, V. (2010). A tour through the visualization zoo. Communications of the ACM, 53(6), 59–67. https://doi.org/10.1145/1743546.1743567 King, M. R. (2022). The future of AI in medicine: A perspective from a chatbot. Annals of Biomedical Engineering. https://doi.org/10.1007/s10439-022-03121-w Knaflic, C. N. (2015). Storytelling with data: A data visualization guide for business professionals. Wiley. ISBN 978-1-119-00225-3 Lee, B., Riche, N. H., Isenberg, P., & Carpendale, S. (2015). More than telling a story: Transforming data into visually shared stories. IEEE Computer Graphics and Applications, 35(5), 84–90. https://doi.org/10.1109/mcg.2015.99 Lee, C., Panda, P., Srinivasan, G., & Roy, K. (2018). Training deep spiking convolutional neural networks with STDP-based unsupervised pre-training followed by supervised fine-tuning. Frontiers in Neuroscience, 12, 435. https://doi.org/10.3389/fn Lo, L. S. (2023). The CLEAR path: A framework for enhancing information literacy through prompt engineering. Journal of Academic Librarianship, 49(4). https://doi. org/10.1016/j.acalib.2023.102720 MacNeil, S., Tran, A., Mogil, D., Bernstein, S., Ross, E., & Huang, Z. (2022). Generating diverse code explanations using the GPT-3 large language model. Proceedings of the ACM Conference on International Computing Education Research, 2, 37–39. Manning, C., & Schutze, H. (1999). Foundations of statistical natural language processing. MIT Press. Marr, B. (2015). Big data: Using SMART big data, analytics and metrics to make better decisions and improve performance. Newark: John Wiley & Sons, Incorporated. [Accessed: 07.09.2023]. ProQuest Ebook Central. McKinsey. (2024). The data-driven enterprise of 2025. Retrieved from https://www. mckinsey.com/capabilities/quantumblack/our-insights/the-data-driven-enterprise-of-2025 [Accessed: 2024.02.05.] Medium.com. (2023a). Prompt engineering for AI language models. Retrieved from https://medium.com/@nirajranasinghe/prompt-engineering-for-ai-language-models-f6d226603c34 [Accessed: 28.09.2023.] Medium.com. (2023b). The ChatGPT list of lists: A collection of 1500 useful, mind-blowing, and strange use cases. Retrieved from https://medium.com/mlearning-ai/thechatgpt-list-of-lists-a-collection-of-1500-useful-mind-blowing-and-strange-usecases-8b14c35eb [Accessed: 28.09.2023.] Medium.com. (2023c). 5 best ways to use ChatGPT API. Retrieved from https://divakersingh29.medium.com/5-best-way-to-use-chatgpt-api-c6e0a8356a34 [Accessed: 28.09.2023.] 71 Murgia, E., Abbasiantaeb, Z., Aliannejadi, M., Huibers, T., Landoni, M., & Pera, M. S. (2023). ChatGPT in the classroom: A preliminary exploration on the feasibility of adapting ChatGPT to support children’s information discovery. UMAP 2023 – Adjunct Proceedings of the 31st ACM Conference on User Modeling, Adaptation and Personalization, 22–27. https://doi.org/10.1145/3563359.3597399 OpenAI. (2023). GPT-4 observed safety challenges. Retrieved from https://cdn.openai. com/papers/gpt-4-system-card.pdf [Accessed: 21.09.2023.] Patriarca, R., Di Gravio, G., Cioponea, R., & Licu, A. (2022). Democratizing business intelligence and machine learning for air traffic management safety. Safety Science, 146, 105530. https://doi.org/10.1016/j.ssci.2021.105530 Paul, J., Ueno, A., & Dennis, C. (2023). ChatGPT and consumers: Benefits, pitfalls and future research agenda. International Journal of Consumer Studies, 47(4), 12131225. https://doi.org/10.1111/ijcs.12928 Pavlik, J. V. (2023). Collaborating with ChatGPT: Considering the implications of generative artificial intelligence for journalism and media education. Journalism and Mass Communication Educator. https://doi.org/10.1177/10776958221149577 Radford, A., Wu, J., Child, R., Luan, D., Amodei, D., & Sutskever, I. (2019). Language models are unsupervised multitask learners. Radford, A., Narasimhan, K., Salimans, T., & Sutskever, I. (2018). Improving language understanding by generative pre-training. Retrieved from https://www.cs.ubc. ca/~amuham01/LING530/papers/radford2018improving.pdf Roubtsova, E., & Michell, V. (2014). KPIs and their properties defined with the EXTREME method. In Shishkov, B. (Ed.), Business modeling and software design. BMSD 2013. Lecture notes in business information processing (Vol. 173, pp. 88–102). Springer, Cham. https://doi.org/10.1007/978-3-319-06671-4_7 Szilágyi, R., & Tóth, M. (2024). Use of LLM for SMEs, opportunities and challenges. Journal of Agricultural Informatics, 14(2). https://doi.org/10.17700/jai. 2023.14.2.703 Tsolaki, K., Vafeiadis, T., Nizamis, A., Ioannidis, D., & Tzovaras, D. (2022). Utilizing machine learning on freight transportation and logistics applications: A review. ICT Express. https://doi.org/10.1016/j.icte.2022.02.001 Turing. (2024). How LLMs are changing the face of business analytics. Retrieved from https://www.turing.com/resources/how-llms-are-changing-the-face-of-business-analytics [Accessed: 2024.02.05.] Umoquit, M., Tso, P., Varga-Atkins, T., O’Brien, M., & Wheeldon, J. (2013). Diagrammatic elicitation: Defining the use of diagrams in data collection The Qualitative Report, 18(30), 1–12. https://doi.org/10.46743/2160-3715/2013.1487 CHAPTER 4: BUSINESS ANALYSIS 72 BUSINESS INFORMATICS Vassiliadis, P., Simitsis, A., & Skiadopoulos, S. (2002). Conceptual modeling for ETL processes. In Proceedings of the 5th ACM international workshop on Data Warehousing and OLAP (DOLAP ‘02) (pp. 14-21). https://doi.org/10.1145/583890.583893 Wilke, C. (2019). Fundamentals of data visualization: A primer on making informative and compelling figures. O’Reilly. ISBN 978-1492031086 Yang, J., Chen, Y.-L., Por, L. Y., & Ku, C. S. (2023). A systematic literature review of information security in chatbots. Applied Sciences (Switzerland), 13(11). https://doi. org/10.3390/app13117228 79 way and might resist changes. Furthermore, if the change implies modifying the information system(s) underpinning the process, the change may be costly or may require changes not only in the organization that coordinates the process, but also in other organizations. Equipped with an understanding of one or several issues in a process and a candidate set of potential remedies, analysts can propose a redesigned version of the process, in other words a to-be process which would address the issues identified in the as-is process. This to-be process is the main output of the process redesign phase. Here, it is important to keep in mind that analysis and redesign are intricately related. There may be multiple redesign options and each of these options needs to be analysed, so that an informed choice can be made as to which option should be chosen. Once redesigned, the necessary changes in the ways of working and the IT systems of the organization should be implemented so that the to-be process can eventually be put into execution. This phase is called process implementation. In the case of the equipment rental process, the process implementation phase would mean putting in place an information system to record and to track equipment rental requests, POs associated to approved requests and invoices associated to these POs. Deploying such an information system means not only developing the IT components of this system. It would also relate to training the process participants so that they perform their work in the spirit of the redesigned process and make the best use of the IT components of the system. More generally, process implementation may involve two complementary facets: organizational change management and process automation. Organizational change management refers to the set of activities required to change the way of working of all participants involved in the process. 4. Business Process Modeling Business process models are important at various stages of the BPM lifecycle. Before starting to model a process, it is crucial to understand why we are modeling it. The models we produce will look quite different depending on the reason for modeling them in the first place. There are many reasons for modeling a process. The first one is simply to understand the process and to share our understanding of the process with the people who are involved with the process on a daily basis. Indeed, process participants typically perform quite specialized activities in a process such that they are hardly confronted with the complexity of the entire CHAPTER 5: BUSINESS PROCESS MANAGEMENT (BPM) 80 BUSINESS INFORMATICS process. Therefore, process modeling helps to better understand the process and to identify and prevent issues. This step towards a thorough understanding is the prerequisite to conducting process analysis, redesign, or automation. There are many languages for modeling business processes diagrammatically. One of the oldest ones is flowcharts. In their most basic form, flowcharts consist of rectangles, representing activities and diamonds, representing points in the process where a decision is made. More generally, we can say that regardless of the specific notation used, a diagrammatic process model typically consists of two types of nodes: activity nodes and control nodes. Activity nodes describe units of work that may be performed by humans or, software applications, or a combination thereof. Control nodes capture the flow of execution between activities. Although not all process modeling languages support it, a third important type of element in process models are event nodes. An event node tells us that something may or must happen, within the process or in the environment of the process, that requires a reaction, like for example, the arrival of a message from a customer asking to cancel their purchase order. Other types of nodes may appear in a process model, but we can say that activity, event, and control nodes are the most basic. Several extensions of flowcharts exist, like cross-organizational flowcharts, where the flowchart is divided into so-called swimlanes that denote different organizational units (e.g. different departments in a company). UML Activity Diagrams are cross-organizational flowcharts. However, UML Activity Diagrams go beyond cross-organizational flowcharts by providing symbols to capture data objects, signals, and parallelism among other aspects. Other languages used for process modeling include data-flow diagrams and IDEF3, just to name two. It would be mind-boggling to try to learn all these languages at once. Fortunately, nowadays there are two widely used standard for process modeling, namely the Business Process Model and Notation (BPMN) and the Extended Event-driven Process Chains (eEPCs). eEPCs have some similarities with flowcharts, but they differ in that they treat events as first-class citizens. 5. Business Process Modeling Notation (BPMN) The latest version of BPMN is BPMN 2.0. It was released as a standard by the Object Management Group (OMG) in 2011. In BPMN, activities are represented as rounded rectangles. Control nodes (called gateways) are represented using diamond shapes. Activities and control nodes are connected by 81 means of arcs (called flows) that determine the order in which the process is executed. The model also shows the process participants involved in specifically the process where these participants is shown as a separate lane containing the activities performed by the participant in question. With over 100 symbols, BPMN is a fairly complex language. The core set of symbols provided by BPMN are events and activities. Events represent things that happen instantaneously (e.g. an invoice has been received) whereas activities represent work units with a duration (e.g. an activity to pay an invoice). The most elementary form of relation is that of sequence, which implies that one event or activity A is followed by another event or activity B. Events are represented by circles, activities by rounded rectangles, and arcs (called sequence flows in BPMN) are represented by arrows with a full arrowhead. Recommended naming conventions: • For activities and tasks, the label should begin with a verb in the imperative form followed by a noun, typically referring to a business object, e.g. “Approve order”. The noun may be preceded by an adjective, e.g. “Issue driver license”, and the verb may be followed by a complement to explain how the action is being done, e.g. “Renew driver license via offline agencies”. • For events, the label should begin with a noun (this would typically be a business object) and end with a verb in past participle form, e.g. “Invoice emitted”. The verb is a past participle to indicate something that has just happened. Like activity labels, the noun may be prefixed by an adjective, e.g. “Urgent order sent”. • To name a process model we should use a noun, potentially preceded by an adjective, e.g. “order fulfilment” or “claim handling” process. This label can be obtained by nominalizing the verb describing the main action of a business process, e.g. “fulfil order” (the main action) becomes “order fulfilment” (the process label). Nouns in hyphenated form, like “order-to-cash” and “procure-to-pay” indicating the sequence of main actions in the process, are also possible. General verbs like “to make”, “to do”, “to perform” or “to conduct” should be replaced with meaningful verbs that capture the specifics of the activity being performed or the event occurring. Words like “process” or “order” are also ambiguous in terms of their part of speech. Both can be used as a verb (“to process”, “to order”) and as a noun (“a process”, “an order”). We recommend using such words consistently, only in one part of speech, e.g. “order” always as CHAPTER 5: BUSINESS PROCESS MANAGEMENT (BPM) 82 BUSINESS INFORMATICS a noun. By following such naming conventions, we will keep our models more consistent, make them easier to understand for communication purposes and increase their reusability. The process begins when a customer feels hungry, then he will pick up the phone and make a pizza order, a clerk answering the telephone in the shop will check the ingredients for the customer. The customer will order his pizza according to the list of ingredients provided. When the clerk receives the order from the customer, he will inform the baker to bake to pizza according to the customer’s demand. The delivery boy takes the pizza when ready and delivers it to the customer. The customer will pay for the pizza on receiving it, and the delivery boy will provide the receipt. After consuming the pizza, the process ends. Business Informatics 79 Figure 5.1. The Pizza Purchasing Ordering Process Model. Source: https://www.businessprocessincubator.com/content/the-pizza-collaboration/ The process begins when a customer feels hungry, then he will pick up the phone and make a pizza order, a clerk answering the telephone in the shop will check the ingredients for the customer. The customer will order his pizza according to the list of ingredients provided. When the clerk receives the order from the customer, he will inform the baker to bake to pizza according to the customer’s demand. The delivery boy takes the pizza when ready and delivers it to the customer. The customer will pay for the pizza on receiving it, and the delivery boy will provide the receipt. After consuming the pizza, the process ends. 6. ARIS – eEPC (extended Event-driven Process Chain) ARIS eEPC, a prominent methodology for modelling business processes, stands for Architektur integrierter Informationssysteme (Architecture of Integrated Information Systems) event-driven Process Chain. It provides a visual language with symbols and Figure 5.1. The Pizza Purchasing Ordering Process Model. Source: https://www.businessprocessincubator.com/content/the-pizza-collaboration/ 83 6. ARIS – eEPC (extended Event-driven Process Chain) ARIS eEPC, a prominent methodology for modelling business processes, stands for Architektur integrierter Informationssysteme (Architecture of Integrated Information Systems) event-driven Process Chain. It provides a visual language with symbols and flowcharts to represent the steps, decisions, and participants involved in a business activity. The ARIS framework defines five different views: organization view, functional view, data view, control view and product/service view. ARIS House is shown in Figure 5.2. shows these five views and the relations between them. As depicted in the figure, the process models are the controlling dispatcher of resources and actions, they act as the central role in the ARIS house, associating with all the other views and integrating them in a uniformed way. A process model respecting these associations between different views is understandable among involved parties despite their different work perspectives and is therefore capable of providing better understandability, maintainability and scalability. Figure 5.2. The ARIS House Source: https://viewpointsonitarchitecture.wordpress.com/tag/aris/ ARIS eEPC is a valuable tool for the first two stages of BPM, allowing businesses to represent and analyze their workflows visually. The ARIS eEPC notation uses a set of symbols to depict different elements within a business process: CHAPTER 5: (BUSINESS) PROCESS MANAGEMENT flowcharts to represent the steps, decisions, and participants involved in a business activity. The ARIS framework defines five different views: organization view, functional view, data view, control view and product/service view. ARIS House is shown in Figure 5.2. shows these five views and the relations between them. As depicted in the figure, the process models are the controlling dispatcher of resources and actions, they act as the central role in the ARIS house, associating with all the other views and integrating them in a uniformed way. A process model respecting these associations between different views is understandable among involved parties despite their different work perspectives and is therefore capable of providing better understandability, maintainability and scalability. Figure 5.2. The ARIS House Source: https://viewpointsonitarchitecture.wordpress.com/tag/aris/ ARIS eEPC is a valuable tool for the first two stages of BPM, allowing businesses to represent and analyze their workflows visually. The ARIS eEPC notation uses a set of symbols to depict different elements within a business process: CHAPTER 5: BUSINESS PROCESS MANAGEMENT (BPM) 84 BUSINESS INFORMATICS Figure 5.3. Notation example Events (rounded rectangles): Represent a specific happening that triggers or ends a process or a particular function within it. Events can be starting points (“Order received”), intermediate milestones (“Payment confirmed”), or concluding points (“Product delivered”). Functions (rectangles): Represent actions or tasks performed within the process. Functions can be manual activities completed by employees or automated steps executed by systems. Connectors (arrows): Show the sequence and flow of the process, connecting events and functions. Solid lines indicate the normal flow, while dashed lines depict alternative paths based on decisions. Organizational units (cylinders): Represent the departments, teams, or individuals responsible for carrying out specific functions. Logical operators (diamonds): Model decision points or branching paths within the process. These include “AND” (all conditions must be met), “OR” (at least one condition must be met), and “XOR” (exclusive OR, only one condition can be true). Data objects (documents): Represent information used or produced during the process. Fig. x illustrates a detailed excerpt of a business process example that focuses the function “manufacture item”. Business Informatics 81 Figure 5.3. Notation example Events (rounded rectangles): Represent a specific happening that triggers or ends a process or a particular function within it. Events can be starting points ("Order received"), intermediate milestones ("Payment confirmed"), or concluding points ("Product delivered"). Functions (rectangles): Represent actions or tasks performed within the process. Functions can be manual activities completed by employees or automated steps executed by systems. Connectors (arrows): Show the sequence and flow of the process, connecting events and functions. Solid lines indicate the normal flow, while dashed lines depict alternative paths based on decisions. Organizational units (cylinders): Represent the departments, teams, or individuals responsible for carrying out specific functions. Logical operators (diamonds): Model decision points or branching paths within the process. These include "AND" (all conditions must be met), "OR" (at least one condition must be met), and "XOR" (exclusive OR, only one condition can be true). Data objects (documents): Represent information used or produced during the process. Fig. x illustrates a detailed excerpt of a business process example that focuses the function “manufacture item”. 85 CHAPTER 5: (BUSINESS) PROCESS MANAGEMENT Figure 5.4. Business Process Example Source: Scheer and Schneider, 2006 The displayed function is enhanced by event and message controls. This enables to describe the process sequence. Events describe condition changes and, e.g., characterize a function's beginning and the result. In addition to these simple events, there are also compounded events. In order to run the function “manufacture item” e.g. the planning needs be finished as well as the necessary parts need to be available. This necessity is expressed by the logical “AND” operator between the events. The method used to describe the process in Fig. 2 is called “Event-Driven Process Chain” (EPC) which was developed in 1992 at the Institute for Information Systems (IWi) at the University of Saarland together with SAP employees in an R&D project financed by SAP AG. The EPC method has become a standard in the field of Business Process Management (BPM), so it is the key component of SAP R/3’s modeling concepts for business engineering and customizing. Figure 5.4. Business Process Example Source: Scheer and Schneider, 2006 The displayed function is enhanced by event and message controls. This enables to describe the process sequence. Events describe condition changes and, e.g., characterize a function’s beginning and the result. In addition to these simple events, there are also compounded events. In order to run the function “manufacture item” e.g. the planning needs be finished as well as the necessary parts need to be available. This necessity is expressed by the logical “AND” operator between the events. The method used to describe the process in Fig. 2 is called “Event-Driven Process Chain” (EPC) which was developed in 1992 at the Institute for Information Systems (IWi) at the University of Saarland together with SAP employees in an R&D project financed by SAP AG. The EPC method has become a standard in the field of Business Process Management (BPM), so it is the key component of SAP R/3’s modeling concepts for business engineering and customizing. CHAPTER 5: BUSINESS PROCESS MANAGEMENT (BPM) 86 BUSINESS INFORMATICS Benefits of Using ARIS eEPC Standardized Notation: Provides a common language for documenting and communicating business processes across the organization. Visual Representation: Simplifies complex processes into easy-to-understand flowcharts, facilitating communication with both technical and non-technical audiences. Improved Analysis: Enables identification of bottlenecks, redundancies, and opportunities for improvement. Process Optimization: Supports the design and implementation of more efficient and effective workflows. Collaboration: Facilitates collaboration between different departments in - volved in a process. Limitations of ARIS eEPC Focus on Events and Functions: May not capture all aspects of a process, such as data flows, roles, or performance metrics. Complexity for Large Processes: Complex diagrams with numerous elements can become cluttered and difficult to understand. Limited Automation Support: ARIS eEPC primarily focuses on process visualization, with limited support for directly translating models into executable workflows. ARIS eEPC is just one component of the broader ARIS platform, a comprehensive suite of tools for enterprise architecture management. The platform offers additional functionalities like: Data Modeling: Defines data structures and relationships used within the organization. Organization Modeling: Represents the organizational structure and roles involved in business processes. Performance Management: Provides tools for measuring and monitoring process performance metrics. By combining ARIS eEPC with other ARIS components, organizations can gain a holistic view of their business operations and implement a more integrated approach to BPM. ARIS eEPC remains a valuable tool for business process modeling due to its simplicity, clarity, and widespread adoption. While other methodologies like BPMN (Business Process Model and Notation) have emerged, ARIS eEPC offers 87 a solid foundation for visualizing and analysing workflows, leading to process improvements and overall business efficiency. 7. Workflow applications Asana “https://asana.com/”: A popular work management platform that helps teams organize tasks, projects, and communication in one place. It offers task assignments, due dates, file sharing, and progress tracking features. Great for collaborative projects and keeping track of individual workloads. Monday.com “https://support.monday.com/hc/en-us/articles/ 11065311570066-Get-started-monday-workflows”: A highly customizable workflow application known for its visual boards and drag-and-drop functionality. Teams can create customized workflows for different processes, automate repetitive tasks, and collaborate in real-time. Ideal for teams that need a flexible platform to adapt to their specific needs. Zapier “https://zapier.com/”: An automation tool that connects different web apps and services. You can create “Zaps” that trigger actions in one app based on events in another. This helps automate repetitive tasks and streamline workflows across different platforms. Useful for integrating various tools teams already use. Kissflow “https://kissflow.com/”: A cloud-based workflow management solution that focuses on automating business processes. It allows users to design custom workflows with approval chains, data collection forms, and integrations with external systems. Well-suited for automating complex workflows within an organization. Trello “https://trello.com/”: A simple and intuitive project management tool that uses Kanban boards to visualize workflows. Tasks are represented as cards that move across different stages (e.g., To Do, In Progress, Done). Trello offers basic functionality like checklists, attachments, and comments, ideal for straightforward workflow visualization and team collaboration. Airtable “https://www.airtable.com/”: A database application that offers a spread sheet-like interface but with greater flexibility. It allows users to create custom bases with different fields and record types. Airtable can be used to manage various workflows by setting up custom views and automations. Powerful for managing complex data sets within workflows. Microsoft Power Automate “https://www.microsoft.com/en-us/power-platform/products/power-automate”: A cloud-based workflow automation CHAPTER 5: BUSINESS PROCESS MANAGEMENT (BPM) 88 BUSINESS INFORMATICS tool included in Microsoft Microsoft 365. It allows users to automate tasks across various Microsoft services (e.g., Outlook, OneDrive) and connect them with external applications. Best suited for businesses heavily invested in the Microsoft ecosystem who want to automate tasks within their existing suite of tools. REFERENCES Buikis, A., Ciegis, R., & Fitt, A. D. (2003). Business modelling. Languages and tools. Progress in Industrial Mathematics at ECMI 2002, 5, 41–52. https://doi. org/10.1007/978-3-662-09510-2_4 Dumas, M., La Rosa, M., Mendling, J., & Reijers, H. A. (2013). Fundamentals of business process management. IndraStra Global. https://doi.org/10.1007/978-3-64233143-5 Gao, F., Derguech, W., & Zaremba, M. (2011). Extending BPMN 2.0 to enable links between process models and ARIS views modeled with linked data. BIS (Workshops), 41–52. https://doi.org/10.1007/978-3-642-25370-6_5 Scheer, A., & Schneider, K. (2006). ARIS — Architecture of integrated information systems. Architecture of Integrated Information Systems, 605–623. https://doi. org/10.1007/3-540-26661-5_25 95 which encrypts files on the infected device (workstation, server, smartphone, etc.) and offers a ransom to obtain the key needed to unlock them. For more information, see ransomware. 2.3. Worms A self-replicating computer program similar to a virus. However, while viruses attach themselves to or become part of other executable programs or documents, worms operate independently. 2.4. Trojan horses Trojan horses named after the war machine used in the ancient siege of Troy, whereby a legitimate-looking download hides a program that eventually activates and causes incidents (e.g. downloads backdoors or launches malicious programs). 2.5. Backdoors Backdoors are add-ons built into software that give selected individuals access to specific programs, computers, or data managed on them. Software developers deliberately build in some of these backdoors for service purposes. In contrast, others are built in by programming errors that allow attackers to bypass access rules and gain unauthorised access. In addition, attack programs are explicitly designed to open backdoors, usually distributed as part of viruses or spyware without the user’s knowledge. Using these for attack purposes is dangerous because they can lead to the installation of malicious code in each case. The backdoor bypasses system security, so the protection that would otherwise be in place will not be adequate. 2.6. System-hiding programs Malicious software designed to gain unrestricted, unauthorised and hidden access to computer resources. It is important to note that these programs bypass the established access protection system so that access gained here cannot be controlled at the system level. CHAPTER 6: DATA SECURITY, DATA PROTECTION 96 BUSINESS INFORMATICS 2.7. Denial of Service (DOS or Distributed Denial of Services – DDoS) attackers: a program running on one or more computers that sends many requests per second to a specified address without looking at or processing the responses sent. In this way, other users using the system do not receive replies to their actual requests due to the congestion of the computer under attack. In this way, if an Internet shop is attacked, for example, it is impossible to shop there, ergo there is a natural loss of revenue. 2.8. Spyware Hidden programs that transmit data to an attacker without the user’s knowledge or permission. They can be hidden as part of any application package that contains executable programs. In addition to computer programs, data-stealing programs written for smartphones have also appeared. Spyware can even log our keystrokes to steal our passwords, for example, or steal other information about us through our camera or microphone. 2.9. Ransomware An attacker injects a program into a user’s computer, phone, or any computer-based system that locks infected devices or encrypts valuable files, rendering them unusable. The program may also claim that it will only unlock for a fee. The victim is not guaranteed to get their data back after payment. 2.10. Cryptocurrency mining programs An attacker installs a program on a user’s computer, phone or other device – increasingly on powerful servers on corporate networks – that mines cryptocurrency for its host (who is not the user) without the user’s knowledge. Cryptocurrency mining is a legal activity if the ‘miner’ does it on infrastructure owned by the user. From the user’s perspective, cryptocurrency mining does not cause direct harm. Still, it can cause indirect harm by significantly slowing down the device running the program, which can degrade the user experience and consume significantly more power than it would during regular operation. In an enterprise environment, mining can cause more severe problems, as applications supporting business processes running on servers can slow down or even stop running, which in turn can cause monetary damage. 97 2.11. Junk mail The name “spam” is borrowed from the name of a canned meat product (Spiced Pork and Ham) from an American company (Hormel Foods) that has been around since 1937. It has become the standard term for mass emails on the Internet, following a Monthy Python piece. A common feature of junk mail is that it promotes a product or service by unauthorised – and, in Hungary, among others, illegal – use of other people’s IT resources. 2.12. Adware These are programs that can be downloaded and used free of charge and display advertisements on the user’s computer. They are also known as PUPs (Potential Unwanted Programs), often used to deliver malicious programs to the user’s computer. 2.13. Zombie network software The English term (botnet) is derived from the words “robot” and “network”. IT jargon refers to a program that works remotely or automatically on an infected machine. It is possible that a user’s computer is part ofa botnet network and is working remotely without the user’s knowledge. This usually requires an online presence. The zombie network software can infect and control a computer without the owner’s permission. The zombie network software can be used to steal data, send spam or attack other computers, as it can be installed on the user’s computer undetected and carry out any activity. The malware is most often delivered to the attacked computer via the Internet, which only requires the computer to be connected to the Internet. It is much less common for attackers to use physical means of attack, as this requires some personal presence, significantly increasing the risk of being caught. However, the following tools can be successfully used in an attack: 2.14. Keyboard keystroke loggers Keyboard keystroke loggers are small hardware devices that an attacker plugs between the keyboard and the computer, with storage capacity to which the device records all keystrokes. An attacker can access sensitive information – typically system administrator passwords or other login credentials – by evaluating the device’s contents. CHAPTER 6: DATA SECURITY, DATA PROTECTION 98 BUSINESS INFORMATICS 2.15. Hidden cameras A small data recording device that can capture high-quality images and sound. Cameras may be continuous or motion/voice-activated, wired or radio controlled, or powered from their internal or electrical mains supply. An attacker can steal passwords or sensitive information while under surveillance. The disadvantage is the need for personal presence or physical location. In some cases, attackers can turn on a computer’s built-in or connected webcams without the user’s knowledge, use them as hidden cameras and steal data from the user’s environment. 3. Typical forms of attack and methods 3.1. Pharming An attacker redirects a user’s traffic to a website to their website (or to a hacked website they own) by modifying some data on the user’s computer so that the user can enter personal information – such as login details – without being suspected, thinking they are on the accurate site. 3.2. Downloading malware embedded in attachments A widespread form of attack is to trick the user into downloading and opening an attractive attachment when the malware embedded in the attachment is activated – possibly while maintaining the pretence (e.g. document/image display, program running, etc.). This is how most ransomware and cryptocurrency mining programs get onto the victim’s machine. 3.3. Phishing The use by attackers of an image of an actual website (fake website) that looks no different from the original. Attackers use it to trick unsuspecting users into providing login or personal information while believing they are providing it on the original website. Advanced spoofed websites may also have a fake SSL certificate. Fake websites are accessed via links embedded in fake messages (e.g. a request for a data change from a system administrator via email, a password change request from a bank following a security incident, a billing statement 99 from a service provider, etc.). This differs from hijacking phishing, where the attacker does not modify anything on the victim’s machine. 3.4.Shoulder surfing A direct surveillance technique where the attacker looks over the user’s shoulder to obtain information. Shoulder surfing is effective in crowded places, when the user types in his PIN at an ATM (ATMs have small mirrors to detect this), or in public places such as an internet café or library, where he types in his customer security code, password, etc. 3.5. Social engineering The attacker deceives the user about their identity to share information that the user would not otherwise be entitled to. For example, the attacker may impersonate a law enforcement officer or a system administrator. Still, it is not uncommon to see the newbie syndrome abused by the willingness to help newbies. 3.6. Data Leakage Today, individuals and organisations generate a lot of electronic information and data daily. Communication channels and data carriers provide opportunities for users to handle and move this data and information. Data leakage is defined as events where data classified as confidential/secret (but certainly not public) is released from the protected control of the organisation due to the user’s negligence or intentional action, and unauthorised access to this confidential data and information may occur. 3.7.Advanced Persistent Threat (APT) This type of attack is characterised by the use of multiple, often interrelated, attack methods, preferably as stealthily as possible, even hidden for long periods, exploiting typically unknown vulnerabilities, attacking the target to carry out activities, such as data theft, the corruption of IT systems or other illegal activities. CHAPTER 6: DATA SECURITY, DATA PROTECTION 100 BUSINESS INFORMATICS 3.8. Cybercrime Cybercrime refers to crimes committed through cyberspace while using a computer. Examples include online phishing and theft of credit card details (name, number, expiry date, CVC). 4. Defending against malicious attacks 4.1. Access protection, password protection, authentication Most attacks are committed over the network because the entire internet community sees an internet-connected computer, smart device and smartphone. In contrast, with a computer, the number of people physically entering the room containing the computer or, in the case of home appliances, the number of people physically entering our home is usually minimal. Whereas in the past, logical protection of networks (firewalls, content filtering, data leakage protection) was much more important than physical protection, today, in the age of portable devices, the physical protection of devices also needs serious attention. It is easy to lose a phone, which can be quickly snatched from your hand in a busy place. The vast majority of portable devices and laptops are stolen from cars. For this reason, portable devices should not be left unattended in a car for even the shortest period, even in a locked place such as the boot. In busy urban areas (shopping malls, shopping centres, parks, schools), thieves will be looking for people who put what looks like a laptop in the boot and either steal it there or the next time they park. When the owner returns, the device will be in cold storage. Often, the owner doesn’t even know where the device was stolen from. In such cases, the best advice is to encrypt the backup storage, password-protect the device, and have a screen lock on the phone and a PIN code on the SIM card. Last but not least, don’t store unsaved data on your portable device, as you can buy another phone, but you can never re-record a video of your child’s first steps, for example. In general, every network has someone who assigns and revokes file and device access. Suppose we need to give more than one person access to our own closed network. In that case, we have implemented a network administrator role, who is authorised to manage authentication, authorisation and accountability on the network and is responsible for maintaining the necessary access 101 to data on the network. This typically means access to our home wireless network in a home environment. It is advisable first to change the default administrator (admin) password and then set an access password (wifi password), as radio signals do not stop at the wall. It may not be suitable if your neighbour is surfing the Internet over our wireless network. There are many threats to the security of the network. You need to be aware that using an unsecured wireless network can allow your data to be intercepted by traffic interceptors or leaked by unauthorised parties, even without your knowledge. When designing password protection, the password must be sufficiently secure. It is recommended that good password management rules are followed, such as not sharing passwords with others, changing them periodically, using the correct password length, using a combination of appropriate password characters – letters, numbers and special characters, and not writing passwords in notebooks, on different files, on sticky notes or using the same password in more than one place. When using passwords, we distinguish between three types of passwords: • reusable password: you enter a password once on a given system and use it until the next time you change it. • Time password (OTP): This password is generated by the user. It can only be used once after generation – typically, a token hardware device is required, or it is generated by the system you want to log in to and sent to you via some channel. The best examples are the SMS passwords banks use to access the Internet banking site and the SMS passwords used for transaction authentication (two-step authentication). • biometric password: a physiological characteristic of a person (e.g. fingerprint, voice, retina, palm print, etc.) Bad passwords do not provide security, as they cannot stop a potential attacker but can delay the attack by a moment or two because bad passwords can be cracked or guessed in seconds. Several analyses have been conducted at home and abroad to illustrate bad password usage habits. From a user perspective, the security of operating systems typically refers to the security of files. File security can be discussed from several aspects through their associated operations. These are read, write, delete, and modify. The critical question is, who has these file permissions? Read access is prevented by file encryption by encryption software – where you can open the file but cannot interpret it – or by password protection in a text editor, where you cannot open (unencrypt) the file without knowing the passCHAPTER 6: DATA SECURITY, DATA PROTECTION 102 BUSINESS INFORMATICS word. Password protection can be set for documents created by office software packages (text, spreadsheets, presentations, etc.) or compressed files. The file can only be written in backing storage if you have the right to do so. Otherwise, the file you want to create will not be moved from memory or deleted when you close the program (if the program’s memory management is set correctly). It is possible to write (modify) a file if the file is assigned to the user for modification-writing; otherwise, the user will not be able to save the modifications. It is also important to note whether there are any file elements that could be used in a malicious attack to write to the file or the system without the owner’s knowledge – for example, macros. Figure 6.2. Setting access rights in the Windows operating system Source: Own editing based on the Windows system If you use a computer at home, it is recommended that each family member has a user account with a general level of access. The administrator account should only be used when necessary. This allows you to restrict access to each other’s data in your operating system. 4.2. Firewalls Firewalls are hardware or software devices that act at the boundary of a network to allow or deny incoming and outgoing data elements based on a predefined CHAPTER 6: DATA SECURITY, DATA PROTECTION Bad passwords do not provide security, as they cannot stop a potential attacker but can delay the attack by a moment or two because bad passwords can be cracked or guessed in seconds. Several analyses have been conducted at home and abroad to illustrate bad password usage habits. From a user perspective, the security of operating systems typically refers to the security of files. File security can be discussed from several aspects through their associated operations. These are read, write, delete, and modify. The critical question is, who has these file permissions? Read access is prevented by file encryption by encryption software - where you can open the file but cannot interpret it - or by password protection in a text editor, where you cannot open (unencrypt) the file without knowing the password. Password protection can be set for documents created by office software packages (text, spreadsheets, presentations, etc.) or compressed files. The file can only be written in backing storage if you have the right to do so. Otherwise, the file you want to create will not be moved from memory or deleted when you close the program (if the program's memory management is set correctly). It is possible to write (modify) a file if the file is assigned to the user for modification-writing; otherwise, the user will not be able to save the modifications. It is also important to note whether there are any file elements that could be used in a malicious attack to write to the file or the system without the owner's knowledge - for example, macros. Figure 6.2. Setting access rights in the Windows operating system 103 set of rules. In other words, firewalls enforce and adhere to the access rules we define for communication. There are many different levels and capabilities of firewalls. On the user side, the most important is the personal firewall. A personal firewall is a software on your computer that allows or denies the running of individual applications and their network communications, in many cases in a self-learning system. A personal firewall is soft ware that continuously runs on your computer. A personal firewall can either be part of the operating system or installed on your compu - ter – for example, as part of a security suite. A firewall’s job is to protect the network from intrusion; in other words, it prevents unauthorised access to the network from an external location by enforcing predefined access protection. Restriction is done by rules that tell network traffic whether it is allowed or denied, which is why a firewall is a rulebased system. Additional rules can be created to manage incoming/outgoing network traffic if necessary. For example, when installing a new game program, ports that have been closed must be opened, i.e. allowed to use the game. The goodness or badness of firewalls is determined by their ability to filter out unwanted traffic and allow expected traffic through all network levels. To do this, you need to be able to set rules for them, and there are many resources, forums, and guides on the Internet. After some experimentation, you can also learn how to create a secure environment independently. 4.3. Digital signature A digital signature is an encrypted code that associates a person’s identity with the signed file; in other words, it authenticates it. Authentication is the confirmation of the claimed identity, so authenticity means that the origin and the sender have not changed. More specifically, a digital signature is a mathematical sequence of numbers based on an asymmetric cryptographic algorithm generated by a digital signature scheme and used to ensure the message’s authenticity (origin and integrity). The signature-creation data (secret key) used to create the digital signature will be paired with the signature-verification key (public key), which is included in the digital certificate by the CA after the signatory has been identified and authenticated. The digital certificate, therefore, certifies that the message’s sender is who they claim to be. Digital certificates can also contain public keys and other authentication data such as name, city, address, personal identification, job title, department, etc. Digital certificates can serve different purposes. Signing, encrypti on, authen tication, personal, organisational, code signing and SSL certifica tes exist. CHAPTER 6: DATA SECURITY, DATA PROTECTION 104 BUSINESS INFORMATICS All certificates are structured in the same way; the differences lie in the content of the data and the purposes for which they are used. Signing certificates are for digital signature purposes. They contain the signature verification data, which is used to create the digital signature with the signature creation data. Steps to create and verify the digital signature on the receiving side: • The data to be signed is extracted into a fixed (usually 160–512 bits) length extract, • the digest is encrypted by the application using the signing algorithm and the secret key and becomes the digital signature, • the initial verification of the signature is done automatically, • the digital signature is attached to the data and sent to the recipient. Digital signatures differ from public key encryption in that the secret key is used to sign the message, and the public key is used to verify the signature – the reverse is true for encryption. 4.4. Confidentiality tools on social networking sites With the proliferation of social networking sites, such information and personal data can be leaked to the public network due to inappropriate or automatic default settings. It is essential to understand why confidential information should not be published on social networking sites and how to implement and monitor the protection settings for this information. A controlled and thoughtful presence on social networking sites is also essential to avoid potential dangers such as cyberbullying, grooming, misleading/dangerous information, false identities, and using or accepting fraudulent links or messages. It is elementary for attackers to gain our trust if we provide intimate details on social networks, such as our nickname. Still, we can also get physically close to them if we disclose our holiday dates and address. The risk can be calculated accordingly because the potential number of virtual attackers is much larger than the number of attackers expected in real space. There is less risk in providing information on musical interests and favourite television programmes, as this data is accessible from more places and is more widely known than a nickname. For a sex offender, every little piece of information we provide on social networking sites can make it easier to prepare for sexual exploitation, a known and dangerous threat here. 111 CHAPTER 7: BLOCKCHAIN TECHNOLOGY AND CRYPTOCURRENCIES Figure 7.1. Network types Source: Khoshavi et al., 2021 A decentralized network is one where control, decision making and resources are not concentrated in a single central unit but distributed across multiple system nodes. In this type of network, the participants communicate directly or indirectly with each other, and the participants operate the network. A distributed network is a system in which control, resources and decision-making are spread across multiple nodes or computers. Distributed networks interact with each other directly or indirectly to accomplish tasks. Distributed networks aim to achieve scalability, redundancy, reliability and more efficient use of resources through coordination and cooperation between participants. A significant advantage of a distributed network is that the failure of one node does not cause any disruption to the system, and more remote, operational nodes immediately take over its tasks. A blockchain is a distributed database created and maintained by nodes in a network. Nodes are key participants in the blockchain system and perform different functions on the network. A blockchain has two main types of nodes: full nodes and miners. The full nodes store and maintain a full copy of the blockchain. These nodes maintain complete control of the blockchain, monitor transactions, and contribute to verifying and accepting new blocks. Full nodes participate in the network control processes and help maintain the integrity of the blockchain. The miners are computers or systems that confirm transactions and add new blocks to the blockchain. Miners solve specific cryptographic tasks (usually in the context of Proof of Work (PoW) or Proof of Stake (PoS) consensus mechanisms) and receive rewards for successful solutions, such as cryptocurrency. Miners are responsible for creating and adding new blocks to the blockchain. The consensus mechanism in a blockchain system is the process that helps participants agree on the state of the network, valid transactions and the Business Informatics 109 Figure 7.1. Network types Source: Khoshavi et al., 2021 A decentralized network is one where control, decision making and resources are not concentrated in a single central unit but distributed across multiple system nodes. In this type of network, the participants communicate directly or indirectly with each other, and the participants operate the network. A distributed network is a system in which control, resources and decision-making are spread across multiple nodes or computers. Distributed networks interact with each other directly or indirectly to accomplish tasks. Distributed networks aim to achieve scalability, redundancy, reliability and more efficient use of resources through coordination and cooperation between participants. A significant advantage of a distributed network is that the failure of one node does not cause any disruption to the system, and more remote, operational nodes immediately take over its tasks. A blockchain is a distributed database created and maintained by nodes in a network. Nodes are key participants in the blockchain system and perform different functions on the network. A blockchain has two main types of nodes: full nodes and miners. The full nodes store and maintain a full copy of the blockchain. These nodes maintain complete control of the blockchain, monitor transactions, and contribute to verifying and accepting new blocks. Full nodes participate in the network control processes and help maintain the integrity of the blockchain. The miners are computers or systems that confirm transactions and add new blocks to the blockchain. Miners solve specific cryptographic tasks (usually in the context of Proof of Work (PoW) or Proof of Stake (PoS) consensus 112 BUSINESS INFORMATICS addition of new blocks. The consensus mechanism is crucial because agreeing on changes or transactions between participants is difficult without a central authority overseeing everything in distributed systems. The most commonly used consensus mechanisms (other solutions exist nowadays): • Proof of Work (PoW): PoW is the best-known consensus mechanism, and it is used, for example, by Bitcoin. In this system, miners’ computers solve complex mathematical problems, and the first one to solve successfully is entitled to add a new block to the blockchain. The PoW system requires high computational power, and the miner who has done the most work is entitled to the prize. • Proof of Stake (PoS): PoS is an alternative to PoW and measures the amount of cryptocurrency participants hold in the system. The more they hold, the more likely they are to be eligible to create new blocks and confirm transactions. The PoS consensus mechanism uses less energy than PoW. Through communication and collaboration between nodes in a blockchain network, each node can verify and confirm transactions, maintain data integrity and reach a consensus on the system’s state. The decentralized nature and consensus mechanisms make the blockchain system more resilient to failures or attacks from individual nodes while providing a single, trusted database for participants. 1.1. An example of how blockchain technology works in financial transactions We can imagine that we want to buy a product with bitcoins. In this case, we see the Bitcoin address of the seller, and in our wallet application, we can specify that we want to send one Bitcoin to this address, for example. The transaction is recorded on the blockchain, which contains the sender and receiver addresses, the time of the transaction and the amount. The miners are responsible for checking that the amount we have designated is available in our wallet, that the amount is only spent once and that all other parameters are correct. Once one miner approves the transaction, the data is passed on to the other miners. If the other machines find it correct, the block is added to the blockchain and thus remains in a time-invariant state. Each node in different parts of the world contains a copy of the blockchain, so they constantly check each other. The owners of the volunteer nodes do not know each other, but the system constantly checks each other to ensure near-flawless operation. The 113 only possible abuse would be to control more than 51% of the nodes. However, this is virtually impossible for a blockchain with tens or even hundreds of thousands of nodes worldwide. Figure 7.2. Models Source: Presthus and O’Malley, 2017 Since transactions are broadcast to the whole network, they are entirely public. In contrast to traditional financial institutions, which protect the privacy of their customers by withholding information about their transactions, the blockchain system ensures this by not disclosing information about the owner of the addresses. In network and distributed database transactions, the payer and the payee appear only with their address. This address is nothing more than the public half of a cryptographic key pair, which allows the owner of the address (who alone holds the private key) to sign transactions issued against the balance on the address. The fundamental problem is to prevent someone from spending the money they have more than once. To prevent this, a block is added to the database every 10 minutes, where the new block is self-assembled by a randomly chosen node so there is no overspending. Transactions in the block, thus added to the database, are accepted by the other nodes as having occurred. When a node publishes a new block, it has to prove that it has solved a problematic cryptographic task that requires significant computational power, and the required rate is continuously regulated so that one node in the network can do this every 10 minutes or so. As a result, the majority of decisions on the network are determined by the underlying computational capacity. 1.2. Hash functions Hash functions are mathematical algorithms that take, as input, a piece of data of arbitrary length (e.g., text or file) and generate a fixed-length code or hash value from it. These codes are usually shorter, of fixed length and unique to the Business Informatics 111 passed on to the other miners. If the other machines find it correct, the block is added to the blockchain and thus remains in a time-invariant state. Each node in different parts of the world contains a copy of the blockchain, so they constantly check each other. The owners of the volunteer nodes do not know each other, but the system constantly checks each other to ensure near-flawless operation. The only possible abuse would be to control more than 51% of the nodes. However, this is virtually impossible for a blockchain with tens or even hundreds of thousands of nodes worldwide. Figure 7.2. Models Source: Presthus and O’Malley, 2017 Since transactions are broadcast to the whole network, they are entirely public. In contrast to traditional financial institutions, which protect the privacy of their customers by withholding information about their transactions, the blockchain system ensures this by not disclosing information about the owner of the addresses. In network and distributed database transactions, the payer and the payee appear only with their address. This address is nothing more than the public half of a cryptographic key pair, which allows the owner of the address (who alone holds the private key) to sign transactions issued against the balance on the address. The fundamental problem is to prevent someone from spending the money they have more than once. To prevent this, a block is added to the database every 10 minutes, where the new block is self-assembled by a randomly chosen node so there is no overspending. Transactions in the block, thus added to the database, are accepted by the other nodes as having occurred. When a node publishes a new block, it has to prove that it has solved a problematic cryptographic task that requires significant computational power, and the required rate is continuously regulated so that one node in the network can do this every 10 minutes or so. As a result, Business Informatics 111 passed on to the other miners. If the other machines find it correct, the block is added to the blockchain and thus remains in a time-invariant state. Each node in different parts of the world contains a copy of the blockchain, so they constantly check each other. The owners of the volunteer nodes do not know each other, but the system constantly checks each other to ensure near-flawless operation. The only possible abuse would be to control more than 51% of the nodes. However, this is virtually impossible for a blockchain with tens or even hundreds of thousands of nodes worldwide. Figure 7.2. Models Source: Presthus and O’Malley, 2017 Since transactions are broadcast to the whole network, they are entirely public. In contrast to traditional financial institutions, which protect the privacy of their customers by withholding information about their transactions, the blockchain system ensures this by not disclosing information about the owner of the addresses. In network and distributed database transactions, the payer and the payee appear only with their address. This address is nothing more than the public half of a cryptographic key pair, which allows the owner of the address (who alone holds the private key) to sign transactions issued against the balance on the address. The fundamental problem is to prevent someone from spending the money they have more than once. To prevent this, a block is added to the database every 10 minutes, where the new block is self-assembled by a randomly chosen node so there is no overspending. Transactions in the block, thus added to the database, are accepted by the other nodes as having occurred. When a node publishes a new block, it has to prove that it has solved a problematic cryptographic task that requires significant computational power, and the required rate is continuously regulated so that one node in the network can do this every 10 minutes or so. As a result, CHAPTER 7: BLOCKCHAIN TECHNOLOGY AND CRYPTOCURRENCIES 114 BUSINESS INFORMATICS input data. Hash functions are used for various purposes, such as data storage, password protection, digital signatures and other cryptographic applications. Hash functions must satisfy the following conditions: • Deterministic: The same input always leads to the same hash value. • Fast computation: hash functions must compute their output efficiently, even for large inputs. • One-way: Recalculating the original input from the hash value should not be easy. • Collision-resistant: It should not be easy to find two different inputs that lead to the same hash value (collision). Figure 7.3. Simplified hashing flowchart Source: https://chainkraft.com/what-is-hashing/ For example, generate a SHA-256 hash from a text. For example, take the text “Hello, world!”.First, convert the text “Hello, world!” to binary form. Then, we will use the binary data before applying the SHA-256 hash function. Using ASCII encoding, you can create binary data from the text “Hello, world!”. ASCII (American Standard Code for Information Interchange) is a character encoding system representing characters by binary numbers. Thus, each character is assigned a unique binary value. “Hello, world!” -> 01001000 01100101 01101100 01101100 01101111 00101100 00100000 01110111 01101111 01110010 01101100 01100100 00100001 Then, we apply the SHA-256 hash function to this binary data. The SHA-256 hash function converts a binary sequence received as input into a hash value of 256-bit length. After the SHA-256 hash function is applied, the result is a hash value of 256-bit length, usually in hexadecimal format. An example of a SHA256 hash value for the text “Hello, world!”: 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824 This hash value uniquely identifies the text “Hello, world!”; you will get the same result a zillion times if you repeat the same process. However, if you change just one bit in the input, the hash value generated will change radically. This feature is very useful in data integrity checking and other applications. CHAPTER 7: BLOCKCHAIN TECHNOLOGY AND CRYPTOCURRENCIES the majority of decisions on the network are determined by the underlying computational capacity. 1.2. Hash functions Hash functions are mathematical algorithms that take, as input, a piece of data of arbitrary length (e.g., text or file) and generate a fixed-length code or hash value from it. These codes are usually shorter, of fixed length and unique to the input data. Hash functions are used for various purposes, such as data storage, password protection, digital signatures and other cryptographic applications. Hash functions must satisfy the following conditions: • Deterministic: The same input always leads to the same hash value. • Fast computation: hash functions must compute their output efficiently, even for large inputs. • One-way: Recalculating the original input from the hash value should not be easy. • Collision-resistant: It should not be easy to find two different inputs that lead to the same hash value (collision). Figure 7.3. Simplified hashing flowchart Source: https://chainkraft.com/what-is-hashing/ For example, generate a SHA-256 hash from a text. For example, take the text "Hello, world!".First, convert the text "Hello, world!" to binary form. Then, we will use the binary data before applying the SHA-256 hash function. Using ASCII encoding, you can create binary data from the text "Hello, world!". ASCII (American Standard Code for Information Interchange) is a character encoding system representing characters by binary numbers. Thus, each character is assigned a unique binary value. "Hello, world!" -> 01001000 01100101 01101100 01101100 01101111 00101100 00100000 01110111 01101111 01110010 01101100 01100100 00100001 115 1.3. Mining A “nonce” (number used once) in blockchain technology is data used by miners to create a new block in the blockchain and thus validate transactions. A nonce is a 32-bit integer used as an identifier during mining. During the mining process, miners must find a nonce that allows them to apply a hash function (usually SHA-256) to the current block header and thus generate a hash value for the block, which must meet specific difficulty criteria. The nonce must be chosen so the resulting hash value is low enough for the rest of the network to accept the block. Since the nonce can be chosen randomly, the miners try different nonce values until they find the value that allows the desired result to be obtained. This process is called the “mining difficulty” or “proof-of-work” algorithm. Nonce is an essential part of blockchain security and integrity, as it ensures that block creation is a more costly process, preventing blockchain manipulation or tampering. The Bitcoin network adjusts the difficulty of mining to ensure an average block creation time of around 10 minutes. This is to maintain the stable operation of the blockchain and the fast processing of transactions. The difficulty of mining affects the nonce value that miners try to find when creating a block. The difficulty is controlled so that the first few bits of the block’s hash value are zero. The more zero bits miners try to achieve, the harder it will be to find the correct nonce value. Setting the difficulty is an automatic process that occurs after every 2016 block in the Bitcoin network. After each block creation, the network checks the average block creation time based on the last 2016 block. Suppose this time is shorter than the target of 10 minutes. In that case, the network will automatically increase the mining difficulty (by reducing the number of zeros in the block hash value) so that the next 2016 block can be created again in 10 minutes on average. If the average block creation time is longer, the difficulty is lowered. This mechanism allows the Bitcoin network to adapt to changes in the number of miners and changes in miner performance, maintaining the average block creation time. The “51% attack” is a threat affecting blockchains’ security, such as the Bitcoin network. This attack occurs when an entity or a group can take control of more than 50% of a blockchain network with its total computing capacity. If an attacker controls more than 50% of the blockchain, it effectively gains complete control of the network. It would therefore be able to perform actions that could be detrimental to the stability and security of the network. CHAPTER 7: BLOCKCHAIN TECHNOLOGY AND CRYPTOCURRENCIES 116 BUSINESS INFORMATICS 1.4. Smart contracts Smart contracts are computer programs or pieces of code that operate and execute on blockchains in a planned way. These contracts automatically execute predefined terms and conditions without the need for intermediary or thirdparty intervention. Smart contracts are essentially composed of code and run on blockchain networks such as Ethereum. The main reasons for using smart contracts: • Automation: smart contracts automatically execute specified conditions without the need for human intervention. This allows for the automation of transactions and processes. • Simplicity and efficiency: smart contracts allow business processes to be simplified and made more efficient by eliminating intermediaries and administrative costs. • Programming patterns and conditions: developers can program smart contracts in detail to behave exactly as they are intended. Conditions and patterns can be precisely defined in the code. • Security: smart contracts also take advantage of the security benefits of blockchain technology, such as a distributed and unalterable database. • Voluntariness: smart contracts are based on voluntariness, and the trust between the parties is anchored in the blockchain network. Smart contracts can be used in a wide range of applications, including finance, real estate, legal agreements, insurance contracts and many other areas where automation of contracts and transactions is required. Smart contract-based supply chain management process effectively automates the ordering, delivery, receipt and payment processes. Through the blockchain network, all transactions and status changes can be tracked transparently and reliably, minimizing the possibility of human error and fraud. It is important to note that the encryption and publication of smart contracts require a strong knowledge of blockchain and cryptography. If one does not have expertise in this area, it is worth involving an expert or developer in creating and testing the smart contract (Mohanta et al., 2018). 117 2. Cryptocurrencies The concept of digital currencies has been on the minds of cryptographers and software developers for decades, but it was only in the 21st century that technology and society reached the point where these initiatives became real financial instruments. Although the concept of digital currencies was first conceived in the 1980s, cryptocurrency as we know it today began in 2009 with the creation of Bitcoin. In 2008, an unknown person or group, publishing under the pseudonym Satoshi Nakamoto, published a Bitcoin “white paper” detailing the workings of the digital currency and the underlying blockchain technology. The Bitcoin network was launched in 2009, and the first block, known as the “Genesis block”, was mined. Bitcoin allows people to send and receive value directly without any central authority. Since then, there have been many different types of cryptocurrencies, each with unique characteristics and objectives. In the world of cryptocurrencies, buying, storing and using are key aspects that allow people to interact with digital currencies. The most common way to buy cryptocurrencies is through various online exchanges such as Coinbase, Binance, or Kraken. These platforms allow users to exchange fiat currencies (e.g. USD, EUR) for cryptocurrencies. Another popular way to buy cryptocurrencies is to use peer-to-peer (P2P) platforms, where buyers and sellers can interact directly with each other. The storage of cryptocurrencies is a crucial consideration for anyone involved in the digital world. How cryptocurrencies are stored can significantly impact their security and availability. The devices that store cryptocurrencies are commonly called “wallets”. They can be software-based, hardware-based or even paper-based: • The “hot Wallets” are online wallets that are permanently connected to the internet, providing greater convenience and quick access to cryptocurrencies. They include mobile, desktop and web wallets. Although convenient, they can pose a security risk if not adequately protected. • The “cold wallets” are offline wallets that are not permanently connected to the internet, thus providing more secure storage for cryptocurrencies. These include hardware wallets, which store cryptocurrencies on physical devices, and paper wallets, which contain private keys in printed form. • The “hardware wallets” are physical devices, such as USB drives, that securely store and manage a user’s private keys. These devices are highly secure as transactions are generated offline and inside the device. CHAPTER 7: BLOCKCHAIN TECHNOLOGY AND CRYPTOCURRENCIES 118 BUSINESS INFORMATICS Following the success of Bitcoin, several other cryptocurrencies, collectively known as “altcoins”, have appeared on the market. These altcoins attempt to build on the foundations laid by Bitcoin, often offering new and innovative technologies or different use cases and features. Among altcoins are Ethereum, which focuses on running smart contracts and decentralized applications (dApps); Litecoin, which offers faster transaction times and lower transaction costs; and many others with different objectives and technological approaches. Bitcoin and altcoins together form a dynamic and rapidly evolving ecosystem that is constantly expanding with new digital currencies and blockchain-based projects. Bitcoin and altcoins play a critical role in the innovation and evolution of the cryptocurrency space, challenging traditional financial systems and exploring new possibilities for electronic money. Bitcoin remains the bestknown and most market-capitalized cryptocurrency, serving as a store of value for many investors as “digital gold”. On the other hand, Altcoins offer a wide range of innovations and specializations, allowing investors and users to participate in developing different aspects and applications of blockchain technology. An ICO, or Initial Coin Offering, raises capital for blockchain and cryptocurrency projects. The essence of ICOs is that companies issue and sell new digital tokens to the public, often in exchange for Bitcoin, Ethereum or other cryptocurrencies. This process is similar to a traditional company’s initial public offering (IPO) but significantly different. ICOs offer a decentralized, unregulated way to raise capital, allowing startups to bypass traditional banking and capital market funding routes. In ICOs, investors buy “tokens” that can grant them various rights in the project, such as a stake, the right to future profits, or access to certain services and products that the project offers. These tokens are usually issued on the project’s blockchain and can function as a speculative instrument, as their value can vary depending on market supply and demand dynamics. ICOs, at the height of their popularity, revolutionized the raising of capital in blockchain technology and cryptocurrencies, enabling small and medium-sized enterprises to raise significant amounts of money without relying on traditional capital markets. However, this form of unregulated capital raising also comes with many risks and challenges, such as high rates of fraud and project failure, which have attracted the attention of regulatory bodies worldwide (Feng et al., 2019). 119 2.1. Risk factors for cryptocurrencies The volatility of cryptocurrencies is one of the most significant features and challenges in the digital currency market. This volatility attracts speculators and investors looking for quick profits while also posing a significant risk to those who do not manage their investments properly. The cryptocurrency market is relatively new and immature compared to traditional financial markets, such as stock or bond markets. Lower liquidity, less developed market infrastructure and lower market capitalization contribute to higher price volatility. Much of the value of cryptocurrencies is based on speculation, which means that prices are often driven by investor sentiment and expectations rather than the underlying economic factors associated with traditional financial instruments. Cryptocurrency prices are highly sensitive to news in the media and the influence of social media. A significant announcement, regulatory change or even a tweet from an influential personality can trigger significant price movements. The second risk is technological uncertainty. Cryptocurrencies and blockchain technology are still evolving, which could expose new vulnerabilities and flaws. These vulnerabilities threaten the technological infrastructure and the assets of investors and users. Historically, several major cryptocurrency exchanges have been victims of hacker attacks, with significant amounts of digital assets stolen. Another important risk is the possibility of market manipulation. Due to the immaturity of cryptocurrency markets and the lack of regulation, market manipulation is much more likely than in traditional financial markets. This includes “pump and dump” schemes, where investors artificially inflate the price of a cryptocurrency only to sell it at a higher price. Last but not least, the risks of storing cryptocurrencies are also significant. Digital assets are stored in online or offline “wallets”, and both have security challenges. Online wallets are convenient and easily accessible but more vulnerable to hacking attacks. Cold storage (offline wallets) is more secure but also poses risks, such as loss or failure of the device. 2.2. Legal environment of cryptocurrencies Cryptocurrency regulation varies widely around the world. Some countries, such as Japan and Switzerland, have adopted relatively pro-cryptocurrency regulations, while others, such as China, have introduced strict restrictions or even banned cryptocurrency trading and mining altogether. The European Union is actively working to develop a single regulatory framework for cryptocurrencies that seeks to protect market integrity and users. In the United CHAPTER 7: BLOCKCHAIN TECHNOLOGY AND CRYPTOCURRENCIES 120 BUSINESS INFORMATICS States, regulation is still under development at several federal and state levels, under the jurisdiction of various regulatory bodies such as the SEC (Securities and Exchange Commission) and the CFTC (Commodity Futures Trading Commission). The taxation of cryptocurrencies also varies from country to country. Many countries, including the United States and the United Kingdom, treat cryptocurrencies as assets, meaning that transactions with cryptocurrencies, such as trading, selling, or even using them as a means of payment, are taxable. Gains from cryptocurrencies may be taxable as capital gains and, in many cases, must be declared with the tax authorities. Users should inform themselves about their country’s tax rules and seek expert advice if necessary. The legal challenges and perspectives on cryptocurrencies change dynamically as technology and markets evolve. The challenge for regulators is to find the delicate balance that allows technological innovation while preserving market integrity and protecting users. REFERENCES Abed, S., Jaffal, R., Mohd, B. J., et al. (2021). An analysis and evaluation of lightweight hash functions for blockchain-based IoT devices. Cluster Computing, 24(3), 30653084. https://doi.org/10.1007/s10586-021-03324-1 Feng, C., Li, N., Wong, M. H. F., & Zhang, M. (2019, March 25). Initial coin offerings, blockchain technology, and white paper disclosures. Available at SSRN: https:// ssrn.com/abstract=3256289 or http://dx.doi.org/10.2139/ssrn.3256289 Khoshavi, N., Tristani, G., & Sargolzaei, A. (2021). Blockchain applications to improve operation and security of transportation systems: A survey. Electronics, 10(5), 629. https://doi.org/10.3390/electronics10050629 Klinkmüller, C., Ponomarev, A., Tran, A. B., Weber, I., & van der Aalst, W. (2019). Mining blockchain processes: Extracting process mining data from blockchain applications. In Di Ciccio, C., et al. Business process management: Blockchain and Central and Eastern Europe forum. BPM 2019. Lecture notes in business information processing (Vol. 361, pp. 71–86). Springer, Cham. https://doi.org/10.1007/978-3030-30429-4_6 Liu, Y., Tsyvinski, A., & Wu, X. (2022). Common risk factors in cryptocurrency. The Journal of Finance, 77(2), 1133–1177. https://doi.org/10.1111/jofi.13119