# The Chief Information Officer

The Chief Information Officer (CIO) at Old Dominion University –ODU- is trying to improve the university’s information network security. The CIO is trying to evaluate a new intrusion detection technology in the market for a possible replacement for the existing system. An intrusion detection system sounds an “alarm” each time possible malicious attack on a network is detected. The following information is provided:

Event of interest, A, is an attack

Evidence, B, is intrusion detection system setting off due to anomalous traffic

Probability of an attack is 0.01

For the currently installed system, the probability of an alarm given that there is an attack is 0.9, while the probability of an alarm given there is no attack is 0.25.

For the new technology, the probability of an alarm given that there is an attack is 0.8, while the probability of an alarm given there is no attack is 0.1.

The CIO assumes that there are only two types of events: either there is, or there is no attack.

The CIO is using “evidence ratio,” described as P(B|A) / P(B|A’) as a way to compare the technologies. Please help the CIO compare the new technology with the currently installed system by answering the following questions:

What is evidence ratio for the currently installed system?

# The Chief Information Officer

The Chief Information Officer (CIO) and the Managing Director (MD) of Illustrious Limited recently had the following conversation regarding the development of a new information system for the company:
CIO: The way to go about the analysis is to first examine the old system, such as reviewing key documents and observing the workers performing their tasks. Then we can determine which aspects are working well and which should be preserved.
MD: We have been through these types of projects before, and what always ends up happening is that we do not get the new system we are promised. Instead we get a modified version of the old system.
CIO: I can assure you that will not happen this time. My team just want a thorough understanding of what is working well and what is not.
MD: I would feel much more comfortable if we first started with a list of our requirements. We should spend more time in determining what exactly we want the system to do upfront. Then your team can come in and determine what portions to salvage if you wish. Just don’t constrain us to the old system!
Required:
a) The CIO and MD have different views on how the system analysis should be performed. Comment
on whose position you sympathise with the most
b) What method would you recommend to Illustrious Limited for system analysis? Explain

