1. Brooks Industries is a large enterprise and has several legacy systems that effectively manage employee records. These legacy systems are maintained by a group of technical staff that are nearing retirement. These systems are used by a number of employees for many different tasks. The technical team have evolved some aspects of these systems, but much of the associated documentation has been lost and relevant staff have already retired. The systems contain personal data relating to employees, including bank details and medical information.
The management team are concerned about potential security and data protection issues given the age and importance of the legacy systems.
The management team are considering evolving the legacy systems to address potential security and data protection issues.
Devise a plan with FOUR clear steps to evolve the legacy systems in the given context.
[8]
The management team has been considering the options for evolving the legacy systems. There are some members of the management team that are arguing for development of replacement systems deployed using Infrastructure as a Service (IaaS). There are other members of the management team that favour utilising an established and specialised Managed Service Provider (MSP). There are members of the management team that are aware of other organisations using an MSP that specialises in employee record management and also employs many university graduates.
Argue for the optimal deployment by comparing and contrasting both options in the given context.
[8]
Brookes Industries is headquartered in the European Union with offices across Europe. The company has opened its first office in the United States of Ruritania. The company plans on transferring some employee personal data out of the European Union to systems in the United States of Ruritania.
The management team are concerned about the potential legal issues in transferring data outside the European Union to the United States of Ruritania. The technical team state there is no concern as they have determined that United States of Ruritania has adequate levels of data protection comparable to the European Union.
Argue the accuracy of the assessment by the technical team in the given context.
[4]