Showing posts with label Miscellanous. Show all posts
Showing posts with label Miscellanous. Show all posts

BS 25999 - Business Continuity Management Standard

Business Continuity Management (BCM) is essential for any business. Planning for crisis or disaster is a complex science and fundamentally an aspect of management that should not be neglected. BS 25999 is a Business Continuity Management (BCM) standard. It is in two parts - BS 25999-1 and BS 25999-2. The former is a code of practice and the latter is a specification for business continuity management that you can be audited against to gain BS 25999 registration.

BS 25999 offers an accepted framework for incident anticipation and response with a series of recommendations for good practice.

BS 25999 is a Business Continuity Management (BCM) standard published by the British Standards Institution (BSI).

It has two parts:
  • The first, "BS 25999-1:2006 Business Continuity Management. Code of Practice", takes the form of general guidance on the processes, principles and terminology recommended for BCM. Part 1 offers good practice advice on the things that ought to be considered to achieve business continuity. It needs to be interpreted by user organizations according to their specific situations.
  • The second, "BS 25999-2:2007 Specification for Business Continuity Management", formally specifies a set of requirements for implementing, operating and improving a BCM System (BCMS). Part 2 describes a how the business continuity arrangements described in part 1 can be managed systematically using a documented BCMS. Since part 2 is a precisely-worded specification, user organizations may opt to have their BCMS objectively and independently audited for compliance with the standard, leading to certification. The certificate assures stakeholders that the organization is proactively managing its business continuity in the structured manner laid down in part 2 of the standard. BS 25999-2 will be withdrawn in November 2012. It has been replaced by the International Standard, ISO 22301.
The contents of the code of practice (BS 25999-1) are as follows:
Section 1 - Scope and Applicability. This section defines the scope of the standard, making clear that it describes generic best practice that should be tailored to the organization implementing it
Section 2 - Terms and Definitions. This section describes the terminology and definitions used within the body of the standard
Section 3 - Overview of Business Continuity Management. A short overview is the subject of the standard. It is not meant to be a beginners guide but describes the overall processes, its relationship with risk management and reasons for an organization to implement along with the benefits
Section 4 - The Business Continuity Management Policy. Central to the implementation of business continuity is having a clear, unambiguous and appropriately resourced policy
Section 5 - BCM Programme Management. Programme management is at the heart of the whole BCM process and the standard defines an approach
Section 6 - Understanding the organization. In order to apply appropriate business continuity strategies and tactics the organization has to be fully understood, its critical activities, resources, duties, obligations, threats, risks and overall risk appetite.
Section 7 - Determining BCM Strategies. Once the organization is thoroughly understood the overall business continuity strategies can be defined that are appropriate.
Section 8 - Developing and implementing a BCM response. The tactical means by which business continuity is delivered. These include incident management structures, incident management and business continuity plans.
Section 9 - Exercising, maintenance, audit and self-assessment of the BCM culture. Without testing the BCM response an organization cannot be certain that they will meet their requirements. Exercise, maintenance and review processes will enable the business continuity capability to continue to meet the organizations goals.
Section 10 - Embedding BCM into the organizations culture. Business continuity should not exist in a vacuum but become part of the way that the organization is managed.

The contents of the specification (BS 25999-2) are as follows:
Section 1 - Scope. Defines the scope of the standard, the requirements for implementing and operating a documented business continuity management system (BCMS)
Section 2 - Terms and Definitions. This section describes the terminology and definitions used within the body of the standard
Section 3 - Planning the Business Continuity Management System (PLAN). Part 2 of the standard is predicated on the well established Plan-Do-Check-Act model of continuous improvement. The first step is to plan the BCMS, establishing and embedding it within the organization.
Section 4 - Implementing and Operating the BCMS (DO) Actually implement ones plans. This section includes a number of topics that are found in Part 1 although Part 1 should only be used for general guidance and information. Only what is in Part 2 can be assessed.
Section 5 - Monitoring and Reviewing the BCMS (CHECK) To ensure that the BCMS is continually monitored the Check stage covers internal audit and management review of the BCMS
Section 6 Maintaining and Improving the BCMS (ACT) To ensure that the BCMS is both maintained and improved on an ongoing basis this section looks at preventative and corrective action

What is Business Continuity Planning?

Business continuity planning (BCP) is the creation and validation of a business continuity plan for how an organisation will recover and restore critical functions after a disaster or incident.
BCP is working out how to stay in business local, regional or national levels and include fires, floods, and pandemic illnesses in the event of disaster. Incidents can occur on local, regional or national levels and include fires, floods, and pandemic illnesses.
The development of a BCP system can have five main phases:
  1. Analysis
  2. Solution design
  3. Implementation
  4. Testing and organisation acceptance
  5. Maintenance
Each of these has many elements that are tailored to the needs of an organisation.

The Benefits of Implementing BS 25999

There are widespread benefits of BS 2599 including the following critical areas:
  1. Delivery - Following a disruption it provides a rehearsed method of restoring the ability to supply critical products and services to an agreed level and timeframe
  2. Resilience - Proactively improves resilience when faced with the disruption of an organisation’s ability to achieve key objectives
  3. Management - Delivers a proven capability for managing a disruption and protecting (and enhancing) reputation and brand
Further benefits include cost savings, compliance with applicable laws and regulations, and identifying opportunities for improvement.

Why Seek Certification to BS 25999?

  • Registration to BS 25999 by an accredited certification body shows commitment to customers in providing confidence that the business can still function irrespective of unforeseen circumstances/interference.
  • It demonstrates the existence of an effective business continuity system that satisfies the rigours of an independent, external audit.
  • A certificate for BS 25999 enhances company image in the eyes of customers, employees and shareholders.
  • It also gives a competitive advantage to an organisation’s marketing.

How do you Start To Implement BS 25999? What is Involved?

  • Identify the requirements of BS 25999 and how they apply to the business involved.
  • Establish business continuity objectives and how they fit in to the operation of the business.
  • Produce a documented business continuity policy indicating how these requirements are satisfied.
  • Communicate them throughout the organisation.
  • Evaluate the business continuity policy, its stated objectives and then prioritise requirements to ensure they are met.
  • Identify the boundaries of the management system and produce documented procedures as required.
  • Ensure these procedures are suitable and adhered to.
  • Once developed, internal audits are needed to ensure the system carries on working.

Assessment to BS 25999

Once all the requirements of BS 25999 have been met, it is time for an external audit. This should be carried out by a third party certification body. The chosen certification body will review the business continuity manuals and procedures. This process involves looking at the company’s evaluation of business continuity and ascertains if targets set for the management programme are measurable and achievable. This is followed at a later date by a full on-site audit to ensure that working practices observe the procedures and stated objectives and that appropriate records are kept.
After a successful audit, a certificate of registration to BS 25999 will be issued. There will then be surveillance visits (usually once or twice a year) to ensure that the system continues to work. This is covered in more detail in ISOQAR’s ‘Audit Procedure’ information sheet.


ISO 27001 - Information Security Management System (ISMS)

ISO 27001 is the international best practice standard for an Information Security Management System (ISMS). ISO/IEC 27001, part of the growing ISO/IEC 27000 family of standards, is an Information Security Management System (ISMS) standard published in October 2005 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).

How the Standard works:
Most organizations have a number of information security controls. However, without an ISMS (Information Security Management System), controls tend to be somewhat disorganized and disjointed, having been implemented often as point solutions to specific situations or simply as a matter of convention. Security controls in operation typically address certain aspects of IT or data security specifically; leaving non-IT information assets (such as paperwork and proprietary knowledge) less protected on the whole. Moreover business continuity planning and physical security may be managed quite independently of IT or information security while Human Resources practices may make little reference to the need to define and assign information security roles and responsibilities throughout the organization.

ISO/IEC 27001 requires that management:
  • Systematically examine the organization's information security risks, taking account of the threats, vulnerabilities, and impacts;
  • Design and implement a coherent and comprehensive suite of information security controls and/or other forms of risk treatment (such as risk avoidance or risk transfer) to address those risks that are deemed unacceptable; and
  • Adopt an overarching management process to ensure that the information security controls continue to meet the organization's information security needs on an ongoing basis.
An Information Security Management System (ISMS) helps you coordinate all your security efforts – both electronic and physical – coherently, consistently and cost-effectively.

Information security is not just about anti-virus software, implementing the latest firewall or locking down your laptops or web servers. The overall approach to information security should be strategic as well as operational, and different security initiatives should be prioritised, integrated and cross-referenced to ensure overall effectiveness.

ISO/IEC 27001:2005, usually referred to just as ISO 27001, is the best practice specification that helps businesses and organisations throughout the world to develop a best-in-class Information Security Management System (ISMS). The Standard was published jointly by the International Security Office (ISO) and the International Electrotechnical Commission (IEC). The British standard BS7799-2 was the forerunner for ISO 27001.

In this modern age, information and information systems are vital to all organisations. ISO 27001 sets out specific requirements, all of which must be followed, and against which an organisations Information Security Management System (ISMS) can be audited and certified.

ISO 27001 is the first in a family of international information security standards that:
  • Will underpin and protect IT worldwide over the next decade
  • ISO 27001 is designed to harmonise with ISO 9001:2008, ISO 14001:2004, ISO 20000 and others for effective management system integration
  • Implements the Plan-Do-Check-Act (PDCA) model, and
  • Reflects the principles of the 2002 OECD guidance on the security of information systems and networks.



ISO 20000 - IT Service Management

ISO 20000 is a global standard that describes the requirements for an information technology service management (ITSM) system. The standard was developed to mirror the best practices described within the IT Infrastructure Library (ITIL) framework. ISO 20000 also supports other frameworks, such as Microsoft's Operations Framework.

ISO 20000 is comprised of two parts: a specification for IT Service Management (ISO 20000-1) and a code of practice for service management (ISO 20000-2).

ISO 20000 was formerly called BS 15000 and was developed by the British Standards Institutions (BSI), an international standards, testing and certification organization.

ISO/IEC 20000 is the first international standard for IT service management. It was developed in 2005, by ISO/IEC JTC1 SC7 and revised in 2011. It is based on and intended to supersede the earlier BS 15000 that was developed by BSI Group.
Formally: ISO/IEC 20000-1:2011 ('part 1') includes "the design, transition, delivery and improvement of services that fulfil service requirements and provide value for both the customer and the service provider. This part of ISO/IEC 20000 requires an integrated process approach when the service provider plans, establishes, implements, operates, monitors, review, maintains and improves a service management system (SMS).". The 2011 version (ISO/IEC 20000-1:2011) comprises nine sections:
  1. Scope
  2. Normative references
  3. Terms and definitions
  4. Service management system general requirements
  5. Design and transition of new or changed services
  6. Service delivery processes
  7. Relationship processes
  8. Resolution processes
  9. Control processes


ISO/IEC 20000-2:2012 provides guidance on the application of service management systems (SMS) based on the requirements in ISO/IEC 20000-1:2011.

ISO/IEC TR 20000-3:2009 provides guidance on scope definition, applicability and demonstration of conformance for service providers aiming to meet the requirements of ISO/IEC 20000-1, or for service providers who are planning service improvements and intending to use ISO/IEC 20000 as a business goal. It supplements the advice in ISO/IEC 20000-2, which provides generic guidelines for implementing an SMS in accordance with ISO/IEC 20000-1.

ISO/IEC TR 20000-4:2010 is intended to facilitate the development of a process assessment model according to ISO/IEC 15504 process assessment principles. ISO/IEC 15504-1 describes the concepts and terminology used for process assessment. ISO/IEC 15504-2 describes the requirements for the conduct of an assessment and a measurement scale for assessing process capability.

ISO/IEC TR 20000-5:2010 is an exemplar implementation plan providing guidance to service providers on how to implement a service management system to fulfil the requirements of ISO/IEC 20000-1 or for service providers who are planning service improvements and intending to use ISO/IEC 20000 as a business goal. It could also be useful for those advising service providers on how to best achieve the requirements of ISO/IEC 20000-1.

ISO/IEC 20000, like its BS 15000 predecessor, was originally developed to reflect best practice guidance contained within the ITIL (Information Technology Infrastructure Library) framework, although it equally supports other IT Service Management frameworks and approaches including Microsoft Operations Framework and components of ISACA's COBIT framework. The differentiation between ISO/IEC 20000 and BS 15000 has been addressed by Jenny Dugmore.[3][4]

The standard was first published in December 2005. In June 2011, the ISO/IEC 20000-1:2005 was updated to ISO/IEC 20000-1:2011. In February 2012, ISO/IEC 20000-2:2005 was updated to ISO/IEC 20000-2:2012.

The Benefits of ISO 20000 Implementation:

Implementation of ISO 20000 brings with it many benefits and advantages. These will fo course differ from organization to organization. However, the following list is a pretty good representation of the common results:
1. Alignment of information technology services and business strategy.
2. Creation of a formal framework for current service improvement projects
3. Provides a benchmark type comparison with best practices
4. Creates competitive advantage via the promotion of consistent and cost-effective services.
5. By requiring ownership and responsibility at all levels, it creates a progressive ethos and culture.
6. Supports 'interchanging' of service providers and staff by virtue of the creation of inter-enterprize operational processes.
7. Reduction of risk and thus cost in terms of external service receipt
8. Through the creation of a standard consistent approach, aids major organizational changes.
9. Enhanced reputation and perception
10. Fundamental shift to pro-active rather than re-active processes
11. Improved relationship between different departments via better defninition and more clarity in terms of responsibility and goals.
12. Creation of a stable framework for both resource training and service management automation. 

Radian6 - Next Generation Social Monitoring

Radian6 covers over 150 million sources each day, including the broadest available coverage of:
  • Blogs
  • Mainstream online news, such as CNN.com
  • Video and Photo sharing sites, like Flickr and YouTube
  • Micromedia, including the full Twitter firehose
  • Forums and Discussion Boards
  • Blog comments
  • Facebook public discussion forums
Radian6 use a combination of RSS and other data feeds in addition to proprietary crawlers in order to index the entire social web. If data is available publicly, then it’ll capture it. That also means that data the community trusts to stay behind a wall, will; it don’t crawl or capture sites like private portions of Facebook, private communities, or anything like that. Radian6 capture over eight million on-topic posts and comments each day, filter out the spam and irrelevant data, and deliver results to you in near real time.

Comparing different monitoring solutions can be like comparing apples to oranges. But here’s what Radian6's customers and clients said about it, and some of the reasons they decided Radian6 platform was right for them:
  • Breadth of Coverage – Every day, Radian6 deliver over eight million relevant results to their customers, pulled from a much larger set of scanned results.
  • Ease of Use – comprehensive, but not so complicated that you need an engineering degree to use us. The Radian6 platform is designed to be easy to use and navigate for a novice, but powerful and flexible enough to meet the needs of the most advanced user. If you need some extra help figuring things out, we’ve got an extensive training program that will ensure you’re an expert in no time.
  • Comprehensive Analytics – Gathering data is one thing. Analyzing it is another. From trends and influencer analysis to deep filtering, social media metrics, and data segmentation, it give you myriad ways to drill down into your data and understand how the social web is impacting your business.
  • Go beyond raw information with Insights – Radian6 Insights platform takes the industry’s best social media monitoring system and combines it with leading insights vendors to bring new understanding to the social web. Discover key intelligence like demographics, influence, geolocation, enhanced sentiment and topic analysis to help drive your decision-making process.
  • Workflow Capabilities – One of more compelling advantages, Radian6 helps you scale social media listening and engagement throughout the company with our workflow capabilities. Assign and route posts, tag results with relevant information, classify and mark action status on items, and receive email or IM alerts for new posts in your topic profiles.
  • Support – Put simply, Radian6 are proud to have a support team that is second to none. It’ll help you get started out on the right foot with Radian6, and Radian6 entire support team is available to you anytime you have questions, issues, or thoughts about how to make the platform better.
  • Community Focus – Radian6 users are what drive Radian6 development. The features Radian6 develop and create are all based on feedback and input Radian6 get from their active user community. That means we’re listening, and always striving to build a platform that’s more valuable for you in your work.
  • Thinking Ahead –  Radian6 is not just trying to build a great listening platform, Radian6 is trying to build a great enterprise social media platform for you. That means Radian6 is committed to enhancing your social media listening experience, through Radian6 integrated web analytics and CRM capabilities – to bridge social media to all areas of your business.
Some Features:

Manage Your Social Media Monitoring

Integrating the use of social media channels into your organization starts with listening. To define how and where you should be responding, you need to know how and where people are talking about you. The sheer volume of social media data can be hard to manage without a proper platform to find and engage discussions that matter most to you. With Radian6, you’ll be poised to absorb and act on the most relevant information people are sharing about your brand, products, competitors, and industry.
The Radian6 dashboard is a complete social media monitoring, engagement, and workflow management platform created to help you aggregate and analyze the comments people are making on the web. View trends and dig deeper into specific posts to get a pulse on how your company is faring online.
 Easy Set-up

Take advantage of the Quickstart topic profile set-up tool and Widget Gallery to get up and running in the dashboard quickly. Select topic profile keywords, then quickly apply filters and get an estimated monthly result volume. Once your topic profile is set, use the Widget Gallery to build your dashboard and get started tracking and analyzing in no time. We’ll even give you 30 days of immediate historical data, with long-range historical data available upon request, to make sure you get caught up on past conversations.
Comprehensive Coverage

Scour more than 150 million public sites and sources including blogs and comments, forums, mainstream online news publications, public photos and videos. We even monitor the open Facebook API and we pull in every tweet through the Twitter Firehose for you, too. Our dashboard gathers it all for you, in real time, so that you’ll never again miss a meaningful post.

Easy Reporting

Sharing data and insights from your Radian6 topic profile is simple. Copy your dashboard to your teammates or supervisors to show them what you’re hearing and seeing, and how your activities are impacting results. Build and save multiple dashboards to segment and easily view data, and download or email dashboard, widget, or engagement reports.

 Social Media Metrics

 Look at your brand or topic through the unique lens of social media, and the specific measurements and metrics that matter in that context. View coverage and mentions by vote count, comment count, Twitter followers, sentiment, media type and more. Look specifically at influencer data to discover who’s got clout in your industry and what they’re saying.

 Workflow Management

Use workflow management in the River of News, our round up of all the stories surrounding your brand, or in our Engagement Console to scale listening across your organization. Assign posts to team members. Add internal notes, flag priority, categorize and classify posts. Set up an “online caller ID” system with post and source tags, schedule alerts, and report on engagement activity right from the dashboard.

Social CRM and Web Analytics Integration

Tie your dashboard into your Salesforce database and create contacts, leads, and support cases right from your River of News. Use our Google Analytics, WebTrends and Omniture integrations to view social media results through the lens of web stats. Understand the context and content that drives action on your website, and connect social media with your sales pipeline.

 Enterprise-level Scalability

The Radian6 dashboard integrates seamlessly with the Engagement Console to bring social media monitoring, engagement, and analysis to every desktop in your company. Both work in concert to feed data into your profile for tracking, reporting and analysis — and guarantee that your social media teams are in sync on the information that matters most to them.

Measuring Facebook

It’s important to note that comparing exact metrics of brand mentions on Twitter versus Facebook can be misleading, because conversations in open-access areas of Facebook only represent a snapshot of the potential total brand mentions. If a mention is posted in a closed or private area of Facebook, we won’t be able to include it in your results. As a business, it’s important to keep this distinction in mind, because it will impact the way you can measure and account for Facebook results in your monitoring and measurement activities.

A Note About Privacy

Something that’s very important to make clear: if your individual Facebook profile privacy settings are set to anything other than being viewable by “Everyone”, or if your Group is set to Closed/Secret, neither we nor any other search or monitoring provider will be able to see or find anything posted there.

Facebook is only a partially open network by design, which means that what’s visible to the outside world is dictated by the users themselves, and controllable via profile settings and preferences. For individuals, you can find those settings on your profile under Account > Privacy Settings. For Page administrators, you can adjust who can post to your page Wall your admin section, but wall posts on Pages are, by design, public. Facebook Groups can be made Open (completely public), Closed, or Secret, the last two only being visible to group members (and controllable by the administrator).
If your individual profile is private but you post to the Wall of a Facebook Page or public Group for a company or brand, that post will be publicly visible and available to Radian6 and other monitoring or search tools via the Social Graph API.

In short, Radian6 can and will only ever cover items that are classified as public, or that are posted in Facebook’s public areas.

What Radian6 Cover

Radian6′s coverage of Facebook is built on Facebook’s Graph API. In clear terms, what that means is that Facebook provides us with a data stream of:
public wall posts or status updates
• wall posts on Facebook Pages (or Fan Pages, as they’re commonly known)
• wall posts on Facebook Community Pages.

Also, a cool new feature: Facebook “likes” (from the Facebook Likes “plugin”) are now included in the “Votes and Likes” metrics on your Radian6 dashboard. Our current support is for the Like Plugin embedded on websites external to Facebook. So if 20 people Like an on-topic piece of content where you’ve got the plugin installed, we’ll count it in the Votes and Likes metric in your dashboard.

(Note: while you’ll see Facebook posts in your search results, Facebook still requires you to log in to be able to view the public individual profile wall posts on Facebook itself.) As it stands right now, the Facebook Graph API doesn’t include comments on wall posts. So, for instance, if someone posts a link on your Facebook wall and 10 people comment underneath that, those comments won’t be included in your Radian6 search results (even if they include keywords from your Topic Profile). It’s a current limitation, but we’re actively working on adding this capability.

As Facebook continues to build out their Graph API, we’ll continue to expand and refine the coverage that we can provide via Radian6. We’re going to continue carrying out coverage checks and enhancements on an ongoing basis, and we’ll keep you updated on how that coverage evolves.

See more:
Radian6 Features
Radian6 Pricing
Listen when no one's talking

SSL Certificates

What is SSL?
SSL stands for "Secure Sockets Layer". SSL Definition; Secure Sockets Layer is a protocol designed to enable applications to transmit information back and forth securely. Applications that use the Secure Sockets Layer protocol inherently know how to give and receive encryption keys with other applications, as well as how to encrypt and decrypt data sent between the two.

To enable SSL on a website, you will need to get an SSL Certificate that identifies you and install it on the server. The use of an SSL certificate on a website is usually indicated by a padlock icon in web browsers but it can also be indicated by a green address bar. Once you have done the SSL install, you can access a site securely by changing the URL from http:// to https://. When an SSL certificate is installed on a website, you can be sure that the information you enter (contact or credit card information), is secured and only seen by the organization that owns the website.


Millions of online businesses use SSL certificates to secure their websites and allow their customers to place trust in them. In order to use the SSL protocol, a web server requires the use of an SSL certificate. SSL certificates are provided by Certificate Authorities (CAs).

Why do I need SSL?

If you are transmitting sensitive information on a web site, such as credit card numbers or personal information, you need to secure it with SSL encryption. It is possible for every piece of data to be seen by others unless it is secured by an SSL certificate.

Your customers won't trust your web site without an SSL certificate. According to Gartner Research, nearly 70 percent of online shoppers have terminated an online order because they did not "trust" the transaction. In those cases, 64 percent indicated that the presence of a trust mark would have likely prevented the termination. An SSL certificate and a site seal could stop people from abandoning your website and that means more money for you. Read our why SSL is necessary page to learn more.

What is a certificate authority (CA)?

A certificate authority is an entity which issues digital certificates to organizations or people after validating them. Certification authorities have to keep detailed records of what has been issued and the information used to issue it, and are audited regularly to make sure that they are following defined procedures. Every certification authority provides a Certification Practice Statement (CPS) that defines the procedures that will be used to verify applications. There are many commercial CAs that charge for their services (VeriSign). Institutions and governments may have their own CAs, and there are also free Certificate Authorities.

Every certificate authority has different products, prices, SSL certificate features, and levels of customer satisfaction. Read our SSL Certificate reviews to find the best provider to purchase from.

How does SSL work? Some applications that are configured to run SSL include web browsers like Internet Explorer and FireFox, email programs like Outlook, Mozilla Thunderbird, Apple Mail.app, and SFTP (secure file transfer protocol) programs, etc. These programs are automatically able to receive SSL connections.
To establish a secure SSL connection, however, your application must first have an encryption key assigned to it by a Certification Authority in the form of a Certificate. Once it has a unique key of its own, you can establish a secure connection using the SSL protocol. 

This is in short how it works.
  1. A browser requests a secure page (usually https://).
  2. The web server sends its public key with its certificate.
  3. The browser checks that the certificate was issued by a trusted party (usually a trusted root CA), that the certificate is still valid and that the certificate is related to the site contacted.
  4. The browser then uses the public key, to encrypt a random symmetric encryption key and sends it to the server with the encrypted URL required as well as other encrypted http data.
  5. The web server decrypts the symmetric encryption key using its private key and uses the symmetric key to decrypt the URL and http data.
  6. The web server sends back the requested html document and http data encrypted with the symmetric key.
  7. The browser decrypts the http data and html document using the symmetric key and displays the information.
 Here is What Happens When a Web Browser Connects to a Secure Web Site. A browser attempts to connect to a Web site secured with SSL. 

The Green Address Bar Restores Trust with Extended Validation
An EV SSL Certificate gives customers more confidence that they are interacting with a trusted Web site and that their information is secure. An EV SSL Certificate triggers high-security Web browsers to display your organization's name in a green address bar and show the name of the Certificate Authority that issued it. The Certificate Authority uses an audited, rigorous authentication method and browsers control the display, making it difficult for phishers and counterfeiters to hijack your brand and your customers.


An EV certificate is a new type of certificate that is designed to prevent phishing attacks. It requires extended validation of your business and authorization to order the certificate and can take a few days to a few weeks to receive. It provides even greater assurance to customers than high assurance certificates by making the address bar turn green.

A wildcard certificate can secure an unlimited number of first level sub domains on a single domain name. For example, you could get a wildcard certificate with *.yourdomain.com as the common name. This certificate would secure www.yourdomain.com, mail.yourdomain.com, secure.yourdomain.com, anything.yourdomain.com, etc... In other words, it will work on any sub-domain that replaces the wildcard character (*).

Encryption is a mathematical process of coding and decoding information. Encryption ensures that information is scrambled in transit so that only the intended recipient can decode it. The number of bits (40-bit, 56-bit, 128-bit, 256-bit) tells you the size of the key. Like a longer password, a larger key has more possible combinations. In fact, 128-bit encryption is one trillion times one trillion times stronger than 40-bit encryption. At current computing speeds, a hacker with the time, tools, and motivation to attack would require a trillion years to break into a session with 128-bit encryption. SSL Certificates with server-gated cryptography (SGC) enable 128- or 256-bit encryption for over 99.9% of Internet users
 


VeriSign Authentication Services

Having a merchant account or payment gateway to process and protect online credit card payments is essential to any online business. VeriSign's payment gateway was acquired by PayPay. Our VeriSign review indicates they still provide the best security for payments.

When shopping online, your customers want to know that they are safe. They want to know that the transactions they make with your Web site are secure, and that they are not likely to have information stolen by a third party. One of the most trusted names in payment gateway security is VeriSign. VeriSign helps protect payment gateways through encryption. It is true that VeriSign used to have its own payment gateway, but it was acquired by PayPal. But, even though VeriSign no longer offers a payment gateway, it does help keep all sorts of Web site payment gateways secure.

VeriSign security certificates

VeriSign uses an encryption method call Secure Socket Layer (SSL) to encode messages. When you enter your information for a transaction, it is scrambled so that third parties who might intercept it can't read it. The seller's Web site has the proper key to decode the message and get the information. SSL encryption is also used by payment gateways to encode it when it is being sent to banks for authorization.

You usually have to pay for your own security certificate. However, in some cases it is possible to sign on to the certificate offered by your ecommerce Web host. This is usually cheaper, but it means that you cannot take the certificate with you when you change Web hosts. If you want your own validation, you will have to pay more for your own certificate. Here are some of the offerings from VeriSign in terms of SLL certifications:
  • Secure Site Pro with EV: This is the most secure certificate. It comes with a warranty of up to $250,000 and offers a minimum of 128-bit encryption and up to 56-bit. The cost for one year is $1,499. For two years, it costs $2,695. Extended validation (EV) is included.
  • Secure Site Pro: This is also a highly rated in terms of security, with the 128 – 256 bit encryption strength. However, it is without the extended validation. It is possible to get this validation for one, two or three years for $995, $1,790 and $2,480, respectively.
  • Secure Site with EV: The security level on this is less than the Secure Site Pro with EV, but still pretty good. This product still has the extended validation. You can get a one year validation for $995 or a two year for $1,790.
  • Secure Site: Offers the features of Secure Site EV, but without the EV. Available in validations of one, two or three years. This is the least expensive options, with the prices ranging from $399 for one year to $995 for three years. However, the security could be a minimum 40 bit encryption. This isn't bad, but it's not that great, either.
In any case, it is important to have some sort of a security certificate for your business Web site. Most online shoppers will check to see if you are adequately protected. The VeriSign name is one that can be trusted, and customers will have peace of mind when they shop on your site if you have validation prominently displayed. However, it is up to you to do your research and decide what level of security and validation you want, as well as whether you want your own certificate or whether you share with your ecommerce Web host.

References site: http://www.verisign.com/

About Payment Gateway

A payment gateway is a way to process electronic transactions. Payment gateways provide the tools to process payments between customers, businesses, and banks. A payment gateway is an e-commerce application service provider service that authorizes payments for e-businesses, online retailers, bricks and clicks, or traditional brick and mortar. It is the equivalent of a physical point of sale terminal located in most retail outlets. Payment gateways protect credit card details by encrypting sensitive information, such as credit card numbers, to ensure that information is passed securely between the customer and the merchant and also between merchant and the payment processor.

Some of the main features of a payment gateway include:
  • Software application designed especially for ecommerce, although it can be used to authorize payments in traditional brick and mortar businesses.
  • Encryption of payment and personal data.
  • Communication between the financial institutions involved and the business and the customer.
  • Authorization of payments.
How payment gateways work

A payment gateway facilitates the transfer of information between a payment portal (such as a website, mobile phone or IVR service) and the Front End Processor or acquiring bank. When a customer orders a product from a payment gateway-enabled merchant, the payment gateway performs a variety of tasks to process the transaction

  1. A customer places order on website by pressing the 'Submit Order' or equivalent button, or perhaps enters their card details using an automatic phone answering service.
  2. If the order is via a website, the customer's web browser encrypts the information to be sent between the browser and the merchant's webserver. This is done via SSL (Secure Socket Layer) encryption.
  3. The merchant then forwards the transaction details to their payment gateway. This is another SSL encrypted connection to the payment server hosted by the payment gateway.
  4. The payment gateway forwards the transaction information to the payment processor used by the merchant's acquiring bank.
  5. The payment processor forwards the transaction information to the card association (e.g., Visa/MasterCard)
    • If an American Express or Discover Card was used, then the processor acts as the issuing bank and directly provides a response of approved or declined to the payment gateway.
    • Otherwise [eg: a Mastercard or Visa card was used], the card association routes the transaction to the correct card issuing bank.
  6. The credit card issuing bank receives the authorization request and does fraud and credit or debit checks and then sends a response back to the processor (via the same process as the request for authorization) with a response code [eg: approved, denied]. In addition to communicating the fate of the authorization request, the response code is used to define the reason why the transaction failed (such as insufficient funds, or bank link not available). Meanwhile, the credit card issuer holds an authorization associated with that merchant and consumer for the approved amount. This can impact the consumer's ability to further spend (eg: because it reduces the line of credit available or because it puts a hold on a portion of the funds in a debit account).
  7. The processor forwards the authorization response to the payment gateway.
  8. The payment gateway receives the response, and forwards it on to the website (or whatever interface was used to process the payment) where it is interpreted as a relevant response then relayed back to the merchant and cardholder. This is known as the Authorization or "Auth"
  9. The entire process typically takes 2–3 seconds.
  10. The merchant then fulfills the order and the above process is repeated but this time to "Clear" the authorization by consummating the transaction. Typically the "Clear" is initiated only after the merchant has fulfilled the transaction (eg: shipped the order). This results in the issuing bank 'clearing' the 'auth' (ie: moves auth-hold to a debit) and prepares them to settle with the merchant acquiring bank.
  11. The merchant submits all their approved authorizations, in a "batch" (eg: end of day), to their acquiring bank for settlement via its processor.
  12. The acquiring bank makes the batch settlement request of the credit card issuer.
  13. The credit card issuer makes a settlement payment to the acquiring bank (eg: the next day)
  14. The acquiring bank subsequently deposits the total of the approved funds in to the merchant's nominated account (eg: the day after). This could be an account with the acquiring bank if the merchant does their banking with the same bank, or an account with another bank.
  15. The entire process from authorization to settlement to funding typically takes 3 days.
Many payment gateways also provide tools to automatically screen orders for fraud and calculate tax in real time prior to the authorization request being sent to the processor. Tools to detect fraud include geolocation, velocity pattern analysis, OFAC list lookups, 'black-list' lookups, delivery address verification, computer finger printing technology, identity morphing detection, and basic AVS checks.

Security
Since the customer is usually required to enter personal details, the entire communication of 'Submit Order' page (i.e. customer - payment gateway) is often carried out through HTTPS protocol. To validate the request of the payment page result, signed request is often used - which is the result of the hash function in which the parameters of an application confirmed by a «secret word», known only to the merchant and payment gateway. To validate the request of the payment page result, sometimes IP of the requesting server has to be verified.
    There is a growing support by acquirers, issuers and subsequently by payment gateways for Virtual Payer Authentication (VPA), implemented as 3-D Secure protocol - branded as Verified by VISA, MasterCard SecureCode and J/Secure by JCB, which adds additional layer of security for online payments. 3-D Secure promises to alleviate some of the problems facing online merchants, like the inherent distance between the seller and the buyer, and the inability of the first to easily confirm the identity of the second.
If you already have a Web site, but you haven't been using it to automatically process payments from customers, you will need to integrate a payment gateway if you are planning to take your Web site to the next level and reach more customers.

What you need for payment gateway integration

Payment gateway integration requires a little bit of work. It is a software application that needs to be stored on your server. This means that you may need a little more bandwidth and/or disk space. Check the requirements of the payment gateway to make sure that your current hosting package will be able to handle the increase in technical requirements. Another thing you will need to do is make sure that the payment gateway is compatible with the programming language used on your ecommerce Web site. 

Check to find out whether you are using one of the following:
  • ASP or ASP.NET
  • Perl/CGI
  • PHP (rather popular)
  • Visual Basic .NET
Make sure that your payment gateway uses the same language as the rest of your Web site, so that they fit together well. Additionally, you will need to find out what sort of fees and costs are associated with payment gateway integration and service.

In many cases, it can be easiest to have your payment gateway integrated by your ecommerce Web host. This way, you know that the gateway is compatible with your site, and your payment gateway costs can be rolled into your hosting service fee. Just make sure you understand whether or not a service upgrade is required when you add a payment gateway to your ecommerce Web site.

Popular payment gateway providers
If you are looking for a good payment gateway, there are some payment providers that are more popular than others. These include:
  • PayPal
  • Google Checkout
  • 2Checkout
  • Authorize.net
  • Cyber Source
  • LinkPoint
What you decide on depends on your needs, as well as what you can afford. You might find that simply integrating PayPal or Google Checkout does the trick, even though it may not be customizable. In some cases, it is worth your while to choose a more expensive company and a programmer that can help you integrate your payment gateway in a more personal manner.

As more and more people do their shopping online, businesses are finding that they need to offer payment options that are easy and convenient to use. One of the payment options growing in popularity is Google Checkout. Google Checkout is not exactly a payment gateway. However, it does facilitate payment from customers. Customers can use credit or debit card in order to pay. Indeed, Google works in such a way that customers can leave their personal payment information with Google Checkout, and they do not have to enter in at other Web sites – as long as that site accepts Google Checkout. Google Checkout does not charge any gateway, set up or monthly fees. The only fees charged are transaction fees. 

Amazon payment gateway
Amazon offers a payment service for sellers and affiliates of Amazon, as well as services for those on other Web sites. For those that sell on Amazon, the payment system is extremely easy to use. It is integrated with your seller account, and it can even work with Amazon fulfillment in the case that you rely on Amazon to ship the items that you sell. The Amazon account can also be used in conjunction with the commissions you might get as part of an affiliate selling Amazon products and services.
For those businesses that are not exactly affiliated with Amazon, but would still like to take advantage of a trusted and inexpensive payment service provider, there are options as well. You can accept payments through the Amazon Pay Now widget or through some other means. This process brings the buyer to the Amazon site, where they can use their Amazon account to pay for purchases at your Web site. For customers, this can bring peace of mind, since many savvy online shoppers do not like to leave personal payment information at multiple sites.

Pricing for the Amazon payment gateway
Pricing for Amazon payment gateway services is relatively reasonable. Indeed, it is faster than most traditional payment gateways. Basically, Amazon has this fee structure for sellers and online businesses that use its services:
  • On transactions that are greater than ten dollars, Amazon charges 2.9% + 30 cents.
  • For transactions that are less than ten dollars, there is a 5% + 5 cents fee.
  • There are volume discounts for different monthly transaction amounts at the $3,000 - $10,000 level, the $10,000 - $100,000 level and the $100,000+ level.
While some of the per-transaction fees are about the same as other payment gateway services, the savings come in with regard to other fees – or the lack of them. Amazon payment services do not require start-up fees or monthly charges. Additionally, you do not have to sign any long-term contracts. There are no charges beyond the per-transaction fee. Most traditional payment gateway services have minimums and monthly charges, as well as other fees.

Payment gateways and merchant accounts are similar, keep reading for differences. If you want to accept credit card payments online, you will generally need an internet merchant account. This type of bank account is specifically designed to allow you to accept online payments.

Merchant accounts are bank accounts set up specifically for receiving credit card payments, such as those processed through a payment gateway. Online stores need an internet merchant account. Many banks prefer to give merchant accounts to brick-and-mortar businesses, those with a physical store, rather than those that are solely online, so those with online-only stores may have to shop around to find an internet merchant account. Some merchant accounts are also regular bank accounts, while others simply accept the payment and then deposit into another business account for you.

You will probably have to go through a third party to get a merchant account unless you are a very large business. Merchant accounts may come as part of an eCommerce package or in conjunction with a shopping cart or payment gateway, or merchants can establish one on their own. If you do get a merchant account separately, make sure that it is compatible with your payment gateway and shopping cart software.

It is important to read the details of a merchant account carefully to avoid being surprised by unexpected fees. It is also wise to do some research about the merchant account bank to make sure it has a good reputation and is legitimate.

Banks that offer merchant accounts make a portion on their profits through fees, some of which may be clearer than others.

Some fees a merchant account may be charged include:
  • Annual fees, charged yearly to keep the account open. In some cases, these fees may be waived if the merchant does a certain amount of business or keeps a minimum balance above a certain amount.
  • Authorization fees may be charged for each transaction.
  • Batch fees for processing payments. A batch is all the transactions for one day, and some accounts charge for processing the batch. A batch must be settled each day or higher fees will be imposed.
  • Minimum monthly fees may set, where the account will be charged a set minimum fee every month unless their transaction fees total a higher amount. 
  • Chargeback fees occur, for instance, if the merchant charges a customer incorrectly.
  • Early termination fees may exist if a customer has a contract with a merchant account bank for a certain amount of time and cancels before the contract is over.
You can expect to go through an application process to get a merchant account just as you might for setting up other kinds of bank accounts. You may need to provide proof that you are a legitimate business as well as have a credit check.

It is often easiest to get a merchant account as part of an eCommerce package, but it is still important to make sure that the account meets your needs and that you understand all the fees and they seem reasonable. Don't hesitate to ask questions about anything that seems unclear to you, and to shop around until you find an internet merchant account you feel comfortable with.
source: bestpaymentgateways

7 Personality Types of Designers

Design is a universal language. It transcends all cultural and national boundaries. It is diverse and ever-changing. Despite the fact that designs can be universally appreciated, the artists behind them are all unique and talented individuals.

What kind of designer are you? What is your philosophy? How do you contribute to the design community? Designers from different walks of life might have similar answers to these questions, and yet we are all different.

Some designers take it upon themselves to educate those who have not yet developed an appreciation for Web design and art. Some designers aim to improve the overall quality of design on the Internet.
And of course, some designers strive primarily to make a good living from their talents so that they can live a comfortable life.

Whatever your reason for being a designer, you are unique.
  • If you want to be a well-paid designer, please the client.
  • If you want to be an award-winning designer, please yourself.
  • If you want to be a great designer, please the audience.

Spotting the 7 Different Designers

Human beings constantly wear masks to hide their true feelings, thoughts and personality quirks. Designers wear masks of their own: one to attend to clients, another to handle a project’s details, another to collaborate with colleagues and yet another to communicate with family and friends. Human nature is to wear a different mask according to the role one is playing.

Despite these masks, our true personality still shines through. There are seven different personality types of designers. Which one best describes you?

1. The Pablo Picasso Designer

A perfectionist, the Pablo Picasso designer does not stand for any pixel to be out of place or unsightly. Egotistical, he does not care about other people’s opinions, and he belittles them for their ignorance and lack of appreciation of design and the arts.
Principled, the Pablo Picasso designer has a strong mind and set beliefs that cannot be swayed by any amount of money. His only concern is for the ingenuity of ideas.
A man out to change the world of design, he does not succumb to the whims of clients, and he believes it is their loss if they do not heed his advice. Believing he is a cut above the rest, he admits to only a few other designers in the world being his peers. The Pablo Picasso designer sees himself, above all else, as an artist.

2. The Albert Einstein Designer

A smart man with an excellent work ethic, the Albert Einstein designer has the motto “No pain, no gain.” Unafraid of ridicule, he dares to be different.
If at first you don’t succeed, try, try and try again. Failure is the mother of all success, and the Albert Einstein designer has a never-give-up attitude that pushes him to continually reach his goals despite countless failures.
The Albert Einstein designer continues to create his own designs, putting them to the test in various design competitions. He may not get it right each time or win every competition, but he believes his hard work will eventually pay off and that he will be recognized for his talents and effort.
His strong faith and his belief in himself enable him to patiently wait for the day when he is praised for his contributions. To him, the question is not if he will be successful, but rather when will he attain his goals and be successful.

3. The David Copperfield Designer

The David Copperfield designer is a great storyteller and illusionist. Capable of anything, regardless of how seemingly impossible it is, he conjures the best designs for his clients.
Convincing his clients to hire him and only him to do everything is a simple task. Given everything he delivers to clients, he does not come cheap. After all, he gives them everything they want, which amounts to a cleverly constructed illusion. Using his great storytelling skills, he leads clients to believe that he is the only person they need to achieve their goals.
Behind the scenes, the David Copperfield designer orchestrates his illusions down to the second. Appearances can be misleading; outsourcing his tasks, he packages the result as his own work.
The client doesn’t realize who are the hard-working talents who support him. He manages the project and delegates work to others but claims credit in the end.

4. The Captain Hook Designer

Image credit: South Florida Pirate
Why create when you can steal? The Captain Hook designer is cunning and sly. He scouts for the most innovative and successful designs and makes them his own—not by blatantly duplicating, mind you, but by cleverly working in his own ideas and inspiration.
Craftily avoiding outright plagiarism, the Captain Hook designer mashes up several successful ideas to create a fresh “new” concept.
Money being his sole interest, the Captain Hook designer tries to squeeze as much as he can out of his designs. By making small, simple changes to the color, font and layout, he passes off designs as new creations.
Unfazed by whether he loses some clients, he simply finds new ones who are unaware of his tricks. His lives by the pirate code that dictates, “A good designer copies, but a great designer steals.”

5. The Mahatma Gandhi Designer

Believing he is obliged to right wrongs, the Mahatma Gandhi designer takes it upon himself to effect change through peaceful means. He feels an obligation to improve Web design standards, regardless of any difficulties or opposition he might face. If he has to achieve his goal one client at a time, he will gladly do so.
Sharing his design philosophy with whomever will listen, the Mahatma Gandhi designer tries to persuade others—designers, clients and the general public alike—to help him make the design industry a better place.
A forward-thinking man who sets trends, he advocates for what he believes is necessary to improve and sustain the design industry. Willing to sacrifice himself for the benefit of other designers, the Mahatma Gandhi designer does whatever he can to improve the world of design through peaceful and lasting change.

6. The Bashful Dwarf Designer

Shunning the spotlight, the Bashful Dwarf designer always feels like he could have done a better job. When praised, he is quick to share the credit with colleagues. Insecure about his talents, he is content to work behind the scenes and let others take the honor.
The Bashful Dwarf designer doesn’t think much of fame or fortune, and he prefers not to show his name or face. Lack of confidence is the cause: he believes many other designers out there deserve more recognition.
As long as he makes enough money to put a roof over his head and not go hungry, he remains content with his lot in life.

7. The Ella of Frell Designer

The real Ella of Frell fell under a spell and couldn’t say no to anyone. Slightly different, the Ella of Frell designer actually has a choice and does not have to do everything she is told.
Instead, she chooses not to decline her clients’ every wish. Believing the customer is always right, she goes out of her way to please clients. Clients never find fault with her because she is ever willing to make whatever changes they ask for. “No” is not in her vocabulary.
Often ignoring her better judgment, the Ella of Frell designer subjugates her design sense to the clients’ will in order to avoid displeasing them. She is at the client’s beck and call, night and day.

We Are All Different

Each designer has their own personality type. Whatever yours is, the important thing is to be true to yourself and honorable. Any one of the seven types covered here could be an extreme version of you. or you may see a little of yourself in each.
The only constant is change, and perhaps we have all been more than one of these seven at different times in our lives. We are, after all, always growing and hopefully wiser.

source: webdesignerdepot

7 Personality Types of Developers

Developers and programmers are meticulous individuals, and developers sometimes stand out even among themselves.

We introduced you to 7 types of designers in our article 7 Personality Types of Designers Today. Developers have peculiar traits and habits of their own. This article looks at 7 types of developers today and their defining characteristics.

“The best programmers are not marginally better than merely good ones. They are an order of magnitude better, measured by whatever standard: conceptual creativity, speed, ingenuity of design or problem-solving ability.” —Randall E. Stross
Stereotyping is generally not good practice. But we’re not trying to squeeze individuals into categories. Rather, delineating these types can help you figure out where you stand and help you understand others.

1. The Self-Help Constructor

The self-help constructor does whatever it takes to get the job done with his experience and skill, no matter how limited.
For example, he may accomplish the job by finding open-source software and other free applications and tools. His best assets are his willingness to learn what he needs to complete the job and his ability to absorb the information like a sponge. He is resourceful, working with whatever is available to him.
Not every client will be impressed. Those who don’t know any better will praise his work, but the self-help constructor does not develop applications or plug-ins himself.
He merely exploits existing tools to construct something seemingly new for clients. With the wide range of sophisticated tools available today, this is becoming easier, but much less impressive.

2. The Experienced Old Man

He may not be the hippest guy in this energetic and creative field, but the experienced old man brings something valuable to the table: a wealth of knowledge and experience.
He may appear outdated, unable to keep up with the latest tools and technology, but he is wise and knows the basics like the back of his hand.
His battle stories of bygone days will fascinate and thrill. He may not be the fastest or most technologically savvy, but slow and steady wins the race, and he delivers the goods as he always has.
He proves that the old-school style of coding may be antique but isn’t extinct. He may not be your heaviest hitter, but in times of great need, you know you can count on the experienced old man to deliver.

3. The Hardcore Geek

Workaholic doesn’t begin to describe the hardcore geek, this martyr of developers. He goes beyond the call of duty to deliver the product and takes great pride in his work.
He spends his lunch hour at his desk working frantically to finish the project ahead of time. When he allows himself a little free time, he reads books, journal articles and the like to improve himself. Very much an introvert, he feels most comfortable in the world of code and programming jargon.
The more code the hardcore geek writes, the more content he feels. As great as he is with code, he makes for a much better worker bee than a leader.

4. The Scholarly Know-It-All

The scholarly know-it-all is a walking encyclopedia on programming. He can spend hours passionately discussing the history of a programming language or dissecting imperfect code.
He is the poet of the programming world, whose code is a work of art that can be appreciated and analyzed. Recursion is his middle name, and he tweaks every block of code to perfection, regardless of timelines or readability.
He sets high standards for himself, and his work sometimes complicates matters: a task that should take only an hour to complete takes him a few months. Mind you, he’s not incompetent. On the contrary, he is highly capable; but he makes work for himself by creating new tools and libraries and even reconstructing entirely new systems, all to meet his own standards.
He feels obliged to impart his knowledge to others and share his passion for the theory and technical intricacies of coding and programming. He tries his best to explain to clients why using state-of-the-art technology is so important. Every project is his precious child.
The scholarly know-it-all is great to have on your team, but be sure you can get him to spend his energy on the important details, rather than waste time satisfying his urge to delve into every nook and cranny.

5. The Ninja

The ninja is a man of few words and keeps to himself. While similar to the hardcore geek, he has more in his life than code and work.
He is an enigma: not outright friendly or forthcoming, but he works surprisingly well on a team. Everyone notices his tireless nature but can’t figure out how he does everything so well and so quickly. There is much evidence of his work but little evidence that he did it. “Show don’t tell” describes his modus operandi best.
Never outwardly frazzled (try as you might to throw him off), he resolves problems quickly and efficiently, regardless of time or place. The ninja’s stealth sends chills down your spine, and he leaves you wondering how he managed to accomplish his feat.
A lone ranger, he gets the job done regardless of his status on the team or his relationship with other members. His motto? Don’t have doubts; just resolve the problem quickly and efficiently. This no-nonsense attitude makes him an absolute joy to work with.

6. The Clever Ambassador

The clever ambassador is the face of the team. He is outspoken and the unofficial project manager. His knowledge of software development, project workflows and code theory is adequate, but he does very little of the actual programming or work.
He is quick to pick up leads and great at communicating with clients. He is the consummate ring-master, able to please both clients (the ferocious lions) and team members (the elephants that could easily trample him if they wanted).
In his supervisory role, the clever ambassador ensures that every project meets the requirements and satisfies the client. He is the go-between, representing the development team for the client and balancing client satisfaction with practicality.
Having to walk this tight rope, he often feels that he should be better compensated, despite never doing any heavy lifting (i.e. coding). He is the model who sits pretty in front of the camera selling the product, while the rest of the team (make-up artists, hair stylists, etc.) works behind the scenes, receiving lower payment for what amounts to the same work.

7. The Half-Cup Speedster

The half-cup speedster takes on multiple projects at once. He works much faster than most, but his amazing quantity is tarnished by its quality: his speed results from cutting corners and hacking core.
He feels that optimizing and checking code takes too long. His code is messy because he does not follow best practices and never makes use of object-oriented programming (OOP).
Amazingly, despite his code looking like a minefield, the product works just as intended. Cutting corners is generally not good practice, but in an impossible crunch, the half-cup speedster might be the person for the job.
Unfortunately, much like the handwriting of physicians, his code is practically indecipherable. Should someone need to fix a problem that surfaces later, they will surely encounter difficulties. You can’t fix what you can’t read or understand.

source: webdesignerdepot

How to Test Banking Applications

Banking applications are considered to be one of the most complex applications in today’s software development and testing industry. What makes Banking application so complex? What approach should be followed in order to test the complex workflows involved? In this article we will be highlighting different stages and techniques involved in testing Banking applications.

The characteristics of a Banking application are as follows:
  • Multi tier functionality to support thousands of concurrent user sessions
  • Large scale Integration , typically a banking application integrates with numerous other applications such as Bill Pay utility and Trading accounts
  • Complex Business workflows
  • Real Time and Batch processing
  • High rate of Transactions per seconds
  • Secure Transactions
  • Robust Reporting section to keep track of day to day transactions
  • Strong Auditing to troubleshoot customer issues
  • Massive storage system
  • Disaster Management.
The above listed ten points are the most important characteristics of a Banking application.
Banking applications have multiple tiers involved in performing an operation. For Example, a banking application may have:
  1. Web Server to interact with end users via Browser
  2. Middle Tier to validate the input and output for web server
  3. Data Base to store data and procedures
  4. Transaction Processor which could be a large capacity Mainframe or any other Legacy system to carry out Trillions of transactions per second.
If we talk about testing banking applications it requires an end to end testing methodology involving multiple software testing techniques to ensure:
  • Total  coverage of all banking workflows and Business Requirements
  • Functional aspect of the application
  • Security aspect of the application
  • Data Integrity
  • Concurrency
  • User Experience
Typical stages involved in testing Banking Applications are as follows :

1) Requirement Gathering:

Requirement gathering phase involves documentation of requirements either as Functional Specifications or Use Cases. Requirements are gathered as per customer needs and documented by Banking Experts or Business Analyst. To write requirements on more than one subject experts are involved as banking itself has multiple sub domains and one full fledge banking application will be the integration of all. For Example: A banking application may have separate modules for Transfers, Credit Cards, Reports, Loan Accounts, Bill Payments, Trading Etc.

2) Requirement Review:

The deliverable of Requirement Gathering is reviewed by all the stakeholders such as QA Engineers, Development leads and Peer Business Analysts. They cross check that neither existing business workflows nor new workflows are violated.

3) Business Scenario Preparations:

In this stage QA Engineers derive Business Scenarios from the requirement documents (Functions Specs or Use Cases); Business Scenarios are derived in such a way that all Business Requirements are covered. Business Scenarios are high level scenarios without any detailed steps, further these Business Scenarios are reviewed by Business Analyst to ensure all of Business Requirements are met and its easier for BAs to review high level scenarios than reviewing low level detailed Test Cases.

4) Functional Testing:

In this stage functional testing is performed and the usual software testing activities are performed such as:

Test Case Preparation:
In this stage Test Cases are derived from Business Scenarios, one Business Scenario leads to several positive test cases and negative test cases. Generally tools used during this stage are Microsoft Excel, Test Director or Quality Center.

Test Case Review:
Reviews by peer QA Engineers

Test Case Execution:
Test Case Execution could be either manual or automatic involving tools like QC, QTP or any other.

5) Database Testing:

Banking Application involves complex transaction which are performed both at UI level and Database level, Therefore Database testing is as important as functional testing. Database in itself is an entirely separate layer hence it is carried out by database specialists and it uses techniques like
  •     Data loading
  •     Database Migration
  •     Testing DB Schema and Data types
  •     Rules Testing
  •     Testing Stored Procedures and Functions
  •     Testing Triggers
  •     Data Integrity
6) Security Testing:

Security Testing is usually the last stage in the testing cycle as completing functional and non functional are entry criteria to commence Security testing. Security testing is one of the major stages in the entire Application testing cycle as this stage ensures that application complies with Federal and Industry standards. Security testing cycle makes sure the application does not have any web vulnerability which may expose sensitive data to an intruder or an attacker and complies with standards like OWASP.

In this stage the major task involves in the whole application scan which is carried out using tools like IBM Appscan or HP WebInspect (2 Most popular tools).
Once the Scan is complete the Scan Report is published out of which False Positives are filtered out and rest of the vulnerability are reported to Development team for fixing depending on the Severity.

Other Manual tools for Security Testing used are: Paros Proxy, Http Watch, Burp Suite, Fortify tools Etc.

Apart from the above stages there might be different stages involved like Integration Testing and Performance Testing.

In today’s scenario majority of Banking Projects are using: Agile/Scrum, RUP and Continuous Integration methodologies, and Tools packages like Microsoft’s VSTS and Rational Tools.
As we mentioned RUP above, RUP stands for Rational Unified Process, which is an iterative software development methodology introduced by IBM which comprises of four phases in which development and testing activities are carried out.

Four phases are:
i) Inception
ii) Collaboration
iii) Construction and
iv) Transition
RUP widely involves IBM Rational tools.