6.1 User Support
Systems analysts often act as internal consultants. User support includes training, help desks, troubleshooting, technical guidance, knowledge bases, and support for new versions or changes.
A help desk is a centralized resource that helps users use system resources effectively, answers technical and operational questions, and improves productivity.
6.2 Maintenance Tasks
| Type | Purpose |
| Corrective | Fix system errors. |
| Adaptive | Add capabilities or respond to new business/system requirements. |
| Perfective | Improve efficiency, performance, or maintainability. |
| Preventive | Reduce the likelihood of future failures. |
6.3-6.4 Maintenance and Performance Management
Maintenance requests are evaluated, prioritized, scheduled, investigated, analyzed, designed, developed, tested, and implemented. Change management controls versions, documentation changes, and release timing.
Performance measures include response time, bandwidth, throughput, and turnaround time. Capacity management uses these measures to forecast future support needs.
6.5-6.6 Security Levels
A security policy defines how assets are protected and how attacks are managed. Risk management identifies, analyzes, anticipates, and reduces risks to an acceptable level.
| Level | Focus |
| Physical | Protect rooms, servers, desktops, and equipment. |
| Network | Protect communications, including wireless links. |
| Application | Use hardening, permissions, input validation, patches, and logs. |
| File | Control file permissions and encryption. |
| User | Manage identities, passwords, awareness, and social engineering risk. |
| Procedural | Use managerial controls and secure operating procedures. |
6.7-6.9 Backup, Recovery and Retirement
Backup and recovery decisions include media, schedules, retention periods, RAID, cloud backup, and business continuity. Systems eventually reach the end of useful life when maintenance or operating costs rise, new technology becomes available, or the system cannot meet new requirements.
Future IT professionals need technical skill, critical thinking, credentials, and awareness of security, environmental, economic, political, and social pressures.
6.1 User Support and Help Desks
After implementation, a systems analyst often acts as an internal consultant. The guide notes that well-designed systems can require even more support because users discover features, ask for improvements, and need help applying the system to real work. Support can be in-house or outsourced, but quality must be actively monitored.
| Help desk objective | Practical meaning |
| Show users how to use resources effectively. | Help with queries, reports, advanced features, intranet/internet access, and everyday operation. |
| Answer technical or operational questions. | Resolve network issues, passwords, licensing, upgrades, hardware costs, and software behavior. |
| Improve productivity. | Build a knowledge base, identify repeated problems, support training, and guide users toward better system use. |
Exam trap: outsourced support still belongs to management. Saving money does not help if long waits, weak online tools, or poor staff performance reduce customer satisfaction.
6.2-6.3 Maintenance Types and Management
Maintenance is a mini-version of the SDLC. A maintenance request is submitted, evaluated, prioritized, scheduled, investigated, analyzed, designed, developed, tested, documented, and implemented. The maintenance team often includes analysts and programmers; in larger IT departments, maintenance and new development can be separate teams.
| Maintenance term | Meaning | Example |
| Corrective | Fixes errors. | Correcting a payroll calculation bug. |
| Adaptive | Adds capabilities or responds to new requirements. | Adding a new tax field after legislation changes. |
| Perfective | Improves efficiency, performance, or maintainability. | Optimizing a slow report or simplifying support procedures. |
| Preventive | Reduces the chance of future problems. | Refactoring fragile code, archiving old data, or updating security controls before failure. |
| Management technique | Purpose |
| Maintenance requests | Capture the need, source, affected system, urgency, and expected benefit. |
| Priorities | Decide what gets handled first based on urgency, value, risk, and resources. |
| Configuration management | Controls maintenance requests, system versions, and documentation changes. |
| Maintenance releases | Group approved changes into planned releases. |
| Version control | Tracks system versions and changes so teams know what is current. |
| Baselines | Formal reference points used to measure and control system evolution. |
6.4-6.6 Performance and Security
System performance management covers fault management, workload measurement, and capacity planning. The guide's performance terms are useful in short questions because they look similar but measure different things.
| Measure | Meaning |
| Fault management | Detect, isolate, diagnose, and correct system problems. |
| Response time | How long the system takes to respond to a user request. |
| Bandwidth | Network capacity for transmitting data. |
| Throughput | Amount of work processed in a given time. |
| Turnaround time | Total time from submitting work to receiving the result. |
| Capacity planning | Forecasting future processing, storage, network, and support needs. |
Security begins with policy and risk management. The guide frames risk management as identifying, analyzing, anticipating, and reducing risks to an acceptable level. Security should be evaluated across physical, network, application, file, user, and procedural levels.
| Security level | Examples of controls |
| Physical | Locks, secure rooms, access cards, fire protection, climate control, and equipment protection. |
| Network | Firewalls, monitoring, wireless protection, secure protocols, and intrusion prevention. |
| Application | Input validation, patches, hardening, permissions, and logging. |
| File | Permissions, encryption, backup, and access logs. |
| User | Authentication, password discipline, awareness, and social engineering prevention. |
| Procedural | Management policies, operating procedures, audits, and separation of duties. |
Worked Example: Recovering and Retiring an Ageing System
Scenario: an old inventory system has rising corrective maintenance, slow reports, repeated outages, and users asking for web access. A power failure damages a server during peak trading.
- Business continuity: use the disaster recovery plan to identify roles, emergency actions, damaged equipment, recovery sequence, and communication responsibilities.
- Backup and recovery: restore data from approved backups, follow retention rules, verify the latest clean copy, and test restored data before normal operations resume.
- Performance review: measure response time, throughput, turnaround time, workload, and capacity to see whether the system can still support business needs.
- Maintenance classification: fix the outage as corrective maintenance, improve slow reports as perfective maintenance, add web access as adaptive maintenance, and reduce future failure through preventive work.
- Retirement decision: rising maintenance, expensive changes, user demands, new technology, poor support for new requirements, and declining value indicate that replacement planning should begin.
Strong exam answer: keep recovery and retirement separate. Recovery restores operations after disruption; retirement is the planned end of a system's useful life.
6.9 Future Challenges, IT Careers and Cyberethics
The closing section looks beyond day-to-day maintenance. IT professionals need technical knowledge, strategic planning ability, credentials or certifications where useful, and critical thinking. The guide also emphasizes cyberethics: security, privacy, fair use of systems, and responsible professional judgment become more important as systems connect more people, suppliers, and data.
| Future-facing area | Revision meaning |
| Trends and predictions | IT work changes with security, operations, outsourcing, new technologies, and supplier expectations. |
| Strategic planning | IT professionals must connect technology decisions to business goals and long-term direction. |
| Credentials and certification | Certifications can demonstrate current technical knowledge in a changing field. |
| Critical thinking | Professionals must analyze problems, evidence, risks, alternatives, and consequences. |
| Cyberethics | Responsible behavior around access, privacy, security, information ownership, and professional conduct. |
Chapter 6 Glossary: Support, Security and Maintenance
user support- Training, guidance, troubleshooting, and operational help provided after a system is implemented.
help desk- Central support point where users ask questions, report issues, request maintenance, and receive technical guidance.
knowledge base- Stored support information built from recurring problems, solutions, and user questions.
corrective maintenance- Maintenance that fixes errors.
adaptive maintenance- Maintenance that adds capability or responds to new requirements.
perfective maintenance- Maintenance that improves efficiency, performance, or maintainability.
preventive maintenance- Maintenance that reduces the likelihood of future failure.
configuration management- Control of maintenance requests, system versions, releases, and documentation changes.
version control- Tracking and managing different versions of software or system components.
baseline- A formal reference point for measuring and controlling system changes.
response time- Time between a user request and the system's response.
bandwidth- Data transmission capacity of a communication channel.
throughput- Amount of processing completed in a given time.
turnaround time- Total time from submitting a job/request to receiving the completed result.
capacity planning- Forecasting resources needed for future workload, storage, network, and support demands.
security policy- Management statement defining how information assets are protected.
risk management- Identifying, analyzing, anticipating, and reducing risks to acceptable levels.
authentication- Confirming a user's identity before allowing access.
authorization- Controlling what an authenticated user is allowed to access or do.
backup policy- Rules for what is backed up, how often, where it is stored, and how long it is retained.
retention period- The required length of time backup copies or records must be kept.
RAID- Redundant array of independent disks; combines disks for improved capacity, performance, or reliability.
disaster recovery plan- Plan for restoring operations after a disaster, including roles, actions, equipment, data recovery, and testing.
business continuity- Planning that keeps essential business functions operating during and after disruption.
system retirement- The planned removal or replacement of a system that no longer supports user or business needs effectively.
cyberethics- Responsible and ethical behavior in the use, protection, access, and management of information systems.