HiLCoE
School of Computer Science and Technology
Unix Administration
Final Project
Ethiopian Commodity Exchange (ECX)
Name: Ammar Jemal
Section: A
ID: FP7866
Submitted to: Ashenafi Kassahun
Due Date: June 12, 2022
Ethiopia Commodity Exchange (ECX)
[Link]
The Ethiopia Commodity Exchange (ECX) is an Ethiopian commodity exchange that was
found in April 2008. The ECX's declared goal was to "guarantee the establishment of an
effective contemporary trading system" that would "defend the rights and advantages
of sellers, purchasers, intermediaries, and the general public," according to
Proclamation 2007-550.
ECX offers an integrated warehouse system from the receipt of commodities on the
basis of industry accepted grades and standards for each traded commodity by type to
the ultimate delivery. Commodities are deposited in warehouses operated by ECX in
major surplus regions of the country. At the ECX warehouse, commodities are sampled,
weighed and graded using state-of-the-art technology grading and weighing equipment.
ECX warehouses issue Electronic Goods Received Note and provide the depositor or
his/her representative with a signed print copy. The Electronic Goods Received Notes
are not negotiable, transferable or represent legal title to the deposited commodity. The
depositor has to get Electronic Warehouse Receipt issued by the ECX Central Depository
in order to establish legal title to the deposited commodity. The deposited goods are
held according to worldwide inventory management standards, which include First-In-
First-Out principles, rotation, and strict environmental control. The ECX Inventory
Management system ensures that the commodity's quality and quantity are maintained
during the storage period. Furthermore, ECX warehouses are fully insured to protect
deposits against loss and damage.
ECX warehouses provide the following services:
• Sampling, grading, weighing, and certifying grain, pulses, oil seeds, and coffee
arriving at each warehouse using ECX-supplied equipment in accordance with
ECX standards.
• Electronic Goods Weighing, receiving, and issue incoming and outgoing
commodity recording system, as well as daily stock position reports
• Proper handling of the commodity at the warehouse (store layout, stacking, bin
numbers, inventory management)
• Reporting system and formats for up-to-date information exchange between ECX
and area warehouses
• Keep the received things in good condition.
• Grain, oil seed, and pulses commodities sold in standardized PP bags
A system administrator's responsibilities in this organization would include
Providing technical support for the entire Server and Storage Area Network (SAN)
at the HEAD OFFICE, Disaster Recovery (DR) site, HEAD OFFICE Trading Center,
and Regional Trading Centers.
ECX Server and Storage Area Network administration and oversight.
Assist the Manager IT Infrastructure & Support in maintaining the Exchange's
System and SAN infrastructure
Maximize ECX's System services uptime via corporate System and SAN
infrastructure maintenance; and provide a quarterly report.
2. Plans
Produce/Update technical architectural paper every 3 months
Monitor and manage SAN storage
Maintain and improve the performance of important ECX core business
applications on administrate servers.
Administer Gateway security solutions to coordinate the Exchange's
information system administration and storage architecture, ensuring that all
externally accessed resources, such as the Trading site, Email, and others are
secure and working effectively.
Ensure that all ECX employees are authorized to access server resources by
ensuring that they are authenticated.
As assigned by the immediate supervisor, participate in System and SAN
infrastructure initiatives from conception to completion.
Use zoning, masking, and other associated technologies to ensure that the
storage area network is adequately protected. With another IT unit,
participates in system/project testing, deployment, and certification;
Participate in technical bid preparation and evaluations for IT procurement
Design installation and maintenance of servers and storage
Configure storage devices, services, directories, and peripherals using
established standards and requirements
3. Policies
3.1 Policies for General Users
3.1.1 Using CDs/ Flash Drives
• Storage devices should only be used with the permission of the system
administrator computer center, and they should be examined before
being utilized.
• Office systems should not be utilized with unofficial floppies, CDs, or flash
drives.
• If data is to be transmitted from a device to a system, storage devices
should be write-protected.
3.1.2 Password
• Keep the password-protected system screen saver turned on.
• Don't give out or reveal your password.
• Network access, screen saver, and other passwords should not be easily
recognizable by the user.
A strong password should be as lengthy as feasible, contain mixed-case
letters, numerals, punctuation marks, and not be based on any personal
information or dictionary term in any language.
• Don't use the same password more than once.
• Change your password on a frequent basis (1 week).
3.1.3 Backup
• Backups should be kept on a regular basis on the department's central
server or on storage media, as per department policy.
• Keep a copy of the server configuration file on paper.
• Store DATs or other removable media away from the computer in a secure
area.
• Always make a backup of your data before leaving your computer.
• Offsite backup should be employed for sensitive and significant data.
3.1.4 Physical Safety of System
• Keep the system safe from illegal access, loss, or damage by locking the
door when you're not in the office.
• Store portable equipment safely.
• Place monitors and printers in such a way that sensitive data is not visible
to others.
• Store storage media in a safe location.
• Seek guidance on equipment disposal.
• Notify the System Administrator/in charge computer center if any data or
accessories are lost.
• Protect the system and critical data from intruders.
• Obtain permission before moving equipment off-site.
• Use caution when transporting equipment (Read instruction on moving
equipment).
• Install a UPS system with enough battery backups to prevent data loss or
corruption in the event of a power outage.
• Before leaving the workplace, make sure the system is properly turned
down.
• If you're getting out of your seat, log off the system.
• Never disconnect the connections while your computer is turned on, since
this might result in an electrical short circuit.
• If the system prompts you to perform scandisk at startup, do not stop it.
• Always place the mouse on the mouse pad.
• Use caution when using the keyboard and mouse.
• Do not open the hardware enclosure.
• Check that the cords connected to your system have some slack.
3.1.5 Computer Files
• The file system is responsible for all file-level security. For the server, only
the most secure file system should be used. Then, for individual files,
folders, and drives, user permissions should be established.
• If there are any default shares, they should be eliminated.
• On the server, only necessary file and object sharing should be enabled.
• Never open or download attachments from an unknown email address.
• Always maintain files in the computer in a logical order for simple access.
Create new folders and subfolders as needed.
• Don't make unnecessary files and directories.
• System files and libraries should not be accessed since they can cause the
system to malfunction.
When transferring data, if asked "Would you like to replace the existing
file" be sure it is going to the destination, before clicking "yes".
3.2 Departmental Policies
• A system administrator or person in charge of the computer center should
be assigned to the department.
• Departmental employees should be familiar with the government's
security rules.
• If necessary, each department should have its own codified security
policies, standards, and practices.
• The administrator should be able to follow clearly established system
security protocols.
• Department employees should have adequate power to carry out IT
security-related tasks and procedures.
• In the event that the regular System Administrator is unavailable,
competent employees should be ready to cover IT security-related
activities.
• The department should have a procedure in place for dealing with events
or compromises.
3.3 Policy for System Administrator
• All acquisitions of new systems and hardware, as well as new components
for existing systems, must adhere to Information Security and other
organization regulations, as well as government-set technical
requirements.
• All access to systems must be approved by the system's owner, and such
access, together with the relevant access rights (or privileges), must be
documented in an Access Control List.
• Equipment must always be properly protected, especially when left
unattended.
• To prevent unwanted access to network resources, access to them must
be rigorously managed. Unless specifically permitted, access to all
computing and information systems, as well as peripherals, is prohibited.
• Only individuals who are permitted to execute systems administration /
management activities should have access to operating system
commands. Even so, such access must be managed under dual control,
with top management clearance required.
• Best practice guidelines should be followed when choosing passwords,
using them, and managing them as a main way of controlling access to
systems. Passwords, in particular, must not be shared with anyone else for
any reason.
• Strong identification and authentication mechanisms will be used to
regulate physical access to high-security sites. Staff having access to such
places should be informed about the possible security hazards.
• Access restrictions should be configured at a level that minimizes
information security risks while allowing the organization's business
activities to proceed without excessive delay.
• Access must be documented and monitored in order to detect potential
system or information misuse.
• Information and document access must be strictly regulated, with only
authorized personnel having access to sensitive information.
• For extremely sensitive information or high-risk systems, access controls
should be configured in line with the value and categorization of the
information assets to be secured.
• Strong identification, authentication, and encryption mechanisms must be
used in remote access control processes to provide acceptable security.
4. Strategies
• Personnel should be educated on the importance of security.
• Viruses, spyware, and other malicious software can pose a threat to data,
computers, and networks.
• Use a firewall to secure internet connection.
• Download and install software updates for operating systems and apps as
they become available.
• Make backup copies of important company data and information.
• Keep PCs and network components under physical control.
• Protect Wi-Fi networks.
• Each employee must have their own username and password.
• Restrict employee access to data and information, as well as the ability to
install software.
• Make it a habit to change passwords on a regular basis.