3.8 Article

Organization Security Metrics: Can Organizations Protect Themselves?

Journal

INFORMATION SECURITY JOURNAL
Volume 17, Issue 5-6, Pages 228-242

Publisher

TAYLOR & FRANCIS INC
DOI: 10.1080/19393550802541200

Keywords

information security and risk management; operations security; physical (environmental) security; risk matrix; security monitoring; security working group; threat assessment

Ask authors/readers for more resources

Organizations normally do not possess a way to communicate those needs back to the rest of an organization. This paper demonstrates that organizations are vigilant to activity within their environment, so this research project will focus on process improvement to better organizations through internal processes. Prior to this project, Company X was unable to communicate and address threats to their organization. Prior to this project, each employee was not trained on security. However, each employee understood the norms and values of company processes on an individual level. Each employee was able to contribute details of security issues as they perceived them to make a comprehensive security model. This Security Working Group (SWG) project describes the steps necessary to create a self-educating, self-perpetuating process that spurns co-generative learning among an entire organization. Security training prepared each employee to be more attentive to risks to potential security issues. The result of this research proves that employees can detect threats in an organization with relatively little training.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

3.8
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available