Organization Security Metrics: Can Organizations Protect Themselves?

  • Authors:
  • Thomas L. Wheeler

  • Affiliations:
  • Colorado Technical University, Colorado Springs, CO, USA

  • Venue:
  • Information Security Journal: A Global Perspective
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Organizations normally do not possess a way to communicate those needs back to the rest of an organization. This paper demonstrates that organizations are vigilant to activity within their environment, so this research project will focus on process improvement to better organizations through internal processes. Prior to this project, Company X was unable to communicate and address threats to their organization. Prior to this project, each employee was not trained on security. However, each employee understood the norms and values of company processes on an individual level. Each employee was able to contribute details of security issues as they perceived them to make a comprehensive security model. This Security Working Group (SWG) project describes the steps necessary to create a self-educating, self-perpetuating process that spurns co-generative learning among an entire organization. Security training prepared each employee to be more attentive to risks to potential security issues. The result of this research proves that employees can detect threats in an organization with relatively little training.