• Open Daily: 10am - 10pm
    Alley-side Pickup: 10am - 7pm

    3038 Hennepin Ave Minneapolis, MN
    612-822-4611

Open Daily: 10am - 10pm | Alley-side Pickup: 10am - 7pm
3038 Hennepin Ave Minneapolis, MN
612-822-4611
Developing a Framework for Evaluating Organizational Information Assurance Metrics Programs

Developing a Framework for Evaluating Organizational Information Assurance Metrics Programs

Paperback

ManagementGeneral EducationComputer Security

ISBN10: 1249401607
ISBN13: 9781249401605
Publisher: Biblioscholar
Published: Sep 17 2012
Pages: 218
Weight: 0.69
Height: 0.46 Width: 6.14 Depth: 9.21
Language: English
The push to secure organizational information has brought about the need to develop better metrics for understanding the state of the organization's security capability. This thesis utilizes case studies of information security metrics programs within Department of Defense organizations, the United States Air Force (USAF), and the National Aeronautics and Space Administration's (NASA's) Jet Propulsion Lab to discover how these organizations make decisions about how the measurement program is designed, how information is collected and disseminated, and how the collected information supports decision making. This research finds that both the DOD and USAF have highly complex information security programs that are primarily focused on determining the return for security investments, meeting budget constraints, and achieving mission objectives while NASA's Jet Propulsion Lab seeks to improve security processes related to compliance. While the analytical techniques were similar in all of the cases, the DOD and USAF use communication processes still based mostly on manual data calls and communications. In contrast, NASA's JPL information security metrics program employs a more automated approach for information collection and dissemination.

Also from

Air Force Institute of Technology

Also in

General Education