Take time to read your paper against the rubric. I have highlighted yellow important rows which you should target.
Running head: Cyber Security Competition Framework
Cyber Security Competition Framework 2
Cyber Security Competition Framework
Divya Valaboju
IST 8101- Field Experience/Internship
9/18/2016
Contents Cyber Security Competition Framework 3 Methodology 5 Action Research 5 History of Action Research 5 The steps that have been suggested for action research include: 7 The planning phase 7 The action phase 7 The observation phase 7 The reflection phase 7 References 9
Cyber Security Competition Framework
Innovation is the main issue that drives economic growth as well as job creation. Cyber security encompasses the protection of an organization’s intellectual property as well as business information that is in digital form of different types of abuse and misuse, which is a growing management issue. The desire to protect intellectual property through trademarks, patents as well as copyrights is vital to the objective of ensuring that an organization can pursue innovation. Thus the ability by an organization top protects their information technology platform from the diverse security threats that could hamper their success is by implementing an effective cyber security competition platform (Andrijcic & Horowitz, 2006). The competition from other players in the industry is the main issue that leads to the increase in the threat of there being theft of an organization productivity base.
Through the framework, it will be possible for an organization to possess risk-based compilation guidelines that are going to make it possible for them to identify, implement and consequently improve their cyber security practices (Tisdale, 2015). Although the framework does not introduce new concept or standards, it serves to leverage as well as integrate diverse cyber security practices that have been developed by the organization as the international standardization organization and the NIST. The framework refers to the compilation of the practices as the “CORE” which encompasses five continuous as well as concurrent functions (Von Solms & Van Niekerk, 2013). These promote the identification, protection, detection, response as well as recovery, which present a strategic view of an organization’s lifecycle in the management of their cyber security risk.
The threat that is posed to business and their operations due to the diverse cyber security threats has seen an increase in the number as well as the form of attacks. The threats that these businesses are also facing change with issues as disgruntled employees releasing sensitive company information taking an organization’s intellectual property to the competitors as well as taking part in online fraud being on the increase. Other organizations have had to ensure that the losses they have suffered as a result of the cyber security threats and breach to their technology infrastructure do not become public (Tisdale, 2015). Other business organizations have been compelled to pay ransom to the cyber criminals as well as to get a description of the vulnerabilities that an attack has exposed.
There is the general trend whereby value is migrating online, and that digital data is becoming increasingly pervasive. The implication of this drift is that institutions are experiencing more online attacks. There is also an increase in the number of people who are accessing the corporate networks via mobile devices they use in their personal lives which increase cyber security threats.
The plan, in this case, is to implement a cyber security competition framework that addresses all the threats that an organization faces. There will be the implementation of a framework to be addressed at the most senior levels of the organization. Addressing these threats will revolve around the protection of the organization’s most vital business assets instead of merely focusing on the technological vulnerabilities as the use of the multilayer programs for the classification of corporate data (Andrijcic & Horowitz, 2006). Further, a framework will be targeted at the protection of an organization’s data instead of on the perimeter through the reorientation of an organization’s security architecture from the devices as well as locations to roles and data. There will be an additional introduction of a paradigm that refreshes the cube security strategies employed by an organization and ensure that they deal with the fast-evolving business needs as well as threats.
Methodology
Action research encompasses the systematic collection of information whose core rationale is the contribution to social change. It entails the learning that is realized through doing, and in this assertion, a group of people identifies a certain problem within their setting or organization, implement strategies that are meant to resolve the problem. Further, the group that is involved in the implementation of the solution evaluates how successful their efforts have been and if they have not been satisfied, they try the implementation again. The issues addressed above lead to the definition of action research, which is believed to revolve around the desire to contribute to practical concerns of the individuals in the problematic situation and at the same time promote the advancement of the goals of science (Stringer, 2007). It is thus clear that there is an element of dual commitment depicted in the use of action research in studying a system as well as collaborating with the members of that system to change the situation they find to be problematic.
Action Research
History of Action Research
The origin of action research is connected with Kurt Lewin. Lewin proposed that action research falls under the classification of research that is needed for social practice and is best attributed as one meant to social management or engineering. The approach that is proposed by Lewin is that of steps, with each step encompassing a circle of planning, action along with fact findings concerning the implication of the action. In the mid-1940s, Lewin developed a theory of action research, saying that it is a proceeding spiral of steps, with each of the steps encompassing the planning, action as well as evaluation of the result of the action (Collis & Hussey, 2003). According to Lewin, the initial step of action research encompasses the careful assessment of the idea in light of the available means. If there is the success in this planning period, there is the emergence of two items that encompass the overall plan on how to realize the objective and the second attribute being the decision relating to the first step.
In the 1960s, action research faced a decline in its effectiveness owing to the association that it had with radical political activism. There was the development of doubts relating to the rigor of AR as well as the training that had been acquired by the individuals using it (Brydon-Miller, Greenwood & Maguire, 2003). It, however, is evident that AR has attained considerable foothold within the areas of community-based as well as participatory AR as well as a type of practice that is oriented towards the improvement of the educative encounters.
Action research has a wide assortment of uses in the scientific field mainly about the advancements that promote the realization of the diverse objectives stipulated in the scientific study. In this assessment, AR is vital to the development of reflective scientific practitioners who are instrumental to the progress of the scientific field, when individual scientists commit themselves to fostering continuous growth and development of the scientific field (Collis & Hussey, 2003). When each of the research is assessed through the empirical investigation into the issues that are causing, the challenges realized in the field and helped in the development of solutions. Further, the use of action research in the scientific investigations aids in the development of a professional culture that promotes their focus in mapping out the solution to the challenges in the field. It follows that the fact that all scientist are committed to realizing the same objective contributes to the sharing of a similar vision of a culture of commitment to coming with solutions to the IT challenges.
The steps that have been suggested for action research include:
The planning phase
The initial AR phase is the planning and encompasses the assessment of the solution and implementing a plan of how the main issues identified are going to be resolved. The main issue in this phase is the development of a plan and procedures that are going to be included in developing the solution.
The action phase
The second phase of AR is the action phase and will revolve around the introduction of the procedures and solutions that have been established in the planning phase. The action shall include the methodical execution of all the steps as enumerated in the planning phase.
The observation phase
The third AR phase is the observation phase and includes the evaluation of the execution of the solutions and procedures. The main reason behind this phase is the assessment of whether the solutions that are being implemented are addressed the issue under focus and making the necessary changes.
The reflection phase
The last phase of AR is a reflection of what was successful in the execution of the solution and what was not successful. There additionally is the assessment of the elements that could be improved during the subsequent execution to ensure that the solutions are successful.
Diagram 1: Action research cycle source (Collis & Hussey, 2003).
The implementation of the cyber security competition program through the employment of action research offers the assurance that the solutions framework is going to be a success as it will be a product of iterative research, ensuring that solutions are better after every cycle.
References
Andrijcic, E., & Horowitz, B. (2006). A Macro‐Economic Framework for Evaluation of Cyber Security Risks Related to Protection of Intellectual Property. Risk Analysis, 26(4), 907-923.
Brydon-Miller, M., Greenwood, D., & Maguire, P. (2003). Why action research?. Action research, 1(1), 9-28.
Collis, J. & Hussey, R. (2003). “Business Research. A Practical Guide for Undergraduate and Graduate Students” 2nd edition, Palgrave Macmillan
Stringer, E. T. (2007). Action Research: A handbook for practitioners 3e, Newbury Park, ca.: Sage. 304 pages. Sets community-based action research in context and develops a model. Chapters on information gathering, interpretation, resolving issues; legitimacy etc. See, also Stringer’s (2003) Action Research in Education, Prentice Hall.
Tisdale, S. M. (2015). Cybersecurity: Challenges From A Systems, Complexity, Knowledge Management And Business Intelligence Perspective. Issues in Information Systems, 16(3).
Von Solms, R., & Van Niekerk, J. (2013). From information security to cyber security. computers & security, 38, 97-102.