Research paper

profileHomeworkSM
ORGANIZATIONALSECURITY.docx

1

Running Header: ORGANIZATIONAL SECURITY

4

ORGANIZATIONAL SECURITY

ORGANIZATIONAL SECURITY

Student’s Name

Tutor’s Name

Course Title

Date

Introduction

The security of the world is currently increasing in a simultaneous manner. Many countries all around the world try harder to cater to its citizens despite having huge numbers of citizens. Business is the core factor that gives out people a way to a better life. Organizations have emerged and that they all try as much as possible to be successful, despite having many challenges in the market square. The exchange of goods and services is the main core issue that led to the emergence of business globally. In general terms there are different products that are produced all around the world, researchers have proven that for the business to be rated in a successful level the security status of the business must also be considered. Security generally protects the product and services of the organization. It is very important to keep the security of the of the company high, this is based on the fact that all the product and services produced by the company will be secured from competitors and the ill motive individuals who might want to bring down the business. Employers and employees are the ones who are responsible for keeping the security in an organization to be at a high level.

Background information

In today’s world, everything that is tangible is always stored in a digital form. When the business lacks a form to defend its digital assets generally the business is lost, thus the potential loss of the business will grow bigger every day. (Gupta, Rees, Chaturvedi & Chi, 2006) The need of having legal security in the organization literally existed ever since the introduction of the first computer in the business environment. Recently the paradigm has greatly shifted over the years, nevertheless from the client-server systems and terminal server mainframe systems.

Despite the security system being very important, in many terms it has not always been set aside to be critical in organizational success. With the existence of the mainframe system being in the place, many organizations manage to protect their own systems from the abuse of the resources, for instances having unauthorized user gaining access to the organizational system and also the act of authorized user hogging company’s resources. Such types of abuse were considered to be more damaging based on the fact that the system had a higher cost during the early mainframes days. As time goes by, the technology techniques developed and increased to some level, hence the cost of the systems resources decreases, this issue apparently becomes less important to the business environment. (Gupta, Rees, Chaturvedi & Chi, 2006)The evolving act of having remote access outside the organizational networks was also considered to be non-existence. Furthermore, only the underground community had higher tools and knowledge that is rightfully needed to compromise the entire mainframe system.

The new security problem was led by the emergence of client-server technology. Processor utilization was never at any point the first priority, but access to systems and networks were the two important activities. Based on the sensitive information the access control becomes more important, such information may include the payroll and the human resources that were being stored in the public file servers. Most of the company all around the world did not want their information out to the public knowledge, and also even to some of their employees. This act led to the new development of unique technologies such as data encryption and granular access control. As it is well known, methods of exploiting and circumventing security products and new application quickly arose. During the server-client era, a few dial-up accounts were the only way to access corporate networks. (Wall, 2013) However, at any given point this process did not open some of the pure security holes, but some of the risks to such account can be easily be mitigated with some valuable procedures such as access lists and dial backs. The dedicated leased lines are the one that branches offices used to communicate with one another.

The rise of the internet was one of the highly advanced forms of technology. It generally opens access to worldwide networks, and out of that everything changed. Most of the companies provided clear internet access to its employee because of the wider rise of email and the World Wide Web. The act of developing an e-business initiative for an organization becomes more critical for the company to stay competitive in the wider market areas. With the internet being in place, most of the data including the information security system became accessible to the public. This is based on the fact that the entire internet is considered to be a public network, anybody on the net is can clearly access and see other systems. (Wall, 2013) As time goes by, the internet use widely spread out, many organizations started to allow access to the networks and information over the internet. The process of allowing anybody to access information on the internet really invites hackers into the system organizational systems, thus lowering the security of the company information.

Recently many events have led information security to be of more significance in any business environment, to which in many cases it focuses on how the business conducts its operations. 85% of the businesses all around the world do have rudimentary security program being in the place, furthermore, many programs are widely grown and developing in maturity. As the programs are growing, there is a need to understand that security is just a technical issue. In today’s world security is being combined with the fabric of the business, so that the operation of the business can be protected from unwanted users. The information security programs are always moved from being recognized as the tactical implementation of technology to a strategic partner in the business. The entire matter about the security program was meant to protect the integrity of the organization in the marketplaces. (Wall, 2013)This is because many companies see that there was a need to protect their data, thus the urge of security was raised. With the internet, the information of an organization was openly exposed to hackers, and that is the main reason as to why a security program is one of the most valuable things in evolving business.

C:\Users\ALLAN\Pictures\pic.PNG

Research objectives

The information and security is the major sector that is always at risk in ant business environment. It is well understood that accidents can occur and that attackers can literally gain access to the organizational system to which it can lead to the disruption of services, thus it can make the whole system useless or the information can be stolen. Some of the biggest companies have already taken an enlightened move about security issues. The deeply believe that to be successful they must be open to show their customer that the protecting information assets and security are some of the core business function. (Ahmad, Maynard & Shanks, 2015)The act of having security by design generally means that security is not an afterthought in the entire design process, instead, it is recognized as one of the requirements that the designer needs to use when starting a project in an organization. The process of securing in deployment implies that the product will be shipped and that it will be ready to use in a way that it cannot compromise other products or the customers.

In a wider definition, the information security is the plan the instantly mitigate risks that are associated with the information processing. Below are some of the objectives of the whole research about organizational security;

i. Confidentiality – This is the act of preventing an authorized use or disclosure of any organizational information. The entire system contains the information that always calls for genuine protection from all unauthorized disclosure.

ii. Integrity – This is the situation whereby the entire information must be ensured that it is accurate and complete and that the data is not is not modified by any an authorized user. It is clearly understood that most of the system contains information that must be protected from unanticipated modification. For instance economic indicators and the survey reports.

iii. Availability – this is the situation whereby the system management ensures that users have reliable and timely access to their assets information. The system provides services and contains information that must be available on a regular timely basis to meet the mission requirements and also to avoid substantial losses that might affect the business, hence lowering its operation. For instance systems critical to safety and online accessibility of the business records. (Tang & Zhang, 2016)

These are the main objectives about the organizational security; the three concepts about information security are linked up together for major protection. The idea carried out that information can be categorized as an asset that always calls for protection is really a sensitive matter.

Method and design

Organization security is one of the conceptual things that many organizations focus and dwell harder to have a strong path. The method that is used to drives the path of security in an organization really matters a lot. Below are some of the methods that are used to ensure the act of organization security is firmly installed in an organization.

i. The installation of the concept that the security do belongs to everyone

It is believed that many companies all around the world believe that the security department is the one that is responsible for all the security strategy. More and advanced sustainable security culture state that for the security in an organization to be paramount, each and every member of the organization must be accounted to the security matters. (AlHogail, 2015) Each employee must feel like a legend security person because it is rendered as the security culture to everybody in the organization. Security always belongs to everyone, starting from executive staff to the lobby ambassador of the company.

ii. Always focuses on awareness and beyond

Security awareness is the process of teaching the entire team in an organization about the security status of the company. Generally, it entails the basic lesson that each and every member in an organization is familiar with. Each employee should be leveled to judge threats before asking them to understand in depth. In many cases, security awareness has gain bad rap according to how it is being delivered to worker or employers. The general awareness is always needed for application security knowledge. The application security awareness is rendered to be of the testers and developers within an organization. (AlHogail, 2015)Awareness, especially on security matters, is always an ongoing activity, based on that it can never pass up a good crisis.

iii. Getting a secured and more developed lifecycle

SDL (secure development lifecycle) is one of the most powerful foundational to sustainable security culture. Secured developed lifecycle is the activity and process that an organization agrees to perform each system or software's released. Basically, it includes things such as threat modeling and security requirements. Secured developing lifecycle (SDL) always answers how the security culture in an organization is. In action, it is a sustainable security culture. Customers across many companies are starting to demand that SDL rules must be followed in an organization. At this juncture, if the company doesn’t have an SDL, Microsoft has gone a step ahead in releasing their details about the SDL free charge. The product security office is the reasonable place for the SDL to live.

iv. Recognize and reward those people that do the right thing for security

Security is a major factor to success in any business environment if an individual is working hard towards making sure that the security of data and the services in an organization are being catered for, that particular person must be recognized. This is based on the fact that when a person is being recognized and thereafter rewarded, automatically the entire issue about organization security will be limited, simply because other employees will also take that initiative of securing their data hoping that one day they will be rewarded too. (AlHogail, 2015) Baring in mind that security is all about each and every person in an organization, individuals should be encouraged so that they can administer and deal with insecurity issue appropriately.

v. Building security advanced community

According to sustainable security culture, the security community is its main backbone. Communities are the one that is responsible for providing all the existing connections between people across the entire organization. The act of security community plays an important role in bringing everyone together against problems that are common. By understanding the different security level, the security level will be achieved within an organization. In general terms, it advocates sponsors and security awareness. (AlHogail, 2015)The act of security awareness is considered to be not passionate but they just contribute to making the security better in some way.

vi. Making security fun and engaging

For a longer period of time, people have always engaged security programs as some of the most boring training in the organizations. That is the reason why many employees never want to involve themselves in any security training. But when the security program is handling in a better way, which involves some fun, automatically a good number of people will gain self-interest in learning more about security programs. People should be shown the effect of insecurity in an organization and be thought all the tactics on how to secure all the information and services provided by the company. (AlHogail, 2015

C:\Users\ALLAN\Pictures\pic 2.PNG

Significance

For any organization to be in place and rendered how successful it is, it should have a security specialist who always keeps the system safe, the security sector of the company must be paramount. With the rise of the internet, emails were widely used in many organizations all around the world. Email is recognized as the safest mode of communication simply because it many organizations ensure that all their email accounts are firmly secured. Thus making email as the primary mode of communication really helps to simplify the entire communication process. In a situation when an employee’s email account is breached, the specialist is the only person who is allowed to identify the problem, and thereafter sorting it out. (Dhillon, Syed & Pedron, 2016)

The idea of having security specialist in an organization really helped many big companies in terms of detecting viruses before the effects the whole systems. The specialist will set out some programs that will secure the whole system from being corrupt. They also play an important part in a fight with hackers who might have bad intentions on the company's system.

Conclusion

Organization security must be taken into consideration because it prevents many the loss of valuable information about an organization. The security system in an organization is tight, no data will be lost, and all the operation in and outside the business will be secured. No data will be corrupted or lost. Employees in an organization must also be responsible for ensuring that there is no data loss or that there is no malicious activity going on. Maximum security will stand to protect both the employee's work and the product produced.

References

Ahmad, A., Maynard, S. B., & Shanks, G. (2015). A case analysis of information systems and security incident responses. International Journal of Information Management35(6), 717-723.

AlHogail, A. (2015). Design and validation of information security culture framework. Computers in Human Behavior49, 567-575.

Dhillon, G., Syed, R., & Pedron, C. (2016). Interpreting information security culture: An organizational transformation case study. computers & security56, 63-69.

Gupta, M., Rees, J., Chaturvedi, A., & Chi, J. (2006). Matching information security vulnerabilities to organizational security profiles: a genetic algorithm approach. Decision Support Systems41(3), 592-603.

Tang, M., & Zhang, T. (2016). The impacts of organizational culture on information security culture: a case study. Information Technology and Management17(2), 179-186.

Wall, D. S. (2013). Enemies within: Redefining the insider threat in organizational security policy. Security Journal26(2), 107-124.

https://research-paper.essayempire.com/examples/management/organizational-security-research-paper/

https://techbeacon.com/6-ways-develop-security-culture-top-bottom