Relevance of the research. Ensuring the effectiveness of the information security systems requires creation of an appropriate information security culture for the employees of the organization in order to reduce human-related risks. Target setting. The techniques currently available for assessing information security risk are excluded as a source of the potential vulnerability. Considering the role of the personnel in the organization's information security systems, there is a need to create automated systems of human-machine interaction assessment through the level of the personnel information security culture, and to determine the integral indicator of the organization's information security culture. Actual scientific researches and issues analysis. Open access publications on the problems of integrating the information security culture into the corporate culture of the organization as a tool for ensuring the proper information security level of business processes are considered. Uninvestigated parts of general matters defining. The absence of formalized models for assessing the organization's information security culture level, as well as an automated process for its assessing were revealed by source analysis. The research objective. The purpose of the article to build a model that describes the process of obtaining an organization's information security culture level assessment in IDEF0 notation. Then, to create an architecture and database for system of information security culture assessment to support the general organization's information security system. The statement of basic materials. According to functional requirements, a conceptual model of «The organization`s ISC level determination» development process was created. Input information, governing elements, execution elements and mechanism, and output information were defined. To accomplish these tasks, an architecture and database of information system for assessing the information security culture level of the organization were proposed. Conclusions. The functional model of top-level development process was proposed. Formed functional requirements became the basis for development of information system architecture with description of its modules and database structure.
Die Sensibilisierung der Mitarbeiter für Belange der Informationssicherheit ist eng verknüpft mit der Unternehmenskultur. Thomas Schlienger zeigt in seinem Beitrag eine systematische Vorgehensweise auf.
An electronic measuring rule wherein the rule tape is formed integrally with a magnetic recording tape imbedded therein along the longitudinal axis of the tape rule. The recording tape which has spaced indicia signals recorded thereon is molded into a recess along the longitudinal center of a vinyl tape so that the vinyl tape covers the outer edges of the magnetic recording tape and the back thereof. A thin protective resin layer covers the recorded side to protect it from abrasions during use. Visible indicia are printed on both sides of the vinyl tape, top and bottom, on each lateral side so that the tape may be "read" visually in the usual manner from either lateral side, both top and bottom. The recording tape portion of the measuring rule is "read" directly by a pick-up head located within the case adjacent the location where the tape exits the enclosing case. An on-off switch turns on the calculator and display portion when the tape is pulled from the case, and off when less than an inch of the tape is extened. Their magnetic readings are converted to digital display.
Information Security Culture includes all socio-cultural measures that support technical security methods, so that information security becomes a natural aspect in the daily activity of every employee. To apply these socio-cultural measures in an effective and efficient way, certain management models and tools are needed. In our research we developed a framework analyzing the security culture of an organization which we then applied in a pre-evaluation survey. This paper is based on the results of this survey. We will develop a management model for creating, changing and maintaining Information Security Culture. This model will then be used to define explicit sociocultural measures, based on the concept of internal marketing.