Towards an Information Security Competence Maturity Model

Kerry-Lynn Thomson, Rossouw von Solms

Computer Fraud & Security · 2006 · 47 citations · 4 references

Abstract

The corporate culture of an organization influences the behaviour of employees and ultimately contributes to the effectiveness of an organization. Information is a vital asset for most organizations. Therefore, ideally, a corporate culture should incorporate information security controls into the daily routines and implicit behaviour of employees. This paper introduces the Information Security Competence Maturity Model as a possible method to evaluate to what extent information security is embedded in the overall current corporate culture of an organization.

References

4