How to measure security culture at Organization X
Gyllenberg, Jenni (2025)
Gyllenberg, Jenni
2025
All rights reserved. This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi:amk-2025051210799
https://urn.fi/URN:NBN:fi:amk-2025051210799
Tiivistelmä
Most information and cyber incidents involve a human component – often an employee making a simple mistake that grants attackers access to systems or data. To mitigate this risk, organizations should consider implementing an effective security awareness program focused on creating a strong security culture to better protect their assets.
The objective of this study is to investigate how security culture can be measured at Organization X. Although the organization places a strong emphasis on security culture, it has been struggling to identify the appropriate methods for assessing the impact of its annual security awareness program and the culture cultivated through its activities.
The literature review in this thesis introduces concepts and frameworks related to security culture, including information security and cybersecurity, security awareness, and organizational culture. It also explores available models for measuring security culture.
This thesis examines how security culture can be measured and how selected measurement techniques can be applied to Organization X. It aims to serve as a valuable resource for other security professionals seeking to evaluate their security culture.
The measurement methods developed to analyze the security culture of Organization X were created in 2024. The research methods included multiple interviews, workshops, and brainstorming sessions. The developed measurement techniques were implemented at Organization X in 2024, and it is recommended that they be applied on a monthly and annual basis.
The objective of this study is to investigate how security culture can be measured at Organization X. Although the organization places a strong emphasis on security culture, it has been struggling to identify the appropriate methods for assessing the impact of its annual security awareness program and the culture cultivated through its activities.
The literature review in this thesis introduces concepts and frameworks related to security culture, including information security and cybersecurity, security awareness, and organizational culture. It also explores available models for measuring security culture.
This thesis examines how security culture can be measured and how selected measurement techniques can be applied to Organization X. It aims to serve as a valuable resource for other security professionals seeking to evaluate their security culture.
The measurement methods developed to analyze the security culture of Organization X were created in 2024. The research methods included multiple interviews, workshops, and brainstorming sessions. The developed measurement techniques were implemented at Organization X in 2024, and it is recommended that they be applied on a monthly and annual basis.
Kokoelmat
Samankaltainen aineisto
Näytetään aineisto, joilla on samankaltaisia nimekkeitä, tekijöitä tai asiasanoja.
-
Research on Optimization of Security Screening Process in AB Airport
Hu, Jianfeng (2025)With the rapid development of the air transportation industry, the efficiency and safety of the airport security check process has become a core issue of concern for the industry. This paper takes AB airport as the research ... -
Making an information security plan
Miettinen, Henrik (2021)The development objective of this thesis was to create a working, efficient and solid information security plan for a small-sized company. This thesis used qualitative and development methods, such as qualitative interview, ... -
Cybersecurity development and business continuity plan for car dealership
Valasvuo, Santeri (2022)The purpose of this thesis was to investigate the capability of the case company to meet the challenges of current and growing security threats and to come up with a development plan to increase the level of cyber security ...



