Managing Internal Security Risk

cityu.schoolSchool of Technology and Computing
cityu.siteSeattle
cityu.site.countryUnited States
dc.contributor.authorLeak, Evan
dc.date.accessioned2022-05-06T23:41:05Z
dc.date.available2022-05-06T23:41:05Z
dc.date.issued2022-03
dc.description.abstractCybersecurity requires a 365-degree approach to an organization's attack surface. Internal points of access require as much care as external access points. Internally, it's important to consider access controls as well as user training as methods for improving security. With training, there are ongoing efforts to learn how to maintain user engagement and improve the internalization of training material. With users' being potential security risks, it's crucial to form an effective training method and maintain access controls for applications and systems. To address this, current research into the topics of user training and zero-trust will be aggregated here with special consideration to being approachable to smaller organizations. Based on current research, suggestions for building a foundation for long-term success in these areas will be made. The benefits of these methods will look to achieve a more secure organization by improving the users' knowledge and awareness of computers and relevant security concepts. Specific topics cover in this approach includes, preparing for the creation of a training program, zero trust implementation, and ways these can implemented. In the interest of discovering what a company may be starting with, a survey was sent out to determine the confidence and interest users had in computing topics. The results showed most users were interested in additional training and security awareness. In the end it was found that implementing training and zero-trust take plenty of work, but the requirements for starting such an approach are limited and can help create a more secure organization.
dc.identifier.urihttp://hdl.handle.net/20.500.11803/1779
dc.language.isoen
dc.publisher.institutionCity University of Seattle (CityU)
dc.rightsAttribution-NonCommercial-NoDerivs 3.0 United States
dc.rightsopenAccess
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/3.0/us/
dc.subjectinternal risk management
dc.subjectcybersecurity training
dc.subjectzero-trust
dc.subjectuser feedback
dc.titleManaging Internal Security Risk
dc.typeCapstone
thesis.degree.disciplineCybersecurity
thesis.degree.grantorCity University of Seattle
thesis.degree.levelUndergraduate
thesis.degree.nameBachelor of Science
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
EvanLeakCapstone.pdf
Size:
154.42 KB
Format:
Adobe Portable Document Format
Description:
Evan Leak Capstone