The aim of this paper is to explore, from
an information manager's perspective, the
confusing issue of security surveys and
the data that they present. The issue that
information managers and information
security managers face is how can this data be used to make key organisational decisions in
relation to security management?