Mandatory Standards and Organizational Information Security

Cited 12 time in webofscience Cited 0 time in scopus
  • Hit : 313
  • Download : 0
DC FieldValueLanguage
dc.contributor.authorLee, Chul Hoko
dc.contributor.authorGeng, Xianjunko
dc.contributor.authorRaghunathan, Scrinivasanko
dc.date.accessioned2016-12-14T04:29:38Z-
dc.date.available2016-12-14T04:29:38Z-
dc.date.created2016-05-30-
dc.date.created2016-05-30-
dc.date.issued2016-03-
dc.identifier.citationINFORMATION SYSTEMS RESEARCH, v.27, no.1, pp.70 - 86-
dc.identifier.issn1047-7047-
dc.identifier.urihttp://hdl.handle.net/10203/214865-
dc.description.abstractMandatory security standards that force firms to establish minimum levels of security controls are enforced in many domains, including information security. The information security domain is characterized by multiple intertwined security controls, not all of which can be regulated by standards, but compliance with existing security standards is often used by firms to deflect liability if a security breach occurs. We analyze a stylized setting where a firm has two security controls that are linked in either a serial or a parallel configuration. One control is directly regulated by a security standard, whereas the other one is not. We show that a higher security standard does not necessarily lead to a higher firm security. Furthermore, the conditions under which a higher standard hurts the firm security are sharply different in the two—serial and parallel—configurations. If standard compliance leads to reduced liability for a firm following a breach, such liability reduction in turn weakens the tie between the standard and firm security. Under a setting in which the firm meets the optimal standard set by a policy maker, both firm security and social welfare are higher when the damage to the firm following a breach takes a higher share of the total damage to social welfare, and also when the firm takes a larger share of liability.-
dc.languageEnglish-
dc.publisherINFORMS-
dc.subjectINVESTMENT-
dc.subjectCONTRACTS-
dc.subjectLIABILITY-
dc.subjectSOFTWARE-
dc.subjectSYSTEMS-
dc.titleMandatory Standards and Organizational Information Security-
dc.typeArticle-
dc.identifier.wosid000375600200005-
dc.identifier.scopusid2-s2.0-84962791707-
dc.type.rimsART-
dc.citation.volume27-
dc.citation.issue1-
dc.citation.beginningpage70-
dc.citation.endingpage86-
dc.citation.publicationnameINFORMATION SYSTEMS RESEARCH-
dc.identifier.doi10.1287/isre.2015.0607-
dc.contributor.localauthorLee, Chul Ho-
dc.contributor.nonIdAuthorGeng, Xianjun-
dc.contributor.nonIdAuthorRaghunathan, Scrinivasan-
dc.type.journalArticleArticle-
dc.subject.keywordAuthorinformation security-
dc.subject.keywordAuthorsecurity regulation-
dc.subject.keywordAuthorunverifiability-
dc.subject.keywordPlusINVESTMENT-
dc.subject.keywordPlusCONTRACTS-
dc.subject.keywordPlusLIABILITY-
dc.subject.keywordPlusSOFTWARE-
dc.subject.keywordPlusSYSTEMS-
Appears in Collection
MG-Journal Papers(저널논문)
Files in This Item
There are no files associated with this item.
This item is cited by other documents in WoS
⊙ Detail Information in WoSⓡ Click to see webofscience_button
⊙ Cited 12 items in WoS Click to see citing articles in records_button

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0