کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
552890 873296 2007 16 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Network externalities, layered protection and IT security risk management
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر سیستم های اطلاعاتی
پیش نمایش صفحه اول مقاله
Network externalities, layered protection and IT security risk management
چکیده انگلیسی

This paper considers two important issues related to security risk management. First, the presence of network externalities in security risks. Second, the distinction of general (network) and system-specific protection measures. We found the optimal allocation of security resources (investments) in protecting every system in an organization. The results show that the consideration of network externalities and layered protection changes the risk mitigation decisions significantly. In addition, accurate estimation of system risk plays a critical role in the success of risk management. Otherwise, the use of a uniform baseline protection approach may be more desirable when the misjudgment of relative system risks is likely to occur.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Decision Support Systems - Volume 44, Issue 1, November 2007, Pages 1–16
نویسندگان
, , , ,