Network externalities, layered protection and IT security risk management

作者:

Highlights:

摘要

This paper considers two important issues related to security risk management. First, the presence of network externalities in security risks. Second, the distinction of general (network) and system-specific protection measures. We found the optimal allocation of security resources (investments) in protecting every system in an organization. The results show that the consideration of network externalities and layered protection changes the risk mitigation decisions significantly. In addition, accurate estimation of system risk plays a critical role in the success of risk management. Otherwise, the use of a uniform baseline protection approach may be more desirable when the misjudgment of relative system risks is likely to occur.

论文关键词:IT risk management,IT risk analysis,IT risk mitigation,Security investments,Security resource planning

论文评审过程:Received 15 June 2005, Revised 26 July 2006, Accepted 13 August 2006, Available online 13 October 2006.

论文官网地址:https://doi.org/10.1016/j.dss.2006.08.009