IS

Arora, Ashish

Topic Weight Topic Terms
0.448 software vendors vendor saas patch cloud release model vulnerabilities time patching overall quality delivery software-as-a-service
0.165 local global link complex view links particularly need thought number supports efforts difficult previously linked
0.138 outsourcing transaction cost partnership information economics relationships outsource large-scale contracts specificity perspective decisions long-term develop
0.125 services service network effects optimal online pricing strategies model provider provide externalities providing base providers

Focal Researcher     Coauthors of Focal Researcher (1st degree)     Coauthors of Coauthors (2nd degree)

Note: click on a node to go to a researcher's profile page. Drag a node to reallocate. Number on the edge is the number of co-authorships.

Forman, Chris 1 Krishnan, Ramayya 1 Telang, Rahul 1 Yang, Yubao 1
disclosure policy 1 hazard model 1 information security 1 informationtechnology outsourcing 1
open source vendors 1 outsourcing 1 patch release time 1 security vulnerability 1
software vendors 1 servicetradability 1 services 1 servicesoutsourcing 1

Articles (2)

An Empirical Analysis of Software Vendors' Patch Release Behavior: Impact of Vulnerability Disclosure. (Information Systems Research, 2010)
Authors: Abstract:
    A key aspect of better and more secure software is timely patch release by software vendors for the vulnerabilities in their products. Software vulnerability disclosure, which refers to the publication of vulnerability information, has generated intense debate. An important consideration in this debate is the behavior of software vendors. How quickly do vendors patch vulnerabilities and how does disclosure affect patch release time? This paper compiles a unique data set from the Computer Emergency Response Team/Coordination Center (CERT) and SecurityFocus to answer this question. Our results suggest that disclosure accelerates patch release. The instantaneous probability of releasing the patch rises by nearly two and a half times because of disclosure. Open source vendors release patches more quickly than closed source vendors. Vendors are more responsive to more severe vulnerabilities. We also find that vendors respond more slowly to vulnerabilities not disclosed by CERT. We verify our results by using another publicly available data set and find that results are consistent. We also show how our estimates can aid policy makers in their decision making.
Proximity and Information Technology Outsourcing: How Local Are IT Services Markets? (Journal of Management Information Systems, 2007)
Authors: Abstract:
    We examine the question of which services are tradable within a concrete setting: the outsourcing of information technology (IT) services across a broad cross-section of establishments in the United States. If markets for IT services are local, then we should expect increases in local supply would increase the likelihood of outsourcing by lowering the cost of outsourcing. If markets are not local, then local supply will not affect outsourcing demand. We analyze the outsourcing decisions of a large sample of 99,775 establishments in 2002 and 2004, for two types of IT services--programming and design and hosting. Programming and design projects require communication of detailed user requirements whereas hosting requires less coordination between client and service provider than programming and design. Our empirical results bear out this intuition: the probability of outsourcing programming and design is increasing in the local supply of outsourcing, and this sensitivity to local supply conditions has been increasing over time. This suggests there is some nontradable or "local" component to programming and design services that cannot be easily removed. In contrast, the decision to outsource hosting is sensitive to local supply only for firms for which network uptime and security concerns are particularly acute.