IS

Subramaniam, Chandrasekar

Topic Weight Topic Terms
0.537 software vendors vendor saas patch cloud release model vulnerabilities time patching overall quality delivery software-as-a-service
0.330 security threat information users detection coping configuration avoidance response firm malicious attack intrusion appraisal countermeasures
0.147 insurance companies growth portfolios intensity company life portfolio industry newly vulnerable terms composition operating implemented
0.121 information types different type sources analysis develop used behavior specific conditions consider improve using alternative
0.103 value business benefits technology based economic creation related intangible cocreation assessing financial improved key economics

Focal Researcher     Coauthors of Focal Researcher (1st degree)     Coauthors of Coauthors (2nd degree)

Note: click on a node to go to a researcher's profile page. Drag a node to reallocate. Number on the edge is the number of co-authorships.

Kumar, Ram L. 2 Park, SungJune 2 Temizkan, Orcun 1
business value of IT 1 economics of IS security 1 information systems security 1 IT asset valuation 1
patch quality 1 patch release time 1 patch types 1 software vendor types 1
software vulnerability characteristics 1 survival analysis 1

Articles (2)

Patch Release Behaviors of Software Vendors in Response to Vulnerabilities: An Empirical Analysis. (Journal of Management Information Systems, 2012)
Authors: Abstract:
    Software vulnerabilities have become a serious concern because unpatched software runs the risk of being exploited by hackers. There is a need for software vendors to make software patches available in a timely manner for vulnerabilities in their products. We develop a survival analysis model of software vendors' patch release behavior and test it using a data set compiled from the National Vulnerability Database, United States Computer Emergency Readiness Team, and vendor Web sites. This model helps to understand how factors specific to vulnerabilities, patches, software vendors, and software affect the patch release behavior of software vendors based on their cost structure. This study also analyzes the impact of the presence of multiple vendors and type of vendor on the patch release behavior of software vendors. Our results indicate that vulnerabilities with high confidentiality impact or high integrity impact are patched faster than vulnerabilities with high availability impact. Interesting differences in the patch release behavior of software vendors based on software type (new release versus update) and type of vendor (open source versus proprietary) are found. Our results illustrate that when there are legislative pressures, vendors react faster in patching vulnerabilities. Thus, appropriate regulations can be an important policy tool to influence vendor behavior toward socially desirable security outcomes.
Understanding the Value of Countermeasure Portfolios in Information Systems Security. (Journal of Management Information Systems, 2008)
Authors: Abstract:
    Organizations are faced with a variety of information security threats and implement several information system security countermeasures (ISSCs) to mitigate possible damage due to security attacks. These security countermeasures vary in their ability to deal with different types of security attacks and, hence, are implemented as a portfolio of ISSCs. A key challenge for organizations is to understand the economic consequences of security attacks relative to the ISSC portfolio implemented. This paper combines the risk analysis and disaster recovery perspectives to build an integrated simulation model of ISSC portfolio value. The model incorporates the characteristics of an ISSC portfolio relative to the threat and business environments and includes the type of attack, frequency of attacks, possible damage, and the extent and time of recovery from damage. The simulation experiments provide interesting insights into the interactions between ISSC portfolio components and characteristics of business and threat environments in determining portfolio value.