Author List: Cavusoglu, Huseyin; Mishra, Birendra; Raghunathan, Srinivasan;
Information Systems Research, 2005, Volume 16, Issue 1, Page 28-46.
The increasing significance of information technology (IT) security to firms is evident from their growing IT security budgets. Firms rely on security technologies such as firewalls and intrusion detection systems (IDSs) to manage IT security risks. Although the literature on the technical aspects of IT security is proliferating, a debate exists in the IT security community about the value of these technologies. In this paper, we seek to assess the value of IDSs in a firm's IT security architecture. We find that the IDS configuration, represented by detection (true positive) and false alarm (false positive) rates, determines whether a firm realizes a positive or negative value from the IDS. Specifically, we show that a firm realizes a positive value from an IDS only when the detection rate is higher than a critical value, which is determined by the hacker's benefit and cost parameters. When the firm realizes a positive (negative) value, the IDS deters (sustains) hackers. However, irrespective of whether the firm realizes a positive or negative value from the IDS, the IDS enables the firm to better target its investigation of users, while keeping the detection rate the same. Our results suggest that the positive value of an IDS results not from improved detection per se, but from an increased deterrence enabled by improved detection. Finally, we show that the firm realizes a strictly nonnegative value if the firm configures the IDS optimally based on the hacking environment.
Keywords: economics of IT security; intrusion detection systems (IDSs); IT security management; ROC curves; security configuration
Algorithm:

List of Topics

#73 0.468 security threat information users detection coping configuration avoidance response firm malicious attack intrusion appraisal countermeasures benefit costs threats ability rate
#143 0.142 value business benefits technology based economic creation related intangible cocreation assessing financial improved key economics assess question created create understanding
#166 0.124 negative positive effect findings results effects blog suggest role blogs posts examined period relationship employees research employee bloggers reveal companies
#168 0.105 firms firm financial services firm's size examine new based result level including results industry important account does suggests characterize limited
#240 0.057 systems information management development presented function article discussed model personnel general organization described presents finally computer-based role examined functional components