Author List: Hui, Kai-Lung; Hui, Wendy; Yue, Wei T.;
Journal of Management Information Systems, 2012, Volume 29, Issue 3, Page 117-156.
The rapid growth of computer networks has led to a proliferation of information security standards. To meet these security standards, some organizations outsource security protection to a managed security service provider (MSSP). However, this may give rise to system interdependency risks. This paper analyzes how such system interdependency risks interact with a mandatory security requirement to affect the equilibrium behaviors of an MSSP and its clients. We show that a mandatory security requirement will increase the MSSP's effort and motivate it to serve more clients. Although more clients can benefit from the MSSP's protection, they are also subjected to greater system interdependency risks. Social welfare will decrease if the mandatory security requirement is high, and imposing verifiability may exacerbate social welfare losses. Our results imply that recent initiatives such as issuing certification to enforce computer security protection, or encouraging auditing of managed security services, may not be advisable.
Keywords: information security; information security outsourcing; interdependency risks; mandatory security requirement; security compliance
Algorithm:

List of Topics

#186 0.636 security information compliance policy organizations breach disclosure policies deterrence breaches incidents results study abuse managed isp violations based comply protection
#47 0.098 outsourcing vendor client sourcing vendors clients relationship firms production mechanisms duration mode outsourced vendor's effort activities in-house managing technology domestic
#112 0.065 services service network effects optimal online pricing strategies model provider provide externalities providing base providers fee complementary demand offer derive
#264 0.057 risk risks management associated managing financial appropriate losses expected future literature reduce loss approach alternative mitigate failures failure cause mitigation