APJIS Asia Pacific Journal of Information Systems

???

The Journal for Information Professionals

Asia Pacific Journal of Information Systems (APJIS), a Scopus and ABDC indexed journal, is a
flagship journal of the information systems (IS) field in the Asia Pacific region.

ISSN 2288-5404 (Print) / ISSN 2288-6818 (Online)

Editor : Seung Hyun Kim

View full editorial board

menu05_sub01_ov.gif

Share this page

Past Issue

Date December 2011
Vol. No. Vol. 21 No. 4
DOI
Page 27~43
Title Vulnerability and Information Security Investment Under Interdependent Risks:A Theoretical Approach
Author Woohyun Shim
Keyword IS Management, Information Security Investment, Security Vulnerability, Interdependent Security Risk, Externalities, Cyber Attacks
Abstract This article explores economic models that show the optimal level of information security investment in the presence of interdependent security risks. Using particular functional forms, the analysis shows that the relationship between the levels of security vulnerability and the levels of optimal security investments is affected by externalities caused by agents??correlated security risks. This article further illustrates that, compared to security investments in the situation of independent security risks, in order to maximize the expected benefits security investments, an agent should invest a larger fraction of the expected loss a security breach in the case of negative externalities, while an agent should spend a smaller fraction of the expected loss in the case of negative externalities.


Home     l      Site Map      l       Abstracting/Indexing      l      FAQ      l      Publisher      l       Contact Us     l       Admin Login

© 2013 The Korean Society of Management Information Systems. All rights reserved.