THE ECONOMICS OF INFORMATIONTECHNOLOGY (IT) SECURITY
Huseyin Cavusoglu
Abstract
Huseyin Cavusoglu
Abstract
IT Security has become a salient issue for many organizations. While the literature on the technical aspects of IT security is proliferating, it is not clear how one can quantify the value of IT security. An assessment of the value of IT security technology is critical both to firms employing this technology as well as to firms that develop the technology. However assessing the value of IT security is a challenging task because of difficulties in measurements of tangible and intangible benefits of it. My thesis addresses the broad issue of the value of IT security. I use both analytical and empirical methodologies. In the first part of my thesis, I conduct an event study analysis of the effect of security breach announcements on market value of firms. This analysis provides an indirect estimate of the costs of inadequate IT security. In the second and third parts of my thesis, I consider a typical IT security architecture that includes preventive, detective, and response security controls. I develop a game theoretical model that incorporates the strategic interaction between a firm that invests in IT security and users of the system. I derive the value of IT security mechanisms as the savings in organizational loss because of security technology. I also plan to analyze the optimal investments in various technologies. My research will yield guidelines and insights that will help firms decide their security architectures and security developers make their design decisions.
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
IT Security has become a salient issue for many organizations. While the literature on the technical aspects of IT security is proliferating, it is not clear how one can quantify the value of IT security. An assessment of the value of IT security technology is critical both to firms employing this technology as well as to firms that develop the technology. However assessing the value of IT security is a challenging task because of difficulties in measurements of tangible and intangible benefits of it. My thesis addresses the broad issue of the value of IT security. I use both analytical and empirical methodologies. In the first part of my thesis, I conduct an event study analysis of the effect of security breach announcements on market value of firms. This analysis provides an indirect estimate of the costs of inadequate IT security. In the second and third parts of my thesis, I consider a typical IT security architecture that includes preventive, detective, and response security controls. I develop a game theoretical model that incorporates the strategic interaction between a firm that invests in IT security and users of the system. I derive the value of IT security mechanisms as the savings in organizational loss because of security technology. I also plan to analyze the optimal investments in various technologies. My research will yield guidelines and insights that will help firms decide their security architectures and security developers make their design decisions.
Key concepts: Security through obscurity, Security information and event management, Security convergence, Computer security, Cloud computing security, Risk analysis (engineering), Security management, Computer security model