2002•Unpublished venueRequires access

THE ECONOMICS OF INFORMATIONTECHNOLOGY (IT) SECURITY

Huseyin Cavusoglu

Open publisher page 1 citations

Abstract

IT Security has become a salient issue for many organizations. While the literature on the technical aspects of IT security is proliferating, it is not clear how one can quantify the value of IT security. An assessment of the value of IT security technology is critical both to firms employing this technology as well as to firms that develop the technology. However assessing the value of IT security is a challenging task because of difficulties in measurements of tangible and intangible benefits of it. My thesis addresses the broad issue of the value of IT security. I use both analytical and empirical methodologies. In the first part of my thesis, I conduct an event study analysis of the effect of security breach announcements on market value of firms. This analysis provides an indirect estimate of the costs of inadequate IT security. In the second and third parts of my thesis, I consider a typical IT security architecture that includes preventive, detective, and response security controls. I develop a game theoretical model that incorporates the strategic interaction between a firm that invests in IT security and users of the system. I derive the value of IT security mechanisms as the savings in organizational loss because of security technology. I also plan to analyze the optimal investments in various technologies. My research will yield guidelines and insights that will help firms decide their security architectures and security developers make their design decisions.

About this research paper

What this paper is about

IT Security has become a salient issue for many organizations. While the literature on the technical aspects of IT security is proliferating, it is not clear how one can quantify the value of IT security. An assessment of the value of IT security technology is critical both to firms employing this technology as well as to firms that develop the technology. However assessing the value of IT security is a challenging task because of difficulties in measurements of tangible and intangible benefits of it. My thesis addresses the broad issue of the value of IT security. I use both analytical and empirical methodologies. In the first part of my thesis, I conduct an event study analysis of the effect of security breach announcements on market value of firms. This analysis provides an indirect estimate of the costs of inadequate IT security. In the second and third parts of my thesis, I consider a typical IT security architecture that includes preventive, detective, and response security controls. I develop a game theoretical model that incorporates the strategic interaction between a firm that invests in IT security and users of the system. I derive the value of IT security mechanisms as the savings in organizational loss because of security technology. I also plan to analyze the optimal investments in various technologies. My research will yield guidelines and insights that will help firms decide their security architectures and security developers make their design decisions.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

IT Security has become a salient issue for many organizations. While the literature on the technical aspects of IT security is proliferating, it is not clear how one can quantify the value of IT security. An assessment of the value of IT security technology is critical both to firms employing this technology as well as to firms that develop the technology. However assessing the value of IT security is a challenging task because of difficulties in measurements of tangible and intangible benefits of it. My thesis addresses the broad issue of the value of IT security. I use both analytical and empirical methodologies. In the first part of my thesis, I conduct an event study analysis of the effect of security breach announcements on market value of firms. This analysis provides an indirect estimate of the costs of inadequate IT security. In the second and third parts of my thesis, I consider a typical IT security architecture that includes preventive, detective, and response security controls. I develop a game theoretical model that incorporates the strategic interaction between a firm that invests in IT security and users of the system. I derive the value of IT security mechanisms as the savings in organizational loss because of security technology. I also plan to analyze the optimal investments in various technologies. My research will yield guidelines and insights that will help firms decide their security architectures and security developers make their design decisions.

Key concepts: Security through obscurity, Security information and event management, Security convergence, Computer security, Cloud computing security, Risk analysis (engineering), Security management, Computer security model

Related papers

Back to paper searchBrowse research topicsOriginal source
THE ECONOMICS OF INFORMATIONTECHNOLOGY (IT) SECURITY — Research Paper | ScholarLens