首页> 外文期刊>Journal of management information systems >Information Security Outsourcing with System Interdependency and Mandatory Security Requirement
【24h】

Information Security Outsourcing with System Interdependency and Mandatory Security Requirement

机译:具有系统依赖性和强制性安全要求的信息安全外包

获取原文
获取原文并翻译 | 示例
       

摘要

The rapid growth of computer networks has led to a proliferation of information security standards. To meet these security standards, some organizations outsource security protection to a managed security service provider (MSSP). However, this may give rise to system interdependency risks. This paper analyzes how such system interdependency risks interact with a mandatory security requirement to affect the equilibrium behaviors of an MSSP and its clients. We show that a mandatory security requirement will increase the MSSP's effort and motivate it to serve more clients. Although more clients can benefit from the MSSP's protection, they are also subjected to greater system interdependency risks. Social welfare will decrease if the mandatory security requirement is high, and imposing verifiability may exacerbate social welfare losses. Our results imply that recent initiatives such as issuing certification to enforce computer security protection, or encouraging auditing of managed security services, may not be advisable.
机译:计算机网络的迅速发展导致信息安全标准的激增。为了满足这些安全标准,某些组织将安全保护外包给了托管安全服务提供商(MSSP)。但是,这可能会导致系统相互依赖的风险。本文分析了这种系统相互依存性风险如何与强制性安全要求交互,从而影响MSSP及其客户的均衡行为。我们表明,强制性安全要求将增加MSSP的工作量,并激发它为更多客户提供服务。尽管更多的客户可以从MSSP的保护中受益,但它们也面临更大的系统相互依赖性风险。如果强制性安全要求很高,社会福利将减少,强加可验证性可能会加剧社会福利损失。我们的结果表明,最近的举措(例如颁发证书以实施计算机安全保护或鼓励对托管安全服务进行审核)可能并不明智。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号