TY - JOUR
T1 - Information security outsourcing with system interdependency and mandatory security requirement
AU - Hui, Kai Lung
AU - Hui, Wendy
AU - Yue, Wei
PY - 2012/1/1
Y1 - 2012/1/1
N2 - The rapid growth of computer networks has led to a proliferation of information security standards. To meet these security standards, some organizations outsource security protection to a managed security service provider (MSSP). However, this may give rise to system interdependency risks. This paper analyzes how such system interdependency risks interact with a mandatory security requirement to affect the equilibrium behaviors of an MSSP and its clients. We show that a mandatory security requirement will increase the MSSP's effort and motivate it to serve more clients. Although more clients can benefit from the MSSP's protection, they are also subjected to greater system interdependency risks. Social welfare will decrease if the mandatory security requirement is high, and imposing verifiability may exacerbate social welfare losses. Our results imply that recent initiatives such as issuing certification to enforce computer security protection, or encouraging auditing of managed security services, may not be advisable.
AB - The rapid growth of computer networks has led to a proliferation of information security standards. To meet these security standards, some organizations outsource security protection to a managed security service provider (MSSP). However, this may give rise to system interdependency risks. This paper analyzes how such system interdependency risks interact with a mandatory security requirement to affect the equilibrium behaviors of an MSSP and its clients. We show that a mandatory security requirement will increase the MSSP's effort and motivate it to serve more clients. Although more clients can benefit from the MSSP's protection, they are also subjected to greater system interdependency risks. Social welfare will decrease if the mandatory security requirement is high, and imposing verifiability may exacerbate social welfare losses. Our results imply that recent initiatives such as issuing certification to enforce computer security protection, or encouraging auditing of managed security services, may not be advisable.
KW - information security
KW - information security outsourcing
KW - interdependency risks
KW - mandatory security requirement
KW - security compliance
UR - https://www.webofscience.com/wos/woscc/full-record/WOS:000318678100005
UR - https://openalex.org/W2015057804
UR - https://www.scopus.com/pages/publications/84878001717
U2 - 10.2753/MIS0742-1222290304
DO - 10.2753/MIS0742-1222290304
M3 - Journal Article
SN - 0742-1222
VL - 29
SP - 117
EP - 156
JO - Journal of Management Information Systems
JF - Journal of Management Information Systems
IS - 3
ER -