The Association Between the Disclosure and the Realization of Information Security Risk Factors

被引:117
|
作者
Wang, Tawei [1 ]
Kannan, Karthik N. [2 ]
Ulmer, Jackie Rees [2 ]
机构
[1] Univ Hawaii Manoa, Shidler Coll Business, Sch Accountancy, Honolulu, HI 96822 USA
[2] Purdue Univ, CERIAS, Krannert Grad Sch Management, W Lafayette, IN 47907 USA
关键词
information security; information security incident; risk factor; text mining; DECISION-TREE INDUCTION; BREACH ANNOUNCEMENTS; LOGISTIC-REGRESSION; MARKET REACTIONS; MANAGEMENT; MODELS; FIRMS; ESTIMATOR; CLUSTERS; EARNINGS;
D O I
10.1287/isre.1120.0437
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Firms often disclose information security risk factors in public filings such as 10-K reports. The internal information associated with disclosures may be positive or negative. In this paper, we evaluate how the nature of the disclosed security risk factors, believed to represent the firm's internal information regarding information security, is associated with future breach announcements reported in the media. For this purpose, we build a decision tree model, which classifies the occurrence of future security breaches based on the textual contents of the disclosed security risk factors. The model is able to accurately associate disclosure characteristics with breach announcements about 77% of the time. We further explore the contents of the security risk factors using text-mining techniques to provide a richer interpretation of the results. The results show that the disclosed security risk factors with risk-mitigation themes are less likely to be related to future breach announcements. We also investigate how the market interprets the nature of information security risk factors in annual reports. We find that the market reaction following the security breach announcement is different depending on the nature of the preceding disclosure. Thus, our paper contributes to the literature in information security and sheds light on how market participants can better interpret security risk factors disclosed in financial reports at the time when financial reports are released.
引用
下载
收藏
页码:201 / 218
页数:18
相关论文
共 50 条
  • [1] Association between maternal HIV disclosure and risk factors for perinatal transmission
    Yee, Lynn M.
    McGregor, Donna V.
    Sutton, Sarah H.
    Garcia, Patricia M.
    Miller, Emily S.
    JOURNAL OF PERINATOLOGY, 2018, 38 (06) : 639 - 644
  • [2] Association between maternal HIV disclosure and risk factors for perinatal transmission
    Lynn M Yee
    Donna V McGregor
    Sarah H Sutton
    Patricia M Garcia
    Emily S Miller
    Journal of Perinatology, 2018, 38 : 639 - 644
  • [3] Information Disclosure as a Means to Security
    Rabinovich, Zinovi
    Jiang, Albert Xin
    Jain, Manish
    Xu, Haifeng
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON AUTONOMOUS AGENTS & MULTIAGENT SYSTEMS (AAMAS'15), 2015, : 645 - 653
  • [4] Information Disclosure and the Diffusion of Information Security Attacks
    Mitra, Sabyasachi
    Ransbotham, Sam
    INFORMATION SYSTEMS RESEARCH, 2015, 26 (03) : 565 - 584
  • [5] On the signal realization set in contracting with information disclosure
    Terstiege, Stefan
    ECONOMICS LETTERS, 2018, 163 : 83 - 86
  • [6] The Association Between Information Security and Reward Processing
    West, Robert
    Malley, Kaitlyn
    INFORMATION SYSTEMS AND NEUROSCIENCE, NEUROIS RETREAT 2020, 2020, 43 : 298 - 306
  • [7] Controls Mitigating the Risk of Confidential Information Disclosure by Facebook: Essential Concern in Auditing Information Security
    Kuyumdzhiev, Ivan Ognyanov
    TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2014, 3 (02): : 113 - 119
  • [8] Information Disclosure, Security, and Data Quality
    Zaman, A. N. K.
    Obimbo, Charlie
    Dara, Rozita A.
    RECENT TRENDS AND FUTURE TECHNOLOGY IN APPLIED INTELLIGENCE, IEA/AIE 2018, 2018, 10868 : 768 - 779
  • [9] Information disclosure and security information protection at water utilities
    Herrick, Charles
    Blaha, Frank J.
    JOURNAL AMERICAN WATER WORKS ASSOCIATION, 2007, 99 (11): : 40 - 42
  • [10] Realization of Information Security in Electronic Commerce
    Li Fu-Guo
    Dong Yu-Jie
    THIRD INTERNATIONAL SYMPOSIUM ON COMPUTER SCIENCE AND COMPUTATIONAL TECHNOLOGY (ISCSCT 2010), 2010, : 14 - 16