Incentive Alignment and Risk Perception: An Information Security Application

被引:8
|
作者
Farahmand, Fariborz [1 ,3 ]
Atallah, Mikhail J. [2 ]
Spafford, Eugene H. [1 ,3 ]
机构
[1] Purdue Univ, Ctr Educ & Res Informat Assurance & Secur, W Lafayette, IN 47907 USA
[2] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
[3] Purdue Univ, W Lafayette, IN 47907 USA
基金
美国国家科学基金会;
关键词
Alignment; decision-making; incentives; information security; perceptions; risk; ENOUGH;
D O I
10.1109/TEM.2012.2185801
中图分类号
F [经济];
学科分类号
02 ;
摘要
Technologies and procedures for effectively securing the enterprise in cyberspace exist, but are largely underdeployed. Reasons for this shortcoming include the neglect of the role of stakeholder perceptions in organizational reward systems, and misaligned incentives for effective allocation of resources. We present a methodology for practitioners to employ, with examples for identification of perverse incentives-situations where the interests of a manager or employee are not aligned with those of the organization-and for estimation of the damage caused by incentive misalignment. We present our revision to the risk perception model developed by Fischhoff and Slovic. We also present the results of our findings from our interviews of 42 information security executives across the U.S. about the role of risk perception and incentives in information security decisions. We discuss how to identify and to correct misalignments, to develop efficient incentive structures, and to include perceptual principles and security governance in making information security a property of the organizational environment. This research contributes to the practice and theory of information security, and has several implications for practitioners and researchers in the alignment of incentives and symmetrization of information across organizations.
引用
收藏
页码:238 / 246
页数:9
相关论文
共 50 条
  • [1] Risk communication, risk perception and information security
    Pattinson, M
    Anderson, G
    [J]. Security Management, Integrity, and Internal Control in Information Systems, 2005, 193 : 175 - 184
  • [2] Survey on Information System Security Risk Management alignment
    Abbass, Wissam
    Baina, Amine
    Bellafkih, Mostafa
    [J]. 2016 INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY FOR ORGANIZATIONS DEVELOPMENT (IT4OD), 2016,
  • [3] Alignment of Perception Information for Cooperative Perception
    Allig, Christoph
    Wanielik, Gerd
    [J]. 2019 30TH IEEE INTELLIGENT VEHICLES SYMPOSIUM (IV19), 2019, : 1849 - 1854
  • [4] Perception of information security
    Huang, Ding-Long
    Rau, Pei-Luen Patrick
    Salvendy, Gavriel
    [J]. BEHAVIOUR & INFORMATION TECHNOLOGY, 2010, 29 (03) : 221 - 232
  • [5] Matlab Application for Information Security Risk Analysis
    Buldakova, T., I
    Mikov, D. A.
    [J]. INTERNATIONAL SCIENTIFIC AND PRACTICAL CONFERENCE MODELING IN EDUCATION 2019, 2019, 2195
  • [6] Investigating effects of security incident awareness on information risk perception
    Volpentesta, Antonio P.
    Ammirato, Salvatore
    Palmieri, Roberto
    [J]. INTERNATIONAL JOURNAL OF TECHNOLOGY MANAGEMENT, 2011, 54 (2-3) : 304 - 320
  • [7] An Application of Probabilistic Risk Assessment to Information Security Audit
    Satoh, Naoki
    Kumamoto, Hiromitsu
    [J]. AIC '09: PROCEEDINGS OF THE 9TH WSEAS INTERNATIONAL CONFERENCE ON APPLIED INFORMATICS AND COMMUNICATIONS: RECENT ADVANCES IN APPLIED INFORMAT AND COMMUNICATIONS, 2009, : 436 - +
  • [8] Firm objectives, IT alignment, and information security
    Anderson, E. E.
    [J]. IBM JOURNAL OF RESEARCH AND DEVELOPMENT, 2010, 54 (03)
  • [9] Integrating Information Security Policy Management with Corporate Risk Management for Strategic Alignment
    Corpuz, Maria Soto
    Barnes, Paul
    [J]. WMSCI 2010: 14TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL III, 2010, : 337 - 342
  • [10] Information, incentive alignment, and company loan financing of insider trades
    Garfinkel, Jon A.
    Kahle, Kathleen
    Shastri, Kuldeep
    [J]. FINANCIAL MANAGEMENT, 2007, 36 (04) : 67 - 87