Incentive Alignment and Risk Perception: An Information Security Application

被引:8
|
作者
Farahmand, Fariborz [1 ,3 ]
Atallah, Mikhail J. [2 ]
Spafford, Eugene H. [1 ,3 ]
机构
[1] Purdue Univ, Ctr Educ & Res Informat Assurance & Secur, W Lafayette, IN 47907 USA
[2] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
[3] Purdue Univ, W Lafayette, IN 47907 USA
基金
美国国家科学基金会;
关键词
Alignment; decision-making; incentives; information security; perceptions; risk; ENOUGH;
D O I
10.1109/TEM.2012.2185801
中图分类号
F [经济];
学科分类号
02 ;
摘要
Technologies and procedures for effectively securing the enterprise in cyberspace exist, but are largely underdeployed. Reasons for this shortcoming include the neglect of the role of stakeholder perceptions in organizational reward systems, and misaligned incentives for effective allocation of resources. We present a methodology for practitioners to employ, with examples for identification of perverse incentives-situations where the interests of a manager or employee are not aligned with those of the organization-and for estimation of the damage caused by incentive misalignment. We present our revision to the risk perception model developed by Fischhoff and Slovic. We also present the results of our findings from our interviews of 42 information security executives across the U.S. about the role of risk perception and incentives in information security decisions. We discuss how to identify and to correct misalignments, to develop efficient incentive structures, and to include perceptual principles and security governance in making information security a property of the organizational environment. This research contributes to the practice and theory of information security, and has several implications for practitioners and researchers in the alignment of incentives and symmetrization of information across organizations.
引用
收藏
页码:238 / 246
页数:9
相关论文
共 50 条
  • [41] The Information Security Risk Management
    Semin, Valeriy G.
    Shmakova, Elena G.
    Los, Lexei B.
    [J]. PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE QUALITY MANAGEMENT,TRANSPORT AND INFORMATION SECURITY, INFORMATION TECHNOLOGIES (IT&QM&IS), 2017, : 106 - 109
  • [42] Information security and risk management
    Bodin, Lawrence D.
    Gordon, Lawrence A.
    Loeb, Martin P.
    [J]. COMMUNICATIONS OF THE ACM, 2008, 51 (04) : 64 - 68
  • [43] Information security: Risk and reward
    Gauci, Donald
    [J]. JPT, Journal of Petroleum Technology, 2007, 59 (05): : 38 - 39
  • [44] Factors affecting perception of information security and their impacts on IT adoption and security practices
    Huang, Ding-Long
    Rau, Pei-Luen Patrick
    Salvendy, Gavriel
    Gao, Fei
    Zhou, Jia
    [J]. INTERNATIONAL JOURNAL OF HUMAN-COMPUTER STUDIES, 2011, 69 (12) : 870 - 883
  • [45] Information security and organizational change perception: Influences on security attitudes and behaviors
    Arantes, Talita
    Neiva, Elaine
    [J]. INTERNATIONAL JOURNAL OF PSYCHOLOGY, 2012, 47 : 487 - 487
  • [46] Social Perception on Security Risk - A Missing Element of the Security Culture
    Chiru, Irena
    [J]. 5TH RSEP INTERNATIONAL CONFERENCES ON SOCIAL ISSUES AND ECONOMIC STUDIES, 2017, : 109 - 109
  • [47] Using Measures of Risk Perception to Predict Information Security Behavior: Insights from Electroencephalography (EEG)
    Vance, Anthony
    Anderson, Bonnie Brinton
    Kirwan, C. Brock
    Eargle, David
    [J]. JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2014, 15 (10): : 679 - 722
  • [48] Understanding the Incentive Mechanism of Penalty for Information Security Policy Compliance Behavior
    Wang, Xiaolong
    Li, Wenli
    [J]. 2018 7TH INTERNATIONAL CONFERENCE ON SOCIAL SCIENCE, EDUCATION AND HUMANITIES RESEARCH (SSEHR 2018), 2018, : 19 - 25
  • [50] Information seeking and workplace safety: A field application of the risk perception attitude framework
    Real, Kevin
    [J]. JOURNAL OF APPLIED COMMUNICATION RESEARCH, 2008, 36 (03) : 339 - 359