Financial data breaches in the US retail economy: Restoring confidence in information technology security standards

被引:17
|
作者
Hemphill, Thomas A. [1 ]
Longstreet, Phil [2 ]
机构
[1] Univ Michigan Flint, Sch Management, 2118 Riverfront Ctr,303 East Kearsley St, Flint, MI 48502 USA
[2] Univ Michigan Flint, Sch Management, 2145 Riverfront Ctr,303 East Kearsley St, Flint, MI 48502 USA
关键词
Cybercrime; Cyber liability insurance coverage; Data breaches; Industry self-regulation; Public regulation; Standards-setting; INDUSTRY SELF-REGULATION;
D O I
10.1016/j.techsoc.2015.11.007
中图分类号
D58 [社会生活与社会问题]; C913 [社会生活与社会问题];
学科分类号
摘要
Managing effective security of personal customer data located in computer networks has become a strategic business and public policy issue for the U.S. retail sector. The article discusses the global credit card payment industry self-regulation regime established by the Payment Card Industry Security Standards Council ("Council") to combat cybercrime, comparing and evaluating the Council's existing standards regime to the theory and practices found in the industry self-regulation literature. A review of national cybercrime trends in both the volume and financial impacts ("losses") of electronic financial record breaches on the U.S. retail sector is presented. After identifying the primary areas of retail electronic records breach vulnerability, an improved industry standards framework is developed that proposes to enhance security and minimize data privacy compromises through the adoption of recommended pure industry self-regulation (improved "security standard") and market force mechanisms (mandatory "cyber liability insurance coverage"). The article concludes with a discussion of the implementation of the proposed industry self-regulation and market force framework; its current limitations; and what technology advancements may bring in the future to provide more effective security and protection for consumers' personal data and financial transactions. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:30 / 38
页数:9
相关论文
共 50 条
  • [1] Security breaches threaten personal and financial data
    Schultz, E
    [J]. COMPUTERS & SECURITY, 2004, 23 (04) : 269 - 270
  • [2] The financial crisis in the US 20082009: losing and restoring confidence
    Swedberg, Richard
    [J]. SOCIO-ECONOMIC REVIEW, 2013, 11 (03) : 501 - 523
  • [3] Information technology and the US economy
    Jorgenson, DW
    [J]. AMERICAN ECONOMIC REVIEW, 2001, 91 (01): : 1 - 32
  • [4] Information technology and the US economy
    Jorgenson, DW
    [J]. ECONOMIC POLICY ISSUES OF THE NEW ECONOMY, 2002, : 37 - 79
  • [5] SECURITY EVALUATION IN INFORMATION TECHNOLOGY STANDARDS
    GENTILE, F
    GIURI, L
    GUIDA, F
    MONTOLIVO, E
    VOLPE, M
    [J]. COMPUTERS & SECURITY, 1994, 13 (08) : 647 - 650
  • [6] WHERE IS IT IN INFORMATION SECURITY? THE INTERRELATIONSHIP AMONG IT INVESTMENT, SECURITY AWARENESS, AND DATA BREACHES
    Li, Wilson Weixun
    Leung, Alvin Chung Man
    Yue, Wei Thoo
    [J]. MIS QUARTERLY, 2023, 47 (01) : 317 - 342
  • [7] Trends of international standards for information security technology
    Moriai, S
    Fujioka, A
    [J]. NTT REVIEW, 2003, 15 (02): : 47 - 52
  • [8] Assessing liability arising from information security breaches in data privacy
    Mitrakas, Andreas
    [J]. INTERNATIONAL DATA PRIVACY LAW, 2011, 1 (02) : 129 - 136
  • [9] Analytical Techniques for Decision Making on Information Security for Big Data Breaches
    Albeshri, Aiiad
    Thayananthan, Vijey
    [J]. INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY & DECISION MAKING, 2018, 17 (02) : 527 - 545
  • [10] Research of information technology security in the financial industry
    Xia Bin
    Bai Hui
    Pan Bin
    [J]. FIRST INTERNATIONAL WORKSHOP ON KNOWLEDGE DISCOVERY AND DATA MINING, PROCEEDINGS, 2007, : 477 - 480