An economic mechanism to manage operational security risks for inter-organizational information systems

被引:12
|
作者
Fang, Fang [1 ]
Parameswaran, Manoj [2 ]
Zhao, Xia [3 ]
Whinston, Andrew B. [4 ]
机构
[1] Calif State Univ San Marcos, Dept ISOM, San Marcos, CA 92096 USA
[2] Univ Washington, Dept ISOM, Seattle, WA 98195 USA
[3] Univ N Carolina, Dept ISOM, Greensboro, NC 27402 USA
[4] Univ Texas Austin, Dept IROM, Austin, TX 78712 USA
基金
美国国家科学基金会;
关键词
Inter-organizational information systems; Information security; Risk management; Economics of information systems; Economic mechanisms; ELECTRONIC DATA INTERCHANGE; INTERNET; MARKET; MODEL;
D O I
10.1007/s10796-012-9348-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As organizations increasingly deploy Inter-organizational Information Systems (IOS), the interdependent security risk they add is a problem affecting market efficiency. Connected organizations become part of entire networks, and are subject to threats from the entire network; but members' security profile information is private, members lack incentives to minimize impact on peers and are not accountable. We model the problem as a signaling-screening game, and outline an incentive mechanism that addresses these problems. Our mechanism proposes formation of secure communities of organizations anchored by Security Compliance Consortium (SCC), with members held accountable to the community for security failures. We study the interconnection decisions with and without the mechanism, and characterize conditions where the mechanism plays roles of addressing moral hazard and hidden information issues by screening the organizations' security types and/or by providing them incentives to improve. We also discuss the welfare gains and the broad impact of the mechanism.
引用
收藏
页码:399 / 416
页数:18
相关论文
共 50 条
  • [1] An economic mechanism to manage operational security risks for inter-organizational information systems
    Fang Fang
    Manoj Parameswaran
    Xia Zhao
    Andrew B. Whinston
    [J]. Information Systems Frontiers, 2014, 16 : 399 - 416
  • [3] INFORMATION SYSTEMS AND INTER-ORGANIZATIONAL SPACE
    JUDGE, AJN
    [J]. ANNALS OF THE AMERICAN ACADEMY OF POLITICAL AND SOCIAL SCIENCE, 1971, 393 (JAN): : 47 - 64
  • [4] Implementation of a Security Access Control Model for Inter-Organizational Healthcare Information Systems
    Chi, Hongmei
    Jones, Edward L.
    Zhao, Lang
    [J]. 2008 IEEE ASIA-PACIFIC SERVICES COMPUTING CONFERENCE, VOLS 1-3, PROCEEDINGS, 2008, : 692 - 696
  • [5] Planning for Inter-Organizational Information Systems in Practice
    Makipaa, Marko
    [J]. NORDIC CONTRIBUTIONS IN IS RESEARCH, 2011, 86 : 98 - 111
  • [6] Data Sovereignty in Inter-organizational Information Systems
    Opriel, Sebastian
    Moeller, Frederik
    Strobel, Gero
    Otto, Boris
    [J]. BUSINESS & INFORMATION SYSTEMS ENGINEERING, 2024,
  • [7] Inter-organizational Information Systems in the Inter-firm Networks
    Sheresheva, M. YU.
    [J]. ROSSIISKII ZHURNAL MENEDZHMENTA, 2006, 4 (01): : 55 - 76
  • [8] INTER-ORGANIZATIONAL INFORMATION-SYSTEMS AS COMPANY RESOURCES
    SUOMI, R
    [J]. INFORMATION & MANAGEMENT, 1988, 15 (02) : 105 - 112
  • [9] Configuration Analysis of Inter-Organizational Information Systems Adoption
    Lyytinen, Kalle
    Damsgaard, Jan
    [J]. SCANDINAVIAN INFORMATION SYSTEMS RESEARCH, 2010, 60 : 127 - +
  • [10] Enhancing the Quality of Information in Inter-Organizational Environmental Reporting Information Systems
    Thies, Hans
    Stanoevska-Slabeva, Katarina
    [J]. PROCEEDINGS OF THE 46TH ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2013, : 3495 - 3504