Information Security as a Credence Good

被引:0
|
作者
Ke, Ping Fan [1 ]
Hui, Kai-Lung [1 ]
Yue, Wei T. [2 ]
机构
[1] Hong Kong Univ Sci & Technol, Hong Kong, Hong Kong, Peoples R China
[2] City Univ Hong Kong, Kowloon, Peoples R China
来源
FINANCIAL CRYPTOGRAPHY AND DATA SECURITY: FC 2013 WORKSHOPS | 2013年 / 7862卷
关键词
Information security outsourcing; credence good; interdependency risks; ECONOMICS; EXPERTS;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With increasing use of information systems, many organizations are outsourcing information security protection to a managed security service provider (MSSP). However, diagnosing the risk of an information system requires special expertise, which could be costly and difficult to acquire. The MSSP may exploit their professional advantage and provide fraudulent diagnosis of clients' vulnerabilities. Such an incentive to mis-represent clients' risks is often called the credence goods problem in the economics literature[3]. Although different mechanisms have been introduced to tackle the credence goods problem, in the information security outsourcing context, such mechanisms may not work well with the presence of system interdependency risks[6], which are introduced by inter-connecting multiple clients' systems by the MSSP. In particular, we find that allowing clients to seek alternative diagnosis of their vulnerabilities may not remove the MSSP's fraudulent behaviors. We shall explore alternative ways to solve the credence goods problem in the information security outsourcing context.
引用
收藏
页码:83 / 93
页数:11
相关论文
共 50 条
  • [1] Pricing for a credence good: an exploratory analysis
    Nagler, Matthew
    Kronenberg, Fredi
    Kennelly, Edward
    Jiang, Bei
    JOURNAL OF PRODUCT AND BRAND MANAGEMENT, 2011, 20 (03): : 238 - 249
  • [2] Equilibrium information in credence goods
    Liu, Ting
    Ma, Ching-to Albert
    GAMES AND ECONOMIC BEHAVIOR, 2024, 145 : 84 - 101
  • [3] Occupational licensing of a credence good: The regulation of midwifery
    Adams, AF
    Ekelund, RB
    Jackson, JD
    SOUTHERN ECONOMIC JOURNAL, 2003, 69 (03) : 659 - 675
  • [4] The influence of a good relationship between the internal audit and information security functions on information security outcomes
    Steinbart, Paul John
    Raschke, Robyn L.
    Gal, Graham
    Dilla, William N.
    ACCOUNTING ORGANIZATIONS AND SOCIETY, 2018, 71 : 15 - 29
  • [5] ARTIFICIAL INTELLIGENCE FOR GOOD AND BAD IN CYBER AND INFORMATION SECURITY
    Kasakliev, Nikolay
    Somova, Elena
    Gocheva, Margarita
    MATHEMATICS AND INFORMATICS, 2024, 67 (01): : 82 - 94
  • [6] Optimal procurement of a credence good under limited liability
    Bester, Helmut
    Ouyang, Yaofu
    INTERNATIONAL JOURNAL OF INDUSTRIAL ORGANIZATION, 2018, 61 : 96 - 129
  • [7] Preventive-service fraud in credence good markets
    Karni, Edi
    ECONOMIC THEORY, 2024, 78 (02) : 593 - 617
  • [8] Competition and Endogenous Impatience in Credence-Good Markets
    Sandford, Jeremy
    JOURNAL OF INSTITUTIONAL AND THEORETICAL ECONOMICS-ZEITSCHRIFT FUR DIE GESAMTE STAATSWISSENSCHAFT, 2013, 169 (03): : 531 - 565
  • [9] A performance-based payment: Signaling the quality of a credence good
    Berg, Nathan
    Kim, Jeong-Yoo
    Seon, Ilgyun
    MANAGERIAL AND DECISION ECONOMICS, 2021, 42 (05) : 1117 - 1131
  • [10] Championing and shaming in a credence good market: Which one to use?
    Volle, Alexandre
    Gonzalez, Patrick
    JOURNAL OF ECONOMICS & MANAGEMENT STRATEGY, 2024, 33 (04) : 937 - 957