Returns to information security investment: Endogenizing the expected loss

被引:19
|
作者
Hausken, Kjell [1 ]
机构
[1] Univ Stavanger, Fac Social Sci, N-4036 Stavanger, Norway
关键词
Security investment; Information protection; Information production; Returns assumptions;
D O I
10.1007/s10796-012-9390-9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper endogenizes the value of an information set which has to be produced and protected. The profit is inverse U shaped in security investment and production effort. The breach probability is commonly assumed to decrease convexly in security investment, which means that modest security investment is sufficient to deter most perpetrators. We allow the breach probability to be not only convex, but concave, which means that substantial security investment is needed to deter most perpetrators. Convexity versus concavity depends on the security environment, perpetrators, technology, and law enforcement. A firm strikes a balance between producing and protecting an information set dependent on seven model parameters for production, protection, convexity, concavity, vulnerability, and resource strength.
引用
收藏
页码:329 / 336
页数:8
相关论文
共 50 条
  • [21] IMPUTING EXPECTED SECURITY RETURNS FROM PORTFOLIO COMPOSITION
    SHARPE, WF
    JOURNAL OF FINANCIAL AND QUANTITATIVE ANALYSIS, 1974, 9 (03) : 463 - 472
  • [22] Expected return—expected loss approach to optimal portfolio investment
    Pavlo Blavatskyy
    Theory and Decision, 2023, 94 : 63 - 81
  • [23] Optimal investment, growth options, and security returns
    Berk, JB
    Green, RC
    Naik, V
    JOURNAL OF FINANCE, 1999, 54 (05): : 1553 - 1607
  • [24] Expected Returns on University Investment: Survey in the Czech Republic and the UK
    Urbanek, Vaclav
    Marsikova, Katerina
    Rehorova, Pavla
    28TH INTERNATIONAL CONFERENCE ON MATHEMATICAL METHODS IN ECONOMICS 2010, PTS I AND II, 2010, : 646 - +
  • [25] Asymmetric loss functions and the rationality of expected stock returns
    Aretz, Kevin
    Bartram, Soehnke M.
    Pope, Peter F.
    INTERNATIONAL JOURNAL OF FORECASTING, 2011, 27 (02) : 413 - 437
  • [26] Expected return-expected loss approach to optimal portfolio investment
    Blavatskyy, Pavlo
    THEORY AND DECISION, 2023, 94 (01) : 63 - 81
  • [27] Expected benefits of information security investments
    Ryan, Julie J. C. H.
    Ryan, Daniel J.
    COMPUTERS & SECURITY, 2006, 25 (08) : 579 - 588
  • [28] Uncovering expected returns: Information in analyst coverage proxies
    Lee, Charles M. C.
    So, Eric C.
    JOURNAL OF FINANCIAL ECONOMICS, 2017, 124 (02) : 331 - 348
  • [29] THE RELATIONSHIP BETWEEN RISK AND EXPECTED RETURNS WITH INCOMPLETE INFORMATION
    Lopez, German
    Marhuenda, Joaquin
    Nieto, Belen
    INVESTIGACIONES ECONOMICAS, 2009, 33 (01): : 69 - 96
  • [30] The Economics of Information Security Investment
    Wang, Heng
    ADVANCED RESEARCH ON INFORMATION SCIENCE, AUTOMATION AND MATERIAL SYSTEM, PTS 1-6, 2011, 219-220 : 1550 - 1553