Effect of security investment strategy on the business value of managed security service providers

被引:9
|
作者
Feng, Nan [1 ]
Wang, Meiyun [1 ]
Li, Minqiang [1 ]
Li, Dahui [2 ]
机构
[1] Tianjin Univ, Coll Management & Econ, Tianjin 300072, Peoples R China
[2] Univ Minnesota Duluth, Labovitz Sch Business & Econ, Duluth, MN 55812 USA
基金
中国国家自然科学基金;
关键词
Managed security service; Security investment; Business value; System dynamics; INFORMATION-SECURITY; E-COMMERCE; DYNAMICS; MODEL; RETURNS; SYSTEMS; GAME;
D O I
10.1016/j.elerap.2019.100843
中图分类号
F [经济];
学科分类号
02 ;
摘要
Managed security service providers (MSSPs) have long provided clients with cost-effective methods and professional solutions for addressing issues related to information security. MSSPs provide three categories of security services, namely, prevention, detection, and response, to satisfy their clients' security requirements and realize business value. This study develops a system dynamics model of the correlation between the security investment strategies of an MSSP and the effect of its business value. Simulations under opportunistic and targeted attacks are performed to discuss the effects of the various security investment strategies of an MSSP on its business value. The study results indicate that investing in prevention has a stronger effect on the business value of an MSSP than investing in detection and response and that security investments on opportunistic attacks are more efficient than those on targeted attacks. Sensitivity analysis shows the robustness of the system dynamics model proposed in this study.
引用
收藏
页数:16
相关论文
共 50 条
  • [41] Trust, tenure security and investment in high-value forests
    Hadera, Amanuel
    Tadesse, Tewodros
    Zeweld, Woldegebrial
    Tesfay, Girmay
    Gebremedhin, Bereket
    FOREST POLICY AND ECONOMICS, 2024, 166
  • [42] Cloud Computing Service Security and Access: From the Providers and Customers' Perspective
    Zhao, Xianghui
    Liu, Hui
    Yi, Jin
    Tian, Wen
    Luo, Ning
    Ye, Lin
    2013 INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND APPLICATIONS (ITA), 2013, : 379 - 383
  • [43] A study on AI algorithms to improve precision rate in a managed security service
    Choi S.
    Jang M.
    Kim M.
    Transactions of the Korean Institute of Electrical Engineers, 2020, 69 (07): : 1046 - 1052
  • [44] Towards performance evaluation of cloud service providers for cloud data security
    Ramachandran, Muthu
    Chang, Victor
    INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2016, 36 (04) : 618 - 625
  • [45] Improve Security over Multiple Cloud Service Providers for Resource Allocation
    Surbiryala, Jayachander
    Agrawal, Bikash
    Rong, Chunming
    2018 1ST INTERNATIONAL CONFERENCE ON DATA INTELLIGENCE AND SECURITY (ICDIS 2018), 2018, : 145 - 148
  • [46] Development of Indicators for Information Security Level Assessment of VoIP Service Providers
    Yoon, Seokung
    Park, Haeryong
    Yoo, Hyeong Seon
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2014, 8 (02): : 634 - 645
  • [47] Contracting managed security service: Double moral hazard and risk interdependency
    Feng, Nan
    Zhang, Shiyue
    Li, Minqiang
    Li, Dahui
    ELECTRONIC COMMERCE RESEARCH AND APPLICATIONS, 2021, 50
  • [48] Security Evaluation of Cloud Service Providers Using Third Party Auditors
    Rizvi, Syed S.
    Bolish, Trent A.
    Pfeffer, Joseph R., III
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, DATA AND CLOUD COMPUTING (ICC 2017), 2017,
  • [49] Security Policy Implementation Strategies for Common Carrier Monitoring Service Providers
    Gunter, Carl A.
    2009 IEEE INTERNATIONAL SYMPOSIUM ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, 2009, : 114 - 117
  • [50] Security-aware Business Process as a Service by hiding provenance
    Bentounsi, Mehdi
    Benbernou, Salima
    Atallah, Mikhail J.
    COMPUTER STANDARDS & INTERFACES, 2016, 44 : 220 - 233