【24h】

A CONCEPTUAL MODEL FOR INFORMATION SECURITY AND ITS IMPLICATIONS FOR INFORMATION INSURANCE

机译:信息安全的概念模型及其对信息保险的启示

获取原文
获取原文并翻译 | 示例

摘要

Over the last few years, information security has been receiving a significant amount of society's attention. However, a fundamental question is still being continually asked: what on earth is information security? In the authors' opinion, although information security has a technological component, it is not a problem that technology can fully solve. This issue is increasingly shifting from what is technically possible to what is economically optimal. In other words, the management of information security is a much deeper and more political problem than is usually realized. Traditional solutions are bound to fail for good technical reasons and good business reasons. A new approach is required. Based on these understandings, this paper presents a conceptual framework and a contingency model for analyzing current initiatives on managing information security. Equally important, the authors propose as well a set of priorities for managerial attention that is contingent upon user's stage of information security activities. Further, the increased vulnerability to substantial economic loss from attacks through information systems is causing many executives to seek additional tools to manage information security risk. One new tool is the use of recently developed information insurance policies (that is, policies that provide coverage against losses from information-related breaches in information system). This paper also proposes some implications for designing information insurance policies in the respects of pricing, adverse selection, and moral hazard.
机译:在过去的几年中,信息安全受到社会的广泛关注。但是,仍在不断问一个基本问题:信息安全到底是什么?作者认为,尽管信息安全具有技术成分,但技术可以完全解决这一问题。这个问题越来越多地从技术上的可能转变为经济上的最佳。换句话说,信息安全的管理比通常意识到的要深得多,政治上也要多。传统解决方案由于技术原因和商业原因而注定会失败。需要一种新方法。基于这些理解,本文提出了一个概念框架和权变模型,用于分析当前管理信息安全的计划。同样重要的是,作者还提出了一系列的管理注意事项,这取决于用户的信息安全活动阶段。此外,由于通过信息系统的攻击而遭受更大的经济损失的脆弱性增加,导致许多高管寻求其他工具来管理信息安全风险。一种新工具是使用最近开发的信息保险单(即,针对因信息系统中与信息相关的违规而造成的损失提供赔偿的保险)。本文还就定价,逆向选择和道德风险方面的信息保险政策设计提出一些建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号