Information Availability as Driver of Information Security Investments: A Systematic Review Approach

被引:0
作者
Dang, Duy [1 ]
Nkhoma, Mathews [1 ]
机构
[1] RMIT Int Univ, Ho Chi Minh City, Vietnam
来源
PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS MANAGEMENT AND EVALUATION (ICIME 2013) | 2013年
关键词
information security; investment; information sharing; systematic review; driver; information availability; RISK; DECISIONS; IMPACT;
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
Despite that information security issues have started to gain managers' attention since computers were first put in use, information security management has not yet reached its maturity and is still requiring input from both the academia and industry. Indeed, today's businesses have still not been widely convinced to invest in information security initiatives, resulting in the shrinking budget allocated for organisational information security. One common finding shows that organisational awareness towards information security can serve as a great driver that would help firms realise the business values of such investments. In addition, such emphasis on the awareness suggests the essential role of training, education and dissemination of quality information. As a result, one could argue that the available information has an indirect influence on the adoption rate of information security, through the impact of awareness. This research analyses the possibility of whether information availability could directly drive the intention to invest in information security initiatives by removing the uncertainty surrounding such investments. In other words, information availability per se could drive investing intention by reducing the obstacle - its uncertainty - rather than stimulate business needs through the enforcing of another factor that is awareness. Through intensive reviews on the literature, this paper synthesises and reports on the definition of information availability and how it could drive the intention to invest in information security. Specifically, the researchers examine the driving force of internal information (risk management, staff suggestions), external information (consultants, external audit) and general information (white papers, security reports). By exploring the direct relationship between information availability and intention to invest in information security, more practical recommendations and directions to promote organisational information security can be suggested. Before that, the researchers aim to update the readers with an understanding of the role of information availability in information security management.
引用
收藏
页码:71 / 80
页数:10
相关论文
共 30 条
[11]   Budgeting process for information security expenditures [J].
Gordon, LA ;
Loeb, MP .
COMMUNICATIONS OF THE ACM, 2006, 49 (01) :121-125
[12]   An economic analysis of the optimal information security investment in the case of a risk-averse firm [J].
Huang, C. Derrick ;
Hu, Qing ;
Behara, Ravi S. .
INTERNATIONAL JOURNAL OF PRODUCTION ECONOMICS, 2008, 114 (02) :793-804
[13]   Security through Information Risk Management [J].
Johnson, M. Eric ;
Goetz, Eric ;
Pfleeger, Shari Lawrence .
IEEE SECURITY & PRIVACY, 2009, 7 (03) :45-52
[14]  
Kleinfeld A., 2006, Information Systems Security, V15, P7, DOI 10.1201/1086.1065898X/46353.15.4.20060901/95426.2
[15]  
LESK M, 2011, IEEE SECUR PRIV, V9, P76
[16]   Knowledge sharing and investment decisions in information security [J].
Liu, Dengpan ;
Ji, Yonghua ;
Mookerjee, Vijay .
DECISION SUPPORT SYSTEMS, 2011, 52 (01) :95-107
[17]   Optimizing Product Improvement Spending with Third-Party Security Consultants [J].
Matthews, Bronwen .
IEEE SECURITY & PRIVACY, 2012, 10 (01) :91-93
[18]   Perception of risk and the strategic impact of existing IT on information security strategy at board level [J].
McFadzean, Elspeth ;
Ezingeard, Jean-Noel ;
Birchall, David .
ONLINE INFORMATION REVIEW, 2007, 31 (05) :622-660
[19]  
Moore T., 2011, The Oxford Handbook of the Digital Economy
[20]   The economics of cybersecurity: Principles and policy options [J].
Moore, Tyler .
INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2010, 3 (3-4) :103-117