Unrealistic optimism on information security management

被引:77
作者
Rhee, Hyeun-Suk [1 ]
Ryu, Young U. [2 ]
Kim, Cheong-Tag [3 ]
机构
[1] United Nat Asian & Pacific Training Ctr Informat, Inchon, South Korea
[2] Univ Texas Dallas, Sch Management, Richardson, TX 75090 USA
[3] Seoul Natl Univ, Sch Social Sci, Dept Psychol, Seoul 151742, South Korea
关键词
Information security; Awareness; Optimistic bias; Risk perception; Perceived controllability; Risk management; PERCEIVED CONTROL; SELF; RISK; BIAS; BEHAVIOR; CONTROLLABILITY; VULNERABILITY; PERCEPTIONS; ILLUSION; SYSTEMS;
D O I
10.1016/j.cose.2011.12.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information security is a critical issue that many firms face these days. While increasing incidents of information security breaches have generated extensive publicity, previous studies repeatedly expose low levels of managerial awareness and commitment, a key obstacle to achieving a good information security posture. The main motivation of our study emanates from this phenomenon that the increased vulnerability to information security breaches is coupled with the low level of managerial awareness and commitment regarding information security threats. We report this dissonance by addressing a cognitive bias called optimistic bias. Using a survey, we study if MIS executives are subject to such a bias in their vulnerability perceptions of information security. We find that they demonstrate optimistic bias in risk perception on information security domain. The extent of this optimistic bias is greater with a distant comparison target with fewer information sharing activities. This optimistic bias is also found to be related to perception of controllability with information security threats. In order to overcome the effects of optimistic bias, firms need more security awareness training and systematic treatments of security threats instead of relying on ad hoc approach to security measure implementation. (c) 2011 Elsevier Ltd. All rights reserved.
引用
收藏
页码:221 / 232
页数:12
相关论文
共 50 条
[41]   Association between unrealistic comparative optimism and self-management in individuals with type 2 diabetes: Results from a cross-sectional, population-based study [J].
Karl, Florian M. ;
Holle, Rolf ;
Schwettmann, Lars ;
Peters, Annette ;
Meisinger, Christa ;
Rueckert-Eheberg, Ina-Maria ;
Laxy, Michael .
HEALTH SCIENCE REPORTS, 2020, 3 (02) :1-14
[42]   Unrealistic optimism about treatment risks for acute appendicitis [J].
Rosen, Joshua E. ;
Agrawal, Nidhi ;
Flum, David R. ;
Liao, Joshua M. .
BRITISH JOURNAL OF SURGERY, 2022, 109 (05) :405-407
[43]   Improving Organisational Information Security Management: The Impact of Training and Awareness [J].
Waly, Nesren ;
Tassabehji, Rana ;
Kamala, Mumtaz .
2012 IEEE 14TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS & 2012 IEEE 9TH INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (HPCC-ICESS), 2012, :1270-1275
[44]   Revisiting information security risk management challenges: a practice perspective [J].
Bergstrom, Erik ;
Lundgren, Martin ;
Ericson, Asa .
INFORMATION AND COMPUTER SECURITY, 2019, 27 (03) :358-372
[45]   Implementing a risk management approach for optimizing information security systems [J].
Petrescu, Marius ;
Stegaroiu, Ion ;
Braboveanu, Mioara ;
Petrescu, Anca-Gabriela ;
Sirbu, Nicoleta .
BUSINESS TRANSFORMATION THROUGH INNOVATION AND KNOWLEDGE MANAGEMENT: AN ACADEMIC PERSPECTIVE, VOLS 1-2, 2010, :304-309
[46]   Study on Information Security of Industry Management [J].
Li Xuemei ;
Li Yan ;
Ding Lixing .
2009 ASIA-PACIFIC CONFERENCE ON INFORMATION PROCESSING (APCIP 2009), VOL 1, PROCEEDINGS, 2009, :522-+
[47]   The Quantification Management of Information Security Risk [J].
Lao, Guoling ;
Wang, Liping .
2008 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-31, 2008, :10377-10380
[48]   Information Security management: A human challenge? [J].
Department of Informatics and Sensors, Cranfield University, Swindon, SN6 8LA, United Kingdom .
Inf Secur Tech Rep, 2008, 4 (195-201) :195-201
[49]   Information Security Management Method for Households [J].
Murane, Ilze .
DATABASES AND INFORMATION SYSTEMS VI: SELECTED PAPERS FROM THE NINTH INTERNATIONAL BALTIC CONFERENCE (DB&IS 2010), 2011, 224 :353-366
[50]   Reducing unrealistic optimism in a national tobacco prevention campaign in Switzerland [J].
Poggiolini, Claudia ;
Wirth, Werner .
SCM STUDIES IN COMMUNICATION AND MEDIA, 2021, 10 (04) :557-589