Choice and Chance: A Conceptual Model of Paths to Information Security Compromise
成果类型:
Article
署名作者:
Ransbotham, Sam; Mitra, Sabyasachi
署名单位:
Boston College; University System of Georgia; Georgia Institute of Technology
刊物名称:
INFORMATION SYSTEMS RESEARCH
ISSN/ISSBN:
1047-7047
DOI:
10.1287/isre.1080.0174
发表日期:
2009
页码:
121-139
关键词:
computer abuse
crime
systems
MARKET
PUNISHMENT
management
judgments
ETHICS
issues
摘要:
No longer the exclusive domain of technology experts, information security is now a management issue. Through a grounded approach using interviews, observations, and secondary data, we advance a model of the information security compromise process from the perspective of the attacked organization. We distinguish between deliberate and opportunistic paths of compromise through the Internet, labeled choice and chance, and include the role of countermeasures, the Internet presence of the firm, and the attractiveness of the firm for information security compromise. Further, using one year of alert data from intrusion detection devices, we find empirical support for the key contributions of the model. We discuss the implications of the model for the emerging research stream on information security in the information systems literature.