Investments in Information Security: A Real Options Perspective with Bayesian Postaudit

成果类型:
Article
署名作者:
Herath, Hemantha S. B.; Herath, Tejaswini C.
署名单位:
Brock University; University of Northern British Columbia; The World Bank
刊物名称:
JOURNAL OF MANAGEMENT INFORMATION SYSTEMS
ISSN/ISSBN:
0742-1222
DOI:
10.2753/MIS0742-1222250310
发表日期:
2008
页码:
337-375
关键词:
technology decisions projects systems
摘要:
The application of real options techniques to information security is significantly different than in the case of general information technology investments due to characteristics unique to information security. Emerging research in the economics of information security has suggested real options analysis (ROA) as a potential technique for assessing the value of information security assets, but has focused primarily on the most effective level of investment and the configuration of intrusion prevention/detection systems. In this paper, we attempt to address significant gaps ill the literature by developing an integrated real options model for information security investments using Bayesian statistics that Incorporates learning and postauditing in the analysis. By using the proposed model with actual data on e-mail and Spain, we demonstrate that ROA with Bayesian postauditing offers a systematic valuation and risk management framework for evaluating information security spending by firms. We also discuss the managerial implications.