Skip to main content
Have a personal or library account? Click to login
Quantitative Model for Economic Analyses of Information Security Investment in an Enterprise Information System Cover

Quantitative Model for Economic Analyses of Information Security Investment in an Enterprise Information System

Open Access
|Jan 2013

References

  1. Acquisti, A., Friedman, A. & Telang, R. (2006). Is there a cost to privacy breaches? An event study. In:UK: Cambridge, Retrieved October 12, 2012 from http://www.heinz.cmu.edu/~acquisti/papers/acquistifriedman-telang-privacy-breaches.pdf
  2. Anderson, R. & Schneier, B. (2005). Guest Editor‘s Introduction: Economics of Information Security., 3(1), 12-13, http://dx.doi.org/10.1109/MSP.2005.14
  3. Anderson, R. (2001). Why information security is hard-an economic perspective, Computer Security Applications. In:, pp. 358-365, http://dx.doi.org/10.1109/ACSAC.2001.991552
  4. Bojanc, R. & Jerman-Blažič, B. (2007). Towards a standard approach for quantifying an ICT security investment., 30(4), 216-222, http://dx.doi.org/10.1016/j.csi.2007.10.013
  5. Bojanc, R. & Jerman-Blažič, B. (2008). An economic modelling approach to information security risk management., 28(5), 413-422, http://dx.doi.org/10.1016/j.ijinfomgt.2008.02.002
  6. Bojanc, R., Jerman-Blažič, B. & Tekavčič, M. (2012). Managing the Investment in Information Security Technology by use of Quantitative Modeling Approach,, 48(6), 1031-1052, http://dx.doi.org/10.1016/j.ipm.2012.01.001
  7. Cavusoglu, H., (2004). Economics of IT Security Management. In: Camp, L. and Lewis, S. (Eds),, Vol. 12, pp. 71-83. Springer US, http://dx.doi.org/10.1007/1-4020-8090-5_6
  8. Computer Security Institute (CSI). (2011). 2010/2011 Computer Crime and Security Survey. The 15th Annual Computer Crime and Security Survey. Retrieved January 17th, 2012, from http://_www.gocsi.com/survey
  9. Farahmand, F., Navathe, S., Enslow, P. & Sharp, G. (2003). Managing vulnerabilities of information systems to security incidents. In:, pp. 348-354. ACM: New York, USA, http://dx.doi.org/ http://dx.doi.org/10.1145/948005.948050
  10. Gordon, A. L. & Loeb, P. M. (2001). Using information security as a response to competitor analysis systems., 44(9), 70-75, http://dx.doi.org/10.1145/383694.383709
  11. Gordon, A. L. & Loeb, P. M. (2002). The Economics of Information Security Investment.5(4), 438-457, http://dx.doi.org/10.1007/1-4020-8090-5_9
  12. Gordon, A. L., & Richardson, R. (April 13, 2004). The New Economics of Information Security., 53-56. Retrieved February 11th, 2007, from http://www.banktech.com/ aml/showArticle.jhtml?articleID=18901266
  13. Hoo, S. (2000).. Retrieved February 28th, 2010, from www.cl.cam.ac.uk/~rja14/econws/06.doc
  14. International Organization for Standardization. (2005).ISO/IEC 27001:2005. Geneva.
  15. International Organization for Standardization. (2009).ISO/IEC 27000:2005. Geneva.
  16. Matsuura, K. (2009). Productivity Space of Information Security in an Extension of the Gordon-Loeb’s Investment Model. In:, pp. 99-119. Springer US, http://dx.doi.org/10.1007/978-0-387-09762-6_5
  17. McGraw, G. (2006).. Addison-Wesley Prof .
  18. National Institute of Standards and Technology. (2004).Special Publication 800-60. Gaithersburg, Md.
  19. National Institute of Standards and Technology (2005).The NIST Handbook. Special Publication 800-12. Gaithersburg, Md.
  20. Ryan, J., & Ryan, D. (2006). Expected benefits of information security investments., 25(8), 579-588, http://dx.doi.org/10.1016/j.cose.2006.08.001
  21. Schneier, B. (2003).. New York: Copernicus Books.
  22. Schneier, B. (2004).. New York: Wiley Publishing.
  23. Tanaka, H., Liu, W. & Matsuura, K. (2006). An Empirical Analysis of Security Investment in Countermeasures Based on an Enterprise Survey in Japan. In:, UK: Cambridge. Retrieved October 12, 2012, from http://weis2006.econinfosec.org/docs/9.pdf
  24. Tanaka, H., Matsuura, K. & Sudoh, O. (2005). Vulnerability and information security investment: An empirical analysis of e-local government in Japan,, 24(1), 37-59, http://dx.doi.org/10.1016/j.jaccpubpol.2004.12.003
  25. Willemson, J. (2006). On the Gordon and Loeb Model for Information Security Investment. In:, UK: Cambridge, Retrieved October 12, 2012, from http://weis2006.econinfosec.org/prog.html
DOI: https://doi.org/10.2478/v10051-012-0027-z | Journal eISSN: 1581-1832 | Journal ISSN: 1318-5454
Language: English
Page range: 276 - 288
Published on: Jan 5, 2013
Published by: University of Maribor
In partnership with: Paradigm Publishing Services

© 2013 Rok Bojanc, Borka Jerman-Blažič, published by University of Maribor
This work is licensed under the Creative Commons License.