Direkt zum Inhalt

Weishäupl, Eva ; Yasasin, Emrah ; Schryen, Guido

Information Security Investments: An Exploratory Multiple Case Study on Decision-Making, Evaluation and Learning

Weishäupl, Eva, Yasasin, Emrah und Schryen, Guido (2018) Information Security Investments: An Exploratory Multiple Case Study on Decision-Making, Evaluation and Learning. Computers & Security. (Im Druck)

Veröffentlichungsdatum dieses Volltextes: 02 Feb 2018 09:58
Artikel
DOI zum Zitieren dieses Dokuments: 10.5283/epub.36695


Zusammenfassung

The need to protect resources against attackers is reflected by huge information security investments of firms worldwide. In the presence of budget constraints and a diverse set of assets to protect, organizations have to decide in which IT security measures to invest, how to evaluate those investment decisions, and how to learn from past decisions to optimize future security investment actions. ...

The need to protect resources against attackers is reflected by huge information security investments of firms worldwide. In the presence of budget constraints and a diverse set of assets to protect, organizations have to decide in which IT security measures to invest, how to evaluate those investment decisions, and how to learn from past decisions to optimize future security investment actions. While the academic literature has provided valuable insights into these issues, there is a lack of empirical contributions. To address this lack, we conduct a theory-based exploratory multiple case study. Our case study reveals that (1) firms’ investments in information security are largely driven by external environmental and industry-related factors, (2) firms do not implement standardized decision processes, (3) the security process is perceived to impact the business process in a disturbing way, (4) both the implementation of evaluation processes and the application of metrics are hardly existent and (5) learning activities mainly occur at an ad-hoc basis.


Beteiligte Einrichtungen


Details

DokumentenartArtikel
Titel eines Journals oder einer ZeitschriftComputers & Security
Verlag:Elsevier
Datum2018
InstitutionenWirtschaftswissenschaften > Institut für Wirtschaftsinformatik > Entpflichtete oder im Ruhestand befindliche Professoren > Professur für Wirtschaftsinformatik (Prof. Dr. Guido Schryen)
Stichwörter / KeywordsInformation Security Investments, Multiple Case Study, Organizations, Single Loop Learning, Double Loop Learning
Dewey-Dezimal-Klassifikation000 Informatik, Informationswissenschaft, allgemeine Werke > 004 Informatik
StatusIm Druck
BegutachtetJa, diese Version wurde begutachtet
An der Universität Regensburg entstandenJa
URN der UB Regensburgurn:nbn:de:bvb:355-epub-366957
Dokumenten-ID36695

Bibliographische Daten exportieren

Nur für Besitzer und Autoren: Kontrollseite des Eintrags

nach oben