What are the economic considerations in information security

Assignment Help Management Information Sys
Reference no: EM131411089

Module- Case: SECURITY VIA TECHNOLOGY

Case Assignment

1. Revisit Bruce Schneier's presentation in Module 2. This time, please focus on his discussions on cost/benefit analysis.

Schneier, B. (2008). What are the implications of spying? CCTV interview with Bruce Schneier. Retrieved from https://www.youtube.com/watch?v=Ar67N94NYr0

If you don't have access to the presentation, then simply read his article mentioned in Module 2. The article is:

Schneier, Bruce. The Psychology of Security. https://www.schneier.com/essay-155.html

The following article provides an example how such a cost/benefit analysis is considered.

Schneier, Bruce. Security at What Cost? National ID System Is Not Worth The $23 Billion Price Tag. https://www.schneier.com/essay-207.html.

The following article uses some typical accounting measurements for economics of information security.

Gordon, L. A., & Richardson, R. (2004). The New Economics of Information Security. Optimize. April, 83-86. (Trident Online Library: ProQuest)

The following article recaps what we talked about perceptions of security. More importantly, it discusses how people generally do not perceive gains and costs equally. When you conduct a cost/benefit analysis of security, you should keep that in mind.

West, R. (2008). The psychology of security. Communications of the ACM, Apr, 51(4), 34-40.

2. Incentive Design

The economics of information security is not only about cost/benefit analysis of implementing a security measure. Another major topic in economics is mechanism design, which provides principles and methods (like game theory) to help design incentive-compatible mechanisms that ensure participants are better off behaving honestly than dishonestly. See the following article to get a peek:

The Economist. (2007) Intelligent Design. Oct 18th, 2007. https://www.economist.com/finance/displaystory.cfm?story_id=9988840

To know more about the three Nobel Prize winners in 2007 economics division, surf https://nobelprize.org/nobel_prizes/economics/laureates/2007/ and check them out.

It is not easy to understand the revelation principle or the incentive-compatible design. I introduce you the concepts here for the purpose of making you aware of such a method. It takes time to learn how to design a game (a mechanism) that every party is better off by being honest.

Well, on a lighter note. Interestingly, a movie called "Mad Money" tells a story of three female employees of the Federal Reserve Bank stealing money that is about to be shredded. It is not a movie that I recommend to watch a second time, but it is entertaining enough to watch once. The movie is also a fit for the educational purpose here. I suggest you watch it once when you get a chance during this term, and pay special attention to the human factors -- especially the incentives of the thieves and the Chief Security Officer.

3. Other Economics Issues as to Security

As a matter of fact, there are many aspects in applying economics to information security. The following article has mentioned a list of authors that research economics of information security and provided a brief overview of their research:

Anderson R. and Schneier B., (2005) Economics of Information Security, IEEE Security and Privacy 3 (1), 2005, pp. 12-13. (Retrieved May 19, 2008).

To know more in depth, you can choose to view the video (optional):

Simonyi Konferencia 2011 - Economics of Information Security and Privacy. Retrieved from https://www.youtube.com/watch?v=fSfH80DY6S4
You are probably overwhelmed now with all these economics. I hope you also have broadened your views on security and have said "wow" to yourself that now you hold a much broader view on security and how to approach it from economic perspective.

Please write a 4- to 6-page paper discussing what you have learned:

What are the economic considerations of information security and its management?

In preparing your paper, you need to discuss the following issues, and support with arguments and evidence:

• What are the major economic considerations in information security and management?

• Are these economic considerations serving their purposes?

• Why do these economic measures help?

• Discuss economic mechanisms that can improve information security and management.

• Provide a comparative table of the economic measures that you discussed.

Assignment Expectations

Length: Minimum 4-6 pages excluding cover page and references (since a page is about 300 words, this is approximately 1,200-1,800 words).

Reference no: EM131411089

Questions Cloud

Discuss about the roman-byzantine period : Explore the website and then write approximately 300 words about a subject that you found to be of interest and why.
Explain method for collecting each of given types of sample : Researchers want to conduct a survey of students taking introductory statistics in the state. Explain a method for collecting each of the given types of samples:
Explain the process and write down the six numbers chosen : Use a computer random number generator or invent your own random mechanism to draw six numbers. Explain your process, and write down the six numbers chosen.
Is the collection of sets inspected a simple random sample : Is the collection of sets inspected a simple random sample, a stratified random sample, a cluster sample, or a systematic sample?
What are the economic considerations in information security : ITM 517- What are the major economic considerations in information security and management? Are these economic considerations serving their purposes? Why do these economic measures help?
Explain problems you see with leaving two systems in place : Identify any additional information you would need to recommend a solution. Explain any problems you see with leaving the two systems in place, and identify which system would be assigned for new employees.
In what ways have your horizons been expanded : GSBS 110- In what ways have your horizons been expanded in terms of relationships with others through social media or other digital communication? What, if anything, have you given up as a result?
Compare three input devices and three output devices : As a computer technician, you must be familiar with a wide range of Input/Output (I/O) devices including; keyboards, mice, monitors, biometric devices, projectors, cameras, and video or graphics cards. Compare three input devices and three output d..
Explain whether width of confidence interval would increase : Explain whether the width of a confidence interval would increase, decrease, or remain the same as a result of each of the given changes:

Reviews

Write a Review

Management Information Sys Questions & Answers

  Watch the video titled-agile soft skills

Consider the manner in which you usually react to conflict and determine your native conflict response behavior. Provide one (1) example that supports your conclusion. Note: This is a safe environment for everyone to share his / her personal exper..

  Describing how information is used

Write a 700- to 1,050-word paper identifying and describing how information is used and how it flows in an organization. Explain this use in your current place of employment or an organization with which you are familiar

  In what ways can the business benefit from a web site

What Internet business model would be appropriate for the company to follow in creating a Web site and why? In what ways can the business benefit from a Web site?

  Hackers and cyber criminal organizations

Hackers and Cyber Criminal Organizations

  Provide a historical timeline of homeland security incidents

Provide a historical timeline of homeland security incidents/events (natural and man-made) along with the call for improved preparedness, response and recovery needs that lead to the creation of NIMs and the NRF documents. Be sure to include each ..

  Create a business impact analysis on sangrafix a video game

Create a business impact analysis on SanGrafix a video game design company. The BIA should include a descriptive list of the organization's key business areas.

  Compare and contrast two siem tools

Compare and contrast two SIEM tools of your choice based on their common uses and market reputation. Determine which of these tools you would prefer to use as part of an incident response strategy and explain why

  Determine the types of monitoring

Determine the types of monitoring

  Describe cryptology and impact on cybercrime response

Summarize the concepts from your written paper in Part 1 of this assignment for the lecture you would give to the class regarding the use of cryptography in corporations to minimize data theft.

  Analyze the means in which data moves within organization

Suggest three (3) logical access control methods to restrict unauthorized entities from accessing sensitive information, and explain why you suggested each method. Analyze the means in which data moves within the organization and identify techniq..

  Digital media project

Digital Media Project-A description of the revisions you would make to your digital media project, an explanation as to why you would make those changes, and an estimate on how long it would take to make the changes

  Discuss about the characterizing data types

Assess the value to an interface designer, of being familiar with the seven basic tasks and create an argument for which five of the seven basic tasks are the most important to incorporate in a design.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd