EconPapers    
Economics at your fingertips  
 

Choice and Chance: A Conceptual Model of Paths to Information Security Compromise

Sam Ransbotham () and Sabyasachi Mitra ()
Additional contact information
Sam Ransbotham: Carroll School of Management, Boston College, Chestnut Hill, Massachusetts 02467
Sabyasachi Mitra: College of Management, Georgia Institute of Technology, Atlanta, Georgia 30308

Information Systems Research, 2009, vol. 20, issue 1, 121-139

Abstract: No longer the exclusive domain of technology experts, information security is now a management issue. Through a grounded approach using interviews, observations, and secondary data, we advance a model of the information security compromise process from the perspective of the attacked organization. We distinguish between deliberate and opportunistic paths of compromise through the Internet, labeled choice and chance , and include the role of countermeasures, the Internet presence of the firm, and the attractiveness of the firm for information security compromise. Further, using one year of alert data from intrusion detection devices, we find empirical support for the key contributions of the model. We discuss the implications of the model for the emerging research stream on information security in the information systems literature.

Keywords: information security management; computer crime; information systems risk management (search for similar items in EconPapers)
Date: 2009
References: View references in EconPapers View complete reference list from CitEc
Citations: View citations in EconPapers (33)

Downloads: (external link)
http://dx.doi.org/10.1287/isre.1080.0174 (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:inm:orisre:v:20:y:2009:i:1:p:121-139

Access Statistics for this article

More articles in Information Systems Research from INFORMS Contact information at EDIRC.
Bibliographic data for series maintained by Chris Asher ().

 
Page updated 2025-03-19
Handle: RePEc:inm:orisre:v:20:y:2009:i:1:p:121-139