EconPapers    
Economics at your fingertips  
 

Outsourcing Information Security: Contracting Issues and Security Implications

Asunur Cezar (), Huseyin Cavusoglu () and Srinivasan Raghunathan ()
Additional contact information
Asunur Cezar: Department of Business Administration, TOBB University of Economics and Technology, Ankara 06560, Turkey
Huseyin Cavusoglu: Naveen Jindal School of Management, University of Texas at Dallas, Richardson, Texas 75080
Srinivasan Raghunathan: Naveen Jindal School of Management, University of Texas at Dallas, Richardson, Texas 75080

Management Science, 2014, vol. 60, issue 3, 638-657

Abstract: A unique challenge in information security outsourcing is that neither the outsourcing firm nor the managed security service provider (MSSP) perfectly observes the outcome , the occurrence of a security breach, of prevention effort. Detection of security breaches often requires specialized effort. The current practice is to outsource both prevention and detection to the same MSSP. Some security experts have advocated outsourcing prevention and detection to different MSSPs. We show that the former outsourcing contract leads to a significant disincentive to provide detection effort. The latter contract alleviates this problem but introduces misalignment of incentives between the firm and the MSSPs and eliminates the advantages offered by complementarity between prevention and detection functions, which may lead to a worse outcome than the current contract. We propose a new contract that is superior to these two on various dimensions. This paper was accepted by Lorin Hitt, information systems.

Keywords: outsourcing; information security; contracting; managed security service providers; IT security services (search for similar items in EconPapers)
Date: 2014
References: View references in EconPapers View complete reference list from CitEc
Citations: View citations in EconPapers (12)

Downloads: (external link)
http://dx.doi.org/10.1287/mnsc.2013.1763 (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:inm:ormnsc:v:60:y:2014:i:3:p:638-657

Access Statistics for this article

More articles in Management Science from INFORMS Contact information at EDIRC.
Bibliographic data for series maintained by Chris Asher ().

 
Page updated 2025-03-19
Handle: RePEc:inm:ormnsc:v:60:y:2014:i:3:p:638-657