4.6 Article

An economic analysis of the optimal information security investment in the case of a risk-averse firm

Journal

INTERNATIONAL JOURNAL OF PRODUCTION ECONOMICS
Volume 114, Issue 2, Pages 793-804

Publisher

ELSEVIER SCIENCE BV
DOI: 10.1016/j.ijpe.2008.04.002

Keywords

information security; optimal investment; expected utility theory

Ask authors/readers for more resources

This paper presents an analysis of information security investment from the perspective of a risk-averse decision maker following common economic principles. Using the expected utility theory, we find that for a risk-averse decision maker, the maximum security investment increases with, but never exceeds, the potential loss from a security breach, and there exists a minimum potential loss below which the optimal investment is zero. Our model also shows that the investment in information security does not necessarily increase with increasing level of risk aversion of the decision maker. Relationships between vulnerability and investment effectiveness and two broad classes of security breach probability functions are examined, leading to interesting insights that can be used as guidelines for managers to determine the optimal level of security investment for certain types of security threats faced by risk-averse firms. Future research directions are discussed based on the limitations and possible extensions of this study. (C) 2008 Elsevier B.V. All rights reserved.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.6
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available