Evaluating the Impact of Cybersecurity Information Sharing on Cyber Incidents and Their Consequences

作者: Matthew H. Fleming , Eric Goldstein , John K Roman

DOI: 10.2139/SSRN.2418357

关键词:

摘要: The Department of Homeland Security (DHS) facilitates cybersecurity information sharing among federal government departments and agencies critical infrastructure owners operators to promote their security. Information is deemed importance accomplish the department’s mission; indeed, one central planks Executive Order 13636: Improving Critical Infrastructure Cybersecurity, which calls for greater between — not least DHS private sector. But while in intuitive that relevant, timely, accurate should help cyber defenders reduce vulnerabilities mitigate threats impact has been empirically assessed. lack empirical support raises two notable issues. First, information-sharing partners, particularly those sector, are sometimes reluctant participate government-sponsored initiatives because concerns about liability, resource costs, return on investment. Absent demonstration value efforts, may be unable better incentivize participation. Second, efforts may, a variety reasons, ineffective (not due participation or dissemination irrelevant information). Without assessing relationship number severity (i.e., consequences) incidents, identify improve poorly performing efforts. A previous Studies Analysis Institute (HSSAI) study recommended suite metrics measure various relevant inputs, processes, outputs, outcomes (Fleming Goldstein 2012). It did not, however, seek suggest ways test hypothesis reduces incidents (it was assumed do so, per guidance). Accordingly, building HSSAI research, present paper sets forth views use dependent variable (some incidents), primary independent sharing), control variables, model specifications.

参考文章(21)
Donald Thomas Campbell, Thomas D. Cook, Quasi-Experimentation: Design & Analysis Issues for Field Settings ,(1979)
Millett Granger Morgan, Max Henrion, Mitchell Small, Uncertainty: A Guide to Dealing with Uncertainty in Quantitative Risk and Policy Analysis ,(1990)
Jeffrey M. Wooldridge, Introductory Econometrics: A Modern Approach ,(1999)
Mark W. Lipsey, Peter Henry Rossi, Howard E. Freeman, Evaluation: A Systematic Approach ,(1979)
Peter Kennedy, A Guide to Econometrics ,(1979)
Julian C. Stanley, Donald Thomas Campbell, Nathaniel Lees Gage, Experimental and Quasi-Experimental Designs for Research ,(1963)