Improving Internet Security through Mandatory Information Disclosure

作者: Qian Tang , Andrew B. Whinston

DOI: 10.1109/HICSS.2015.572

关键词:

摘要: Although disclosure has long been considered as a solution to internalize externalities, mandatory security information is still in debate. We propose mechanism based on existing data. The disclosed straightforward rankings of organizations for users understand, interpret, and make comparisons. As result, the can influence through reputational effects. created public website disclose regularly conducted quasi-experiment outgoing spam test effectiveness our four matched country groups. For each treated country, we released ranking list top 10 most spamming every month, while control countries, no was disclosed. find that treatment subject reduced significantly more than comparison organizations.

参考文章(31)
Andrew B. Whinston, Qian Tang, John S. Quarterman, Leigh L. Linden, REPUTATION AS PUBLIC POLICY FOR INTERNET SECURITY : A FIELD STUDY international conference on information systems. pp. 3507- 3522 ,(2012)
Anand Nandkumar, Ashish Arora, Rahul Telang, Ramayya Krishnan, H. John Heinz, Yubao Yang, Impact of Vulnerability Disclosure and Patch Availability - An Empirical Analysis ,(2004)
R. Anderson, Why information security is hard - an economic perspective annual computer security applications conference. pp. 358- 365 ,(2001) , 10.1109/ACSAC.2001.991552
Arthur Cecil Pigou, The Economics of Welfare ,(1920)
Charlotte L Villiers, Corporate Reporting and Company Law ,(2006)
Vern Paxson, Chris Grier, Juan Caballero, Christian Kreibich, Measuring pay-per-install: the commoditization of malware distribution usenix security symposium. pp. 13- 13 ,(2011)
Katherine Campbell, Lawrence A. Gordon, Martin P. Loeb, Lei Zhou, The economic cost of publicly announced information security breaches: empirical evidence from the stock market Journal of Computer Security. ,vol. 11, pp. 431- 448 ,(2003) , 10.3233/JCS-2003-11308
Stephen W. Raudenbush, Xiaofeng Liu, Statistical power and optimal design for multisite randomized trials. Psychological Methods. ,vol. 5, pp. 199- 213 ,(2000) , 10.1037/1082-989X.5.2.199
Richard Blundell, Monica Costa Dias, Evaluation Methods for Non-Experimental Data Fiscal Studies. ,vol. 21, pp. 427- 468 ,(2005) , 10.1111/J.1475-5890.2000.TB00031.X
Robert E. Verrecchia, Information quality and discretionary disclosure Journal of Accounting and Economics. ,vol. 12, pp. 365- 380 ,(1990) , 10.1016/0165-4101(90)90021-U