Knowledge Set of Attack Surface and Cybersecurity Rating for Firms in a Supply Chain

Shaun S. Wang
{"title":"Knowledge Set of Attack Surface and Cybersecurity Rating for Firms in a Supply Chain","authors":"Shaun S. Wang","doi":"10.2139/ssrn.3064533","DOIUrl":null,"url":null,"abstract":"This paper presents economic models of cybersecurity investments by a firm, first considering the cost-benefit to the firm itself, and then to the eco-system of a supply-chain. We introduce a concept of a firm’s security knowledge set of its attack surface, relative to the universe of threats. We propose three classes of security production functions as the frontier curve of a firm’s knowledge set. We distinguish two types of security investments in acquiring data, information and expertise, vis-a-vis deploying defense measures and detection tools, and derive formula for optimal allocations. We analyze cyber breach propagations between firms in a supply-chain, and demonstrate that large firms requiring contractors to show security rating by third-parties can be an effective way of reducing information gap in a supply chain. We present a model for the reliability (sharpness) of cybersecurity rating for firms, and show how the perceived reliability of cybersecurity rating affects the incentives for firms to increase their security investments.","PeriodicalId":416291,"journal":{"name":"IO: Firm Structure","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-11-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IO: Firm Structure","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.2139/ssrn.3064533","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

This paper presents economic models of cybersecurity investments by a firm, first considering the cost-benefit to the firm itself, and then to the eco-system of a supply-chain. We introduce a concept of a firm’s security knowledge set of its attack surface, relative to the universe of threats. We propose three classes of security production functions as the frontier curve of a firm’s knowledge set. We distinguish two types of security investments in acquiring data, information and expertise, vis-a-vis deploying defense measures and detection tools, and derive formula for optimal allocations. We analyze cyber breach propagations between firms in a supply-chain, and demonstrate that large firms requiring contractors to show security rating by third-parties can be an effective way of reducing information gap in a supply chain. We present a model for the reliability (sharpness) of cybersecurity rating for firms, and show how the perceived reliability of cybersecurity rating affects the incentives for firms to increase their security investments.
供应链企业攻击面知识集与网络安全等级
本文提出了企业网络安全投资的经济模型,首先考虑了企业自身的成本效益,然后考虑了供应链生态系统的成本效益。我们引入了一个概念,一个公司的攻击面安全知识集,相对于威胁的宇宙。我们提出了三种安全生产函数作为企业知识集的前沿曲线。我们在获取数据、信息和专业知识方面区分了两种类型的安全投资,相对于部署防御措施和检测工具,并推导出最佳分配公式。我们分析了供应链中公司之间的网络漏洞传播,并证明大公司要求承包商展示第三方的安全评级可能是减少供应链信息差距的有效方法。我们提出了一个企业网络安全评级的可靠性(清晰度)模型,并展示了网络安全评级的感知可靠性如何影响企业增加安全投资的激励。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信