{"title":"Data Security, Data Breaches, and Compliance","authors":"Chirantan Chatterjee, D. Sokol","doi":"10.1017/9781108759458.064","DOIUrl":null,"url":null,"abstract":"This chapter explores the attributes of compliance in the context of data breaches. First, it identifies the sort of corporate governance problem that data breaches create. Then, it approaches the empirical work related to data breaches and to the organization of compliance-based responses in terms of risk assessment, training and compliance, both preemptively and after a breach. \n \nNext, the chapter discusses the extant theoretical and empirical evidence about the short and the long term impact of IT security events on breached firms as well as corporate governance issues relating to data breaches. It also examines studies that evaluate the impact of different types of events on various types of firms and stakeholders. The chapter also explores how data breaches impact broader issues of corporate governance and compliance. In the end, it identifies potential research questions and avenues for future researchers on how firms or governments might have to think about their IT security investments and the necessary measures that have to be in place to respond effectively if such events occur.","PeriodicalId":171289,"journal":{"name":"Corporate Law: Corporate Governance Law eJournal","volume":"61 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Corporate Law: Corporate Governance Law eJournal","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1017/9781108759458.064","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
Abstract
This chapter explores the attributes of compliance in the context of data breaches. First, it identifies the sort of corporate governance problem that data breaches create. Then, it approaches the empirical work related to data breaches and to the organization of compliance-based responses in terms of risk assessment, training and compliance, both preemptively and after a breach.
Next, the chapter discusses the extant theoretical and empirical evidence about the short and the long term impact of IT security events on breached firms as well as corporate governance issues relating to data breaches. It also examines studies that evaluate the impact of different types of events on various types of firms and stakeholders. The chapter also explores how data breaches impact broader issues of corporate governance and compliance. In the end, it identifies potential research questions and avenues for future researchers on how firms or governments might have to think about their IT security investments and the necessary measures that have to be in place to respond effectively if such events occur.