login

Choice and Chance: A Conceptual Model of Paths to Information Security Compromise

Information Systems ResearchPublished 21 June 2008
Sam Ransbotham, Sabyasachi Mitra
Citations246
SJR quartileQ1
SJR score4.85
SNIP2.57

TL;DR

A grounded approach using interviews, observations, and secondary data is advanced to advance a model of the information security compromise process from the perspective of the attacked organization, and the implications for the emerging research stream on information security in the information systems literature are discussed.

Abstract

No longer the exclusive domain of technology experts, information security is now a management issue. Through a grounded approach using interviews, observations, and secondary data, we advance a model of the information security compromise process from the perspective of the attacked organization. We distinguish between deliberate and opportunistic paths of compromise through the Internet, labeled choice and chance, and include the role of countermeasures, the Internet presence of the firm, and the attractiveness of the firm for information security compromise. Further, using one year of alert data from intrusion detection devices, we find empirical support for the key contributions of the model. We discuss the implications of the model for the emerging research stream on information security in the information systems literature.

Keywords

Computer Science