作者
Yong Wu, Giri Kumar Tayi, Gengzhong Feng, Richard YK Fung
发表日期
2021
期刊
Journal of the Association for Information Systems
卷号
22
期号
3
页码范围
2
简介
To efficiently manage information security, firms typically outsource part of their security functions to a managed security service provider (MSSP) under a variety of contractual arrangements. Based on this practice, we study a business setting in which the management of security outsourcing depends on the security efforts of both the MSSP and its clients, taking into account that their allocation of efforts can change during the contract horizon. Since their efforts are private to each other, a double moral hazard (DMH) problem can arise with the use of bilateral refund contracts, which have been widely adopted in the MSSP industry. Moreover, both the high probability of undirected attacks and system interdependency can exacerbate the DMH problem. We propose two new types of contracts to solve this problem. One is a monitoring contract, in which a cyberinsurance firm monitors the security efforts of the MSSP and …
引用总数
20212022202320244776
学术搜索中的文章
Y Wu, GK Tayi, G Feng, RYK Fung - Journal of the Association for Information Systems, 2021