Research Note—A Value-at-Risk Approach to Information Security Investment
Published Online:1 Mar 2008https://doi.org/10.1287/isre.1070.0143
References
- Understanding the Insider Threat (2004) (RAND Corporation, Santa Monica) Google Scholar
- Extreme Value Theory in Engineering (1988) (Academic Press, San Diego) Google Scholar
- Towards a theory of insider threat assessment. The 2005 Internat. Conf. Dependable Systems and Networks (DSN'05) (2005) Yokohama, Japan(IEEE Computer Society, Washington, D.C.) 108–117Crossref, Google Scholar
- An Introduction to Statistical Modeling of Extreme Values (2001) (Springer-Verlag, London) Crossref, Google Scholar
- Risk Management (2001) (McGraw-Hill, New York) Google Scholar
- An extreme-value model of concept testing. Management Sci. (2001) 47(1):102–116Link, Google Scholar
- Models for exceedances over high thresholds (with discussion). J. Roy. Statist. Soc. (1990) 52:393–442Google Scholar
- Implication of alternative operational risk modeling techniques. (2005) . NBER Working Paper 11103, National Bureau of Economic Research. Cambridge, MA. Available at http://www.nber.org/papers/w11103Crossref, Google Scholar
- The IT Payoff (2002) (Prentice Hall, Upper Saddle River, NJ) Google Scholar
- Distribution of the estimators for autoregressive time series with a unit root. J. Amer. Statist. Assoc. (1979) 74:427–431Crossref, Google Scholar
- Likelihood ratio tests for autoregressive time series with a unit root. Econometrica (1981) 49:1057–1072Crossref, Google Scholar
- Beyond Value at Risk; The New Science of Risk Management (1998) (John Wiley & Sons, New York) Google Scholar
- An overview of value at risk. J. Derivatives (1997) 4(3):7–49Crossref, Google Scholar
- Actuarial versus financial pricing of insurance. (1996) . Working paper, The Wharton School, Philadelphia. Available at http://fic.wharton.upenn.edu/fic/papers/96/9617.pdfGoogle Scholar
- Modeling Extremal Events for Insurance and Finance (1997) (Springer, New York) Crossref, Google Scholar
- Ernst & Young Global Information Security Survey 2003. (2003) (Ernst & Young LLP)Google Scholar
- Ernst & Young Global Information Security Survey 2004. (2004) (Ernst & Young LLP)Google Scholar
- A management perspective on risk of security threats to information systems. Inform. Tech. Management (2005) 6(2–3):203–255Crossref, Google Scholar
- Limiting Forms of the Frequency Distributions of the Largest or Smallest Member of a Sample (1928) (The Cambridge Philosophical Society, Cambridge University Press, London) Crossref, Google Scholar
- The economic incentives for sharing security information. Inform. Systems Res. (2005) 16(2):186–208Link, Google Scholar
- Information security: Why the future belongs to the quants. IEEE Security & Privacy (2003) 1:32–40Crossref, Google Scholar
- The economics of information security investment. ACM Trans. Inform. Systems Secur. (2002) 5(4):438–457Crossref, Google Scholar
- 2005 CSI/FBI Computer Crime and Security Survey. (2005) (Computer Security Institute, San Francisco) Google Scholar
- Econometric Analysis (2000) (Prentice Hall, Upper Saddle River, NJ) Google Scholar
- Statistics of Extremes (1958) (Columbia University, New York) Crossref, Google Scholar
- Value at risk as a diagnostic tool for corporates: The airline industry. (1999) . Papers No. 99-023/2, Tinbergen Institute Discussion Papers, Rotterdam, The Netherlands. Available at http://www.tinbergen.nl/discussionpapers/99023.pdfGoogle Scholar
- Value at Risk: Theory and Practice (2003) (Academic Press, London) Google Scholar
- How much is enough? A risk-management approach to computer security. (2000) . Working paper, Center for International Security and Cooperation, Stanford University. Available at http://iis-db.stanford.edu/pubs/11900/soohoo.pdfGoogle Scholar
- Value at Risk (1997) (McGraw-Hill, New York) Google Scholar
- Market for software vulnerabilities? Think again. Management Sci. (2005) 51(5):726–740Link, Google Scholar
- A framework for analyzing e-commerce security. Inform. Management Comput. Secur. (2002) 10(4):149–158Crossref, Google Scholar
- On clustering of high levels in statistically stationary series. The 4th Internat. Meeting on Statist. Climatology (1989) (New Zealand Meteorological Service, Wellington, New Zealand) Google Scholar
- Are we forgetting the risks of information technology? IEEE Comput. (2000) 33(12):43–51Crossref, Google Scholar
- Agricultural applications of value-at-risk analysis: A perspective. The NCR-134 Conf. Appl. Commodity Price Anal., Forecasting, and Market Risk Management (1998) St. LouisCrossref, Google Scholar
- Analyzing security costs. Comm. ACM (2003) 46(6):15–18Crossref, Google Scholar
- Stochastic traffic engineering for demand uncertainty and risk-aware network revenue management. IEEE/ACM Trans. Networking (2005) 13(2):221–233Crossref, Google Scholar
- Statistical inference using extreme order statistics. Ann. Statist. (1975) 3:119–131Crossref, Google Scholar
- How much security is enough to stop a thief? The economics of outsider theft via computer systems networks. Proc. 7th Financial Cryptography Conf. (2003) Guadeloupe, French West Indies:122–137Crossref, Google Scholar
- The insider threat to information systems. Security Awareness Bull. (1998) 2-98Google Scholar
- Extreme value analysis of enviromental time series: An example based on ozone data (with discussion). Statist. Sci. (1989) 4:367–393Crossref, Google Scholar
- Estimating the extremal index. J. Roy. Statist. Soc. (1994) B(56):515–528Google Scholar
- An information systems security risk assessment model under Dempster-Shafer theory of belief functions. J. Management Inform. Systems (2006) 22(3):190–142Google Scholar
- An extreme value theory model for dependent observations. J. Hydrology (1988) 101:227–250Crossref, Google Scholar
- , Camp L. J., Lewis S. System reliability and free riding. Economics of Information Security (2004) (Kluwer Academic Publishers, Boston/Dordrecht/London) 1–15Crossref, Google Scholar

