Choice and Chance: A Conceptual Model of Paths to Information Security Compromise
Published Online:1 Mar 2009https://doi.org/10.1287/isre.1080.0174
References
- Social learning and deviant behavior: A specific test of a general theory. Amer. Sociol. Rev. (1979) 44(4):636–655Crossref, Google Scholar
- Timing disclosure of software vulnerability for optimal social welfare. Proc. Third Workshop Econom. Inform. Systems (2004) Minneapolis:1–47Google Scholar
- Typologies and Taxonomies: An Introduction to Classification Techniques (1994) (Sage Publications, Thousand Oaks, CA) Crossref, Google Scholar
- Modeling IT ethics: A study in situational ethics. MIS Quart. (1998) 22(1):31–60Crossref, Google Scholar
- The moderator-mediator variable distinction in social psychological research: Conceptual, strategic, and statistical considerations. J. Personality Soc. Psych. (1986) 51(6):1173–1182Crossref, Google Scholar
- Information systems security design methods: Implications for information systems development. ACM Comput. Surveys (1993) 25(4):375–414Crossref, Google Scholar
- A new product growth for model consumer durables. Management Sci. (1969) 15(5):215–227Link, Google Scholar
- Crime and punishment: An economic approach. J. Political Econom. (1968) 76(2):169–217Crossref, Google Scholar
- Implementing security and integrity in micro-mainframe networks. MIS Quart. (1989) 13(2):134–144Crossref, Google Scholar
- Guide for Developing Security Plans for Federal Information Systems (2005) (National Institute of Standards and Technology Special Publication 800-18, Revision 1, Gaithersburg, MD) 1–45Google Scholar
- Racial harrassment and the process of victimization. British J. Criminology (1993) 33(2):231–250Crossref, Google Scholar
- Crime, Shame and Reintegration (1989) (Cambridge University Press, Cambridge, UK) Crossref, Google Scholar
- Key issues in information systems management: 1994–1995 SIM Delphi results. MIS Quart. (1996) 20(2):225–242Crossref, Google Scholar
- The impact of Internet security breach announcements on market value of breached firms and Internet security developers. Internat. J. Electronic Commerce (2004) 9(1):69–104Crossref, Google Scholar
- The value of intrusion detection systems in information technology security architecture. Inform. Systems Res. (2005) 16(1):28–46Link, Google Scholar
- Internet infrastructure security: A taxonomy. IEEE Network (2002) 16(6):13–21Crossref, Google Scholar
- Delinquent Boys: The Culture of the Gang (1955) (Free Press, New York) Google Scholar
- Social change and crime rate change: A routine activity approach. Amer. Sociol. Rev. (1979) 44(4):588–608Crossref, Google Scholar
- Toward an integrated theory of white-collar crime. Amer. J. Sociol. (1987) 93(2):406–439Crossref, Google Scholar
- Grounded theory research: Procedures, canons and evaluative criteria. Qualitative Sociol. (1990) 13(1):3–21Crossref, Google Scholar
- Alert correlation in a cooperative intrusion detection framework. Proc. 2002 IEEE Sympos. Security Privacy (2002) Oakland, CA:202–215Crossref, Google Scholar
- Classification of computer attacks using a self-organizing map. Proc. 2004 IEEE Workshop Inform. Assurance (2004) (U.S. Military Academy, West Point, NY) 365–369Crossref, Google Scholar
- Current directions in IS security research: Towards socio-organizational perspectives. Inform. Systems J. (2001) 11(2):127–153Crossref, Google Scholar
- Fuzzy intrusion detection. Proc. Joint 9th IFSA World Congress and 20th NAFIPS Internat. Conf., 2001 (2001) Vancouver, Canada:1506–1510Crossref, Google Scholar
- Security and privacy issues of handheld and wearable wireless devices. Comm. ACM (2003) 46(9):74–79Crossref, Google Scholar
- Management's role in information security in a cyber economy. California Management Rev. (2002) 45(1):67–87Crossref, Google Scholar
- Participation in illegitimate activities: A theoretical and empirical investigation. J. Political Econom. (1973) 81(3):521–565Crossref, Google Scholar
- Crime, punishment and the market for offences. J. Econom. Perspectives (1996) 10(1):43–67Crossref, Google Scholar
- Cyberterrorism: Are we under siege? Amer. Behavioral Scientist (2002) 45(6):1033–1043Crossref, Google Scholar
- Morality and computers: Attitudes and differences in moral judgments. Inform. Systems Res. (1999) 10(3):233–254Link, Google Scholar
- The Discovery of Grounded Theory: Strategies for Qualitative Research (1967) (Aldine De Gruyter, New York) Google Scholar
- The economics of information security investment. ACM Trans. Inform. System Security (2002) 5(4):438–457Crossref, Google Scholar
- A General Theory of Crime (1990) (Stanford University Press, Stanford, CA) Crossref, Google Scholar
- Discourses of danger and the computer hacker. Inform. Soc. (1997) 13(4):361–374Crossref, Google Scholar
- The effect of codes of ethics and personal denial of responsibility on computer abuse judgements and intentions. MIS Quart. (1996) 20(3):257–278Crossref, Google Scholar
- An Analysis of Security Incidents on the Internet 1989–1995 (1998) (Carnegie Mellon University, Pittsburgh) Google Scholar
- Clustering intrusion detection alarms to support root cause analysis. ACM Trans. Inform. System Security (2003) 6(4):443–471Crossref, Google Scholar
- Market for software vulnerabilities? Think again. Management Sci. (2005) 51(5):726–740Link, Google Scholar
- Intrusion detection: A brief history and overview. IEEE Comput. (2002) 35(4):27–30Crossref, Google Scholar
- Threats to information systems: Today's reality, yesterday's understanding. MIS Quart. (1992) 16(2):173–186Crossref, Google Scholar
- Managing information security. McKinsey Quart. (2002) Special Edition(2):12–16Google Scholar
- Victims of Crime and the Victimization Process (1997) 6(Garland Publications, New York) Google Scholar
- Crime and Its Social Context: Toward an Integrated Theory of Offenders, Victims, and Situations (1994) (State University of New York Press, New York) Google Scholar
- Techniques and tools for analyzing intrusion alerts. ACM Trans. Inform. System Security (2004) 7(2):274–318Crossref, Google Scholar
- Authentication, access control, and audit. ACM Comput. Surveys (1996) 28(1):241–243Crossref, Google Scholar
- The security of confidential numerical data in databases. Inform. Systems Res. (2002) 13(4):389–403Link, Google Scholar
- , Davida G., Frankel Y., Rees O. How much security is enough to stop a thief? The economics of outsider theft via computer systems and networks. Proc. Seventh Financial Cryptography Conf. (2003) 2742January 27–30, 2003(Springer-Verlag, New York) 7–10Lecture Notes in Computer Science, LCNS 2437Crossref, Google Scholar
- Sarbanes-Oxley: A huge boon to information security in the US. Comput. Security (2004) 23(5):353–354Crossref, Google Scholar
- Analysis of modern IS security development approaches: Towards the next generation of social and adaptable ISS methods. Inform. Organ. (2005) 15:339–375Crossref, Google Scholar
- Asymptotic confidence intervals for indirect effects in structural equation models. Sociol. Methodology (1982) 13:290–312Crossref, Google Scholar
- The privacy rule, security rule, and transaction standards: Three sides of the same coin. J. Health Care Compliance (2004) 6(1):11–14Google Scholar
- Effective IS security: An empirical study. Inform. Systems Res. (1990) 1(3):255–276Link, Google Scholar
- Discovering and disciplining computer abuse in organizations: A field study. MIS Quart. (1990) 14(1):45–60Crossref, Google Scholar
- Coping with systems risk: Security planning models for management decision making. MIS Quart. (1998) 22(4):441–469Crossref, Google Scholar
- Principles of Criminology (1947) (Lippincot, Philadelphia) Google Scholar
- Flow-based model of computer hacker's motivation. Cyber Psych. Behav. (2003) 6(2):171–180Crossref, Google Scholar
- Theoretically speaking. MIS Quart. (2002) 27(3):iii–xiiCrossref, Google Scholar
- What constitutes a theoretical contribution? Acad. Management Rev. (1989) 14(4):490–495Crossref, Google Scholar
- Opportunities for Computer Abuse: Assessing a Crime Specific Approach in the Cast of Barings Bank (2002) (London School of Economics and Political Science, London) Google Scholar
- Editor's comments. MIS Quart. (1998) 22(2):7–10Google Scholar

