Research Note—An Exploration of Risk Characteristics of Information Security Threats and Related Public Information Search Behavior

Published Online:https://doi.org/10.1287/isre.2015.0581

References

  • Allen BL (1991) Topic knowledge and online catalog search formulation. Library Quart. 61(2):188–213.CrossrefGoogle Scholar
  • Anderson CL, Agarwal R (2010) Practicing safe computing: A multimethod empirical examination of home computer user security behavioral intentions. MIS Quart. 34(3):613–643.CrossrefGoogle Scholar
  • Baeza-Yates R, Ribeiro-Neto B (1999) Modern Information Retrieval (Addison Wesley, New York).Google Scholar
  • Bailey P, White RW, Liu H, Kumaran G (2010) Mining historic query trails to label long and rare search engine queries. ACM Trans. Web 1(2):1–25.CrossrefGoogle Scholar
  • Baye MR, Gatti JRJ, Kattuman P, Morgan J (2009) Clicks, discontinuities, and firm demand online. J. Econom. Management Strategy 18(4):935–975.CrossrefGoogle Scholar
  • Boholm Å (1998) Comparative studies of risk perception: A review of twenty years of research. J. Risk Res. 1(2):135–163.CrossrefGoogle Scholar
  • Braverman M, Williams J, Mador Z (2006) Microsoft security intelligence report. Microsoft, Redmond, WA.Google Scholar
  • Brooks S, Gelman A (1998) General methods for monitoring convergence of iterative simulations. J. Comput. Graphical Statist. 7(4):434–455.Google Scholar
  • Brucks M (1985) The effects of product class knowledge on information search behavior. J. Consumer Res. 12(1):1–16.CrossrefGoogle Scholar
  • Bucklin RE, Sismeiro C (2003) A model of Web site browsing behavior estimated on clickstream data. J. Marketing Res. 40(3):249–267.CrossrefGoogle Scholar
  • Chou PHB, Wister AV (2005) From cues to action: Information seeking and exercise self–care among older adults managing chronic illness. Canadian J. Aging 24(4):395–408.CrossrefGoogle Scholar
  • Compeau D, Marcolin B, Kelley H, Higgins C (2012) Generalizability of information systems research using student subjects—A reflection on our practices and recommendations for future research. Inform. Systems Res. 23(4):1093–1109.LinkGoogle Scholar
  • D’Arcy J, Hovav A, Galletta D (2009) User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach. Inform. Systems Res. 20(1):79–98.LinkGoogle Scholar
  • Duff DE (2014) A comparative study of nuclear power risk perceptions with selected technological hazards. Unpublished doctoral dissertation, North Dakota State University, Fargo.Google Scholar
  • Fischhoff B, Slovic P, Lichtenstein S, Read S, Combs B (1978) How safe is safe enough? A psychometric study of attitudes towards technological risks and benefits. Policy Sci. 9(2):127–152.CrossrefGoogle Scholar
  • Gelman A, Carlin JB, Stern HS, Rubin DB (2003) Bayesian Data Analysis, 2nd ed. (Chapman and Hall/CRC, Boca Raton, FL).Google Scholar
  • Geman S, Geman D (1984) Stochastic relaxation, Gibbs distributions, and the Bayesian restoration of images. IEEE Trans. Pattern Anal. Machine Intelligence 6(6):721–741.CrossrefGoogle Scholar
  • Gordon ME, Slade LA, Schmitt N (1986) The “Science of the Sophomore” revisited: From conjecture to empiricism. Acad. Management Rev. 11(1):191–207.Google Scholar
  • Griffin R, Dunwoody S, Neuwirth K (1999) Proposed model of the relationship of risk information seeking and processing to the development of preventive behaviors. Environ. Res. 80(2):S230–S245.CrossrefGoogle Scholar
  • Heit E (1997) Knowledge and concept learning. Lamberts K, Shanks D, eds. Knowledge, Concepts, and Categories (Psychology Press, Hove, UK), 7–41.Google Scholar
  • Herath T, Rao HR (2009) Protection motivation and deterrence: A framework for security policy compliance in organizations. Eur. J. Inform. Systems 18(2):106–125.CrossrefGoogle Scholar
  • Holscher C, Strube G (2000) Web search behavior of Internet experts and newbies. Comput. Networks 33(1–6):337–346.CrossrefGoogle Scholar
  • Hovick SR, Freimuth VS, Johnson-Turbes A, Chervin DD (2011) Multiple health risk perception and information processing among African Americans and whites living in poverty. Risk Anal. 31(11):1789–1799.CrossrefGoogle Scholar
  • Hsiao C (2003) Analysis of Panel Data, 2nd ed. (Cambridge University Press, New York).CrossrefGoogle Scholar
  • Jarvenpaa SL, Shaw TR, Staples DS (2004) Toward contextualized theories of trust: The role of trust in global virtual teams. Inform. Systems Res. 15(3):250–267.LinkGoogle Scholar
  • Johnson EJ, Bellman S, Lohse GL (2003) Cognitive lock-in and the power law of practice. J. Marketing 67(2):62–75.CrossrefGoogle Scholar
  • Johnston AC, Warkentin M (2010) Fear appeals and information security behavior: An empirical study. MIS Quart. 34(3):549–566.CrossrefGoogle Scholar
  • Jonas E, Graupmann V, Frey D (2006) The influence of mood on the search for supporting versus conflicting information: Dissonance reduction as a means of mood regulation? Personality Soc. Psych. Bulletin 32(3):3–15.CrossrefGoogle Scholar
  • Jones S (2002) The Internet goes to college: How students are living in the future with today’s technology. Pew Internet and American Life Project, Washington, DC.Google Scholar
  • Kahlor LA (2007) An augmented risk information seeking model: The case of global warming. Media Psych. 10(3):414–435.CrossrefGoogle Scholar
  • Kass RE, Raftery AE (1995) Bayes factors. J. Amer. Statist. Assoc. 90(430):773–795.CrossrefGoogle Scholar
  • Kelly D, Cool C (2002) The effects of topic familiarity on information search behavior. 2nd ACM/IEEE-CS Joint Conf. Digital Libraries (ACM, Portland, OR), 74–75.CrossrefGoogle Scholar
  • Kievik M, Gutteling JM (2011) Yes, we can: Motivate Dutch citizens to engage in self-protective behavior with regard to flood risks. Natural Hazards 59(3):1475–1490.CrossrefGoogle Scholar
  • Kim K, Kim HJ, Song DJ, Cho YM, Choi J (2014) Risk perception and public concerns of electromagnetic waves from cellular phones in Korea. Bioelectromagnetics 35(4):235–244.CrossrefGoogle Scholar
  • Kraus NN, Slovic P (1988) Taxonomic analysis of perceived risk: Modelling individual and group perceptions. Risk Anal. 8(3):435–455.CrossrefGoogle Scholar
  • Kulviwat S, Guo C, Engchanil N (2004) Determinants of online information search: A critical review and assessment. Internet Res. 14(3):245–253.CrossrefGoogle Scholar
  • Kuttschreuter M (2006) Psychological determinants of reactions to food risk messages. Risk Anal. 26(4):1045–1057.CrossrefGoogle Scholar
  • Leroy G, Xu J, Chung W, Eggers S, Chen H (2007) An end user evaluation of query formulation and results review tools in three medical meta-search engines. Internat. J. Medical Informatics 76(11):780–789.CrossrefGoogle Scholar
  • Liang H, Xue Y (2009) Avoidance of information technology threats: A theoretical perspective. MIS Quart. 33(1):71–90.CrossrefGoogle Scholar
  • Lion R, Meertens RM, Bot I (2002) Priorities in information desire about unknown risks. Risk Anal. 22(4):765–776.CrossrefGoogle Scholar
  • Luo X, Liao Q (2007) Awareness education as the key to ransomware prevention. Inform. Systems Security 16(4):195–202.CrossrefGoogle Scholar
  • Mahmood MA, Siponen M, Straub D, Rao HR, Raghu T (2010) Moving toward black hat research in information systems security: An editorial introduction to the special issue. MIS Quart. 34(3):431–433.CrossrefGoogle Scholar
  • Marris C, Langford I, Saunderson T, O’Riordan T (1997) Exploring the “psychometric paradigm”: Comparisons between aggregate and individual analyses. Risk Anal. 17(3):303–312.CrossrefGoogle Scholar
  • Mookerjee V, Mookerjee R, Bensoussan A, Yue WT (2011) When hackers talk: Managing information security under variable attack rates and knowledge dissemination. Inform. Systems Res. 22(3):606–623.LinkGoogle Scholar
  • Morris EJ (2011) A semi-quantitative approach to GMO risk-benefit analysis. Transgenic Res. 20(5):1055–1071.CrossrefGoogle Scholar
  • Neuendorf KA (2002) The Content Analysis Guidebook (Sage, Thousand Oaks, CA).Google Scholar
  • Neuwirth K, Dunwoody S, Griffin RJ (2000) Protection motivation and risk communication. Risk Anal. 20(5):721–734.CrossrefGoogle Scholar
  • Newman JW, Staelin R (1972) Prepurchase information seeking for new cars and major household appliances. J. Marketing Res. 9(3):249–257.CrossrefGoogle Scholar
  • Ngo LT, Bruhn R, Custer B (2013) Risk perception and its role in attitudes toward blood transfusion: A qualitative systematic review. Transfusion Medicine Rev. 27(2):119–128.CrossrefGoogle Scholar
  • Ntzoufras I (2009) Bayesian Modeling Using WinBUGS (John Wiley & Sons, Hoboken, NJ).CrossrefGoogle Scholar
  • Pass G, Chowdhury A, Torgeson C (2006) A picture of search. First Internat. Conf. Scalable Inform. Systems (INFOSCALE ’06) (ACM, New York).CrossrefGoogle Scholar
  • Pirolli P (2007) Information Foraging Theory: Adaptive Interaction with Information (Oxford University Press, New York).CrossrefGoogle Scholar
  • Pirolli P, Card S (1995) Information foraging in information access environments. Conf. Human Factors Comput. Systems (ACM, New York), 51–58.CrossrefGoogle Scholar
  • Pirolli P, Card S (1999) Information foraging. Psych. Rev. 106(4):643–675.CrossrefGoogle Scholar
  • Portell M, Gil RM, Losilla JM, Vives J (2014) Characterizing occupational risk perception: The case of biological, ergonomic and organizational hazards in Spanish healthcare workers. Spanish J. Psych. 17(e51):1–12.Google Scholar
  • Puhakainen P, Siponen M (2010) Improving employees’ compliance through information systems security training: An action research study. MIS Quart. 34(4):757–778.CrossrefGoogle Scholar
  • Punj GN, Staelin R (1983) A model of consumer information search behavior for new automobiles. J. Consumer Res. 9(4):366–380.CrossrefGoogle Scholar
  • Richardson R (2008) CSI computer crime and security survey, Computer Security Institute, New York.Google Scholar
  • Sachse K, Jungermann H, Belting JM (2012) Investment risk—The perspective of individual investors. J. Econom. Psych. 33(3):437–447.CrossrefGoogle Scholar
  • Sandman PM (1993) Responding to Community Outrage: Strategies for Effective Risk Communication (American Industrial Hygiene Association, Fairfax, VA).CrossrefGoogle Scholar
  • Schmidt JB, Sprang RA (1996) A proposed model of external consumer information search. J. Acad. Marketing Sci. 24(3):246–256.CrossrefGoogle Scholar
  • Sinharay S (2004) Experiences with Markov chain Monte Carlo convergence assessment in two psychometric examples. J. Educational Behavioral Statist. 29(4):461–488.CrossrefGoogle Scholar
  • Slovic P (1987) Perception of risk. Science 236(4700):280–285.CrossrefGoogle Scholar
  • Slovic P (2000) The Perception of Risk (Earthscan, Sterling, VA).Google Scholar
  • Slovic P, Fischhoff B, Lichtenstein S (1980) Facts and fears: Understanding perceived risk. Schwing R, Albers WA, eds. Societal Risk Assessment: How Safe Is Safe Enough? (Plenum, New York), 181–216.CrossrefGoogle Scholar
  • Slovic P, MacGregor DG, Kraus NN (1987) Perception of risk from automobile safety defects. Accident Anal. Prevention 19(5):359–373.CrossrefGoogle Scholar
  • Spears JL, Barki H (2010) User participation in information systems security risk management. MIS Quart. 34(3):503–522.CrossrefGoogle Scholar
  • Spiegelhalter D, Thomas A, Best N, Lunn D (2003) WinBUGS user manual. MRC Biostatistics Unit, Institute of Public Health, Cambridge, UK.Google Scholar
  • Srinivasan N (1990) Pre-purchase external search for information. Zeithaml VA, ed. Review of Marketing (American Marketing Association, Chicago), 153–189.Google Scholar
  • Straub DW, Welke RJ (1998) Coping with systems risk: Security planning models for management decision making. MIS Quart. 22(4):441–469.CrossrefGoogle Scholar
  • ter Huurne EFJ, Griffin RJ, Gutteling JM (2009) Risk information seeking among U.S. and Dutch residents: An application of the model of risk information seeking and processing. Sci. Commun. 31(2):215–237.CrossrefGoogle Scholar
  • Turner D, Fossi M, Johnson E, Mack T, Blackbird J, Entwisle S, Low MK, McKinney D, Wueest C (2008) Internet security threat report. Symantec Corporation, Cupertino, CA.Google Scholar
  • Vakkari P, Pennanen M, Serola S (2003) Changes of search terms and tactics while writing a research proposal: A longitudinal case study. Inform. Processing Management 39(3):445–463.CrossrefGoogle Scholar
  • Wang J, Xiao N, Rao HR (2010) Drivers of information security search behavior: An investigation of network attacks and vulnerability disclosures. ACM Trans. Management Inform. Systems 1(1):Article 3.CrossrefGoogle Scholar
  • Wang J, Xiao N, Rao HR (2012) An exploration of risk information search via a search engine: Queries and clicks in healthcare and information security. Decision Support Systems 52(2):395–405.CrossrefGoogle Scholar
  • Wang M, Keller C, Siegrist M (2011) The less you know, the more you are afraid of—A survey on risk perceptions of investment products. J. Behavioral Finance 12(1):9–19.CrossrefGoogle Scholar
  • Warkentin M, Willison R (2009) Behavioral and policy issues in information systems security: The insider threat. Eur. J. Inform. Systems 18(2):101–105.CrossrefGoogle Scholar
  • Whitman ME (2003) Enemy at the gate: Threats to information security. Commun. ACM 46(8):91–95.CrossrefGoogle Scholar
  • Wildmuth BM (2004) The effects of domain knowledge on search tactic formulation. J. Amer. Soc. Inform. Sci. Technol. 55(3):246–258.CrossrefGoogle Scholar
  • Ybarra ML, Sumanb M (2006) Help seeking behavior and the Internet: A national survey. Internat. J. Medical Informatics 75(1):29–41.CrossrefGoogle Scholar
  • Zhang X, Anghelescu HGB, Yuan X (2005) Domain knowledge, search behaviour, and search effectiveness of engineering and science students: An exploratory study. Inform. Res. 10(2):Paper 217. http://InformationR.net/ir/10-2/paper217.html.Google Scholar
  • Zillmann D, Bryant J (1985) Affect, mood, and emotion as determinants of selective exposure. Zillmann D, Bryant J, eds. Selective Exposure to Communication (Lawrence Erlbaum, Hillsdale, NJ).Google Scholar
INFORMS site uses cookies to store information on your computer. Some are essential to make our site work; Others help us improve the user experience. By using this site, you consent to the placement of these cookies. Please read our Privacy Statement to learn more.