Outsourcing Information Security: Contracting Issues and Security Implications
No Thumbnail Available
Date
2014-03
Journal Title
Journal ISSN
Volume Title
Publisher
INFORMS Inst.for Operations Res.and the Management Sciences
Open Access Color
Green Open Access
No
OpenAIRE Downloads
OpenAIRE Views
Publicly Funded
No
Abstract
A unique challenge in information security outsourcing is that neither the outsourcing firm nor the managed security service provider (MSSP) perfectly observes the outcome, the occurrence of a security breach, of prevention effort. Detection of security breaches often requires specialized effort. The current practice is to outsource both prevention and detection to the same MSSP. Some security experts have advocated outsourcing prevention and detection to different MSSPs. We show that the former outsourcing contract leads to a significant disincentive to provide detection effort. The latter contract alleviates this problem but introduces misalignment of incentives between the firm and the MSSPs and eliminates the advantages offered by complementarity between prevention and detection functions, which may lead to a worse outcome than the current contract. We propose a new contract that is superior to these two on various dimensions.
Description
Keywords
Industry, Security of data, Security of data, Industry
Turkish CoHE Thesis Center URL
Fields of Science
0502 economics and business, 05 social sciences
Citation
Cezar, A., Cavusoglu, H., & Raghunathan, S. (2013). Outsourcing information security: Contracting issues and security implications. Management Science, 60(3), 638-657.
WoS Q
Q1
Scopus Q
Q1

OpenCitations Citation Count
57
Source
Management Science
Volume
60
Issue
3
Start Page
638
End Page
657
PlumX Metrics
Citations
CrossRef : 48
Scopus : 71
Captures
Mendeley Readers : 126
SCOPUS™ Citations
71
checked on Dec 22, 2025
Web of Science™ Citations
54
checked on Dec 22, 2025
Page Views
500
checked on Dec 22, 2025
Google Scholar™

OpenAlex FWCI
7.00619912
Sustainable Development Goals
3
GOOD HEALTH AND WELL-BEING

7
AFFORDABLE AND CLEAN ENERGY

8
DECENT WORK AND ECONOMIC GROWTH

9
INDUSTRY, INNOVATION AND INFRASTRUCTURE

10
REDUCED INEQUALITIES

11
SUSTAINABLE CITIES AND COMMUNITIES

12
RESPONSIBLE CONSUMPTION AND PRODUCTION

16
PEACE, JUSTICE AND STRONG INSTITUTIONS

17
PARTNERSHIPS FOR THE GOALS


