{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T06:43:11Z","timestamp":1751265791039},"publisher-location":"Boston","reference-count":30,"publisher":"Kluwer Academic Publishers","isbn-type":[{"type":"print","value":"1402080891"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/1-4020-8090-5_6","type":"book-chapter","created":{"date-parts":[[2006,1,14]],"date-time":"2006-01-14T08:04:14Z","timestamp":1137225854000},"page":"71-83","source":"Crossref","is-referenced-by-count":14,"title":["Economics of IT Security Management"],"prefix":"10.1007","author":[{"given":"Huseyin","family":"Cavusoglu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"6_CR1","doi-asserted-by":"crossref","unstructured":"Axelsson, S., \u201cThe Base-Rate Fallacy and the Difficulty of Intrusion Detection,\u201d ACM Transactions on Information and System Security, 3(3), August 2000.","DOI":"10.1145\/357830.357849"},{"key":"6_CR2","doi-asserted-by":"crossref","unstructured":"Berinato, S. \u201cFinally, A Return on Security Spending,\u201d CIO Magazine, Feb 15, 2002.","DOI":"10.1016\/S1361-3723(02)00228-2"},{"issue":"12","key":"6_CR3","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1145\/163298.163309","volume":"36","author":"E. Brynjolfsson","year":"1993","unstructured":"Brynjolfsson, E., \u201cThe Productivity Paradox of Information Technology,\u201d Communications of the ACM, 36(12), pp. 66\u201377, 1993.","journal-title":"Communications of the ACM"},{"key":"6_CR4","unstructured":"Cagnemi, M. P., \u201cTop Technology Issues,\u201d Information Systems Control Journal, 4(6), 2001."},{"key":"6_CR5","unstructured":"Cavusoglu, H., B. K. Mishra and Raghunathan, S., \u201cAssessing the Value of Detective Control in IT Security,\u201d Proceedings of 8th Americas Conference on Information Systems, pp. 1910\u20131918, 2002a."},{"key":"6_CR6","unstructured":"Cavusoglu, H., B. K. Mishra and Raghunathan, S., \u201cConfiguration of Intrusion Detection Systems\u201d Working Paper, 2002b."},{"key":"6_CR7","unstructured":"Cavusoglu, H. and Raghunathan, S., \u201cConfiguration of Intrusion Detection Systems: A Comparison of Decision and Game Theoretic Approaches,\u201d International Conference on Information Systems (ICIS), Seattle, Washington, December 2003."},{"key":"6_CR8","unstructured":"Cavusoglu, H., Mishra, B. K. and Raghunathan, S., \u201cQuantifying the Value of IT Security Mechanisms and Setting Up an Effective Security Architecture,\u201d 2nd Annual Workshop on Economics and Information Security, College Park, Maryland, May 29\u201330, 2003a."},{"key":"6_CR9","unstructured":"Cavusoglu, H., B. K. Mishra and Raghunathan, S., \u201cA Model for Evaluating IT Security Investments,\u201d Communications of the ACM, Forthcoming, 2003b."},{"key":"6_CR10","doi-asserted-by":"crossref","unstructured":"Cavusoglu, H., B. K. Mishra and Raghunathan, S., \u201cThe Effect of Internet Security Breach Announcements on Market Value of Breached Firms and Internet Security Developers,\u201d International Journal of E-Commerce, Forthcoming, 2004a.","DOI":"10.1080\/10864415.2004.11044320"},{"key":"6_CR11","unstructured":"Cavusoglu H., S. Raghunathan and W. T. Yue, \u201cDecision Theoretic and Game Theoretic Approaches to IT Security Investment,\u201d Working Paper, 2004b."},{"key":"6_CR12","unstructured":"CERT\/CC Statistics, 2003, available at http:\/\/www.cert.org\/stats\/cert_stats.html ."},{"key":"6_CR13","unstructured":"Crume, J., Inside Internet Security, Addison Wesley, 2001."},{"key":"6_CR14","unstructured":"CSC News Release, CSC Survey Reveals Inadequate Information Security Practices Among Companies Worldwide, November 19, 2001, available at http:\/\/www.csc.com\/newsandevents\/news\/1584.shtml ."},{"key":"6_CR15","unstructured":"D\u2019Amico, A. D., What Does a Computer Security Breach Really Cost?, Secure Decisions, a Division of Applied Visions, Inc., September 7, 2000."},{"issue":"4","key":"6_CR16","first-page":"43","volume":"16","author":"D. Denning","year":"2000","unstructured":"Denning, D., \u201cReflections on Cyberweapons Controls,\u201d Computer Security Journal, 16(4), pp. 43\u201353, 2000.","journal-title":"Computer Security Journal"},{"key":"6_CR17","doi-asserted-by":"crossref","unstructured":"Escamilla, T., Intrusion Detection: Network Security Beyond the Firewall, John Wiley & Sons, 1998.","DOI":"10.1016\/S1353-4858(00)87593-5"},{"issue":"1","key":"6_CR18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.2307\/2525569","volume":"10","author":"E. Fama","year":"1969","unstructured":"Fama, E., L. Fisher, M. C. Jensen and R. Roll, \u201cThe Adjustment of Stock Prices to New Information,\u201d International Economic Review, 10(1), pp. 1\u201321, 1969.","journal-title":"International Economic Review"},{"key":"6_CR19","doi-asserted-by":"crossref","unstructured":"Gaffney, J.E. Jr. and J.W. Ulvila, \u201cEvaluation of Intrusion Detectors: A Decision Theory Approach,\u201d Proceedings of IEEE Symposium on Security and Privacy, pp. 50\u201361, 2001.","DOI":"10.1109\/SECPRI.2001.924287"},{"key":"6_CR20","doi-asserted-by":"crossref","unstructured":"Gordon, L. A. and M. P. Loeb, \u201cThe Economics of Information Security Investment,\u201d ACM Transactions on Information and Systems Security, pp. 438\u2013457, November 2002.","DOI":"10.1145\/581271.581274"},{"issue":"1\/2","key":"6_CR21","doi-asserted-by":"crossref","first-page":"5","DOI":"10.3233\/JCS-2002-101-202","volume":"10","author":"W. Lee","year":"2002","unstructured":"Lee, W., W. Fan, M. Miller, S. Stolfo and E. Zadok, \u201cToward Cost-Sensitive Modeling for Intrusion Detection and Response,\u201d Journal of Computer Security, 10,1\/2, pp. 5\u201322, 2002.","journal-title":"Journal of Computer Security"},{"key":"6_CR22","doi-asserted-by":"crossref","unstructured":"Longstaff, T. A., C. Chittister, R. Pethia and Y. Y. Haimes, \u201cAre We Forgetting the Risks of Information Technology?,\u201d IEEE Computer, pp. 43\u201351, December 2000.","DOI":"10.1109\/2.889092"},{"key":"6_CR23","unstructured":"Moitra, S. D. and S. L. Konda, \u201cThe Survivability of Network Systems: An Empirical Analysis,\u201d Technical Report, CMU\/SEI-2000-TR-021, December 2000."},{"key":"6_CR24","unstructured":"Nicholson, L. J., T. F. Shebar and M. R. Weinberg, \u201cComputer Crimes,\u201d The American Criminal Law Review, Spring 2000."},{"key":"6_CR25","unstructured":"Pastore, M., Companies Lack Understanding of Information Security Issues, Internet. Com, October 10, 2001."},{"key":"6_CR26","doi-asserted-by":"crossref","unstructured":"Power, R., \u201c2002 CSI\/FBI Computer Crime and Security Survey,\u201d Computer Security Issues and Trends, 8(1), 2002.","DOI":"10.1016\/S1361-3723(02)01001-1"},{"key":"6_CR27","unstructured":"Russell, D. and G. T. Gangemi, Computer Security Basics, O\u2019Reilly & Associates, Inc. 1992."},{"key":"6_CR28","unstructured":"Soo Hoo, K. J., \u201cHow Much is Enough? A Risk-Management Approach to Computer Security,\u201d PhD Dissertation, Stanford University, June 2000."},{"key":"6_CR29","doi-asserted-by":"crossref","unstructured":"Stoneburner, G., A. Goguen and A. Feringa, Risk Management Guide for Information Technology Systems, NIST Special Publication 800-30, 2001.","DOI":"10.6028\/NIST.SP.800-30"},{"key":"6_CR30","unstructured":"Wei, H., D. Frinke, O. Carter and C. Ritter, \u201cCost-Benefit Analysis for Intrusion Detection Systems,\u201d CSI 28th Annual Computer Security Conference, 2001."}],"container-title":["Advances in Information Security","Economics of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/1-4020-8090-5_6.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,5,6]],"date-time":"2023-05-06T05:27:59Z","timestamp":1683350879000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/1-4020-8090-5_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["1402080891"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/1-4020-8090-5_6","relation":{},"subject":[]}}