{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T12:25:50Z","timestamp":1780403150821,"version":"3.54.1"},"publisher-location":"Berlin, Heidelberg","reference-count":50,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642168246","type":"print"},{"value":"9783642168253","type":"electronic"}],"license":[{"start":{"date-parts":[[2010,1,1]],"date-time":"2010-01-01T00:00:00Z","timestamp":1262304000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-16825-3_2","type":"book-chapter","created":{"date-parts":[[2010,11,2]],"date-time":"2010-11-02T13:30:44Z","timestamp":1288704644000},"page":"10-24","source":"Crossref","is-referenced-by-count":35,"title":["Security Metrics and Security Investment Models"],"prefix":"10.1007","author":[{"given":"Rainer","family":"B\u00f6hme","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"2_CR1","unstructured":"Canalys Enterprise Security Analysis: Global enterprise security market to grow 13.8% in 2010 (2010), http:\/\/www.canalys.com\/pr\/2010\/r2010072.html"},{"key":"2_CR2","unstructured":"Richardson, R.: CSI Computer Crime and Security Survey. Computer Security Institute (2008)"},{"key":"2_CR3","unstructured":"METI: Report on survey of actual condition of it usage in FY 2009 (June 2009), http:\/\/www.meti.go.jp\/statistics\/zyo\/zyouhou\/result-1.html"},{"issue":"4","key":"2_CR4","doi-asserted-by":"publisher","first-page":"438","DOI":"10.1145\/581271.581274","volume":"5","author":"L.A. Gordon","year":"2002","unstructured":"Gordon, L.A., Loeb, M.P.: The economics of information security investment. ACM Transactions on Information and System Security\u00a05(4), 438\u2013457 (2002)","journal-title":"ACM Transactions on Information and System Security"},{"key":"2_CR5","unstructured":"Willemson, J.: On the Gordon & Loeb model for information security investment. In: Workshop on the Economics of Information Security (WEIS). University of Cambridge, UK (2006)"},{"issue":"5","key":"2_CR6","doi-asserted-by":"publisher","first-page":"338","DOI":"10.1007\/s10796-006-9011-6","volume":"8","author":"K. Hausken","year":"2006","unstructured":"Hausken, K.: Returns to information security investment: The effect of alternative information security breach functions on optimal investment and sensitivity to vulnerability. Information Systems Frontiers\u00a08(5), 338\u2013349 (2006)","journal-title":"Information Systems Frontiers"},{"key":"2_CR7","doi-asserted-by":"crossref","unstructured":"Matsuura, K.: Productivity space of information security in an extension of the Gordon\u2013Loeb\u2019s investment model. In: Workshop on the Economics of Information Security (WEIS), Tuck School of Business, Dartmouth College, Hanover, NH (2008)","DOI":"10.1007\/978-0-387-09762-6_5"},{"key":"2_CR8","doi-asserted-by":"crossref","unstructured":"Tatsumi, K.i., Goto, M.: Optimal timing of information security investment: A real options approach. In: Workshop on the Economics of Information Security (WEIS). University College London, UK (2009)","DOI":"10.1007\/978-1-4419-6967-5_11"},{"key":"2_CR9","unstructured":"B\u00f6hme, R., Moore, T.W.: The iterated weakest link: A model of adaptive security investment. In: Workshop on the Economics of Information Security (WEIS), University College London, UK (2009)"},{"key":"2_CR10","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1016\/j.jaccpubpol.2004.12.003","volume":"24","author":"H. Tanaka","year":"2005","unstructured":"Tanaka, H., Matsuura, K., Sudoh, O.: Vulnerability and information security investment: An empirical analysis of e-local government in Japan. Journal of Accounting and Public Policy\u00a024, 37\u201359 (2005)","journal-title":"Journal of Accounting and Public Policy"},{"key":"2_CR11","unstructured":"Brocke, J., Grob, H., Buddendick, C., Strauch, G.: Return on security investments. Towards a methodological foundation of measurement systems. In: Proc. of AMCIS (2007)"},{"key":"2_CR12","volume-title":"Security Metrics: Replacing Fear, Uncertainty, and Doubt","author":"A. Jacquith","year":"2007","unstructured":"Jacquith, A.: Security Metrics: Replacing Fear, Uncertainty, and Doubt. Addison-Wesley, Reading (2007)"},{"key":"2_CR13","unstructured":"Alberts, C.J., Dorofee, A.J.: An introduction to the OCTAVE $^{\\rm TM} $ method (2001), http:\/\/www.cert.org\/octave\/methodintro.html"},{"issue":"2","key":"2_CR14","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1145\/1042091.1042094","volume":"48","author":"L.D. Bodin","year":"2005","unstructured":"Bodin, L.D., Gordon, L.A., Loeb, M.P.: Evaluating information security investments using the analytic hierarchy process. Communications of the ACM\u00a048(2), 79\u201383 (2005)","journal-title":"Communications of the ACM"},{"key":"2_CR15","unstructured":"Su, X.: An overview of economic approaches to information security management. Technical Report TR-CTIT-06-30, University of Twente (2006)"},{"key":"2_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"176","DOI":"10.1007\/978-3-540-68947-8_15","volume-title":"Dependability Metrics","author":"R. B\u00f6hme","year":"2008","unstructured":"B\u00f6hme, R., Nowey, T.: Economic security metrics. In: Eusgeld, I., Freiling, F.C., Reussner, R. (eds.) Dependability Metrics. LNCS, vol.\u00a04909, pp. 176\u2013187. Springer, Heidelberg (2008)"},{"key":"2_CR17","unstructured":"Sheen, J.: Fuzzy economic decision-models for information security investment. In: Proc.\u00a0of IMCAS, Hangzhou, China, pp. 141\u2013147 (2010)"},{"key":"2_CR18","unstructured":"Schryen, G.: A fuzzy model for it security investments. In: Proc.\u00a0of ISSE\/GI-SICHERHEIT, Berlin, Germany (to appear, 2010)"},{"key":"2_CR19","unstructured":"Soo Hoo, K.J.: How much is enough? A risk-management approach to computer security. In: Workshop on Economics and Information Security (WEIS), University of California, Berkeley, CA (2002)"},{"issue":"2","key":"2_CR20","first-page":"86","volume":"10","author":"D.E. Geer","year":"2009","unstructured":"Geer, D.E., Conway, D.G.: Hard data is good to find. IEEE Security & Privacy\u00a010(2), 86\u201387 (2009)","journal-title":"IEEE Security & Privacy"},{"key":"2_CR21","doi-asserted-by":"crossref","unstructured":"Anderson, R., B\u00f6hme, R., Clayton, R., Moore, T.: Security Economics and the Internal Market. Study commissioned by ENISA (2008)","DOI":"10.1007\/978-0-387-09762-6_3"},{"key":"2_CR22","unstructured":"Matsuura, K.: Security tokens and their derivatives. Technical report, Centre for Communications Systems Research (CCSR), University of Cambridge, UK (2001)"},{"key":"2_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"298","DOI":"10.1007\/11766155_21","volume-title":"Emerging Trends in Information and Communication Security","author":"R. B\u00f6hme","year":"2006","unstructured":"B\u00f6hme, R.: A comparison of market approaches to software vulnerability disclosure. In: M\u00fcller, G. (ed.) ETRICS 2006. LNCS, vol.\u00a03995, pp. 298\u2013311. Springer, Heidelberg (2006)"},{"key":"2_CR24","doi-asserted-by":"publisher","first-page":"542","DOI":"10.1016\/j.cose.2004.09.004","volume":"23","author":"S.A. Purser","year":"2004","unstructured":"Purser, S.A.: Improving the ROI of the security management process. Computers & Security\u00a023, 542\u2013546 (2004)","journal-title":"Computers & Security"},{"key":"2_CR25","unstructured":"Schneier, B.: Security ROI: Fact or fiction? CSO Magazine (September 2008)"},{"issue":"2","key":"2_CR26","first-page":"1","volume":"14","author":"L.A. Gordon","year":"2003","unstructured":"Gordon, L.A., Loeb, M.P., Lucyshyn, W.: Information security expenditures and real options: A wait-and-see approach. Computer Security Journal\u00a014(2), 1\u20137 (2003)","journal-title":"Computer Security Journal"},{"issue":"3","key":"2_CR27","doi-asserted-by":"publisher","first-page":"337","DOI":"10.2753\/MIS0742-1222250310","volume":"25","author":"H.S.B. Herath","year":"2008","unstructured":"Herath, H.S.B., Herath, T.C.: Investments in information security: A real options perspective with Bayesian postaudit. Journal of Management Information Systems\u00a025(3), 337\u2013375 (2008)","journal-title":"Journal of Management Information Systems"},{"issue":"1","key":"2_CR28","doi-asserted-by":"publisher","first-page":"329","DOI":"10.2753\/MIS0742-1222240110","volume":"24","author":"W.T. Yue","year":"2007","unstructured":"Yue, W.T., \u00c7akanyildirim, M.: Intrusion prevention in information systems: Reactive and proactive responses. Journal of Management Information Systems\u00a024(1), 329\u2013353 (2007)","journal-title":"Journal of Management Information Systems"},{"key":"2_CR29","doi-asserted-by":"publisher","first-page":"673","DOI":"10.1109\/GAMENETS.2009.5137460","volume-title":"Proceedings of the International Conference on Game Theory for Networks (GameNets 2009), Istanbul, Turkey","author":"J. Grossklags","year":"2009","unstructured":"Grossklags, J., Johnson, B.: Uncertainty in the weakest-link security game. In: Proceedings of the International Conference on Game Theory for Networks (GameNets 2009), Istanbul, Turkey, pp. 673\u2013682. IEEE Press, Los Alamitos (2009)"},{"key":"2_CR30","doi-asserted-by":"crossref","unstructured":"Gordon, L.A., Loeb, M.P., Lucysshyn, W.: Sharing information on computer systems security: An economic analysis. Journal of Accounting and Public Policy 22(6) (2003)","DOI":"10.1016\/j.jaccpubpol.2003.09.001"},{"issue":"2","key":"2_CR31","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1287\/isre.1050.0053","volume":"16","author":"E. Gal-Or","year":"2005","unstructured":"Gal-Or, E., Ghose, A.: The economic incentives for sharing security information. Information Systems Research\u00a016(2), 186\u2013208 (2005)","journal-title":"Information Systems Research"},{"issue":"1-2","key":"2_CR32","doi-asserted-by":"publisher","first-page":"5","DOI":"10.3233\/JCS-2002-101-202","volume":"10","author":"W. Lee","year":"2002","unstructured":"Lee, W., Fan, W., Miller, M., Stolfo, S.J., Zadok, E.: Toward cost-sensitive modeling for intrusion detection and response. Journal of Computer Security\u00a010(1-2), 5\u201322 (2002)","journal-title":"Journal of Computer Security"},{"issue":"1","key":"2_CR33","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1287\/isre.1050.0041","volume":"16","author":"H. Cavusoglu","year":"2005","unstructured":"Cavusoglu, H., Mishra, B., Raghunathan, S.: The value of intrusion detection systems in information technology security architecture. Information Systems Research\u00a016(1), 28\u201346 (2005)","journal-title":"Information Systems Research"},{"key":"2_CR34","unstructured":"B\u00f6hme, R., F\u00e9legyh\u00e1zi, M.: Optimal information security investment with penetration testing. In: Decision and Game Theory for Security (GameSec), Berlin, Germany (to appear, 2010)"},{"key":"2_CR35","doi-asserted-by":"publisher","DOI":"10.21236\/ADA412014","volume-title":"Outsourcing managed Security Services","author":"J. Allen","year":"2003","unstructured":"Allen, J., Gabbard, D., May, C.: Outsourcing managed Security Services. Carnegie Mellon Software Engineering Institute, Pittsburgh (2003)"},{"issue":"4","key":"2_CR36","doi-asserted-by":"publisher","first-page":"305","DOI":"10.1016\/0304-405X(76)90026-X","volume":"3","author":"M.C. Jensen","year":"1976","unstructured":"Jensen, M.C., Meckling, W.H.: Theory of the firm: Managerial behavior, agency costs and ownership structure. Journal of Financial Economics\u00a03(4), 305\u2013360 (1976)","journal-title":"Journal of Financial Economics"},{"key":"2_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"947","DOI":"10.1007\/11600930_96","volume-title":"Internet and Network Economics","author":"W. Ding","year":"2005","unstructured":"Ding, W., Yurcik, W., Yin, X.: Outsourcing internet security: Economic analysis of incentives for managed security service providers. In: Deng, X., Ye, Y. (eds.) WINE 2005. LNCS, vol.\u00a03828, pp. 947\u2013958. Springer, Heidelberg (2005)"},{"key":"2_CR38","doi-asserted-by":"crossref","unstructured":"Ding, W., Yurcik, W.: Outsourcing internet security: The effect of transaction costs o managed service providers. In: Prof. of Intl. Conf.on Telecomm. Systems, pp. 947\u2013958 (2005)","DOI":"10.1007\/11600930_96"},{"key":"2_CR39","unstructured":"Rowe, B.R.: Will outsourcing IT security lead to a higher social level of security? In: Workshop on the Economics of Information Security (WEIS), Carnegie Mellon University, Pittsburgh, PA (2007)"},{"key":"2_CR40","unstructured":"Schneier, B.: Why Outsource? Counterpane Inc. (2006)"},{"key":"2_CR41","unstructured":"Cezar, A., Cavusoglu, H., Raghunathan, S.: Outsourcing information security: Contracting issues and security implications. In: Workshop on the Economics of Information Security (WEIS), Harvard University, Cambridge, MA (2010)"},{"key":"2_CR42","unstructured":"B\u00f6hme, R., Schwartz, G.: Modeling cyber-insurance: Towards a unifying framework. In: Workshop on the Economics of Information Security (WEIS), Harvard University, Cambridge, MA (2010)"},{"key":"2_CR43","doi-asserted-by":"crossref","unstructured":"Zhao, X., Xue, L., Whinston, A.B.: Managing interdependent information security risks: A study of cyberinsurance, managed security service and risk pooling. In: Proc. of ICIS (2009)","DOI":"10.2139\/ssrn.1593137"},{"key":"2_CR44","unstructured":"Varian, H.R.: System reliability and free riding. In: Workshop on the Economics of Information Security (WEIS), University of California, Berkeley (2002)"},{"key":"2_CR45","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1007\/BF00141070","volume":"41","author":"J. Hirshleifer","year":"1983","unstructured":"Hirshleifer, J.: From weakest-link to best-shot: The voluntary provision of public goods. Public Choice\u00a041, 371\u2013386 (1983)","journal-title":"Public Choice"},{"issue":"2-3","key":"2_CR46","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1023\/A:1024119208153","volume":"26","author":"H. Kunreuther","year":"2003","unstructured":"Kunreuther, H., Heal, G.: Interdependent security. Journal of Risk and Uncertainty\u00a026(2-3), 231\u2013249 (2003)","journal-title":"Journal of Risk and Uncertainty"},{"key":"2_CR47","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1145\/1367497.1367526","volume-title":"Proceeding of the International Conference on World Wide Web (WWW)","author":"J. Grossklags","year":"2008","unstructured":"Grossklags, J., Christin, N., Chuang, J.: Secure or insure? A game-theoretic analysis of information security games. In: Proceeding of the International Conference on World Wide Web (WWW), Beijing, China, pp. 209\u2013218. ACM Press, New York (2008)"},{"key":"2_CR48","unstructured":"Cremonini, M., Nizovtsev, D.: Understanding and influencing attackers\u2019 decisions: Implications for security investment strategies. In: Workshop on the Economics of Information Security (WEIS), University of Cambridge, UK (2006)"},{"key":"2_CR49","unstructured":"Liu, W., Tanaka, H., Matsuura, K.: An empirical analysis of security investment in countermeasures based on an enterprise survey in Japan. In: Workshop on the Economics of Information Security (WEIS), University of Cambridge, UK (2006)"},{"key":"2_CR50","doi-asserted-by":"crossref","unstructured":"Berthold, S., B\u00f6hme, R.: Valuating privacy with option pricing theory. In: Workshop on the Economics of Information Security (WEIS), University College London, UK (2009)","DOI":"10.1007\/978-1-4419-6967-5_10"}],"container-title":["Lecture Notes in Computer Science","Advances in Information and Computer Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-16825-3_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,6]],"date-time":"2019-06-06T01:00:16Z","timestamp":1559782816000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-16825-3_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642168246","9783642168253"],"references-count":50,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-16825-3_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010]]}}}