{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T01:10:21Z","timestamp":1781917821243,"version":"3.54.5"},"publisher-location":"Berlin, Heidelberg","reference-count":29,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642329456","type":"print"},{"value":"9783642329463","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-32946-3_11","type":"book-chapter","created":{"date-parts":[[2012,8,14]],"date-time":"2012-08-14T08:56:16Z","timestamp":1344934576000},"page":"129-147","source":"Crossref","is-referenced-by-count":14,"title":["Security Audits Revisited"],"prefix":"10.1007","author":[{"given":"Rainer","family":"B\u00f6hme","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"11_CR1","doi-asserted-by":"crossref","unstructured":"Anderson, R., B\u00f6hme, R., Clayton, R., Moore, T.: Security Economics and the Internal Market. Study commissioned by ENISA (2008)","DOI":"10.1007\/978-0-387-09762-6_3"},{"key":"11_CR2","unstructured":"Anderson, R.J.: Why information security is hard \u2013 An economic perspective (2001)"},{"key":"11_CR3","unstructured":"Armbrust, M., et al.: Above the clouds: A Berkeley view of cloud computing. Technical Report EECS\u20132009\u201328, University of California, Berkeley (2009)"},{"key":"11_CR4","unstructured":"Axelrod, R.: The Evolution of Cooperation. Basic Books, New York (1984)"},{"key":"11_CR5","doi-asserted-by":"crossref","unstructured":"Baye, M.R., Morgan, J.: Red queen pricing effects in e-retail markets. Working Paper (2003)","DOI":"10.2139\/ssrn.655448"},{"key":"11_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1007\/978-3-642-16825-3_2","volume-title":"Advances in Information and Computer Security","author":"R. B\u00f6hme","year":"2010","unstructured":"B\u00f6hme, R.: Security Metrics and Security Investment Models. In: Echizen, I., Kunihiro, N., Sasaki, R. (eds.) IWSEC 2010. LNCS, vol.\u00a06434, pp. 10\u201324. Springer, Heidelberg (2010)"},{"key":"11_CR7","unstructured":"B\u00f6hme, R., Moore, T.W.: The iterated weakest link: A model of adaptive security investment. In: Workshop on the Economics of Information Security (WEIS). University College London, UK (2009)"},{"issue":"4","key":"11_CR8","doi-asserted-by":"publisher","first-page":"793","DOI":"10.1162\/003465303772815736","volume":"85","author":"E. Brynjolfsson","year":"2003","unstructured":"Brynjolfsson, E., Hitt, L.: Computing productivity: Firm-level evidence. The Review of Economics and Statistics\u00a085(4), 793\u2013808 (2003)","journal-title":"The Review of Economics and Statistics"},{"issue":"5","key":"11_CR9","first-page":"41","volume":"81","author":"N.G. Carr","year":"2003","unstructured":"Carr, N.G.: IT doesn\u2019t matter. Harvard Business Review\u00a081(5), 41\u201349 (2003)","journal-title":"Harvard Business Review"},{"key":"11_CR10","unstructured":"Edelman, B.: Adverse selection in online \u201ctrust\u201d certifications. In: Workshop on the Economics of Information Security (WEIS). University of Cambridge, UK (2006)"},{"issue":"4","key":"11_CR11","doi-asserted-by":"publisher","first-page":"438","DOI":"10.1145\/581271.581274","volume":"5","author":"L.A. Gordon","year":"2002","unstructured":"Gordon, L.A., Loeb, M.P.: The economics of information security investment. ACM Trans.\u00a0on Information and System Security\u00a05(4), 438\u2013457 (2002)","journal-title":"ACM Trans.\u00a0on Information and System Security"},{"key":"11_CR12","doi-asserted-by":"crossref","first-page":"209","DOI":"10.1145\/1367497.1367526","volume-title":"Proc.\u00a0of the Int\u2019l Conference on World Wide Web (WWW)","author":"J. Grossklags","year":"2008","unstructured":"Grossklags, J., Christin, N., Chuang, J.: Secure or insure? A game-theoretic analysis of information security games. In: Proc.\u00a0of the Int\u2019l Conference on World Wide Web (WWW), pp. 209\u2013218. ACM Press, Beijing (2008)"},{"key":"11_CR13","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1007\/BF00141070","volume":"41","author":"J. Hirshleifer","year":"1983","unstructured":"Hirshleifer, J.: From weakest-link to best-shot: The voluntary provision of public goods. Public Choice\u00a041, 371\u2013386 (1983)","journal-title":"Public Choice"},{"key":"11_CR14","unstructured":"Jacquith, A.: Security Metrics: Replacing Fear, Uncertainty, and Doubt. Addison-Wesley (2007)"},{"key":"11_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1007\/978-3-642-25280-8_11","volume-title":"Decision and Game Theory for Security","author":"B. Johnson","year":"2011","unstructured":"Johnson, B., B\u00f6hme, R., Grossklags, J.: Security Games with Market Insurance. In: Baras, J.S., Katz, J., Altman, E. (eds.) GameSec 2011. LNCS, vol.\u00a07037, pp. 117\u2013130. Springer, Heidelberg (2011)"},{"issue":"2-3","key":"11_CR16","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1023\/A:1024119208153","volume":"26","author":"H. Kunreuther","year":"2003","unstructured":"Kunreuther, H., Heal, G.: Interdependent security. Journal of Risk and Uncertainty\u00a026(2-3), 231\u2013249 (2003)","journal-title":"Journal of Risk and Uncertainty"},{"key":"11_CR17","unstructured":"Liu, W., Tanaka, H., Matsuura, K.: An empirical analysis of security investment in countermeasures based on an enterprise survey in Japan. In: Workshop on the Economics of Information Security (WEIS). University of Cambridge, UK (2006)"},{"key":"11_CR18","unstructured":"Molnar, D., Schechter, S.: Self hosting vs. cloud hosting: Accounting for the security impact of hosting in the cloud. In: Workshop on the Economics of Information Security (WEIS). Harvard University, Cambridge (2010)"},{"key":"11_CR19","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"H. Ogut","year":"2005","unstructured":"Ogut, H., Menon, N., Raghunathan, S.: Cyber insurance and it security investment: Impact of interdependent risk. In: Workshop on the Economics of Information Security (WEIS). Harvard University, Cambridge (2005)"},{"key":"11_CR20","unstructured":"Parameswaran, M., Whinston, A.B.: Incentive mechanisms for internet security. In: Rao, H.R., Upadhyaya, S. (eds.) Handbooks in Information Systems, Emerald, vol.\u00a04, pp. 101\u2013138 (2009)"},{"key":"11_CR21","volume-title":"Geekonomics \u2013 The Real Cost of Insecure Software","author":"D. Rice","year":"2007","unstructured":"Rice, D.: Geekonomics \u2013 The Real Cost of Insecure Software. Addison-Wesley, New York (2007)"},{"key":"11_CR22","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"B.R. Rowe","year":"2007","unstructured":"Rowe, B.R.: Will outsourcing IT security lead to a higher social level of security? In: Workshop on the Economics of Information Security (WEIS). Carnegie Mellon University, Pittsburgh (2007)"},{"issue":"9","key":"11_CR23","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1145\/1151030.1151052","volume":"49","author":"S. Sackmann","year":"2006","unstructured":"Sackmann, S., Str\u00fcker, J., Accorsi, R.: Personalization in privacy-aware highly dynamic systems. Communications of the ACM\u00a049(9), 32\u201338 (2006)","journal-title":"Communications of the ACM"},{"key":"11_CR24","volume-title":"The Strategy of Conflict","author":"T. Schelling","year":"1965","unstructured":"Schelling, T.: The Strategy of Conflict. Oxford University Press, Oxford (1965)"},{"key":"11_CR25","doi-asserted-by":"crossref","unstructured":"Shetty, N., Schwartz, G., Felegyhazi, M., Walrand, J.: Competitive cyber-insurance and internet security. In: Workshop on Economics of Information Security (WEIS). University College London, UK (2009)","DOI":"10.1007\/978-1-4419-6967-5_12"},{"key":"11_CR26","unstructured":"Telang, R., Yang, Y.: Do security certifications work? Evidence from Common Criteria certification. In: IEEE International Conference on Technologies for Homeland Security (2011)"},{"key":"11_CR27","unstructured":"Varian, H.R.: System reliability and free riding. In: Workshop on the Economics of Information Security (WEIS). University of California, Berkeley (2002)"},{"key":"11_CR28","unstructured":"Winkler, S., Proschinger, C.: Collaborative penetration testing. In: Business Services: Konzepte, Technologien, Anwendungen (9. Internationale Tagung Wirtschaftsinformatik), vol.\u00a01, pp. 793\u2013802 (2009)"},{"key":"11_CR29","doi-asserted-by":"crossref","unstructured":"Zhao, X., Xue, L., Whinston, A.B.: Managing interdependent information security risks: A study of cyberinsurance, managed security service and risk pooling. In: Proceedings of ICIS (2009)","DOI":"10.2139\/ssrn.1593137"}],"container-title":["Lecture Notes in Computer Science","Financial Cryptography and Data Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-32946-3_11.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,26]],"date-time":"2022-01-26T14:26:14Z","timestamp":1643207174000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-32946-3_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642329456","9783642329463"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-32946-3_11","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012]]}}}