{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T06:06:49Z","timestamp":1777615609842,"version":"3.51.4"},"reference-count":28,"publisher":"Emerald","issue":"5","license":[{"start":{"date-parts":[[2007,10,16]],"date-time":"2007-10-16T00:00:00Z","timestamp":1192492800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2007,10,16]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>This research paper aims to examine how incident\u2010reporting systems function and particularly how the steady growth of high\u2010priority incidents and the semi\u2010exponential growth of low\u2010priority incidents affect reporting effectiveness. Social pressures that can affect low\u2010 and high\u2010priority incident\u2010reporting rates are also examined.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>The authors reviewed the incident\u2010reporting system literature. As there are few studies of information security reporting systems, they also considered safety\u2010reporting systems. These have been in use for many years and much is known about them. Safety is used to \u201cfill in the gaps\u201d. The authors then constructed a system dynamics computer simulation model. The model is used to test how an incident\u2010reporting system reacts under different conditions.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>Incident reporters face incentives and disincentives based on effects on through\u2010put but have limited knowledge of what is important to the organization's security. Even if a successful incident\u2010reporting policy is developed, the organization may become the victim of its own success, as a growing volume of reports put higher pressure on incident\u2010handling resources. Continuously hiring personnel is unsustainable. Continuously improving automated tools for incident response promises more leverage.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Research limitations\/implications<\/jats:title><jats:p>The challenges in safety may not be the same as those in information security. However, the model does provide a starting\u2010point for further enquiries into information security reporting systems.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>An examination of basic factors that affect information security reporting systems is provided. Four different policies are presented and examined through simulation scenarios.<\/jats:p><\/jats:sec>","DOI":"10.1108\/09685220710831143","type":"journal-article","created":{"date-parts":[[2007,9,29]],"date-time":"2007-09-29T07:03:01Z","timestamp":1191049381000},"page":"408-419","source":"Crossref","is-referenced-by-count":6,"title":["Toward viable information security reporting systems"],"prefix":"10.1108","volume":"15","author":[{"given":"Finn","family":"Olav Sveen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jose M.","family":"Sarriegi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eliot","family":"Rich","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jose J.","family":"Gonzalez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022012220354457700_b1","doi-asserted-by":"crossref","unstructured":"Anderson, D.J. and Webster, C.S. (2001), \u201cA system approach to the reduction of medication error on the hospital ward\u201d, Journal of Advanced Nursing, Vol. 35, pp. 34\u201041.","DOI":"10.1046\/j.1365-2648.2001.01820.x"},{"key":"key2022012220354457700_b2","doi-asserted-by":"crossref","unstructured":"Barlas, Y. (1989), \u201cMultiple tests for validation of system dynamics type of simulation models\u201d, European Journal of Operations Research, Vol. 42, pp. 59\u201087.","DOI":"10.1016\/0377-2217(89)90059-3"},{"key":"key2022012220354457700_b3","doi-asserted-by":"crossref","unstructured":"Barlas, Y. (1996), \u201cFormal aspects of model validity and validation in system dynamics\u201d, System Dynamics Review, Vol. 12, pp. 183\u2010210.","DOI":"10.1002\/(SICI)1099-1727(199623)12:3<183::AID-SDR103>3.0.CO;2-4"},{"key":"key2022012220354457700_b4","unstructured":"Calder, A. and Watkins, S. (2005), IT Governance, Kogan Page, London."},{"key":"key2022012220354457700_b5","doi-asserted-by":"crossref","unstructured":"Cooke, D.L. and Rohleder, T.R. (2006), \u201cLearning from incidents: from normal accidents to high reliability\u201d, System Dynamics Review, Vol. 22.","DOI":"10.1002\/sdr.338"},{"key":"key2022012220354457700_b6","unstructured":"Ernst & Young (2004), Global Information Security Survey, EYGM, Bangalore."},{"key":"key2022012220354457700_b7","unstructured":"Forrester, J.W. and Senge, P.M. (1980), \u201cTests for building confidence in system dynamics models\u201d, TIMS Studies in the Management Sciences, Vol. 14, pp. 209\u201028."},{"key":"key2022012220354457700_b8","doi-asserted-by":"crossref","unstructured":"Gonzalez, J.J. (2005), Towards a Cyber Security Reporting System \u2013 A Quality Improvement Process, Springer, Berlin Heidelberg.","DOI":"10.1007\/11563228_28"},{"key":"key2022012220354457700_b9","unstructured":"Gonzalez, J.J., Qian, Y., Sveen, F.O. and Rich, E. (2005), \u201cHelping prevent information security risks in the transition to integrated operations\u201d, Telektronikk, Vol. 101, pp. 29\u201037."},{"key":"key2022012220354457700_b10","unstructured":"ISO (2007), Information Technology \u2013 Security Techniques \u2014 Code of Practice for Information Security Management, International Organization for Standardization, Geneva."},{"key":"key2022012220354457700_b11","unstructured":"Johnson, C. (2003), Failure in Safety Critical Systems: A Handbook of Incident and Accident Reporting, Glasgow University Press, Glasgow."},{"key":"key2022012220354457700_b12","doi-asserted-by":"crossref","unstructured":"Kjell\u00e9n, U. (2000), Prevention of Accidents through Experience Feedback, Taylor & Francis, London.","DOI":"10.1201\/b17206"},{"key":"key2022012220354457700_b13","unstructured":"Lee, P.I. and Weitzel, T.R. (2005), \u201cAir carrier safety and culture: an investigation of Taiwan's adaptation to western incident reporting programs\u201d, Journal of Air Transportation, Vol. 10."},{"key":"key2022012220354457700_b14","doi-asserted-by":"crossref","unstructured":"Martinez\u2010Moyano, I.J., Rich, E., Conrad, S., Andersen, D.F. and Stewart, T.R. (2007), \u201cA behavioral theory of insider\u2010threat risks: a system dynamics approach\u201d, ACM Transactions on Modeling and Computer Simulation, pp. 1\u201036.","DOI":"10.1145\/1346325.1346328"},{"key":"key2022012220354457700_b15","doi-asserted-by":"crossref","unstructured":"Nyssen, A.S., Aunac, S., Faymonville, M.E. and Lutte, I. (2004), \u201cReporting systems in healthcare from a case\u2010by\u2010case experience to a general framework: an example in anaesthesia\u201d, European Journal of Anaesthesiology, pp. 757\u201065.","DOI":"10.1097\/00003643-200410000-00001"},{"key":"key2022012220354457700_b16","unstructured":"OLF (2006) OLF Guideline No. 104, OLF Information Security Baseline Requirements for Process Control, Safety and Support ICT Systems, Norwegian Oil Industry Association, Stavanger."},{"key":"key2022012220354457700_b17","doi-asserted-by":"crossref","unstructured":"Phimister, J.R., Oktem, U., Kleindorfer, P.R. and Kunreuther, H. (2003), \u201cNear\u2010miss incident management in the chemical process industry\u201d, Risk Analysis, Vol. 23, pp. 445\u201059.","DOI":"10.1111\/1539-6924.00326"},{"key":"key2022012220354457700_b18","doi-asserted-by":"crossref","unstructured":"Repenning, N.P. and Sterman, J.D. (2002), \u201cCapability traps and self\u2010confirming attribution errors in the dynamics of process improvement\u201d, Administrative Science Quarterly, Vol. 47, pp. 265\u201095.","DOI":"10.2307\/3094806"},{"key":"key2022012220354457700_b19","unstructured":"Rich, E., Sveen, F.O. and Jager, M. (2006), \u201cOvercoming organizational challenges to secure knowledge management\u201d, paper presented at 2nd Secure Knowledge Management Workshop, New York, NY."},{"key":"key2022012220354457700_b20","unstructured":"Schneier, B. (2000), Secrets and Lies, Wiley, New York, NY."},{"key":"key2022012220354457700_b21","unstructured":"Sterman, J.D. (2000), Business Dynamics, Irwin McGraw\u2010Hill, Boston, MA."},{"key":"key2022012220354457700_b22","doi-asserted-by":"crossref","unstructured":"Stoneburner, G. (2006), \u201cToward a unified security\/safety model\u201d, IEEE Computer, Vol. 39 No. 8, pp. 96\u20107.","DOI":"10.1109\/MC.2006.283"},{"key":"key2022012220354457700_b23","doi-asserted-by":"crossref","unstructured":"Wiant, T.L. (2005), \u201cInformation security policy's impact on reporting security incidents\u201d, Computers & Security, Vol. 24, pp. 448\u201059.","DOI":"10.1016\/j.cose.2005.03.008"},{"key":"key2022012220354457700_b24","unstructured":"Wiik, J. (2007), \u201cDynamics of incident response effectiveness \u2013 a SD approach\u201d, unpublished PhD thesis, University of Bergen, Bergen."},{"key":"key2022012220354457700_b25","unstructured":"Wiik, J., Gonzalez, J.J. and Kossakowski, K\u2010P. (2004), \u201cLimits to effectiveness in computer security incident response teams\u201d, paper presented at 23rd International Conference of the System Dynamics Society, Oxford."},{"key":"key2022012220354457700_b26","unstructured":"Wiik, J., Gonzalez, J.J. and Kossakowski, K\u2010P. (2005), \u201cLimits to effectiveness of computer security incident response teams (CSIRTs)\u201d, paper presented at Twenty Third International Conference of the System Dynamics Society, The System Dynamics Society, Boston, MA."},{"key":"key2022012220354457700_b27","unstructured":"Winkler, I. (2005), Spies Among Us, Wiley, New York, NY."},{"key":"key2022012220354457700_b28","doi-asserted-by":"crossref","unstructured":"Zangwill, W.I. and Kantor, P.B. (1998), \u201cTowards a theory of continuous improvement and the learning curve\u201d, Management Science, Vol. 44, pp. 910\u201020.","DOI":"10.1287\/mnsc.44.7.910"}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/09685220710831143","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685220710831143\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685220710831143\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:09:04Z","timestamp":1753402144000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/15\/5\/408-419\/180968"}},"subtitle":[],"editor":[{"given":"Steven","family":"Furnell","sequence":"first","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2007,10,16]]},"references-count":28,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2007,10,16]]}},"alternative-id":["10.1108\/09685220710831143"],"URL":"https:\/\/doi.org\/10.1108\/09685220710831143","relation":{},"ISSN":["0968-5227"],"issn-type":[{"value":"0968-5227","type":"print"}],"subject":[],"published":{"date-parts":[[2007,10,16]]}}}