{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,13]],"date-time":"2026-03-13T13:45:26Z","timestamp":1773409526928,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":21,"publisher":"ACM","license":[{"start":{"date-parts":[[2015,10,12]],"date-time":"2015-10-12T00:00:00Z","timestamp":1444608000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2015,10,12]]},"DOI":"10.1145\/2808128.2808132","type":"proceedings-article","created":{"date-parts":[[2015,10,6]],"date-time":"2015-10-06T15:22:12Z","timestamp":1444144932000},"page":"31-42","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":12,"title":["Mandatory Security Information Sharing with Authorities"],"prefix":"10.1145","author":[{"given":"Stefan","family":"Laube","sequence":"first","affiliation":[{"name":"Department of Information Systems, University of M\u00fcnster, M\u00fcnster, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rainer","family":"B\u00f6hme","sequence":"additional","affiliation":[{"name":"Institute of Computer Science, University of Innsbruck, Innsbruck, Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2015,10,12]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Target puts data breach costs at $148 million, and forecasts profit drop","author":"Abrams R.","year":"2014","unstructured":"R. Abrams . Target puts data breach costs at $148 million, and forecasts profit drop , 2014 . Access: http:\/\/www.nytimes.com\/2014\/08\/06\/business\/target-puts-data-breach-costs-at-148-million.html. Last accessed: 27.07.2015. R. Abrams. Target puts data breach costs at $148 million, and forecasts profit drop, 2014. Access: http:\/\/www.nytimes.com\/2014\/08\/06\/business\/target-puts-data-breach-costs-at-148-million.html. Last accessed: 27.07.2015."},{"key":"e_1_3_2_1_2_1","volume-title":"Security economics and the internal market. Technical report","author":"Anderson R.","year":"2008","unstructured":"R. Anderson , R. B\u00f6hme , R. Clayton , and T. Moore . Security economics and the internal market. Technical report , European Union Agency for Network and Information Security (ENISA) , 2008 . R. Anderson, R. B\u00f6hme, R. Clayton, and T. Moore. Security economics and the internal market. Technical report, European Union Agency for Network and Information Security (ENISA), 2008."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.telpol.2009.09.001"},{"key":"e_1_3_2_1_4_1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"129","DOI":"10.1007\/978-3-642-32946-3_11","volume-title":"Proceedings of Financial Cryptography and Data Security","author":"B\u00f6hme R.","year":"2012","unstructured":"R. B\u00f6hme . Security audits revisited . In A. Keromytis, editor, Proceedings of Financial Cryptography and Data Security , volume 7397 of Lecture Notes in Computer Science , pages 129 -- 147 , Berlin, Heidelberg , 2012 . Springer . R. B\u00f6hme. Security audits revisited. In A. Keromytis, editor, Proceedings of Financial Cryptography and Data Security, volume 7397 of Lecture Notes in Computer Science, pages 129--147, Berlin, Heidelberg, 2012. Springer."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1005817.1005828"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1080\/10864415.2004.11044320"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1050.0041"},{"key":"e_1_3_2_1_8_1","volume-title":"Cyber incident reporting in the EU -- An overview of security articles in EU legislation. Technical report","author":"Dekker D. M.","year":"2012","unstructured":"D. M. Dekker , C. Karsberg , and B. Daskala . Cyber incident reporting in the EU -- An overview of security articles in EU legislation. Technical report , European Union Agency for Network and Information Security (ENISA) , 2012 . D. M. Dekker, C. Karsberg, and B. Daskala. Cyber incident reporting in the EU -- An overview of security articles in EU legislation. Technical report, European Union Agency for Network and Information Security (ENISA), 2012."},{"issue":"31","key":"e_1_3_2_1_9_1","first-page":"1324","article-title":"Gesetz zur Erh\u00f6hung der Sicherheit informationstechnischer Systeme (IT-Sicherheitsgesetz)","year":"2015","unstructured":"Deutscher Bundestag . Gesetz zur Erh\u00f6hung der Sicherheit informationstechnischer Systeme (IT-Sicherheitsgesetz) . Bundesgesetzblatt , I ( 31 ): 1324 -- 1331 , 2015 . Deutscher Bundestag. Gesetz zur Erh\u00f6hung der Sicherheit informationstechnischer Systeme (IT-Sicherheitsgesetz). Bundesgesetzblatt, I(31):1324--1331, 2015.","journal-title":"Bundesgesetzblatt"},{"key":"e_1_3_2_1_10_1","volume-title":"Proposal for a Directive of the European Parliament and of the Council concerning measures to ensure a high common level of network and information security across the Union. COM (2013) 48 final","author":"European Commission","year":"2013","unstructured":"European Commission . Proposal for a Directive of the European Parliament and of the Council concerning measures to ensure a high common level of network and information security across the Union. COM (2013) 48 final , 2013 . European Commission. Proposal for a Directive of the European Parliament and of the Council concerning measures to ensure a high common level of network and information security across the Union. COM (2013) 48 final, 2013."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1050.0053"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/581271.581274"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jaccpubpol.2003.09.001"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jaccpubpol.2007.10.001"},{"key":"e_1_3_2_1_15_1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1007\/978-3-319-12601-2_4","volume-title":"Decision and Game Theory for Security","author":"Khouzani M.","year":"2014","unstructured":"M. Khouzani , V. Pham , and C. Cid . Strategic discovery and sharing of vulnerabilities in competitive environments . In R. Poovendran and W. Saad, editors, Decision and Game Theory for Security , volume 8840 of Lecture Notes in Computer Science , pages 59 -- 78 , Berlin, Heidelberg , 2014 . Springer . M. Khouzani, V. Pham, and C. Cid. Strategic discovery and sharing of vulnerabilities in competitive environments. In R. Poovendran and W. Saad, editors, Decision and Game Theory for Security, volume 8840 of Lecture Notes in Computer Science, pages 59--78, Berlin, Heidelberg, 2014. Springer."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1024119208153"},{"key":"e_1_3_2_1_17_1","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"Laube S.","year":"2015","unstructured":"S. Laube and R. B\u00f6hme . The economics of mandatory security breach reporting to authorities . In Workshop on the Economics of Information Security (WEIS) , Delft , 2015 . S. Laube and R. B\u00f6hme. The economics of mandatory security breach reporting to authorities. In Workshop on the Economics of Information Security (WEIS), Delft, 2015."},{"key":"e_1_3_2_1_18_1","volume-title":"Conference of State Legislatures. State security breach notification laws","author":"National","year":"2014","unstructured":"National Conference of State Legislatures. State security breach notification laws , 2014 . Access : http:\/\/www.ncsl.org\/research\/telecommunications-and-information-technology\/security-breach-notification-laws.aspx. Last accessed: 27.07.2015. National Conference of State Legislatures. State security breach notification laws, 2014. Access: http:\/\/www.ncsl.org\/research\/telecommunications-and-information-technology\/security-breach-notification-laws.aspx. Last accessed: 27.07.2015."},{"key":"e_1_3_2_1_19_1","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"\u00d6g\u00fct H.","year":"2005","unstructured":"H. \u00d6g\u00fct , N. Memon , and S. Raghunathan . Cyber insurance and IT security investment: Impact of interdependent risk . In Workshop on the Economics of Information Security (WEIS) , Harvard , 2005 . H. \u00d6g\u00fct, N. Memon, and S. Raghunathan. Cyber insurance and IT security investment: Impact of interdependent risk. In Workshop on the Economics of Information Security (WEIS), Harvard, 2005."},{"key":"e_1_3_2_1_20_1","volume-title":"Managing Cyber risks in an interconnected world: Key findings from the global state of information security survey","year":"2014","unstructured":"PricewaterhouseCoopers. Managing Cyber risks in an interconnected world: Key findings from the global state of information security survey 2014 . Technical report, PricewaterhouseCoopers , 2014. PricewaterhouseCoopers. Managing Cyber risks in an interconnected world: Key findings from the global state of information security survey 2014. Technical report, PricewaterhouseCoopers, 2014."},{"key":"e_1_3_2_1_21_1","volume-title":"Workshop on Economics of Information Security (WEIS)","author":"Romanosky S.","year":"2010","unstructured":"S. Romanosky , R. Sharp , and A. Acquisti . Data breaches and identity theft: When is mandatory disclosure optimal ? In Workshop on Economics of Information Security (WEIS) , Harvard , 2010 . S. Romanosky, R. Sharp, and A. Acquisti. Data breaches and identity theft: When is mandatory disclosure optimal? In Workshop on Economics of Information Security (WEIS), Harvard, 2010."}],"event":{"name":"CCS'15: The 22nd ACM Conference on Computer and Communications Security","location":"Denver Colorado USA","acronym":"CCS'15","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2nd ACM Workshop on Information Sharing and Collaborative Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2808128.2808132","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2808128.2808132","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T05:07:12Z","timestamp":1750223232000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2808128.2808132"}},"subtitle":["Implications on Investments in Internal Controls"],"short-title":[],"issued":{"date-parts":[[2015,10,12]]},"references-count":21,"alternative-id":["10.1145\/2808128.2808132","10.1145\/2808128"],"URL":"https:\/\/doi.org\/10.1145\/2808128.2808132","relation":{},"subject":[],"published":{"date-parts":[[2015,10,12]]},"assertion":[{"value":"2015-10-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}