信息安全外包激励契约设计  被引量:8

Design of incentive contracts for information security outsourcing

在线阅读下载全文

作  者:顾建强[1] 梅姝娥[1] 仲伟俊[1] 

机构地区:[1]东南大学经济管理学院,南京211189

出  处:《系统工程理论与实践》2016年第2期392-399,共8页Systems Engineering-Theory & Practice

基  金:国家自然科学基金(71071033)~~

摘  要:研究了信息安全外包背景下委托公司如何通过激励措施来协调管理安全服务提供商(MSSP)的努力水平从而有效地控制信息安全风险的问题.基于前人的研究和委托代理理论,提出了三种契约模型,即一般惩罚契约、部分外包契约和奖励-惩罚契约.然后对不同外包模式的均衡结果分别讨论并进行全面比较.研究结果表明,部分外包契约优于一般惩罚契约,但只有奖励-惩罚契约能够诱导MSsP最优努力的同时也使委托公司获得最大的回报.结论对信息安全外包的契约设计和风险控制有一定的管理启示.This paper analyzes how an outsourcing firm develops effective incentive measures to coordinate efforts of managed security service provider(MSSP) in the information security outsourcing project in order to control the risk associated with information security.Based on previous researches and the principal-agency theory,three models of contractual arrangements are introduced,which include general penalty contract,partial outsourcing contract and reward-penalty contract.Then,the equilibrium results of different outsourcing contracts are discussed respectively and compared comprehensively.The results indicate that,partial outsourcing contract is superior to penalty contract.But only the reward-penalty contract is able to induce first-best efforts from MSSP,by which the outsourcing firm can enjoy the maximum payoff as well.The conclusion provides some managerial implications for the contract design and risk control in the information security outsourcing.

关 键 词:信息安全 管理安全服务 外包 契约设计 

分 类 号:F270[经济管理—企业管理]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象