检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:吴勇 王林萍 冯耕中[2] WU Yong;WANG Linping;FENG Gengzhong(Glorious Sun School of Business&Management,Donghua University,Shanghai 200051,China;School of Management,Xi'an Jiaotong University,Xi'an 710049,China)
机构地区:[1]东华大学旭日工商管理学院,上海200051 [2]西安交通大学管理学院,西安710049
出 处:《系统工程理论与实践》2022年第11期2916-2926,共11页Systems Engineering-Theory & Practice
基 金:国家自然科学基金(71801035,71832001);国家社科基金重大项目(20&ZD053);中央高校基本科研业务费专项资金(2232018H-07)。
摘 要:研究了供应链中的企业在信息存在互补时,如何与管理安全服务提供商(MSSP)进行信息安全合作管理以解决安全外包中的双边道德风险问题.研究结果表明,供应链企业之间的信息互补度会一定程度上减小企业的预期损失,从而抑制企业与MSSP的投资动机以及MSSP对企业的赔偿额,但增大了企业的被攻击概率.证明了信息安全外包产业中常用的双边赔偿契约存在双边道德风险问题,并且受到供应链企业间互补度的影响,进而提出责任契约来解决该问题.与双边赔偿契约不同,责任契约主要根据企业不同的安全状态来进行赔偿,当两个互补企业都被攻击时,MSSP对双方进行赔偿;当只有一个企业被攻击时,MSSP对被攻击的企业进行惩罚而对未被攻击的企业进行奖励,研究表明该机制可以有效解决供应链互补企业在双边赔偿契约中的双边道德风险问题,且在实施成本小于一定阈值时,MSSP倾向于选择责任契约.研究结果可以为供应链互补企业的信息安全外包管理提供启示.In this paper,we study how firms in the supply chain can cooperate with managed security service providers(MSSP),to solve the double moral hazard(DMH)problem in security outsourcing when the firms'information assets are complementary.The results show that the complementation degree between the firms will reduce their expected loss to some extent,thus not only suppressing the investment incentive of both the firms and the MSSP but also reducing the compensation amount of the MSSP to the firms,whereas increasing the probability of firms being breached.Furthermore,our study shows that both firms and the MSSP would suffer from the DMH problem in a bilateral refund contract,which is commonly used in the information security outsourcing industry,and the DMH problem becomes complicated due to the information complementation of firms.Therefore,we propose the liability contract to solve the DMH problem.Unlike the bilateral refund contract,the implementation of the liability contract is according to the security states of firms.Specifically,when both complementary firms are breached,the MSSP compensates for the two firms,while the MSSP penalizes the breached firm and rewards the un-breached firm if only one firm is breached.Our results show that the liability contract can solve the DMH problem effectively,and the MSSP would like the liability contract when the implementation cost is less than a threshold.These findings give some insights that can guide complementary firms in the supply chain to make an information security outsourcing strategy.
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.7