中小型企业投资于电子商务基础设施的安全即服务:蒙特卡洛方法

D. Nazareth, Jae Choi, Thomas L. Ngo-Ye
{"title":"中小型企业投资于电子商务基础设施的安全即服务:蒙特卡洛方法","authors":"D. Nazareth, Jae Choi, Thomas L. Ngo-Ye","doi":"10.1108/jsit-04-2023-0071","DOIUrl":null,"url":null,"abstract":"Purpose\nThis paper aims to examine the conditions under which small and medium enterprises (SMEs) invest in security services when they migrate their e-commerce applications to the cloud environment. Using a risk management perspective, the paper assesses the impact of security service pricing, security incident prevalence and virulence to estimate SME security spending at the market level and draw out implications for SMEs and security service providers.\n\nDesign/methodology/approach\nSecurity risks are inherently characterized by uncertainty. This study uses a Monte Carlo approach to understand the role of uncertainty in the decision to adopt security services. A model relating key security constructs is assembled based on key constructs from the domain. By manipulating security service costs and security incident types, the model estimates the market-level adoption of services, security incidents and damages incurred, along with measures of their relative dispersion.\n\nFindings\nThree key findings emerge from this study. First, adoption of services and protection is higher when tiered security services are provided, indicating that SMEs prefer to choose their security services rather than accept uniformly priced products. Second, SMEs are considered price-sensitive, resulting in a maximum level of spending in the market. Third, results indicate that security incidents and damages can be much higher than the mean in some cases, and this should serve as a cautionary note to SMEs.\n\nOriginality/value\nSecurity spending has been modeled at the firm level. Adopting a market-level perspective represents a novel contribution. Additionally, the Monte Carlo approach provides managers with tangible measures of uncertainty, affording additional information and insight when making security service adoption decisions.\n","PeriodicalId":38615,"journal":{"name":"Journal of Systems and Information Technology","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2024-04-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Investing in security-as-a-service for e-commerce infrastructure by small and medium enterprises: a Monte Carlo approach\",\"authors\":\"D. Nazareth, Jae Choi, Thomas L. Ngo-Ye\",\"doi\":\"10.1108/jsit-04-2023-0071\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Purpose\\nThis paper aims to examine the conditions under which small and medium enterprises (SMEs) invest in security services when they migrate their e-commerce applications to the cloud environment. Using a risk management perspective, the paper assesses the impact of security service pricing, security incident prevalence and virulence to estimate SME security spending at the market level and draw out implications for SMEs and security service providers.\\n\\nDesign/methodology/approach\\nSecurity risks are inherently characterized by uncertainty. This study uses a Monte Carlo approach to understand the role of uncertainty in the decision to adopt security services. A model relating key security constructs is assembled based on key constructs from the domain. By manipulating security service costs and security incident types, the model estimates the market-level adoption of services, security incidents and damages incurred, along with measures of their relative dispersion.\\n\\nFindings\\nThree key findings emerge from this study. First, adoption of services and protection is higher when tiered security services are provided, indicating that SMEs prefer to choose their security services rather than accept uniformly priced products. Second, SMEs are considered price-sensitive, resulting in a maximum level of spending in the market. Third, results indicate that security incidents and damages can be much higher than the mean in some cases, and this should serve as a cautionary note to SMEs.\\n\\nOriginality/value\\nSecurity spending has been modeled at the firm level. Adopting a market-level perspective represents a novel contribution. Additionally, the Monte Carlo approach provides managers with tangible measures of uncertainty, affording additional information and insight when making security service adoption decisions.\\n\",\"PeriodicalId\":38615,\"journal\":{\"name\":\"Journal of Systems and Information Technology\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2024-04-09\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Systems and Information Technology\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1108/jsit-04-2023-0071\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"Computer Science\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Systems and Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1108/jsit-04-2023-0071","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"Computer Science","Score":null,"Total":0}
引用次数: 0

摘要

本文旨在研究中小型企业(SMEs)在将其电子商务应用迁移到云环境时投资安全服务的条件。本文采用风险管理的视角,评估了安全服务定价、安全事件发生率和病毒传播率的影响,以估算中小企业在市场层面的安全支出,并得出对中小企业和安全服务提供商的影响。本研究采用蒙特卡罗方法来了解不确定性在采用安全服务决策中的作用。本研究以该领域的关键结构为基础,建立了一个与关键安全结构相关的模型。通过操纵安全服务成本和安全事件类型,该模型估算了市场层面的服务采用率、安全事件和造成的损失,以及它们的相对分散程度。首先,当提供分级安全服务时,服务和保护的采用率更高,这表明中小企业更愿意选择安全服务,而不是接受统一定价的产品。其次,中小型企业被认为对价格敏感,因此在市场上的消费水平最高。第三,研究结果表明,在某些情况下,安全事件和损失可能远远高于平均值,这一点应引起中小型企业的警惕。采用市场层面的视角是一项新贡献。此外,蒙特卡洛方法还为管理者提供了不确定性的具体衡量标准,为他们在做出采用安全服务的决策时提供了更多的信息和洞察力。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Investing in security-as-a-service for e-commerce infrastructure by small and medium enterprises: a Monte Carlo approach
Purpose This paper aims to examine the conditions under which small and medium enterprises (SMEs) invest in security services when they migrate their e-commerce applications to the cloud environment. Using a risk management perspective, the paper assesses the impact of security service pricing, security incident prevalence and virulence to estimate SME security spending at the market level and draw out implications for SMEs and security service providers. Design/methodology/approach Security risks are inherently characterized by uncertainty. This study uses a Monte Carlo approach to understand the role of uncertainty in the decision to adopt security services. A model relating key security constructs is assembled based on key constructs from the domain. By manipulating security service costs and security incident types, the model estimates the market-level adoption of services, security incidents and damages incurred, along with measures of their relative dispersion. Findings Three key findings emerge from this study. First, adoption of services and protection is higher when tiered security services are provided, indicating that SMEs prefer to choose their security services rather than accept uniformly priced products. Second, SMEs are considered price-sensitive, resulting in a maximum level of spending in the market. Third, results indicate that security incidents and damages can be much higher than the mean in some cases, and this should serve as a cautionary note to SMEs. Originality/value Security spending has been modeled at the firm level. Adopting a market-level perspective represents a novel contribution. Additionally, the Monte Carlo approach provides managers with tangible measures of uncertainty, affording additional information and insight when making security service adoption decisions.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Journal of Systems and Information Technology
Journal of Systems and Information Technology Computer Science-Computer Science (all)
CiteScore
4.40
自引率
0.00%
发文量
18
期刊介绍: The Journal provides an avenue for scholarly work that researches systems thinking applications, information systems, electronic business, data analytics, information sciences, information management, business intelligence, and complex adaptive systems in the application domains of the business environment, health, the built environment, cultural settings, and the natural environment. Papers examine the wider implications of the systems or technology being researched. This means papers consider aspects such as social and organisational relevance, business value, cognitive implications, social implications, impact on individuals or community perspectives, and the development of solutions, rather than focusing solely on the technology. The Journal of Systems and Information Technology is open to a wide range of research methodologies and paper styles including case studies, surveys, experiments, review papers, design science, design thinking and both theoretical and methodological papers. The focus of the journal will be to publish work that fits into the following broad areas of research: Behavioural Information Systems and Human-Computer Interaction, Data Analytics, Data, Information and Security, E-Business, Intelligent Systems and Applications, Logistics and Supply Chain Management/Optimisation, Social Media Analysis, Technology Enhanced Learning.
期刊最新文献
An empirical investigation of student online learning continuance intention in the post-COVID-19 pandemic era Examining the role of expectations in outsourcing success utilizing the hierarchy of effects model The use of enterprise social networks for knowledge sharing: the impact of intra-organizational trust and governance Behavioral responses resulting from e-health services and the role of user satisfaction: the case of the online diabetes test County-level prioritization for managing the Covid-19 pandemic: a systematic unsupervised learning approach
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1