[{"status":"public","has_accepted_license":"1","page":"3 - 31","_id":"16249","publisher":"Information Institute Publishing, Washington DC, USA","ddc":["000"],"user_id":"61579","volume":16,"file_date_updated":"2020-03-05T10:35:49Z","citation":{"short":"E. Szubartowicz, G. Schryen, Journal of Information System Security 16 (2020) 3–31.","chicago":"Szubartowicz, Eva, and Guido Schryen. “Timing in Information Security: An Event Study on the Impact of Information Security Investment Announcements.” <i>Journal of Information System Security</i> 16, no. 1 (2020): 3–31.","ieee":"E. Szubartowicz and G. Schryen, “Timing in Information Security: An Event Study on the Impact of Information Security Investment Announcements,” <i>Journal of Information System Security</i>, vol. 16, no. 1, pp. 3–31, 2020.","apa":"Szubartowicz, E., &#38; Schryen, G. (2020). Timing in Information Security: An Event Study on the Impact of Information Security Investment Announcements. <i>Journal of Information System Security</i>, <i>16</i>(1), 3–31.","bibtex":"@article{Szubartowicz_Schryen_2020, title={Timing in Information Security: An Event Study on the Impact of Information Security Investment Announcements}, volume={16}, number={1}, journal={Journal of Information System Security}, publisher={Information Institute Publishing, Washington DC, USA}, author={Szubartowicz, Eva and Schryen, Guido}, year={2020}, pages={3–31} }","ama":"Szubartowicz E, Schryen G. Timing in Information Security: An Event Study on the Impact of Information Security Investment Announcements. <i>Journal of Information System Security</i>. 2020;16(1):3-31.","mla":"Szubartowicz, Eva, and Guido Schryen. “Timing in Information Security: An Event Study on the Impact of Information Security Investment Announcements.” <i>Journal of Information System Security</i>, vol. 16, no. 1, Information Institute Publishing, Washington DC, USA, 2020, pp. 3–31."},"oa":"1","title":"Timing in Information Security: An Event Study on the Impact of Information Security Investment Announcements","year":"2020","author":[{"last_name":"Szubartowicz","first_name":"Eva","full_name":"Szubartowicz, Eva"},{"first_name":"Guido","last_name":"Schryen","full_name":"Schryen, Guido","id":"72850"}],"date_updated":"2022-01-06T06:52:47Z","intvolume":"        16","language":[{"iso":"eng"}],"issue":"1","publication":"Journal of Information System Security","abstract":[{"lang":"eng","text":"Timing plays a crucial role in the context of information security investments. We regard timing in two dimensions, namely the time of announcement in relation to the time of investment and the time of announcement in relation to the time of a fundamental security incident. The financial value of information security investments is assessed by examining the relationship between the investment announcements and their stock market reaction focusing on the two time dimensions. Using an event study methodology, we found that both dimensions influence the stock market return of the investing organization. Our results indicate that (1) after fundamental security incidents in a given industry, the stock price will react more positively to a firm’s announcement of actual information security investments than to announcements of the intention to invest; (2) the stock price will react more positively to a firm’s announcements of the intention to invest after the fundamental security incident compared to before; and (3) the stock price will react more positively to a firm’s announcements of actual information security investments after the fundamental security incident compared to before. Overall, the lowest abnormal return can be expected when the intention to invest is announced before a fundamental information security incident and the highest return when actual investing after a fundamental information security incident in the respective industry."}],"file":[{"date_created":"2020-03-05T10:26:11Z","creator":"hsiemes","file_id":"16250","content_type":"application/pdf","relation":"main_file","date_updated":"2020-03-05T10:35:49Z","file_name":"Timing in Information Security - JISSEC format PREPUBLICATION.pdf","file_size":478056,"access_level":"open_access"}],"date_created":"2020-03-05T10:29:00Z","keyword":["Event Study","Information Security","Investment Announcements","Stock Price Reaction","Value of Information Security Investments"],"type":"journal_article","department":[{"_id":"277"}]},{"oa":"1","citation":{"mla":"Weishäupl, Eva, et al. “Information Security Investments: An Exploratory Multiple Case Study on Decision-Making, Evaluation and Learning.” <i>Computers &#38; Security</i>, vol. 77, Elsevier, 2018, pp. 807–23.","ama":"Weishäupl E, Yasasin E, Schryen G. Information Security Investments: An Exploratory Multiple Case Study on Decision-Making, Evaluation and Learning. <i>Computers &#38; Security</i>. 2018;77:807-823.","bibtex":"@article{Weishäupl_Yasasin_Schryen_2018, title={Information Security Investments: An Exploratory Multiple Case Study on Decision-Making, Evaluation and Learning}, volume={77}, journal={Computers &#38; Security}, publisher={Elsevier}, author={Weishäupl, Eva and Yasasin, Emrah and Schryen, Guido}, year={2018}, pages={807–823} }","apa":"Weishäupl, E., Yasasin, E., &#38; Schryen, G. (2018). Information Security Investments: An Exploratory Multiple Case Study on Decision-Making, Evaluation and Learning. <i>Computers &#38; Security</i>, <i>77</i>, 807–823.","ieee":"E. Weishäupl, E. Yasasin, and G. Schryen, “Information Security Investments: An Exploratory Multiple Case Study on Decision-Making, Evaluation and Learning,” <i>Computers &#38; Security</i>, vol. 77, pp. 807–823, 2018.","short":"E. Weishäupl, E. Yasasin, G. Schryen, Computers &#38; Security 77 (2018) 807–823.","chicago":"Weishäupl, Eva, Emrah Yasasin, and Guido Schryen. “Information Security Investments: An Exploratory Multiple Case Study on Decision-Making, Evaluation and Learning.” <i>Computers &#38; Security</i> 77 (2018): 807–23."},"file_date_updated":"2018-12-13T15:06:10Z","volume":77,"ddc":["000"],"user_id":"61579","_id":"5586","publisher":"Elsevier","page":"807 - 823","has_accepted_license":"1","status":"public","department":[{"_id":"277"}],"keyword":["Information Security Investments","Multiple Case Study","Organizations","Single Loop Learning","Double Loop Learning"],"type":"journal_article","date_created":"2018-11-14T11:24:37Z","file":[{"date_updated":"2018-12-13T15:06:10Z","relation":"main_file","file_size":809490,"access_level":"open_access","file_name":"JOURNAL VERSION.pdf","content_type":"application/pdf","file_id":"6022","creator":"hsiemes","date_created":"2018-12-07T11:26:53Z"}],"abstract":[{"lang":"eng","text":"The need to protect resources against attackers is reflected by huge information security investments of firms worldwide. In the presence of budget constraints and a diverse set of assets to protect, organizations have to decide in which IT security measures to invest, how to evaluate those investment decisions, and how to learn from past decisions to optimize future security investment actions. While the academic literature has provided valuable insights into these issues, there is a lack of empirical contributions. To address this lack, we conduct a theory-based exploratory multiple case study. Our case study reveals that (1) firms? investments in information security are largely driven by external environmental and industry-related factors, (2) firms do not implement standardized decision processes, (3) the security process is perceived to impact the business process in a disturbing way, (4) both the implementation of evaluation processes and the application of metrics are hardly existent and (5) learning activities mainly occur at an ad-hoc basis."}],"extern":"1","publication":"Computers & Security","language":[{"iso":"eng"}],"intvolume":"        77","date_updated":"2022-01-06T07:02:03Z","author":[{"full_name":"Weishäupl, Eva","first_name":"Eva","last_name":"Weishäupl"},{"last_name":"Yasasin","first_name":"Emrah","full_name":"Yasasin, Emrah"},{"id":"72850","last_name":"Schryen","first_name":"Guido","full_name":"Schryen, Guido"}],"year":"2018","title":"Information Security Investments: An Exploratory Multiple Case Study on Decision-Making, Evaluation and Learning"},{"file":[{"date_created":"2018-12-07T11:45:31Z","creator":"hsiemes","file_id":"6038","content_type":"application/pdf","file_name":"ICIS PROCEEDINGS PAPER - Security Investments.pdf","access_level":"open_access","file_size":958019,"relation":"main_file","date_updated":"2018-12-13T15:09:32Z"}],"date_created":"2018-11-14T11:25:38Z","keyword":["Information Security","Investment","Literature review","Resource-based View","Organi-zational Learning Theory","Multi-theoretical Perspective"],"type":"conference","department":[{"_id":"277"}],"publication":"International Conference on Information Systems","extern":"1","abstract":[{"lang":"eng","text":"The protection of information technology (IT) has become and is predicted to remain a key economic challenge for organizations. While research on IT security investment is fast growing, it lacks a theoretical basis for structuring research, explaining economic-technological phenomena and guide future research. We address this shortcoming by suggesting a new theoretical model emerging from a multi-theoretical perspective adopt-ing the Resource-Based View and the Organizational Learning Theory. The joint appli-cation of these theories allows to conceptualize in one theoretical model the organiza-tional learning effects that occur when the protection of organizational resources through IT security countermeasures develops over time. We use this model of IT security invest-ments to synthesize findings of a large body of literature and to derive research gaps. We also discuss managerial implications of (closing) these gaps by providing practical ex-amples."}],"language":[{"iso":"eng"}],"year":"2015","title":"A Multi-Theoretical Literature Review on Information Security Investments using the Resource-Based View and the Organizational Learning Theory","author":[{"first_name":"Eva","last_name":"Weishäupl","full_name":"Weishäupl, Eva"},{"full_name":"Yasasin, Emrah","last_name":"Yasasin","first_name":"Emrah"},{"full_name":"Schryen, Guido","first_name":"Guido","last_name":"Schryen","id":"72850"}],"date_updated":"2022-01-06T07:02:03Z","oa":"1","file_date_updated":"2018-12-13T15:09:32Z","citation":{"ama":"Weishäupl E, Yasasin E, Schryen G. A Multi-Theoretical Literature Review on Information Security Investments using the Resource-Based View and the Organizational Learning Theory. In: <i>International Conference on Information Systems</i>. ; 2015.","bibtex":"@inproceedings{Weishäupl_Yasasin_Schryen_2015, title={A Multi-Theoretical Literature Review on Information Security Investments using the Resource-Based View and the Organizational Learning Theory}, booktitle={International Conference on Information Systems}, author={Weishäupl, Eva and Yasasin, Emrah and Schryen, Guido}, year={2015} }","mla":"Weishäupl, Eva, et al. “A Multi-Theoretical Literature Review on Information Security Investments Using the Resource-Based View and the Organizational Learning Theory.” <i>International Conference on Information Systems</i>, 2015.","chicago":"Weishäupl, Eva, Emrah Yasasin, and Guido Schryen. “A Multi-Theoretical Literature Review on Information Security Investments Using the Resource-Based View and the Organizational Learning Theory.” In <i>International Conference on Information Systems</i>, 2015.","short":"E. Weishäupl, E. Yasasin, G. Schryen, in: International Conference on Information Systems, 2015.","apa":"Weishäupl, E., Yasasin, E., &#38; Schryen, G. (2015). A Multi-Theoretical Literature Review on Information Security Investments using the Resource-Based View and the Organizational Learning Theory. In <i>International Conference on Information Systems</i>.","ieee":"E. Weishäupl, E. Yasasin, and G. Schryen, “A Multi-Theoretical Literature Review on Information Security Investments using the Resource-Based View and the Organizational Learning Theory,” in <i>International Conference on Information Systems</i>, 2015."},"_id":"5588","user_id":"61579","ddc":["000"],"status":"public","has_accepted_license":"1"},{"department":[{"_id":"277"}],"type":"conference","keyword":["Identity and Access Management","Economic Decision Making","Information Systems","Information Security Investment","Decision Theory"],"date_created":"2018-11-14T11:27:20Z","file":[{"date_updated":"2018-12-13T15:09:54Z","relation":"main_file","access_level":"open_access","file_size":166015,"file_name":"Towards an Economic Approach to IAMS.PDF","content_type":"application/pdf","file_id":"6040","creator":"hsiemes","date_created":"2018-12-07T11:46:28Z"}],"abstract":[{"text":"Nowadays, providing employees with failure-free access to various systems, applications and services is a crucial factor for organizations? success as disturbances potentially inhibit smooth workflows and thereby harm productivity. However, it is a challenging task to assign access rights to employees? accounts within a satisfying time frame. In addition, the management of multiple accounts and identities can be very onerous and time consuming for the responsible administrator and therefore expensive for the organization. In order to meet these challenges, firms decide to invest in introducing an Identity and Access Management System (IAMS) that supports the organization by using policies to assign permissions to accounts, groups, and roles. In practice, since various versions of IAMSs exist, it is a challenging task to decide upon introduction of an IAMS. The following study proposes a first attempt of a decision support model for practitioners which considers four alternatives: Introduction of an IAMS with Role-based Access Control RBAC) or without and no introduction of IAMS again with or without RBAC. To underpin the practical applicability of the proposed model, we parametrize and operationalize it based on a real world use case using input from an expert interview.","lang":"eng"}],"extern":"1","publication":"2nd International Workshop on Security in highly connected IT Systems (SHCIS?15)","language":[{"iso":"eng"}],"date_updated":"2022-01-06T07:02:04Z","author":[{"last_name":"Weishäupl","first_name":"Eva","full_name":"Weishäupl, Eva"},{"last_name":"Kunz","first_name":"Michael","full_name":"Kunz, Michael"},{"last_name":"Yasasin","first_name":"Emrah","full_name":"Yasasin, Emrah"},{"full_name":"Wagner, Gerit","last_name":"Wagner","first_name":"Gerit"},{"full_name":"Prester, Julian","last_name":"Prester","first_name":"Julian"},{"id":"72850","full_name":"Schryen, Guido","last_name":"Schryen","first_name":"Guido"},{"full_name":"Pernul, Günther","last_name":"Pernul","first_name":"Günther"}],"year":"2015","title":"Towards an Economic Approach to Identity and Access Management Systems Using Decision Theory","oa":"1","citation":{"bibtex":"@inproceedings{Weishäupl_Kunz_Yasasin_Wagner_Prester_Schryen_Pernul_2015, title={Towards an Economic Approach to Identity and Access Management Systems Using Decision Theory}, booktitle={2nd International Workshop on Security in highly connected IT Systems (SHCIS?15)}, author={Weishäupl, Eva and Kunz, Michael and Yasasin, Emrah and Wagner, Gerit and Prester, Julian and Schryen, Guido and Pernul, Günther}, year={2015} }","ama":"Weishäupl E, Kunz M, Yasasin E, et al. Towards an Economic Approach to Identity and Access Management Systems Using Decision Theory. In: <i>2nd International Workshop on Security in Highly Connected IT Systems (SHCIS?15)</i>. ; 2015.","mla":"Weishäupl, Eva, et al. “Towards an Economic Approach to Identity and Access Management Systems Using Decision Theory.” <i>2nd International Workshop on Security in Highly Connected IT Systems (SHCIS?15)</i>, 2015.","short":"E. Weishäupl, M. Kunz, E. Yasasin, G. Wagner, J. Prester, G. Schryen, G. Pernul, in: 2nd International Workshop on Security in Highly Connected IT Systems (SHCIS?15), 2015.","chicago":"Weishäupl, Eva, Michael Kunz, Emrah Yasasin, Gerit Wagner, Julian Prester, Guido Schryen, and Günther Pernul. “Towards an Economic Approach to Identity and Access Management Systems Using Decision Theory.” In <i>2nd International Workshop on Security in Highly Connected IT Systems (SHCIS?15)</i>, 2015.","ieee":"E. Weishäupl <i>et al.</i>, “Towards an Economic Approach to Identity and Access Management Systems Using Decision Theory,” in <i>2nd International Workshop on Security in highly connected IT Systems (SHCIS?15)</i>, 2015.","apa":"Weishäupl, E., Kunz, M., Yasasin, E., Wagner, G., Prester, J., Schryen, G., &#38; Pernul, G. (2015). Towards an Economic Approach to Identity and Access Management Systems Using Decision Theory. In <i>2nd International Workshop on Security in highly connected IT Systems (SHCIS?15)</i>."},"file_date_updated":"2018-12-13T15:09:54Z","ddc":["000"],"user_id":"61579","_id":"5590","has_accepted_license":"1","status":"public"}]
