0% found this document useful (0 votes)
8 views6 pages

Economics of IT Security in Colleges

Uploaded by

floydmullings
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views6 pages

Economics of IT Security in Colleges

Uploaded by

floydmullings
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Information Technology Security 1

Running Head: Information Technology Security Economics Consideration for a Community

College.

Module 4 – Session Long Project

Course #: ITM517

Information Security Overview for Managers and Policy Makers


Information Technology Security 2

Introduction

Information security requires not only technology, but a clear understanding of risks,

decision-making behaviors and metrics for evaluating business and policy options (WEIS, 2008).

How much should be spent on security? What incentives really drive privacy decisions? What

are the trade-offs that individuals, firms, and governments face when allocating resources to

protect data assets? It is clear that the discipline of economics and information security are

interconnected. Therefore, when making information security decisions, economics mechanisms

and concepts should not be ignored. This paper begins by outlining a security issue that exist at

a community college followed by a discussion on three economics security considerations can be

taken into consideration to address the issue.

An Overview of the Information Security Issue: Success Training College is a small

community college located in the Bahamas. The college has three different campuses located on

separate islands in the country. The college has approximately 1000 students. In terms of

information technology the institution has two computer labs, one is used as a classroom for the

computer courses and the other lab is made available to the students during the days. There is

also a wireless internet service made available to the students and faculties which can be

accessed while on campus. The main software that is used by the institution is Campus

Anywhere. Campus Anywhere is a software that allows campus PCs and applications to be

securely available to students, staff, and faculty from ‘anywhere’, at anytime. Campus Anywhere

provides 24/7 computer lab access to students from anywhere; it allows faculty and staff to

access it on their own desktop PCs from anywhere. As it relates to technical staffing, the

institution does not have a structured IT department of such. The main IT person is the

institution’s systems administrator who ensures the smooth running of the network and oversees
Information Technology Security 3

other systems tasks such as information security. There is also one lab technician who monitors

the activities in the computer labs. All other IT duties are carried out by outsiders.

As it relates to information security, the college believes that its information system is

secure. But is it really secure? Is it really getting its money’s worth? Most of the information

security decisions were made with little or no consideration for information security economics.

In this paper the author will discuss some information security concerns that may exist in the

institution’s system as a result of overlooking some vital information security considerations.

Attackers are driven by economics: Another important consideration is that attackers

are driven by economic reasons. Hacking as a hobby is now a thing of the past (Schneier, 2007).

Attacks carried out from both inside and outside have some economic motives. This is because

of the economic value of the information itself. This simply means that attackers will have little

or no tolerance when attempting to launch an attack. What does this mean for STC? It means that

every effort should be made to safeguard its information, because the attackers are aware of its

value and will stop at nothing to obtain or corrupt it. Precaution should also be made for the

malicious insiders who are often overlooked since 80% of all attacks are normally form inside.

Therefore, STC should install some employee monitoring mechanism and apply rigid employee

profiling techniques.

Network Externalities: According to Bruce Schneier, an insecure operating system is

the international standard, in part because its economic effects are largely borne not by the

company that builds the operating system, but by the customers that buy it (Anderson and

Schneier, 2005). This is due to the economic concept of network externalities which means the

value of a product increases when more people has it. A popular example is the telephone--the

more people who own telephones, the more valuable the telephone is to each owner. What does
Information Technology Security 4

this mean for STC? Network externalities can also have a negative effect. This is evident in the

statement made by Schnier, “an insecure operating system is the international standard…” The

Windows operating system used by STC surely adds value to the institution due to network

externalities; however, when it comes to security, it may not be the best choice. Therefore the

institution needs to take the negative effects of its operating system as well as other software

network externalities into consideration. A typical example is using the operating systems default

security features as a security measure. This is not very smart because attackers are more familiar

with the settings of a common software.

Security is a Trade-off: Security is a trade-off; whether it's trading some additional

home security against the inconvenience of having to carry a key around in your pocket and stick

it into a door every time you want to get into your house; or trading additional security from a

particular kind of airplane terrorism, against the time and expense of searching every passenger,

all security is a trade-off. (Scheiner, 2008). In other words, security costs; convenience, time and

money. Since information is such a valuable asset, information security failures are economic

failures. These failures occur when companies get their trade-offs wrong. Security often comes

with a high price tag, but that high price does not necessarily guarantee good security. The

institution therefore needs to carryout a security risk assessment to decide on how much should

be spent on security. After management is convinced that security is a trade-off and decides to

pay to implement an effective security mechanism, employees and students should also be

educated about security trade-offs to ensure the full corporation of all system users. Tightening

security by making systems more inaccessible can hinder employees and students and make

them less productive. It can also result in lower security as workers or students struggle to find
Information Technology Security 5

ways around the security conditions to enable them to do their work. This therefore means that

everyone in the institution must understand and appreciate information security as a trade-off.

Conclusion

Information security is surrounded by various economics issues. When making

information security decisions economics considerations should not be ignored. Information has

an economic value and attackers are driven by economics and that is why information security

exists in the first place. Network externalities is another issue that should be considered since the

more common a technology becomes the more knowledge the attackers have about it. Finally,

everyone in an organization must understand and appreciate the fact that information security is a

trade-off.
Information Technology Security 6

References

Schneier, B. (2007). The economics of information security. Public lecture at the London School

of Economics. Retrieved February 27, 2010 from

[Link]

WEIS. (2008). Workshop on the economics of information security. Retrieved March 1, 2010

from [Link]

You might also like