Information Technology Security 1
Running Head: Information Technology Security Economics Consideration for a Community
College.
Module 4 – Session Long Project
Course #: ITM517
Information Security Overview for Managers and Policy Makers
Information Technology Security 2
Introduction
Information security requires not only technology, but a clear understanding of risks,
decision-making behaviors and metrics for evaluating business and policy options (WEIS, 2008).
How much should be spent on security? What incentives really drive privacy decisions? What
are the trade-offs that individuals, firms, and governments face when allocating resources to
protect data assets? It is clear that the discipline of economics and information security are
interconnected. Therefore, when making information security decisions, economics mechanisms
and concepts should not be ignored. This paper begins by outlining a security issue that exist at
a community college followed by a discussion on three economics security considerations can be
taken into consideration to address the issue.
An Overview of the Information Security Issue: Success Training College is a small
community college located in the Bahamas. The college has three different campuses located on
separate islands in the country. The college has approximately 1000 students. In terms of
information technology the institution has two computer labs, one is used as a classroom for the
computer courses and the other lab is made available to the students during the days. There is
also a wireless internet service made available to the students and faculties which can be
accessed while on campus. The main software that is used by the institution is Campus
Anywhere. Campus Anywhere is a software that allows campus PCs and applications to be
securely available to students, staff, and faculty from ‘anywhere’, at anytime. Campus Anywhere
provides 24/7 computer lab access to students from anywhere; it allows faculty and staff to
access it on their own desktop PCs from anywhere. As it relates to technical staffing, the
institution does not have a structured IT department of such. The main IT person is the
institution’s systems administrator who ensures the smooth running of the network and oversees
Information Technology Security 3
other systems tasks such as information security. There is also one lab technician who monitors
the activities in the computer labs. All other IT duties are carried out by outsiders.
As it relates to information security, the college believes that its information system is
secure. But is it really secure? Is it really getting its money’s worth? Most of the information
security decisions were made with little or no consideration for information security economics.
In this paper the author will discuss some information security concerns that may exist in the
institution’s system as a result of overlooking some vital information security considerations.
Attackers are driven by economics: Another important consideration is that attackers
are driven by economic reasons. Hacking as a hobby is now a thing of the past (Schneier, 2007).
Attacks carried out from both inside and outside have some economic motives. This is because
of the economic value of the information itself. This simply means that attackers will have little
or no tolerance when attempting to launch an attack. What does this mean for STC? It means that
every effort should be made to safeguard its information, because the attackers are aware of its
value and will stop at nothing to obtain or corrupt it. Precaution should also be made for the
malicious insiders who are often overlooked since 80% of all attacks are normally form inside.
Therefore, STC should install some employee monitoring mechanism and apply rigid employee
profiling techniques.
Network Externalities: According to Bruce Schneier, an insecure operating system is
the international standard, in part because its economic effects are largely borne not by the
company that builds the operating system, but by the customers that buy it (Anderson and
Schneier, 2005). This is due to the economic concept of network externalities which means the
value of a product increases when more people has it. A popular example is the telephone--the
more people who own telephones, the more valuable the telephone is to each owner. What does
Information Technology Security 4
this mean for STC? Network externalities can also have a negative effect. This is evident in the
statement made by Schnier, “an insecure operating system is the international standard…” The
Windows operating system used by STC surely adds value to the institution due to network
externalities; however, when it comes to security, it may not be the best choice. Therefore the
institution needs to take the negative effects of its operating system as well as other software
network externalities into consideration. A typical example is using the operating systems default
security features as a security measure. This is not very smart because attackers are more familiar
with the settings of a common software.
Security is a Trade-off: Security is a trade-off; whether it's trading some additional
home security against the inconvenience of having to carry a key around in your pocket and stick
it into a door every time you want to get into your house; or trading additional security from a
particular kind of airplane terrorism, against the time and expense of searching every passenger,
all security is a trade-off. (Scheiner, 2008). In other words, security costs; convenience, time and
money. Since information is such a valuable asset, information security failures are economic
failures. These failures occur when companies get their trade-offs wrong. Security often comes
with a high price tag, but that high price does not necessarily guarantee good security. The
institution therefore needs to carryout a security risk assessment to decide on how much should
be spent on security. After management is convinced that security is a trade-off and decides to
pay to implement an effective security mechanism, employees and students should also be
educated about security trade-offs to ensure the full corporation of all system users. Tightening
security by making systems more inaccessible can hinder employees and students and make
them less productive. It can also result in lower security as workers or students struggle to find
Information Technology Security 5
ways around the security conditions to enable them to do their work. This therefore means that
everyone in the institution must understand and appreciate information security as a trade-off.
Conclusion
Information security is surrounded by various economics issues. When making
information security decisions economics considerations should not be ignored. Information has
an economic value and attackers are driven by economics and that is why information security
exists in the first place. Network externalities is another issue that should be considered since the
more common a technology becomes the more knowledge the attackers have about it. Finally,
everyone in an organization must understand and appreciate the fact that information security is a
trade-off.
Information Technology Security 6
References
Schneier, B. (2007). The economics of information security. Public lecture at the London School
of Economics. Retrieved February 27, 2010 from
[Link]
WEIS. (2008). Workshop on the economics of information security. Retrieved March 1, 2010
from [Link]