A framework for using insurance for cyber-risk management

被引:121
作者
Gordon, LA [1 ]
Loeb, MP [1 ]
Sohail, T [1 ]
机构
[1] Univ Maryland, Sch Business, College Pk, MD 20742 USA
关键词
D O I
10.1145/636772.636774
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Various aspects related to the use of recently developed cyber-risk insurance policies aimed at providing coverage against losses from internet related breaches in information security are discussed. A generic framework for using cyber-risk insurance for helping to manage information security risk is described. The framework is based on the entire risk management process and includes a comprehensive four-step cyber-risk insurance decision plan. Various aspects related to pricing of such insurance policies, and the effects that may arise out of adverse selection are also discussed.
引用
收藏
页码:81 / 85
页数:5
相关论文
共 11 条
[1]  
[Anonymous], 2002, COMPUTER SECURITY IS
[2]  
BRYCE R, 2001, INTERACTIVE WEE 0528, P11
[3]  
*GAUNTL ASS, 2001, INS PROD REV 0815
[4]  
GOLD J, 2001, E BUSINESS INSU 0816
[5]  
MADDEN J, 2000, PC WEEK 0216, P15
[6]  
*MARSH CO, 2001, MARSH AT T UNV 0815
[7]  
*NAT I STAND TECHN, 1995, INTRO COMP SEC NIST
[8]  
RADCLIFF D, 2001, COMPUTER WORLD, V35, P34
[9]  
ROSSI MA, 2001, NEW STANDALONE E COM
[10]  
ROSSI MA, 2001, STANDALONE E COM JUL