Anderson, R. Why information security is hard - an economic perspective Computer Security Applications Conference, 2001. ACSAC 2001. Proceedings 17th Annual http://ieeexplore.ieee.org/xpls/abs_all.jsp?arnumber=991552
Abstract
According to one common view, information security comes down to technical measures. Given better access control policy models, formal proofs of cryptographic protocols, approved firewalls, better ways of detecting intrusions and malicious code, and better tools for system evaluation and assurance, the problems can be solved. The author puts forward a contrary view: information insecurity is at least as much due to perverse incentives. Many of the problems can be explained more clearly and convincingly using the language of microeconomics: network externalities, asymmetric information, moral hazard, adverse selection, liability dumping and the tragedy of the commons.
Andrew G. Kotulic & Jan Guynes Clark 2004 “Why there aren't more information security research studies” Information and Management Volume 41 , Issue 5 (May 2004) Pages: 597 - 607 http://portal.acm.org/citation.cfm?id=1005438.1005444
Noting a serious lack of empirical research in the area of security risk management (SRM), we proposed a conceptual model based on the study of SRM at the firm level. Although considerable time and effort were expended in attempting to validate the usefulness of the proposed model, we were not successful. We provide here a description of our conceptual model, the methodology designed to test this model, the problems we faced while attempting to test the model, and our suggestions for those who attempt to conduct work in highly sensitive areas.
KJ Knapp, TE Marshall, RK Rainer, FN Ford 2006 “Information security: management's effect on culture and policy” Information Management & Computer Security, 2006
http://www.emeraldinsight.com/Insight/viewPDF.jsp?Filename=html/Output/Published/EmeraldFullTextArticle/Pdf/0460140102.pdf
JK Sinclaire 2003 “ Current Research in Information Security and Privacy” Information Systems Management, 2003 http://sais.aisnet.org/SAIS2005/Sinclaire.pdf
Mikko Siponen 2006 “ Information Security Standards Focus on the Existence of Process, Not Its Content” COMMUNICATIONS OF THE ACM August 2006/Vol. 49, No. 8 http://portal.acm.org/citation.cfm?id=1145316

