Why Information Security is Hard-An Economic Perspective

  • Authors:
  • R. Anderson

  • Affiliations:
  • -

  • Venue:
  • ACSAC '01 Proceedings of the 17th Annual Computer Security Applications Conference
  • Year:
  • 2001

Quantified Score

Hi-index 0.02

Visualization

Abstract

According to one common view, information securitycomes down to technical measures. Given betteraccess control policy models, formal proofs of crypto-graphicprotocols, approved firewalls, better ways of detectingintrusions and malicious code, and better toolsfor system evaluation and assurance, the problems canbe solved.In this note, I put forward a contrary view: informationinsecurity is at least as much due to perverseincentives. Many of the problems can be explainedmore clearly and convincingly using the language ofmicroeconomics: network externalities, asymmetricinformation, moral hazard, adverse selection, liabilitydumping and the tragedy of the commons.