Improving Internet Security through Mandatory Information Disclosure

Although disclosure has long been considered as a solution to internalize externalities, mandatory security information disclosure is still in debate. We propose a mandatory disclosure mechanism based on existing data. The information is disclosed as straightforward rankings of organizations for use...

Full description

Saved in:
Bibliographic Details
Main Authors: TANG, Qian, WHINSTON, Andrew B.
Format: text
Language:English
Published: Institutional Knowledge at Singapore Management University 2015
Subjects:
Online Access:https://ink.library.smu.edu.sg/sis_research/2637
https://ink.library.smu.edu.sg/context/sis_research/article/3637/viewcontent/Improv_Internet_Security_Mandatory_HICSS_2015_pv.pdf
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Singapore Management University
Language: English
id sg-smu-ink.sis_research-3637
record_format dspace
spelling sg-smu-ink.sis_research-36372020-01-07T07:43:50Z Improving Internet Security through Mandatory Information Disclosure TANG, Qian WHINSTON, Andrew B. Although disclosure has long been considered as a solution to internalize externalities, mandatory security information disclosure is still in debate. We propose a mandatory disclosure mechanism based on existing data. The information is disclosed as straightforward rankings of organizations for users to understand, interpret, and make comparisons. As a result, the disclosure can influence organizations through reputational effects. We created a public website to disclose information regularly and conducted a quasi-experiment on outgoing spam to test the effectiveness of our mechanism on four matched country groups. For each treated country, we released the ranking list of top 10 most spamming organizations every month, while for the control countries, no information was disclosed. We find that the treatment organizations subject to spam information disclosure reduced significantly more spam than comparison organizations. 2015-01-01T08:00:00Z text application/pdf https://ink.library.smu.edu.sg/sis_research/2637 info:doi/10.1109/HICSS.2015.572 https://ink.library.smu.edu.sg/context/sis_research/article/3637/viewcontent/Improv_Internet_Security_Mandatory_HICSS_2015_pv.pdf http://creativecommons.org/licenses/by-nc-nd/4.0/ Research Collection School Of Computing and Information Systems eng Institutional Knowledge at Singapore Management University Computer Sciences Information Security Management Information Systems
institution Singapore Management University
building SMU Libraries
continent Asia
country Singapore
Singapore
content_provider SMU Libraries
collection InK@SMU
language English
topic Computer Sciences
Information Security
Management Information Systems
spellingShingle Computer Sciences
Information Security
Management Information Systems
TANG, Qian
WHINSTON, Andrew B.
Improving Internet Security through Mandatory Information Disclosure
description Although disclosure has long been considered as a solution to internalize externalities, mandatory security information disclosure is still in debate. We propose a mandatory disclosure mechanism based on existing data. The information is disclosed as straightforward rankings of organizations for users to understand, interpret, and make comparisons. As a result, the disclosure can influence organizations through reputational effects. We created a public website to disclose information regularly and conducted a quasi-experiment on outgoing spam to test the effectiveness of our mechanism on four matched country groups. For each treated country, we released the ranking list of top 10 most spamming organizations every month, while for the control countries, no information was disclosed. We find that the treatment organizations subject to spam information disclosure reduced significantly more spam than comparison organizations.
format text
author TANG, Qian
WHINSTON, Andrew B.
author_facet TANG, Qian
WHINSTON, Andrew B.
author_sort TANG, Qian
title Improving Internet Security through Mandatory Information Disclosure
title_short Improving Internet Security through Mandatory Information Disclosure
title_full Improving Internet Security through Mandatory Information Disclosure
title_fullStr Improving Internet Security through Mandatory Information Disclosure
title_full_unstemmed Improving Internet Security through Mandatory Information Disclosure
title_sort improving internet security through mandatory information disclosure
publisher Institutional Knowledge at Singapore Management University
publishDate 2015
url https://ink.library.smu.edu.sg/sis_research/2637
https://ink.library.smu.edu.sg/context/sis_research/article/3637/viewcontent/Improv_Internet_Security_Mandatory_HICSS_2015_pv.pdf
_version_ 1770572532164853760