Item Details
Skip Navigation Links
   ActiveUsers:1362Hits:19822743Skip Navigation Links
Show My Basket
Contact Us
IDSA Web Site
Ask Us
Today's News
HelpExpand Help
Advanced search

In Basket
  Journal Article   Journal Article
 

ID114080
Title ProperResponsive regulation and the reporting of information security incidents
Other Title InformationTaiwan and China
LanguageENG
AuthorChang, Lennon Yao-Chung
Publication2012.
Summary / Abstract (Note)As most software used by government agencies and companies is proprietary, malicious computer activity targeting breaches in that software can be likened to a pandemic of an infectious disease in the cyber world. When a breach occurs, the consequences can be widespread and damaging because the damage can spread rapidly. Therefore, cybercrime prevention needs to involve all users in a cooperative effort,with warnings and information on countermeasures distributed to users in order to prevent the "disease" from spreading when unprotected computers encounter an attack. This cooperative effort relies heavily on all institutions reporting information security incidents. Based on institutional theory, together with regulatory pluralism and responsive regulation theory, this paper examines the pluralized regulatory approach adopted to promote a system for sharing reports of information security incidents in Taiwan and China. An expanded model of regulatory enforcement and a strengths-based pyramid are proposed and used as a framework for discussing existing systems for encouraging the reporting of information security incidents.
`In' analytical NoteIssues and Studies Vol. 48, No.1; Mar 2012: p.85-119
Journal SourceIssues and Studies Vol. 48, No.1; Mar 2012: p.85-119
Key WordsInstitutional Theory ;  Responsive Regulation ;  Information Security ;  Incident Reporting ;  Expanded Regulatory Pyramid