The Effects of Security Management on Security Events
The Effects of Security Management on Security Events
复制标题
安全管理对安全事件的影响
DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
F. Nagle
中科院分区:
文献类型:
--
作者:
F. Nagle
Although the desired outcome of security management is better security, empirical evidence for this link is scarce. The scarcity arises from lack of data at the firm level for either security posture or incidents across a broad sample of companies. To address this, we use a novel dataset of daily firm-level security information for 480 of the Fortune 500 enterprises that consists of over 33 million security events. The dataset, obtained from a security monitoring company, contains daily measures of security management and negative security events for a 294 day period, yielding 133,248 firm/day observations. Empirical analysis finds that the number of open ports in a firm is associated with higher incidences of botnet activity, potential exploitation, and unsolicited communications, with some analyses also showing a link to malware activity. The findings are robust to several alternative specifications using hidden Markov and hierarchical linear models. This paper thus finds empirical evidence for a fundamental assumption of security practice — a link between security management and improved security.