Security Standardization in the Presence of Unverifiable Control.
Chul‐Ho Lee, Xianjun Geng, Srinivasan Raghunathan · 2011
Increasingly, policy makers in both private and public sectors mandate information security standards upon organizations in order to protect both organizational and individual digital assets. One major issue in security standardization is that standards often cannot cover all possible security efforts by organizations because some efforts are unverifiable by nature. This paper analytically studies how a policy maker should design the standard on a verifiable security control when another related unverifiable one exists. We find that naively ignoring the existence of the unverifiable control will in general lead to a sub-optimal standard. Furthermore, optimal standard depends critically on how the two security controls work together-- which we refer to as security configurations-- to protect the firm's digital asset. Under parallel configuration, the existence of the unverifiable control induces the policy maker to set a higher standard; under serial configuration, a lower standard. Under best-shot configuration and if the verifiable control is more cost-efficient, the existence of the unverifiable control has no impact on the optimal standard. We also find that whether attackers are strategically targeting the weakest-link control has a significant impact on optimal security standard under the parallel configuration. Such strategic attacking behavior can severely handicap the policy maker's optimal standard and thus reduce its effectiveness.