Outsourcing Information Security: Contracting Issues and Security Implications.
Asunur Cezar, Huseyin Cavusoglu, Srinivasan Raghunathan · 2010
We examine the implications of a firm outsourcing both (i) security device management which attempts to prevent security breaches and (ii) security monitoring which attempts to detect security breaches to managed security service providers (MSSPs). In the context of security outsourcing, the firm not only faces the traditional moral hazard problem as it cannot observe an MSSP’s prevention or detection effort, but also observes the security breach outcome only imperfectly. Furthermore, outsourced prevention and detection services are separate but interrelated security functions, and thereby cannot be considered independently. Hence, the firm needs to carefully design a contract or contracts to induce the desired efforts from the service providers to effectively manage the cost of information security. We first show that the current practice of outsourcing both device management and monitoring functions to the same MSSP using a contract that imposes a penalty on MSSP when the MSSP is deemed responsible for a breach results in a higher than the first-best prevention effort and zero (and less than the first-best) detection effort. This is due to the conflict of interest faced by the MSSP and the substitutable nature of prevention and detection services. We then propose two new contracts, both of which achieve the firstbest outcomes. The first contract imposes a penalty for a breach and offers a reward for detecting and