{"id":"https://openalex.org/W1550987893","doi":"https://doi.org/10.1108/09685221211267675","title":"Can spending on information security be justified?","display_name":"Can spending on information security be justified?","publication_year":2012,"publication_date":"2012-10-05","ids":{"openalex":"https://openalex.org/W1550987893","doi":"https://doi.org/10.1108/09685221211267675","mag":"1550987893"},"language":"en","primary_location":{"id":"doi:10.1108/09685221211267675","is_oa":false,"landing_page_url":"https://doi.org/10.1108/09685221211267675","pdf_url":null,"source":{"id":"https://openalex.org/S204075876","display_name":"Information Management & Computer Security","issn_l":"0968-5227","issn":["0968-5227","1758-5805"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319811","host_organization_name":"Emerald Publishing Limited","host_organization_lineage":["https://openalex.org/P4310319811"],"host_organization_lineage_names":["Emerald Publishing Limited"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Information Management &amp; Computer Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5083699810","display_name":"Andrew Stewart","orcid":"https://orcid.org/0000-0003-4568-2124"},"institutions":[{"id":"https://openalex.org/I58610484","display_name":"Seattle University","ror":"https://ror.org/02jqc0m91","country_code":"US","type":"education","lineage":["https://openalex.org/I58610484"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Andrew Stewart","raw_affiliation_strings":["Seattle, Washington, USA","(Seattle, Washington, USA)"],"affiliations":[{"raw_affiliation_string":"Seattle, Washington, USA","institution_ids":["https://openalex.org/I58610484"]},{"raw_affiliation_string":"(Seattle, Washington, USA)","institution_ids":["https://openalex.org/I58610484"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":["https://openalex.org/A5083699810"],"corresponding_institution_ids":["https://openalex.org/I58610484"],"apc_list":null,"apc_paid":null,"fwci":1.4211,"has_fulltext":false,"cited_by_count":13,"citation_normalized_percentile":{"value":0.8608599,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":"20","issue":"4","first_page":"312","last_page":"326"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9977999925613403,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9968000054359436,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.5151268243789673},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.4351254999637604},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4056756794452667},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.3819820284843445},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.34150487184524536}],"concepts":[{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.5151268243789673},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.4351254999637604},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4056756794452667},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.3819820284843445},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.34150487184524536}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1108/09685221211267675","is_oa":false,"landing_page_url":"https://doi.org/10.1108/09685221211267675","pdf_url":null,"source":{"id":"https://openalex.org/S204075876","display_name":"Information Management & Computer Security","issn_l":"0968-5227","issn":["0968-5227","1758-5805"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319811","host_organization_name":"Emerald Publishing Limited","host_organization_lineage":["https://openalex.org/P4310319811"],"host_organization_lineage_names":["Emerald Publishing Limited"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Information Management &amp; Computer Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":17,"referenced_works":["https://openalex.org/W164190891","https://openalex.org/W199870329","https://openalex.org/W587461618","https://openalex.org/W1497179850","https://openalex.org/W1501321335","https://openalex.org/W1526490979","https://openalex.org/W1863670505","https://openalex.org/W2018085556","https://openalex.org/W2028907687","https://openalex.org/W2031563537","https://openalex.org/W2096830520","https://openalex.org/W2117634019","https://openalex.org/W2122243892","https://openalex.org/W2144677027","https://openalex.org/W2160258502","https://openalex.org/W6632833816","https://openalex.org/W6683716699"],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W2358668433","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W2382290278","https://openalex.org/W2478288626","https://openalex.org/W2350741829","https://openalex.org/W2530322880","https://openalex.org/W4210648132"],"abstract_inverted_index":{"Purpose":[0],"The":[1,35,116],"purpose":[2],"of":[3,11,27,43,57,82,85,143,163],"this":[4,214],"paper":[5,209],"is":[6,30,59,71,91],"to":[7,21,32,77,101,105,110,123,131,184],"investigate":[8],"the":[9,23,44,69,79,158],"optimality":[10],"various":[12],"strategies":[13,29,121,138],"for":[14,61,128,140,148],"spending":[15,28,46,62,87,111,120,149,197],"on":[16,63,112,150,213],"information":[17,64,113,151],"security.":[18,65,114,152],"Being":[19],"able":[20],"understand":[22],"strengths":[24],"and":[25,52,54,126,202],"weaknesses":[26,144],"useful":[31,211],"organizations.":[33],"Design/methodology/approach":[34],"author's":[36],"analysis":[37,75],"begins":[38],"with":[39,73,175],"a":[40,55,83,98,107,134,141,161],"whole\u2010systems":[41],"view":[42],"security":[45],"decision":[47],"that":[48,74,93,160,188],"encompasses":[49],"people,":[50],"technology,":[51],"economics":[53],"taxonomy":[56,70],"justifications":[58,147],"presented":[60],"Each":[66],"justification":[67],"within":[68],"discussed,":[72],"used":[76,96],"examine":[78],"apparent":[80],"rationality":[81],"number":[84,142,162],"common":[86,146],"strategies.":[88],"A":[89],"model":[90],"constructed":[92],"can":[94],"be":[95,124,199],"in":[97,133,145,169,204],"practical":[99,135],"manner":[100],"enable":[102],"an":[103,129],"organization":[104,130],"select":[106],"rational":[108,205],"approach":[109],"Findings":[115],"author":[117],"describes":[118],"two":[119],"intended":[122],"simple":[125],"straightforward":[127],"employ":[132],"manner.":[136],"These":[137],"account":[139],"They":[153],"also":[154],"take":[155],"into":[156],"consideration":[157],"observation":[159],"pressures":[164],"push":[165],"companies":[166],"towards":[167],"inefficiency":[168],"their":[170],"spending.":[171],"Originality/value":[172],"When":[173],"faced":[174],"budgeting":[176],"decisions,":[177],"managers":[178],"are":[179],"bound":[180],"by":[181],"fiduciary":[182],"duty":[183],"identify":[185],"those":[186],"investments":[187],"will":[189],"maximize":[190],"shareholder":[191],"value.":[192],"As":[193],"such,":[194],"decisions":[195],"about":[196],"must":[198],"carefully":[200],"considered":[201],"evaluated":[203],"economic":[206],"terms.":[207],"This":[208],"provides":[210],"thinking":[212],"important":[215],"topic.":[216]},"counts_by_year":[{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":9},{"year":2014,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
