Publications-Issues & Studies

Article View/Open

Publication Export

Google ScholarTM

NCCU Library

Citation Infomation

Related Publications in TAIR

題名 Responsive Regulation and the Reporting of Information Security Incidents-Taiwan and China
作者 Chang, Lennon Yao-Chung
關鍵詞 institutional theory ; responsive regulation ; information security ; incident reporting ; expanded regulatory pyramid
日期 2012-03
上傳時間 18-Nov-2016 15:00:07 (UTC+8)
摘要 As most software used by government agencies and companies is proprietary, malicious computer activity targeting breaches in that software can be likened to a pandemic of an infectious disease in the cyber world. When a breach occurs, the consequences can be widespread and damaging because the damage can spread rapidly. Therefore, cybercrime prevention needs to involve all users in a cooperative effort, with warnings and information on countermeasures distributed to users in order to prevent the ”disease” from spreading when unprotected computers encounter an attack. This cooperative effort relies heavily on all institutions reporting information security incidents. Based on institutional theory, together with regulatory pluralism and responsive regulation theory, this paper examines the pluralized regulatory approach adopted to promote a system for sharing reports of regulatory information security incidents in Taiwan and China. An expanded model of regulatory enforcement and a strengths-based pyramid are proposed and used as a framework for discussing existing systems for encouraging the reporting of information security incidents.
關聯 Issues & Studies,48(1),85-119
資料類型 article
dc.creator (作者) Chang, Lennon Yao-Chung
dc.date (日期) 2012-03
dc.date.accessioned 18-Nov-2016 15:00:07 (UTC+8)-
dc.date.available 18-Nov-2016 15:00:07 (UTC+8)-
dc.date.issued (上傳時間) 18-Nov-2016 15:00:07 (UTC+8)-
dc.identifier.uri (URI) http://nccur.lib.nccu.edu.tw/handle/140.119/104099-
dc.description.abstract (摘要) As most software used by government agencies and companies is proprietary, malicious computer activity targeting breaches in that software can be likened to a pandemic of an infectious disease in the cyber world. When a breach occurs, the consequences can be widespread and damaging because the damage can spread rapidly. Therefore, cybercrime prevention needs to involve all users in a cooperative effort, with warnings and information on countermeasures distributed to users in order to prevent the ”disease” from spreading when unprotected computers encounter an attack. This cooperative effort relies heavily on all institutions reporting information security incidents. Based on institutional theory, together with regulatory pluralism and responsive regulation theory, this paper examines the pluralized regulatory approach adopted to promote a system for sharing reports of regulatory information security incidents in Taiwan and China. An expanded model of regulatory enforcement and a strengths-based pyramid are proposed and used as a framework for discussing existing systems for encouraging the reporting of information security incidents.
dc.format.extent 662242 bytes-
dc.format.mimetype application/pdf-
dc.relation (關聯) Issues & Studies,48(1),85-119
dc.subject (關鍵詞) institutional theory ; responsive regulation ; information security ; incident reporting ; expanded regulatory pyramid
dc.title (題名) Responsive Regulation and the Reporting of Information Security Incidents-Taiwan and China
dc.type (資料類型) article