<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : WEIS 2008</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/WEIS+2008/default.aspx</link><description>Tags: WEIS 2008</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>WEIS 2008 and “Economics of Identity Management”</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/11/weis-2008-and-economics-of-identity-management.aspx</link><pubDate>Tue, 10 Jun 2008 21:47:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83204</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/11/weis-2008-and-economics-of-identity-management.aspx#comments</comments><description>&lt;p class="MsoNormal" style="MARGIN:0pt 30.6pt 0pt 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="COLOR:black;"&gt;R&amp;amp;D papers and work presented at the &lt;/span&gt;Workshops on Economics of Information Security&lt;span style="COLOR:black;"&gt; (WEIS) &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;discuss and explore how economic theory and economic analysis can be successfully applied to information security, instead of focusing just on the traditional technology-driven approaches. &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="COLOR:black;"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;What are the “Economics of Identity Management”?&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;Something I believe it would be worth exploring too, with a scientific approach.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;The &lt;/font&gt;&lt;a href="http://weis2008.econinfosec.org/index.htm"&gt;&lt;font face="Times New Roman" size="3"&gt;7&lt;sup&gt;th&lt;/sup&gt; workshop on Economics of Information Security - WEIS 2008&lt;/font&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt; is going to take place in Hanover, HN, June 25-28, 2008: &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt 30.6pt 0pt 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;“Information security requires not only technology, but a clear understanding of risks, decision-making behaviors and metrics for evaluating business and policy options. How much should we spend on security? What incentives really drive privacy decisions? What are the trade-offs that individuals, firms, and governments face when allocating resources to protect data assets? Are there good ways to distribute risks and align goals when securing information systems?&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt 30.6pt 0pt 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;The 2008 Workshop on the Economics of Information Security, the seventh workshop, will build on a strong and growing interdisciplinary tradition, bringing together information technology academics and practitioners with social scientists and business and legal scholars to better understand security and privacy threats. Until recently, research in security and dependability focused almost exclusively on technical factors, rather than incentives. However, we know that economic, behavioral, and legal factors often contribute as much as technology to the dependability of information and information systems. The application of economic analysis to these problems has proven to be an exciting and fruitful area of research.”&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;Most of the above points also apply to the “Identity Management” field. An opportunity to contribute.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/font&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;font face="Times New Roman" size="3"&gt;mirror blog&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83204" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/WEIS+2008/default.aspx">WEIS 2008</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+Management/default.aspx">Economics of Identity Management</category></item><item><title>Data Breach Disclosure Laws Are Not so Effective in Reducing Identity Theft …</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/07/data-breach-disclosure-laws-are-not-so-effective-in-reducing-identity-theft.aspx</link><pubDate>Fri, 06 Jun 2008 17:11:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83164</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/07/data-breach-disclosure-laws-are-not-so-effective-in-reducing-identity-theft.aspx#comments</comments><description>&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;This is the message I got from a very interesting paper, titled “Do Data Breach Disclosure Laws Reduce Identity Theft?” (Authors: Sasha Romanosky, Rahul Telang, Alessandro Acquisti), that is going to be presented at the &lt;/font&gt;&lt;a href="http://weis2008.econinfosec.org/index.htm"&gt;&lt;font face="Times New Roman" size="3"&gt;7&lt;sup&gt;th&lt;/sup&gt; workshop on Economics of Information Security - WEIS 2008&lt;/font&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;, Hanover, HN, June 25-28, 2008.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;Based on their current studies, the authors found “&lt;/span&gt;no statistically significant effect that laws reduce identity theft, even after considering income, urbanization, strictness of law and interstate commerce”. The full abstract of a &lt;/font&gt;&lt;/font&gt;&lt;a href="http://weis2008.econinfosec.org/papers/Romanosky.pdf"&gt;&lt;font face="Times New Roman" size="3"&gt;draft version of their paper&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; (accessible online) follows:&lt;/font&gt;&lt;/p&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;mso-layout-grid-align:none;"&gt;&lt;font face="Times New Roman" size="3"&gt;“Identity theft resulted in corporate and consumer losses of $56 billion dollars in 2005, with about 30% of known identity thefts caused by corporate data breaches. Many US states have responded by adopting data breach disclosure laws that require firms to notify consumers if their personal information has been lost or stolen. While the laws are expected to reduce losses, their full effects have yet to be empirically measured.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;mso-layout-grid-align:none;"&gt;&lt;font face="Times New Roman" size="3"&gt;We use panel from the US Federal Trade Commission with state and time fixed-effects regression to estimate the impact of data breach disclosure laws on identity theft over the years 2002 to 2006. We find no statistically significant effect that laws reduce identity theft, even after considering income, urbanization, strictness of law and interstate commerce. If the probability of becoming a victim conditional on a data breach is very small, then the law’s maximum effectiveness is inherently limited. Quality of data and the possibility of reporting bias also make proper identification difficult. However, we appreciate that these laws may have other benefits such as reducing a victim’s average losses and improving a firm’s security and operational practices.”&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;mso-layout-grid-align:none;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/font&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;font face="Times New Roman" size="3"&gt;mirror blog&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83164" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Theft/default.aspx">Identity Theft</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Data+Breach+Disclosure+Laws/default.aspx">Data Breach Disclosure Laws</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/WEIS+2008/default.aspx">WEIS 2008</category></item></channel></rss>