Article (Scientific journals)
When Your Thing Won’t Behave: Security Governance in the Internet of Things
BRENNECKE, Martin; FRIDGEN, Gilbert; JÖHNK, Jan et al.
2024In Information Systems Frontiers
Peer Reviewed verified by ORBi
 

Files


Full Text
Brennecke_et_al_2024_Security Governance in the Internet of Things.pdf
Publisher postprint (771.69 kB) Creative Commons License - Attribution
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Information Security; Internet of Things (IoT); IT Governance; IT Security; Risk Analysis; Security Breach
Abstract :
[en] In the Internet of Things (IoT), interconnected smart things enable new products and services in cyber-physical systems. Yet, smart things not only inherit information technology (IT) security risks from their digital components, but they may also aggravate them through the use of technology platforms (TPs). In the context of the IoT, TPs describe a tangible (e.g., hardware) or intangible (e.g., software and standards) general-purpose technology that is shared between different models of smart things. While TPs are evolving rapidly owing to their functional and economic benefits, this is partly to the detriment of security, as several recent IoT security incidents demonstrate. We address this problem by formalizing the situation’s dynamics with an established risk quantification approach from platforms in the automotive industry, namely a Bernoulli mixture model. We outline and discuss the implications of relevant parameters for security risks of TP use in the IoT, i.e., correlation and heterogeneity, vulnerability probability and conformity costs, exploit probability and non-conformity costs, as well as TP connectivity. We argue that these parameters should be considered in IoT governance decisions and delineate prescriptive governance implications, identifying potential counter-measures at the individual, organizational, and regulatory levels.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > FINATRAX - Digital Financial Services and Cross-organizational Digital Transformations
Disciplines :
Computer science
Management information systems
Author, co-author :
BRENNECKE, Martin  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > FINATRAX
FRIDGEN, Gilbert  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > FINATRAX
JÖHNK, Jan;  University of Bayreuth > FIM Research Institute for Information Management
RADSZUWILL, Sven;  University of Bayreuth > FIM Research Institute for Information Management
SCHÖNRICH-SEDLMEIR, Johannes  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > FINATRAX
External co-authors :
yes
Language :
English
Title :
When Your Thing Won’t Behave: Security Governance in the Internet of Things
Publication date :
22 August 2024
Journal title :
Information Systems Frontiers
ISSN :
1387-3326
eISSN :
1572-9419
Publisher :
Springer, New-York, United States - New York
Peer reviewed :
Peer Reviewed verified by ORBi
Focus Area :
Security, Reliability and Trust
Development Goals :
9. Industry, innovation and infrastructure
16. Peace, justice and strong institutions
FnR Project :
FNR13342933 - Paypal-fnr Pearl Chair In Digital Financial Services, 2019 (01/01/2020-31/12/2024) - Gilbert Fridgen
FNR16326754 - Privacy-preserving Tokenisation Of Artworks, 2021 (01/06/2022-31/05/2025) - Gilbert Fridgen
Name of the research project :
R-AGR-3728 - PEARL/IS/13342933/DFS - FRIDGEN Gilbert
U-AGR-7110 - C21/IS/16326754/PABLO - FRIDGEN Gilbert
Funders :
FNR - Fonds National de la Recherche
FNR - Luxembourg National Research Fund
Banque et Caisse d’Épargne de l’État, Luxembourg (Spuerkeess)
Funding number :
13342933; 16326754
Funding text :
This research was funded in part by the Luxembourg National Research Fund (FNR) and PayPal, PEARL grant reference 13342933/Gilbert Fridgen, as well as grant reference 16326754/PABLO. Supported by Banque et Caisse d’Épargne de l’État, Luxembourg (Spuerkeess). For the purpose of open access, and in fulfillment of the obligations arising from the grant agreement, the authors have applied a Creative Commons Attribution 4.0 International (CC BY 4.0) license to any Author Accepted Manuscript version arising from this submission. Open Access funding enabled and organized by Projekt DEAL.
Available on ORBilu :
since 22 August 2024

Statistics


Number of views
95 (25 by Unilu)
Number of downloads
24 (8 by Unilu)

Scopus citations®
 
1
Scopus citations®
without self-citations
1
OpenCitations
 
0
OpenAlex citations
 
1

Bibliography


Similar publications



Contact ORBilu