Skip to main content
Erschienen in: Operations Management Research 1-4/2009

01.12.2009

Managing supply chain risk and disruption from IT security incidents

verfasst von: Jason K. Deane, Cliff T. Ragsdale, Terry R. Rakes, Loren Paul Rees

Erschienen in: Operations Management Research | Ausgabe 1-4/2009

Einloggen

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Supply chain practices often put companies and their supply chains at risk. One of the most serious risks is disruptions. While many types of disruptions have been considered, little attention has been given to disruptions caused by information technology (IT) security incidents. Partner cooperation can assist in preventing or mitigating damage from IT security breaches in supply chains, where breaches can disrupt production, cause loss of essential data, and compromise confidential information. We develop a generalizable mathematical model that quantifies IT security risk in the supply chain. We then show how to find solutions for optimal risk reduction under several definitions of optimality: minimizing upstream risk, minimizing downstream risk, and minimizing global (supply chain) risk. We show how to develop curves for each of the above scenarios that indicate when extra funds should be spent on security, which security controls should be implemented, and when subsidies among partners are beneficial.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
Zurück zum Zitat Baker W, Wallace L (2007) Dependable computing: is information security under control? IEEE Security & Privacy, January/February: 24–32 Baker W, Wallace L (2007) Dependable computing: is information security under control? IEEE Security & Privacy, January/February: 24–32
Zurück zum Zitat Blackhurst J, Craighead C, Elkins D, Handfield R (2005) An empirically-derived agenda of critical research issues for managing supply chain disruptions. Int J Prod Res 43:4067–4081CrossRef Blackhurst J, Craighead C, Elkins D, Handfield R (2005) An empirically-derived agenda of critical research issues for managing supply chain disruptions. Int J Prod Res 43:4067–4081CrossRef
Zurück zum Zitat Craighead C, Blackhurst J, Rungtusantham J, Handfield R (2007) The severity of supply chain disruptions: design characteristics and mitigation capabilities. Decis Sci 38:131–156CrossRef Craighead C, Blackhurst J, Rungtusantham J, Handfield R (2007) The severity of supply chain disruptions: design characteristics and mitigation capabilities. Decis Sci 38:131–156CrossRef
Zurück zum Zitat Kolluru R, Meredith P (2001) Security and trust management in supply chains. Inf Manag Comput Secur 9:233–236 Kolluru R, Meredith P (2001) Security and trust management in supply chains. Inf Manag Comput Secur 9:233–236
Zurück zum Zitat Narasimhan R, Jayaram J (1998) Casual linkages in supply chain management: an exploratory study of North American manufacturing firms. Decis Sci 29:579–606CrossRef Narasimhan R, Jayaram J (1998) Casual linkages in supply chain management: an exploratory study of North American manufacturing firms. Decis Sci 29:579–606CrossRef
Zurück zum Zitat Prahinski C, Benton W (2004) Supplier evaluations: communication strategies to improve supplier performance. J Oper Manag 22:39–62CrossRef Prahinski C, Benton W (2004) Supplier evaluations: communication strategies to improve supplier performance. J Oper Manag 22:39–62CrossRef
Zurück zum Zitat Rice J, Caniato F (2003) Building a secure and resilient supply chain. Supply Chain Manag Rev 7:22–30 Rice J, Caniato F (2003) Building a secure and resilient supply chain. Supply Chain Manag Rev 7:22–30
Zurück zum Zitat Sanders N (2005) IT alignment in supply chain relationships: a study of supplier benefits. J Supply Chain Mang 41(2):4–13 Sanders N (2005) IT alignment in supply chain relationships: a study of supplier benefits. J Supply Chain Mang 41(2):4–13
Zurück zum Zitat Sherali H, Bazaraa M, Jarvis J (2004) Linear programming and network flows. Wiley, New York Sherali H, Bazaraa M, Jarvis J (2004) Linear programming and network flows. Wiley, New York
Zurück zum Zitat Vakharia A (2002) E-business and supply chain management. Decis Sci 33:495–504CrossRef Vakharia A (2002) E-business and supply chain management. Decis Sci 33:495–504CrossRef
Zurück zum Zitat Wagner S, Bode C (2008) An empirical examination of supply chain performance along several dimensions of risk. J Bus Logist 29:307–326 Wagner S, Bode C (2008) An empirical examination of supply chain performance along several dimensions of risk. J Bus Logist 29:307–326
Zurück zum Zitat Zsidisin G (2003) A grounded definition of supply risk. J Purch & Supply Manag 9:217–224CrossRef Zsidisin G (2003) A grounded definition of supply risk. J Purch & Supply Manag 9:217–224CrossRef
Metadaten
Titel
Managing supply chain risk and disruption from IT security incidents
verfasst von
Jason K. Deane
Cliff T. Ragsdale
Terry R. Rakes
Loren Paul Rees
Publikationsdatum
01.12.2009
Verlag
Springer US
Erschienen in
Operations Management Research / Ausgabe 1-4/2009
Print ISSN: 1936-9735
Elektronische ISSN: 1936-9743
DOI
https://doi.org/10.1007/s12063-009-0018-2

Weitere Artikel der Ausgabe 1-4/2009

Operations Management Research 1-4/2009 Zur Ausgabe