<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cyber.harvard.edu/cybersecurity/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Intern2</id>
	<title>Cybersecurity Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://cyber.harvard.edu/cybersecurity/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Intern2"/>
	<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/Special:Contributions/Intern2"/>
	<updated>2026-09-06T02:26:37Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods&amp;diff=495</id>
		<title>An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods&amp;diff=495"/>
		<updated>2010-06-04T14:12:20Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&#039;&#039;An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Bruce H. Kobayashi (2006), &#039;&#039;An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods.&#039;&#039; Supreme Court Economic Review, Vol. 14. [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=708562 SSRN&#039;&#039;]&lt;br /&gt;
 &lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;keyword=kob&amp;amp;f=wikibiblio.bib#Kobayashi:2006 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Economics of Cybersecurity]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
Cybersecurity, public goods, private goods&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
This paper examines the incentives of private actors to invest in cybersecurity. Prior analyses have examined investments in security goods, such as locks or safes that have the characteristics of private goods. The analysis in this paper extends this analysis to examine expenditures on security goods, such as information, that have the characteristics of public goods. In contrast to the private goods case, where individual uncoordinated security expenditures can lead to an overproduction of security, the public goods case can result in the underproduction of security expenditures, and incentives to free ride. Thus, the formation of collective organizations may be necessary to facilitate the production of public security goods, and the protection of information produced by the collective organization should be a central feature of such organizations. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods&amp;diff=494</id>
		<title>An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods&amp;diff=494"/>
		<updated>2010-06-04T14:11:44Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&#039;&#039;An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Bruce H. Kobayashi (2006), &#039;&#039;An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods.&#039;&#039; Supreme Court Economic Review, Vol. 14. [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=708562 SSRN&#039;&#039;]&lt;br /&gt;
 &lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;keyword=kob&amp;amp;f=wikibiblio.bib#Kobayashi:2006 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Economics of Cybersecurity]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
Cybersecurity, public goods, private goods&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
This paper examines the incentives of private actors to invest in cybersecurity. Prior analyses have examined investments in security goods, such as locks or safes that have the characteristics of private goods. The analysis in this paper extends this analysis to examine expenditures on security goods, such as information, that have the characteristics of public goods. In contrast to the private goods case, where individual uncoordinated security expenditures can lead to an overproduction of security, the public goods case can result in the underproduction of security expenditures, and incentives to free ride. Thus, the formation of collective organizations may be necessary to facilitate the production of public security goods, and the protection of information produced by the collective organization should be a central feature of such organizations. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods&amp;diff=493</id>
		<title>An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods&amp;diff=493"/>
		<updated>2010-06-04T14:08:27Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&#039;&#039;An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Bruce H. Kobayashi (2006), &#039;&#039;An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods.&#039;&#039; Supreme Court Economic Review, Vol. 14. [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=708562 SSRN&#039;&#039;]&lt;br /&gt;
 &lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Kobayashi:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Economics of Cybersecurity]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
Cybersecurity, public goods, private goods&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
This paper examines the incentives of private actors to invest in cybersecurity. Prior analyses have examined investments in security goods, such as locks or safes that have the characteristics of private goods. The analysis in this paper extends this analysis to examine expenditures on security goods, such as information, that have the characteristics of public goods. In contrast to the private goods case, where individual uncoordinated security expenditures can lead to an overproduction of security, the public goods case can result in the underproduction of security expenditures, and incentives to free ride. Thus, the formation of collective organizations may be necessary to facilitate the production of public security goods, and the protection of information produced by the collective organization should be a central feature of such organizations. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=A_Model_for_When_Disclosure_Helps_Security:_What_Is_Different_About_Computer_and_Network_Security&amp;diff=469</id>
		<title>A Model for When Disclosure Helps Security: What Is Different About Computer and Network Security</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=A_Model_for_When_Disclosure_Helps_Security:_What_Is_Different_About_Computer_and_Network_Security&amp;diff=469"/>
		<updated>2010-06-03T19:30:20Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: ==Full Title of Reference==  A Model for  When Disclosure  Helps Security: What is Different About Computer and Network Security?   ==Full Citation==  Peter P. Swire, &amp;#039;&amp;#039;A Model for  When D...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
A Model for  When Disclosure  Helps Security: What is Different About Computer and Network Security? &lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Peter P. Swire, &#039;&#039;A Model for  When Disclosure  Helps Security: What is Different About Computer and Network Security? &#039;&#039; (Journal on Telecommunications and High Technology Law, Vol. 2, Public Law and Legal Theory Working Paper Series No. 17, 2004).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID581001_code69688.pdf?abstractid=531782&amp;amp;mirid=1 &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Swire:2004&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=531782 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;See the article itself for any key words as a starting point&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
This Article asks the question: When does disclosure actually help security? The discussion begins with a paradox. Most experts in computer and network security are familiar with the slogan that there is no security through obscurity. The Open Source and encryption view is that revealing the details of a system will actually tend to improve security, notably due to peer review. In sharp contrast, a famous World War II slogan says loose lips sink ships. Most experts in the military and intelligence areas believe that secrecy is a critical tool for  maintaining security. Both cannot be right - disclosure  cannot both help and hurt security.&lt;br /&gt;
&lt;br /&gt;
Using a law and economics approach to resolve the paradox, Part I provides a model for deciding when either the Open Source or the military/intelligence viewpoints is likely to be correct. Part II explains why many computer and network security problems appear different from the traditional security problems of the physical world. Part III applies the analytic tools developed earlier in the paper to issues including the following: the enlargement of the public domain in a world of search engines; the relationship between disclosure  and deterrence; the importance of not disclosing passwords or the combination to a safe.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons:_Open_Source,_Proprietary_Software,_and_Government_Systems&amp;diff=468</id>
		<title>A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons:_Open_Source,_Proprietary_Software,_and_Government_Systems&amp;diff=468"/>
		<updated>2010-06-03T19:29:08Z</updated>

		<summary type="html">&lt;p&gt;Intern2: Undo revision 467 by Intern2 (Talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Peter P. Swire, &#039;&#039;A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems&#039;&#039; (Hous. L. Rev., Vol. 42, No. 5, Ohio State Public Law Working Paper No. 4, 2006).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID842228_code515373.pdf?abstractid=842228&amp;amp;mirid=1&#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Swire:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=842228 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;See the article itself for any key words as a starting point&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
The paper presents a 2x3 matrix, where disclosure for  security and  competition are assessed for three types of systems  or software: Open Source; proprietary software; and  government systems. The paper finds greater convergence on disclosure between Open  Source and proprietary  software than most commentators have believed. For instance, Open Source security  experts use secrecy in stealth firewalls and  in other ways. Open Source programmers also often rely on gaps in Open Source licenses to gain competitive advantage by keeping key information secret. Meanwhile, proprietary  software often uses more disclosure than assumed. For security, large purchasers and market forces often lead to disclosure about proprietary software. For competitive reasons, proprietary  software companies often disclose a great deal when seeking to become a standard in an area or for other reasons.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons:_Open_Source,_Proprietary_Software,_and_Government_Systems&amp;diff=467</id>
		<title>A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons:_Open_Source,_Proprietary_Software,_and_Government_Systems&amp;diff=467"/>
		<updated>2010-06-03T19:28:27Z</updated>

		<summary type="html">&lt;p&gt;Intern2: /* Full Citation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Peter P. Swire, &#039;&#039;A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems&#039;&#039; (Hous. L. Rev., Vol. 42, No. 5, Ohio State Public Law Working Paper No. 4, 2006).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID842228_code515373.pdf?abstractid=842228&amp;amp;mirid=1&#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Swire:2004&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=531782 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;See the article itself for any key words as a starting point&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
The paper presents a 2x3 matrix, where disclosure for  security and  competition are assessed for three types of systems  or software: Open Source; proprietary software; and  government systems. The paper finds greater convergence on disclosure between Open  Source and proprietary  software than most commentators have believed. For instance, Open Source security  experts use secrecy in stealth firewalls and  in other ways. Open Source programmers also often rely on gaps in Open Source licenses to gain competitive advantage by keeping key information secret. Meanwhile, proprietary  software often uses more disclosure than assumed. For security, large purchasers and market forces often lead to disclosure about proprietary software. For competitive reasons, proprietary  software companies often disclose a great deal when seeking to become a standard in an area or for other reasons.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=466</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=466"/>
		<updated>2010-06-03T19:23:41Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis]]&lt;br /&gt;
&lt;br /&gt;
Schwartz, Paul and Janger, Edward (&#039;&#039;2007&#039;&#039;) [[Notification of Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Granick, Jennifer Stisa (&#039;&#039;2005&#039;&#039;) [[The Price of Restricting Vulnerability Publications]]&lt;br /&gt;
&lt;br /&gt;
Romanosky et al. (&#039;&#039;2008&#039;&#039;) [[Do Data Breach Disclosure Laws Reduce Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2005)&#039;&#039; [[An Economic Analysis of Notification Requirements for Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2006)&#039;&#039; [[Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers]]&lt;br /&gt;
&lt;br /&gt;
Swire, Peter P (&#039;&#039;2006&#039;&#039;) [[A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems]]&lt;br /&gt;
&lt;br /&gt;
Swire, Peter P (&#039;&#039;2004&#039;&#039;) [[A Model for When Disclosure Helps Security: What Is Different About Computer and Network Security]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons:_Open_Source,_Proprietary_Software,_and_Government_Systems&amp;diff=465</id>
		<title>A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons:_Open_Source,_Proprietary_Software,_and_Government_Systems&amp;diff=465"/>
		<updated>2010-06-03T19:22:12Z</updated>

		<summary type="html">&lt;p&gt;Intern2: /* Full Citation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Peter P. Swire, &#039;&#039;A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems&#039;&#039; (Hous. L. Rev., Vol. 42, No. 5, Ohio State Public Law Working Paper No. 4, 2006).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID842228_code515373.pdf?abstractid=842228&amp;amp;mirid=1&#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Swire:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=842228 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;See the article itself for any key words as a starting point&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
The paper presents a 2x3 matrix, where disclosure for  security and  competition are assessed for three types of systems  or software: Open Source; proprietary software; and  government systems. The paper finds greater convergence on disclosure between Open  Source and proprietary  software than most commentators have believed. For instance, Open Source security  experts use secrecy in stealth firewalls and  in other ways. Open Source programmers also often rely on gaps in Open Source licenses to gain competitive advantage by keeping key information secret. Meanwhile, proprietary  software often uses more disclosure than assumed. For security, large purchasers and market forces often lead to disclosure about proprietary software. For competitive reasons, proprietary  software companies often disclose a great deal when seeking to become a standard in an area or for other reasons.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons:_Open_Source,_Proprietary_Software,_and_Government_Systems&amp;diff=464</id>
		<title>A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons:_Open_Source,_Proprietary_Software,_and_Government_Systems&amp;diff=464"/>
		<updated>2010-06-03T19:18:08Z</updated>

		<summary type="html">&lt;p&gt;Intern2: /* Full Citation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Peter P. Swire, &#039;&#039;A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems&#039;&#039;, Hous. L. Rev., Vol. 42, No. 5, Ohio State Public Law Working Paper No. 4 (2006).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID842228_code515373.pdf?abstractid=842228&amp;amp;mirid=1&#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Swire:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=842228 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;See the article itself for any key words as a starting point&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
The paper presents a 2x3 matrix, where disclosure for  security and  competition are assessed for three types of systems  or software: Open Source; proprietary software; and  government systems. The paper finds greater convergence on disclosure between Open  Source and proprietary  software than most commentators have believed. For instance, Open Source security  experts use secrecy in stealth firewalls and  in other ways. Open Source programmers also often rely on gaps in Open Source licenses to gain competitive advantage by keeping key information secret. Meanwhile, proprietary  software often uses more disclosure than assumed. For security, large purchasers and market forces often lead to disclosure about proprietary software. For competitive reasons, proprietary  software companies often disclose a great deal when seeking to become a standard in an area or for other reasons.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons:_Open_Source,_Proprietary_Software,_and_Government_Systems&amp;diff=463</id>
		<title>A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons:_Open_Source,_Proprietary_Software,_and_Government_Systems&amp;diff=463"/>
		<updated>2010-06-03T19:11:26Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: ==Full Title of Reference==  ==Full Citation==  Peter P. Swire, &amp;#039;&amp;#039;A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems&amp;#039;&amp;#039;, ...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Peter P. Swire, &#039;&#039;A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems&#039;&#039;, Houston Law Review, Vol. 42, No. 5 (2006).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID842228_code515373.pdf?abstractid=842228&amp;amp;mirid=1&#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Swire:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=842228 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;See the article itself for any key words as a starting point&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
The paper presents a 2x3 matrix, where disclosure for  security and  competition are assessed for three types of systems  or software: Open Source; proprietary software; and  government systems. The paper finds greater convergence on disclosure between Open  Source and proprietary  software than most commentators have believed. For instance, Open Source security  experts use secrecy in stealth firewalls and  in other ways. Open Source programmers also often rely on gaps in Open Source licenses to gain competitive advantage by keeping key information secret. Meanwhile, proprietary  software often uses more disclosure than assumed. For security, large purchasers and market forces often lead to disclosure about proprietary software. For competitive reasons, proprietary  software companies often disclose a great deal when seeking to become a standard in an area or for other reasons.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=462</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=462"/>
		<updated>2010-06-03T19:07:10Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis]]&lt;br /&gt;
&lt;br /&gt;
Schwartz, Paul and Janger, Edward (&#039;&#039;2007&#039;&#039;) [[Notification of Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Granick, Jennifer Stisa (&#039;&#039;2005&#039;&#039;) [[The Price of Restricting Vulnerability Publications]]&lt;br /&gt;
&lt;br /&gt;
Romanosky et al. (&#039;&#039;2008&#039;&#039;) [[Do Data Breach Disclosure Laws Reduce Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2005)&#039;&#039; [[An Economic Analysis of Notification Requirements for Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2006)&#039;&#039; [[Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers]]&lt;br /&gt;
&lt;br /&gt;
Swire, Peter P (&#039;&#039;2006&#039;&#039;) [[A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Much_Ado_About_Notification:_Does_the_Rush_to_Pass_State-Level_Data_Security_Regulations_Benefit_Consumers&amp;diff=461</id>
		<title>Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Much_Ado_About_Notification:_Does_the_Rush_to_Pass_State-Level_Data_Security_Regulations_Benefit_Consumers&amp;diff=461"/>
		<updated>2010-06-03T19:06:23Z</updated>

		<summary type="html">&lt;p&gt;Intern2: /* Full Citation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Thomas M. Lenard and Paul H. Rubin, &#039;&#039;Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?&#039;&#039;, Regulation, Vol. 29, No. 1 (2006).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID898208_code614152.pdf?abstractid=898208&amp;amp;mirid=1 &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Lenard_Rubin:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]  [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=898208# &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
Data security breaches&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
Data security breaches have received considerable public attention of late, and have prompted several states to mandate that firms whose data may have been compromised to notify their customers of the security breaches. This study finds that the costs of a notification requirement are likely to be substantially higher than the benefits. Even for consumers whose data have been compromised, the probability of being a victim of fraud is so low - only 2 percent - that little action is justified. Overall, we estimate that the expected benefits of mandatory notification are very small - less than $10 per compromised individual. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=460</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=460"/>
		<updated>2010-06-03T19:05:44Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis]]&lt;br /&gt;
&lt;br /&gt;
Schwartz, Paul and Janger, Edward (&#039;&#039;2007&#039;&#039;) [[Notification of Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Granick, Jennifer Stisa (&#039;&#039;2005&#039;&#039;) [[The Price of Restricting Vulnerability Publications]]&lt;br /&gt;
&lt;br /&gt;
Romanosky et al. (&#039;&#039;2008&#039;&#039;) [[Do Data Breach Disclosure Laws Reduce Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2005)&#039;&#039; [[An Economic Analysis of Notification Requirements for Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2006)&#039;&#039; [[Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?]]&lt;br /&gt;
&lt;br /&gt;
Swire, Peter P (&#039;&#039;2006&#039;&#039;) [[A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=459</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=459"/>
		<updated>2010-06-03T19:05:06Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis]]&lt;br /&gt;
&lt;br /&gt;
Schwartz, Paul and Janger, Edward (&#039;&#039;2007&#039;&#039;) [[Notification of Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Granick, Jennifer Stisa (&#039;&#039;2005&#039;&#039;) [[The Price of Restricting Vulnerability Publications]]&lt;br /&gt;
&lt;br /&gt;
Romanosky et al. (&#039;&#039;2008&#039;&#039;) [[Do Data Breach Disclosure Laws Reduce Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2005)&#039;&#039; [[An Economic Analysis of Notification Requirements for Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2006)&#039;&#039; [[Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?]&lt;br /&gt;
&lt;br /&gt;
Swire, Peter P (&#039;&#039;2006&#039;&#039;) [[A Theory of Disclosure for Security and Competitive Reasons: Open Source, Proprietary Software, and Government Systems]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Much_Ado_About_Notification:_Does_the_Rush_to_Pass_State-Level_Data_Security_Regulations_Benefit_Consumers&amp;diff=458</id>
		<title>Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Much_Ado_About_Notification:_Does_the_Rush_to_Pass_State-Level_Data_Security_Regulations_Benefit_Consumers&amp;diff=458"/>
		<updated>2010-06-03T18:55:16Z</updated>

		<summary type="html">&lt;p&gt;Intern2: /* Full Citation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Thomas M. Lenard and Paul H. Rubin, Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?, Regulation, Vol. 29, No. 1 (2006).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID898208_code614152.pdf?abstractid=898208&amp;amp;mirid=1 &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Lenard_Rubin:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]  [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=898208# &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
Data security breaches&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
Data security breaches have received considerable public attention of late, and have prompted several states to mandate that firms whose data may have been compromised to notify their customers of the security breaches. This study finds that the costs of a notification requirement are likely to be substantially higher than the benefits. Even for consumers whose data have been compromised, the probability of being a victim of fraud is so low - only 2 percent - that little action is justified. Overall, we estimate that the expected benefits of mandatory notification are very small - less than $10 per compromised individual. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Much_Ado_About_Notification:_Does_the_Rush_to_Pass_State-Level_Data_Security_Regulations_Benefit_Consumers&amp;diff=457</id>
		<title>Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Much_Ado_About_Notification:_Does_the_Rush_to_Pass_State-Level_Data_Security_Regulations_Benefit_Consumers&amp;diff=457"/>
		<updated>2010-06-03T18:53:22Z</updated>

		<summary type="html">&lt;p&gt;Intern2: /* Full Citation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Thomas M. Lenard and Paul H. Rubin, Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?, Regulation, Vol. 29, No. 1 (2006).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID898208_code614152.pdf?abstractid=898208&amp;amp;mirid=1 &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Lenard_Rubin:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
Data security breaches&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
Data security breaches have received considerable public attention of late, and have prompted several states to mandate that firms whose data may have been compromised to notify their customers of the security breaches. This study finds that the costs of a notification requirement are likely to be substantially higher than the benefits. Even for consumers whose data have been compromised, the probability of being a victim of fraud is so low - only 2 percent - that little action is justified. Overall, we estimate that the expected benefits of mandatory notification are very small - less than $10 per compromised individual. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Much_Ado_About_Notification:_Does_the_Rush_to_Pass_State-Level_Data_Security_Regulations_Benefit_Consumers&amp;diff=456</id>
		<title>Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Much_Ado_About_Notification:_Does_the_Rush_to_Pass_State-Level_Data_Security_Regulations_Benefit_Consumers&amp;diff=456"/>
		<updated>2010-06-03T18:53:04Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: ==Full Title of Reference==  Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?  ==Full Citation==  Thomas M. Lenard and Paul H. Ru...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Thomas M. Lenard and Paul H. Rubin, Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?, Regulation, Vol. 29, No. 1 (2006).  [http://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID898208_code614152.pdf?abstractid=898208&amp;amp;mirid=1 &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Lenard_Rubin:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
Data security breaches&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
Data security breaches have received considerable public attention of late, and have prompted several states to mandate that firms whose data may have been compromised to notify their customers of the security breaches. This study finds that the costs of a notification requirement are likely to be substantially higher than the benefits. Even for consumers whose data have been compromised, the probability of being a victim of fraud is so low - only 2 percent - that little action is justified. Overall, we estimate that the expected benefits of mandatory notification are very small - less than $10 per compromised individual. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=455</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=455"/>
		<updated>2010-06-03T18:39:38Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis]]&lt;br /&gt;
&lt;br /&gt;
Schwartz, Paul and Janger, Edward (&#039;&#039;2007&#039;&#039;) [[Notification of Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Granick, Jennifer Stisa (&#039;&#039;2005&#039;&#039;) [[The Price of Restricting Vulnerability Publications]]&lt;br /&gt;
&lt;br /&gt;
Romanosky et al. (&#039;&#039;2008&#039;&#039;) [[Do Data Breach Disclosure Laws Reduce Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2005)&#039;&#039; [[An Economic Analysis of Notification Requirements for Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2006)&#039;&#039; [[Much Ado About Notification: Does the Rush to Pass State-Level Data Security Regulations Benefit Consumers?]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches&amp;diff=448</id>
		<title>An Economic Analysis of Notification Requirements for Data Security Breaches</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches&amp;diff=448"/>
		<updated>2010-06-03T16:30:07Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
An Economic Analysis of Notification Requirements for Data Security Breaches&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Thomas M. Lenard and Paul H. Rubin, &#039;&#039;An Economic Analysis of Notification Requirements for Data Security Breaches&#039;&#039;, Progress on Point (July 2005), The Progress &amp;amp; Freedom Foundation. [http://www.pff.org/issues-pubs/pops/pop12.12datasecurity.pdf &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Lenard_Rubin:2005&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information Sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;See the article itself for any key words as a starting point&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;This could be an abstract from the article.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches&amp;diff=447</id>
		<title>An Economic Analysis of Notification Requirements for Data Security Breaches</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches&amp;diff=447"/>
		<updated>2010-06-03T16:29:33Z</updated>

		<summary type="html">&lt;p&gt;Intern2: /* Full Citation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
An Economic Analysis of Notification Requirements for Data Security Breaches&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Thomas M. Lenard and Paul H. Rubin, &#039;&#039;An Economic Analysis of Notification Requirements for Data Security Breaches&#039;&#039;, Progress on Point (July 2005), The Progress &amp;amp; Freedom Foundation. [http://www.pff.org/issues-pubs/pops/pop12.12datasecurity.pdf &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Lenard_Rubin:2005&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;See the article itself for any key words as a starting point&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;This could be an abstract from the article.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches&amp;diff=446</id>
		<title>An Economic Analysis of Notification Requirements for Data Security Breaches</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches&amp;diff=446"/>
		<updated>2010-06-03T16:29:03Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: ==Full Title of Reference== An Economic Analysis of Notification Requirements for Data Security Breaches  ==Full Citation==  Thomas M. Lenard and Paul H. Rubin, &amp;#039;&amp;#039;An Economic Analysis of N...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
An Economic Analysis of Notification Requirements for Data Security Breaches&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Thomas M. Lenard and Paul H. Rubin, &#039;&#039;An Economic Analysis of Notification Requirements for Data Security Breaches&#039;&#039;, Progress on Point (July 2005), The Progress &amp;amp; Freedom Foundation. [www.pff.org/issues-pubs/pops/pop12.12datasecurity.pdf &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;view=&amp;amp;startkey=Lenard_Rubin:2005&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Information sharing/Disclosure]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;See the article itself for any key words as a starting point&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;This could be an abstract from the article.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039; * Outline key points of interest&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods&amp;diff=445</id>
		<title>An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods&amp;diff=445"/>
		<updated>2010-06-03T16:26:33Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&#039;&#039;An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Bruce H. Kobayashi (2006), &#039;&#039;An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods.&#039;&#039; Supreme Court Economic Review, Vol. 14. [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=708562  &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Kobayashi:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Economics of Cybersecurity]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
Cybersecurity, public goods, private goods&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
This paper examines the incentives of private actors to invest in cybersecurity. Prior analyses have examined investments in security goods, such as locks or safes that have the characteristics of private goods. The analysis in this paper extends this analysis to examine expenditures on security goods, such as information, that have the characteristics of public goods. In contrast to the private goods case, where individual uncoordinated security expenditures can lead to an overproduction of security, the public goods case can result in the underproduction of security expenditures, and incentives to free ride. Thus, the formation of collective organizations may be necessary to facilitate the production of public security goods, and the protection of information produced by the collective organization should be a central feature of such organizations. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods&amp;diff=444</id>
		<title>An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods&amp;diff=444"/>
		<updated>2010-06-03T16:26:02Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: ==Full Title of Reference== An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods  ==Full Citation==  Bruce H. Kobayashi (2...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Bruce H. Kobayashi (2006), &#039;&#039;An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods.&#039;&#039; Supreme Court Economic Review, Vol. 14. [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=708562  &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Kobayashi:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Economics of Cybersecurity]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
Cybersecurity, public goods, private goods&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
This paper examines the incentives of private actors to invest in cybersecurity. Prior analyses have examined investments in security goods, such as locks or safes that have the characteristics of private goods. The analysis in this paper extends this analysis to examine expenditures on security goods, such as information, that have the characteristics of public goods. In contrast to the private goods case, where individual uncoordinated security expenditures can lead to an overproduction of security, the public goods case can result in the underproduction of security expenditures, and incentives to free ride. Thus, the formation of collective organizations may be necessary to facilitate the production of public security goods, and the protection of information produced by the collective organization should be a central feature of such organizations. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Economics_of_Cybersecurity&amp;diff=443</id>
		<title>Economics of Cybersecurity</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Economics_of_Cybersecurity&amp;diff=443"/>
		<updated>2010-06-03T16:22:27Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Anderson, Ross &#039;&#039;(2001)&#039;&#039; [[Why Information Security is Hard]]&lt;br /&gt;
&lt;br /&gt;
Anderson, Ross, et. al &#039;&#039;(2008)&#039;&#039; [[Security Economics and the Internal Market]]&lt;br /&gt;
&lt;br /&gt;
Anderson, Ross and Moore, Tyler &#039;&#039;(2006)&#039;&#039;  [[The Economics of Information Security]]&lt;br /&gt;
&lt;br /&gt;
Camp, L. Jean and Wolfram, Catherine  &#039;&#039;(2004)&#039;&#039; [[Pricing Security]]&lt;br /&gt;
&lt;br /&gt;
Computer Economics, Inc. &#039;&#039;(2007)&#039;&#039; [[2007 Malware Report]] &lt;br /&gt;
&lt;br /&gt;
Franklin, Jason, et. al &#039;&#039;(2007&#039;&#039;) [[An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants]]&lt;br /&gt;
&lt;br /&gt;
Kobayashi, Bruce H. &#039;&#039;(2006)&#039;&#039; [[An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods]]&lt;br /&gt;
&lt;br /&gt;
Moore, Tyler, et. al &#039;&#039;(2009)&#039;&#039; [[The Economics of Online Crime]]&lt;br /&gt;
&lt;br /&gt;
Powell, Benjamin  &#039;&#039;(2005)&#039;&#039;  [[Is Cybersecurity a Public Good]]&lt;br /&gt;
&lt;br /&gt;
Thomas, Rob and Martin, Jerry (2006) [[The Underground Economy]]&lt;br /&gt;
&lt;br /&gt;
van Eeten, Michel J. G.  and  Bauer, Johannes M. &#039;&#039;(2008)&#039;&#039; [[Economics of Malware: Security Decisions, Incentives and Externalities]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Models_and_Measures_for_Correlation_in_Cyber-Insurance&amp;diff=436</id>
		<title>Models and Measures for Correlation in Cyber-Insurance</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Models_and_Measures_for_Correlation_in_Cyber-Insurance&amp;diff=436"/>
		<updated>2010-06-03T16:12:40Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: ==Full Title of Reference== Models and Measures for Correlation in Cyber-Insurance  ==Full Citation==  Rainer Bohme, &amp;#039;&amp;#039;Models and Measures for Correlation in Cyber-Insurance&amp;#039;&amp;#039;, Workshop on...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
Models and Measures for Correlation in Cyber-Insurance&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Rainer Bohme, &#039;&#039;Models and Measures for Correlation in Cyber-Insurance&#039;&#039;, Workshop on the Economics of Information Security (2006).  [http://weis2006.econinfosec.org/docs/16.pdf  &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Bohme_Kataria:2006&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Insurance]] [[Economics of Cyber Security]]&lt;br /&gt;
&lt;br /&gt;
==Key Words==&lt;br /&gt;
Insurance&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
High correlation in failure of information systems due to worms and viruses has been cited as major impediment to cyber-insurance. However, of the many cyber-risk classes that inﬂuence failure of information systems, not all exhibit similar correlation properties. In this paper, we introduce a new classiﬁcation of correlation properties of cyber-risks based on a twin-tier approach. At the ﬁrst tier, is the correlation of cyber-risks within a ﬁrm i.e. correlated failure of multiple systems on its internal network. At second tier, is the correlation in risk at a global level i.e. correlation across independent ﬁrms in an insurer’s portfolio. Various classes of cyber-risks exhibit diﬀerent level of correlation at two tiers, for instance, insider attacks &lt;br /&gt;
exhibit high internal but low global correlation. While internal risk correlation within a ﬁrm inﬂuences its decision to seek insurance, the global correlation inﬂuences insurers’ decision in setting the premium. Citing real data we study the combined dynamics of the two-step risk arrival process to determine conditions conducive to the existence of cyber-insurance market. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Insurance&amp;diff=433</id>
		<title>Insurance</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Insurance&amp;diff=433"/>
		<updated>2010-06-03T16:08:12Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Clinton, Larry &#039;&#039;(Undated)&#039;&#039; [[Cyber-Insurance Metrics and Impact on Cyber-Security]]&lt;br /&gt;
&lt;br /&gt;
Bohme, Rainer &#039;&#039;(2005)&#039;&#039; [[Cyber-Insurance Revisited]]&lt;br /&gt;
&lt;br /&gt;
Bohme, Rainer and Kataria, Gaurav &#039;&#039;(2006)&#039;&#039; [[Models and Measures for Correlation in Cyber-Insurance]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=432</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=432"/>
		<updated>2010-06-03T16:05:21Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis]]&lt;br /&gt;
&lt;br /&gt;
Schwartz, Paul and Janger, Edward (&#039;&#039;2007&#039;&#039;) [[Notification of Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Granick, Jennifer Stisa (&#039;&#039;2005&#039;&#039;) [[The Price of Restricting Vulnerability Publications]]&lt;br /&gt;
&lt;br /&gt;
Romanosky et al. (&#039;&#039;2008&#039;&#039;) [[Do Data Breach Disclosure Laws Reduce Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
Lernard, Thomas M. and Rubin, Paul H. &#039;&#039;(2005)&#039;&#039; [[An Economic Analysis of Notification Requirements for Data Security Breaches]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft&amp;diff=431</id>
		<title>Do Data Breach Disclosure Laws Reduce Identity Theft</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft&amp;diff=431"/>
		<updated>2010-06-03T15:47:57Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Do Data Breach Disclosure Laws Reduce Identity Theft?==&lt;br /&gt;
&lt;br /&gt;
Sasha Romanosky, Rahul Telang, Alessandro Acquisti, &#039;&#039;Do Data Breach Disclosure Laws Reduce Identity Theft&#039;&#039; (2007).  [http://weis2008.econinfosec.org/papers/Romanosky.pdf &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Romanosky_et_al:2008&amp;amp;f=wikibiblio.bib&#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Data Breach]]; [[Disclosure Laws]]; [[Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[[information security]], [[disclosure laws]], [[disclosure policy]], [[identity theft]], [[security breach notification]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
Identity theft resulted in corporate and consumer losses of $56 billion dollars in 2005, with about 30% of known identity thefts caused by corporate data breaches. Many US states have responded by adopting data breach disclosure laws that require firms to notify consumers if their personal information has been lost or stolen. While the laws are expected to reduce identity theft, their full effects have yet to be empirically measured. We use panel from the US Federal Trade Commission with state and time fixed effects regression to estimate the impact of data breach disclosure laws on identity theft from 2002 to 2007. We find that adoption of data breach disclosure laws have a marginal effect on the incidences of identity thefts and reduce the rate by just under 2%, on average. While this effect is marginal, reducing identity theft is only one means by which these laws can be evaluated: we appreciate that they may have other benefits such as reducing the average victim&#039;s losses or improving a firm&#039;s security and operational practices. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
[http://www.networkworld.com/newsletters/sec/2008/072808sec1.html/ Paper review from networkworld.com: &amp;quot;Do data-breach-disclosure laws reduce identity theft? Research attempts to answer the question&amp;quot;]&lt;br /&gt;
&lt;br /&gt;
[http://www.consumeraffairs.com/news04/2008/06/data_breaches.html/ Paper review from consumeraffairs.com: &amp;quot;Data Breach Disclosure Laws Don&#039;t Slow Down Identity Theft; Results of recent legislation called &#039;statistically insignificant&#039;&amp;quot;]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft&amp;diff=430</id>
		<title>Do Data Breach Disclosure Laws Reduce Identity Theft</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft&amp;diff=430"/>
		<updated>2010-06-03T15:47:14Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: ==Do Data Breach Disclosure Laws Reduce Identity Theft?==  Sasha Romanosky, Rahul Telang, Alessandro Acquisti, &amp;#039;&amp;#039;Do Data Breach Disclosure Laws Reduce Identity Theft&amp;#039;&amp;#039; (2007).  [http://wei...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Do Data Breach Disclosure Laws Reduce Identity Theft?==&lt;br /&gt;
&lt;br /&gt;
Sasha Romanosky, Rahul Telang, Alessandro Acquisti, &#039;&#039;Do Data Breach Disclosure Laws Reduce Identity Theft&#039;&#039; (2007).  [http://weis2008.econinfosec.org/papers/Romanosky.pdf &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Romanosky_et_al:2008&amp;amp;f=wikibiblio.bib&#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Data Breach]]; [[Disclosure Laws]]; [[Identity Theft]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[[information security]], [[disclosure laws]], [[disclosure policy]], [[identity theft]], [[security breach notification]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
Identity theft resulted in corporate and consumer losses of $56 billion dollars in 2005, with about 30% of known identity thefts caused by corporate data breaches. Many US states have responded by adopting data breach disclosure laws that require firms to notify consumers if their personal information has been lost or stolen. While the laws are expected to reduce identity theft, their full effects have yet to be empirically measured. We use panel from the US Federal Trade Commission with state and time fixed effects regression to estimate the impact of data breach disclosure laws on identity theft from 2002 to 2007. We find that adoption of data breach disclosure laws have a marginal effect on the incidences of identity thefts and reduce the rate by just under 2%, on average. While this effect is marginal, reducing identity theft is only one means by which these laws can be evaluated: we appreciate that they may have other benefits such as reducing the average victim&#039;s losses or improving a firm&#039;s security and operational practices. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
[http://www.networkworld.com/newsletters/sec/2008/072808sec1.html/ from networkworld: &amp;quot;Do data-breach-disclosure laws reduce identity theft? Research attempts to answer the question&amp;quot;]&lt;br /&gt;
&lt;br /&gt;
[http://www.consumeraffairs.com/news04/2008/06/data_breaches.html/ from consumeraffairs &amp;quot;Data Breach Disclosure Laws Don&#039;t Slow Down Identity Theft; Results of recent legislation called &#039;statistically insignificant&#039;&amp;quot;]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=429</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=429"/>
		<updated>2010-06-03T15:33:34Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis]]&lt;br /&gt;
&lt;br /&gt;
Schwartz, Paul and Janger, Edward (&#039;&#039;2007&#039;&#039;) [[Notification of Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Granick, Jennifer Stisa (&#039;&#039;2005&#039;&#039;) [[The Price of Restricting Vulnerability Publications]]&lt;br /&gt;
&lt;br /&gt;
Romanosky et al. (&#039;&#039;2008&#039;&#039;) [[Do Data Breach Disclosure Laws Reduce Identity Theft]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=The_Price_of_Restricting_Vulnerability_Publications&amp;diff=428</id>
		<title>The Price of Restricting Vulnerability Publications</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=The_Price_of_Restricting_Vulnerability_Publications&amp;diff=428"/>
		<updated>2010-06-03T15:25:30Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Price of Restricting Vulnerability Publications==&lt;br /&gt;
&lt;br /&gt;
Jennifer Stisa Granick, &#039;&#039;The Price of Restricting Vulnerability Publications&#039;&#039; (2007).  [http://www.ijclp.net/files/ijclp_web-doc_10-cy-2004.pdf  &#039;&#039;Web&#039;&#039;] &lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Granick:2005&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Disclosure]]; [[Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[[information security]], [[vulnerability disclosure]], [[disclosure policy]], [[exploit]], [[code as speech]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
There are calls from some quarters to restrict the publication of information about security vulnerabilities in an effort to limit the number of people with the knowledge and ability to attack computer systems. Scientists in other fields have considered similar proposals and rejected them, or adopted only narrow, voluntary restrictions. As in other fields of science, there is a real danger that publication restrictions will inhibit the advancement of the state of the art in computer security. Proponents of disclosure restrictions argue that computer security information is different from other scientific research because it is often expressed in the form of functioning software code. Code has a dual nature, as both speech and tool. While researchers readily understand the information expressed in code, code enables many more people to do harm more readily than with the non-functional information typical of most research publications. Yet, there are strong reasons to reject the argument that code is different, and that restrictions are therefore good policy. Code&#039;s functionality may help security as much as it hurts it and the open distribution of functional code has valuable effects for consumers, including the ability to pressure vendors for more secure products and to counteract monopolistic practices. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=The_Price_of_Restricting_Vulnerability_Publications&amp;diff=427</id>
		<title>The Price of Restricting Vulnerability Publications</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=The_Price_of_Restricting_Vulnerability_Publications&amp;diff=427"/>
		<updated>2010-06-03T15:25:14Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: ==The Price of Restricting Vulnerability Publications==  Jennifer Stisa Granick, &amp;#039;&amp;#039;The Price of Restricting Vulnerability Publications&amp;#039;&amp;#039; (2007).  [http://www.ijclp.net/files/ijclp_web-doc_...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Price of Restricting Vulnerability Publications==&lt;br /&gt;
&lt;br /&gt;
Jennifer Stisa Granick, &#039;&#039;The Price of Restricting Vulnerability Publications&#039;&#039; (2007).  [http://www.ijclp.net/files/ijclp_web-doc_10-cy-2004.pdf  &#039;&#039;Web&#039;&#039;] &lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Granick:2005&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Disclosure]]; [[Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[[information security]], [[vulnerability disclosure]], [[disclosure policy]], [[exploit]], [[code as speech]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
There are calls from some quarters to restrict the publication of information about security vulnerabilities in an effort to limit the number of people with the knowledge and ability to attack computer systems. Scientists in other fields have considered similar proposals and rejected them, or adopted only narrow, voluntary restrictions. As in other fields of science, there is a real danger that publication restrictions will inhibit the advancement of the state of the art in computer security. Proponents of disclosure restrictions argue that computer security information is different from other scientific research because it is often expressed in the form of functioning software code. Code has a dual nature, as both speech and tool. While researchers readily understand the information expressed in code, code enables many more people to do harm more readily than with the non-functional information typical of most research publications. Yet, there are strong reasons to reject the argument that code is different, and that restrictions are therefore good policy. Code&#039;s functionality may help security as much as it hurts it and the open distribution of functional code has valuable effects for consumers, including the ability to pressure vendors for more secure products and to counteract monopolistic practices. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=426</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=426"/>
		<updated>2010-06-03T15:19:28Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis]]&lt;br /&gt;
&lt;br /&gt;
Schwartz, Paul and Janger, Edward (&#039;&#039;2007&#039;&#039;) [[Notification of Data Security Breaches]]&lt;br /&gt;
&lt;br /&gt;
Granick, Jennifer Stisa (&#039;&#039;2005&#039;&#039;) [[The Price of Restricting Vulnerability Publications]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Notification_of_Data_Security_Breaches&amp;diff=425</id>
		<title>Notification of Data Security Breaches</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Notification_of_Data_Security_Breaches&amp;diff=425"/>
		<updated>2010-06-03T15:10:30Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Notification of Data Security Breaches==&lt;br /&gt;
&lt;br /&gt;
Paul Schwartz and Edward Janger, &#039;&#039;Notification of Data Security Breaches&#039;&#039; (2007).  [http://www.michiganlawreview.org/assets/pdfs/105/5/schwartz.pdf &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Schwartz_Janger:2007&amp;amp;keyword=schwartz&amp;amp;f=wikibiblio.bib&#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Disclosure]]; [[Data Security]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[[information security]], [[disclosure policy]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
The law increasingly requires private companies to disclose information for the benefit of consumers. The latest examples of such regulation are state and federal laws that require companies to notify individuals of data security incidents involving their personal information. These laws, proposed in the wake of highly publicized data spills, seek to punish the breached entity and to protect consumers by requiring the entity to notify its customers about the security breach. There are competing approaches, however, to how the law is to mandate release of information about data leaks. This Article finds that the current statutes’ focus on reputational sanction is incomplete. An important function of breach notification is mitigation of harm after a data leak. This function requires a multi-institutional coordinated response of the kind that is absent from current policy proposals. This Article advocates creation of a coordinated response architecture and develops the elements of such an approach. Central to this architecture is a coordinated response agent (CRA) that oversees steps for automatic consumer protection and heightens mitigation. This Article also proposes a bifurcated notice scheme that lets firms know that the CRA is watching and is scrutinizing their decision whether or not to disclose information about a breach to the affected individuals. Moreover, the CRA will set in motion automatic protective measures on behalf of the breached consumers. Finally, the CRA will regulate the content of notification messages to reflect the nature of the data breach. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Notification_of_Data_Security_Breaches&amp;diff=424</id>
		<title>Notification of Data Security Breaches</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Notification_of_Data_Security_Breaches&amp;diff=424"/>
		<updated>2010-06-03T15:10:12Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Notification of Data Security Breaches==&lt;br /&gt;
&lt;br /&gt;
Paul Schwartz and Edward Janger &#039;&#039;Notification of Data Security Breaches&#039;&#039; (2007).  [http://www.michiganlawreview.org/assets/pdfs/105/5/schwartz.pdf &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Schwartz_Janger:2007&amp;amp;keyword=schwartz&amp;amp;f=wikibiblio.bib&#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Disclosure]]; [[Data Security]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[[information security]], [[disclosure policy]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
The law increasingly requires private companies to disclose information for the benefit of consumers. The latest examples of such regulation are state and federal laws that require companies to notify individuals of data security incidents involving their personal information. These laws, proposed in the wake of highly publicized data spills, seek to punish the breached entity and to protect consumers by requiring the entity to notify its customers about the security breach. There are competing approaches, however, to how the law is to mandate release of information about data leaks. This Article finds that the current statutes’ focus on reputational sanction is incomplete. An important function of breach notification is mitigation of harm after a data leak. This function requires a multi-institutional coordinated response of the kind that is absent from current policy proposals. This Article advocates creation of a coordinated response architecture and develops the elements of such an approach. Central to this architecture is a coordinated response agent (CRA) that oversees steps for automatic consumer protection and heightens mitigation. This Article also proposes a bifurcated notice scheme that lets firms know that the CRA is watching and is scrutinizing their decision whether or not to disclose information about a breach to the affected individuals. Moreover, the CRA will set in motion automatic protective measures on behalf of the breached consumers. Finally, the CRA will regulate the content of notification messages to reflect the nature of the data breach. &lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Notification_of_Data_Security_Breaches&amp;diff=423</id>
		<title>Notification of Data Security Breaches</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Notification_of_Data_Security_Breaches&amp;diff=423"/>
		<updated>2010-06-03T15:06:34Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Schwartz_Janger:2007&amp;amp;keyword=schwartz&amp;amp;f=wikibiblio.bib&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Schwartz_Janger:2007&amp;amp;keyword=schwartz&amp;amp;f=wikibiblio.bib&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=422</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=422"/>
		<updated>2010-06-03T15:06:18Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis]]&lt;br /&gt;
&lt;br /&gt;
Schwartz, Paul and Janger, Edward (&#039;&#039;2007&#039;&#039;) [[Notification of Data Security Breaches]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure_-_An_Empirical_Analysis&amp;diff=421</id>
		<title>Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure_-_An_Empirical_Analysis&amp;diff=421"/>
		<updated>2010-06-03T14:41:04Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: ==Does Information Security Attack Frequency Increase With Vulnerability Disclosure? - An Empirical Analysis==  Ashish Arora, Anand Nandkumar, Rahul Telang, &amp;#039;&amp;#039;Does Information Security Att...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Does Information Security Attack Frequency Increase With Vulnerability Disclosure? - An Empirical Analysis==&lt;br /&gt;
&lt;br /&gt;
Ashish Arora, Anand Nandkumar, Rahul Telang, &#039;&#039;Does Information Security Attack Frequency Increase With Vulnerability Disclosure?&#039;&#039; (2007).  [http://www.heinz.cmu.edu/~rtelang/vuln_freq_ISF.pdf &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Arora_Nandkumar_Telang:2006&amp;amp;f=wikibiblio.bib&#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Disclosure]]; [[Information Sharing]]; [[Information Security]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[[information security]], [[software vulnerability]], [[disclosure policy]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
Research in information security, risk management and investment has grown in importance over the last few years. However, without reliable estimates on attack probabilities, risk management is difficult to do in practice. Using a novel data set, we provide estimates on attack propensity and how it changes with disclosure and patching of vulnerabilities. Disclosure of software vulnerability has been controversial. On one hand are those who propose full and instant disclosure whether the patch is available or not and on the other hand are those who argue for limited or no disclosure. Which of the two policies is socially optimal depends critically on how attack frequency changes with disclosure and patching. In this paper, we empirically explore the impact of vulnerability information disclosure and availability of patches on attacks targeting the vulnerability. Our results suggest that on an average both secret (non-published) and published (published and not patched) vulnerabilities attract fewer attacks than patched (published and patched) vulnerabilities. When we control for time since publication and patches, we find that patching an already known vulnerability decreases the number of attacks, although attacks gradually increase with time after patch release. Patching an unknown vulnerability, however, causes a spike in attacks, which then gradually decline after patch release. Attacks on secret vulnerabilities slowly increase with time until the vulnerability is published and then attacks rapidly decrease with time after publication.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=420</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=420"/>
		<updated>2010-06-03T14:40:53Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure - An Empirical Analysis]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=419</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=419"/>
		<updated>2010-06-03T14:40:19Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure. An Empirical Analysis]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure&amp;diff=418</id>
		<title>Does Information Security Attack Frequency Increase With Vulnerability Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure&amp;diff=418"/>
		<updated>2010-06-03T14:36:34Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Does Information Security Attack Frequency Increase With Vulnerability Disclosure? - An Empirical Analysis==&lt;br /&gt;
&lt;br /&gt;
Ashish Arora, Anand Nandkumar, Rahul Telang, &#039;&#039;Does Information Security Attack Frequency Increase With Vulnerability Disclosure?&#039;&#039; (2007).  [http://www.heinz.cmu.edu/~rtelang/vuln_freq_ISF.pdf &#039;&#039;Web&#039;&#039;] [http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Arora_Nandkumar_Telang:2006&amp;amp;f=wikibiblio.bib&#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Disclosure]]; [[Information Sharing]]; [[Information Security]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[[information security]], [[software vulnerability]], [[disclosure policy]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
Research in information security, risk management and investment has grown in importance over the last few years. However, without reliable estimates on attack probabilities, risk management is difficult to do in practice. Using a novel data set, we provide estimates on attack propensity and how it changes with disclosure and patching of vulnerabilities. Disclosure of software vulnerability has been controversial. On one hand are those who propose full and instant disclosure whether the patch is available or not and on the other hand are those who argue for limited or no disclosure. Which of the two policies is socially optimal depends critically on how attack frequency changes with disclosure and patching. In this paper, we empirically explore the impact of vulnerability information disclosure and availability of patches on attacks targeting the vulnerability. Our results suggest that on an average both secret (non-published) and published (published and not patched) vulnerabilities attract fewer attacks than patched (published and patched) vulnerabilities. When we control for time since publication and patches, we find that patching an already known vulnerability decreases the number of attacks, although attacks gradually increase with time after patch release. Patching an unknown vulnerability, however, causes a spike in attacks, which then gradually decline after patch release. Attacks on secret vulnerabilities slowly increase with time until the vulnerability is published and then attacks rapidly decrease with time after publication.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure&amp;diff=417</id>
		<title>Does Information Security Attack Frequency Increase With Vulnerability Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure&amp;diff=417"/>
		<updated>2010-06-03T14:32:20Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Arora_Nandkumar_Telang:2006&amp;amp;f=wikibiblio.bib&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Arora_Nandkumar_Telang:2006&amp;amp;f=wikibiblio.bib&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=416</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=416"/>
		<updated>2010-06-03T14:31:31Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;br /&gt;
&lt;br /&gt;
Arora et al. (&#039;&#039;2006&#039;&#039;) [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure? An Empirical Analysis]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors_-_An_Empirical_Investigation&amp;diff=410</id>
		<title>Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors_-_An_Empirical_Investigation&amp;diff=410"/>
		<updated>2010-06-03T14:13:41Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Rahul Telang, Sunil Wattal, &#039;&#039;Impact of Software Vulnerability Announcements on the Market Value of Software Vendors&#039;&#039; (2007).  [http://infosecon.net/workshop/pdf/telang_wattal.pdf  &#039;&#039;Web&#039;&#039;] &lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Telang_Wattal:2007&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Disclosure]]; [[Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[[information security]], [[software vulnerability]], [[quality]], [[disclosure policy]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
Researchers in the area of information security have mainly been concerned with tools, techniques and policies that firms can use to protect themselves against security breaches. However, information security is as much about security software as it is about secure software. Software is not secure when it has defects or flaws which can be exploited by hackers to cause attacks such as unauthorized intrusion or denial of service attacks. Any public announcement about a software defect is termed as ‘vulnerability disclosure’. In this paper, we use the event study methodology to examine the role that financial markets play in determining the impact of vulnerability disclosures on software vendors. We collect data from leading national newspapers and industry sources by searching for reports on published software vulnerabilities. Our main result is that vulnerability disclosures do lead to a negative and significant change in market value for a software vendor. On average, a vendor loses around 0.6 % value in stock price when a vulnerability is reported. This is equivalent to a loss in market capitalization values of $0.86 billion per vulnerability announcement. To provide further insight, we use the information content of the disclosure announcement to classify vulnerabilities into various types. This is the first study to measure vendors ’ incentive to develop secure software and also provides many interesting implications for software vendors as well as policy makers.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors_-_An_Empirical_Investigation&amp;diff=409</id>
		<title>Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors_-_An_Empirical_Investigation&amp;diff=409"/>
		<updated>2010-06-03T14:12:35Z</updated>

		<summary type="html">&lt;p&gt;Intern2: New page: ==Impact of Software Vulnerability Announcements on the Market Value of Software Vendors==  ==Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Em...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Impact of Software Vulnerability Announcements on the Market Value of Software Vendors==&lt;br /&gt;
&lt;br /&gt;
==Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Rahul Telang, Sunil Wattal, &#039;&#039;Impact of Software Vulnerability Announcements on the Market Value of Software Vendors&#039;&#039; (2007).  [http://infosecon.net/workshop/pdf/telang_wattal.pdf  &#039;&#039;Web&#039;&#039;] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=Telang_Wattal:2007&amp;amp;f=wikibiblio.bib &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Issues: [[Disclosure]]; [[Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[[information security]], [[software vulnerability]], [[quality]], [[disclosure policy]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
Researchers in the area of information security have mainly been concerned with tools, techniques and policies that firms can use to protect themselves against security breaches. However, information security is as much about security software as it is about secure software. Software is not secure when it has defects or flaws which can be exploited by hackers to cause attacks such as unauthorized intrusion or denial of service attacks. Any public announcement about a software defect is termed as ‘vulnerability disclosure’. In this paper, we use the event study methodology to examine the role that financial markets play in determining the impact of vulnerability disclosures on software vendors. We collect data from leading national newspapers and industry sources by searching for reports on published software vulnerabilities. Our main result is that vulnerability disclosures do lead to a negative and significant change in market value for a software vendor. On average, a vendor loses around 0.6 % value in stock price when a vulnerability is reported. This is equivalent to a loss in market capitalization values of $0.86 billion per vulnerability announcement. To provide further insight, we use the information content of the disclosure announcement to classify vulnerabilities into various types. This is the first study to measure vendors ’ incentive to develop secure software and also provides many interesting implications for software vendors as well as policy makers.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=408</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=408"/>
		<updated>2010-06-03T14:06:39Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=407</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=407"/>
		<updated>2010-06-03T14:06:33Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]];&lt;br /&gt;
&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=406</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=406"/>
		<updated>2010-06-03T14:06:23Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]],&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=405</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=405"/>
		<updated>2010-06-03T14:06:14Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;br /&gt;
Telang, Rahul and Wattal, Sunil (&#039;&#039;2007&#039;&#039;) [[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=404</id>
		<title>Information Sharing/Disclosure</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Sharing/Disclosure&amp;diff=404"/>
		<updated>2010-06-03T14:05:04Z</updated>

		<summary type="html">&lt;p&gt;Intern2: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Aviram, Amitai and Tor, Avishalom (&#039;&#039;2003&#039;&#039;) [[Overcoming Impediments to Information Sharing]]&lt;/div&gt;</summary>
		<author><name>Intern2</name></author>
	</entry>
</feed>