메뉴 건너뛰기




Volumn 33, Issue 8, 2007, Pages 544-557

An empirical analysis of the impact of software vulnerability announcements on firm stock price

Author keywords

Event study; Information security; Patching; Quality; Software vendors; Software vulnerability

Indexed keywords

EMPIRICAL ANALYSIS; SOFTWARE VENDORS; SOFTWARE VULNERABILITY;

EID: 34547100991     PISSN: 00985589     EISSN: None     Source Type: Journal    
DOI: 10.1109/TSE.2007.70712     Document Type: Article
Times cited : (210)

References (48)
  • 1
    • 34547125270 scopus 로고    scopus 로고
    • Whose Bug Is It Anyway? The Battle over Handling Software Flaws
    • Mar.-Apr
    • A. Applewhite, "Whose Bug Is It Anyway? The Battle over Handling Software Flaws," IEEE Software, vol. 21, no. 2, pp. 94-97, Mar.-Apr. 2004.
    • (2004) IEEE Software , vol.21 , Issue.2 , pp. 94-97
    • Applewhite, A.1
  • 3
    • 33644916146 scopus 로고    scopus 로고
    • Sell First, Fix Later: Impact of Patching on Software Quality
    • research note, Management Science
    • A. Arora, J. Caulkins, and R. Telang, "Sell First, Fix Later: Impact of Patching on Software Quality," research note, Management Science, vol. 52, no. 3, pp. 465-471, 2006.
    • (2006) , vol.52 , Issue.3 , pp. 465-471
    • Arora, A.1    Caulkins, J.2    Telang, R.3
  • 5
    • 71549173177 scopus 로고
    • Toward an Assessment of Software Development Risk
    • H. Barki, H. Rivard, S.J. Talbot, "Toward an Assessment of Software Development Risk," J. Management Information Systems, vol. 10, no. 2, pp. 203-225, 1993.
    • (1993) J. Management Information Systems , vol.10 , Issue.2 , pp. 203-225
    • Barki, H.1    Rivard, H.2    Talbot, S.J.3
  • 6
    • 0002930385 scopus 로고
    • The Future Engineering of Software: A Management Perspective
    • Apr
    • V.R. Basiliand and J.D. Musa, "The Future Engineering of Software: A Management Perspective," Computer, vol. 20, no. 4, pp. 90-96, Apr. 1991.
    • (1991) Computer , vol.20 , Issue.4 , pp. 90-96
    • Basiliand, V.R.1    Musa, J.D.2
  • 7
    • 84989099586 scopus 로고
    • Measuring Security Price Performance
    • S.J. Brown and J.B. Warner, "Measuring Security Price Performance," J. Financial Economics, vol. 8, pp. 205-258, 1980.
    • (1980) J. Financial Economics , vol.8 , pp. 205-258
    • Brown, S.J.1    Warner, J.B.2
  • 8
    • 36749092418 scopus 로고
    • Using Daily Stock Returns: The Case of Event Studies
    • S.J. Brown and J.B. Warner, "Using Daily Stock Returns: The Case of Event Studies," J. Financial Economics, vol 14, pp. 3-31, 1985.
    • (1985) J. Financial Economics , vol.14 , pp. 3-31
    • Brown, S.J.1    Warner, J.B.2
  • 9
    • 0006298293 scopus 로고    scopus 로고
    • E. Brynjolfsson and C.F. Kemerer, Network Externalities in Microcomputer Software: An Econometric Analysis of the Spreadsheet Market, Management Science, 42, no. 12, pp. 1627-1647, 1996
    • E. Brynjolfsson and C.F. Kemerer, "Network Externalities in Microcomputer Software: An Econometric Analysis of the Spreadsheet Market," Management Science, vol. 42, no. 12, pp. 1627-1647, 1996.
  • 11
    • 0037599474 scopus 로고    scopus 로고
    • The Economic Cost of Publicly Announced Information Security Breaches: Empirical Evidence from the Stock Market
    • K. Campbell, L.A. Gordon, M.P. Loeb, and L. Zhou, "The Economic Cost of Publicly Announced Information Security Breaches: Empirical Evidence from the Stock Market," J. Computer Security, vol 11, no. 3, pp. 431-448, 2003.
    • (2003) J. Computer Security , vol.11 , Issue.3 , pp. 431-448
    • Campbell, K.1    Gordon, L.A.2    Loeb, M.P.3    Zhou, L.4
  • 12
    • 7444242205 scopus 로고    scopus 로고
    • The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers
    • H. Cavusoglu, B. Mishra, and S. Raghunathan, "The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers," Int'l J. Electronic Commerce, vol. 9, no. 1, p. 69, 2004.
    • (2004) Int'l J. Electronic Commerce , vol.9 , Issue.1 , pp. 69
    • Cavusoglu, H.1    Mishra, B.2    Raghunathan, S.3
  • 13
    • 0011257387 scopus 로고    scopus 로고
    • Examining the Shareholder Wealth Effects of Announcements of Newly Created CIO Positions
    • D. Chatterjee, V.J. Richardson, and R.W. Zmud, "Examining the Shareholder Wealth Effects of Announcements of Newly Created CIO Positions," MIS Quarterly, vol. 25, no. 1, pp. 43-70, 2001.
    • (2001) MIS Quarterly , vol.25 , Issue.1 , pp. 43-70
    • Chatterjee, D.1    Richardson, V.J.2    Zmud, R.W.3
  • 14
    • 34547096411 scopus 로고    scopus 로고
    • J. Clayman, Microsoft Security Response Center A, Case 9B01E019, Richard Ivey School of Business, 2001
    • J. Clayman, "Microsoft Security Response Center (A), Case 9B01E019," Richard Ivey School of Business, 2001.
  • 15
    • 0039698146 scopus 로고    scopus 로고
    • A Rose.com by Any Other Name
    • M.J. Cooper, O. Dimitrov, and P.R. Rau, "A Rose.com by Any Other Name" J. Finance," vol. 6, pp. 2371-2387, 2001.
    • (2001) J. Finance , vol.6 , pp. 2371-2387
    • Cooper, M.J.1    Dimitrov, O.2    Rau, P.R.3
  • 16
    • 4243100594 scopus 로고    scopus 로고
    • Who Is Liable for Bugs and Security Flaws in Software?
    • M.A. Cusumano, "Who Is Liable for Bugs and Security Flaws in Software?" Comm. ACM, vol. 47, no. 3, pp. 25-27, 2004.
    • (2004) Comm. ACM , vol.47 , Issue.3 , pp. 25-27
    • Cusumano, M.A.1
  • 17
    • 84989141785 scopus 로고
    • The Effect of Product Recall Announcements on Shareholder Wealth
    • W.L. Davidson III and D.L. Worrell, "The Effect of Product Recall Announcements on Shareholder Wealth," Strategic Management J., vol. 13, no. 6, pp. 467-473, 1992.
    • (1992) Strategic Management J , vol.13 , Issue.6 , pp. 467-473
    • Davidson III, W.L.1    Worrell, D.L.2
  • 18
    • 84970947585 scopus 로고    scopus 로고
    • Software Engineering for Security: A Roadmap
    • P. Devanbu and S. Stubblebine, "Software Engineering for Security: A Roadmap," Future of Software Eng., pp. 225-239, 2000.
    • (2000) Future of Software Eng , pp. 225-239
    • Devanbu, P.1    Stubblebine, S.2
  • 19
    • 71149116783 scopus 로고
    • The Impact of Information Technology on the Market Value of the Firm
    • Mar
    • B.L. Dos Santos, K. Peffers, and D. Mauer, "The Impact of Information Technology on the Market Value of the Firm," Information Systems Research, vol. 4, pp. 1-23, Mar. 1993.
    • (1993) Information Systems Research , vol.4 , pp. 1-23
    • Dos Santos, B.L.1    Peffers, K.2    Mauer, D.3
  • 20
    • 1142304788 scopus 로고    scopus 로고
    • Understanding Network Effects in Software Markets: Evidence from Webserver Pricing
    • J.M. Gallaugher and Y.M. Yang, "Understanding Network Effects in Software Markets: Evidence from Webserver Pricing," MIS Quarterly vol 26, no. 4, pp. 303-327, 2002.
    • (2002) MIS Quarterly , vol.26 , Issue.4 , pp. 303-327
    • Gallaugher, J.M.1    Yang, Y.M.2
  • 21
    • 1942479041 scopus 로고
    • Hedonic Price Indexes for Spreadsheets and an Empirical Test for Network Externalities
    • N. Gandal, "Hedonic Price Indexes for Spreadsheets and an Empirical Test for Network Externalities," Rand J. Economics, vol. 25, no. 1, pp. 160-170, 1994.
    • (1994) Rand J. Economics , vol.25 , Issue.1 , pp. 160-170
    • Gandal, N.1
  • 23
  • 24
    • 4243121902 scopus 로고    scopus 로고
    • A Framework for Using Insurance for Cyber Risk Management
    • L.A. Gordon, M.P. Loeb, and T. Sohail, "A Framework for Using Insurance for Cyber Risk Management," Comm. ACM, vol. 46, no. 3, pp. 81-85, 2003.
    • (2003) Comm. ACM , vol.46 , Issue.3 , pp. 81-85
    • Gordon, L.A.1    Loeb, M.P.2    Sohail, T.3
  • 26
    • 0033746131 scopus 로고    scopus 로고
    • Effects of Process Maturity on Quality, Cycle Time, and Effort in Software Product Development
    • D.E. Harter, M.S. Krishnan, and S.A. Slaughter, "Effects of Process Maturity on Quality, Cycle Time, and Effort in Software Product Development," Management Science, vol. 46, no. 4, pp. 451-466, 2000.
    • (2000) Management Science , vol.46 , Issue.4 , pp. 451-466
    • Harter, D.E.1    Krishnan, M.S.2    Slaughter, S.A.3
  • 27
    • 0001496179 scopus 로고    scopus 로고
    • Quality Awards and the Market Value of the Firm: An Empirical Investigation
    • K.B. Hendricks and V.R. Singhal, "Quality Awards and the Market Value of the Firm: An Empirical Investigation," Management Science, vol 42, no. 2, pp. 415-436, 1996.
    • (1996) Management Science , vol.42 , Issue.2 , pp. 415-436
    • Hendricks, K.B.1    Singhal, V.R.2
  • 28
    • 0031109010 scopus 로고    scopus 로고
    • Delays in New Product Introductions and the Market Value of the Firm: The Consequences of Being Late to the Market
    • K.B. Hendricks and V.R. Singhal, "Delays in New Product Introductions and the Market Value of the Firm: The Consequences of Being Late to the Market," Management Science, vol 43, no. 4, pp. 422-436, 1997.
    • (1997) Management Science , vol.43 , Issue.4 , pp. 422-436
    • Hendricks, K.B.1    Singhal, V.R.2
  • 30
    • 15744399767 scopus 로고    scopus 로고
    • The Impact of Denial-of-Service Attack Announcements of the Market Value of Firms
    • A. Hovav and J. D'Arcy, "The Impact of Denial-of-Service Attack Announcements of the Market Value of Firms," Risk Management and Insurance Rev., vol. 6, no. 2, pp. 97-121, 2003.
    • (2003) Risk Management and Insurance Rev , vol.6 , Issue.2 , pp. 97-121
    • Hovav, A.1    D'Arcy, J.2
  • 31
    • 24344475266 scopus 로고    scopus 로고
    • Capital Market Reaction to Defective IT Products: The Case of Computer Viruses
    • A. Hovav and J. D'Arcy, "Capital Market Reaction to Defective IT Products: The Case of Computer Viruses," Computers and Security, vol. 24, pp. 409-424, 2005.
    • (2005) Computers and Security , vol.24 , pp. 409-424
    • Hovav, A.1    D'Arcy, J.2
  • 32
    • 0035589482 scopus 로고    scopus 로고
    • Research Report: A Reexamination of IT Investment and the Market Value of the Firm_An Event Study Methodology
    • K.S. Im, K.E. Dow, and V. Grover, "Research Report: A Reexamination of IT Investment and the Market Value of the Firm_An Event Study Methodology," Information Systems Research, vol. 12, no. 1, pp. 103-117, 2001.
    • (2001) Information Systems Research , vol.12 , Issue.1 , pp. 103-117
    • Im, K.S.1    Dow, K.E.2    Grover, V.3
  • 33
    • 84934349880 scopus 로고
    • The Impact of Product Recalls on the Wealth of Sellers
    • G. Jarrell and S. Peltzman, "The Impact of Product Recalls on the Wealth of Sellers," J. Political Economy, vol. 93, no. 1, pp. 512-536, 1985.
    • (1985) J. Political Economy , vol.93 , Issue.1 , pp. 512-536
    • Jarrell, G.1    Peltzman, S.2
  • 34
    • 20944441343 scopus 로고    scopus 로고
    • Market for Software Vulnerabilities? Think Again
    • K. Kannan, R. Telang, "Market for Software Vulnerabilities? Think Again," Management Science, vol. 51, no. 5, pp. 726-740, 2005.
    • (2005) Management Science , vol.51 , Issue.5 , pp. 726-740
    • Kannan, K.1    Telang, R.2
  • 36
    • 84882486619 scopus 로고    scopus 로고
    • Econometrics of Event Studies
    • Espin Eckbo, ed. pp, Elsevier-North-Holland
    • S.P. Kothari and J.P. Warner, "Econometrics of Event Studies," Handbook of Empirical Corporate Finance, Espin Eckbo, ed. pp. 33-36, Elsevier-North-Holland, 2007.
    • (2007) Handbook of Empirical Corporate Finance , pp. 33-36
    • Kothari, S.P.1    Warner, J.P.2
  • 37
    • 0011765591 scopus 로고    scopus 로고
    • Event Studies in Economics and Finance
    • A.C. MacKinlay, "Event Studies in Economics and Finance," J. Economic Literature, vol. 35, no. 1, pp. 13-39, 1997.
    • (1997) J. Economic Literature , vol.35 , Issue.1 , pp. 13-39
    • MacKinlay, A.C.1
  • 38
    • 2342469291 scopus 로고    scopus 로고
    • Software Security
    • G. McGraw, "Software Security" IEEE Security and Privacy, vol. 2, no. 2, pp. 80-83, 2004.
    • (2004) IEEE Security and Privacy , vol.2 , Issue.2 , pp. 80-83
    • McGraw, G.1
  • 39
    • 34547113011 scopus 로고    scopus 로고
    • The Economic Impacts of Inadequate Infrastructure for Software Testing
    • "The Economic Impacts of Inadequate Infrastructure for Software Testing," US Nat'l Inst. of Standards and Technology, http://www.nist.gov/director/prog-ofc/report02-3.pdf, 2002.
    • (2002) US Nat'l Inst. of Standards and Technology
  • 40
    • 84989095272 scopus 로고
    • Diversification Strategy, Profit Performance and the Entropy Measure
    • K. Palepu, "Diversification Strategy, Profit Performance and the Entropy Measure," Strategic Management J., vol. 6, pp. 239-255, 1985.
    • (1985) Strategic Management J , vol.6 , pp. 239-255
    • Palepu, K.1
  • 42
    • 84991269825 scopus 로고    scopus 로고
    • The Fundamentals of Information Security
    • Jan.-Feb
    • C.P. Pfleeger, "The Fundamentals of Information Security," IEEE Software, vol. 14, no. 1, pp. 15-17, Jan.-Feb. 1997.
    • (1997) IEEE Software , vol.14 , Issue.1 , pp. 15-17
    • Pfleeger, C.P.1
  • 43
    • 3042744350 scopus 로고    scopus 로고
    • Two Views of Security Software Liability
    • Jan.-Feb
    • D. Ryan, "Two Views of Security Software Liability," IEEE Security and Privacy, pp. 70-73, Jan.-Feb. 2003.
    • (2003) IEEE Security and Privacy , pp. 70-73
    • Ryan, D.1
  • 44
    • 0032131311 scopus 로고    scopus 로고
    • Evaluating the Cost of Software Quality
    • S.A. Slaughter, D.E. Harter, and M.S. Krishnan, "Evaluating the Cost of Software Quality," Comm. ACM, vol. 41, no. 8, pp. 67-73, 1998.
    • (1998) Comm. ACM , vol.41 , Issue.8 , pp. 67-73
    • Slaughter, S.A.1    Harter, D.E.2    Krishnan, M.S.3
  • 45
    • 0035595781 scopus 로고    scopus 로고
    • The Impact of E-Commerce Announcements on the Market Value of Firms
    • M. Subramani and E. Walden, "The Impact of E-Commerce Announcements on the Market Value of Firms," Information Systems Research, vol 12, no. 2, pp. 135-154, 2001.
    • (2001) Information Systems Research , vol.12 , Issue.2 , pp. 135-154
    • Subramani, M.1    Walden, E.2
  • 46
    • 33645209293 scopus 로고    scopus 로고
    • How Software Project Risk Affects Project Performance: An Investigation of the Dimensions of Risk and An Exploratory Model
    • L. Wallace, M. Keil, and A. Rai, "How Software Project Risk Affects Project Performance: An Investigation of the Dimensions of Risk and An Exploratory Model," Decision Sciences, vol. 35, no. 2, pp. 289-321, 2004.
    • (2004) Decision Sciences , vol.35 , Issue.2 , pp. 289-321
    • Wallace, L.1    Keil, M.2    Rai, A.3
  • 47
    • 1942521938 scopus 로고    scopus 로고
    • Taxonomy of Security Considerations and Software Quality
    • H. Wang and C. Wang, "Taxonomy of Security Considerations and Software Quality," Comm. ACM, vol. 46, no. 6, pp. 75-78, 2003.
    • (2003) Comm. ACM , vol.46 , Issue.6 , pp. 75-78
    • Wang, H.1    Wang, C.2
  • 48
    • 2442585261 scopus 로고    scopus 로고
    • The Cost Behavior of Software Defects
    • J.C. Westland, "The Cost Behavior of Software Defects," Decision Sciences, vol. 37, pp. 229-238, 2003.
    • (2003) Decision Sciences , vol.37 , pp. 229-238
    • Westland, J.C.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.