Paper Type

ERF

Abstract

Software supply chain attacks are a growing threat, yet organizations lack systematic approaches for synthesizing distributed vulnerability signals into actionable intelligence. Vendors possess security knowledge that buyers cannot verify, creating information asymmetry that distorts procurement decisions. This study contributes to organizational decision-making under security information asymmetry by integrating organizational information processing, sensemaking, and information asymmetry as nested levels of one problem (capacity, interpretation, and market consequence). We employ a sequential mixed-methods design combining semi-structured practitioner interviews analyzed through the Gioia methodology with machine learning classification on GitHub events linked to NVD records. Detection accuracy and lead-time are inputs to interpretation, not ends in themselves.

Paper Number

1836

Comments

SIG SEC

Share

COinS
 
Aug 15th, 12:00 AM

Resolving Information Asymmetry in Software Supply Chain Risk Assessment: An Organizational Sensemaking Perspective on Vulnerability Intelligence

Software supply chain attacks are a growing threat, yet organizations lack systematic approaches for synthesizing distributed vulnerability signals into actionable intelligence. Vendors possess security knowledge that buyers cannot verify, creating information asymmetry that distorts procurement decisions. This study contributes to organizational decision-making under security information asymmetry by integrating organizational information processing, sensemaking, and information asymmetry as nested levels of one problem (capacity, interpretation, and market consequence). We employ a sequential mixed-methods design combining semi-structured practitioner interviews analyzed through the Gioia methodology with machine learning classification on GitHub events linked to NVD records. Detection accuracy and lead-time are inputs to interpretation, not ends in themselves.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.