首页> 外文学位 >From the weakest link to the best defense: Exploring the factors that affect employee intention to comply with information security policies .
【24h】

From the weakest link to the best defense: Exploring the factors that affect employee intention to comply with information security policies .

机译:从最弱的环节到最佳的防御:探索影响员工遵守信息安全策略的意愿的因素。

获取原文
获取原文并翻译 | 示例

摘要

Information and information systems have become embedded in the fabric of contemporary organizations throughout the world. As the reliance on information technology has increased, so too have the threats and costs associated with protecting organizational information resources. To combat potential information security threats, organizations rely upon information security policies to guide employee actions. Unfortunately, employee violations of such policies are common and costly enough that users are often considered the weakest link in information security. The challenge for researchers and practitioners alike is to help transform employees from the weakest link to the best line of information security defense.;Building upon recent empirical research in information security policy behavioral compliance, this study provides a composite theoretical framework that captures key factors shown to impact an employee’s behavioral intent to comply with related policies. The theoretical framework is tested and validated in a real organizational context employing a robust and well-defined set of information security policies, a first in this burgeoning line of research. This study also evaluates how behavioral intent to follow security policies varies for employees for both the general specter of information security policy compliance and specific guidance for three common security threats.;This study found that the primary factors affecting behavioral intent (subjective norms, organizational commitment, attitude, perceived behavioral control, and self-efficacy) had strong, positive relationships with intent to comply with information security policies when examined at a high level of general compliance. However, when the factors affecting behavioral intent and attitude towards a security behavior were evaluated for specific information security threat contexts, individual factor importance and significance varied greatly. These results indicate that threat context plays an essential role in clarifying the roles of specific behavioral antecedents; there may be limited value in future research focusing on general information security threats. Finally, while this study failed to establish a significant relationship between behavioral compliance intent and an employee’s perception of their ability to enforce of mandatory information security policy requirements on coworkers, it did highlight a potential gap in the composite theoretical framework for this important phenomenon that should be addressed in future research.
机译:信息和信息系统已经嵌入到全世界当代组织的结构中。随着对信息技术的依赖增加,与保护组织信息资源相关的威胁和成本也随之增加。为了应对潜在的信息安全威胁,组织依靠信息安全策略来指导员工的行动。不幸的是,员工违反此类政策很普遍,而且成本很高,以至于用户通常被视为信息安全中最薄弱的环节。研究人员和从业人员面临的挑战都是如何帮助员工从最薄弱的环节转变为最佳的信息安全防御路线。基于最新的信息安全政策行为合规性经验研究,本研究提供了一个综合的理论框架,可以捕获所显示的关键因素影响员工遵守相关政策的行为意图。该理论框架是在实际组织环境中使用可靠且定义明确的一组信息安全策略进行测试和验证的,这是该研究领域中的第一项。这项研究还评估了员工遵循安全策略的行为意图在信息安全策略合规性的一般幽灵和针对三种常见安全威胁的具体指导方面如何变化;这项研究发现,影响行为意图的主要因素(主观规范,组织承诺) ,态度,感知的行为控制和自我效能感)之间有很强的积极联系,并有意在较高的总体合规性水平下遵守信息安全政策。但是,当针对特定的信息安全威胁上下文评估影响行为意图和对安全行为的态度的因素时,各个因素的重要性和重要性差异很大。这些结果表明,威胁情境在阐明特定行为前因的作用中起着至关重要的作用。将来针对一般信息安全威胁的研究可能价值有限。最后,尽管该研究未能在行为合规意图与员工对同事强制执行强制性信息安全政策要求的能力之间建立显着关系,但确实凸显了该重要现象的综合理论框架中的潜在差距。在未来的研究中加以解决。

著录项

  • 作者

    Aurigemma, Salvatore.;

  • 作者单位

    University of Hawai'i at Manoa.;

  • 授予单位 University of Hawai'i at Manoa.;
  • 学科 Business Administration Management.;Information Technology.
  • 学位 Ph.D.
  • 年度 2013
  • 页码 176 p.
  • 总页数 176
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号