...
首页> 外文期刊>Computers & Security >Don't make excuses! Discouraging neutralization to reduce IT policy violation
【24h】

Don't make excuses! Discouraging neutralization to reduce IT policy violation

机译:不要找借口!禁止中和以减少违反IT策略的行为

获取原文
获取原文并翻译 | 示例
           

摘要

Past research on information technology (IT) security training and awareness has focused on informing employees about security policies and formal sanctions for violating those policies. However, research suggests that deterrent sanctions may not be the most powerful influencer of employee violations. Often, employees use rationalizations, termed neutralization techniques, to overcome the effects of deterrence when deciding whether or not to violate a policy. Therefore, neutralization techniques often are stronger than sanctions in predicting employee behavior. For this study, we examine "denial of injury," "metaphor of the ledger," and "defense of necessity" as relevant justifications for violating password policies that are commonly used in organizations as used in (Siponen and Vance, 2010). Initial research on neutralization in IS security has shown that results are consistent regardless of which type of neutralization is considered (Siponen and Vance, 2010). In this study, we investigate whether IT security communication focused on mitigating neutralization, rather than deterrent sanctions, can reduce intentions to violate security policies. Additionally, considering the effects of message framing in persuading individuals against security policy violations are largely unexamined, we predict that negatively-framed communication will be more persuasive than positively-framed communication. We test our hypotheses using the factorial survey method. Our results suggest that security communication and training that focuses on neutralization techniques is just as effective as communication that focuses on deterrent sanctions in persuading employees not to violate policies, and that both types of framing are equally effective.
机译:过去有关信息技术(IT)安全培训和意识的研究的重点是通知员工有关安全策略和违反这些策略的正式制裁措施。但是,研究表明,威慑制裁可能不是影响员工行为的最有力影响者。通常,员工在决定是否违反政策时会使用合理化(称为中和技术)来克服威慑的影响。因此,在预测员工行为方面,中和技术通常比制裁更强。在本研究中,我们将“拒绝伤害”,“分类帐隐喻”和“必要性防御”作为违反在组织中常用的密码策略的相关理由(Siponen和Vance,2010年)。最初对IS安全中和的研究表明,无论考虑哪种类型的中和,结果都是一致的(Siponen和Vance,2010年)。在这项研究中,我们调查了专注于缓解中和而不是威慑性制裁的IT安全通信是否可以减少违反安全策略的意图。此外,考虑到消息框架在说服个人抵御安全策略违规方面的效果还没有得到检验,我们预测否定框架的通信比肯定框架的通信更具说服力。我们使用析因调查方法检验我们的假设。我们的结果表明,针对中立技术的安全沟通和培训与针对威慑制裁的沟通在说服员工不违反政策方面同样有效,并且两种类型的框架同样有效。

著录项

  • 来源
    《Computers & Security》 |2013年第ptab期|145-159|共15页
  • 作者单位

    Department of Operations and Decision Technologies, Kelley School of Business, Indiana University, USA;

    Department of Management and Information Systems, College of Business, Mississippi State University, USA,Department of Management and Information Systems, College of Business, Mississippi State University, P.O. Box 9581, Mississippi State, MS 39762, USA;

    Department of Management and Information Systems, College of Business, Mississippi State University, USA;

    Department of Operations and Decision Technologies, Kelley School of Business, Indiana University, USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    IT security; Policies; Neutralization; Deterrence; Rationalization; Message framing; Training; Awareness; Compliance;

    机译:IT安全;政策;中和;威慑;合理化;消息框架;训练;意识;合规;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号