首页> 外文期刊>MIS quarterly >Information Security Policy Compliance: An Empirical Study of Rationality-Based Beliefs and Information Security Awareness
【24h】

Information Security Policy Compliance: An Empirical Study of Rationality-Based Beliefs and Information Security Awareness

机译:信息安全策略合规性:基于理性的信念和信息安全意识的实证研究

获取原文
获取原文并翻译 | 示例
           

摘要

Many organizations recognize that their employees, who are often considered the weakest link in information security, can also be great assets in the effort to reduce risk related to information security. Since employees who comply with therninformation security rules and regulations of the organization are the key to strengthening information security, understanding compliance behavior is crucial for organizations that want to leverage their human capital.rnThis research identifies the antecedents of employee compliance with the information security policy (ISP) of an organization. Specifically, we investigate the rationality-based factors that drive an employee to comply with requirements of the ISP with regard to protecting the organization's information and technology resources. Drawing on the theory of planned behavior, we posit that, along with normative belief and self-efficacy, an employee's attitude toward compliance determines intention to comply with the ISP. As a key contribution, we posit that an employee's attitude is influenced by benefit of compliance, cost of compliance, and cost of noncompliance, which are beliefs about the overall assessment of consequences of compliance or noncompliance. We then postulate that these beliefs are shaped by the employee's outcome beliefs concerning the events that follow compliance or noncompliance: benefit of compliance is shaped by intrinsic benefit, safety of resources, and rewards, while cost of compliance is shaped by work impediment; and cost of noncompliance is shaped by intrinsic cost, vulnerability of resources, and sanctions. We also investigate the impact of information security awareness (ISA) on outcome beliefs and an employee's attitude toward compliance with the ISP.rnOur results show that an employee's intention to comply with the ISP is significantly influenced by attitude, normative beliefs, and self-efficacy to comply. Outcome beliefs significantly affect beliefs about overall assessment of consequencesrn, and they, in turn, significantly affect an employee's attitude. Furthermore, ISA positively affects both attitude and outcome beliefs. As the importance of employees 'following their organizations' information security rules and regulations increases, our study sheds light on the role of ISA and compliance-related beliefs in an organization's efforts to encourage compliance.
机译:许多组织认识到,通常被认为是信息安全中最薄弱环节的员工,在减少与信息安全相关的风险方面也可以成为宝贵的资产。由于遵守组织信息安全法规的员工是加强信息安全的关键,因此了解遵从行为对于希望利用其人力资本的组织至关重要.rn这项研究确定了员工遵守信息安全政策的前提( ISP)。具体来说,我们调查基于合理性的因素,这些因素促使员工在保护组织的信息和技术资源方面遵守ISP的要求。基于计划行为的理论,我们认为,与规范性信念和自我效能感一起,员工对合规性的态度决定了遵守ISP的意图。作为一项重要贡献,我们假设员工的态度受合规利益,合规成本和不合规成本的影响,这是对合规或不合规后果的整体评估的信念。然后,我们假设这些信念是由员工对遵从或不遵从事件的结果信念所形成的:遵从的利益由内在的利益,资源的安全性和报酬所决定,而遵从的成本则由工作障碍所决定;违规成本由内在成本,资源的脆弱性和制裁决定。我们还调查了信息安全意识(ISA)对结果信念和员工遵守ISP的态度的影响。我们的结果表明,员工遵守ISP的意愿受到态度,规范性信念和自我效能的显着影响遵守。结果信念显着影响对后果总体评估的信念,进而反过来显着影响员工的态度。此外,ISA对态度和结果信念都有积极影响。随着员工“遵循其组织的信息安全规则和法规”重要性的增加,我们的研究揭示了ISA和合规性信念在组织鼓励合规性方面的作用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号