A Conceptual Model for Explaining Violations of the Information Security Policy (ISP): A Cross Cultural Perspective
نویسندگان
چکیده
This paper is an attempt to develop a model that explores the factors that affect the frequency of violations of information security policies (ISPs). Additionally, it examines the moderating effect of cultural attributes on the frequency of ISP violations. Does national culture affect the way managers and employees perceive and practice ISPs? If we understand why ISPs are violated, perhaps we can deter future violations before they occur. We look at three groups of factors and the impact they have on the frequency of violations of ISPs. The factors examined are 1) the individual characteristics and capabilities of employees, 2) the information security policy (ISP) itself and 3) management issues. Finally, the study examines the moderating effect of Hofstede’s cultural dimensions (uncertainty avoidance, individualism/collectivism, and power distance) on the proposed model.
منابع مشابه
Investigating the Impact of Information Quality on Relationship Marketing with Mediating Role of Salespeople’ Relational Competency: Survey about Iranian ISP
Despite the vital role of information in relational-oriented firms, there are limited studies on the impact of information quality on relationship marketing. To address this gap, this study develops a conceptual model to examine the impact of information quality on the successful implementation of relationship marketing by assessing the mediating role of salespeople's relational competency. The...
متن کاملA Framework for Evaluating Cloud Computing User’s Satisfaction in Information Technology Management
Cloud computing is a new discussion in enterprise IT. It has already become popular in terms of distributed technology in some companies. It enables managers to setup and run the intended businesses by avoiding excessive spending on computers, software and hiring expert staff, which proves to be cost effective. Cloud computing also helps users pay for the IT services without spending massive am...
متن کاملStakeholders in Security Policy Development
The Information Security Policy (ISP) of an organisation is expected to specify for employees their behaviour towards security, and the security ethos of the organisation. However, there are a wide range of opinions and expertise that should be considered by organisations when developing an ISP. This paper aims to identify the stakeholders that should be utilised in an ISP development process a...
متن کاملImproving Information Security Training: An Intercultural Perspective
To ensure successful compliance with information security (InfoSec) policy and standards, organisations must harmonise their InfoSec training programmes with the national culture of the local workforce. A successful InfoSec policy must demonstrate the value of security, not just the requirement for security. We conducted a quantitative study of 177 professionals across 35 national cultures to i...
متن کاملطراحی مدل سیاست گذاری رسانه ایی سازمان تامین اجتماعی ایران
Introduction: Mass media plays a crucial role in information distribution and thus in the political market and public policy making. Theory predicts that the information provided by mass media reflects the media’s incentives to provide news to different types of groups in society, and affects these groups’ influence in policy-making. A few empirical studies have tried to assess the effect of me...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2008