The Last Line of Defense: Motivating Employees to Follow Corporate Security Guidelines

نویسندگان

  • Laurie J. Kirsch
  • Scott R. Boss
چکیده

Information security has become increasingly important to organizations. Despite the prevalence of technical security measures, individual employees remain the last line – and frequently the weakest link – in corporate defenses. When individuals choose to disregard security policies and procedures, the organization is at risk. How, then, can organizations motivate their employees to follow security guidelines? Using an organizational control lens, we build a model to explain individual information security precaution-taking behavior. Specific hypotheses are developed and tested using a field survey. We examine elements of control and introduce the concept of “mandatoriness” which we define as the degree to which individuals perceive that compliance with existing security policies and procedures is compulsory or expected by organizational management. We find that the acts of specifying policies and evaluating behaviors are effective in convincing individuals that security policies are mandatory. The perception of mandatoriness is effective in motivating individuals to take security precautions.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Organizational Factors Affecting Knowledge Sharing Within Group (Case Study: Offices of the Central Building of BSI)

One of the most important resources for any organization, competitiveness and innovation, knowledge management and knowledge sharing in the organization and the process is correct. Despite the importance knowledge sharing, manpower agencies may refrain from doing it. That's why one of the key challenges in knowledge management is how organizations can encourage employees to share their knowledg...

متن کامل

If someone is watching, I'll do what I'm asked: mandatoriness, control, and information security

Received: 8 April 2008 Revised: 15 August 2008 2nd Revision: 18 January 2009 Accepted: 23 February 2009 Abstract Information security has become increasingly important to organizations. Despite the prevalence of technical security measures, individual employees remain the key link – and frequently the weakest link – in corporate defenses. When individuals choose to disregard security policies a...

متن کامل

Work Motivation: A Study on Regular and Part-time Employees of Bangladesh

Nowadays both part-time as well as regular employees are working in many organizations of Bangladesh. Though many studies have been conducted to know the motivation status of regular employees but no study is found that addressed motivations status of both regular and part-time employees of Bangladesh. Thus, this study is conducted on 300 regular and part-time employees of Bangladesh to know th...

متن کامل

Authenticating Users on Handheld Devices

Adequate user authentication is a persistent problem, particularly with handheld devices, which tend to be highly personal and at the fringes of an organization’s influence. Yet, these devices are being used increasingly in corporate settings where they pose a security risk, not only by the sensitive information they may contain, but also the means to access such information they may provide. U...

متن کامل

Information Security Policies - The Legal Risk of Uninformed Personnel

Although the development and deployment of an effective information security infrastructure within the company is imperative to the success of the overall information security discipline, it will be a futile exercise if those people who are expected to maintain and monitor information security in the company do not know what is expected and demanded of them. The importance of information securi...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007