Encouraging information security behaviors in organizations: Role of penalties, pressures and perceived effectiveness

نویسندگان

  • Tejaswini Herath
  • H. Raghav Rao
چکیده

a r t i c l e i n f o Keywords: Principal agent theory Information security End-user security behaviors Security policy compliance Secure management of information systems is crucially important in information intensive organizations. Although most organizations have long been using security technologies, it is well known that technology tools alone are not sufficient. Thus, the area of end-user security behaviors in organizations has gained an increased attention. In information security observing end-user security behaviors is challenging. Moreover, recent studies have shown that the end users have divergent security views. The inability to monitor employee IT security behaviors and divergent views regarding security policies, in our view, provide a setting where the principal agent paradigm applies. In this paper, we develop and test a theoretical model of the incentive effects of penalties, pressures and perceived effectiveness of employee actions that enhances our understanding of employee compliance to information security policies. Based on 312 employee responses from 77 organizations, we empirically validate and test the model. Our findings suggest that security behaviors can be influenced by both intrinsic and extrinsic motivators. Pressures exerted by subjective norms and peer behaviors influence employee information security behaviors. Intrinsic motivation of employee perceived effectiveness of their actions was also found to play an important role in security policy compliance intentions. In analyzing the penalties, certainty of detection was found to be significant while surprisingly, severity of punishment was found to have a negative effect on security behavior intentions. We discuss the implications of our findings for theory and practice. In information intensive organizations secured management of information has become an important issue. Organizations have been actively using security technologies. Extant research in information security has been focused on the use technology (e.g., [27,69]). However more recently, practitioners and academics have started to realize that information security cannot be achieved through only technological tools and effective organizational information security depends on all three components, namely: people, processes and technology [34]. However, empirical research on end-user security behaviors and factors influencing them is still in its infancy. With the advances in security technologies, many computing behaviors such as patch management and antivirus updates are now being automated to reduce the task knowledge and time burdens on end users. However, behaviors such as appropriate use of computer and network resources, appropriate password habits etc., that cannot be addressed by security technologies are often dealt through organizational computer …

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

نقش تعدیل‌کننده رفتارهای انحرافی در رابطه بین استرس شغلی و امنیت روانشناختی ادراک شده

Deviant behaviors are harmful to individuals and organizations in most situations. However, at the individual level these behaviors in response to stress can be considered as compensatory behaviors. The present study aimed to investigate the moderating role of deviant behaviors on the relationship between job stress and perceived psychological safety and compare discussed relations between the ...

متن کامل

شناسایی و رتبه‌بندی عوامل کلیدی مؤثر بر اثربخشی سیستم‌های اطلاعاتی در سازمان‌های دولتی

Nowadays, information systems organizations can help in gaining competitive advantage, because the quality of the output of these systems play an important role in improving the performance of the organization. The main objective of this study is Identification and ranking of key factors influencing the effectiveness of information systems in State-Owned Organizations. For this purpose, the rol...

متن کامل

A systematic review of the use of financial incentives and penalties to encourage uptake of healthy behaviors: protocol

UNLABELLED BACKGROUND The use of financial incentives and penalties to encourage uptake of healthy behaviors is increasingly seen as a viable intervention in developed countries. Previous reviews of the effectiveness of financial incentives and penalties for encouraging the uptake of healthy behaviors have focused on individual behaviors making it difficult to draw overall conclusions about ...

متن کامل

Systems Thinking as a Platform for the Improved Performance of Leaders and the Effectiveness of Public Organizations

The purpose of this study is to investigate the impact of systems thinking on the performance of leaders of public organizations in Tehran and the effectiveness of their organizations. It was an applied, descriptive and correlational research. The statistical population of the study consisted of all public organizations in Tehran. According to Morgan's table, the sample size was 80. Data were c...

متن کامل

Investigating Women\'s Pregnancy Care Behaviors Based on the Health Belief Model and Social Support Patterns in Pregnant Women Referring to Health Centers Covered affiliated by Iranshahr-Iran faculty of medical science

Background: Pregnant women need information, skills and social support for the effectiveness of pregnancy care. Health education patterns play a major role in educational needs assessment in designing and implementing educational interventions. Objectives: The present study aimed to investigate the pregnancy care behaviors, based on the health belief and social support model among pregnant wom...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Decision Support Systems

دوره 47  شماره 

صفحات  -

تاریخ انتشار 2009