Control, Risk and Information Security Precautions

نویسنده

  • Scott R. Boss
چکیده

The introduction of the Internet to the business world has changed many ways of doing business. Unfortunately, the Internet has also become an arena where individuals are constantly at risk for computer viruses, spyware/adware infection, and malicious attacks designed to misuse or appropriate corporate assets. The wide-spread publicity of both cyber-attacks and ways to combat these problems, public and corporate education efforts, and prevention efforts (including corporate spending on new protections and enforcement of existing policies), suggest that it is logical for users to put precautionary practices in place. Unfortunately, they often don’t. Many individuals within organizations underestimate their vulnerability and do not follow prescribed security policies and procedures implemented within their organizations. Extant security literature heavily emphasizes automatic or programmed security measures, but does not focus strongly on the behaviors of individuals in the security setting. This paper examines two research questions: What are the effects of organizational policies and procedures on security precautions taken by individuals? What is the role that individual risk perceptions play in individual cyberprecautions choices? These questions will be addressed by theory taken from the formal control and fear of crime literatures. This theory posits that formal controls and individuals’ experiences have a strong effect on both individual perceptions of mandatory rules and individual risk perceptions. These perceptions, in turn, lead to precaution-taking behaviors. The resulting model will be tested with a field survey.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Survey of Knowledge, Attitude, and Adherence to Standard Precautions of Infection Control among Khoy Nursing Students during the COVID-19 Pandemic in 2021: A Short Report

Background and Objectives: The risk of transmission of various infections threatens nursing students. The aim of this study was to evaluate the level of knowledge, attitude, and adherence to standard infection control precautions among nursing students during the Corona pandemic. Materials and Methods: This descriptive study was performed on 70 senior nursing students in Khoy in 2021. Data col...

متن کامل

Identifying Information Security Risk Components in Military Hospitals in Iran

Background and Aim: Information systems are always at risk of information theft, information change, and interruptions in service delivery. Therefore, the present study was conducted to develop a model for identifying information security risk in military hospitals in Iran. Methods: This study was a qualitative content analysis conducted in military hospitals in Iran in 2019. The sample consist...

متن کامل

Information Security: Facilitating User Precautions Vis-à-Vis Enforcement Against Attackers

We compare alternative information security policies—facilitating enduser precautions and enforcement against attackers. The context is mass and targeted attacks, taking account of strategic interactions between end users and attackers. For both mass and targeted attacks, facilitating end-user precautions reduces the expected loss of end users. However, the impact of enforcement on expected los...

متن کامل

If someone is watching, I'll do what I'm asked: mandatoriness, control, and information security

Received: 8 April 2008 Revised: 15 August 2008 2nd Revision: 18 January 2009 Accepted: 23 February 2009 Abstract Information security has become increasingly important to organizations. Despite the prevalence of technical security measures, individual employees remain the key link – and frequently the weakest link – in corporate defenses. When individuals choose to disregard security policies a...

متن کامل

The Last Line of Defense: Motivating Employees to Follow Corporate Security Guidelines

Information security has become increasingly important to organizations. Despite the prevalence of technical security measures, individual employees remain the last line – and frequently the weakest link – in corporate defenses. When individuals choose to disregard security policies and procedures, the organization is at risk. How, then, can organizations motivate their employees to follow secu...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005