To Enforce or To Influence? Understanding the Effects of Organizational, Workgroup, and Personal-Self Sanctions on Preventing Information Security Policy Violations in the Workplace
ثبت نشده
چکیده
“Insiders” – employees within organizations – have been seen as a major problem for information security management. Employees were often found to intentionally violate organizational information security policies despite the possibility of being disciplined for their actions. In this study, we aim to examine the effects of different types of sanctions – organizational, workgroup, and personal self-sanctions – on employees’ intention to violate information security policies. We collected survey data from a sample of 306 computer users at work to empirically test our proposed research model. The results suggest that the effect of organizational sanctions on employee behavioral intention diminishes when workgroup and personal self-sanctions are taken into account; personal self-sanctions also partially mediate the effect of organizational and workgroup sanctions. Implications for theories and information security management practices are also discussed.
منابع مشابه
Understanding Nonmalicious Security Violations in the Workplace: A Composite Behavior Model
End users are said to be “the weakest link” in information systems (IS) security management in the workplace. they often knowingly engage in certain insecure uses of IS and violate security policies without malicious intentions. Few studies, however, have examined end user motivation to engage in such behavior. to fill this research gap, in the present study we propose and test empirically a no...
متن کاملA Rational Choice Perspective
Employee violations of IS security policies are reported as a key concern for organizations. Although behavioral research on IS security has received increasing attention from IS scholars, little empirical research has examined this problem. To address this research gap, the authors test a model based on Rational Choice Theory (RCT)—a prominent criminological theory not yet applied in IS—which ...
متن کاملطراحی مدل سیاست گذاری رسانه ایی سازمان تامین اجتماعی ایران
Introduction: Mass media plays a crucial role in information distribution and thus in the political market and public policy making. Theory predicts that the information provided by mass media reflects the media’s incentives to provide news to different types of groups in society, and affects these groups’ influence in policy-making. A few empirical studies have tried to assess the effect of me...
متن کاملطراحی مدل سیاست گذاری رسانه ایی سازمان تامین اجتماعی ایران
Introduction: Mass media plays a crucial role in information distribution and thus in the political market and public policy making. Theory predicts that the information provided by mass media reflects the media’s incentives to provide news to different types of groups in society, and affects these groups’ influence in policy-making. A few empirical studies have tried to assess the effect of me...
متن کاملTowards Understanding Deterrence: Information Security Managers' Perspective
The enforcement of information security policy is an important issue in organisations. Previous studies approach policy enforcement using deterrence theory to deal with information security violations and focus on end-users’ awareness. This study investigates deterrence strategy within organisations from the perspective of information security managers. The results primarily reveal that current...
متن کامل