吓阻理论
信息安全
顺从(心理学)
业务
信息系统安全
前提
信息安全管理
公共关系
安全策略
计划行为理论
知识管理
信息系统
经济
心理学
计算机安全
控制(管理)
云安全计算
社会心理学
管理信息系统
安全信息和事件管理
政治学
管理
计算机科学
法学
哲学
云计算
语言学
作者
Tejaswini Herath,H. Raghav Rao
摘要
Enterprises establish computer security policies to ensure the security of information resources; however, if employees and end-users of organisational information systems (IS) are not keen or are unwilling to follow security policies, then these efforts are in vain. Our study is informed by the literature on IS adoption, protection-motivation theory, deterrence theory, and organisational behaviour, and is motivated by the fundamental premise that the adoption of information security practices and policies is affected by organisational, environmental, and behavioural factors. We develop an Integrated Protection Motivation and Deterrence model of security policy compliance under the umbrella of Taylor-Todd's Decomposed Theory of Planned Behaviour. Furthermore, we evaluate the effect of organisational commitment on employee security compliance intentions. Finally, we empirically test the theoretical model with a data set representing the survey responses of 312 employees from 78 organisations. Our results suggest that (a) threat perceptions about the severity of breaches and response perceptions of response efficacy, self-efficacy, and response costs are likely to affect policy attitudes; (b) organisational commitment and social influence have a significant impact on compliance intentions; and (c) resource availability is a significant factor in enhancing self-efficacy, which in turn, is a significant predictor of policy compliance intentions. We find that employees in our sample underestimate the probability of security breaches.
科研通智能强力驱动
Strongly Powered by AbleSci AI