Protection motivation and deterrence: a framework for security policy compliance in organisations

Protection motivation and deterrence: a framework for security policy compliance in organisations
复制标题

DOI:
10.1057/ejis.2009.6
复制
发表时间:
2009-04-01
影响因子:
9.5
通讯作者:
Rao, H. Raghav
Rao, H. Raghav
中科院分区:
管理学3区
文献类型:
--
作者:
Herath, Tejaswini;Rao, H. Raghav

文献摘要

被引文献

相似文献

企业制定计算机安全策略以确保信息资源的安全;然而,如果组织信息系统(IS)的员工和最终用户不热衷于或不愿遵循安全策略,则这些努力是徒劳的。我们的研究受到信息系统采用、保护-激励理论、威慑理论和组织行为的文献的启发,并受到一个基本前提的推动,即信息安全实践和政策的采用受到组织、环境和行为因素的影响。在泰勒-托德计划行为分解理论的框架下,我们建立了安全政策遵从性的综合保护动机和威慑模型。此外,我们还评估了组织承诺对员工安全合规意愿的影响。最后,我们用一个代表来自78个组织的312名员工的调查回复的数据集对理论模型进行了实证检验。我们的结果表明:(A)对违规严重程度的威胁感知和对响应效能、自我效能和响应成本的响应感知可能会影响政策态度;(B)组织承诺和社会影响力对遵约意愿有显著影响;以及(C)资源可用性是提高自我效能感的重要因素,而自我效能感又是政策遵从性意图的重要预测因素。我们发现,我们样本中的员工低估了安全漏洞的可能性。《欧洲信息系统杂志》(2009)18,106-125。DOI:10.1057/ejis.2009.6;2009年4月21日在线发布
Enterprises establish computer security policies to ensure the security of information resources; however, if employees and end-users of organisational information systems (IS) are not keen or are unwilling to follow security policies, then these efforts are in vain. Our study is informed by the literature on IS adoption, protection-motivation theory, deterrence theory, and organisational behaviour, and is motivated by the fundamental premise that the adoption of information security practices and policies is affected by organisational, environmental, and behavioural factors. We develop an Integrated Protection Motivation and Deterrence model of security policy compliance under the umbrella of Taylor-Todd's Decomposed Theory of Planned Behaviour. Furthermore, we evaluate the effect of organisational commitment on employee security compliance intentions. Finally, we empirically test the theoretical model with a data set representing the survey responses of 312 employees from 78 organisations. Our results suggest that (a) threat perceptions about the severity of breaches and response perceptions of response efficacy, self-efficacy, and response costs are likely to affect policy attitudes; (b) organisational commitment and social influence have a significant impact on compliance intentions; and (c) resource availability is a significant factor in enhancing self-efficacy, which in turn, is a significant predictor of policy compliance intentions. We find that employees in our sample underestimate the probability of security breaches. European Journal of Information Systems (2009) 18, 106-125. doi:10.1057/ejis.2009.6; published online 21 April 2009