The moderating effect of abusive supervision on information security policy compliance: Evidence from the hospitality industry

The moderating effect of abusive supervision on information security policy compliance: Evidence from the hospitality industry
复制标题

滥用监管对信息安全政策合规性的调节作用:来自酒店业的证据

DOI:
10.1016/j.cose.2021.102455
复制
发表时间:
2021
影响因子:
5.6
通讯作者:
Lvxin Yan
Lvxin Yan
中科院分区:
计算机科学3区
文献类型:
--
作者:
Jian Xu;Xuequn Wang;Lvxin Yan

文献摘要

相似文献

组织已经认识到信息安全的重要性,并为其员工制定了信息安全策略。威慑常用于增强员工的合规意愿。然而,文献报告的威慑效果的结果好坏参半,我们认为这些相互矛盾的发现可能是由于组织之间不同的管理环境造成的。为了了解管理因素如何影响威慑效果,我们的研究重点关注滥用监督,并研究滥用监督如何调节威慑感知与员工遵守信息安全政策的意图之间的关系。我们进行了两轮调查,收集中国酒店员工的数据。结果表明,当使用第二轮调查的合规意向进行假设检验时,滥用监管并不能增强感知严重性和威慑确定性的效果。我们的研究通过迈出第一步来解释威慑文献中不一致的结果,从而对文献做出了贡献。我们的研究还提供了重要的战略指导方针,告知管理者不应使用滥用监督来提高员工对信息安全政策的遵守程度。
Organizations have recognized the importance of information security and have developed information security policies for their employees. Deterrence is often used to enhance employees’ compliance intention. However, the literature reports mixed results for the effects of deterrence, and we argue that those conflicting findings can be due to different managerial contexts across organizations. To understand how managerial factors influence the effects of deterrence, our study focused on abusive supervision and examined how abusive supervision moderated the relationship between deterrence perception and employee’ intention to comply with information security policies. Two rounds of surveys were conducted to collect data from Chinese hotel employees. The results show that abusive supervision could not enhance the effect of perceived severity and certainty of deterrence, when compliance intention from the second-round survey was used for hypotheses testing. Our study contributes to the literature by taking the first step toward explaining the inconsistent results in the literature on deterrence. Our study also provides important strategic guidelines informing managers that abusive supervision should not be used to enhance employees’ compliance with information security policies.