首页 | 本学科首页   官方微博 | 高级检索  
     


If someone is watching,I'll do what I'm asked: mandatoriness,control, and information security
Authors:Scott R Boss  Laurie J Kirsch  Ingo Angermeier  Raymond A Shingler  R Wayne Boss
Affiliation:1.Department of Accountancy,Bentley University,U.S.A.;2.Joseph M. Katz Graduate School of Business & College of Business Administration, University of Pittsburgh,U.S.A.;3.Spartanburg Regional Medical Center,U.S.A.;4.Spartanburg Regional Medical Center,U.S.A.;5.Leeds School of Business, University of Colorado at Boulder,U.S.A.
Abstract:Information security has become increasingly important to organizations. Despite the prevalence of technical security measures, individual employees remain the key link – and frequently the weakest link – in corporate defenses. When individuals choose to disregard security policies and procedures, the organization is at risk. How, then, can organizations motivate their employees to follow security guidelines? Using an organizational control lens, we build a model to explain individual information security precaution-taking behavior. Specific hypotheses are developed and tested using a field survey. We examine elements of control and introduce the concept of ‘mandatoriness,’ which we define as the degree to which individuals perceive that compliance with existing security policies and procedures is compulsory or expected by organizational management. We find that the acts of specifying policies and evaluating behaviors are effective in convincing individuals that security policies are mandatory. The perception of mandatoriness is effective in motivating individuals to take security precautions, thus if individuals believe that management watches, they will comply.
Keywords:
本文献已被 SpringerLink 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号