4.5 Article

An exploratory examination of organizational insiders' descriptive and normative perceptions of cyber-relevant rights and responsibilities

期刊

COMPUTERS & SECURITY
卷 99, 期 -, 页码 -

出版社

ELSEVIER ADVANCED TECHNOLOGY
DOI: 10.1016/j.cose.2020.102038

关键词

Information security policy (ISP) compliance; Deonance theory; Normative assessment; Organizational security; Moral obligations; Organizational insider

资金

  1. IFIP [WG8.11/WG11.13]

向作者/读者索取更多资源

Within the field of organizational cybersecurity, much attention has been given to insider compliance and non-compliance with the information security policies (ISPs) set forth by their organizations. Most of these efforts apply theoretical foundations based on self-interest, personal incentive, and cost-benefit calculations to explain compliance and noncompliance motives. We take a different approach to understand insiders' ISP compliance by exploring how insiders view their rights and responsibilities related to security-relevant behaviors. Relying on Deonance Theory, we assess the extent to which insiders categorize a wide variety of behaviors that are or can be implemented in corporate ISPs according to several deontic conditional operators (e.g., nature of perceived requiredness). These operators form the basis for a rights and responsibility framework. We find that out of 38 unique security-relevant behaviors, 22 exhibit one or more forms of potential moral gray area patterns. Among these patterns, significant differences between insiders' descriptive (i.e., is) and normative (i.e., should be) assessments of rights and responsibilities perceptions are particularly interesting. Our findings shed additional light on insiders' compliance with organizational ISPs when those ISPs place increased restrictions on what the insider must or must not do. (C) 2020 Elsevier Ltd. All rights reserved.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据