4.5 Article Proceedings Paper

If someone is watching, I'll do what I'm asked: mandatoriness, control, and information security

期刊

EUROPEAN JOURNAL OF INFORMATION SYSTEMS
卷 18, 期 2, 页码 151-164

出版社

TAYLOR & FRANCIS LTD
DOI: 10.1057/ejis.2009.8

关键词

information security; control; mandatoriness

向作者/读者索取更多资源

Information security has become increasingly important to organizations. Despite the prevalence of technical security measures, individual employees remain the key link - and frequently the weakest link - in corporate defenses. When individuals choose to disregard security policies and procedures, the organization is at risk. How, then, can organizations motivate their employees to follow security guidelines? Using an organizational control lens, we build a model to explain individual information security precaution-taking behavior. Specific hypotheses are developed and tested using a field survey. We examine elements of control and introduce the concept of 'mandatoriness,' which we define as the degree to which individuals perceive that compliance with existing security policies and procedures is compulsory or expected by organizational management. We find that the acts of specifying policies and evaluating behaviors are effective in convincing individuals that security policies are mandatory. The perception of mandatoriness is effective in motivating individuals to take security precautions, thus if individuals believe that management watches, they will comply. European Journal of Information Systems (2009) 18, 151-164. doi:10.1057/ejis.2009.8; published online 31 March 2009

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据