4.5 Article

Protection motivation and deterrence: a framework for security policy compliance in organisations

期刊

EUROPEAN JOURNAL OF INFORMATION SYSTEMS
卷 18, 期 2, 页码 106-125

出版社

TAYLOR & FRANCIS LTD
DOI: 10.1057/ejis.2009.6

关键词

security policy compliance; protection motivation; deterrence; organisational commitment

资金

  1. Cyber Task Force, Buffalo Division, FBI
  2. NSF [0402388, 0809186]
  3. MDRF [F0630]
  4. Direct For Computer & Info Scie & Enginr
  5. Div Of Information & Intelligent Systems [0809186] Funding Source: National Science Foundation
  6. Division Of Undergraduate Education
  7. Direct For Education and Human Resources [0402388] Funding Source: National Science Foundation

向作者/读者索取更多资源

Enterprises establish computer security policies to ensure the security of information resources; however, if employees and end-users of organisational information systems (IS) are not keen or are unwilling to follow security policies, then these efforts are in vain. Our study is informed by the literature on IS adoption, protection-motivation theory, deterrence theory, and organisational behaviour, and is motivated by the fundamental premise that the adoption of information security practices and policies is affected by organisational, environmental, and behavioural factors. We develop an Integrated Protection Motivation and Deterrence model of security policy compliance under the umbrella of Taylor-Todd's Decomposed Theory of Planned Behaviour. Furthermore, we evaluate the effect of organisational commitment on employee security compliance intentions. Finally, we empirically test the theoretical model with a data set representing the survey responses of 312 employees from 78 organisations. Our results suggest that (a) threat perceptions about the severity of breaches and response perceptions of response efficacy, self-efficacy, and response costs are likely to affect policy attitudes; (b) organisational commitment and social influence have a significant impact on compliance intentions; and (c) resource availability is a significant factor in enhancing self-efficacy, which in turn, is a significant predictor of policy compliance intentions. We find that employees in our sample underestimate the probability of security breaches. European Journal of Information Systems (2009) 18, 106-125. doi:10.1057/ejis.2009.6; published online 21 April 2009

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据