بررسی تأثیر عوامل بازدارنده در برابر امنیت سیستم های اطلاعاتی
ترجمه نشده

بررسی تأثیر عوامل بازدارنده در برابر امنیت سیستم های اطلاعاتی

عنوان فارسی مقاله: بررسی تأثیر عوامل بازدارنده و معیارهای مقاومت در برابر امنیت سیستم های اطلاعاتی
عنوان انگلیسی مقاله: Examining the impact of deterrence factors and norms on resistance to Information Systems Security
مجله/کنفرانس: کامپیوترها در رفتار انسان - Computers in Human Behavior
رشته های تحصیلی مرتبط: مهندسی کامپیوتر، مهندسی فناوری اطلاعات
گرایش های تحصیلی مرتبط: امنیت اطلاعات، مدیریت سیستم های اطلاعاتی
کلمات کلیدی فارسی: مقاومت به امنیت سیستم های اطلاعاتی، سیاست های امنیتی اطلاعات، معیارهای اخلاقی، مجازات های سازمان
کلمات کلیدی انگلیسی: Resistance to information systems security، Information security policies، Moral norms، Organizational punishment
نوع نگارش مقاله: مقاله پژوهشی (Research Article)
شناسه دیجیتال (DOI): https://doi.org/10.1016/j.chb.2018.10.031
دانشگاه: Department of Decision Sciences, Judd Leighton School of Business & Economics, Indiana University South Bend, South Bend, IN, USA
صفحات مقاله انگلیسی: 26
ناشر: الزویر - Elsevier
نوع ارائه مقاله: ژورنال
نوع مقاله: ISI
سال انتشار مقاله: 2019
ایمپکت فاکتور: 4/198 در سال 2017
شاخص H_index: 123 در سال 2019
شاخص SJR: 1/555 در سال 2017
شناسه ISSN: 0747-5632
شاخص Quartile (چارک): Q1 در سال 2017
فرمت مقاله انگلیسی: PDF
وضعیت ترجمه: ترجمه نشده است
قیمت مقاله انگلیسی: رایگان
آیا این مقاله بیس است: بله
کد محصول: E10984
فهرست مطالب (انگلیسی)

Abstract

1- Introduction

2- Literature review

3- Theoretical background and research hypotheses

4- Methodology

5- Data analysis and results

6- Discussion

7- Implications

8- Limitations and future research

9- Conclusion

References

بخشی از مقاله (انگلیسی)

Abstract

Numerous studies have found that employees are the principal source of adverse Information Systems Security (ISS) incidents in organizational settings. Consequently, the ISS research focuses on examining factors that affect employees' behaviour towards complying with ISS policy. Most of this research, based on the theory of reasoned action, considers that employees' intention to comply with ISS policies is a good predictor of their behaviour. This paper argues that the employees' compliance with ISS policies within organizations is usually enforced, and that the non-compliance is mainly due to the resistance towards these policies. This research examines the role of organizational punishment and organizational norms in impacting employees' resistance towards the ISS policies. The data were collected from 133 employees of 10 organizations spanning four industries and the hypotheses were tested and validated using PLS-SEM analytical procedures. The results show that moral and descriptive norms are useful in reducing the resistance.

Introduction

Several studies report that the increasing violations of Information Systems Security (ISS) policies result in a wide range of negative consequences for organizations, such as data loss or theft, computer intrusions, and privacy breaches (Ernst & Young, 2011; Ponemon Institute, 2016; Ponemon, 2017). A recent study by the Ponemon Institute found that nearly 90 percent of healthcare organizations represented in their study had experienced at least one data breach in the two years period (Ponemon Institute, 2016). Researchers have agreed that, very often, the end users are the weakest link in ensuring ISS in organizations (Kolkowska et al., 2017; Merhi & Ahluwalia, 2014; Moody et al., 2018; Safa & Von Solms, 2016). Numerous studies also show that employees’ behaviour remains a major challenge for successfully implementing strict ISS policies in organizations. In a survey of IT security practitioners, nearly 56% of the participants attributed employees’ resistance to comply with ISS policies as the biggest barrier to implementing effective security strategies in their organizations (Ponemon Institute, 2016). Likewise, in the “Global State of IS Survey 2018,” PWC found that employees’ actions remain the foremost cause of ISS incidents in organizations (PWC, 2017). Accordingly, the ISS research has focused on studying employee behaviour in the context of the compliance of ISS policies (Bulgurcu et al., 2010; Hwang & Cha, 2018; Merhi & Ahluwalia, 2013; Merhi & Midha, 2012).