Author:
Yuryna Connolly Lena,Lang Michael,Gathegi John,Tygar Doug J.
Abstract
Purpose
This paper provides new insights about security behaviour in selected US and Irish organisations by investigating how organisational culture and procedural security countermeasures tend to influence employee security actions. An increasing number of information security breaches in organisations presents a serious threat to the confidentiality of personal and commercially sensitive data. While recent research shows that humans are the weakest link in the security chain and the root cause of a great portion of security breaches, the extant security literature tends to focus on technical issues.
Design/methodology/approach
This paper builds on general deterrence theory and prior organisational culture literature. The methodology adapted for this study draws on the analytical grounded theory approach employing a constant comparative method.
Findings
This paper demonstrates that procedural security countermeasures and organisational culture tend to affect security behaviour in organisational settings.
Research limitations/implications
This paper fills the void in information security research and takes its place among the very few studies that focus on behavioural as opposed to technical issues.
Practical implications
This paper highlights the important role of procedural security countermeasures, information security awareness and organisational culture in managing illicit behaviour of employees.
Originality/value
This study extends general deterrence theory in a novel way by including information security awareness in the research model and by investigating both negative and positive behaviours.
Subject
Management of Technology and Innovation,Information Systems and Management,Computer Networks and Communications,Information Systems,Software,Management Information Systems
Reference57 articles.
1. A qualitative study of users’ view on information security;Computers & Security,2007
2. A situated cultural approach for cross-cultural studies in IS;Journal of Enterprise Information Management,2009
3. Managing organizational culture;Management Review,1980
4. Don’t make excuses! discouraging neutralization to reduce IT policy violation;Computers & Security,2013
5. Deterrence and incapacitation: estimating the effects of criminal sanctions on crime rates,1978
Cited by
41 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献