Abstract
PurposeThe aim of this study was to explore the organizational and social prerequisites for employees' participative and rule-compliant information security behaviour in Swedish nuclear power production and its related industry. These industries are high-risk activities that must be meticulously secured. Protecting the information security in the related organizations is an essential aspect of this.Design/methodology/approachIndividual in-depth interviews were conducted with 24 employees in two organizations within the nuclear power industry in Sweden.FindingsWe found that prerequisites for employees' participative and rule-compliant information security behaviour could be categorized into structural, social and individual aspects. Structural aspects included well-adapted rules, knowledge support and resources. Social aspects included a supportive organizational culture, collaboration and adequate resources, and individual aspects included individual responsibility.Originality/valueThe qualitative approach of the study provided comprehensive descriptions of the identified preconditions. The results may thus enable organizations to better promote conditions important for information security in a high-risk industry.
Reference51 articles.
1. A framework of information security integrated with human factors,2019
2. Information security culture: a behaviour compliance conceptual framework,2010
3. Managing major accident risk: concerns about complacency and complexity in practice;Safety Science,2017
4. CISOs and organisational culture: their own worst enemy?;Computers and Security,2013
5. Productive security: a scalable methodology for analysing employee security behaviours,2016
Cited by
3 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Cybersecurity Risk;Transformational Interventions for Business, Technology, and Healthcare;2023-10-16
2. The Ways to Improve Nuclear Cybersecurity for Zero Emission;Circular Economy and the Energy Market;2022
3. Value conflicts and information security – a mixed-methods study in high-risk industry;Information & Computer Security;2021-12-21