首页> 外文会议>International conference on information systems (ICIS 2007) >The Last Line of Defense: Motivating Employees to Follow Corporate Security Guidelines
【24h】

The Last Line of Defense: Motivating Employees to Follow Corporate Security Guidelines

机译:最后一道防线:激励员工遵守公司安全准则

获取原文

摘要

Information security has become increasingly important to organizations. Despite the prevalence of technical security measures, individual employees remain the last line - and frequently the weakest link - in corporate defenses. When individuals choose to disregard security policies and procedures, the organization is at risk. How, then, can organizations motivate their employees to follow security guidelines? Using an organizational control lens, we build a model to explain individual information security precaution-taking behavior. Specific hypotheses are developed and tested using a field survey. We examine elements of control and introduce the concept of "mandatoriness" which we define as the degree to which individuals perceive that compliance with existing security policies and procedures is compulsory or expected by organizational management. We find that the acts of specifying policies and evaluating behaviors are effective in convincing individuals that security policies are mandatory. The perception of mandatoriness is effective in motivating individuals to take security precautions.
机译:信息安全对组织而言变得越来越重要。尽管普遍采用了技术安全措施,但个人雇员仍然是公司防御中的最后一道,通常是最薄弱的一环。当个人选择不考虑安全策略和程序时,组织将面临风险。那么,组织如何才能激励其员工遵循安全准则?使用组织控制的角度,我们建立了一个模型来解释个人信息安全预防措施的行为。使用现场调查来开发和检验特定的假设。我们研究了控制要素,并引入了“强制性”概念,我们将其定义为个人认为组织管理必须或期望遵守现有安全策略和程序的程度。我们发现,指定策略和评估行为的行为可以有效地说服个人安全策略是强制性的。强制性的观念可以有效地激发个人采取安全预防措施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号