首页> 外文期刊>European journal of information systems >If someone is watching, I'll do what I'm asked: mandatoriness, control, and information security
【24h】

If someone is watching, I'll do what I'm asked: mandatoriness, control, and information security

机译:如果有人在看,我会被问到:强制性,控制力和信息安全性

获取原文
获取原文并翻译 | 示例
       

摘要

Information security has become increasingly important to organizations. Despite the prevalence of technical security measures, individual employees remain the key link - and frequently the weakest link - in corporate defenses. When individuals choose to disregard security policies and procedures, the organization is at risk. How, then, can organizations motivate their employees to follow security guidelines? Using an organizational control lens, we build a model to explain individual information security precaution-taking behavior. Specific hypotheses are developed and tested using a field survey. We examine elements of control and introduce the concept of 'mandatoriness,' which we define as the degree to which individuals perceive that compliance with existing security policies and procedures is compulsory or expected by organizational management. We find that the acts of specifying policies and evaluating behaviors are effective in convincing individuals that security policies are mandatory. The perception of mandatoriness is effective in motivating individuals to take security precautions, thus if individuals believe that management watches, they will comply.
机译:信息安全对组织而言变得越来越重要。尽管采用了广泛的技术安全措施,但个人雇员仍然是公司防御中的关键环节,而且通常是最薄弱的环节。当个人选择不考虑安全策略和程序时,组织将面临风险。那么,组织如何才能激励其员工遵循安全准则?使用组织控制镜头,我们建立了一个模型来解释个人信息安全预防措施的行为。使用现场调查来制定和检验特定的假设。我们研究了控制要素,并引入了“强制性”概念,我们将其定义为个人认为组织管理必须或期望遵守现有安全策略和程序的程度。我们发现,指定策略和评估行为的行为可以有效地说服个人安全策略是强制性的。强制性的观念可以有效地激励个人采取安全预防措施,因此,如果个人认为管理层注意,他们就会遵守。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号