Earticle

금융회사의 고객정보보호에 대한 내부직원의 태도 연구
The Behavioral Attitude of Financial Firmsʼ Employees on the Customer Information Security in Korea

  • 간행물
    Asia Pacific Journal of Information Systems KCI 등재 바로가기
  • 권호(발행년)
    제22권 제1호 (2012.03) 바로가기
  • 페이지
    pp.53-77
  • 저자
    정우진, 신유형, 이상용
  • 언어
    한국어(KOR)
  • URL
    https://www.earticle.net/Article/A171032

원문정보

초록

영어
Financial firms, especially large scaled firms such as KB bank, NH bank, Samsung Card, Hana SK Card, Hyundai Capital, Shinhan Card, etc. should be securely dealing with the personal financial information. Indeed, people have tended to believe that those big financial companies are relatively safer in terms of information security than typical small and medium sized firms in other industries. However, the recent incidents of personal information privacy invasion showed that this may not be true. Financial firms have increased the investment of information protection and security, and they are trying to prevent the information privacy invasion accidents by doing all the necessary efforts. This paper studies how effectively a financial firm will be able to avoid personal financial information privacy invasion that may be deliberately caused by internal staffs. Although there are several literatures relating to information security, to our knowledge, this is the first study to focus on the behavior of internal staffs. The big financial firms are doing variety of information security activities to protect personal information. This study is to confirm what types of such activities actually work well. The primary research model of this paper is based on Theory of Planned Behavior (TPB) that describes the rational choice of human behavior. Also, a variety of activities to protect the personal information of financial firms, especially credit card companies with the most customer information, were modeled by the four-step process Security Action Cycle (SAC) that Straub and Welke (1998) claimed. Through this proposed conceptual research model, we study whether information security activities of each step could suppress personal information abuse. Also, by measuring the morality of internal staffs, we checked whether the act of information privacy invasion caused by internal staff is in fact a serious criminal behavior or just a kind of unethical behavior. In addition, we also checked whether there was the cognition difference of the moral level between internal staffs and the customers. Research subjects were customer call center operators in one of the big credit card company. We have used multiple regression analysis. Our results showed that the punishment of the remedy activities, among the firm's information security activities, had the most obvious effects of preventing the information abuse (or privacy invasion) by internal staff. Somewhat effective tools were the prevention activities that limited the physical accessibility of non-authorities to the system of customers’ personal information database. Some examples of the prevention activities are to make the procedure of access rights complex and to enhance security instrument. We also found that 'the unnecessary information searches out of work' as the behavior of information abuse occurred frequently by internal staffs. They perceived these behaviors somewhat minor criminal or just unethical action rather than a serious criminal behavior. Also, there existed the big cognition difference of the moral level between internal staffs and the public (customers). Based on the findings of our research, we should expect that this paper help practically to prevent privacy invasion and to protect personal information properly by raising the effectiveness of information security activities of finance firms. Also, we expect that our suggestions can be utilized to effectively improve personnel management and to cope with internal security threats in the overall information security management system.

목차

Abstract
 Ⅰ. 서론
 Ⅱ. 연구 배경
  2.1 금융회사의 정보보호체계
  2.2 계획된 행위이론(Theory of Planned Behavior)
  2.3 억제이론(Deterrence Theory)과 보안주기활동(Security Action Cycle2.3 억제이론(Deterrence Theory)과 보안 주기활동(Security Action Cycle))
 Ⅲ. 연구 모형과 가설
 Ⅳ. 연구방법 및 설계
 Ⅴ. 분석 및 결과
 Ⅵ. 결론
 References
  설문 문항
 About the Authors

저자

  • 정우진 [ Woo-Jin Jung | MS Student, School of Business, Hanyang University ]
  • 신유형 [ Yuhyung Shin | Assistant Professor, School of Business, Hanyang University ]
  • 이상용 [ Sang-Yong Tom Lee | Professor, School of Business, Hanyang University ] Corresponding Author

참고문헌

자료제공 : 네이버학술정보

    간행물 정보

    • 간행물
      Asia Pacific Journal of Information Systems
    • 간기
      계간
    • pISSN
      2288-5404
    • eISSN
      2288-6818
    • 수록기간
      1990~2026
    • 등재여부
      KCI 등재,SCOPUS
    • 십진분류
      KDC 325 DDC 658