Earticle

현재 위치 Home

Investigate the Roles of Sanctions, Psychological Capital, and Organizational Security Resources Factors in Information Security Policy Violation

첫 페이지 보기
  • 발행기관
    한국경영정보학회 바로가기
  • 간행물
    Asia Pacific Journal of Information Systems KCI 등재 SCOPUS 바로가기
  • 통권
    제33권 제4호 (2023.12)바로가기
  • 페이지
    pp.863-898
  • 저자
    Ayman Hasan Asfoor, Hairoladenan kasim, Aliza Binti Abdul Latif, Fiza Binti Abdul Rahim
  • 언어
    영어(ENG)
  • URL
    https://www.earticle.net/Article/A440264

※ 기관로그인 시 무료 이용이 가능합니다.

7,900원

원문정보

초록

영어
Previous studies have shown that insiders pose risks to the security of organisations’ secret information. Information security policy (ISP) intentional violation can jeopardise organisations. For years, ISP violations persist despite organisations’ best attempts to tackle the problem through security, education, training and awareness (SETA) programs and technology solutions. Stopping hacking attempts e.g., phishing relies on personnel’s behaviour. Therefore, it is crucial to consider employee behaviour when designing strategies to protect sensitive data. In this case, organisations should also focus on improving employee behaviour on security and creating positive security perceptions. This paper investigates the role of psychological capital (PsyCap), punishment and organisational security resources in influencing employee behaviour and ultimately reducing ISP violations. The model of the proposed study has been modified to investigate the connection between self-efficacy, resilience, optimism, hope, perceived sanction severity, perceived sanction certainty, security response effectiveness, security competence and ISP violation. The sample of the study includes 364 bank employees in Jordan who participated in a survey using a self-administered questionnaire. The findings show that the proposed approach acquired an acceptable fit with the data and 17 of 25 hypotheses were confirmed to be correct. Furthermore, the variables self-efficacy, resilience, security response efficacy, and protection motivation directly influence ISP violations, while perceived sanction severity and optimism indirectly influence ISP violations through protection motivation. Additionally, hope, perceived sanction certainty, and security skills have no effect on ISP infractions that are statistically significant. Finally, self-efficacy, resiliency, optimism, hope, perceived severity of sanctions, perceived certainty of sanctions, perceived effectiveness of security responses, and security competence have a substantial influence on protection motivation.

목차

ABSTRACT
Ⅰ. Introduction
Ⅱ. Literature Review
2.1. Information and Cyber Security
2.2. Human Behaviours
2.3. Related Work
2.4. Theory of Planned Behaviour (TPB)
2.5. General Deterrence Theory (GDT)
2.6. Psychological Capital (PsyCap)
2.7. Organizational Security Resources
Ⅲ. Research Model and Hypothesis Development
3.1. Related Variables and Assumptions on General Deterrence Theory (GDT)
3.2. Related Variables and Assumptions on Psychological Capital (PsyCap)
3.3. Related Variables and Assumptions on Organizational Security Resources
Ⅳ. Research Methodology
4.1. Research Method and Data Collection
4.2. Measurement
4.3. Measurement Model Assessment
4.4. Data Analysis and Results
4.5. Path Coefficient Analyses
4.6. Mediation Effect of Protection Motivation(Indirect)
Ⅴ. Discussion
5.1. Theoretical Contribution
5.2. Practical Implications
Ⅵ. Limitations and Future Research

키워드

Violation of Information Security Policy Psychological Capital Organizational Punishment Organizational Security Resource

저자

  • Ayman Hasan Asfoor [ Department of Information Technology, Faculty of Computer Science, Jubail Industrial College, Jubail Industrial, KSA ] Corresponding author
  • Hairoladenan kasim [ Department of Informatics, Faculty of Computer and Information Technology, Tanga Nasional University, Selangor, Malaysia ]
  • Aliza Binti Abdul Latif [ Department of Informatics, Faculty of Computer and Information Technology, Tanga Nasional University, Selangor, Malaysia ]
  • Fiza Binti Abdul Rahim [ Penyelaras Program, Fakulti Teknologi and Informatik Raza, Universiti Teknologi Malaysia, Kuala Lumpur, Malaysia ]

참고문헌

자료제공 : 네이버학술정보

간행물 정보

발행기관

  • 발행기관명
    한국경영정보학회 [The Korea Society of Management information Systems]
  • 설립연도
    1989
  • 분야
    사회과학>경영학
  • 소개
    이 학회는 경영정보학의 연구 및 교류를 촉진하고 학문의 발전과 응용에 공헌함을 목적으로 합니다.

간행물

  • 간행물명
    Asia Pacific Journal of Information Systems
  • 간기
    계간
  • pISSN
    2288-5404
  • eISSN
    2288-6818
  • 수록기간
    1990~2026
  • 등재여부
    KCI 등재,SCOPUS
  • 십진분류
    KDC 325 DDC 658

이 권호 내 다른 논문 / Asia Pacific Journal of Information Systems 제33권 제4호

    피인용수 : 0(자료제공 : 네이버학술정보)

    함께 이용한 논문 이 논문을 다운로드한 분들이 이용한 다른 논문입니다.

      페이지 저장