PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
January 26, 2017Online Information Review85 citations

Why not comply with information security? An empirical approach for the causes of non-compliance

View Full Paper
IHInho HwangDKDaejin KimTKTaeha Kim

Key Points

Key points are not available for this paper at this time.

Abstract

Purpose The purpose of this paper is to empirically investigate the negative casual relationships between organizational security factors (security systems, security education, and security visibility) and individual non-compliance causes (work impediment, security system anxiety, and non-compliance behaviors of peers), which have negative influences on compliance intention. Design/methodology/approach Based on literature review, the authors propose a research model together with hypotheses. The survey questionnaires were developed to collect data, which then validated the measurement model. The authors collected 415 responses from employees at manufacturing and service firms that had already implemented security policies. The hypothesized relationships were tested using the structural equation model approach with AMOS 18.0. Findings Survey results validate that work impediment, security system anxiety, and non-compliance peer behaviors are the causes of employee non-compliance. In addition, the authors found that security systems, security education, and security visibility decrease instances of non-compliance. Research limitations/implications Organizations should establish a mixture of security investment in their systems, education, and visibility in order to effectively reduce employees’ non-compliance. In addition, organizations should recognize the importance of minimizing the particular causes of employees’ non-compliance to positively increase intentions to comply with information security. Originality/value An important issue in information security management is employee compliance. Understanding the reasons behind employees’ non-compliance is a critical issue. This paper investigates empirically why employees do not comply, and how organizations can induce employees to comply by a mixture of investments in security systems, education, and visibility.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Hwang et al. (2017) studied this question.

synapsesocial.com/papers/69d6ea1d639f29d8dcab3792https://doi.org/10.1108/oir-11-2015-0358
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Comparative fit indexes in structural models.1990 · 24,104 citations
  2. 2Social media strategies2011 · 20 citations
  3. 3Understanding User Evaluations of Information Systems1995 · 1,224 citations
  4. 4Information security management and modelling1999 · 42 citations
  5. 5Review of Psychometric theory (2nd ed.).1979 · 11,482 citations