Information security policy compliance model in organizations

The Internet and information technology have influenced human life significantly. However, information security is still an important concern for both users and organizations. Technology cannot solely guarantee a secure environment for information; the human aspects of information security should be...

Full description

Bibliographic Details
Main Author: Sohrabi Safa, N.
Format: Article
Language:English
Published: Elsevier 2016
Subjects:
Online Access:http://eprints.um.edu.my/15147/1/Information_security_policy_compliance_model_in_organizations.pdf
_version_ 1825720640515080192
author Sohrabi Safa, N.
author_facet Sohrabi Safa, N.
author_sort Sohrabi Safa, N.
collection UM
description The Internet and information technology have influenced human life significantly. However, information security is still an important concern for both users and organizations. Technology cannot solely guarantee a secure environment for information; the human aspects of information security should be taken into consideration, besides the technological aspects. The lack of information security awareness, ignorance, negligence, apathy, mischief, and resistance are the root of users' mistakes. In this research, a novel model shows how complying with organizational information security policies shapes and mitigates the risk of employees' behaviour. The significant aspect of this research is derived from the conceptualization of different aspects of involvement, such as information security knowledge sharing, collaboration, intervention and experience, as well as attachment, commitment, and personal norms that are important elements in the Social Bond Theory. The results of the data analysis revealed that information security knowledge sharing, collaboration, intervention and experience all have a significant effect on employees' attitude towards compliance with organizational information security policies. However, attachment does not have a significant effect on employees' attitude towards information security policy compliance. In addition, the findings have shown that commitment and personal norms affect employees' attitude. Attitude towards compliance with information security organizational policies also has a significant effect on the behavioural intention regarding information security compliance.
first_indexed 2024-03-06T05:38:11Z
format Article
id um.eprints-15147
institution Universiti Malaya
language English
last_indexed 2024-03-06T05:38:11Z
publishDate 2016
publisher Elsevier
record_format dspace
spelling um.eprints-151472015-12-22T00:41:17Z http://eprints.um.edu.my/15147/ Information security policy compliance model in organizations Sohrabi Safa, N. Information services. Information centers The Internet and information technology have influenced human life significantly. However, information security is still an important concern for both users and organizations. Technology cannot solely guarantee a secure environment for information; the human aspects of information security should be taken into consideration, besides the technological aspects. The lack of information security awareness, ignorance, negligence, apathy, mischief, and resistance are the root of users' mistakes. In this research, a novel model shows how complying with organizational information security policies shapes and mitigates the risk of employees' behaviour. The significant aspect of this research is derived from the conceptualization of different aspects of involvement, such as information security knowledge sharing, collaboration, intervention and experience, as well as attachment, commitment, and personal norms that are important elements in the Social Bond Theory. The results of the data analysis revealed that information security knowledge sharing, collaboration, intervention and experience all have a significant effect on employees' attitude towards compliance with organizational information security policies. However, attachment does not have a significant effect on employees' attitude towards information security policy compliance. In addition, the findings have shown that commitment and personal norms affect employees' attitude. Attitude towards compliance with information security organizational policies also has a significant effect on the behavioural intention regarding information security compliance. Elsevier 2016 Article PeerReviewed application/pdf en http://eprints.um.edu.my/15147/1/Information_security_policy_compliance_model_in_organizations.pdf Sohrabi Safa, N. (2016) Information security policy compliance model in organizations. Computers & Security, 56 (1). pp. 70-82. ISSN 0167-4048, DOI https://doi.org/10.1016/j.cose.2015.10.006 <https://doi.org/10.1016/j.cose.2015.10.006>. http://www.sciencedirect.com/science/article/pii/S0167404815001583 http://dx.doi.org/10.1016/j.cose.2015.10.006
spellingShingle Information services. Information centers
Sohrabi Safa, N.
Information security policy compliance model in organizations
title Information security policy compliance model in organizations
title_full Information security policy compliance model in organizations
title_fullStr Information security policy compliance model in organizations
title_full_unstemmed Information security policy compliance model in organizations
title_short Information security policy compliance model in organizations
title_sort information security policy compliance model in organizations
topic Information services. Information centers
url http://eprints.um.edu.my/15147/1/Information_security_policy_compliance_model_in_organizations.pdf
work_keys_str_mv AT sohrabisafan informationsecuritypolicycompliancemodelinorganizations