Universal and Culture-dependent Employee Compliance of Information Systems Security Procedures

被引:11
|
作者
Karjalainen, Mari [1 ]
Siponen, Mikko [2 ]
Puhakainen, Petri [3 ]
Sarker, Suprateek [4 ]
机构
[1] Univ Oulu, Fac Informat Technol & Elect Engn, Oulu, Finland
[2] Univ Jyvaskyla, Res Fac Informat Technol, Jyvaskyla, Finland
[3] Prime Ministers Off, Helsinki, Finland
[4] Univ Virginia, McIntire Sch Commerce, Charlottesville, VA 22904 USA
基金
芬兰科学院;
关键词
Information systems security behavior; national culture; qualitative study; CYBERSECURITY ISSUES; VALUES; IMPACT; TECHNOLOGIES; BEHAVIORS; STYLES; US;
D O I
10.1080/1097198X.2019.1701355
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Employee information systems security behavior (ISSB) is a key concern for organizations. Previous studies have proposed models aimed at explaining employees' ISSB and related behavioral change. While these studies have contributed to our understanding of the reasons for ISSB (change), there is a lack of research related to cultural differences and distinguishing cultural-specific reasons for ISSB. This paper takes the first step in addressing this research gap by theorizing about employee ISSB based on empirical material collected in Finland, Switzerland, the UAE, and China. This paper suggests that ISSB constitute a learned information systems security (ISS) conventions that may be somewhat generic across different cultures; however, different paradigms of learning seem to be effective in different cultures for supporting behavioral change. From a theoretical perspective, the results help us to understand why employees comply or do not comply with ISS procedures. This study also highlights the need for future research on employee compliance to understand cultural differences regarding key ISS interventions. Finally, from a managerial perspective, the theory suggests that different cultures require different ISS interventions.
引用
收藏
页码:5 / 24
页数:20
相关论文
共 50 条
  • [41] Neutralization: New insights into the problem of employee information systems security policy violations
    Siponen M.
    Vance A.
    MIS Quarterly: Management Information Systems, 2010, 34 (SPEC. ISSUE 3): : 487 - 502
  • [42] Constructing Conceptual Model for Security Culture in Health Information Systems Security Effectiveness
    Shahri, Ahmad Bakhtiyari
    Ismail, Zuraini
    Ab Rahim, Nor Zairah
    ADVANCES IN INFORMATION SYSTEMS AND TECHNOLOGIES, 2013, 206 : 213 - 220
  • [43] The Dark Side of Leadership in Information Systems Security: A Model of the Effect of Manager Transgressions on Employee Security Behaviors
    Wall, Jeffrey D.
    Iyer, Lakshmi S.
    AMCIS 2012 PROCEEDINGS, 2012,
  • [44] Information Security Culture: A General Living Systems Theory Perspective
    Reid, Rayne
    Van Niekerk, Johan
    Renaud, Karen
    2014 INFORMATION SECURITY FOR SOUTH AFRICA (ISSA), 2014,
  • [45] Factors influencing employee compliance with information security policies: a systematic literature review of behavioral and technological aspects in cybersecurity
    Delso-Vicente, Alberto-Tomas
    Diaz-Marcos, Luis
    Aguado-Tevar, Oscar
    de Blanes-Sebastian, Maria Garcia
    FUTURE BUSINESS JOURNAL, 2025, 11 (01)
  • [46] Integrating Information Security Culture and Protection Motivation to Enhance Compliance with Information Security Policies in Banking: Evidence from PLS-SEM and fsQCA
    Alrawhani, Ebrahim Mohammed
    Romli, Awanis Binti
    Al-Sharafi, Mohammed A.
    Alkawsi, Gamal
    INTERNATIONAL JOURNAL OF HUMAN-COMPUTER INTERACTION, 2025,
  • [47] The determinants of an information security policy compliance culture in organisations: the combined effects of organisational and behavioural factors
    Amankwa, Eric
    Loock, Marianne
    Kritzinger, Elmarie
    INFORMATION AND COMPUTER SECURITY, 2022, 30 (04) : 583 - 614
  • [48] Information systems security policy compliance: An empirical study of the effects of socialisation, influence, and cognition
    Ifinedo, Princely
    INFORMATION & MANAGEMENT, 2014, 51 (01) : 69 - 79
  • [49] Investigating Continuous Security Compliance Behavior: Insights from Information Systems Continuance Model
    Abed, Javad
    Dhillon, Gurpreet
    Ozkan, Sevgi
    AMCIS 2016 PROCEEDINGS, 2016,
  • [50] Improving employees' compliance through information systems security training: An action research study
    Puhakainen P.
    Siponen M.
    MIS Quarterly: Management Information Systems, 2010, 34 (04): : 757 - 778