The effect of perceived organizational culture on employees' information security compliance

被引:8
|
作者
Karlsson, Martin [1 ]
Karlsson, Fredrik [2 ]
Astrom, Joachim [1 ]
Denk, Thomas [1 ]
机构
[1] Orebro Univ, Dept Polit Sci, Orebro, Sweden
[2] Orebro Univ, Dept Informat, CERIS, Orebro, Sweden
关键词
Organizational culture; Information security policy compliance; Competing values framework; Information security policy; Information security culture; Bureaucratic culture; COMPETING-VALUES; PROTECTION MOTIVATION; POLICY COMPLIANCE; SYSTEMS MISUSE; DETERRENCE; FRAMEWORK; IMPLEMENTATION; MANAGEMENT; AWARENESS; INSIGHTS;
D O I
10.1108/ICS-06-2021-0073
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose This paper aims to investigate the connection between different perceived organizational cultures and information security policy compliance among white-collar workers. Design/methodology/approach The survey using the Organizational Culture Assessment Instrument was sent to white-collar workers in Sweden (n = 674), asking about compliance with information security policies. The survey instrument is an operationalization of the Competing Values Framework that distinguishes between four different types of organizational culture: clan, adhocracy, market and bureaucracy. Findings The results indicate that organizational cultures with an internal focus are positively related to employees' information security policy compliance. Differences in organizational culture with regards to control and flexibility seem to have less effect. The analysis shows that a bureaucratic form of organizational culture is most fruitful for fostering employees' information security policy compliance. Research limitations/implications The results suggest that differences in organizational culture are important for employees' information security policy compliance. This justifies further investigating the mechanisms linking organizational culture to information security compliance. Practical implications Practitioners should be aware that the different organizational cultures do matter for employees' information security compliance. In businesses and the public sector, the authors see a development toward customer orientation and marketization, i.e. the opposite an internal focus, that may have negative ramifications for the information security of organizations. Originality/value Few information security policy compliance studies exist on the consequences of different organizational/information cultures.
引用
收藏
页码:382 / 401
页数:20
相关论文
共 50 条
  • [1] The Influence of Organizational Enforcement on the Attitudes of Employees towards Information Security Compliance
    AlKalbani, Ahmed
    Deng, Hepu
    Kam, Booi
    2019 10TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS (ICICS), 2019, : 152 - 158
  • [2] Motivating Information Security Policy Compliance: Insights from Perceived Organizational Formalization
    Hong, Yuxiang
    Furnell, Steven
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2022, 62 (01) : 19 - 28
  • [3] Perceived National Culture and Perceived Organizational Support Effect on Transgender Employees Job Satisfaction
    Yousuf, Adnan
    Khan, Naveed R.
    Khan, Mustafa Rehman
    Ali, Akhtiar
    Shaikh, Sarfaraz Ahmed
    EMPLOYEE RESPONSIBILITIES AND RIGHTS JOURNAL, 2022, 34 (04) : 487 - 513
  • [4] Perceived National Culture and Perceived Organizational Support Effect on Transgender Employees Job Satisfaction
    Adnan Yousuf
    Naveed R. Khan
    Mustafa Rehman Khan
    Akhtiar Ali
    Sarfaraz Ahmed Shaikh
    Employee Responsibilities and Rights Journal, 2022, 34 : 487 - 513
  • [5] The Effect of Employees' Perceived Organizational Fit on Organizational Myopia
    Uysal, H. Tezcan
    Aydemir, Sibel
    INTERNATIONAL JOURNAL OF BUSINESS, 2022, 27 (01):
  • [6] The Effect of Employee Competency and Organizational Culture on Employees' Perceived Stress for Better Workplace
    Kim, Jina
    Jung, Hye-Sun
    INTERNATIONAL JOURNAL OF ENVIRONMENTAL RESEARCH AND PUBLIC HEALTH, 2022, 19 (08)
  • [7] Organizational power and information security rule compliance
    Kolkowska, Ella
    Dhillon, Gurpreet
    COMPUTERS & SECURITY, 2013, 33 : 3 - 11
  • [8] Organizational Power and Information Security Rule Compliance
    Kolkowska, Ella
    Dhillon, Gurpreet
    FUTURE CHALLENGES IN SECURITY AND PRIVACY FOR ACADEMIA AND INDUSTRY, 2011, 354 : 185 - +
  • [9] Ensuring employees' information security policy compliance by carrot and stick: the moderating roles of organizational commitment and gender
    Liu, Chenhui
    Liang, Huigang
    Wang, Nengmin
    Xue, Yajiong
    INFORMATION TECHNOLOGY & PEOPLE, 2022, 35 (02) : 802 - 834
  • [10] Readability as lever for employees' compliance with information security policies
    Ammann, Franz-Emst
    Sowa, Aleksandra
    ISACA Journal, 2013, 4 : 39 - 42