The effect of perceived organizational culture on employees' information security compliance

被引:8
|
作者
Karlsson, Martin [1 ]
Karlsson, Fredrik [2 ]
Astrom, Joachim [1 ]
Denk, Thomas [1 ]
机构
[1] Orebro Univ, Dept Polit Sci, Orebro, Sweden
[2] Orebro Univ, Dept Informat, CERIS, Orebro, Sweden
关键词
Organizational culture; Information security policy compliance; Competing values framework; Information security policy; Information security culture; Bureaucratic culture; COMPETING-VALUES; PROTECTION MOTIVATION; POLICY COMPLIANCE; SYSTEMS MISUSE; DETERRENCE; FRAMEWORK; IMPLEMENTATION; MANAGEMENT; AWARENESS; INSIGHTS;
D O I
10.1108/ICS-06-2021-0073
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose This paper aims to investigate the connection between different perceived organizational cultures and information security policy compliance among white-collar workers. Design/methodology/approach The survey using the Organizational Culture Assessment Instrument was sent to white-collar workers in Sweden (n = 674), asking about compliance with information security policies. The survey instrument is an operationalization of the Competing Values Framework that distinguishes between four different types of organizational culture: clan, adhocracy, market and bureaucracy. Findings The results indicate that organizational cultures with an internal focus are positively related to employees' information security policy compliance. Differences in organizational culture with regards to control and flexibility seem to have less effect. The analysis shows that a bureaucratic form of organizational culture is most fruitful for fostering employees' information security policy compliance. Research limitations/implications The results suggest that differences in organizational culture are important for employees' information security policy compliance. This justifies further investigating the mechanisms linking organizational culture to information security compliance. Practical implications Practitioners should be aware that the different organizational cultures do matter for employees' information security compliance. In businesses and the public sector, the authors see a development toward customer orientation and marketization, i.e. the opposite an internal focus, that may have negative ramifications for the information security of organizations. Originality/value Few information security policy compliance studies exist on the consequences of different organizational/information cultures.
引用
收藏
页码:382 / 401
页数:20
相关论文
共 50 条
  • [21] An Empirical Investigation of the Role of Culture on Employees' Information Systems Security Policy Compliance: Developing Economy Context
    Arage, Tilahun M.
    Belanger, France
    Tesema, Tibebe B.
    AMCIS 2016 PROCEEDINGS, 2016,
  • [22] THE INFLUENCE OF ORGANIZATIONAL CULTURE AND ORGANIZATIONAL JUSTICE ON GROUP COHESION AS PERCEIVED BY MERGER AND ACQUISITION EMPLOYEES
    Ismail, Maimunah
    Baki, Nordahlia Umar
    Omar, Zoharah
    ORGANIZATIONS AND MARKETS IN EMERGING ECONOMIES, 2018, 9 (02) : 233 - 250
  • [23] Impact of Organizational Culture to Information Security Triad
    Sari, Puspita Kencana
    Deniharza, Rully Satriawan
    PROCEEDINGS OF THE 3RD INTERNATIONAL SEMINAR AND CONFERENCE ON LEARNING ORGANIZATION (ISCLO-15), 2016, 45
  • [24] Exploring organizational culture for information security management
    Chang, Shuchih Ernest
    Lin, Chin-Shien
    INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2007, 107 (3-4) : 438 - 458
  • [25] Information Security Culture Dimensions in Information Security Policy Compliance Study: A Review
    Nasir, Akhyari
    Arshah, Ruzaini Abdullah
    ADVANCED SCIENCE LETTERS, 2018, 24 (02) : 943 - 946
  • [26] Mitigating the Harmful Effect of Perceived Organizational Compliance on Trust in Top Management: Buffering Roles of Employees' Personal Resources
    De Clercq, Dirk
    Bouckenooghe, Dave
    JOURNAL OF PSYCHOLOGY, 2019, 153 (02): : 187 - 213
  • [27] The impacts of organizational culture on information security culture: a case study
    Mincong Tang
    Meng’gang Li
    Tao Zhang
    Information Technology and Management, 2016, 17 : 179 - 186
  • [28] The impacts of organizational culture on information security culture: a case study
    Tang, Mincong
    Li, Meng'gang
    Zhang, Tao
    INFORMATION TECHNOLOGY & MANAGEMENT, 2016, 17 (02): : 179 - 186
  • [29] Deriving the Relationship between Organizational Culture and Information Security Culture
    Hassan, Noor Hafizah
    Ismail, Zuraini
    VISION 2020: INNOVATION, DEVELOPMENT SUSTAINABILITY, AND ECONOMIC GROWTH, VOLS 1-3, 2013, : 926 - 932
  • [30] An exploration of research information security data affecting organizational compliance
    De Matas, Sweden S.
    Keegan, Brendan P.
    DATA IN BRIEF, 2018, 21 : 1864 - 1871