Theorizing the Behavioral Effects of Control Complementarity in Security Control Portfolios

被引:0
|
作者
Jeffrey D. Wall
Prashant Palvia
John D’Arcy
机构
[1] Michigan Technological University,College of Business
[2] The University of North Carolina at Greensboro,Bryan School of Business and Economics
[3] University of Delaware,Department of Accounting and Management Information Systems
来源
关键词
Control theory; Information security; Security behavior; Security controls;
D O I
暂无
中图分类号
学科分类号
摘要
Employees are a major cause of information security vulnerabilities and breaches. Organizations implement controls, such as information security policies, fear appeals, and computer monitoring, to manage the security threats that employees pose. Behavioral information security research seeks to understand how these security controls influence employees’ behaviors. In practice, organizations adopt many coexisting security controls in security control portfolios (SCPs). Unfortunately, the complexities of SCPs are not well understood in the information security literature. To assist in studying SCPs, we present a typology and a theoretical model of security control grounded in an extension of control theory. We identify twelve types of security controls that can exist in practice based on three important control dimensions. We develop a number of propositions to explain how the complementarity of security controls in SCPs affect motivation to protect information. Our efforts produce a behaviorally grounded extension of control theory that is well suited for studying individual-level security behavior governed by complex SCPs.
引用
收藏
页码:637 / 658
页数:21
相关论文
共 50 条
  • [1] Theorizing the Behavioral Effects of Control Complementarity in Security Control Portfolios
    Wall, Jeffrey D.
    Palvia, Prashant
    D'Arcy, John
    INFORMATION SYSTEMS FRONTIERS, 2022, 24 (02) : 637 - 658
  • [2] Management control as a system: Integrating and extending theorizing on MC complementarity and institutional logics
    Gerdin, Jonas
    MANAGEMENT ACCOUNTING RESEARCH, 2020, 49
  • [3] The complementarity of control formalization and control flexibility: The contingent effects of competitive turbulence
    Yang, Feifei
    Shinkle, George A.
    Goudsmit, Mirjam
    AUSTRALIAN JOURNAL OF MANAGEMENT, 2022, 47 (04) : 773 - 792
  • [4] Stage theorizing in behavioral information systems security research
    Siponen, Mikko
    PROCEEDINGS OF THE 57TH ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2024, : 4724 - 4733
  • [5] Impulsive Control of Portfolios
    Jan Palczewski
    Lukasz Stettner
    Applied Mathematics and Optimization, 2007, 56 : 67 - 103
  • [6] Impulsive control of portfolios
    Palczewski, Jan
    Stettner, Lukasz
    APPLIED MATHEMATICS AND OPTIMIZATION, 2007, 56 (01): : 67 - 103
  • [7] CONTROL OF BANK PORTFOLIOS AS AN INSTRUMENT OF MONETARY CONTROL
    Seltzer, Lawrence H.
    AMERICAN ECONOMIC REVIEW, 1952, 42 (02): : 236 - 246
  • [8] Inclusionary control? Theorizing the effects of penal voluntary organizations' work
    Tomczak, Philippa
    Thompson, David
    THEORETICAL CRIMINOLOGY, 2019, 23 (01) : 4 - 24
  • [9] Theorizing surveillance in crime control
    Haggerty, Kevin D.
    Wilson, Dean
    Smith, Gavin J. D.
    THEORETICAL CRIMINOLOGY, 2011, 15 (03) : 231 - 237
  • [10] OPTIMAL IMPULSE CONTROL OF PORTFOLIOS
    EASTHAM, JF
    HASTINGS, KJ
    MATHEMATICS OF OPERATIONS RESEARCH, 1988, 13 (04) : 588 - 605