Theorizing the Behavioral Effects of Control Complementarity in Security Control Portfolios

被引:0
|
作者
Jeffrey D. Wall
Prashant Palvia
John D’Arcy
机构
[1] Michigan Technological University,College of Business
[2] The University of North Carolina at Greensboro,Bryan School of Business and Economics
[3] University of Delaware,Department of Accounting and Management Information Systems
来源
关键词
Control theory; Information security; Security behavior; Security controls;
D O I
暂无
中图分类号
学科分类号
摘要
Employees are a major cause of information security vulnerabilities and breaches. Organizations implement controls, such as information security policies, fear appeals, and computer monitoring, to manage the security threats that employees pose. Behavioral information security research seeks to understand how these security controls influence employees’ behaviors. In practice, organizations adopt many coexisting security controls in security control portfolios (SCPs). Unfortunately, the complexities of SCPs are not well understood in the information security literature. To assist in studying SCPs, we present a typology and a theoretical model of security control grounded in an extension of control theory. We identify twelve types of security controls that can exist in practice based on three important control dimensions. We develop a number of propositions to explain how the complementarity of security controls in SCPs affect motivation to protect information. Our efforts produce a behaviorally grounded extension of control theory that is well suited for studying individual-level security behavior governed by complex SCPs.
引用
收藏
页码:637 / 658
页数:21
相关论文
共 50 条