Information Security Compliance in Organizations: An Institutional Perspective

被引:0
|
作者
AlKalbani A. [2 ]
Deng H. [2 ]
Kam B. [2 ]
Zhang X. [1 ]
机构
[1] School of Information Management, Wuhan University, Wuhan
[2] School of Business Information Technology and Logistics, RMIT University, Melbourne
基金
中国国家自然科学基金;
关键词
empirical study; information security; information security compliance; institutional pressures; management support;
D O I
10.1515/dim-2017-0006
中图分类号
学科分类号
摘要
The increasing recognition of the importance of information security has created institutional pressures on organizations to comply with information security standards and policies for protecting their information. How such pressures influence information security compliance in organisations, however, is unclear. This paper presents an empirical study to investigate the impact of institutional pressures on information security compliance in organizations. With the use of structural equation modelling for analysing the data collected through an online survey, the study shows that coercive pressures, normative pressures, and mimetic pressures positively influence information security compliance in organizations. It reveals that the benefits of information security compliance motivate management to strengthen their commitments at information security compliance. Furthermore, the study finds out that social pressures do not have a significant impact on management commitments towards information security compliance. Theoretically this study contributes to the information security research by better understanding how institutional pressures can be used for enhancing information security compliance in organizations. Practically this study informs information security policy makers of the major institutional drivers for information security compliance. © 2017 © 2017 Ahmed AlKalbani et al.
引用
收藏
页码:104 / 114
页数:10
相关论文
共 50 条
  • [1] Reducing fraud in organizations through information security policy compliance: An information security controls perspective
    Brown D.
    Batra G.
    Zafar H.
    Saeed K.
    Computers and Security, 2024, 144
  • [2] Information security policy compliance model in organizations
    Safa, Nader Sohrabi
    Von Solms, Rossouw
    Furnell, Steven
    COMPUTERS & SECURITY, 2016, 56 : 70 - 82
  • [3] Establishing information security policy compliance culture in organizations
    Amankwa, Eric
    Loock, Marianne
    Kritzinger, Elmarie
    INFORMATION AND COMPUTER SECURITY, 2018, 26 (04) : 420 - 436
  • [4] Organizations' Information Security Policy Compliance: Stick or Carrot Approach?
    Chen, Yan
    Ramamurthy, K.
    Wen, Kuang-Wei
    JOURNAL OF MANAGEMENT INFORMATION SYSTEMS, 2012, 29 (03) : 157 - 188
  • [5] Information security governance practices in critical infrastructure organizations: A socio-technical and institutional logic perspective
    Williams, Susan P.
    Hardy, Catherine A.
    Holgate, Janine A.
    ELECTRONIC MARKETS, 2013, 23 (04) : 341 - 354
  • [6] Information security governance practices in critical infrastructure organizations: A socio-technical and institutional logic perspective
    Susan P. Williams
    Catherine A. Hardy
    Janine A. Holgate
    Electronic Markets, 2013, 23 : 341 - 354
  • [7] The Influence of Institutional Forces on Employee Compliance with Information Security Policies
    Hou, Ye
    Gao, Ping
    Heeks, Richard
    WOSIS 2011: SECURITY IN INFORMATION SYSTEMS, 2011, : 132 - 141
  • [8] Information Systems Security Training in Organizations: Andragogical Perspective
    Offor, Patrick I.
    Tejay, Gurvirender
    AMCIS 2014 PROCEEDINGS, 2014,
  • [9] Employees' information security policy compliance: A norm activation perspective
    Yazdanmehr, Adel
    Wang, Jingguo
    DECISION SUPPORT SYSTEMS, 2016, 92 : 36 - 46
  • [10] Regulatory Compliance to Ensure Information Security: Financial Supervision Perspective
    Kull, Andro
    PROCEEDINGS OF THE 10TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2011, : 298 - 306