Reducing fraud in organizations through information security policy compliance: An information security controls perspective

被引:1
|
作者
Brown, Dennis [1 ]
Batra, Gunjan [1 ]
Zafar, Humayun [1 ]
Saeed, Khawaja [1 ]
机构
[1] Kennesaw State Univ, Kennesaw, GA 30144 USA
关键词
Information security control proficiency; Information security policy quality; Information security; Enforcement; Computer based occupational fraud; Information security policy compliance; PROTECTION MOTIVATION; SYSTEMS SECURITY; BEHAVIORAL-RESEARCH; FEAR APPEALS; DETERRENCE; MANAGEMENT; NEUTRALIZATION; INTENTIONS; AWARENESS; INSIGHTS;
D O I
10.1016/j.cose.2024.103958
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As more business processes and information assets are digitized, computer resources are increasingly being misused to perpetrate fraudulent activities. Research shows that fraud committed by (or with) trusted insiders (called occupational fraud or internal organizational fraud) is responsible for significantly more damage than that committed by external actors (for example, cyber fraud). Current fraud research has primarily focused on the person perpetuating the fraud instead of the internal mechanisms organizations can employ in reducing fraud. The study examines the relationship between compliance with organizations' technology controls (primarily focused on information security) and its impact on computer-based occupational fraud. Based on general deterrence and fraud triangle theories, the study proposes information security control proficiency (ISCP) modeled as an integration of the quality of information security policy and its enforcement as a key factor that influences information security policy compliance. We further postulate that compliance with information security policy mediates the relationship between information security control proficiency and computer-basedoccupational fraud. Empirical assessment supports the structure of the information security control proficiency construct. Model testing shows that information security control proficiency positively impacts information security policy compliance, which further deters the use of a company's computer systems and resources to conduct fraudulent activities. Thus, if an organization establishes high-quality information security policies and supports the policies with effective enforcement, it correspondingly leads to better compliance. Furthermore, less fraud is committed when compliance with information security controls is high. We offer various managerial implications and future research extension ideas.
引用
收藏
页数:17
相关论文
共 50 条
  • [11] Information Security Culture Dimensions in Information Security Policy Compliance Study: A Review
    Nasir, Akhyari
    Arshah, Ruzaini Abdullah
    ADVANCED SCIENCE LETTERS, 2018, 24 (02) : 943 - 946
  • [12] Social control through deterrence on the compliance with information security policy
    Choi, Myeonggil
    Song, Jeongseok
    SOFT COMPUTING, 2018, 22 (20) : 6765 - 6772
  • [13] Social control through deterrence on the compliance with information security policy
    Myeonggil Choi
    Jeongseok Song
    Soft Computing, 2018, 22 : 6765 - 6772
  • [14] Impact of employees' demographic characteristics on the awareness and compliance of information security policy in organizations
    Chua, Hui Na
    Wong, Siew Fan
    Low, Yeh Ching
    Chang, Younghoon
    TELEMATICS AND INFORMATICS, 2018, 35 (06) : 1770 - 1780
  • [15] The Formulation of Comprehensive Information Security Culture Dimensions for Information Security Policy Compliance Study
    Nasir, Akhyari
    Arshah, Ruzaini Abdullah
    Ab Hamid, Mohd Rashid
    ADVANCED SCIENCE LETTERS, 2018, 24 (10) : 7690 - 7695
  • [16] Automating Information Security Policy Compliance Checking
    Mandal, Debashis
    Mazumdar, Chandan
    PROCEEDINGS OF 2018 FIFTH INTERNATIONAL CONFERENCE ON EMERGING APPLICATIONS OF INFORMATION TECHNOLOGY (EAIT), 2018,
  • [17] Information Security Policy Compliance: Leadership and Trust
    Paliszkiewicz, Joanna
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2019, 59 (03) : 211 - 217
  • [18] Issues and Trends in Information Security Policy Compliance
    Bhaharin, Surayahani Hasnul
    Mokhtar, Umi Asma
    Sulaiman, Rossilawati
    Yusof, Maryati Mohd
    2019 6TH INTERNATIONAL CONFERENCE ON RESEARCH AND INNOVATION IN INFORMATION SYSTEMS: EMPOWERING DIGITAL INNOVATION (ICRIIS 2019), 2019,
  • [19] Predictors of Success in Information Security Policy Compliance
    Nord, Jeretta
    Sargent, Carol Springer
    Koohang, Alex
    Marotta, Angelica
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2022, 62 (04) : 863 - 873
  • [20] Behavioral Approach to Information Security Policy Compliance
    Mady, Ashraf
    Gupta, Saurabh
    AMCIS 2017 PROCEEDINGS, 2017,