Understanding the Incentive Mechanism of Penalty for Information Security Policy Compliance Behavior

被引:4
|
作者
Wang, Xiaolong [1 ,2 ]
Li, Wenli [1 ]
机构
[1] Dalian Univ Technol, Fac Management & Econ, Dalian 116024, Peoples R China
[2] Shandong Transport Vocat Coll, Dept Management & Informat, Weifang 261206, Peoples R China
基金
中国国家自然科学基金;
关键词
Incentive mechanism; Information security policy; Compliance behavior; Principal-agent model with moral hazard; Penalty; SYSTEMS SECURITY; MORAL HAZARD; DETERRENCE; MISUSE; ADHERENCE; THREATS; MODEL;
D O I
10.25236/ssehr.2018.005
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
A significant number of information security incidents have been attributed to the internal employees' failure to comply with the information security policy (ISP) in the organizational setting. There exists a principal-agent problem with moral hazard between the employer and the employee individual for the practical compliance effort of the employee is not observable without high costs. In this study, an ISP compliance game has been proposed to analyze the incentive mechanism of penalty on the compliance behavior of employee individual. It is shown that in a no-penalty contract, the employee will decline to comply with the ISP if the expected payoff obtained from her noncompliance is larger than that from the outside options; and in a penalty contract, an appropriate penalty will motivate her to exert the compliance effort level expected by her employer. A numerical example has been presented to show the validity of this game analysis.
引用
收藏
页码:19 / 25
页数:7
相关论文
共 50 条
  • [1] Designing an incentive mechanism for information security policy compliance: An experiment
    Li, Yuanxiang John
    Hoffman, Elizabeth
    JOURNAL OF ECONOMIC BEHAVIOR & ORGANIZATION, 2023, 212 : 138 - 159
  • [2] An optimal coupling incentive mechanism concerning insider's compliance behavior towards marine information security policy
    Wang, Xiaolong
    Wang, Changlin
    Sun, Zaiguan
    Wang, Chunhui
    JOURNAL OF OCEAN ENGINEERING AND SCIENCE, 2023, 8 (05) : 573 - 575
  • [3] The Theory of Planned Behavior and Information Security Policy Compliance
    Sommestad, Teodor
    Karlzen, Henrik
    Hallberg, Jonas
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2019, 59 (04) : 344 - 353
  • [4] Nurse Information Security Policy Compliance, Information Competence, and Information Security Attitudes Predict Information Security Behavior
    Kang, Purum
    Kang, Jiwon
    Monsen, Karen A.
    CIN-COMPUTERS INFORMATICS NURSING, 2023, 41 (08) : 595 - 602
  • [5] Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory
    Ifinedo, Princely
    COMPUTERS & SECURITY, 2012, 31 (01) : 83 - 95
  • [6] Information Security Behavior and Information Security Policy Compliance: A Systematic Literature Review for Identifying the Transformation Process from Noncompliance to Compliance
    Ali, Rao Faizan
    Dominic, P. D. D.
    Ali, Syed Emad Azhar
    Rehman, Mobashar
    Sohail, Abid
    APPLIED SCIENCES-BASEL, 2021, 11 (08):
  • [7] Information Security Policy Compliance: The Role of Information Security Awareness
    AL-Omari, Ahmad
    El-Gayar, Omar
    Deokar, Amit
    AMCIS 2012 PROCEEDINGS, 2012,
  • [8] Using the Theory of Interpersonal Behavior to predict Information Security Policy Compliance
    Chin, Won Yoon
    Chua, Hui Na
    2021 EIGHT INTERNATIONAL CONFERENCE ON EDEMOCRACY & EGOVERNMENT (ICEDEG), 2021, : 80 - 87
  • [9] The sufficiency of the theory of planned behavior for explaining information security policy compliance
    Sommestad, Teodor
    Karlzen, Henrik
    Hallberg, Jonas
    INFORMATION AND COMPUTER SECURITY, 2015, 23 (02) : 200 - 217
  • [10] Understanding Employee Information Security Policy Compliance from Role Theory Perspective
    Nasirpouri Shadbad, Forough
    Biros, David
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2021, 61 (06) : 571 - 580