Understanding the Incentive Mechanism of Penalty for Information Security Policy Compliance Behavior

被引:4
|
作者
Wang, Xiaolong [1 ,2 ]
Li, Wenli [1 ]
机构
[1] Dalian Univ Technol, Fac Management & Econ, Dalian 116024, Peoples R China
[2] Shandong Transport Vocat Coll, Dept Management & Informat, Weifang 261206, Peoples R China
基金
中国国家自然科学基金;
关键词
Incentive mechanism; Information security policy; Compliance behavior; Principal-agent model with moral hazard; Penalty; SYSTEMS SECURITY; MORAL HAZARD; DETERRENCE; MISUSE; ADHERENCE; THREATS; MODEL;
D O I
10.25236/ssehr.2018.005
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
A significant number of information security incidents have been attributed to the internal employees' failure to comply with the information security policy (ISP) in the organizational setting. There exists a principal-agent problem with moral hazard between the employer and the employee individual for the practical compliance effort of the employee is not observable without high costs. In this study, an ISP compliance game has been proposed to analyze the incentive mechanism of penalty on the compliance behavior of employee individual. It is shown that in a no-penalty contract, the employee will decline to comply with the ISP if the expected payoff obtained from her noncompliance is larger than that from the outside options; and in a penalty contract, an appropriate penalty will motivate her to exert the compliance effort level expected by her employer. A numerical example has been presented to show the validity of this game analysis.
引用
收藏
页码:19 / 25
页数:7
相关论文
共 50 条
  • [31] Promoting Information Security Policy Compliance - An Empirical Study
    Li, Lei
    Han, Meng
    AMCIS 2020 PROCEEDINGS, 2020,
  • [32] Leader power and employees’ information security policy compliance
    Hyungjin Lukas Kim
    HanByeol Stella Choi
    Jinyoung Han
    Security Journal, 2019, 32 : 391 - 409
  • [33] The effect of compliance knowledge and compliance support systems on information security compliance behavior
    Kim, Sang Soo
    Kim, Yong Jin
    JOURNAL OF KNOWLEDGE MANAGEMENT, 2017, 21 (04) : 986 - 1010
  • [34] Narratives and Information Security Policy Compliance: A Narrative Policy Framework Perspective
    Al Nuaim, Abdullah
    Ramirez, Ronald
    Dincelli, Ersin
    AMCIS 2020 PROCEEDINGS, 2020,
  • [35] Information Security Policy Compliance: Investigating the role of intrinsic motivation towards policy compliance in the organisation
    Alzahrani, Ahmed
    Johnson, Chris
    Altamimi, Saad
    2018 4TH INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT (ICIM2018), 2018, : 125 - 132
  • [36] The Impact of Challenge Information Security Stress on Information Security Policy Compliance: The Mediating Roles of Emotions
    Chen, Lin
    Xie, Zongxiao
    Zhen, Jie
    Dong, Kunxiang
    PSYCHOLOGY RESEARCH AND BEHAVIOR MANAGEMENT, 2022, 15 : 1177 - 1191
  • [37] Reducing fraud in organizations through information security policy compliance: An information security controls perspective
    Brown D.
    Batra G.
    Zafar H.
    Saeed K.
    Computers and Security, 2024, 144
  • [38] Fostering information security compliance as organizational citizenship behavior
    Vedadi, Ali
    Warkentin, Merrill
    Straub, Detmar W.
    Shropshire, Jordan
    INFORMATION & MANAGEMENT, 2024, 61 (05)
  • [39] Penalty policy and incentive policy of JIT for multi-supplier
    Pu, Xu-Jin
    Shi, Qin
    Ling, Liu-Yi
    Jisuanji Jicheng Zhizao Xitong/Computer Integrated Manufacturing Systems, CIMS, 2006, 12 (11): : 1876 - 1880
  • [40] Social control through deterrence on the compliance with information security policy
    Choi, Myeonggil
    Song, Jeongseok
    SOFT COMPUTING, 2018, 22 (20) : 6765 - 6772