Understanding Information Security Policy Violation from a Situational Action Perspective

被引:18
|
作者
Li, Han [1 ]
Luo, Xin [1 ]
Chen, Yan [2 ]
机构
[1] Univ New Mexico, Anderson Sch Management, Albuquerque, NM 87131 USA
[2] Florida Int Univ, Coll Business, Miami, FL 33199 USA
来源
关键词
Insider Threats; Situational Action Theory; Morality; Self-Control; Deterrence; Cognitive Moral Development; ETHICAL DECISION-MAKING; SELF-CONTROL; RATIONAL CHOICE; COMPUTER ABUSE; PROTECTION MOTIVATION; SYSTEMS MISUSE; GENERAL-THEORY; DETERRENCE; MODEL; EMPLOYEES;
D O I
10.17705/1jais.00678
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Insiders' negligence or abuse is regarded as a leading cause of information security breaches in organizations. As most of the extant studies have largely examined insider threats at a high level of abstraction, the role of situational moral reasoning for information security policy (ISP) violations in specific situations has received little attention. To advance this line of research, this paper opens up a potentially fruitful path for IS researchers by applying situational action theory (SAT) to contextually examine why employees violate ISPs in particular situations. We consider the violations of password security policy, internet use policy, and confidential data security policy, and examine specific violation intents ranging from altruistic to malicious. The results support most of the assertions derived from SAT. We found situational moral beliefs to be the predominant driver for ISP violations across three situations in an organizational setting. However, the moderation effect of moral beliefs was only significant in situations involving sharing passwords and selling confidential data. Sanction certainty and sanction severity were also found to have different effects across situations. We conclude by presenting implications for IS security practitioners and suggestions for future research.
引用
收藏
页码:739 / 772
页数:34
相关论文
共 50 条
  • [1] Understanding Employee Information Security Policy Compliance from Role Theory Perspective
    Nasirpouri Shadbad, Forough
    Biros, David
    [J]. JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2021, 61 (06) : 571 - 580
  • [2] Dispositional and situational factors: influences on information security policy violations
    Johnston, Allen C.
    Warkentin, Merrill
    McBride, Maranda
    Carter, Lemuria
    [J]. EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2016, 25 (03) : 231 - 251
  • [3] Understanding Israel's Foreign Policy from the Perspective of Identity and Security
    Salameh, Mohammed Torki Bani
    Ishakat, Ahmad
    [J]. INSIGHT TURKEY, 2022, 24 (02) : 181 - 201
  • [4] A Policy that Deters Violation of Security Policy
    Parker, Donn B.
    [J]. COMMUNICATIONS OF THE ACM, 2011, 54 (08) : 7 - 7
  • [5] Smart City Development in Taiwan: From the Perspective of the Information Security Policy
    Wu, Yung Chang
    Sun, Rui
    Wu, Yenchun Jim
    [J]. SUSTAINABILITY, 2020, 12 (07)
  • [6] Violation of safeguards by trusted personnel and understanding related information security concerns
    Dhillon, G
    [J]. COMPUTERS & SECURITY, 2001, 20 (02) : 165 - 172
  • [7] An Integrated Approach to Information Systems Security Policy Violation: The Case of Ethiopia
    Arage, Tilahun Muluneh
    Tesema, Tibebe Beshah
    [J]. INTERNATIONAL CONFERENCE ON INFORMATICS AND SYSTEMS (INFOS 2016), 2016, : 228 - 232
  • [8] From Information Security Awareness to Reasoned Compliant Action: Analyzing Information Security Policy Compliance in a Large Banking Organization
    Bauer, Stefan
    Bernroider, Edward W. N.
    [J]. DATA BASE FOR ADVANCES IN INFORMATION SYSTEMS, 2017, 48 (03): : 44 - 68
  • [9] Implementation of an Information Systems Security Policy: Action Research
    Lopes, Isabel
    Oliveira, Pedro
    [J]. PROCEEDINGS OF THE 13TH EUROPEAN CONFERENCE ON RESEARCH METHODOLOGY FOR BUSINESS AND MANAGEMENT STUDIES (ECRM 2014), 2014, : 244 - 252
  • [10] Narratives and Information Security Policy Compliance: A Narrative Policy Framework Perspective
    Al Nuaim, Abdullah
    Ramirez, Ronald
    Dincelli, Ersin
    [J]. AMCIS 2020 PROCEEDINGS, 2020,