Organizational Information Security Management for Sustainable Information Systems: An Unethical Employee Information Security Behavior Perspective

被引:11
|
作者
Chu, Amanda M. Y. [1 ]
So, Mike K. P. [2 ]
机构
[1] Educ Univ Hong Kong, Dept Social Sci, Hong Kong, Peoples R China
[2] Hong Kong Univ Sci & Technol, Dept Informat Syst Business Stat & Operat Managem, Hong Kong, Peoples R China
关键词
business continuity; information security; information systems misuse; insider; unethical behavior; RANDOMIZED-RESPONSE TECHNIQUE; COMMON METHOD VARIANCE; COMPUTER ABUSE; AGENCY THEORY; BUSINESS ETHICS; WORKPLACE; DETERRENCE; VIOLATIONS; MISUSE; MODEL;
D O I
10.3390/su12083163
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
This article examines the occurrences of four types of unethical employee information security behavior-misbehavior in networks/applications, dangerous Web use, omissive security behavior, and poor access control-and their relationships with employees' information security management efforts to maintain sustainable information systems in the workplace. In terms of theoretical contributions, this article identifies and develops reliable and valid instruments to measure different types of unethical employee information security behavior. In addition, it investigates factors affecting different types of such behavior and how such behavior can be used to predict employees' willingness to report information security incidents. In terms of managerial contributions, the article suggests that information security awareness programs and perceived punishment have differential effects on the four types of unethical behavior and that certain types of unethical information security behavior exert negative effects on employees' willingness to report information security incidents. The findings will help managers to derive better security rules and policies, which are important for business continuity.
引用
收藏
页数:25
相关论文
共 50 条
  • [1] Comparison of Information Security Systems for Asymptotic Information Security Management Critical Information Infrastructures
    Erokhin, Sergey
    Petukhov, Andrey
    Pilyugin, Pavel
    [J]. PROCEEDINGS OF THE 28TH CONFERENCE OF OPEN INNOVATIONS ASSOCIATION FRUCT, 2021, : 89 - 95
  • [2] A management perspective on risk of security threats to information systems
    Farahmand F.
    Navathe S.B.
    Sharp G.P.
    Enslow P.H.
    [J]. Information Technology and Management, 2005, 6 (2-3) : 203 - 225
  • [3] SOME ASPECTS OF INFORMATION SECURITY IN DIGITAL ORGANIZATIONAL MANAGEMENT SYSTEMS
    Skrynnyk, Olena
    [J]. MARKETING AND MANAGEMENT OF INNOVATIONS, 2020, (04): : 279 - 289
  • [4] Information security culture: A management perspective
    Van Niekerk, J. F.
    Von Solms, R.
    [J]. COMPUTERS & SECURITY, 2010, 29 (04) : 476 - 486
  • [6] New organizational forms for information security management
    Baskerville, R
    [J]. INFORMATION SECURITY IN RESEARCH AND BUSINESS, 1997, : 296 - 307
  • [7] Exploring organizational culture for information security management
    Chang, Shuchih Ernest
    Lin, Chin-Shien
    [J]. INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2007, 107 (3-4) : 438 - 458
  • [8] Identifying factors of "organizational information security management"
    Singh, Abhishek Narain
    Gupta, M. P.
    Ojha, Amitabh
    [J]. JOURNAL OF ENTERPRISE INFORMATION MANAGEMENT, 2014, 27 (05) : 644 - +
  • [9] Information Technology as the Enabler for Organizational Agility and the Needs of Information Security Management
    Zaini, Muhamad Khairulnizam
    Masrek, Mohamad Noorman
    Sani, Mad Khir Johari Abdullah
    [J]. SUSTAINABLE ECONOMIC GROWTH, EDUCATION EXCELLENCE, AND INNOVATION MANAGEMENT THROUGH VISION 2020, VOLS I-VII, 2017, : 2255 - 2267
  • [10] Leadership of Information Security Managers on the Effectiveness of Information Systems Security Through Mediate of Organizational Culture
    Choi, Myeonggil
    Song, Jeongsuk
    [J]. ADVANCED MULTIMEDIA AND UBIQUITOUS ENGINEERING: FUTURETECH & MUE, 2016, 393 : 649 - 654