Acknowledging and Reducing the Knowing and Doing gap in Employee Cybersecurity Compliance

被引:0
|
作者
Gundu, Tapiwa [1 ]
机构
[1] Sol Plaatje Univ, Kimberley, South Africa
关键词
cybersecurity compliance; omissive behaviours; knowing -doing gap; deterrence theory; cybersecurity awareness; INFORMATION SECURITY AWARENESS; POLICY COMPLIANCE; INTEGRATED MODEL; USER SECURITY; BEHAVIOR; DETERRENCE; MANAGEMENT; IMPACT; MOTIVATION; ATTITUDES;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Organisations have a tendency of worrying about their vulnerabilities to outsider threats when contrasted with their weakness to insider threats, despite how industry-particular research proposes that a substantial amount of security breaches emanate from a trusted insider(employee) within the organisation. Insiders frequently participate unconsciously in unsafe practices (naive mistakes) that may debilitate the security, privacy and trustworthiness of organisations' data or debilitate the current technological security barriers. Insider threat is frequently counted by, initially, a security policy followed by awareness and training initiatives on the policy and good security practices. These measures ensure that insiders are capable and know how to complete their everyday duties securely. Nonetheless, literature demonstrates that awareness and training activities increment on knowledge; however, not all knowledge cultivates expected cybersecurity practices. This might be credited to the gap between knowing and doing, emanating from omissive behaviours. Understanding this gap is key to sufficiently addressing security breaches. The purpose of this study is to present a cybersecurity policy compliance motivation/reinforcement model which helps with advancing the change of knowledge into positive cybersecurity practices (behaviours). The model draws from the deterrence theory and the theory of planned action. The strategies utilised include action research and expert review to refine and validate the model. The action research was thoroughly conducted in two cycles at an SME in South Africa and included 30 participating employees. The study observed the connection between knowledge, punishments/rewards and behaviour, and affirmed that knowledge does not ensure good behaviour. After knowledge dispersal initiatives, around 64% of behavioural intentions translated to desirable action. Nonetheless, prevention utilising rewards for good conduct and punishment for bad conduct made a change of 19%. This uncovered the relationship between employees dreading discipline or being pulled in by remunerations, hence behaving securely.
引用
收藏
页码:94 / 102
页数:9
相关论文
共 50 条
  • [41] The knowing-doing gap in acute stroke-Does stroke knowledge translate into action?
    Faiz, Kashif W.
    Sundseth, Antje
    Thommessen, Bente
    Ronning, Ole M.
    [J]. BRAIN AND BEHAVIOR, 2019, 9 (03):
  • [42] Closing the Knowing-Doing Gap in Invasive Plant Management: Accessibility and Interdisciplinarity of Scientific Research
    Matzek, Virginia
    Covino, Justin
    Funk, Jennifer L.
    Saunders, Martin
    [J]. CONSERVATION LETTERS, 2014, 7 (03): : 208 - 215
  • [43] The knowing-doing gap - preoperative assessments via telemedicine during COVID-19
    Milner, A.
    [J]. SOUTHERN AFRICAN JOURNAL OF ANAESTHESIA AND ANALGESIA, 2022, 28 (04) : 159 - 160
  • [44] Training Environmental Managers to Control Invasive Plants: Acting to Close the Knowing-Doing Gap
    Lavoie, Claude
    Brisson, Jacques
    [J]. INVASIVE PLANT SCIENCE AND MANAGEMENT, 2015, 8 (04) : 430 - 435
  • [45] The role of information technology in bridging the knowing-doing gap: an exploratory case study on knowledge application
    Haamann, Thilo
    Basten, Dirk
    [J]. JOURNAL OF KNOWLEDGE MANAGEMENT, 2019, 23 (04) : 705 - 741
  • [46] New horizons in the implementation and research of comprehensive geriatric assessment: knowing, doing and the 'know-do' gap
    Gladman, John R. F.
    Conroy, Simon Paul
    Ranhoff, Anette Hylen
    Gordon, Adam Lee
    [J]. AGE AND AGEING, 2016, 45 (02) : 194 - 200
  • [47] Peri-Implant Health and the Knowing-Doing Gap-A Digital Survey on Procedures and Therapies
    Hussain, Badra
    Haugen, Havard Jostein
    Aass, Anne Merete
    Sanz, Mariano
    Antonoglou, Georgios N.
    Bouchard, Philippe
    Bozic, Darko
    Eickholz, Peter
    Jepsen, Karin
    Jepsen, Soeren
    Karaca, Ebru Ozkan
    Kuru, Bahar Eren
    Nemcovsky, Carlos E.
    Papapanou, Panos N.
    Pilloni, Andrea
    Renvert, Stefan
    Roccuzzo, Mario
    Sanz-Esporrin, Javier
    Spahr, Axel
    Stavropoulos, Andreas
    Verket, Anders
    Vrazic, Domagoj
    Lyngstadaas, Stale Petter
    [J]. FRONTIERS IN DENTAL MEDICINE, 2021, 2
  • [48] 4D visualization to bridge the knowing-doing gap in megaprojects: an Australian case study
    Datta, Abhijnan
    Ninan, Johan
    Sankaran, Shankar
    [J]. CONSTRUCTION ECONOMICS AND BUILDING, 2020, 20 (04): : 25 - 41
  • [49] The Gap Between Knowing and Doing: How Canadians Understand Physical Activity as a Health Risk Management Strategy
    Dallaire, Christine
    Lemyre, Louise
    Krewski, Daniel
    Gibbs, Laura Beth
    [J]. SOCIOLOGY OF SPORT JOURNAL, 2012, 29 (03) : 325 - 347
  • [50] Knowing "what" to do is not enough: Turning knowledge into action (Reprinted from The knowing-doing gap: How smart companies turn knowledge into action)
    Pfeffer, J
    Sutton, RI
    [J]. CALIFORNIA MANAGEMENT REVIEW, 1999, 42 (01) : 83 - +