Shaping intention to resist social engineering through transformational leadership, information security culture and awareness

被引:63
|
作者
Flores, Waldo Rocha [1 ]
Ekstedt, Mathias [1 ]
机构
[1] Royal Inst Technol KTH, Dept Ind Informat & Control Syst, Stockholm, Sweden
关键词
Transformational leadership; Information security culture; Information security awareness; Theory of planned behavior; Social engineering; Mixed methods research; POLICY COMPLIANCE; BEHAVIORAL-RESEARCH; TOP MANAGEMENT; USER SECURITY; MODEL; BIAS; PERFORMANCE; DIRECTIONS; VALIDATION; VARIANCE;
D O I
10.1016/j.cose.2016.01.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper empirically investigates how organizational and individual factors complement each other in shaping employees' intention to resist social engineering. The study followed a mixed methods research design, wherein qualitative data were collected to both establish the study's research model and develop a survey instrument that was distributed to 4296 organizational employees from a diverse set of organizations located in Sweden. The results showed that attitude toward resisting social engineering has the strongest direct association with intention to resist social engineering, while both self-efficacy and normative beliefs showed weak relationships with intention to resist social engineering. Furthermore, the results showed that transformational leadership was strongly associated with both perceived information security culture and information security awareness. Two mediation tests showed that attitude and normative beliefs partially mediate the effect of information security culture on employees' intention to resist social engineering. This suggests that both attitude and normative beliefs play important roles in governing the relationship between information security culture and intention to resist social engineering. A third mediation test revealed that information security culture fully explains the effect of transformational leadership on employees' attitude toward resisting social engineering. Discussion of the results and practical implications of the performed research are provided. (C) 2016 Elsevier Ltd. All rights reserved.
引用
下载
收藏
页码:26 / 44
页数:19
相关论文
共 50 条
  • [1] The Role of Employees' Information Security Awareness on the Intention to Resist Social Engineering
    Grassegger, Tanja
    Nedbal, Dietmar
    INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS / INTERNATIONAL CONFERENCE ON PROJECT MANAGEMENT / INTERNATIONAL CONFERENCE ON HEALTH AND SOCIAL CARE INFORMATION SYSTEMS AND TECHNOLOGIES 2020 (CENTERIS/PROJMAN/HCIST 2020), 2021, 181 : 59 - 66
  • [2] Social Engineering for Diagnostic the Information Security Culture
    Marchand-Nino, William-Rogelio
    Guzman Fonseca, Bruno Paolo
    2019 IEEE 39TH CENTRAL AMERICA AND PANAMA CONVENTION (CONCAPAN XXXIX), 2019, : 233 - 238
  • [3] TRAINING IN SHAPING EMPLOYEE INFORMATION SECURITY AWARENESS
    Stefaniuk, Tomasz
    ENTREPRENEURSHIP AND SUSTAINABILITY ISSUES, 2020, 7 (03): : 1832 - 1846
  • [4] Leadership of Information Security Managers on the Effectiveness of Information Systems Security Through Mediate of Organizational Culture
    Choi, Myeonggil
    Song, Jeongsuk
    ADVANCED MULTIMEDIA AND UBIQUITOUS ENGINEERING: FUTURETECH & MUE, 2016, 393 : 649 - 654
  • [5] Transformational leadership influences on work engagement and turnover intention in an engineering organisation
    Ntseke, Thabisile
    Mitonga-Monga, Jeremy
    Hoole, Crystal
    SA JOURNAL OF HUMAN RESOURCE MANAGEMENT, 2022, 20
  • [6] CONCERN ON HEALTHCARE INFORMATION SECURITY: IMPROVING AWARENESS OF AND RESPONSE TO SOCIAL ENGINEERING
    Li, Huayan
    MEDICINE, 2023, 102 (52) : 9 - 9
  • [7] Considering transformational leadership model in branches of Tehran social security organization
    Allameh, Sayyed Mohsen
    Davoodi, Sayyed Mohammad Reza
    3RD WORLD CONFERENCE ON EDUCATIONAL SCIENCES - 2011, 2011, 15 : 3131 - 3137
  • [8] SOCIAL ENGINEERING AWARENESS GAME (SEAG): AN EMPIRICAL EVALUATION OF USING GAME TOWARDS IMPROVING INFORMATION SECURITY AWARENESS
    Olanrewaju, Abdus-Samad Temitope
    Zakaria, Nur Haryani
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON COMPUTING & INFORMATICS, 2015, : 187 - 193
  • [9] Exploring the role of gamified information security education systems on information security awareness and protection behavioral intention
    Hao Chen
    Yan Zhang
    Song Zhang
    Tu Lyu
    Education and Information Technologies, 2023, 28 : 15915 - 15948
  • [10] Exploring the role of gamified information security education systems on information security awareness and protection behavioral intention
    Chen, Hao
    Zhang, Yan
    Zhang, Song
    Lyu, Tu
    EDUCATION AND INFORMATION TECHNOLOGIES, 2023, 28 (12) : 15915 - 15948