Shaping intention to resist social engineering through transformational leadership, information security culture and awareness

被引:63
|
作者
Flores, Waldo Rocha [1 ]
Ekstedt, Mathias [1 ]
机构
[1] Royal Inst Technol KTH, Dept Ind Informat & Control Syst, Stockholm, Sweden
关键词
Transformational leadership; Information security culture; Information security awareness; Theory of planned behavior; Social engineering; Mixed methods research; POLICY COMPLIANCE; BEHAVIORAL-RESEARCH; TOP MANAGEMENT; USER SECURITY; MODEL; BIAS; PERFORMANCE; DIRECTIONS; VALIDATION; VARIANCE;
D O I
10.1016/j.cose.2016.01.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper empirically investigates how organizational and individual factors complement each other in shaping employees' intention to resist social engineering. The study followed a mixed methods research design, wherein qualitative data were collected to both establish the study's research model and develop a survey instrument that was distributed to 4296 organizational employees from a diverse set of organizations located in Sweden. The results showed that attitude toward resisting social engineering has the strongest direct association with intention to resist social engineering, while both self-efficacy and normative beliefs showed weak relationships with intention to resist social engineering. Furthermore, the results showed that transformational leadership was strongly associated with both perceived information security culture and information security awareness. Two mediation tests showed that attitude and normative beliefs partially mediate the effect of information security culture on employees' intention to resist social engineering. This suggests that both attitude and normative beliefs play important roles in governing the relationship between information security culture and intention to resist social engineering. A third mediation test revealed that information security culture fully explains the effect of transformational leadership on employees' attitude toward resisting social engineering. Discussion of the results and practical implications of the performed research are provided. (C) 2016 Elsevier Ltd. All rights reserved.
引用
下载
收藏
页码:26 / 44
页数:19
相关论文
共 50 条
  • [21] Social engineering in the context of ensuring information security
    Mamedova, Natalia
    Urintsov, Arkadiy
    Staroverova, Olga
    Ivanov, Evgeniy
    Galahov, Dmitriy
    INTERNATIONAL SCIENTIFIC AND PRACTICAL CONFERENCE CURRENT ISSUES OF LINGUISTICS AND DIDACTICS: THE INTERDISCIPLINARY APPROACH IN HUMANITIES AND SOCIAL SCIENCES (CILDIAH-2019), 2019, 69
  • [22] SOCIAL ENGINEERING: AN INFORMATION SECURITY THREAT IN ENTERPRISES
    Acilar, Ali
    Bastug, Ayse
    GLOBAL BUSINESS RESEARCH CONGRESS (GBRC) 2016, VOL 2, 2016, 2 : 289 - 297
  • [23] An Overview of Social Engineering in the Context of Information Security
    Kaushalya, S. A. D. T. P.
    Randeniya, R. M. R. S. B.
    Liyanage, A. D. S.
    2018 5TH IEEE INTERNATIONAL CONFERENCE ON ENGINEERING TECHNOLOGIES AND APPLIED SCIENCES (IEEE ICETAS), 2018,
  • [24] Social engineering: Application of psychology to information security
    Del Pozo, Ivan
    Iturralde, Mauricio
    Restrepo, Felipe
    2018 IEEE 6TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD WORKSHOPS (W-FICLOUD 2018), 2018, : 108 - 114
  • [25] The Awareness of Social Engineering in Information Revolution: Techniques and Challenges
    Alazri, Aisha Suliaman
    2015 10TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2015, : 198 - 201
  • [26] Social Engineering through Social Media: An Investigation on Enterprise Security
    Wilcox, Heidi
    Bhattacharya, Maumita
    Islam, Rafiqul
    APPLICATIONS AND TECHNIQUES IN INFORMATION SECURITY, ATIS 2014, 2014, 490 : 243 - 255
  • [27] Social engineering through social media: An investigation on enterprise security
    Wilcox, Heidi
    Bhattacharya, Maumita
    Islam, Rafiqul
    Communications in Computer and Information Science, 2014, 490 : 243 - 255
  • [28] Helping the hacker? Library information, security, and social engineering
    Thompson, Samuel T. C.
    INFORMATION TECHNOLOGY AND LIBRARIES, 2006, 25 (04) : 222 - 225
  • [29] The persuasion and security awareness experiment: reducing the success of social engineering attacks
    Bullee, Jan-Willem H.
    Montoya, Lorena
    Pieters, Wolter
    Junger, Marianne
    Hartel, Pieter H.
    JOURNAL OF EXPERIMENTAL CRIMINOLOGY, 2015, 11 (01) : 97 - 115
  • [30] Educating and Raising Awareness on Cyber Security Social Engineering: A Literature Review
    Aldawood, Hussain
    Skinner, Geoffrey
    PROCEEDINGS OF 2018 IEEE INTERNATIONAL CONFERENCE ON TEACHING, ASSESSMENT, AND LEARNING FOR ENGINEERING (TALE), 2018, : 62 - 68