Exploring behavioral information security networks in an organizational context: An empirical case study

被引:6
|
作者
Duy Dang-Pham [1 ]
Pittayachawan, Siddhi [1 ]
Bruno, Vince [1 ]
机构
[1] RMIT Univ, Sch Business IT & Logist, Melbourne, Vic, Australia
关键词
Social network analysis; Security behavior; Security compliance; Security influence; Organizational behavior; PROTECTION MOTIVATION THEORY; POLICY COMPLIANCE; ATTITUDE-CHANGE; SELF-EFFICACY; FEAR APPEALS; DETERRENCE; COUNTERMEASURES; EMPLOYEES; INTENTION; AWARENESS;
D O I
10.1016/j.jisa.2016.06.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The purpose of this research is to propose network research as an alternative approach in the behavioral security field. A case study was conducted in a large interior contractor to explore eight organizational networks, four of which focus on security behaviors. The researchers employed social network analysis methods, including quantitative and qualitative ones, to analyze the case study's data and demonstrate the analytical capability of the network analysis approach in the behavioral security field. Key features of the security networks' structures include high transitivity, hierarchy, and centralization, whereas reciprocity and density are lower than other organizational networks. Moreover, work-related interactions were found to impact security influence, among which giving IT advice increases significantly one's influential status in security matters. Practical implications include suggestions about the use of network analysis methods as a tool for security managers to monitor their behavioral security networks and devise appropriate strategies. Potential research directions are also elaborated, which future research can employ and promote the novel and practical use of network analysis techniques. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:46 / 62
页数:17
相关论文
共 50 条
  • [1] Cultivating and Assessing an Organizational Information Security Culture; an Empirical Study
    Al Hogail, Areej
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (07): : 163 - 178
  • [2] Information Systems Security Leadership: An Empirical Study of Behavioral Influences
    Winkfield, Marcus
    Parrish, James
    Tejay, Gurvirender
    [J]. AMCIS 2017 PROCEEDINGS, 2017,
  • [3] Information Security and Organizational Performance: Empirical Study of Korean Securities Industry
    Kong, Heekyung
    Jung, Suhyun
    Lee, Insung
    Yeon, Seung-Jun
    [J]. ETRI JOURNAL, 2015, 37 (02) : 428 - 437
  • [4] Exploring organizational culture for information security management
    Chang, Shuchih Ernest
    Lin, Chin-Shien
    [J]. INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2007, 107 (3-4) : 438 - 458
  • [5] Interpreting information security culture: An organizational transformation case study
    Dhillon, Gurpreet
    Syed, Romilla
    Pedron, Cristiane
    [J]. COMPUTERS & SECURITY, 2016, 56 : 63 - 69
  • [6] Organizational Transformation and Information Security Culture: A Telecom Case Study
    Dhillon, Gurpreet
    Chowdhuri, Romilla
    Pedron, Cristiane
    [J]. ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, IFIP TC 11 INTERNATIONAL CONFERENCE, SEC 2014, 2014, 428 : 431 - 437
  • [7] The impacts of organizational culture on information security culture: a case study
    Tang, Mincong
    Li, Meng'gang
    Zhang, Tao
    [J]. INFORMATION TECHNOLOGY & MANAGEMENT, 2016, 17 (02): : 179 - 186
  • [8] The impacts of organizational culture on information security culture: a case study
    Mincong Tang
    Meng’gang Li
    Tao Zhang
    [J]. Information Technology and Management, 2016, 17 : 179 - 186
  • [9] Exploring Organizational Human Resource Information System Security
    Zafar, Humayun
    [J]. AMCIS 2012 PROCEEDINGS, 2012,
  • [10] The concept of information security as an organizational strategy in the context of Industry 4.0
    Martins, Tailise Mascarenhas
    Carneiro, Rafael Nunes
    Mergulhao, Ricardo Coser
    [J]. REVISTA DE GESTAO E SECRETARIADO-GESEC, 2023, 14 (01): : 1068 - 1082