کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
454759 695289 2013 15 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Don't make excuses! Discouraging neutralization to reduce IT policy violation
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Don't make excuses! Discouraging neutralization to reduce IT policy violation
چکیده انگلیسی


• Employees use rationalizations when deciding whether or not to violate a policy.
• Rationalizations often are stronger than sanctions in predicting employee behavior.
• We propose that focus of security communication influences intentions to violate.
• We test our hypotheses using the factorial survey method.
• Security communication focused on neutralization is as effective as sanctions.

Past research on information technology (IT) security training and awareness has focused on informing employees about security policies and formal sanctions for violating those policies. However, research suggests that deterrent sanctions may not be the most powerful influencer of employee violations. Often, employees use rationalizations, termed neutralization techniques, to overcome the effects of deterrence when deciding whether or not to violate a policy. Therefore, neutralization techniques often are stronger than sanctions in predicting employee behavior. For this study, we examine “denial of injury,” “metaphor of the ledger,” and “defense of necessity” as relevant justifications for violating password policies that are commonly used in organizations as used in (Siponen and Vance, 2010). Initial research on neutralization in IS security has shown that results are consistent regardless of which type of neutralization is considered (Siponen and Vance, 2010). In this study, we investigate whether IT security communication focused on mitigating neutralization, rather than deterrent sanctions, can reduce intentions to violate security policies. Additionally, considering the effects of message framing in persuading individuals against security policy violations are largely unexamined, we predict that negatively-framed communication will be more persuasive than positively-framed communication. We test our hypotheses using the factorial survey method. Our results suggest that security communication and training that focuses on neutralization techniques is just as effective as communication that focuses on deterrent sanctions in persuading employees not to violate policies, and that both types of framing are equally effective.

Figure optionsDownload as PowerPoint slide

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computers & Security - Volume 39, Part B, November 2013, Pages 145–159
نویسندگان
, , , ,