کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
553910 873560 2014 8 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Employees’ adherence to information security policies: An exploratory field study
ترجمه فارسی عنوان
کارمندان؟ پیروی از سیاست های امنیت اطلاعات: یک مطالعه علمی اکتشافی
کلمات کلیدی
امنیت اطلاعات، رعایت سیاست امنیت اطلاعات، نظریه انگیزه حمایت، نظریه ارزیابی شناختی، تئوری اقدام منطقی، ارزیابی تهدید، خود کارآمدی، اثربخشی پاسخ، نگرش، باورهای نظری، پاداش اثر تعدیل کننده
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر سیستم های اطلاعاتی
چکیده انگلیسی

The key threat to information security comes from employees who do not comply with information security policies. We developed a new multi-theory based model that explained employees’ adherence to security policies. The paradigm combines elements from the Protection Motivation Theory, the Theory of Reasoned Action, and the Cognitive Evaluation Theory. We validated the model by using a sample of 669 responses from four corporations in Finland. The SEM-based results showed that perceived severity of potential information security threats, employees’ belief as to whether they can apply and adhere to information security policies, perceived vulnerability to potential security threats, employees’ attitude toward complying with information security policies, and social norms toward complying with these policies had a significant and positive effect on the employees’ intention to comply with information security policies. Intention to comply with information security policies also had a significant impact on actual compliance with these policies. High level managers must warn employees of the importance of information security and why it is necessary to carry out these policies. In addition, employees should be provided with security education and hands on training.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Information & Management - Volume 51, Issue 2, March 2014, Pages 217–224
نویسندگان
, , ,