Exploring Staff Perception of InfoSec Policy Compliance: Palestine Universities Empirical Study

Yousef Mohammad Iriqat, A. R. Ahlan, Nurul Nuha Abdul Molok, Noor Hayani Abd Rahim
{"title":"Exploring Staff Perception of InfoSec Policy Compliance: Palestine Universities Empirical Study","authors":"Yousef Mohammad Iriqat, A. R. Ahlan, Nurul Nuha Abdul Molok, Noor Hayani Abd Rahim","doi":"10.1109/ICOICE48418.2019.9035133","DOIUrl":null,"url":null,"abstract":"There is worldwide recognition of the problems associated with insider threats, intentional and unintentional; One of the significant issues in mitigating InfoSec risks is Staff compliance intention of InfoSec policies (ISP‘s). The study purpose seeks to understand and explore Staff compliance intention of ISP's based on how Staff perceive several factors adopted from multi-theories from ISP's research. Such as Sanction from General Deterrence Theory, Rewards as extrinsic motivation, Coping Appraisal from Protection Motivation Theory, and, Information Reinforcement that constitute the theoretical model. In the context of Palestine universities, the research Model first part constitutes the understanding of Staff awareness of ISP's based on four selected Policy-Focused Areas (PFA) from SANS 2014. Moreover, to assess this knowledge to reflect on the multi-theory perception factors effects on Staff compliance intention. Furthermore, to investigated Staff SETA to assess how universities value their Staff knowledge on ISP's. The research Methodology explores the problem empirically using descriptive analysis research design such as summaries and regression analysis. The study has 600 datasets collected from six universities by the developed research quantitative instrument. The findings show that Staff value the importance of the model factors in promoting Staff compliance intention. Staff have some awareness of PFA's and SETA needs extra attention. The Practical implications for creating ISP compliance among university Staff by drawing on their perception of factors adopted from multi-theories. Consequently, as for the organisation, effective SETA programs to sustain the effort of Staff compliance intention of ISP's. Meanwhile, this study seeks to assert that ISP's compliance is the responsibility of all academic and administrative Staff from all department and as a paradigm for other employees. The research covers ISP perception among Palestine Staff, and the expected outcome includes - a novel theoretical contribution model with six significantly contributing factors. Also, PFA in the context of Palestine contributes as a methodological contribution and Staff SETA as practical research contribution.","PeriodicalId":109414,"journal":{"name":"2019 First International Conference of Intelligent Computing and Engineering (ICOICE)","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 First International Conference of Intelligent Computing and Engineering (ICOICE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOICE48418.2019.9035133","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

There is worldwide recognition of the problems associated with insider threats, intentional and unintentional; One of the significant issues in mitigating InfoSec risks is Staff compliance intention of InfoSec policies (ISP‘s). The study purpose seeks to understand and explore Staff compliance intention of ISP's based on how Staff perceive several factors adopted from multi-theories from ISP's research. Such as Sanction from General Deterrence Theory, Rewards as extrinsic motivation, Coping Appraisal from Protection Motivation Theory, and, Information Reinforcement that constitute the theoretical model. In the context of Palestine universities, the research Model first part constitutes the understanding of Staff awareness of ISP's based on four selected Policy-Focused Areas (PFA) from SANS 2014. Moreover, to assess this knowledge to reflect on the multi-theory perception factors effects on Staff compliance intention. Furthermore, to investigated Staff SETA to assess how universities value their Staff knowledge on ISP's. The research Methodology explores the problem empirically using descriptive analysis research design such as summaries and regression analysis. The study has 600 datasets collected from six universities by the developed research quantitative instrument. The findings show that Staff value the importance of the model factors in promoting Staff compliance intention. Staff have some awareness of PFA's and SETA needs extra attention. The Practical implications for creating ISP compliance among university Staff by drawing on their perception of factors adopted from multi-theories. Consequently, as for the organisation, effective SETA programs to sustain the effort of Staff compliance intention of ISP's. Meanwhile, this study seeks to assert that ISP's compliance is the responsibility of all academic and administrative Staff from all department and as a paradigm for other employees. The research covers ISP perception among Palestine Staff, and the expected outcome includes - a novel theoretical contribution model with six significantly contributing factors. Also, PFA in the context of Palestine contributes as a methodological contribution and Staff SETA as practical research contribution.
巴勒斯坦大学员工对信息安全政策合规认知的实证研究
全世界都认识到与内部威胁有关的问题,无论是有意的还是无意的;降低信息安全风险的一个重要问题是员工对信息安全政策的遵从意愿。本研究的目的是通过员工对ISP研究中多个因素的感知来了解和探讨ISP员工的合规意愿。如一般威慑理论的制裁、奖励作为外在动机、保护动机理论的应对评价、信息强化等构成理论模型。在巴勒斯坦大学的背景下,研究模型的第一部分是基于2014年SANS选定的四个政策重点领域(PFA),对员工对ISP的认识的理解。此外,评估这方面的知识,以反映多理论感知因素对员工合规意愿的影响。此外,我们调查了员工SETA,以评估大学如何重视员工对ISP的了解。研究方法采用摘要分析、回归分析等描述性分析研究设计对问题进行实证探讨。该研究使用先进的研究定量仪器从六所大学收集了600个数据集。研究结果表明,员工重视模式因素在促进员工合规意愿方面的重要性。员工对PFA有一定的了解,SETA需要额外的关注。从多理论角度探讨高校员工对互联网服务依从性因素的认知对营造高校员工互联网服务依从性的现实意义。因此,对于组织而言,有效的SETA计划可以维持工作人员的努力,符合ISP的意图。同时,本研究试图断言ISP的合规是所有部门的学术和行政人员的责任,并作为其他员工的典范。该研究涵盖了巴勒斯坦工作人员对互联网服务提供商的看法,预期结果包括-一个具有六个显著贡献因素的新颖理论贡献模型。此外,巴勒斯坦方面的PFA作为一种方法贡献,工作人员SETA作为实际研究贡献。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信