The Effect of Rational Based Beliefs and Awareness on Employee Compliance with Information Security Procedures: A Case Study of a Financial Corporation in Israel

Q2 Computer Science
Golan Carmi, D. Bouhnik
{"title":"The Effect of Rational Based Beliefs and Awareness on Employee Compliance with Information Security Procedures: A Case Study of a Financial Corporation in Israel","authors":"Golan Carmi, D. Bouhnik","doi":"10.28945/4596","DOIUrl":null,"url":null,"abstract":"Aim/Purpose This paper examines the behavior of financial firm employees with regard to information security procedures instituted within their organization. Furthermore, the effect of information security awareness and its importance within a firm is explored. Background The study focuses on employees’ attitude toward compliance with information security policies (ISP), combined with various norms and personal abilities. Methodology A self-reported questionnaire was distributed among 202 employees of a large financial Corporation Contribution As far as we know, this is the first paper to thoroughly explore employees’ awareness of information system procedures, among financial organizations in Israel, and also the first to develop operative recommendations for these organizations aimed at increasing ISP compliance behavior. The main contribution of this study is that it investigates compliance with information security practices among employees of a defined financial corporation operating under rigid regulatory governance, confidentiality and privacy of data, and stringent requirements for compliance with information security procedures. Findings Our results indicate that employees’ attitudes, normative beliefs and personal capabilities to comply with firm’s ISP, have positive effects on the firm’s ISP compliance. Also, employees’ general awareness of IS, as well as awareness to ISP within the firm, positively affect employees’ ISP compliance. Rational Based Beliefs and Awareness 110 Recommendations for Practitioners This study can help information security managers identify the motivating factors for employee behavior to maintain information security procedures, properly channel information security resources, and manage appropriate information security behavior. Recommendations for Researchers Researchers can see that corporate rewards and sanctions have significant effects on employee security behavior, but other motivational factors also reinforce the ISP’s compliance behavior. Distinguishing between types of corporations and organizations is essential to understanding employee compliance with information security procedures. Impact on Society This study offers another level of understanding of employee behavior with regard to information security in organizations and comprises a significant contribution to the growing knowledge in this area. The research results form an important basis for IS policymakers, culture designers, managers, and those directly responsible for IS in the organization. Future Research Future work should sample employees from another type of corporation from other fields and should apply qualitative analysis to explore other aspects of behavioral patterns related to the subject matter.","PeriodicalId":38962,"journal":{"name":"Interdisciplinary Journal of Information, Knowledge, and Management","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2020-07-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Interdisciplinary Journal of Information, Knowledge, and Management","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.28945/4596","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"Computer Science","Score":null,"Total":0}
引用次数: 6

Abstract

Aim/Purpose This paper examines the behavior of financial firm employees with regard to information security procedures instituted within their organization. Furthermore, the effect of information security awareness and its importance within a firm is explored. Background The study focuses on employees’ attitude toward compliance with information security policies (ISP), combined with various norms and personal abilities. Methodology A self-reported questionnaire was distributed among 202 employees of a large financial Corporation Contribution As far as we know, this is the first paper to thoroughly explore employees’ awareness of information system procedures, among financial organizations in Israel, and also the first to develop operative recommendations for these organizations aimed at increasing ISP compliance behavior. The main contribution of this study is that it investigates compliance with information security practices among employees of a defined financial corporation operating under rigid regulatory governance, confidentiality and privacy of data, and stringent requirements for compliance with information security procedures. Findings Our results indicate that employees’ attitudes, normative beliefs and personal capabilities to comply with firm’s ISP, have positive effects on the firm’s ISP compliance. Also, employees’ general awareness of IS, as well as awareness to ISP within the firm, positively affect employees’ ISP compliance. Rational Based Beliefs and Awareness 110 Recommendations for Practitioners This study can help information security managers identify the motivating factors for employee behavior to maintain information security procedures, properly channel information security resources, and manage appropriate information security behavior. Recommendations for Researchers Researchers can see that corporate rewards and sanctions have significant effects on employee security behavior, but other motivational factors also reinforce the ISP’s compliance behavior. Distinguishing between types of corporations and organizations is essential to understanding employee compliance with information security procedures. Impact on Society This study offers another level of understanding of employee behavior with regard to information security in organizations and comprises a significant contribution to the growing knowledge in this area. The research results form an important basis for IS policymakers, culture designers, managers, and those directly responsible for IS in the organization. Future Research Future work should sample employees from another type of corporation from other fields and should apply qualitative analysis to explore other aspects of behavioral patterns related to the subject matter.
基于理性的信念和意识对员工遵守信息安全程序的影响:以以色列一家金融公司为例
目的/目的本文考察了金融公司员工在其组织内制定的信息安全程序方面的行为。此外,本文还探讨了信息安全意识在企业内部的作用及其重要性。本研究结合各种规范和个人能力,重点研究员工对信息安全政策合规的态度。一份自我报告问卷在一家大型金融公司的202名员工中分发。据我们所知,这是第一篇深入探讨以色列金融机构员工对信息系统程序意识的论文,也是第一篇为这些组织制定旨在提高ISP合规行为的操作建议的论文。本研究的主要贡献在于,它调查了在严格的监管治理、数据的机密性和隐私性以及严格的信息安全程序合规要求下运营的特定金融公司员工对信息安全实践的遵从性。研究结果表明,员工的态度、规范信念和个人能力对企业网络服务合规有正向影响。此外,员工对信息系统的普遍认识,以及公司内部对ISP的认识,对员工的ISP合规性有积极的影响。本研究可以帮助信息安全管理者识别员工行为的激励因素,以维护信息安全程序,正确引导信息安全资源,管理适当的信息安全行为。研究人员的建议研究人员可以看到,企业奖励和制裁对员工的安全行为有显著的影响,但其他激励因素也加强了ISP的合规行为。区分不同类型的公司和组织对于理解员工遵守信息安全程序是至关重要的。对社会的影响本研究提供了关于组织中信息安全的员工行为的另一个层面的理解,并对该领域不断增长的知识做出了重大贡献。研究结果为信息系统政策制定者、文化设计师、管理者和组织中直接负责信息系统的人员提供了重要依据。未来的研究未来的工作应该从其他领域的另一种类型的公司取样员工,应该应用定性分析来探索与主题相关的行为模式的其他方面。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
CiteScore
2.30
自引率
0.00%
发文量
14
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信