建立促进和预防机制对中国中小企业信息系统安全政策至关重要

Hung-Pin Shih, K. Lai, Xitong Guo, T. Cheng
{"title":"建立促进和预防机制对中国中小企业信息系统安全政策至关重要","authors":"Hung-Pin Shih, K. Lai, Xitong Guo, T. Cheng","doi":"10.1109/INFOMAN.2016.7477543","DOIUrl":null,"url":null,"abstract":"Deterrence and rational choice calculus theories can regulate or motivate employees' compliance with information systems security policy (ISSP). However, the two well-developed theories may not fully induce compliance behavior of ISSP given the growing trend of IS security violation in China. Deterrence and rational choice calculus employ an assumption of general awareness of ISSP to address compliance behavior. However, employees may judge their compliance behavior of ISSP in terms of positive and negative emotions but not the trade-off of benefits and costs (risks) only in the compliance. Grounded in regulatory focus theory (RFT), we propose a research model that addresses the motivational mechanisms for employees to comply with ISSP. We adopt a scenario-based questionnaire to survey employees of Chinese SMEs for model testing. The empirical results indicate that promotion-approach is better than promotion-avoidance in motivating compliance intention when employees are aware of the ISSP in their companies. However, promotion-approach and promotion-avoidance are ineffective in inducing compliance intention when employees are unaware of ISSP in Chinese SMEs. Information security awareness is not a necessary condition of the compliance of ISSP. Additionally, prevention-approach is better than prevention-avoidance in motivating compliance intention regardless of whether employees are aware or unaware of ISSP in the workplace. Our empirical results can provide meaningful implications for academics and practitioners.","PeriodicalId":182252,"journal":{"name":"2016 2nd International Conference on Information Management (ICIM)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-05-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"Taking promotion and prevention mechanisms matter for information systems security policy in Chinese SMEs\",\"authors\":\"Hung-Pin Shih, K. Lai, Xitong Guo, T. Cheng\",\"doi\":\"10.1109/INFOMAN.2016.7477543\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Deterrence and rational choice calculus theories can regulate or motivate employees' compliance with information systems security policy (ISSP). However, the two well-developed theories may not fully induce compliance behavior of ISSP given the growing trend of IS security violation in China. Deterrence and rational choice calculus employ an assumption of general awareness of ISSP to address compliance behavior. However, employees may judge their compliance behavior of ISSP in terms of positive and negative emotions but not the trade-off of benefits and costs (risks) only in the compliance. Grounded in regulatory focus theory (RFT), we propose a research model that addresses the motivational mechanisms for employees to comply with ISSP. We adopt a scenario-based questionnaire to survey employees of Chinese SMEs for model testing. The empirical results indicate that promotion-approach is better than promotion-avoidance in motivating compliance intention when employees are aware of the ISSP in their companies. However, promotion-approach and promotion-avoidance are ineffective in inducing compliance intention when employees are unaware of ISSP in Chinese SMEs. Information security awareness is not a necessary condition of the compliance of ISSP. Additionally, prevention-approach is better than prevention-avoidance in motivating compliance intention regardless of whether employees are aware or unaware of ISSP in the workplace. Our empirical results can provide meaningful implications for academics and practitioners.\",\"PeriodicalId\":182252,\"journal\":{\"name\":\"2016 2nd International Conference on Information Management (ICIM)\",\"volume\":\"22 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-05-07\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 2nd International Conference on Information Management (ICIM)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/INFOMAN.2016.7477543\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 2nd International Conference on Information Management (ICIM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/INFOMAN.2016.7477543","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

摘要

威慑理论和理性选择演算理论可以调节或激励员工遵守信息系统安全策略。然而,鉴于中国IS安全违规的增长趋势,这两种成熟的理论可能无法完全诱导ISSP的合规行为。威慑和理性选择演算采用ISSP普遍意识的假设来解决合规行为。然而,员工可能会从积极情绪和消极情绪的角度来判断自己对ISSP的合规行为,而不是只从合规的利益与成本(风险)的权衡来判断。基于监管焦点理论(RFT),我们提出了一个研究员工遵守ISSP的激励机制的模型。我们采用场景式问卷对中国中小企业员工进行调查,进行模型检验。实证结果表明,当员工意识到企业内部的信息安全策略时,提升策略比提升规避策略更能激发员工的合规意愿。然而,在中国中小企业中,当员工不了解ISSP时,晋升-接近和晋升-回避在诱导合规意愿方面是无效的。信息安全意识不是ISSP合规的必要条件。此外,无论员工是否意识到工作场所的ISSP,预防方法都比预防避免更能激发合规意愿。我们的实证结果可以为学术界和实践者提供有意义的启示。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Taking promotion and prevention mechanisms matter for information systems security policy in Chinese SMEs
Deterrence and rational choice calculus theories can regulate or motivate employees' compliance with information systems security policy (ISSP). However, the two well-developed theories may not fully induce compliance behavior of ISSP given the growing trend of IS security violation in China. Deterrence and rational choice calculus employ an assumption of general awareness of ISSP to address compliance behavior. However, employees may judge their compliance behavior of ISSP in terms of positive and negative emotions but not the trade-off of benefits and costs (risks) only in the compliance. Grounded in regulatory focus theory (RFT), we propose a research model that addresses the motivational mechanisms for employees to comply with ISSP. We adopt a scenario-based questionnaire to survey employees of Chinese SMEs for model testing. The empirical results indicate that promotion-approach is better than promotion-avoidance in motivating compliance intention when employees are aware of the ISSP in their companies. However, promotion-approach and promotion-avoidance are ineffective in inducing compliance intention when employees are unaware of ISSP in Chinese SMEs. Information security awareness is not a necessary condition of the compliance of ISSP. Additionally, prevention-approach is better than prevention-avoidance in motivating compliance intention regardless of whether employees are aware or unaware of ISSP in the workplace. Our empirical results can provide meaningful implications for academics and practitioners.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信