组织违反外部治理的隐私和安全规则:在紧张和过度条件下的选择性违反的解释和预测

Jeffrey D. Wall, P. Lowry, Jordan B. Barlow
{"title":"组织违反外部治理的隐私和安全规则:在紧张和过度条件下的选择性违反的解释和预测","authors":"Jeffrey D. Wall, P. Lowry, Jordan B. Barlow","doi":"10.17705/1jais.00420","DOIUrl":null,"url":null,"abstract":"Privacy and security concerns are pervasive because of the ease of access to information. Recurrent negative cases in the popular press attest to the failure of current privacy regulations to keep consumer and protected health information sufficiently secure in today’s climate of increased IT use. One reason for such failure is that organizations violate these regulations for multiple reasons. To address this issue, we propose a theoretical model to explain the likelihood that organizations will select an externally governed privacy or security rule for violation in response to organizational strain or slack resources. Our proposed theoretical model, the selective organizational information privacy and security violations model (SOIPSVM), explains how organizational structures and processes, along with characteristics of regulatory rules, alter perceptions of risk when an organization’s performance does not match its aspiration levels and thereby affects the likelihood of rule violations. Importantly, SOIPSVM is contextualized to organizational privacy and security violations. SOIPSVM builds on and extends the selective organizational rule violations model (SORVM), which posits that organizational rule violations are selective. SOIPSVM provides at least four contributions to the privacy and security literature that can further guide empirical research and practice. First, SOIPSVM introduces the concept of selectivity in rule violations to privacy and security research. This concept can improve privacy and security research by showing that organizational violations of privacy and security rules are dynamic and selective yet influenced by external forces. Second, SOIPSVM extends the boundaries of SORVM, which is limited to explaining the behavior of organizations under strain, such as economic hardship. We contribute to the theory of selective deviance by proposing that selectivity extends to organizations with slack resources. Third, we address ideas of non-economic risk and strain in addition to economic risk and strain. SOIPSVM thus explains organizational rule-violating behavior as an attempt to protect core organizational values from external entities that pressure organizations to change their values to comply with rules. Fourth, we broaden the theoretical scope of two important constructs, namely structural secrecy and procedural emphasis to improve the explanatory power of the model. Fifth, we identify important elements of rule enforcement by drawing from the tenets of general deterrence theory. We also discuss how constructs from general deterrence theory can be studied at the organizational level. To conclude, we offer recommendations for the structuring of organizations and external regulations to decrease organizational rule violations, which often lead to the abuse of consumer information.","PeriodicalId":401061,"journal":{"name":"LSN: Consumer Privacy (Sub-Topic)","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-05-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"64","resultStr":"{\"title\":\"Organizational Violations of Externally Governed Privacy and Security Rules: Explaining and Predicting Selective Violations Under Conditions of Strain and Excess\",\"authors\":\"Jeffrey D. Wall, P. Lowry, Jordan B. Barlow\",\"doi\":\"10.17705/1jais.00420\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Privacy and security concerns are pervasive because of the ease of access to information. Recurrent negative cases in the popular press attest to the failure of current privacy regulations to keep consumer and protected health information sufficiently secure in today’s climate of increased IT use. One reason for such failure is that organizations violate these regulations for multiple reasons. To address this issue, we propose a theoretical model to explain the likelihood that organizations will select an externally governed privacy or security rule for violation in response to organizational strain or slack resources. Our proposed theoretical model, the selective organizational information privacy and security violations model (SOIPSVM), explains how organizational structures and processes, along with characteristics of regulatory rules, alter perceptions of risk when an organization’s performance does not match its aspiration levels and thereby affects the likelihood of rule violations. Importantly, SOIPSVM is contextualized to organizational privacy and security violations. SOIPSVM builds on and extends the selective organizational rule violations model (SORVM), which posits that organizational rule violations are selective. SOIPSVM provides at least four contributions to the privacy and security literature that can further guide empirical research and practice. First, SOIPSVM introduces the concept of selectivity in rule violations to privacy and security research. This concept can improve privacy and security research by showing that organizational violations of privacy and security rules are dynamic and selective yet influenced by external forces. Second, SOIPSVM extends the boundaries of SORVM, which is limited to explaining the behavior of organizations under strain, such as economic hardship. We contribute to the theory of selective deviance by proposing that selectivity extends to organizations with slack resources. Third, we address ideas of non-economic risk and strain in addition to economic risk and strain. SOIPSVM thus explains organizational rule-violating behavior as an attempt to protect core organizational values from external entities that pressure organizations to change their values to comply with rules. Fourth, we broaden the theoretical scope of two important constructs, namely structural secrecy and procedural emphasis to improve the explanatory power of the model. Fifth, we identify important elements of rule enforcement by drawing from the tenets of general deterrence theory. We also discuss how constructs from general deterrence theory can be studied at the organizational level. To conclude, we offer recommendations for the structuring of organizations and external regulations to decrease organizational rule violations, which often lead to the abuse of consumer information.\",\"PeriodicalId\":401061,\"journal\":{\"name\":\"LSN: Consumer Privacy (Sub-Topic)\",\"volume\":\"12 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2015-05-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"64\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"LSN: Consumer Privacy (Sub-Topic)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.17705/1jais.00420\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"LSN: Consumer Privacy (Sub-Topic)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.17705/1jais.00420","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 64

摘要

由于获取信息很容易,隐私和安全问题普遍存在。大众媒体上反复出现的负面案例证明,在当今IT使用日益增加的环境下,当前的隐私法规未能确保消费者和受保护的健康信息的充分安全。这种失败的一个原因是组织出于多种原因违反了这些规定。为了解决这个问题,我们提出了一个理论模型来解释组织在应对组织紧张或资源松弛时选择违反外部治理的隐私或安全规则的可能性。我们提出的理论模型,选择性组织信息隐私和安全违规模型(SOIPSVM),解释了当组织的绩效与其期望水平不匹配时,组织结构和流程以及监管规则的特征如何改变对风险的感知,从而影响违反规则的可能性。重要的是,SOIPSVM被上下文化为组织隐私和安全违规。SOIPSVM建立并扩展了选择性组织规则违反模型(SORVM),该模型假定组织规则违反是选择性的。SOIPSVM为隐私和安全文献提供了至少四项贡献,可以进一步指导实证研究和实践。首先,SOIPSVM将规则违反的选择性概念引入到隐私和安全研究中。这一概念表明,组织对隐私和安全规则的违反是动态的、有选择性的,但受到外部力量的影响,可以改善隐私和安全研究。其次,SOIPSVM扩展了SORVM的边界,SORVM仅限于解释组织在压力下(如经济困难)的行为。我们通过提出选择性延伸到资源松弛的组织,为选择性偏差理论做出了贡献。第三,除了经济风险和压力之外,我们还讨论了非经济风险和压力的概念。因此,SOIPSVM将组织违反规则的行为解释为保护组织核心价值免受外部实体的影响,这些外部实体迫使组织改变价值观以遵守规则。第四,拓宽了结构保密和程序强调两个重要构式的理论范围,提高了模型的解释力。第五,我们通过借鉴一般威慑理论的原则来确定规则执行的重要要素。我们还讨论了如何在组织层面上研究一般威慑理论的构念。最后,我们为组织结构和外部法规提供建议,以减少组织规则违规,这通常会导致消费者信息的滥用。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Organizational Violations of Externally Governed Privacy and Security Rules: Explaining and Predicting Selective Violations Under Conditions of Strain and Excess
Privacy and security concerns are pervasive because of the ease of access to information. Recurrent negative cases in the popular press attest to the failure of current privacy regulations to keep consumer and protected health information sufficiently secure in today’s climate of increased IT use. One reason for such failure is that organizations violate these regulations for multiple reasons. To address this issue, we propose a theoretical model to explain the likelihood that organizations will select an externally governed privacy or security rule for violation in response to organizational strain or slack resources. Our proposed theoretical model, the selective organizational information privacy and security violations model (SOIPSVM), explains how organizational structures and processes, along with characteristics of regulatory rules, alter perceptions of risk when an organization’s performance does not match its aspiration levels and thereby affects the likelihood of rule violations. Importantly, SOIPSVM is contextualized to organizational privacy and security violations. SOIPSVM builds on and extends the selective organizational rule violations model (SORVM), which posits that organizational rule violations are selective. SOIPSVM provides at least four contributions to the privacy and security literature that can further guide empirical research and practice. First, SOIPSVM introduces the concept of selectivity in rule violations to privacy and security research. This concept can improve privacy and security research by showing that organizational violations of privacy and security rules are dynamic and selective yet influenced by external forces. Second, SOIPSVM extends the boundaries of SORVM, which is limited to explaining the behavior of organizations under strain, such as economic hardship. We contribute to the theory of selective deviance by proposing that selectivity extends to organizations with slack resources. Third, we address ideas of non-economic risk and strain in addition to economic risk and strain. SOIPSVM thus explains organizational rule-violating behavior as an attempt to protect core organizational values from external entities that pressure organizations to change their values to comply with rules. Fourth, we broaden the theoretical scope of two important constructs, namely structural secrecy and procedural emphasis to improve the explanatory power of the model. Fifth, we identify important elements of rule enforcement by drawing from the tenets of general deterrence theory. We also discuss how constructs from general deterrence theory can be studied at the organizational level. To conclude, we offer recommendations for the structuring of organizations and external regulations to decrease organizational rule violations, which often lead to the abuse of consumer information.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信