2012 · 68 citations · 45 references
EngineeringInformation SecurityUser AwarenessInformation Security EducationCommunicationInformation Security PoliciesOrganizational BehaviorSecurity AwarenessManagementWorkplace ComplianceInformation Security AwarenessPublic PolicyCompliance ManagementSecurity ManagementSecurity Policy ComplianceRegulatory ComplianceInformation ManagementInformation Security ManagementOrganizational CommunicationSecurityTechnologyRegulation
Information security policy compliance is a key concern for organizations, yet technical measures alone are insufficient; human, social, and organizational factors must be considered, as employees are both the weakest link and valuable assets. The study aims to develop a measurement tool to better predict and explain employees’ compliance with information security policies. It does so by examining how information security awareness enhances employees’ compliance. The study is the first to address compliance intention from a users’ perspective, and analysis results strongly support the proposed instrument, confirming the underlying theoretical model.
Information security policy compliance is one of the key concerns that face organizations today. Although, technical and procedural security measures help improve information security, there is an increased need to accommodate human, social and organizational factors. While employees are considered the weakest link in information security domain, they also are assets that organizations need to leverage effectively. Employees' compliance with Information Security Policies (ISPs) is critical to the success of an information security program. The purpose of this research is to develop a measurement tool that provides better measures for predicting and explaining employees' compliance with ISPs by examining the role of information security awareness in enhancing employees' compliance with ISPs. The study is the first to address compliance intention from a users' perspective. Overall, analysis results indicate strong support for the proposed instrument and represent an early confirmation for the validation of the underlying theoretical model.
45
User Acceptance of Information Technology: Toward A Unified View1
Venkatesh, Davis, Davis · MIS Quarterly · 2003 · 40.2K citations