The effect of rational based beliefs and awareness on employee compliance with information security procedures: A case study of a financial corporation in Israel

被引:7
|
作者
Carmi G. [1 ]
Bouhnik D. [1 ]
机构
[1] Jerusalem College of Technology, Jerusalem
关键词
Employee compliance financial corporation; Information security awareness; Information security behavior; Information security management; Information security policy;
D O I
10.28945/4596
中图分类号
学科分类号
摘要
Aim/Purpose This paper examines the behavior of financial firm employees with regard to information security procedures instituted within their organization. Furthermore, the effect of information security awareness and its importance within a firm is explored. Background The study focuses on employees' attitude toward compliance with information security policies (ISP), combined with various norms and personal abilities. Methodology A self-reported questionnaire was distributed among 202 employees of a large financial Corporation Contribution As far as we know, this is the first paper to thoroughly explore employees' awareness of information system procedures, among financial organizations in Israel, and also the first to develop operative recommendations for these organizations aimed at increasing ISP compliance behavior. The main contribution of this study is that it investigates compliance with information security practices among employees of a defined financial corporation operating under rigid regulatory governance, confidentiality and privacy of data, and stringent requirements for compliance with information security procedures. Findings Our results indicate that employees' attitudes, normative beliefs and personal capabilities to comply with firm's ISP, have positive effects on the firm's ISP compliance. Also, employees' general awareness of IS, as well as awareness to ISP within the firm, positively affect employees' ISP compliance. Recommendations for Practitioners This study can help information security managers identify the motivating factors for employee behavior to maintain information security procedures, properly channel information security resources, and manage appropriate information security behavior. Recommendations for Researchers Researchers can see that corporate rewards and sanctions have significant effects on employee security behavior, but other motivational factors also reinforce the ISP's compliance behavior. Distinguishing between types of corporations and organizations is essential to understanding employee compliance with information security procedures. Impact on Society This study offers another level of understanding of employee behavior with regard to information security in organizations and comprises a significant contribution to the growing knowledge in this area. The research results form an important basis for IS policymakers, culture designers, managers, and those directly responsible for IS in the organization. Future Research Future work should sample employees from another type of corporation from other fields and should apply qualitative analysis to explore other aspects of behavioral patterns related to the subject matter. © 2020 Informing Science Institute. All rights reserved.
引用
收藏
页码:109 / 125
页数:16
相关论文
共 5 条
  • [1] INFORMATION SECURITY POLICY COMPLIANCE: AN EMPIRICAL STUDY OF RATIONALITY-BASED BELIEFS AND INFORMATION SECURITY AWARENESS
    Bulgurcu, Burcu
    Cavusoglu, Hasan
    Benbasat, Izak
    MIS QUARTERLY, 2010, 34 (03) : 523 - 548
  • [2] Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness
    Bulgurcu B.
    Cavusoglu H.
    Benbasat I.
    MIS Quarterly: Management Information Systems, 2010, 34 (SPEC. ISSUE 3): : 523 - 548
  • [3] Information Security Awareness Level Measurement for Employee: Case Study at Ministry of Research, Technology, and Higher Education
    Wahyudiwan, Doni Dwi Hantyoko
    Sucahyo, Yudho Giri
    Gandhi, Arfive
    2017 3RD INTERNATIONAL CONFERENCE ON SCIENCE IN INFORMATION TECHNOLOGY (ICSITECH), 2017, : 654 - 658
  • [4] Measuring Information Security Awareness on Employee Using HAIS-Q: Case Study at XYZ Firm
    Cindana, Alvin
    Ruldeviyani, Yova
    2018 INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER SCIENCE AND INFORMATION SYSTEMS (ICACSIS), 2018, : 289 - 294
  • [5] Measurement of Employee Information Security Awareness Using the Human Aspects of Information Security Questionnaire (HAIS-Q): Case Study at PT. PQS
    Zulfia, Aulia
    Adawiyah, Rodiatul
    Hidayanto, Achmad Nizar
    Budi, Nur Fitriah Ayuning
    2019 5TH INTERNATIONAL CONFERENCE ON COMPUTING, ENGINEERING, AND DESIGN (ICCED), 2019,