COVID-19 pandemic-induced organisational cultural shifts and employee information security compliance behaviour: a South African case study

被引:4
作者
Butler, Kiara Jordan [1 ]
Brown, Irwin [1 ]
机构
[1] Univ Cape Town, Dept Informat Syst, Cape Town, South Africa
关键词
Organisational culture; Information security culture; Environmental disruption; Pandemic; COVID-19; Compliance; Information security; Competing values framework; South Africa; SYSTEMS; NONCOMPLIANCE; MANAGEMENT; POLICIES;
D O I
10.1108/ICS-09-2022-0152
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
PurposeThe purpose of this preliminary empirical research study is to understand how environmental disruption such as brought on by the COVID-19 pandemic induces shifts in organisational culture, information security culture and subsequently employee information security compliance behaviour. Design/methodology/approachA single-organisation case study was used to develop understanding from direct experiences of organisational life. Both quantitative and qualitative data were collected using a sequential mixed methods approach, with the qualitative phase following the quantitative to achieve complementarity and completeness in analysis. For the quantitative phase, 48 useful responses were received after a questionnaire was sent to all 150-200 employees. For the qualitative phase, eight semi-structured interviews were conducted. Statistical software was used to analyse the quantitative data and NVivo software was used to analyse the qualitative data. FindingsThe pandemic-induced environmental disruption manifested as a sudden shift to work-from-home for employees, and relatedly an increase in cybercrime. The organisational response to this gave rise to shifts in both organisational and information security culture towards greater control (rule and goal orientations) and greater flexibility (support and innovation orientations), most significantly with information security culture flexibility. The net effect was an increase in employee information security compliance. Originality/valueThe vast literature on organisational culture and information security culture was drawn on to theoretically anchor and develop parsimonious measures of information security culture. Environmental disruptions such as those caused by the pandemic are unpredictable and their effects uncertain, hence, the study provides insight into the consequences of such disruption on information security in organisations.
引用
收藏
页码:221 / 243
页数:23
相关论文
共 58 条