Organizational Governance, Social Bonds and Information Security Policy Compliance: A Perspective towards Oil and Gas Employees

被引:20
作者
Ali, Rao Faizan [1 ]
Dominic, P. D. D. [1 ]
Ali, Kashif [2 ]
机构
[1] Univ Teknol PETRONAS, Dept Comp & Informat Sci, Bandar Seri Iskandar 32610, Perak, Malaysia
[2] COMSATS Univ Islamabad, Dept Management Sci, Islamabad 46000, Pakistan
关键词
information security policy compliance; social bond theory; organizational governance; O& G organizations; behavioral intentions; PROTECTION MOTIVATION; USER SECURITY; SYSTEMS; DETERRENCE; BEHAVIOR; AWARENESS; INSIGHTS; IMPACT; MODEL; NEUTRALIZATION;
D O I
10.3390/su12208576
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
Information security attacks on oil and gas (O&G) organizations have increased since the last decade. From 2015 to 2019, almost 70 percent of O&G organizations faced at least one significant security breach worldwide. Research has shown that 43 percent of security attacks on O&G organizations occur due to the non-compliant behavior of O&G employees towards information security policy. The existing literature provides multiple solutions for technical security controls of O&G organizations. However, there are very few studies available that address behavioral security controls, specifically for O&G organizations of developing countries. The purpose of this study is to provide a comprehensive framework for information security policy compliance (ISPC) for the O&G sector. A mixed-method approach is used to develop the research framework. Semi-structured interviews from O&G specialists refined the developed framework. Based on qualitative study a survey questionnaire was developed. To evaluate the research framework, structural equation modeling was applied to a sample of 254 managers/executives from 150 Malaysian O&G organizations. The obtained test results confirmed the proposed research model, according to which good social bonding among employees plays a critical role in improving ISPC. However, there was less support for the notion that all organizational governance factors significantly improve the social bonding of Malaysian O&G organizations employees. This paper contributes to the current information system (IS) literature by exploring the interrelationships among organizational governance, social bonding, and information security policy compliance (ISPC) in Malaysian O&G organizations.
引用
收藏
页码:1 / 27
页数:27
相关论文
共 94 条
[11]  
Burdenski T., 2000, Multiple Linear Regression Viewpoints, V26, P15
[12]   Examining the relationship of organizational insiders' psychological capital with information security threat and coping appraisals [J].
Burns, A. J. ;
Posey, Clay ;
Roberts, Tom L. ;
Lowry, Paul Benjamin .
COMPUTERS IN HUMAN BEHAVIOR, 2017, 68 :190-209
[13]  
Byrne B.M., 2013, Multivariate Applications Series: Structural Equation Modeling with Mplus: Basic Concepts, Applications, and Programming
[14]   Protective Measures and Security Policy Non-Compliance Intention: IT Vision Conflict as a Moderator [J].
Chang, Kuo-Chung ;
Seow, Yoke May .
JOURNAL OF ORGANIZATIONAL AND END USER COMPUTING, 2019, 31 (01) :1-21
[15]  
Chapple W., 2005, BUSINESS SOC, V44, P415, DOI DOI 10.1177/0007650305281658
[16]   IMPACTS OF COMPREHENSIVE INFORMATION SECURITY PROGRAMS ON INFORMATION SECURITY CULTURE [J].
Chen, Yan ;
Ramamurthy, K. ;
Wen, Kuang-Wei .
JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2015, 55 (03) :11-19
[17]   Understanding the violation of IS security policy in organizations: An integrated model based on social control and deterrence theory [J].
Cheng, Lijiao ;
Li, Ying ;
Li, Wenli ;
Holm, Eric ;
Zhai, Qingguo .
COMPUTERS & SECURITY, 2013, 39 :447-459
[18]  
Chin W., 2000, Proceedings of the 2000 ICIS, P741
[19]  
Chin W.W, 1998, Technol Stud, V2, P315
[20]   Explaining the Misuse of Information Systems Resources in the Workplace: A Dual-Process Approach [J].
Chu, Amanda M. Y. ;
Chau, Patrick Y. K. ;
So, Mike K. P. .
JOURNAL OF BUSINESS ETHICS, 2015, 131 (01) :209-225