The role of abusive supervision and organizational commitment on employees' information security policy noncompliance intention

被引:27
作者
Guan, Bowen [1 ]
Hsu, Carol [1 ]
机构
[1] Tongji Univ, Shanghai, Peoples R China
基金
中国国家自然科学基金;
关键词
Information security policy noncompliance; Abusive supervision; Organizational commitment; Moderation effect of sanctions; STRUCTURAL EQUATION MODELS; LATENT INTERACTIONS; WORKPLACE DEVIANCE; COMPUTER ABUSE; BOARD-LEVEL; DETERRENCE; WORK; NEUTRALIZATION; ANTECEDENTS; TECHNOLOGY;
D O I
10.1108/INTR-06-2019-0260
中图分类号
F [经济];
学科分类号
02 ;
摘要
Purpose The purpose of this paper is to investigate the association between abusive supervision and employees' information security policy (ISP) noncompliance intention, building on affective commitment, normative commitment and continuance commitment. The study also examines the moderating effect of perceived certainty and severity of sanctions on the relationship between the three dimensions of organizational commitment and ISP noncompliance intention. Design/methodology/approach Survey methodology was used for data collection through a well-designed online questionnaire. Data was analyzed using the structural equation model with Amos v. 22.0 software. Findings This study demonstrates that abusive supervision has a significant, negative impact on affective, normative and continuance commitment, and the three dimensions of organizational commitment are negatively associated with employees' ISP noncompliance intention. Results also indicate that the moderating effect of perceived severity of sanctions is significant, and perceived certainty of sanctions plays a positive moderating role in the relationship between affective commitment and employees' ISP noncompliance intention. Practical implications Findings of this research are beneficial for organizational management in the relationships between supervisors and employees. These results provide significant evidence that avoiding abusive supervision is important in controlling employees' ISP noncompliance behavior. Originality/value This research fills an important gap in examining employees' ISP noncompliance intentions from the perspective of abusive supervision and the impact of affective, normative and continuance commitment on ISP noncompliance. The study is also of great value for information systems research to examine the moderating role of perceived certainty and severity of sanctions.
引用
收藏
页码:1383 / 1405
页数:23
相关论文
共 85 条
[21]  
Henle C.A., 2008, Journal of Managerial Issues, VXX, P383
[22]   Protection motivation and deterrence: a framework for security policy compliance in organisations [J].
Herath, Tejaswini ;
Rao, H. Raghav .
EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2009, 18 (02) :106-125
[23]   Encouraging information security behaviors in organizations: Role of penalties, pressures and perceived effectiveness [J].
Herath, Tejaswini ;
Rao, H. R. .
DECISION SUPPORT SYSTEMS, 2009, 47 (02) :154-165
[24]   The Relationship between Board-Level Technology Committees and Reported Security Breaches [J].
Higgs, Julia L. ;
Pinsker, Robert E. ;
Smith, Thomas J. ;
Young, George R. .
JOURNAL OF INFORMATION SYSTEMS, 2016, 30 (03) :79-98
[25]  
Hsu C., 2014, Handbook of Research on Digital Crime, Cyberspace Security, and Information Assurance, P1436
[26]  
Hsu Carol, 2014, Asia Pacific Journal of Information Systems, V24, P531
[27]  
Hu Q, 2012, DECISION SCI, V43, P615, DOI 10.1111/j.1540-5915.2012.00361.x
[28]   Does Deterrence Work in Reducing Information Security Policy Abuse by Employees? [J].
Hu, Qing ;
Xu, Zhengchuan ;
Dinev, Tamara ;
Ling, Hong .
COMMUNICATIONS OF THE ACM, 2011, 54 (06) :54-60
[29]   Examining technostress creators and role stress as potential threats to employees' information security compliance [J].
Hwang, Inho ;
Cha, Oona .
COMPUTERS IN HUMAN BEHAVIOR, 2018, 81 :282-293
[30]   Understanding supervisor-targeted aggression: A within-person, between-jobs design [J].
Inness, M ;
Barling, J ;
Tumer, N .
JOURNAL OF APPLIED PSYCHOLOGY, 2005, 90 (04) :731-739