Privilege or procedure: Evaluating the effect of employee status on intent to comply with socially interactive information security threats and controls

被引:18
作者
Aurigemma, Salvatore [1 ]
Mattson, Thomas [2 ]
机构
[1] Univ Tulsa, 800 S Tucker Dr, Tulsa, OK 74104 USA
[2] Univ Richmond, 28 Westhampton Way, Richmond, VA 23173 USA
关键词
Theory of planned behavior; Information security policies; Status; Tailgating; Decomposition of perceived behavioral control; Self-efficacy; Controllability; Hierarchical organizations; PROTECTION MOTIVATION; POLICY COMPLIANCE; PLANNED BEHAVIOR; SYSTEMS SECURITY; STATUS HIERARCHIES; SELF-EFFICACY; FIT INDEXES; CULTURE; POWER; DETERRENCE;
D O I
10.1016/j.cose.2017.02.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Existing information security literature does not account for an employee's status (hierarchical relationship (rank order) among employees) within the organizational chain of command when theorizing about his/her information security policy compliance behaviors and behavioral intentions. We argue that this is a potentially important theoretical gap specifically concerning socially interactive threats and controls within hierarchical organizations, because an individual's status within these types of social structures impacts his/her capacity to control another person's resources, behaviors, and outcomes. In this paper, we investigate the main and moderating effect of an employee's status within the organizational hierarchy on an individual's perceived behavioral control related to interactive security threats and controls, specifically tailgating (i.e., the act of gaining access to a restricted area by following someone who has legitimate access). In a survey of Department of Defense employees, we find that the effect of status on perceived behavioral control over tailgating behaviors is positive for employees who report average and above average levels of controllability of coworkers but negative for employees who report below average levels of controllability of coworkers. Our paper has both theoretical and practical value for socially interactive security behaviors within hierarchical organizations with respected levels of command and control. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:218 / 234
页数:17
相关论文
共 103 条
  • [1] Perceived behavioral control, self-efficacy, locus of control, and the theory of planned behavior
    Ajzen, I
    [J]. JOURNAL OF APPLIED SOCIAL PSYCHOLOGY, 2002, 32 (04) : 665 - 683
  • [2] THE THEORY OF PLANNED BEHAVIOR
    AJZEN, I
    [J]. ORGANIZATIONAL BEHAVIOR AND HUMAN DECISION PROCESSES, 1991, 50 (02) : 179 - 211
  • [3] TEACHERS' BELIEFS AND THE FORMATION OF ENTREPRENEURIAL POTENTIAL IN STUDENTS
    Cruz, Tamara de la Torre
    Escolar-Llamazares, Maria-Camino
    Valle, Cristina Di Giusto
    Rico, Isabel Luis
    Eguizabal, Alfredo Jimenez
    Jimenez, Alfredo
    [J]. INTERCIENCIA, 2023, 48 (08) : 398 - 408
  • [4] Anderson CL, 2010, MIS QUART, V34, P613
  • [5] [Anonymous], 2006, J COMMUN, DOI DOI 10.1111/j.1460-2466.2006.00280.x
  • [6] [Anonymous], 2000, A first course in structural equation modeling
  • [7] [Anonymous], 2007, J ASS INF SYS
  • [8] [Anonymous], 2013, 270022013 ISOIEC
  • [9] Positive and negative deviant workplace behaviors: causes, impacts, and solutions
    Appelbaum, Steven H.
    Iaconi, Giulio David
    Matousek, Albert
    [J]. CORPORATE GOVERNANCE-THE INTERNATIONAL JOURNAL OF BUSINESS IN SOCIETY, 2007, 7 (05): : 586 - +
  • [10] Efficacy of the theory of planned behaviour: A meta-analytic review
    Armitage, CJ
    Conner, M
    [J]. BRITISH JOURNAL OF SOCIAL PSYCHOLOGY, 2001, 40 : 471 - 499