Privilege or procedure: Evaluating the effect of employee status on intent to comply with socially interactive information security threats and controls

被引:18
作者
Aurigemma, Salvatore [1 ]
Mattson, Thomas [2 ]
机构
[1] Univ Tulsa, 800 S Tucker Dr, Tulsa, OK 74104 USA
[2] Univ Richmond, 28 Westhampton Way, Richmond, VA 23173 USA
关键词
Theory of planned behavior; Information security policies; Status; Tailgating; Decomposition of perceived behavioral control; Self-efficacy; Controllability; Hierarchical organizations; PROTECTION MOTIVATION; POLICY COMPLIANCE; PLANNED BEHAVIOR; SYSTEMS SECURITY; STATUS HIERARCHIES; SELF-EFFICACY; FIT INDEXES; CULTURE; POWER; DETERRENCE;
D O I
10.1016/j.cose.2017.02.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Existing information security literature does not account for an employee's status (hierarchical relationship (rank order) among employees) within the organizational chain of command when theorizing about his/her information security policy compliance behaviors and behavioral intentions. We argue that this is a potentially important theoretical gap specifically concerning socially interactive threats and controls within hierarchical organizations, because an individual's status within these types of social structures impacts his/her capacity to control another person's resources, behaviors, and outcomes. In this paper, we investigate the main and moderating effect of an employee's status within the organizational hierarchy on an individual's perceived behavioral control related to interactive security threats and controls, specifically tailgating (i.e., the act of gaining access to a restricted area by following someone who has legitimate access). In a survey of Department of Defense employees, we find that the effect of status on perceived behavioral control over tailgating behaviors is positive for employees who report average and above average levels of controllability of coworkers but negative for employees who report below average levels of controllability of coworkers. Our paper has both theoretical and practical value for socially interactive security behaviors within hierarchical organizations with respected levels of command and control. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:218 / 234
页数:17
相关论文
共 103 条
  • [61] Kline R. B., 2016, Principles and Practice of Structural Equation Modeling, V4th
  • [62] ORGANIZATIONAL GROWTH OF SMALL FIRMS - AN OUTCOME OF MARKETS AND HIERARCHIES
    LAZERSON, MH
    [J]. AMERICAN SOCIOLOGICAL REVIEW, 1988, 53 (03) : 330 - 342
  • [63] Generalizing generalizability in information systems research
    Lee, AS
    Baskerville, RL
    [J]. INFORMATION SYSTEMS RESEARCH, 2003, 14 (03) : 221 - 243
  • [64] LUO X, 2012, INT J ACCOUNT INF MA, V20, P335
  • [65] MacGregor W, COMPUTER SECURITY DI
  • [66] Social Hierarchy: The Self-Reinforcing Nature of Power and Status
    Magee, Joe C.
    Galinsky, Adam D.
    [J]. ACADEMY OF MANAGEMENT ANNALS, 2008, 2 : 351 - 398
  • [67] In search of golden rules: Comment on hypothesis-testing approaches to setting cutoff values for fit indexes and dangers in overgeneralizing Hu and Bentler's (1999) findings
    Marsh, HW
    Hau, KT
    Wen, ZL
    [J]. STRUCTURAL EQUATION MODELING-A MULTIDISCIPLINARY JOURNAL, 2004, 11 (03) : 320 - 341
  • [68] Martin JL, 2009, SOCIAL STRUCTURES, P1
  • [69] Prospective prediction of health-related behaviours with the Theory of Planned Behaviour: a meta-analysis
    McEachan, Rosemary Robin Charlotte
    Conner, Mark
    Taylor, Natalie Jayne
    Lawton, Rebecca Jane
    [J]. HEALTH PSYCHOLOGY REVIEW, 2011, 5 (02) : 97 - 144
  • [70] Morgan J., 2014, The future of work: Attract new talent, build better leaders, and create a competitive organization