Ensuring employees' information security policy compliance by carrot and stick: the moderating roles of organizational commitment and gender

被引:19
作者
Liu, Chenhui [1 ,2 ]
Liang, Huigang [3 ]
Wang, Nengmin [1 ,2 ]
Xue, Yajiong [4 ]
机构
[1] Xi An Jiao Tong Univ, Sch Management, Xian, Peoples R China
[2] ERC Proc Min Mfg Serv Shaanxi Prov, Xian, Peoples R China
[3] Univ Memphis, Fogelman Coll Business & Econ, Memphis, TN 38152 USA
[4] East Carolina Univ, Coll Business, Greenville, NC 27858 USA
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
Information security policy compliance; Organizational commitment; Punishment expectancy; Reward expectancy; Gender difference; COMMON METHOD VARIANCE; PROTECTION MOTIVATION; BEHAVIORAL-RESEARCH; SYSTEMS MISUSE; DETERRENCE; IMPACT; MODEL; ANTECEDENTS; TECHNOLOGY; FRAMEWORK;
D O I
10.1108/ITP-09-2019-0452
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Purpose Employees' information security policy (ISP) compliance exerts a significant strain on information security management. Drawing upon the compliance theory and control theory, this study attempts to examine the moderating roles of organizational commitment and gender in the relationships between reward/punishment expectancy and employees' ISP compliance. Design/methodology/approach Using survey data collected from 310 employees in Chinese organizations that have formally adopted information security policies, the authors applied the partial least square method to test hypotheses. Findings Punishment expectancy positively affects ISP compliance, but reward expectancy has no significant impact on ISP compliance. Compared with committed employees, both reward expectancy and punishment expectancy have stronger impacts on low-commitment employees' ISP compliance. As for gender differences, punishment expectancy exerts a stronger effect on females' ISP compliance than it does on males. Originality/value By investigating the moderating roles of organizational commitment and gender, this paper offers a deeper understanding of reward and punishment in the context of ISP compliance. The findings reveal that efforts in building organizational commitment will reduce the reliance on reward and punishment, and further controls rather than the carrot and stick should be applied to ensure male employees' ISP compliance.
引用
收藏
页码:802 / 834
页数:33
相关论文
共 90 条
[1]   The information security digital divide between information security managers and users [J].
Albrechtsen, Eirik ;
Hovden, Jan .
COMPUTERS & SECURITY, 2009, 28 (06) :476-490
[2]   Employees' behavioural intention to smartphone security: A gender-based, cross-national study [J].
Ameen, Nisreen ;
Tarhini, Ali ;
Shah, Mahmood Hussain ;
Madichie, Nnamdi O. .
COMPUTERS IN HUMAN BEHAVIOR, 2020, 104
[3]  
Anderson CL, 2010, MIS QUART, V34, P613
[4]  
Bansal G., 2016, P 11 MIDW US ASS INF, P1
[5]   Information system security policy noncompliance: the role of situation-specific ethical orientation [J].
Bansal, Gaurav ;
Muzatko, Steven ;
Shin, Soo Il .
INFORMATION TECHNOLOGY & PEOPLE, 2021, 34 (01) :250-296
[6]   GENDER DIFFERENCES IN RISK AVERSION AND AMBIGUITY AVERSION [J].
Borghans, Lex ;
Heckman, James J. ;
Golsteyn, Bart H. H. ;
Meijers, Huub .
JOURNAL OF THE EUROPEAN ECONOMIC ASSOCIATION, 2009, 7 (2-3) :649-658
[7]   If someone is watching, I'll do what I'm asked: mandatoriness, control, and information security [J].
Boss, Scott R. ;
Kirsch, Laurie J. ;
Angermeier, Ingo ;
Shingler, Raymond A. ;
Boss, R. Wayne .
EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2009, 18 (02) :151-164
[8]  
Brislin R., 1980, Handbook of cross-cultural psychology, V2, P389
[9]  
Bulgurcu B, 2010, MIS QUART, V34, P523
[10]  
Chan M., 2005, Journal of information privacy and security, V1, P18, DOI [10.1080/15536548.2005.10855772, DOI 10.1080/15536548.2005.10855772]