Dawei (David) Wang, Alexandra Durcikova, A. Dennis
{"title":"Security is Local: The Influence of the Immediate Workgroup on Information Security","authors":"Dawei (David) Wang, Alexandra Durcikova, A. Dennis","doi":"10.17705/1jais.00812","DOIUrl":null,"url":null,"abstract":"Information security is a multilevel phenomenon with employee security decisions being influenced by macrolevel factors (e.g., organizational policies), mesolevel factors (e.g., one’s immediate workgroup—IW), and microlevel factors (e.g., individual personalities). We argue that an employee’s local IW (i.e., immediate supervisor and coworkers) has a strong effect on security. This paper focuses on the effects of these mesolevel factors in the presence of macro- and microlevel factors. Drawing on the social structure and social learning framework as well as workgroup research, we hypothesize that the security behavior of an employee’s IW supervisor and coworkers moderated by the nature of these relationships influences information security decisions. Our research, based on a sample of 217 full-time employees, reveals that the IW significantly affects security decisions, over and above the micro- and macrolevel factors. These effects are moderated by the nature of the relationship between employees and their IW supervisor (leader-member exchange) and coworkers (team-member exchange). A post hoc analysis shows that the mesolevel factors alone had the same explanatory power as the micro- and macrolevels combined. Our research suggests that future theory and research should include the IW and that organizations should share security responsibilities with line managers and help them understand their substantial impact on information security. Security training programs should ask employees about the behaviors of their IW supervisor and coworkers and, where needed, deliver anti-neutralization training to mitigate the effects of the IW’s noncompliance behaviors.","PeriodicalId":51101,"journal":{"name":"Journal of the Association for Information Systems","volume":"60 1","pages":"4"},"PeriodicalIF":7.0000,"publicationDate":"2023-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of the Association for Information Systems","FirstCategoryId":"91","ListUrlMain":"https://doi.org/10.17705/1jais.00812","RegionNum":3,"RegionCategory":"管理学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 1
Abstract
Information security is a multilevel phenomenon with employee security decisions being influenced by macrolevel factors (e.g., organizational policies), mesolevel factors (e.g., one’s immediate workgroup—IW), and microlevel factors (e.g., individual personalities). We argue that an employee’s local IW (i.e., immediate supervisor and coworkers) has a strong effect on security. This paper focuses on the effects of these mesolevel factors in the presence of macro- and microlevel factors. Drawing on the social structure and social learning framework as well as workgroup research, we hypothesize that the security behavior of an employee’s IW supervisor and coworkers moderated by the nature of these relationships influences information security decisions. Our research, based on a sample of 217 full-time employees, reveals that the IW significantly affects security decisions, over and above the micro- and macrolevel factors. These effects are moderated by the nature of the relationship between employees and their IW supervisor (leader-member exchange) and coworkers (team-member exchange). A post hoc analysis shows that the mesolevel factors alone had the same explanatory power as the micro- and macrolevels combined. Our research suggests that future theory and research should include the IW and that organizations should share security responsibilities with line managers and help them understand their substantial impact on information security. Security training programs should ask employees about the behaviors of their IW supervisor and coworkers and, where needed, deliver anti-neutralization training to mitigate the effects of the IW’s noncompliance behaviors.
期刊介绍:
The Journal of the Association for Information Systems (JAIS), the flagship journal of the Association for Information Systems, publishes the highest quality scholarship in the field of information systems. It is inclusive in topics, level and unit of analysis, theory, method and philosophical and research approach, reflecting all aspects of Information Systems globally. The Journal promotes innovative, interesting and rigorously developed conceptual and empirical contributions and encourages theory based multi- or inter-disciplinary research.