对抗之舞:了解内部人士对组织资讯安全措施的反应

IF 7 3区 管理学 Q1 COMPUTER SCIENCE, INFORMATION SYSTEMS Journal of the Association for Information Systems Pub Date : 2022-01-01 DOI:10.17705/1jais.00798
P. Balozian, A. Burns, D. Leidner
{"title":"对抗之舞:了解内部人士对组织资讯安全措施的反应","authors":"P. Balozian, A. Burns, D. Leidner","doi":"10.17705/1jais.00798","DOIUrl":null,"url":null,"abstract":"Despite the increased focus on organizational security policies and programs, some employees continue to engage in maladaptive responses to security measures (i.e., behaviors other than those recommended, intended, or prescribed). To help shed light on insiders’ adaptive and maladaptive responses to IS security measures, we conducted a case study of an organization at the forefront of security policy initiatives. Drawing on the beliefs-actions-outcomes (BAO) model to analyze our case data, we uncover a potentially nonvirtuous cycle consisting of security-related beliefs, actions, and outcomes, which we refer to as an “adversarial dance.” Explaining our results, we describe a novel belief framework that identifies four security belief profiles and uncovers an underexplored outcome of IS security: insiders’ lived security experiences. We find that individuals’ unfavorable lived security experiences produce counterproductive security-related beliefs that, in turn, lead to maladaptive behaviors. Maladaptive behaviors create new potential for security risk, leading to increased organizational security measures to counter them. Thus, the adversarial dance continues, as the new security measures have the potential to reinforce counterproductive security-related beliefs about the importance and risk of IS security and lead to new maladaptive behaviors. To help situate our findings within the current security literature, we integrate the results with prior research based on extant theories. While this paper is not the first to suggest that security measures can elicit maladaptive behaviors, the emergent belief framework and expanded BAO model of IS security constitute an important contribution to the behavioral IS security literature.","PeriodicalId":51101,"journal":{"name":"Journal of the Association for Information Systems","volume":"108 1","pages":"4"},"PeriodicalIF":7.0000,"publicationDate":"2022-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"An Adversarial Dance: Toward an Understanding of Insiders' Responses to Organizational Information Security Measures\",\"authors\":\"P. Balozian, A. Burns, D. Leidner\",\"doi\":\"10.17705/1jais.00798\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Despite the increased focus on organizational security policies and programs, some employees continue to engage in maladaptive responses to security measures (i.e., behaviors other than those recommended, intended, or prescribed). To help shed light on insiders’ adaptive and maladaptive responses to IS security measures, we conducted a case study of an organization at the forefront of security policy initiatives. Drawing on the beliefs-actions-outcomes (BAO) model to analyze our case data, we uncover a potentially nonvirtuous cycle consisting of security-related beliefs, actions, and outcomes, which we refer to as an “adversarial dance.” Explaining our results, we describe a novel belief framework that identifies four security belief profiles and uncovers an underexplored outcome of IS security: insiders’ lived security experiences. We find that individuals’ unfavorable lived security experiences produce counterproductive security-related beliefs that, in turn, lead to maladaptive behaviors. Maladaptive behaviors create new potential for security risk, leading to increased organizational security measures to counter them. Thus, the adversarial dance continues, as the new security measures have the potential to reinforce counterproductive security-related beliefs about the importance and risk of IS security and lead to new maladaptive behaviors. To help situate our findings within the current security literature, we integrate the results with prior research based on extant theories. While this paper is not the first to suggest that security measures can elicit maladaptive behaviors, the emergent belief framework and expanded BAO model of IS security constitute an important contribution to the behavioral IS security literature.\",\"PeriodicalId\":51101,\"journal\":{\"name\":\"Journal of the Association for Information Systems\",\"volume\":\"108 1\",\"pages\":\"4\"},\"PeriodicalIF\":7.0000,\"publicationDate\":\"2022-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of the Association for Information Systems\",\"FirstCategoryId\":\"91\",\"ListUrlMain\":\"https://doi.org/10.17705/1jais.00798\",\"RegionNum\":3,\"RegionCategory\":\"管理学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of the Association for Information Systems","FirstCategoryId":"91","ListUrlMain":"https://doi.org/10.17705/1jais.00798","RegionNum":3,"RegionCategory":"管理学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

尽管对组织安全政策和计划的关注有所增加,但一些员工继续对安全措施(即,与推荐、预期或规定的行为不同的行为)做出不适应的反应。为了帮助阐明内部人员对IS安全措施的适应和不适应反应,我们对处于安全策略倡议前沿的组织进行了案例研究。利用信念-行动-结果(BAO)模型来分析我们的案例数据,我们发现了一个由与安全相关的信念、行动和结果组成的潜在的非良性循环,我们将其称为“对抗之舞”。为了解释我们的结果,我们描述了一个新的信念框架,该框架确定了四种安全信念概况,并揭示了信息系统安全的一个未被探索的结果:内部人员的生活安全体验。我们发现,个人不良的生活安全经历会产生适得其反的安全相关信念,进而导致适应不良行为。适应不良的行为会产生新的安全风险,导致增加组织的安全措施来应对它们。因此,对抗的舞蹈仍在继续,因为新的安全措施有可能加强对IS安全的重要性和风险的适得其反的安全相关信念,并导致新的适应不良行为。为了帮助将我们的发现置于当前的安全文献中,我们将结果与基于现有理论的先前研究相结合。虽然本文并不是第一个提出安全措施会引发不适应行为的研究,但信息系统安全的涌现信念框架和扩展的BAO模型对行为信息系统安全文献做出了重要贡献。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
An Adversarial Dance: Toward an Understanding of Insiders' Responses to Organizational Information Security Measures
Despite the increased focus on organizational security policies and programs, some employees continue to engage in maladaptive responses to security measures (i.e., behaviors other than those recommended, intended, or prescribed). To help shed light on insiders’ adaptive and maladaptive responses to IS security measures, we conducted a case study of an organization at the forefront of security policy initiatives. Drawing on the beliefs-actions-outcomes (BAO) model to analyze our case data, we uncover a potentially nonvirtuous cycle consisting of security-related beliefs, actions, and outcomes, which we refer to as an “adversarial dance.” Explaining our results, we describe a novel belief framework that identifies four security belief profiles and uncovers an underexplored outcome of IS security: insiders’ lived security experiences. We find that individuals’ unfavorable lived security experiences produce counterproductive security-related beliefs that, in turn, lead to maladaptive behaviors. Maladaptive behaviors create new potential for security risk, leading to increased organizational security measures to counter them. Thus, the adversarial dance continues, as the new security measures have the potential to reinforce counterproductive security-related beliefs about the importance and risk of IS security and lead to new maladaptive behaviors. To help situate our findings within the current security literature, we integrate the results with prior research based on extant theories. While this paper is not the first to suggest that security measures can elicit maladaptive behaviors, the emergent belief framework and expanded BAO model of IS security constitute an important contribution to the behavioral IS security literature.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Journal of the Association for Information Systems
Journal of the Association for Information Systems 工程技术-计算机:信息系统
CiteScore
11.20
自引率
5.20%
发文量
33
审稿时长
>12 weeks
期刊介绍: The Journal of the Association for Information Systems (JAIS), the flagship journal of the Association for Information Systems, publishes the highest quality scholarship in the field of information systems. It is inclusive in topics, level and unit of analysis, theory, method and philosophical and research approach, reflecting all aspects of Information Systems globally. The Journal promotes innovative, interesting and rigorously developed conceptual and empirical contributions and encourages theory based multi- or inter-disciplinary research.
期刊最新文献
"My Precious!": A Values-Affordances Perspective on the Adoption of Bitcoin A Warning Approach to Mitigating Bandwagon Bias in Online Ratings: Theoretical Analysis and Experimental Investigations Social Inclusion: The Use of Social Media and the Impact on First-Generation College Students Positively Fearful: Activating the Individual's HERO Within to Explain Volitional Security Technology Adoption The Effectiveness of Highlighting Different Communication Orientations in Promoting Mobile Communication Technology at Work vs. at Home: Evidence from a Field Experiment
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1