当前位置: X-MOL 学术Journal of Enterprise Information Management › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
The influence of organisational culture and information security culture on employee compliance behaviour
Journal of Enterprise Information Management ( IF 5.661 ) Pub Date : 2020-10-07 , DOI: 10.1108/jeim-08-2019-0217
Grant Solomon , Irwin Brown

Purpose

Organisational culture plays an important role in influencing employee compliance with information security policies. Creating a subculture of information security can assist in facilitating compliance. The purpose of this paper is to explain the nature of the combined influence of organisational culture and information security culture on employee information security compliance. This study also aims to explain the influence of organisational culture on information security culture.

Design/methodology/approach

A theoretical model was developed showing the relationships between organisational culture, information security culture and employee compliance. Using an online survey, data was collected from a sample of individuals who work in organisations having information security policies. The data was analysed with Partial Least Square Structural Equation Modelling (PLS-SEM) to test the model.

Findings

Organisational culture and information security culture have significant, yet similar influences on employee compliance. In addition, organisational culture has a strong causal influence on information security culture.

Practical implications

Control-oriented organisational cultures are conducive to information security compliant behaviour. For an information security subculture to be effectively embedded in an organisation's culture, the dominant organisational culture would have to be considered first.

Originality/value

This research provides empirical evidence that information security subculture is influenced by organisational culture. Compliance is best explained by their joint influence.



中文翻译:

组织文化和信息安全文化对员工合规行为的影响

目的

组织文化在影响员工遵守信息安全政策方面发挥着重要作用。创建信息安全亚文化有助于促进合规性。本文的目的是解释组织文化和信息安全文化对员工信息安全合规性的综合影响的性质。本研究还旨在解释组织文化对信息安全文化的影响。

设计/方法/方法

开发了一个理论模型,显示了组织文化、信息安全文化和员工合规性之间的关系。使用在线调查,数据是从在具有信息安全政策的组织中工作的个人样本中收集的。使用偏最小二乘结构方程模型 (PLS-SEM) 分析数据以测试模型。

发现

组织文化和信息安全文化对员工合规性具有显着但相似的影响。此外,组织文化对信息安全文化有很强的因果影响。

实际影响

以控制为导向的组织文化有利于信息安全合规行为。为了将信息安全亚文化有效地嵌入组织文化中,必须首先考虑占主导地位的组织文化。

原创性/价值

这项研究提供了信息安全亚文化受组织文化影响的经验证据。合规性最好通过它们的共同影响来解释。

更新日期:2020-10-07
down
wechat
bug