Stress-based security compliance model – an exploratory study. (10th October 2016)
- Record Type:
- Journal Article
- Title:
- Stress-based security compliance model – an exploratory study. (10th October 2016)
- Main Title:
- Stress-based security compliance model – an exploratory study
- Authors:
- Pham, Hiep-Cong
El-Den, Jamal
Richardson, Joan - Abstract:
- Abstract : Purpose: This paper aims to extend current information security compliance research by adapting "work-stress model" of the extended Job Demands-Resources model to explore how security compliance demands, organization and personal resources influence end-user security compliance. The paper proposes that security compliance burnout and security engagement as the mediating factors between security compliance demands, organizational and personal resources and individual security compliance. Design/methodology/approach: The authors used a multi-case in-depth interview method to explore the relevance and significance of security demands, organizational resources and personal resources on security compliance at work. Seventeen participants in three organizations including a bank, a university and an oil distribution company in Vietnam were interviewed during a four-month period. Findings: The study identified three security demands, three security resources and two aspects of personal resources that influence security compliance. The study demonstrates that the security environment factors such as security demands and resources affected compliance burden and security engagement. Personal resources could play an integral role in moderating the impact of security environment on security compliance. Research limitations/implications: The findings presented are not generalizable to the wider population of end-users in Vietnam due to the small sample size used in theAbstract : Purpose: This paper aims to extend current information security compliance research by adapting "work-stress model" of the extended Job Demands-Resources model to explore how security compliance demands, organization and personal resources influence end-user security compliance. The paper proposes that security compliance burnout and security engagement as the mediating factors between security compliance demands, organizational and personal resources and individual security compliance. Design/methodology/approach: The authors used a multi-case in-depth interview method to explore the relevance and significance of security demands, organizational resources and personal resources on security compliance at work. Seventeen participants in three organizations including a bank, a university and an oil distribution company in Vietnam were interviewed during a four-month period. Findings: The study identified three security demands, three security resources and two aspects of personal resources that influence security compliance. The study demonstrates that the security environment factors such as security demands and resources affected compliance burden and security engagement. Personal resources could play an integral role in moderating the impact of security environment on security compliance. Research limitations/implications: The findings presented are not generalizable to the wider population of end-users in Vietnam due to the small sample size used in the interviews. Further quantitative studies need to measure the extent of each predictor on security compliance. Originality/value: The originality of the research stems from proposing not only stress-based but also motivating factors from the security environment on security compliance. By using qualitative approach, the study provides more insight to understand the impact of the security environments on security compliance. … (more)
- Is Part Of:
- Information and computer security. Volume 24:Number 4(2016)
- Journal:
- Information and computer security
- Issue:
- Volume 24:Number 4(2016)
- Issue Display:
- Volume 24, Issue 4 (2016)
- Year:
- 2016
- Volume:
- 24
- Issue:
- 4
- Issue Sort Value:
- 2016-0024-0004-0000
- Page Start:
- 326
- Page End:
- 347
- Publication Date:
- 2016-10-10
- Subjects:
- Compliance burnout -- Job demands-resources -- Security compliance -- Security engagement -- Security resources
Computer security -- Management -- Periodicals
Computer networks -- Security measures -- Periodicals
Data protection -- Management -- Periodicals
658.47 - Journal URLs:
- http://www.emeraldinsight.com/loi/ics ↗
http://www.emeraldinsight.com/ ↗ - DOI:
- 10.1108/ICS-10-2014-0067 ↗
- Languages:
- English
- ISSNs:
- 2056-4961
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4481.796000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 2268.xml