The Role of Extra-Role Behaviors and Social Controls in Information Security Policy Effectiveness
成果类型:
Article
署名作者:
Hsu, Jack Shih-Chieh; Shih, Sheng-Pao; Hung, Yu Wen; Lowry, Paul Benjamin
署名单位:
National Sun Yat Sen University; Tamkang University; City University of Hong Kong
刊物名称:
INFORMATION SYSTEMS RESEARCH
ISSN/ISSBN:
1047-7047
DOI:
10.1287/isre.2015.0569
发表日期:
2015
页码:
282-300
关键词:
organizational citizenship behavior
decision-making
software piracy
IN-ROLE
systems
deterrence
MODEL
COMMITMENT
VIOLATIONS
WORKPLACE
摘要:
Although most behavioral security studies focus on organizational in-role behaviors such as information security policy (ISP) compliance, the role of organizational extra-role behaviors-security behaviors that benefit organizations but are not specified in ISPs-has long been overlooked. This study examines (1) the consequences of organizational in-role and extra-role security behaviors on the effectiveness of ISPs and (2) the role of formal and social controls in enhancing in-role and extra-role security behaviors in organizations. We propose that both in-role security behaviors and extra-role security behaviors contribute to ISP effectiveness. Furthermore, based on social control theory, we hypothesize that social control can boost both in-and extra-role security behaviors. Data collected from practitioners-including information systems (IS) managers and employees at many organizations-confirmed most of our hypotheses. Survey data from IS managers substantiated the importance of extra-role behaviors in improving ISP effectiveness. Paired data, collected from managers and employees in the same organizations, indicated that formal control and social control individually and interactively enhance both in-and extra-role security behaviors. We conclude by discussing the implications of this research for academics and practitioners, along with compelling future research possibilities.