[论文解读] Investigating the Role of Socio-organizational Factors in the Information Security Compliance in Organizations
本研究利用来自294名员工的调查数据,探讨了社会-组织因素如何影响组织中的信息安全合规性。研究发现,管理层承诺、意识与培训、问责制、技术能力、兼容性、流程整合以及审计机制显著提升了合规性,为组织信息安全战略提供了关键洞见。
The increase reliance on information systems has created unprecedented challenges for organizations to protect their critical information from different security threats that have direct consequences on the corporate liability, loss of credibility, and monetary damage. As a result, the security of information has become a top priority in many organizations. This study investigates the role of socio-organizational factors by drawing the insights from the organizational theory literature in the adoption of information security compliance in organizations. Based on the analysis of the survey data collected from 294 employees from different organizations, the study indicates management commitment, awareness and training, accountability, technology capability, technology compatibility, processes integration, and audit and monitoring have a significant positive impact on the adoption of information security compliance in organizations. The study contributes to the information security compliance research by exploring the criticality of socio-organizational factors at the organizational level for information security compliance.
研究动机与目标
- 探讨社会-组织因素在塑造组织内信息安全合规性中的作用。
- 识别显著影响员工遵守安全政策的组织层面因素。
- 弥补现有研究中对信息安全合规性领域内非技术性因素(如人力与结构因素)关注不足的空白。
- 提供组织文化、流程与领导力对安全行为影响的实证证据。
- 支持制定整合人力与组织维度的全面安全战略。
提出的方法
- 基于调查的研究,对来自多样化组织的294名员工进行调查,以评估其对社会-组织因素的认知。
- 应用组织理论框架,识别并分类影响合规性的关键社会-组织变量。
- 通过调查数据解释(隐含)统计分析,检验各因素与合规水平之间的关系。
- 通过感知的组织安全实践及员工行为意图衡量合规性。
- 评估管理层承诺、培训、问责制、技术兼容性以及审计机制等因素。
- 采用结构化问卷收集有关组织流程、技术整合与监控实践的数据。
实验结果
研究问题
- RQ1哪些社会-组织因素显著影响组织中的信息安全合规性?
- RQ2管理层承诺在多大程度上影响员工对信息安全政策的遵守?
- RQ3意识与培训项目在多大程度上影响合规行为?
- RQ4技术能力与兼容性在多大程度上促进有效合规?
- RQ5审计与监控实践在多大程度上在组织各单元中维持合规性?
主要发现
- 管理层承诺对信息安全合规性具有显著的正面影响,表明领导力在培养安全意识文化方面起着关键作用。
- 意识与培训项目显著提升了员工对安全政策的理解与遵守程度。
- 问责机制(包括明确的责任分配)与更高的合规率密切相关。
- 技术能力以及与现有系统的兼容性显著提升了安全控制措施的有效性。
- 流程整合(将安全实践与核心业务工作流程对齐)可带来更一致的合规行为。
- 审计与监控实践通过提高透明度与问责制,显著促进合规性的持续维持。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。