2010 43rd Hawaii International Conference on System Sciences 2010
DOI: 10.1109/hicss.2010.312
|View full text |Cite
|
Sign up to set email alerts
|

Quality and Fairness of an Information Security Policy As Antecedents of Employees' Security Engagement in the Workplace: An Empirical Investigation

Abstract: This paper investigates the impact of the characteristics of information security policy (ISP) on an employee's security compliance in the workplace. Two factors were proposed as the antecedents of employees' security compliance: ISP Fairness and ISP Quality. ISP Quality is comprised of three quality dimensions--Clarity, Completeness, and Consistency. It is shown that ISP fairness has a strong positive effect on an employee's ISP Compliance. In addition, it is found that ISP quality does not only have a strong… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
24
0

Year Published

2013
2013
2023
2023

Publication Types

Select...
5
3
1

Relationship

0
9

Authors

Journals

citations
Cited by 23 publications
(24 citation statements)
references
References 16 publications
0
24
0
Order By: Relevance
“…Bulgurcu et al [7] posit that the quality and fairness of an information security policy, as perceived by employees, are factors in employee security compliance. 'Security hygiene', as defined by Pfleeger et al, is a combination of workable security habits that also delivers effective risk management to the level required by the organisation [20].…”
Section: Challenge 2: the Organisation Must Reflect On The Existing Smentioning
confidence: 99%
“…Bulgurcu et al [7] posit that the quality and fairness of an information security policy, as perceived by employees, are factors in employee security compliance. 'Security hygiene', as defined by Pfleeger et al, is a combination of workable security habits that also delivers effective risk management to the level required by the organisation [20].…”
Section: Challenge 2: the Organisation Must Reflect On The Existing Smentioning
confidence: 99%
“…Common security controls reduce security risk to information systems [7]. Controls can be introduced in an ad hoc nature, but ISS controls based on policy are more effective [2], [18]. Senior management involvement is critical for not only establishing ISS policy, but also ensuring employee compliance [1], [19], [20].…”
Section: Literature Reviewmentioning
confidence: 99%
“…After applying the inclusion and exclusion criteria, 13 articles were excluded, resulting in 36 articles included in the final review. From the 13 excluded references, seven were excluded based on the third criteria: five references were conferences proceedings [1,[44][45][46][47], one was a book chapter [48] and one was a thesis [49]. The remaining six excluded references discussed domains that could be argued to be under the IS policy scope.…”
Section: Search Processmentioning
confidence: 99%