Generally Speaking, Context Matters: Making the Case for a Change from Universal to Particular ISP Research

The objective of our paper is to conceptually and empirically challenge the idea of general information security policy (ISP) compliance. Conceptually, we argue that general ISP compliance is an ill-defined concept that has minimal theoretical usefulness because the policy-directed security actions...

Descripción completa

Guardado en:  
Detalles Bibliográficos
Autor principal: Aurigemma, Sal (Autor)
Otros Autores: Mattson, Thomas
Tipo de documento: Electrónico Libro
Lenguaje:Inglés
Publicado: 2019
En:Año: 2019
Acceso en línea: Volltext (kostenfrei)
Verificar disponibilidad: HBZ Gateway

MARC

LEADER 00000cam a22000002c 4500
001 1866309005
003 DE-627
005 20250114054910.0
007 cr uuu---uuuuu
008 231019s2019 xx |||||o 00| ||eng c
035 |a (DE-627)1866309005 
035 |a (DE-599)KXP1866309005 
040 |a DE-627  |b ger  |c DE-627  |e rda 
041 |a eng 
084 |a 2,1  |2 ssgn 
100 1 |a Aurigemma, Sal  |e VerfasserIn  |4 aut 
245 1 0 |a Generally Speaking, Context Matters: Making the Case for a Change from Universal to Particular ISP Research 
264 1 |c 2019 
336 |a Text  |b txt  |2 rdacontent 
337 |a Computermedien  |b c  |2 rdamedia 
338 |a Online-Ressource  |b cr  |2 rdacarrier 
520 |a The objective of our paper is to conceptually and empirically challenge the idea of general information security policy (ISP) compliance. Conceptually, we argue that general ISP compliance is an ill-defined concept that has minimal theoretical usefulness because the policy-directed security actions vary considerably from threat to threat in terms of time, difficulty, diligence, knowledge, and effort. Yet, our senior IS scholars’ basket of journals has a strong preference to publish models in which the authors speculate that their findings are generalizable across all (or many) threats and controls contained in an organization’s ISP document. In our paper, we argue that compliance with each of the mandatory threat-specific security actions may require different (as opposed to similar) explanatory models, which makes constructing a universal model of ISP compliance problematic. Therefore, we argue that future ISP compliance literature will be more valuable if it focuses on the mechanisms, treatments, and behavioral antecedents associated with the required actions around specific threats instead of attempting to build a model that purportedly covers all (or many) threat-specific security actions (or intentions thereof). To support this claim empirically, we conducted two studies comparing general compliance intentions (i.e., undefined security action) and threat-specific compliance intentions. In both studies, our data show that compliance intentions vary significantly across general compliance measures and multiple threat-specific security measures or scenarios. Our results indicate that it is problematic to generalize about the behavioral antecedents from general compliance intentions to threat-specific security compliance intentions, from one threat-specific security action to other threat-specific security actions, and from one threat-specific security action to general compliance intentions 
700 1 |a Mattson, Thomas  |e VerfasserIn  |4 aut 
856 4 0 |u https://core.ac.uk/download/301386399.pdf  |x Verlag  |z kostenfrei  |3 Volltext 
935 |a mkri 
951 |a BO 
ELC |a 1 
LOK |0 000 xxxxxcx a22 zn 4500 
LOK |0 001 4392952576 
LOK |0 003 DE-627 
LOK |0 004 1866309005 
LOK |0 005 20231019043632 
LOK |0 008 231019||||||||||||||||ger||||||| 
LOK |0 035   |a (DE-2619)CORE17828850 
LOK |0 040   |a DE-2619  |c DE-627  |d DE-2619 
LOK |0 092   |o n 
LOK |0 852   |a DE-2619 
LOK |0 852 1  |9 00 
LOK |0 935   |a core 
OAS |a 1 
ORI |a SA-MARC-krimdoka001.raw