Information systems user security: A structured model of the knowing–doing gap

作者:

Highlights:

摘要

The corporate information systems users often engage in risky behavior that can threaten the security and integrity of an organization by exposing sensitive information or weakening the existing technological perimeter security. This risky user behavior can be intentional or unintentional, but in either case can cause severe damage to an organization’s reputation as well as potentially extending harm to the organization’s clients and customers. Information systems users not following the corporate security policies, even though they know the policies, is known as user omissive behavior, also known as the knowing–doing gap. This research examines the information assurance understanding and security awareness at the user level by developing a structured model of the user knowing–doing gap. The model examines the role of organizational narcissism and its affect on user attitudes towards following the organization’s information security policies and procedures. It also includes perceived threat as a factor affecting user attitudes towards following information security rules, as well as subjective norms and perceived behavior control consistent with the theory of planned behavior. This structured model provides a framework and description of user information security behavior and the knowing–doing gap.

论文关键词:Attitude,Information security,Intention,Narcissism,Omissive behavior,Threat

论文评审过程:Available online 31 May 2012.

论文官网地址:https://doi.org/10.1016/j.chb.2012.05.003