From hindrance to challenge: How employees understand and respond to information security policies
Journal of Enterprise Information Management
ISSN: 1741-0398
Article publication date: 1 October 2019
Issue publication date: 22 January 2020
Abstract
Purpose
This paper is to investigate how employees respond to information security policies (ISPs) when they view the policies as a challenge rather than a hindrance to work. Specifically, the authors examine the roles of challenge security demands (i.e. continuity and mandatory) and psychological resources (i.e. personal and job resources) in influencing employees’ ISP non-compliance.
Design/methodology/approach
Applying a hypothetical scenario-based survey method, the authors tested our proposed model in six typical ISPs violation scenarios. In sum, 347 responses were collected from a global company. The data were analyzed using partial least square-based structural equation model.
Findings
Findings indicated that continuity and mandatory demands increased employees’ level of perseverance of effort, which, in turn, decreased their ISPs non-compliance intention. In addition, job resources, such as the trust enhancement gained from co-workers and the opportunities for professional development, enhanced the perseverance of effort.
Practical implications
The findings offer implications to practice by suggesting that organizations should design training programs to persuade employees to understand the ISPs in a positive way. Meanwhile, organizations should encourage employees to invest more personal resources by creating a trusting atmosphere and providing them opportunities to learn security knowledge and skills.
Originality/value
This study is among the few to empirically explore how employees respond and behave when they view the security policies as challenge stressors. The paper also provides a novel understanding of how psychological resources contribute to buffering ISP non-compliance.
Keywords
Acknowledgements
This research was supported by China Ministry of Education of Humanities and Social Science (17YJC630072), National Natural Science Foundation of China (71431002, 71874022, 71421001, 91846301).
Citation
Li, Y., Pan, T. and Zhang, N.(A). (2020), "From hindrance to challenge: How employees understand and respond to information security policies", Journal of Enterprise Information Management, Vol. 33 No. 1, pp. 191-213. https://doi.org/10.1108/JEIM-01-2019-0018
Publisher
:Emerald Publishing Limited
Copyright © 2019, Emerald Publishing Limited