To read this content please select one of the options below:

From hindrance to challenge: How employees understand and respond to information security policies

Ying Li (School of Economics and Management, Dalian University of Technology, Dalian, China)
Ting Pan (School of Economics and Management, Dalian University of Technology, Dalian, China)
Nan (Andy) Zhang (School of Management, Harbin Institute of Technology, Harbin, China)

Journal of Enterprise Information Management

ISSN: 1741-0398

Article publication date: 1 October 2019

Issue publication date: 22 January 2020

1092

Abstract

Purpose

This paper is to investigate how employees respond to information security policies (ISPs) when they view the policies as a challenge rather than a hindrance to work. Specifically, the authors examine the roles of challenge security demands (i.e. continuity and mandatory) and psychological resources (i.e. personal and job resources) in influencing employees’ ISP non-compliance.

Design/methodology/approach

Applying a hypothetical scenario-based survey method, the authors tested our proposed model in six typical ISPs violation scenarios. In sum, 347 responses were collected from a global company. The data were analyzed using partial least square-based structural equation model.

Findings

Findings indicated that continuity and mandatory demands increased employees’ level of perseverance of effort, which, in turn, decreased their ISPs non-compliance intention. In addition, job resources, such as the trust enhancement gained from co-workers and the opportunities for professional development, enhanced the perseverance of effort.

Practical implications

The findings offer implications to practice by suggesting that organizations should design training programs to persuade employees to understand the ISPs in a positive way. Meanwhile, organizations should encourage employees to invest more personal resources by creating a trusting atmosphere and providing them opportunities to learn security knowledge and skills.

Originality/value

This study is among the few to empirically explore how employees respond and behave when they view the security policies as challenge stressors. The paper also provides a novel understanding of how psychological resources contribute to buffering ISP non-compliance.

Keywords

Acknowledgements

This research was supported by China Ministry of Education of Humanities and Social Science (17YJC630072), National Natural Science Foundation of China (71431002, 71874022, 71421001, 91846301).

Citation

Li, Y., Pan, T. and Zhang, N.(A). (2020), "From hindrance to challenge: How employees understand and respond to information security policies", Journal of Enterprise Information Management, Vol. 33 No. 1, pp. 191-213. https://doi.org/10.1108/JEIM-01-2019-0018

Publisher

:

Emerald Publishing Limited

Copyright © 2019, Emerald Publishing Limited

Related articles