Impact of deterrence theory methods on employees' information security behavior
Peloteteoria (Deterrence theory) on alun perin psykologiassa ja kriminologiassa käytetty termi, ja sen mukaan rangaistuksen pelko estää yksilöä toimimasta vastoin lakia ja sääntöjä. Digitalisoituvassa maailmassa on viimeisen kahdenkymmenen vuoden aikana tehty paljon tutkimusta, jossa peloteteoriaa on sovellettu tietojärjestelmien sekä tietoturvakäyttäytymisen kontekstiin. Tutkielma käsittelee käytössä olevia peloteteorian keinoja tässä kontekstissa sekä nii-den vaikutuksia työntekijöiden tietoturvakäyttäytymiseen.
Tutkielma on toteutettu kirjallisuuskatsauksena ja sen tarkoitus on määritellä peloteteorian käsitettä tietojärjestelmien ja tietoturvakäyttäytymisen kontekstissa sekä tutkia olemassa olevia keinoja ja niiden vaikutuksia. Tutkimuksen tuloksina voidaan todeta, ettei ole olemassa absoluuttista totuutta peloteteori-an keinojen vaikutuksista työntekijöiden käyttäytymiseen. Tämä johtuu siitä, että tuloksiin vaikuttavat myös esimerkiksi yksilön ominaisuudet, toimintaympäristö ja kulttuuri. Peloteteoria on edelleen tutkituimpia teorioita työntekijöiden tietoturvakäyttäytymisen kontekstissa, ja aiheen tutkimus jatkuu varmasti myös tulevaisuudessa.
...
Deterrence theory is originally a term used in psychology and criminology. According to the theory sanction fear prevents individuals from committing illicit acts against the rules. As the corporate world digitalizes, there has been a lot of research on the topic in the context of information systems and security policy compliance in the last 20 years. This study examines the deterrence theory methods and their impacts in employees’ information security behavior.
This study is implemented as a literary review and its purpose is to define de-terrence theory in the context of information systems and information security compliance as well as study the existing methods and their impacts on employee behavior. The results of the study suggest that there is no absolute truth about the impacts of the deterrence theory methods in the information security behavior of the employees. This is because there are other variables that influence the results, such as qualities of the employees, working environment and culture. Deterrence theory is one of the most-used theories in the context of information security behavior, and research on the topic will surely continue in the future.
...
Keywords
Metadata
Show full item recordCollections
- Kandidaatintutkielmat [5315]
Related items
Showing items with similar title or keywords.
-
Exploring determinants of different information security behaviors
Kinnunen, Sanna (2016)Aim: The aim was to introduce new explanatory construct, namely illegitimate tasks from Stress-as-Offense-to-Self Theory (SOS), to better understand information security behavior (ISB). In addition, more commonly used ... -
Influence of Organizational Culture on Employees Information Security Policy Compliance in Ethiopian Companies
Ejigu, Kibrom; Siponen, Mikko; Muluneh, Tilahun (Association for Information Systems, 2021)Information security is one of the organizations' top agendas worldwide. Similarly, there is a growing trend in the kinds and rate of security breaches. Information security experts and scholars concentrate on outsiders' ... -
The moderating impact of organizational culture on information security compliance
Ejigu, Kibrom; Siponen, Mikko; Muluneh, Tilahun (Addis Ababa University Press, 2023)This research paper investigates the association between organizational culture and employees' compliance with information security policies. Drawing upon rational choice theory (RCT) and the competing values framework ... -
Investigating the Impact of Organizational Culture on Information Security Policy Compliance : The Case of Ethiopia
Ejigu, Kibrom Tadesse; Siponen, Mikko; Arage, Tilahun Muluneh (Association for Information Systems, 2021)Information security is one of the organizations' top agendas worldwide. Similarly, there is a growing trend in the kinds and rate of security breaches. Information security experts and scholars concentrate on outsiders' ... -
Toward a stage theory of the development of employees' information security behavior
Karjalainen, Mari; Siponen, Mikko; Sarker, Suprateek (Elsevier, 2020)Existing behavioral information security research proposes continuum or non-stage models that focus on finding static determinants for information security behavior (ISB) that remains unchanged. Such models cannot explain ...