Author List: Hsu, Jack Shih-Chieh; Shih, Sheng-Pao; Hung, Yu Wen; Lowry, Paul Benjamin;
Information Systems Research, 2015, Volume 26, Issue 2, Page 282-300.
Although most behavioral security studies focus on organizational in-role behaviors such as information security policy (ISP) compliance, the role of organizational extra-role behaviorsÑsecurity behaviors that benefit organizations but are not specified in ISPsÑhas long been overlooked. This study examines (1) the consequences of organizational in-role and extra-role security behaviors on the effectiveness of ISPs and (2) the role of formal and social controls in enhancing in-role and extra-role security behaviors in organizations. We propose that both in-role security behaviors and extra-role security behaviors contribute to ISP effectiveness. Furthermore, based on social control theory, we hypothesize that social control can boost both in- and extra-role security behaviors. Data collected from practitionersÑincluding information systems (IS) managers and employees at many organizationsÑconfirmed most of our hypotheses. Survey data from IS managers substantiated the importance of extra-role behaviors in improving ISP effectiveness. Paired data, collected from managers and employees in the same organizations, indicated that formal control and social control individually and interactively enhance both in- and extra-role security behaviors. We conclude by discussing the implications of this research for academics and practitioners, along with compelling future research possibilities.
Keywords: IS security ; behavioral security ; in-role behaviors ; extra-role behaviors ; social control theory ; SCT ; security management ; information security policy ; ISP ; formal control ; social control ; organizations
Algorithm:

List of Topics

#186 0.289 security information compliance policy organizations breach disclosure policies deterrence breaches incidents results study abuse managed isp violations based comply protection
#75 0.170 behavior behaviors behavioral study individuals affect model outcomes psychological individual responses negative influence explain hypotheses expected theories consequences impact theory
#1 0.139 organizational organizations effectiveness factors managers model associated context characteristics variables paper relationships level attention environmental technological based maturity organization's relationship
#280 0.122 control controls formal systems mechanisms modes clan informal used internal literature outsourced outcome theory configuration attempts evolution authority complementary little
#127 0.094 systems information research theory implications practice discussed findings field paper practitioners role general important key grounded researchers domain new identified
#234 0.068 social networks influence presence interactions network media networking diffusion implications individuals people results exchange paper sites evidence self-disclosure important examine