To read this content please select one of the options below:

Work-related groups and information security policy compliance

Teodor Sommestad (Information Security and IT Architecture, Swedish Defence Research Agency (FOI), Linköping, Sweden)

Information and Computer Security

ISSN: 2056-4961

Article publication date: 12 November 2018

838

Abstract

Purpose

It is widely acknowledged that norms and culture influence decisions related to information security. The purpose of this paper is to investigate how work-related groups influence information security policy compliance intentions and to what extent this influence is captured by the Theory of Planned Behavior, an established model over individual decision-making.

Design/methodology/approach

A multilevel model is used to test the influence of work-related groups using a cluster sample of responses from 2,291 employees from 203 worksites, 119 organizations, 6 industries and 38 professions.

Findings

The results suggest that work-related groups influence individuals’ decision-making in the manner in which contemporary theories of information security culture posit. However, the influence is weak to modest and overshadowed by individual perceptions that are straightforward to measure.

Research limitations/implications

This paper is limited to one national culture and four types of work-related groups. However, the results suggest that the Theory of Planned Behavior captures most of the influence that work-related groups have on decision-making. Future research on security culture and similar phenomena should take this into account.

Practical implications

Information security perceptions in work-related groups are diverse and information security decisions appear to be based on individual perceptions and priorities rather than groupthink or peer-pressure. Security management interventions may be more effective if they target individuals rather than groups.

Originality/value

This paper tests some of the basic ideas related to information security culture and its influence on individuals’ decision-making.

Keywords

Citation

Sommestad, T. (2018), "Work-related groups and information security policy compliance", Information and Computer Security, Vol. 26 No. 5, pp. 533-550. https://doi.org/10.1108/ICS-08-2017-0054

Publisher

:

Emerald Publishing Limited

Copyright © 2018, Emerald Publishing Limited

Related articles