To read this content please select one of the options below:

Examining employee security violations: moral disengagement and its environmental influences

Tejaswini Herath (Brock University, St Catharines, Canada)
Myung-Seong Yim (Sahmyook University, Seoul, Korea)
John D’Arcy (University of Delaware, Newark, Delaware, USA)
Kichan Nam (American University of Sharjah, Sharjah, UAE)
H.R. Rao (University of Texas at San Antonio, San Antonio, Texas, USA)

Information Technology & People

ISSN: 0959-3845

Article publication date: 14 August 2018

Issue publication date: 4 October 2018

1314

Abstract

Purpose

Employee security behaviors are the cornerstone for achieving holistic organizational information security. Recent studies in the information systems (IS) security literature have used neutralization and moral disengagement (MD) perspectives to examine employee rationalizations of noncompliant security behaviors. Extending this prior work, the purpose of this paper is to identify mechanisms of security education, training, and awareness (SETA) programs and deterrence as well as employees’ organizational commitment in influencing MD of security policy violations and develop a theoretical model to test the proposed relationships.

Design/methodology/approach

The authors validate and test the model using the data collected from six large multinational organizations in Korea using survey-based methodology. The model was empirically analyzed by structural equation modeling.

Findings

The results suggest that security policy awareness (PA) plays a central role in reducing MD of security policy violations and that the certainty of punishment and immediacy of enforcing penalties are instrumental toward reducing such MD; however, the higher severity of penalties does not have an influence. The findings also suggest that SETA programs are an important mechanism in creating security PA.

Originality/value

The paper expands the literature in IS security that has examined the role of moral evaluations. Drawing upon MD theory and social cognitive theory, the paper points to the central role of SETA and security PA in reducing MD of security policy violations, and ultimately the likelihood of this behavior. The paper not only contributes to theory but also provides important insights for practice.

Keywords

Acknowledgements

This study was supported in part by the Social Sciences and Humanities Research Council (SSHRC) of Canada (Grant No. 410-2010-18489). This research has also been supported in part NSF under Grant No. 0916612, and by the World Class University program funded by the Ministry of Education, Science and Technology through the National Research Foundation of Korea (R31-20002).

Citation

Herath, T., Yim, M.-S., D’Arcy, J., Nam, K. and Rao, H.R. (2018), "Examining employee security violations: moral disengagement and its environmental influences", Information Technology & People, Vol. 31 No. 6, pp. 1135-1162. https://doi.org/10.1108/ITP-10-2017-0322

Publisher

:

Emerald Publishing Limited

Copyright © 2018, Emerald Publishing Limited

Related articles