Many workers have started working remotely, with a significant increase during and after the COVID-19 pandemic. At the same time, increasing costs of data breaches and number of security incidents continue to be a concern for organizations seeking to protect their organization, systems, and data. Using the theoretical frameworks of the Theory of Planned Behavior (TPB) and the Social Bonds Theory (SBT), we sought to understand employee compliance with information security policies (ISP). Using phenomenology, we interviewed both in-person and remote workers in a variety of industries. We uncovered their experiences with their organization’s implementation and enforcement of ISP, organizational culture and leadership attitudes shaping ISP compliance, and clarity and training of ISP for employees. Top factors that influenced employee compliance of ISPs of both in-person and remote workers included the automation of policies, hectic/busy times, efficiency, availability, training, and enforcement of the ISPs. Overall, participants reported positive relationships within their organization, regardless of whether they were in-person or remote; however, nearly all participants also noted that building relationships was easier to do in-person than remote, even as technology has bridged some of the gap between in-person and remote working relationships. We offer implications for practice and research.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

In-Person and Remote Employees and Information Security Policy Compliance

  • Joyce Y. Mui,
  • Barbara A. W. Eversole,
  • Cindy L. Crowder

摘要

Many workers have started working remotely, with a significant increase during and after the COVID-19 pandemic. At the same time, increasing costs of data breaches and number of security incidents continue to be a concern for organizations seeking to protect their organization, systems, and data. Using the theoretical frameworks of the Theory of Planned Behavior (TPB) and the Social Bonds Theory (SBT), we sought to understand employee compliance with information security policies (ISP). Using phenomenology, we interviewed both in-person and remote workers in a variety of industries. We uncovered their experiences with their organization’s implementation and enforcement of ISP, organizational culture and leadership attitudes shaping ISP compliance, and clarity and training of ISP for employees. Top factors that influenced employee compliance of ISPs of both in-person and remote workers included the automation of policies, hectic/busy times, efficiency, availability, training, and enforcement of the ISPs. Overall, participants reported positive relationships within their organization, regardless of whether they were in-person or remote; however, nearly all participants also noted that building relationships was easier to do in-person than remote, even as technology has bridged some of the gap between in-person and remote working relationships. We offer implications for practice and research.