Beyond Deterrence: An Expanded View of Employee Computer Abuse
نویسندگان
چکیده
Recent academic investigations of computer security policy violations have largely focused on non-malicious noncompliance due to poor training, low employee motivation, weak affective commitment, or individual oversight. Established theoretical foundations applied to this domain have related to protection motivation, deterrence, planned behavior, self-efficacy, individual adoption factors, organizational commitment, and other individual cognitive factors. But another class of violation demands greater research emphasis: the intentional commission of computer security policy violation, or insider computer abuse. Whether motivated by greed, disgruntlement, or other psychological processes, this act has the greatest potential for loss and damage to the employer. We argue the focus must include not only the act and its immediate antecedents of intention (to commit computer abuse) and deterrence (of the crime), but also phenomena which temporally precede these areas. Specifically, we assert the need to consider the thought processes of the potential offender and how these are influenced by the organizational context, prior to deterrence. We believe the interplay between thought processes and this context may significantly impact the efficacy of IS security controls, specifically deterrence safeguards. Through this focus, we extend the Straub and Welke (1998) security action cycle framework and propose three areas worthy of empirical investigation—techniques of neutralization (rationalization), expressive/instrumental criminal motivations, and disgruntlement as a result of perceptions of organizational injustice—and propose questions for future research in these areas.
منابع مشابه
The Role of Perceptions of Organizational Injustice and Techniques of Neutralization in Forming Computer Abuse Intentions
Insider computer abuse, the problem of intentional computer-related crimes by employees, is a costly problem for firms (Warkentin and Willison, 2009). To counter this threat, IT practitioners and IS researchers assess potential antecedents of and motivations for computer abuse intentions among employees. The theory of organizational justice, the techniques of neutralization, and the role of det...
متن کاملUnderstanding Organization Employee's Information Security Omission Behavior: an Integrated Model of Social norm and Deterrence
Employee`s information security behavior is critical to ensure the security of organization`s information assets. Countermeasures, such as information security policies, are helpful to reduce computer abuse and information systems misuse. However, employees in practice tend to engage in these violation behaviors, although they know policies and countermeasures. Undoubtedly, these omission behav...
متن کاملA Rational Choice Perspective
Employee violations of IS security policies are reported as a key concern for organizations. Although behavioral research on IS security has received increasing attention from IS scholars, little empirical research has examined this problem. To address this research gap, the authors test a model based on Rational Choice Theory (RCT)—a prominent criminological theory not yet applied in IS—which ...
متن کاملAn integrative model of computer abuse based on social control and general deterrence theories
In spite of continuous organizational efforts and investments, computer abuse shows no sign of decline. According to social control theory (SCT), ‘‘organizational trust’’ can help prevent it by enhancing insiders’ involvement in computer abuse. The aim of our study was to develop a new integrative model for analyzing computer abuse through assessing the role of Self Defense Intention (SDI) and ...
متن کاملWorkplace Management and Employee Misuse: Does Punishment Matter? Journal of Computer Information Systems
With the ubiquitous deployment of Internet, workplace Internet misuse has raised increasing concern for organizations. Research has demonstrated employee reactions to monitoring systems and how they are implemented. However, little is known about the impact of punishment-related policies on employee intention to misuse Internet. To extend this line of research beyond prior studies, this paper p...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- MIS Quarterly
دوره 37 شماره
صفحات -
تاریخ انتشار 2013