Control mechanisms in information security: a principal agent perspective
Tejaswini Herath and
H. Raghav Rao
International Journal of Business Governance and Ethics, 2010, vol. 5, issue 1/2, 2-13
Abstract:
End user security behaviours are an important part of enterprise-wide information security. Although organisations have been actively using security technologies and practices, it is known that information security cannot be achieved through technological tools alone. In order to find appropriate control mechanisms to encourage employee security behaviours in organisations, we look at this problem through a principal agent perspective. Since employee security behaviours cannot be continuously monitored and employees may have conflicting views regarding security policies (moral hazard problem), we believe that the principal agent paradigm can provide insight in developing effective controls.
Keywords: principal agent theory; information security; employee security behaviour; employee monitoring; security policies; control mechanisms; business governance; business ethics; economic crime prevention. (search for similar items in EconPapers)
Date: 2010
References: Add references at CitEc
Citations:
Downloads: (external link)
http://www.inderscience.com/link.php?id=29551 (text/html)
Access to full text is restricted to subscribers.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:ids:ijbget:v:5:y:2010:i:1/2:p:2-13
Access Statistics for this article
More articles in International Journal of Business Governance and Ethics from Inderscience Enterprises Ltd
Bibliographic data for series maintained by Sarah Parker ().