On Security Guidelines and Policy Compliance: Considering Users’ Need for Autonomy
Christian M. Olt and
Fenne große Deters
Publications of Darmstadt Technical University, Institute for Business Studies (BWL) from Darmstadt Technical University, Department of Business Administration, Economics and Law, Institute for Business Studies (BWL)
Abstract:
Recent studies raise the concern that the regular communication of security guidelines and policies and their updates is not always the best option for organizations to protect information system's security. Users show symptoms of being frustrated or overwhelmed by security guidelines and consequently either ignore policies or actively pursue workarounds. Our aim is first, to understand the affective states of employees being confronted with security-related guidelines and the reasons for negative emotions. Second, we develop a communication strategy for security policies that avoids negative affective states and reduces the chance of security policies being ignored or worked around to foster compliance. In this paper, we introduce a framework by connecting the theories of security fatigue, psychological reactance, and the elaboration likelihood model. Our framework moreover considers different strategies to communicate security guidelines or policies. Finally, we draft an experimental setup to empirically evaluate our research model.
Date: 2021-12-15
Note: for complete metadata visit http://tubiblio.ulb.tu-darmstadt.de/129230/
References: Add references at CitEc
Citations:
Downloads: (external link)
https://aisel.aisnet.org/icis2021/cyber_security/cyber_security/2/
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:dar:wpaper:129230
Access Statistics for this paper
More papers in Publications of Darmstadt Technical University, Institute for Business Studies (BWL) from Darmstadt Technical University, Department of Business Administration, Economics and Law, Institute for Business Studies (BWL) Contact information at EDIRC.
Bibliographic data for series maintained by Dekanatssekretariat ().