Title | ||
---|---|---|
The Influence Of Professional Subculture On Information Security Policy Violations: A Field Study In A Healthcare Context |
Abstract | ||
---|---|---|
In recent years, we have witnessed substantial increases in the frequency, scope, and cost of data breaches. Accordingly, information security researchers have sought to understand why employees comply with or violate information security policies (ISPs) designed to prevent security incidents. Research suggests that compliance is not uniform but rather depends on contextual and individual factors, such as national culture. Scholars have long recognized that organizational subculture may be equally influential. A key example is professional subcultures, within which members typically share similar education, training, values, and identity. Research shows that behavior can vary widely across professional subcultures, and thus a single approach to promoting ISP compliance may not be equally effective across these subcultures. However, it is presently unclear how subculture influences ISP compliance. To address this need, we adopt a mixed-methods design to examine differences in ISP violation behavior among different professional subcultures in a healthcare organization. We first conducted an exploratory qualitative study to identify different attitudes toward ISP violations among three prominent professional healthcare groups: physicians, nurses, and support staff. Then, using a combination of qualitative interviews, observational fieldwork, and a quantitative survey, we explored how professional group membership moderates (1) the influence of perceptions of sanctions on intentions to violate the ISP and (2) the effect of intentions to violate on actual ISP violation behaviors. Our findings highlight the substantial effect of professional subculture on ISP violations in organizations and provide insights for researchers and managers that may be used to improve overall ISP compliance. |
Year | DOI | Venue |
---|---|---|
2020 | 10.1287/isre.2020.0941 | INFORMATION SYSTEMS RESEARCH |
Keywords | DocType | Volume |
professional subculture, information security policy violations, mixed methods, healthcare | Journal | 31 |
Issue | ISSN | Citations |
4 | 1047-7047 | 0 |
PageRank | References | Authors |
0.34 | 0 | 5 |
Name | Order | Citations | PageRank |
---|---|---|---|
Sumantra Sarkar | 1 | 26 | 3.78 |
Anthony Vance | 2 | 726 | 26.44 |
Balasubramaniam Ramesh | 3 | 2097 | 141.59 |
Menelaos Demestihas | 4 | 0 | 0.34 |
Daniel Thomas Wu | 5 | 0 | 0.34 |