摘要
频发的员工信息安全违规已经成为企业管理中亟待解决的现实问题。然而,现阶段以个体为分析层次归纳员工信息安全违规行为类别,同时以组织为分析层次验证员工信息安全违规控制措施的研究相对较少,这不利于信息安全管理中员工与企业的良性互动。本研究基于扎根理论分析员工信息安全违规行为的类别及影响路径,并探讨可以有效抑制员工信息安全违规的组织控制策略。研究结果表明,员工信息安全违规行为可划分为3大类下的12个小类;员工参与对其工作投入有正向影响,并负向影响信息安全违规意愿,而工作投入在员工参与和信息安全违规意愿关系中起部分中介作用;组织支持作为控制策略在抑制员工信息安全违规发生上是有效的。上述研究结论有助于企业完善信息安全管理举措,减少员工信息安全违规行为的发生。
Frequent employees’information security violations have become a real organizational problem that need to be solved urgently.However,few studies have refined employees’violations from individual perspectives and verified which organizational control measures could suppress employees’violations from an organizational perspective at the same time.This study aims to address the above concern based on job characteristics using the grounded theory.Results show that:(1)employees’information security violations can be divided into three categories and twelve subcategories.(2)employee participation has positive effects on job engagement and negative effects on employees’information security violations.In addition,job engagement plays a partial mediation role between employee participation and information security violations.(3)organizational support is effective in suppressing employees’information security violations.The results can provide firms with implications on how to improve information security management,which can reduce employees’information security violations.
作者
甄杰
谢宗晓
董坤祥
陈琳
ZHEN Jie;XIE Zong-xiao;DONG Kun-xiang;CHEN Lin(School of Management Science and Engineering School,Chongqing Technology and Business University,Chongqing 400067,China;China Financial Certification Authority,Beijing 100054,China;School of Management Science and Engineering,Shandong University of Finance and Economics,Jinan 250014,China;College of Humanities and Law,Shandong University of Science and Technology,Qingdao 266590,China)
出处
《管理案例研究与评论》
CSSCI
北大核心
2021年第1期111-122,共12页
Journal of Management Case Studies
基金
重庆市自然科学基金面上项目“员工信息安全违规行为研究:自我管理、组织控制与匹配机制”(cstc2020jcyj-msxmX0820)
山东省自然科学基金面上项目“信息安全压力的形成机理、双面影响效应及组织干预策略研究”(ZR2020MG024)。
关键词
员工参与
工作投入
组织支持
信息安全违规
employee participation
job engagement
organizational support
information security violation