Cargando…

An Investigation of Employees’ Intention to Comply with Information Security System—A Mixed Approach Based on Regression Analysis and fsQCA

Employee security compliance behavior has become an important safeguard to protect the security of corporate information assets. Focusing on human factors, this paper discusses how to regulate and guide employees’ compliance with information security systems through effective methods. Based on prote...

Descripción completa

Detalles Bibliográficos
Autores principales: Li, Wenqin, Liu, Rongmin, Sun, Linhui, Guo, Zigu, Gao, Jie
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2022
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9737675/
https://www.ncbi.nlm.nih.gov/pubmed/36498115
http://dx.doi.org/10.3390/ijerph192316038
_version_ 1784847349972992000
author Li, Wenqin
Liu, Rongmin
Sun, Linhui
Guo, Zigu
Gao, Jie
author_facet Li, Wenqin
Liu, Rongmin
Sun, Linhui
Guo, Zigu
Gao, Jie
author_sort Li, Wenqin
collection PubMed
description Employee security compliance behavior has become an important safeguard to protect the security of corporate information assets. Focusing on human factors, this paper discusses how to regulate and guide employees’ compliance with information security systems through effective methods. Based on protection motivation theory (PMT), a model of employees’ intention to comply with the information security system was constructed. A questionnaire survey was adopted to obtain 224 valid data points, and SPSS 26.0 was applied to verify the hypotheses underlying the research model. Then, based on the results of a regression analysis, fuzzy set qualitative comparative analysis (fsQCA) was used to explore the conditional configurations that affect employees’ intention to comply with the information security system from a holistic perspective. The empirical results demonstrated that perceived severity, perceived vulnerability, response efficacy, and self-efficacy all positively influenced the employees’ intention to comply with the information security system; while rewards and response costs had a negative effect. Threat appraisal had a greater effect on employees’ intention to comply with the information security system compared to response appraisal. The fsQCA results showed that individual antecedent conditions are not necessary to influence employees’ intention to comply with an information security system. Seven pathways exist that influence an employees’ intention to comply with an information security system, with reward, self-efficacy, and response cost being the core conditions having the highest probability of occurring in each configuration of pathways, and with perceived severity and self-efficacy appearing in the core conditions of configurations with an original coverage greater than 40%. Theoretically, this study discusses the influence of the elements of PMT on employees’ intention to comply with an information security system, reveals the mechanism of influence of the combination of the influencing factors on the outcome variables, and identifies the core factors and auxiliary factors in the condition configurations, providing a new broader perspective for the study of information security compliance behavior and providing some theoretical support for strengthening enterprise security management. Practically, targeted suggestions are proposed based on the research results, to increase the intention of enterprise employees to comply with information security systems, thereby improving the effectiveness of enterprise information security management and the degree of information security in enterprises.
format Online
Article
Text
id pubmed-9737675
institution National Center for Biotechnology Information
language English
publishDate 2022
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-97376752022-12-11 An Investigation of Employees’ Intention to Comply with Information Security System—A Mixed Approach Based on Regression Analysis and fsQCA Li, Wenqin Liu, Rongmin Sun, Linhui Guo, Zigu Gao, Jie Int J Environ Res Public Health Article Employee security compliance behavior has become an important safeguard to protect the security of corporate information assets. Focusing on human factors, this paper discusses how to regulate and guide employees’ compliance with information security systems through effective methods. Based on protection motivation theory (PMT), a model of employees’ intention to comply with the information security system was constructed. A questionnaire survey was adopted to obtain 224 valid data points, and SPSS 26.0 was applied to verify the hypotheses underlying the research model. Then, based on the results of a regression analysis, fuzzy set qualitative comparative analysis (fsQCA) was used to explore the conditional configurations that affect employees’ intention to comply with the information security system from a holistic perspective. The empirical results demonstrated that perceived severity, perceived vulnerability, response efficacy, and self-efficacy all positively influenced the employees’ intention to comply with the information security system; while rewards and response costs had a negative effect. Threat appraisal had a greater effect on employees’ intention to comply with the information security system compared to response appraisal. The fsQCA results showed that individual antecedent conditions are not necessary to influence employees’ intention to comply with an information security system. Seven pathways exist that influence an employees’ intention to comply with an information security system, with reward, self-efficacy, and response cost being the core conditions having the highest probability of occurring in each configuration of pathways, and with perceived severity and self-efficacy appearing in the core conditions of configurations with an original coverage greater than 40%. Theoretically, this study discusses the influence of the elements of PMT on employees’ intention to comply with an information security system, reveals the mechanism of influence of the combination of the influencing factors on the outcome variables, and identifies the core factors and auxiliary factors in the condition configurations, providing a new broader perspective for the study of information security compliance behavior and providing some theoretical support for strengthening enterprise security management. Practically, targeted suggestions are proposed based on the research results, to increase the intention of enterprise employees to comply with information security systems, thereby improving the effectiveness of enterprise information security management and the degree of information security in enterprises. MDPI 2022-11-30 /pmc/articles/PMC9737675/ /pubmed/36498115 http://dx.doi.org/10.3390/ijerph192316038 Text en © 2022 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Li, Wenqin
Liu, Rongmin
Sun, Linhui
Guo, Zigu
Gao, Jie
An Investigation of Employees’ Intention to Comply with Information Security System—A Mixed Approach Based on Regression Analysis and fsQCA
title An Investigation of Employees’ Intention to Comply with Information Security System—A Mixed Approach Based on Regression Analysis and fsQCA
title_full An Investigation of Employees’ Intention to Comply with Information Security System—A Mixed Approach Based on Regression Analysis and fsQCA
title_fullStr An Investigation of Employees’ Intention to Comply with Information Security System—A Mixed Approach Based on Regression Analysis and fsQCA
title_full_unstemmed An Investigation of Employees’ Intention to Comply with Information Security System—A Mixed Approach Based on Regression Analysis and fsQCA
title_short An Investigation of Employees’ Intention to Comply with Information Security System—A Mixed Approach Based on Regression Analysis and fsQCA
title_sort investigation of employees’ intention to comply with information security system—a mixed approach based on regression analysis and fsqca
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9737675/
https://www.ncbi.nlm.nih.gov/pubmed/36498115
http://dx.doi.org/10.3390/ijerph192316038
work_keys_str_mv AT liwenqin aninvestigationofemployeesintentiontocomplywithinformationsecuritysystemamixedapproachbasedonregressionanalysisandfsqca
AT liurongmin aninvestigationofemployeesintentiontocomplywithinformationsecuritysystemamixedapproachbasedonregressionanalysisandfsqca
AT sunlinhui aninvestigationofemployeesintentiontocomplywithinformationsecuritysystemamixedapproachbasedonregressionanalysisandfsqca
AT guozigu aninvestigationofemployeesintentiontocomplywithinformationsecuritysystemamixedapproachbasedonregressionanalysisandfsqca
AT gaojie aninvestigationofemployeesintentiontocomplywithinformationsecuritysystemamixedapproachbasedonregressionanalysisandfsqca
AT liwenqin investigationofemployeesintentiontocomplywithinformationsecuritysystemamixedapproachbasedonregressionanalysisandfsqca
AT liurongmin investigationofemployeesintentiontocomplywithinformationsecuritysystemamixedapproachbasedonregressionanalysisandfsqca
AT sunlinhui investigationofemployeesintentiontocomplywithinformationsecuritysystemamixedapproachbasedonregressionanalysisandfsqca
AT guozigu investigationofemployeesintentiontocomplywithinformationsecuritysystemamixedapproachbasedonregressionanalysisandfsqca
AT gaojie investigationofemployeesintentiontocomplywithinformationsecuritysystemamixedapproachbasedonregressionanalysisandfsqca