A4 Artikkeli konferenssijulkaisussa
New Insights into the Justifiability of Organizational Information Security Policy Noncompliance : A Case Study (2022)


Soliman, W., & Mohammadnazar, H. (2022). New Insights into the Justifiability of Organizational Information Security Policy Noncompliance : A Case Study. In Proceedings of the 55th Hawaii International Conference on System Sciences (HICSS 2022) (pp. 6812-6821). University of Hawai'i at Manoa. Proceedings of the Annual Hawaii International Conference on System Sciences. https://doi.org/10.24251/HICSS.2022.823


JYU-tekijät tai -toimittajat


Julkaisun tiedot

Julkaisun kaikki tekijät tai toimittajatSoliman, Wael; Mohammadnazar, Hojat

EmojulkaisuProceedings of the 55th Hawaii International Conference on System Sciences (HICSS 2022)

Konferenssi:

  • Hawaii International Conference on System Sciences

Konferenssin paikka ja aikaMaui, HI, USA3.-7.1.2022

eISBN978-0-9981331-5-7

Lehti tai sarjaProceedings of the Annual Hawaii International Conference on System Sciences

ISSN1530-1605

eISSN2572-6862

Julkaisuvuosi2022

Artikkelin sivunumerot6812-6821

KustantajaUniversity of Hawai'i at Manoa

JulkaisumaaYhdysvallat (USA)

Julkaisun kielienglanti

DOIhttps://doi.org/10.24251/HICSS.2022.823

Pysyvä verkko-osoitehttp://hdl.handle.net/10125/80163

Julkaisun avoin saatavuusAvoimesti saatavilla

Julkaisukanavan avoin saatavuusKokonaan avoin julkaisukanava

Julkaisu on rinnakkaistallennettu (JYX)https://jyx.jyu.fi/handle/123456789/79384


Tiivistelmä

Information security policies as apparatus for communicating security principles with employees are the cornerstone of organizational information security. Resultantly, extant literature has looked at different theories to better understand the noncompliance problem. Neutralization theory is emerging as one of the most popular approaches, not only as an explanation but also as a solution. In this in-depth qualitative study, we ask the question ‘how do employees justify violating the ISP’? Our findings reveal nine rationalizing techniques, three of which have not been recognized in previous research. We label them ‘I follow my own rules’, ‘matter of mere legality’ and ‘defense of uniqueness’. But more importantly, our in-depth insights point to the danger of taking these rationalizations out of context, since without context, it becomes impossible to judge whether the behavior or the rule, needs correcting, reflecting a dilemma recognized in the original writing of neutralization theory, which has since been forgotten.


YSO-asiasanattietosuojatietoturvaorganisaatiottyöntekijätasenteet


Liittyvät organisaatiot


OKM-raportointiKyllä

Raportointivuosi2022

JUFO-taso1


Viimeisin päivitys 2024-22-04 klo 20:01