Towards analysing the rationale of information security non-compliance: Devising a Value-Based Compliance analysis method
针对员工不遵守信息安全政策的问题,提出一种基于价值的合规分析方法,帮助管理者系统分析员工遵守或不遵守政策的理性原因。
Employees’ poor compliance with information security policies is a perennial problem. Current information security analysis methods do not allow information security managers to capture the rationalities behind employees’ compliance and non-compliance. To address this shortcoming, this design science research paper suggests: (a) a Value-Based Compliance analysis method and (b) a set of design principles for methods that analyse different rationalities for information security. Our empirical demonstration shows that the method supports a systematic analysis of why employees comply/do not comply with policies. Thus we provide managers with a tool to make them more knowledgeable about employees’ information security behaviours.