Effect of Targeted Antineutralization Communication on Information Security Policy Violation Intention
Information Security, Violation Intention, Neutralization Theory, Antineutralization Communication, Experiment
Lately, as the importance of information security continues to rise, companies have not only made information security policies but also used information security awareness training programs in order to enhance employees' awareness of information security. However, many employees use neutralization techniques to rationalize their noncompliant behavior, thereby increasing the information security risks for companies.
Therefore, we have designed targeted antineutralization communication, aiming to reduce employees' intention to violate information security policies when using specific neutralization techniques. We selected neutralization techniques based on relevant antineutralization research and a model of neutralization techniques; the chosen techniques are denial of injury and defense of necessity, for which targeted antineutralization communication has been designed. In this study, experimental method was used in which participants read situations that included different combinations of neutralization techniques and antineutralization communication.
The results showed that the defense of necessity increased the participants’ intention to violate information security policies, and if the defense of necessity was combined with the antineutralization communication against the defense of necessity technique, it could effectively reduce the participants’ intention to violate information security policies.
目次 Table of Contents
論文審定書 i
摘要 ii
Abstract iii
第一章 緒論 1
第一節 研究背景與動機 1
第二節 研究目的與研究問題 5
第三節 研究流程 6
第二章 文獻探討 7
第一節 資訊安全政策違規行為及常見理論 7
第二節 中立化理論及中立化技巧整合模型 16
第三節 反中立化溝通 24
第三章 研究架構與研究方法 26
第一節 研究假設發展及研究架構圖 26
第二節 操作型定義 31
第三節 研究設計 32
第四章 資料分析 39
第一節 樣本背景資料 39
第二節 信度分析 41
第三節 研究假設驗證 42
第五章 結論與建議 51
第一節 研究結果討論 51
第二節 理論與實務意涵 53
第三節 研究限制及未來研究方向 55
參考文獻 56
附錄:實驗問卷 61
