Employee Attitudes Towards Information Security Measures: An Empirical Assessment

Authors

Keywords:

information security measures, attitude, technology acceptance model

Abstract

Information age has made information security an essential concern for us all. While institutions and organizations focus on reducing technical vulnerability by continuously improving security technologies, threats to information security have started to focus on the human element by constantly evolving in terms of target, domain and techniques used. Employees are shown to be responsible for the most critical security threats due to social engineering and careless user behavior. However, there is a lack of studies on the effect of the attitude, which is considered to be effective in predicting real behaviors, on the acceptance and use of information security measures by employees. The present study explores and tries explain employees’ attitudes towards information security measures through the Technology Acceptance Model (TAM). For this purpose, a survey was conducted on 1490 public employees in Zonguldak. As predicted in theory, the results have shown that perceived usefulness and ease of use have a statistically significant effect on attitude. In addition, some subdimensions of information security awareness partially have a statistically significant impact on perceived usefulness, perceived ease of use, and attide.

References

Ajzen, I., & Fishbein, M. (1975). A Bayesian Analysis of Attribution Processes. Psychological Bulletin, 82(2), 261-277.

Ajzen, I. (1985). From Intentions to Actions: A Theory of Planned Behavior. In Action Control (s. 11-39). Springer, Berlin, Heidelberg.

Albers, S. (2010). PLS and Success Factor Studies in Marketing. V. E. Vinzi, W. W. Chin, J. Henseler, & H. Wang (Eds.), Handbook of Partial Least Squares Concepts, Methods and Applications. Almanya: Springer.

Al-Omari, A., El-Gayar, O., & Deokar, A. (2012). Security Policy Compliance: User Acceptance Perspective. 45th Hawaii International Conference on System Sciences (s.3317-3326). IEEE.

Anderson, J. B. (2021). Inadequacy of Risk Acceptance Criteria for Cloud Services Adoption: A Qualitative Generic Study. (Yayımlanmamış doktora tezi), Capella University School of Business, Minnesota.

Antoniou, G. S. (2015). Design an Effective Information Security Policy for Exceptional Situations in an Organization: An Experimental Study. Nova Southeastern University, Graduate School of Computer and Information Sciences.

Arshinskiy, L. & Shurkhoetsky, G. (2022). Methods of Information Security in Cloud Storages. Transportation Research Procedia, 61(2022), 455-461.

Boone, R. G. (2011). Factors Impacting Innovation Acceptance in Product Development Organization: Utilizing Technology Acceptance Model. (Yayımlanmamış doktora tezi), Capella University School of Business and Technology, Minnesota.

Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information Security Policy Compliance: An Empirical Study of Rationality-Based Beliefs and Information Security Awareness. MIS Quarterly, 34(3), 523-548.

Chen, V. V. (2012). Ensuring the Effectiveness of Information Security Policy: The Development and Validationof an Information Security Model. State University of New York College of Computing and Information, New York.

Cherdantseva, Y., & Hilton, J. (2013). A Reference Model of Information Assurance & Security. IEEE Proceedings of ARES 2013, (s.1-11). Resenburg.

Chetioui, K., Bah, B., Alami, A. O., & Bahnasse, A.(2022). Overview of Social Engineering Attacks on Social Networks. Procedia Computer Science, 198(2022), 656-661.

Chin, W. W. (1998). Issues and Opinion on Structural Equation Modeling. MIS Quarterly, 22(1), vii-xvi.

Corallo, A., Lazoi, M., Lezzi, M., & Luperto, A. (2022). Cybersecurity Awareness in the Context of the Industrial Internet of Things: A Systematic Literature Review. Computers in Industry, 137(2022), 1-16.

Çatuk, C. (2018). Siber Risklerin Karşısında KOBİ’lerin Bilgi Güvenliği Farkındalıklarını Ölçen Bir Ölçek Geliştirme: Gaziantep Örneklemi. (Yayımlanmamış doktora tezi), Hasan Kalyoncu Üniversitesi Sosyal Bilimler Enstitüsü, Gaziantep.

Davis, F. D. (1989). Perceived Usefulness, Perceived Ease of Use, and User Acceptance of Information Technology. MIS Quarterly, 13(3), 319-340.

Davis, F. D. (1993). User Acceptance of Information Technology: System Characteristics, User Perception and Behavioral Impacts. Int. J. Man-Machine Studies, 38, 475-487.

Dhillon, G., & Backhouse, J. (2000). Technical Opinion: Information System Security Management in the New Millennium. Communications of the ACM, 43(7), 125-128.

Eminağaoğlu, M., & Gökşen, Y. (2009). Bilgi Güvenliği Nedir, Ne Değildir, Türkiye’de Bilgi Güvenliği Sorunları ve Çözüm Önerileri. Dokuz Eylül Üniversitesi Sosyal Bilimler Enstitüsü Dergisi, 11(4), 1-5.

Erkan, A. (2006). Bilgi Güvenliği Yönetim Sistemi İçin Otomatik Bir Araç. (Yayımlanmamış yüksek lisans tezi), Orta Doğu Teknik Üniversitesi Enformatik Enstitüsü, Ankara.

Ersoy, E. V. (2012). ISO/IEC 27001 Bilgi Güvenliği Standardı. Ankara: ODTÜ Yayıncılık.

Farrel, A. M. (2010). Insufficient Discriminant Validity: A Comment on Bove, Pervan, Beatty, and Shiu (2009). Journal of Business Research, 63(3), 324-327.

Feistel, G. (2014). Technology Acceptance Model: Factor Influencing Consumers’ Intent to Use Electronic Personal Health Records. (Yayımlanmamış doktora tezi), Central Michigan University School of Health Sciences, Michigan.

Fornell, C., & Larcker, D. F. (1981). Structural Equation Models with Unobservable Variables and Measurement Error: Algebra and Statistics. Journal of Marketing Research, 18(3), 382-388.

Gabbard, R. B. (2004). Applying the Technology Acceptance Model to Online Education. (Yayımlanmamış doktora tezi), Trident University International Faculty of the College of Business Administration, California.

Garson, G. D. (2016). Partial Least Squares: Regression and Structural Equation Models. Asheboro, NC: Statistical Associates Publishers.

Gelişken, U. (2009). 10 Adımda Bilgisayar Güvenliği. İstanbul: KODLAB Yayıncılık.

Grassegger, T., & Nedbal, D. (2021). The Role of Employees’ Information Security Awareness on the Intention to Resist Social Engineering. Procedia Computer Science, 181, 59-66.

Güldüren, C. (2015). Yükseköğretim Kurumlarındaki Öğretim Elemanlarının Bilgi Güvenliği Farkındalık Düzeylerinin Değerlendirilmesi. (Yayımlanmamış doktora tezi), Ankara Üniversitesi Eğitim Bilimleri Enstitüsü, Ankara.

Hair, J. F., Hult, T. M., Ringle, C., & Sarstedt, M. (2014a). A Primer on Partial Least Squares Structural Equation Modeling (PLS-SEM). America: SAGE Publications.

Hair, J. F., Ringle, C. M., & Sarstedt, M. (2011). Indeed a Silver Bullet. Journal of Marketing Theory and Practice, 1(2), 139-151.

Hair, J. F., Risher, J. J., Sarstedt, M., & Ringle, C. M. (2019). When to Use and How to Report the Results of PLS-SEM. European Business Review, 31(1), 2-4.

Hair, J. F., Sarstedt, M., Hopkins, L., & Kuppelwieser, V. G. (2014b). Partial Least Squares Structural Equation Modeling (PLS-SEM) An Emerging Tool in Business Research. European Business Review, 26(2), 106-121.

Henseler, J., Dijkstra, T. K., Sarstedt, M., Ringle, C. M., Diamantopoulos, A., Straub, D. W., …Calantone, R. J. (2014). Common Beliefs and Reality About PLS: Comments on Rönkkö and Evermann (2013). Organizational Research Methods, 17(2), 182-209.

Henseler, J. (2017). Partial Least Squares Path Modeling Advanced Methods for Modeling Markets. International Series in Quantitative Marketing. Retrieved on 10 10, 2021 from file:///C:/Users/nurg%C3%BCl/Downloads/Henseler2017-PLSPathModeling.pdf

Henseler, J., Hubona, G., & Ray, P. A. (2015). Using PLS Path Modeling in New Technology Research: Updated Guidelines. Industrial Management & Data Systems, 116(1), 2-20.

Hernandez, T. E. (2021). Strategies for Implementing Internet of Things Devices in Manufacturing Environments. (Yayımlanmamış doktora tezi), Walden University Information Systems and Technology, Minnesota.

Hu, L. T., & Bentler, P. M. (1999). Cutoff Criteria for Fit Indexes in Covariance Structure Analysis: Conventional Criteria Versus New Alternatives. Structural Equation Modeling: A Multidisciplinary Journal, 6(1), 1-55.

Hulland, J. (1999). Use of Partial Least Squares (PLS) in Strategic Management Research: A Review of Four Recent Studies. Strategic Management Journal, 20, 195-204.

Hwang, I., Wakefield, R., Kim, S., & Kim, T. (2019). Security Awareness: The First Step in Information Security Compliance Behavior. Journal of Computer Information Systems. Retrieved on 03 11, 2020 from https://doi.org/10.1080/08874417.2019.1650676

İleri, Y. Y. (2018). Kurumsal Bilgi Kaynaklarına Erişimde Güvenlik: Hekimlerin Şifre Yönetimine Yönelik Bir Araştırma. Uluslararası Sağlık Yönetimi ve Stratejileri Araştırma Dergisi, 4(1), 15-25.

Jones, C. M. (2009). Utilizing the Technology Acceptance Model to Assess Employee Adoption of Information Systems Security Measures. (Yayımlanmamış doktora tezi), Nova Southeastern University School of Business and Entrepreneurship, Florida.

Jouini, M., Rabai, L. B., & Aissa, A. B. (2014). Classification of Security Threats in Information Systems. 5th International Conference on Ambient Systems, Networks and Technologies, (s. 489-496). Belgium.

Karaoğlan Yılmaz, F. G., Yılmaz, R., & Sezer, B. (2014). Üniversite Öğrencilerinin Güvenli Bilgi ve İletişim Teknolojisi Kullanım Davranışları ve Bilgi Güvenliği Eğitimine Genel Bir Bakış. Bartın Üniversitesi Eğitim Fakültesi Dergisi, 3(1), 176-199.

Kim, J. A. (2005). User Acceptance of Web-Based Subscription Databases: Extending the Technology Acceptance Model. (Yayımlanmamış doktora tezi), The Florida State University College of Information, Tallahassee.

Koohang, A., Sargent, C. S., Nord, J. H., & Paliszkiewicz, J. (2022). Internet of Things (IoT): From Awareness to Continued Use. International Journal of Information Management, 62 (2022), 1-10.

Koza, M. (2008). Bilgi Yönetimi: Bilgiyi Doğru Kullanmak. İstanbul: Kum Saati Yayınları.

Laudon, K. C., & Laudon, J. P. (2011). Management Information Systems Managing The Digital Firm. England: Pearson Education Limited.

Lee, V. C. (2015). Examining the Relationship between Autonomy, Competence, and Relatedness and Security Policy Compliant Behavior. (Yayımlanmamış doktora tezi), Northcentral University Graduate Faculty of the School of Business and Technology Management, Arizona.

Lionel, B. (2020). Examining the Relationship Between Cybersecurity-Employee Vulnerabilities and Reduction of Security Breaches in Information Technology Organization. (Yayımlanmamış doktora tezi), Colorado Technical University Computer Science, Colorado.

Loch, K. D., Carr, H. H., & Warkentin, M. E. (1992). Threats to Information Systems: Today’s Reality, Yesterday’s Understanding. MIS Quarterly, 16(2), 173-186.

Marakas, G. M., & O’Brien, J. A. (2013). Introduction to Information Systems. USA: The McGraw-Hill Companies.

Matney, J. L. (2022). Exploring the Cybersecurity Challenges of Quantum -Resistant Solution Implementations for Securing Internet of Things Data.(Yayımlanmamış doktora tezi), Colorado Technical University, Colorado.

McCumber, J. R. (1990). Information Systems Security: A Comprehensive Model. 14th National Computer Security Conference. Washington, s.334

McCormac, A., Zwaans, T., Parsons, K., Calic, D., Butavicius, M., & Pattinson, M. (2017). Individual Differences and Information Security Awareness. Computers in Human Behavior, 69, 151-156.

Merhi, M. I. (2014). Creating An Information Systems Security Culture Through An Integrated Model of Employees Compliance. (Yayımlanmamış doktora tezi), the Graduate School of the University of Texas-Pan American, Edinburg.

Metalidou, E., Marinagi, C., Trivellas, P., Eberhagen, N., Skourlas, C., & Giannakopoulos, G. (2014). The Human Factor of Information Security: Unintentional Damage Perspective. Procedia-Social and Behavioral Sciences, 147, 424-428.

Mitnick, K. D., & Simon, W. L. (2005). Aldatma Sanatı. (N. E. Tezcan, Çev.) Ankara: ODTÜ Yayıncılık.

Ngufor, F. A. (2020). Understanding the Perspective of Information Security Managers on Insider Threat: A Phenomenology Investigation. (Yayımlanmamış doktora tezi), Northcentral University School of Business, Arizona.

Nitzl, C. (2016). The Use of Partial Least Squares Structural Equation Modelling (PLS-SEM) in Management Accounting Research: Directions for Future Theory Development. Journal of Accounting Literature, 37, 19-35.

Özer, G., Özcan, M., & Aktaş, S. (2010). Muhasebecilerin Bilgi Teknolojisi Kullanımının Teknoloji Kabul Modeli (TKM) İncelenmesi. Journal of Yasar University, 3278-3293.

Parsons, K., Calic, D., & Pattinson, M. (2017). The Human Aspects of Information Security Questionnaire (HAIS-Q): Two Further Validation Studies. Computer & Security, 66, 40-51.

Peltier, T. R. (2001). Information Security Risk Analysis. Auerbach. Retrieved on 30 12, 2021 from https://books.google.com.tr/books?id=O0_fO2Xvp98C&printsec=frontcover&dq=information+security+definition&hl=tr&sa=X&redir_esc=y#v=onepage&q=information%20security&f=false

Raggad, B. G. (2010). Information Security Management: Concepts and Practice. Boca Raton: CRC Press. Retrieved on 30 12, 2021 from https://books.google.com.tr/books?id=PQ3SBQAAQBAJ&pg=PA537&dq=ISO/IEC+27002+(2005)+information+security&hl=tr&sa=X&ved=2ahUKEwjZ2LHf6MD0AhXBSvEDHVBWB7QQ6wF6BAgFEAE#v=onepage&q=ISO%2FIEC%2027002%20(2005)%20information%20security&f=false

Rome, J. D. (2021). Understanding Adoption Barriers of Superior Technologies to Authenticate and Protect Users from Ongoing Cyber Threats. (Yayımlanmamış doktora tezi). Ashford University, Arizona.

Safa, N. S., Sookhak, M., Solms, R. V., Furnell, S., Ghani, N. AN., & Herawan, T. (2015). Information Security Conscious Care Behaviour Formation in Organizations. Computers & Security, 53, 65-78.

Solms, B. v. (2000). Information Security-The Third Wave? Computer & Security, 19(7), 615-620.

Solms, B. v. (2006). Information Security-The Fourth Wave. Computer & Security, 25(3), 165-168.

Solms, B. v. (2010). The 5Waves of Information Security-From Kristian Beckman to Present. IFIP International Information Security Conference, SEC: 2010 Security and Privacy – Silver Linings in the Cloud, (s. 1-8).

Şahinaslan, E. (2010). Standartlara Dayalı Bilgi Güvenliği Risk Analiz ve Ölçümleme Metodolojisinin Bankacılık Sektörüne Özgü Modellenmesi ve Uygulama Yazılımının Geliştirilmesi. (Yayımlanmamış doktora tezi), Trakya Üniversitesi Fen Bilimleri Enstitüsü, Edirne.

Teo, T., & Lee, C. B. (2008). Understanding pre-service teachers’ computer attitudes: Applying and Extending the Technology acceptance model. Journal of Computer Assisted Learning, 24(2), 128-143.

Tientcheu, P. P. (2021). Security Awareness Strategies Used in the Prevention of Cybercrimes by Cybercriminals. (Yayımlanmamış doktora tezi), Walden University College of Management and Technology, Minnesota.

Turan, M. (2019). Ceza Almadan Tedbir Al Kişisel Veriler Bilgi Güvenliği İlkeleri İle Nasıl Korunur? KVKK İşletmenizin Kanuna Uyumlu Olması için Ne Yapmalısınız? İstanbul: Cinius Yayınları.

Vargas Moya, E. (2021). Security and Privacy Risks Associated of Cloud Computing: A Correlational Study. (Yayımlanmamış doktora tezi), Capella University School of Business and Technology, Minnesota.

Wright, C. (2008). The IT Regulatory and Standards Compliance Handbook: How to Survive an Information Systems Audit and Assessments. Burlington: Syngress Publishing

Young, R. (2010). Evaluating the Perceived Impact of Collaborative Exchange and Formalization on Information Security. Journal of International Technology and Information Management, 19(3), 2.

Yurtsever, G. (2013). Bilgi Güvenliği İçin Ne Yapmalı? Turcomoney Dergisi. Retrieved on 12 10, 2020 from https://www.turcomoney.com/bilgi-guvenligi-icin-ne-yapmali.html

Downloads

Published

2022-10-20

Issue

Section

Research Articles

How to Cite

Employee Attitudes Towards Information Security Measures: An Empirical Assessment. (2022). International Journal of Applied Economic and Finance Studies, 7(2), 26-44. https://journal.bauderpress.org.tr/index.php/ijaefs/article/view/133