The Australasian Journal of Information Systems
Author ORCID Identifier
Hiep Cong Pham
Duy Dang Pham
Linda Brennan
Joan Richardson
Document Type
Research Article
Abstract
This evaluation of end-users and IT experts/managers’ attitudes towards performing IT security tasks indicates important differences between their perspectives on what is and is not necessary to establish a secure corporate IT environment. Through a series of case studies, this research illustrates that making it easier for end-users to comply does not necessarily equate to enhanced implementation of security measures. End-users want to be autonomous, competent, self-motivated and active participants in the development of secure environments. However, managers and experts want to limit autonomy to ensure that procedures are followed closely, rather than permitting flexibility. This results in the creation of environments that are intrinsically de-motivating rather than motivating end-users to become self-determined and self-regulating co-creators of a secure IT environment. The paper also discusses alternative approaches to developing a human system that works for end-users and experts.
Recommended Citation
Pham, Hiep Cong; Pham, Duy Dang; Brennan, Linda; and Richardson, Joan
(2017)
"Information Security and People: A Conundrum for Compliance,"
The Australasian Journal of Information Systems: Vol. 21:
No.
1, Article 2.
DOI: 10.3127/ajis.v21i0.1321
Available at:
https://aisel.aisnet.org/ajis/vol21/iss1/2