关键词:
Information technology
Computer science
摘要:
As was observed during the 2014 Target security breach and the global 2017 Wannacry ransomware attack, information security policy noncompliance can have dire consequences, not only on the secured private information but on the finances of the organizations that are attacked. Information security policy noncompliance is the most significant risk to organizational security, but risk assessment models are insufficient to address emerging threats and the current body of research lacks investigations into actual noncompliant behaviors perpetrated by non-IT personnel. The purpose of this qualitative phenomenological study was to investigate the lived experiences of 24 Department of Defense level IT professionals to identify specific noncompliant behaviors of organizational personnel. The conceptual framework of the study was cyber physical systems security, which encompasses all physical, hardware, and software domains within any given IT/IS implementation. Qualitative analysis of the collected interview data yielded 5 thematic categories that contain distinct patterns of policy noncompliance and antecedents to noncompliant behaviors: convenience noncompliance, lack of education or awareness, noncompliance due to human nature, leadership noncompliance, and misinterpretation of policy. Data saturation was achieved. It is recommended that the results be used to create compliance models based on human experiences, to create quantitative instruments and studies, to design experimental or causal studies, to contribute to risk assessment models, and to apply to cyber physical systems security models.