Cybersecurity Policy Compliance Assessment

Charlette Donalds, Corlane Barclay, Kweku-Muata Osei-Bryson · 2022

In addition to implementing technological tools, entities have adopted cybersecurity policies (CSPs) to address the rising number of employee-related cybersecurity (CS) incidents. If, however, employees do not understand the importance of or are unwilling to comply with CSPs, CS efforts may be in vain. This study investigates employees’ actual CS compliance behaviour. Informed by the literatures on security behavioural interventions and organizational behaviour, this study is motivated by the fundamental premise that employee CS compliance is influenced by security behavioural intervention and organizational context factors. An integrated CS compliance model of CS awareness (CSAW), CS policy awareness (CSPA), CS training (CSTR) and top management support (TMSP) is developed. The theoretical model is empirically validated with a data set representing the survey responses of employees in key government agencies in the Global South. The results from the structural equation modelling tests suggest that (a) CSAW and CSPA are significant factors contributing to employees’ actual CS compliance behaviour; (b) the support and involvement of top management have a significant impact on CSPA; and (c) CSTR influences both CSAW and CSPA.

Read the paper · More papers on PaperTik