In-Person and Remote Employees and Information Security Policy Compliance
摘要
Many workers have started working remotely, with a significant increase during and after the COVID-19 pandemic. At the same time, increasing costs of data breaches and number of security incidents continue to be a concern for organizations seeking to protect their organization, systems, and data. Using the theoretical frameworks of the Theory of Planned Behavior (TPB) and the Social Bonds Theory (SBT), we sought to understand employee compliance with information security policies (ISP). Using phenomenology, we interviewed both in-person and remote workers in a variety of industries. We uncovered their experiences with their organization’s implementation and enforcement of ISP, organizational culture and leadership attitudes shaping ISP compliance, and clarity and training of ISP for employees. Top factors that influenced employee compliance of ISPs of both in-person and remote workers included the automation of policies, hectic/busy times, efficiency, availability, training, and enforcement of the ISPs. Overall, participants reported positive relationships within their organization, regardless of whether they were in-person or remote; however, nearly all participants also noted that building relationships was easier to do in-person than remote, even as technology has bridged some of the gap between in-person and remote working relationships. We offer implications for practice and research.