Dalal Reeshad S, Howard David J, Bennett Rebecca J, Posey Clay, Zaccaro Stephen J, Brummel Bradley J
Department of Psychology, George Mason University, 4400 University Drive, MSN 3F5, Fairfax, VA 22030-4444 USA.
Department of Psychology and Muma College of Business, University of South Florida, Tampa, FL USA.
J Bus Psychol. 2022;37(1):1-29. doi: 10.1007/s10869-021-09732-9. Epub 2021 Feb 4.
Cybersecurity is an ever-present problem for organizations, but organizational science has barely begun to enter the arena of cybersecurity research. As a result, the "human factor" in cybersecurity research is much less studied than its technological counterpart. The current manuscript serves as an introduction and invitation to cybersecurity research by organizational scientists. We define cybersecurity, provide definitions of key cybersecurity constructs relevant to employee behavior, illuminate the unique opportunities available to organizational scientists in the cybersecurity arena (e.g., publication venues that reach new audiences, novel sources of external funding), and provide overall conceptual frameworks of the antecedents of employees' cybersecurity behavior. In so doing, we emphasize both end-users of cybersecurity in organizations and employees focused specifically on cybersecurity work. We provide an expansive agenda for future organizational science research on cybersecurity-and we describe the benefits such research can provide not only to cybersecurity but also to basic research in organizational science itself. We end by providing a list of potential objections to the proposed research along with our responses to these objections. It is our hope that the current manuscript will catalyze research at the interface of organizational science and cybersecurity.
网络安全是各组织一直面临的问题,但组织科学才刚刚开始涉足网络安全研究领域。因此,网络安全研究中的“人为因素”远不如其技术方面受到的研究多。本手稿旨在作为组织科学家对网络安全研究的介绍与邀请。我们定义了网络安全,给出了与员工行为相关的关键网络安全概念的定义,阐明了组织科学家在网络安全领域可获得的独特机会(例如,能接触新受众的出版渠道、新的外部资金来源),并提供了员工网络安全行为前因的总体概念框架。在此过程中,我们既强调组织中网络安全的终端用户,也强调专门从事网络安全工作的员工。我们为未来组织科学在网络安全方面的研究提供了一个广泛的议程——并且我们描述了此类研究不仅能为网络安全带来的益处,还能为组织科学本身的基础研究带来的益处。我们最后列出了对所提议研究的潜在反对意见以及我们对这些反对意见的回应。我们希望本手稿能推动组织科学与网络安全交叉领域的研究。