Chen Lin, Xie Zongxiao, Zhen Jie, Dong Kunxiang
College of Humanities and Law, Shandong University of Science and Technology, Qingdao, 266590, People's Republic of China.
China Financial Certification Authority, Beijing, 100054, People's Republic of China.
Psychol Res Behav Manag. 2022 May 11;15:1177-1191. doi: 10.2147/PRBM.S359277. eCollection 2022.
Information security policy (ISP) compliance of employees has a profound impact on organization. In the context of information technology innovation and information systems upgrade, employees' information security behavior is one of the most crucial elements in the information security management of organizations. Based on the two-dimensional model of challenge-hindrance stressor theory and affective events theory, this study explores the mediating effects of emotions on the relationship between challenge information security stress and ISP compliance.
A field quasi-experimental method was used in this study. Materials include the Challenge Information Security Stress Scale, Information System Security Policy Compliance Scale, and Emotions Scale, which were used to form the two-stage questionnaire surveys. Data of 217 employees from three Chinese companies in Shanghai and Beijing that had passed certifications for information security management system (GB/t22080-2008/ISO/IEC 27001:2005) were collected. Bootstrapping method for multiple mediation models and the Process 3.0 plug-in of SPSS 20.0 were used for data analysis.
The findings indicate that challenge information security stress has a positive effect on ISP compliance. Challenge information security stress has a positive effect on positive emotions and a negative effect on negative emotions. Positive emotions have mediating effect between challenge information security stress and ISP compliance, but negative emotions have no mediating effect.
The research results expand the research scope of challenging stress in the two-dimensional model of challenge-hindrance stressor theory in the context of organizational information security. The findings reveal the mediating effect of positive emotions in challenge information security stress and ISP compliance relationship, which provides empirical support for the application of positive psychology in the field of management.
员工对信息安全政策(ISP)的合规性对组织有着深远影响。在信息技术创新和信息系统升级的背景下,员工的信息安全行为是组织信息安全管理中最关键的要素之一。基于挑战 - 阻碍压力源理论和情感事件理论的二维模型,本研究探讨了情绪在挑战性信息安全压力与ISP合规性之间关系中的中介作用。
本研究采用现场准实验方法。材料包括挑战性信息安全压力量表、信息系统安全政策合规量表和情绪量表,用于形成两阶段问卷调查。收集了来自上海和北京三家通过信息安全管理体系认证(GB/t22080 - 2008/ISO/IEC 27001:2005)的中国公司的217名员工的数据。使用多重中介模型的Bootstrapping方法和SPSS 20.0的Process 3.0插件进行数据分析。
研究结果表明,挑战性信息安全压力对ISP合规性有积极影响。挑战性信息安全压力对积极情绪有积极影响,对消极情绪有消极影响。积极情绪在挑战性信息安全压力与ISP合规性之间起中介作用,但消极情绪没有中介作用。
研究结果扩展了组织信息安全背景下挑战 - 阻碍压力源理论二维模型中挑战性压力的研究范围。研究结果揭示了积极情绪在挑战性信息安全压力与ISP合规性关系中的中介作用,为积极心理学在管理领域的应用提供了实证支持。