  • 學位論文


Understanding information security behavioral intentions: A Deterrence Approach

指導教授 : 施盛寶




In the dynamic enterprise environment, information technology infrastructure and the computers in organizations often suffer from security threats. In addition to the research on information security technology, many literatures have studied information security from management side, such as managing the information security behavior of employees to ensure internal information security of the organizations. Deterrence theory, therefore, has been employed to investigate employees’ information security behavior. However, these researches showed inconsistent results that perceived severity and perceived certainty may not both affect individuals’ behaviors because of the contextual effects influenced by the individual or environmental factors. Draw on this issue, based on the social influence theory proposed by Kelman, this study tend to understand the effects of the employees’ organizational commitment on the relations between the deterrence and employees’ information security behavior intention. We collected 168 samples from top 500 service companies on the list of CommonWealth magazine in 2011. The results showed that severity of punishment and certainty of detection had positive effects on employees’ information security behavior intention. In addition, employees' psychological aspects of organizational commitment enhanced the effects of deterrence on information security behavior intention. From this study, we implied that management has to notice the psychological part of employees’ commitment to the organizations when introducing disciplinary actions in companies.


Ajzen, I. 1991. "The Theory of Planned Behavior," Organizational behavior and human decision processes (50:2), pp 179-211.
Akers, R.L. 1990. "Rational Choice, Deterrence, and Social Learning Theory in Criminology: The Path Not Taken," J. Crim. L. & Criminology (81:3), pp 653-676.
Alavi, M., and Leidner, D.E. 2001. "Review: Knowledge Management and Knowledge Management Systems: Conceptual Foundations and Research Issues," Mis Quarterly (25:1), pp 107-136.
Albrechtsen, E. 2007. "A Qualitative Study of Users' View on Information Security," Computers & Security (26:4), pp 276-289.
Anderson, C., and Agarwal, R. 2006. "Practicing Safe Computing: Message Framing, Self-View, and Home Computer User Security Behavior Intentions," ICIS 2006 Proceedings.
