articleMIS QuarterlySep 1, 2010Closed access

Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations1

University of Oulu · Brigham Young University

Indexed incrossref

Abstract

Employees’ failure to comply with information systems security policies is a major concern for information technology security managers. In efforts to understand this problem, IS security researchers have traditionally viewed violations of IS security policies through the lens of deterrence theory. In this article, we show that neutralization theory, a theory prominent in Criminology but not yet applied in the context of IS, provides a compelling explanation for IS security policy violations and offers new insight into how employees rationalize this behavior. In doing so, we propose a theoretical model in which the effects of neutralization techniques are tested alongside those of sanctions described by…

Citation impact

930
total citations
FWCI
89.19
Percentile
100%
References
99
Citations per year

Authors

2

Topics & keywords

Keywords
  • Information security
  • Business
  • Computer security
  • Information system
  • Information systems security
  • Computer science
  • Risk analysis (engineering)
  • Knowledge management
UN Sustainable Development Goals
  • Peace, Justice and strong institutions
No related works found for this paper.