Understanding the deterrence effect of punishment for marine information security policies non-compliance
At a glance
- Citations
- 2
- References
- 35
- Comments
- 0
Öz
In the organizational setting of marine engineering, a significant number of information security incidents have been arised from the employees’ failure to comply with the information security policies (ISPs). This may be treated as a principal-agent problem with moral hazard between the employer and the employee for the practical compliance effort of an employee is not observable without high cost-. On the other hand, according to the deterrence theory, the employer and the employee are inherently self-interested beings.It is worth examining to what extent the employee is self-interested in the marine ISPs compliance context. Moreover, it is important to clarify the proper degree of severity of punishment in terms of the deterrent effect. In this study, a marine ISPs compliance game model has been proposed to evaluate the deterrence effect of punishment on the non-compliance behavior of employee individuals. It is found that in a non-punishment contract, the employee will decline to comply with the marine ISPs; but in a punishment contract, appropriate punishment will lead her to select the marine ISPs compliance effort level expected by the employer, and cause no potential backfire effect.
Publication details
- DOI
- 10.1016/j.joes.2022.06.001
- OpenAlex
- W4281727578
- Document type
- article
- Language
- EN
- Source
- Journal of Ocean Engineering and Science
- Last metadata update
Comments
Oturum Açın to join the discussion.