Nâng cao thành quả an toàn thông tin: Vai trò của hành vi né tránh nguy cơ và sự sẵn sàng của doanh nghiệp
DOI:
https://doi.org/10.24311/jabes/2025.36.7.04Từ khóa:
Thành quả an toàn thông tin, Sự sẵn sàng đối với an toàn thông tin, Hành vi né tránh nguy cơ, Việt NamTóm tắt
Các nguy cơ đối với an toàn thông tin (Information Security – ISe) ngày càng nhiều và tác động nghiêm trọng đến hoạt động kinh doanh bền vững, nhưng không có nhiều nghiên cứu về thành quả ISe từ góc nhìn quản trị con người. Vì vậy, nghiên cứu này được thực hiện để kiểm tra mô hình nhằm giải thích cách thức thành quả ISe bị ảnh hưởng bởi sự sẵn sàng đối với ISe, hành vi né tránh nguy cơ, và các yếu tố khác. Kết quả phân tích bình phương nhỏ nhất từng phần (Partial Least Squares – PLS) dữ liệu của 320 doanh nghiệp cho thấy sự sẵn sàng đối với ISe là trung gian toàn phần cho tác động của hành vi né tránh nguy cơ đến thành quả ISe. Nghiên cứu cũng xác nhận vai trò quan trọng của động lực né tránh nguy cơ, chương trình giáo dục, huấn luyện, và nâng cao nhận thức về ISe, và ảnh hưởng xã hội đến cả hành vi né tránh nguy cơ và sự sẵn sàng đối với ISe. Các khám phá này đã hỗ trợ nhà quản trị doanh nghiệp, công ty tư vấn về ISe, và các cơ quan nhà nước có thẩm quyền những hiểu biết về chiến lược tăng cường thành quả ISe.
Tài liệu tham khảo
Armstrong, J. S., & Overton, T. S. (1977). Estimating nonresponse bias in mail surveys. Journal of Marketing Research, 14(3), 396-402.
Bandura, A., & Walters, R. H. (1977). Social Learning Theory (Vol. 1). Prentice hall Englewood Cliffs, NJ.
Burns, A., Roberts, T. L., Posey, C., Bennett, R. J., & Courtney, J. F. (2018). Intentions to comply versus intentions to protect: A VIE theory approach to understanding the influence of insiders’ awareness of organizational SETA efforts. Decision Sciences, 49(6), 1187-1228.
Carpenter, D., Young, D. K., Barrett, P., & McLeod, A. J. (2019). Refining technology threat avoidance theory. Communications of the Association for Information Systems, 44.
Chatterjee, S., Sarker, S., & Valacich, J. S. (2015). The behavioral roots of information systems security: Exploring key factors related to unethical IT use. Journal of Management Information Systems, 31(4), 49-87.
Chin, W. W. (1998). The partial least squares approach to structural equation modeling. Modern Methods for Business Research, 295(2), 295-336.
Cisco Systems, I. (2023). Cybersecurity Readiness Index. In: Cisco.
D'Arcy, J., & Devaraj, S. (2012). Employee misuse of information technology resources: Testing a contemporary deterrence model. Decision Sciences, 43(6), 1091-1124.
D'Arcy, J., Hovav, A., & Galletta, D. (2009). User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach. Information Systems Research, 20(1), 79-98.
Davis, F. D., Bagozzi, R. P., & Warshaw, P. R. (1989). User acceptance of computer technology: A comparison of two theoretical models. Management Science, 35(8), 982-1003.
DeLone, W. H., & McLean, E. R. (2003). The DeLone and McLean model of information systems success: A ten-year update. Journal of Management Information Systems, 19(4), 9-30.
Ernest C., S., & Ho, C. B. (2006). Organizational factors to the effectiveness of implementing information security management. Industrial Management & Data Systems, 106(3), 345-361.
Federal Bureau of, I. (2023). Internet Crime Report 2022. Retrieved from https://www.ic3.gov/AnnualReport/Reports/2022_ic3report.pdf?utm_source=chatgpt.com
Fornell, C., & Larcker, D. F. (1981). Structural equation models with unobservable variables and measurement error: Algebra and statistics. Journal of Marketing Research, 18, 382-388.
Hair, J. F., Hult, G. T. M., Ringle, C., & Sarstedt, M. (2017). A Primer on Partial Least Squares Structural Equation Modeling (PLS-SEM) (2 ed.). Sage Publications.
Hair, J. F., Sarstedt, M., Ringle, C. M., & Gudergan, S. P. (2017). Advanced Issues in Partial Least Squares Structural Equation Modeling. Sage Publications.
Hasan, S., Ali, M., Kurnia, S., & Thurasamy, R. (2021). Evaluating the cyber security readiness of organizations and its influence on performance. Journal of Information Security and Applications, 58, 102726.
Henseler, J., Hubona, G., & Ray, P. A. (2016). Using PLS path modeling in new technology research: updated guidelines. Industrial Management & Data Systems, 116(1), 2-20.
Johnston, A. C., & Warkentin, M. (2010). Fear appeals and information security behaviors: An empirical study. MIS Quarterly, 34(3), 549-566.
Khando, K., Gao, S., Islam, S. M., & Salman, A. (2021). Enhancing employees information security awareness in private and public organisations: A systematic literature review. Computers & security, 106, 102267.
Lankton, N. K., Stivason, C., & Gurung, A. (2019). Information protection behaviors: morality and organizational criticality. Information & Computer Security, 27(3), 468-488.
Lebek, B., Uffen, J., Breitner, M. H., Neumann, M., & Hohler, B. (2013). Employees' information security awareness and behavior: A literature review. 2013 46th Hawaii International Conference on System Sciences.
Lee, S. M., Lee, S. G., & Yoo, S. (2004). An integrative model of computer abuse based on social control and general deterrence theories. Information & Management, 41(6), 707-718.
Liang, & Xue. (2009). Avoidance of information technology threats: A theoretical Perspective. MIS Quarterly, 33(1), 71-90.
Lincoln, S. H., & Holmes, E. K. (2011). Ethical decision making: A process influenced by moral intensity. Journal of Healthcare, Science and the Humanities, 1(1), 55-69.
Meltzer, J. P. (2020). Cybersecurity, digital trade, and data flows: Re-thinking a role for international trade rules. https://www.brookings.edu/articles/cybersecurity-digital-trade-and-data-flows-re-thinking-role-for-international-trade-rules/?utm_source=chatgpt.com
Molander, E. A. (1987). A paradigm for design, promulgation and enforcement of ethical codes. Journal of Business Ethics, 6, 619-631.
NCSGroup. (2025). Báo cáo an ninh mạng 2024. Truy cập từ https://ncsgroup.vn/wp-content/uploads/2025/01/NCS-Bao-cao-an-ninh-mang-2024.pdf
Nemati, H. (2007). Information security and ethics: concepts, methodologies, tools, and applications: concepts, methodologies, tools, and applications. IGI global.
Podsakoff, P. M., MacKenzie, S. B., & Podsakoff, N. P. (2012). Sources of method bias in social science research and recommendations on how to control it. Annual Review of Psychology, 63, 539-569.
Puhakainen, P., & Siponen, M. (2010). Improving employees' compliance through information systems security training: An action research study. MIS Quarterly, 34(4), 757-778.
Rashotte, L. (2007). Social Influence. In The Blackwell Encyclopedia of Sociology. https://doi.org/10.1002/9781405165518.wbeoss154
Rezgui, Y., & Marks, A. (2008). Information security awareness in higher education: An exploratory study. Computers & Security, 27(7-8), 241-253.
Rîndașu, S. M. (2017). Emerging information technologies in accounting and related security risks–what is the impact on the Romanian accounting profession. Journal of Accounting and Management Information Systems, 16(4), 581-609.
Rogers, R. W. (1975). A protection motivation theory of fear appeals and attitude change1. The Journal of Psychology, 91(1), 93-114.
Rogers, R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In Social psychology: A Sourcebook, (pp.153-176). Guilford
Rosenberg, R. S. (1998). Beyond the code of ethics: The responsibility of professional societies. Proceedings of the Ethics and Social Impact Component on Shaping Policy in the Information Age, https://doi.org/10.1145/276755.276768
Samtani, S., Zhu, H., & Yu, S. (2019). Fear appeals and information security behaviors: An empirical study on Mechanical Turk. AIS Transactions on Replication Research, 5(1), 5.
Siponen, M., & Willison, R. (2009). Information security management standards: Problems and solutions. Information & Management, 46(5), 267-270. https://doi.org/https://doi.org/10.1016/j.im.2008.12.007
Vance, A., & Siponen, M. T. (2012). IS security policy violations: A rational choice perspective. Journal of Organizational and End User Computing (JOEUC), 24(1), 21-41.
Venkatesh, V., Thong, J. Y., & Xu, X. (2012). Consumer acceptance and use of information technology: Extending the unified theory of acceptance and use of technology. MIS Quarterly, 36(1), 157-178.
Vroom, V. (1964). Work and Motivation. Wiley and Sons, New York.
Weiner, B. J. (2020). A theory of organizational readiness for change. In Handbook on Implementation Science (pp. 215-232). Edward Elgar Publishing.
Whitman, & Mattord. (2022). Principles of Information Security (7 ed.). Cengage Learning, Inc.
Young, D. K., Carpenter, D., & McLeod, A. (2016). Malware avoidance motivations and behaviors: A technology threat avoidance replication. AIS Transactions on Replication Research, 2(1), 8.
Lượt tải xuống
Đã Xuất bản
Số
Chuyên mục
Giấy phép
Bản quyền (c) {copyrightHolder}

Tác phẩm này được cấp phép theo Giấy phép Creative Commons Ghi công-Phi thương mại 4.0 Quốc tế.



