JOURNAL OF MANAGEMENT POLICY AND PRACTICE
Policy Awareness, Enforcement and Maintenance: Critical to Information
Security Effectiveness in Organizations
Author(s): Kenneth J. Knapp, Claudia J. Ferrante
Citation: Kenneth J. Knapp, Claudia J. Ferrante, (2012) "Policy Awareness, Enforcement and Maintenance: Critical to Information Security Effectiveness in Organizations," Journal of Management Policy and Practice, Vol. 13, Iss. 5, pp. 66 - 80
Article Type: Research paper
Publisher: North American Business Press
Abstract:
To minimize the probability of costly information security incidents, organizations should be highly
motivated to communicate, enforce and maintain security policies. With insight from the workplace
deviance and organizational learning literature, we investigate a model exploring the impact of policy
awareness, enforcement and maintenance on the effectiveness of information security programs in
organizations. Utilizing a sample of 297 certified information security professionals located in the United
States, we found support for the model as well as a second-order version of a modified structure. Before
concluding, we discuss our results, study limitations and offer implications for research and practice.