To read this content please select one of the options below:

Information security policy effectiveness: a managerial perspective of the financial industry in Vietnam

Thai Pham (Faculty of Business, Economics and Law, Auckland University of Technology, Auckland, New Zealand)
Farkhondeh Hassandoust (Department of Information Systems and Operation Management, University of Auckland, Auckland, New Zealand)

Information and Computer Security

ISSN: 2056-4961

Article publication date: 30 April 2024

18

Abstract

Purpose

Information security (InfoSec) policy violations are of great concern to all organisations worldwide, especially in the financial industry. Although the importance of InfoSec policy has been highlighted for many decades, InfoSec breaches still occur due to a low level of employee compliance and a lack of engagement and competence in high-level management. However, previous studies have primarily investigated the behavioural aspects of InfoSec policy compliance at the individual level rather than the managerial factors involved in constructing InfoSec policy and developing its effectiveness. Thus, drawing on neo-institutional theory and a transformational leadership framework, this research investigated the influence of external mechanisms and transformational leadership on InfoSec policy effectiveness.

Design/methodology/approach

The research model was implemented using field survey data from professional managers in the financial sector.

Findings

The results reported that neo-institutional mechanisms and transformational leadership shape InfoSec policy effectiveness in an organisation.

Originality/value

This study broadens current InfoSec policy research from an individual level to a managerial perspective and enhances the existing literature on neo-institutional and transformational leadership in the context of InfoSec. It highlights the need to evaluate InfoSec policy based on external factors and to support transformational leadership styles that promote InfoSec policy enforcement and effectiveness.

Keywords

Citation

Pham, T. and Hassandoust, F. (2024), "Information security policy effectiveness: a managerial perspective of the financial industry in Vietnam", Information and Computer Security, Vol. ahead-of-print No. ahead-of-print. https://doi.org/10.1108/ICS-09-2023-0165

Publisher

:

Emerald Publishing Limited

Copyright © 2024, Emerald Publishing Limited

Related articles