Supports
Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations
Mikko Siponen, Anthony Vance · MIS Quarterly, 34(3), 487-502, 2010
Key finding
Employees' rationalizations for rule-breaking ('neutralization' techniques from criminology) explained intentions to violate security policy better than deterrence theory's sanctions. The authors argue policies should address these rationalizations.
Why it matters for PsySec
Suggests that threatening punishment does less than engaging with the reasons people give themselves for bending rules.
Stance: Supports. Evidence consistent with a PsySec claim. Summaries are written by the database editors; read the original for full results and limitations.
Tags
P2. Culture eats compliance for breakfastP6. Brains are not computers
BeliefBehavior
ComplianceInsider behaviorBlame and fearDecision making
Behaviors this study informs
Cite this study
APA
Siponen, M., & Vance, A. (2010). Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations. MIS Quarterly, 34(3), 487-502. https://doi.org/10.2307/25750688
BibTeX
@article{siponen_2010_neutralization,
title = {Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations},
author = {Mikko Siponen and Anthony Vance},
year = {2010},
journal = {MIS Quarterly, 34(3), 487-502},
doi = {10.2307/25750688},
url = {https://doi.org/10.2307/25750688}
}