组织内部员工的信息安全保护行为是保障企业信息安全的重要前提。然而,从个体行为视角分析组织内部员工信息安全保护行为的研究较少,且没有系统归纳员工的安全保护行为,这对于企业信息安全策略的实施非常不利。本研究基于整合恐惧诉求后的保护动机理论,通过多案例研究的方法对员工的信息安全保护行为进行研究。研究发现,依据企业信息安全的定义可以将员工的信息安全保护行为归纳为9种不同的类别;员工是否做出安全保护行为的威胁评价过程(包括感知威胁的严重性和感知威胁的易感性)和应对评价过程(包括响应效能和自我效能)都需要通过风险认知产生作用。本研究对于企业信息安全管理制度的完善和实施提供了有益的管理启示。
Organization insiders’ protection behavior on information security is an important prerequisite for enterprise information security. However, few studies have investigated insiders? protection behaviors on information security from the standpoint of individual behavior, and ex-tant literature fails to provide systematic analysis regarding such protection behaviors, which is adverse to the implementation of an enterprise? s information system security policy. This re-search aims to address the above concern based on PMT and FA using a multi-case study. Results indicate that insiders? protection behaviors on information security can be divided into nine cate-gories in accordance with the definition of enterprise information security. In addition, insiders’ protection-motivated behaviors depend on threat appraisal and coping appraisal? and the processes of threat appraisal and coping appraisal make actual sense only by individuals? risk cognition. This study provides beneficial management implications for the improvement and implementation of enterprises? information security management system.