지속적인 정보보호 거버넌스를 위해서는 단순히 접근통제, 문서보안 등 기술적인 측면이 아닌 개인의 보안 행위, 문화, 규범, 개인적 가치 등 비공식적인 정보보호 행위를 관리하는데 초점...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T13142953
서울 : 서울대학교 대학원, 2013
2013
한국어
658
서울
124 p. ; 26cm
지도교수:안중호
0
상세조회0
다운로드지속적인 정보보호 거버넌스를 위해서는 단순히 접근통제, 문서보안 등 기술적인 측면이 아닌 개인의 보안 행위, 문화, 규범, 개인적 가치 등 비공식적인 정보보호 행위를 관리하는데 초점...
지속적인 정보보호 거버넌스를 위해서는 단순히 접근통제, 문서보안 등 기술적인 측면이 아닌 개인의 보안 행위, 문화, 규범, 개인적 가치 등 비공식적인 정보보호 행위를 관리하는데 초점을 맞추어야 한다. 그러나 많은 연구들이 정보보호 규정과 같은 공식적인 수준의 거버넌스나 기술과 같은 수단에 집중하고 있는 실정이며, 개인의 정보보호 위반 행위와 개인적 신념, 규범, 문화, 개인적 가치 등 비공식적인 수준에 대한 연구는 거의 이루어지지 않고 있다. 이에 본 연구는 정보보호 문화, 규범적 신념, 행위, 가치가 정보보호 규정 위반 행위에 어떠한 영향을 미치는 지에 대해 실증분석을 수행하고자 하였다. 또한 본 연구에서는 사회조직적 관점의 아노미 개념을 이용하여 조직 내에서 정보보호 규정의 중요성에 대한 인식 결핍과 정보보호 규정의 가치 결여를 ‘정보보호 아노미 현상’으로 정의하고, 이를 바탕으로 정보보호 문화, 규범, 행위, 가치가 정보보호 규정 위반 행위에 미치는 영향에 있어 정보보호 아노미 현상이 어떠한 역할을 하는지에 대해 실증분석을 수행하고자 하였다. 이를 위해 선행 문헌에 대한 고찰을 통해 개인의 정보 보호 규정 위반 행위에 영향을 미치는 요소들과 정보보호 아노미 현상의 역할에 대한 가설들을 다음과 같이 도출하였다.
H1(-): 정보보호 문화에 대한 인식 수준은 조직원의 정보보호 아노미에 대한 인식 수준에 부정적인 영향을 미칠 것이다.
H2(-): 정보보호 규범적 신념에 대한 인식 수준은 조직원의 정보보호 아노미에 대한 인식 수준에 부정적인 영향을 미칠 것이다.
H3(-): 타인의 정보보호 행위에 대한 인식 수준은 조직원의 정보보호 아노미에 대한 인식 수준에 부정적인 영향을 미칠 것이다.
H4(-): 정보보호의 개인적 가치에 대한 인식 수준은 조직원의 정보보호 아노미에 대한 인식 수준에 부정적인 영향을 미칠 것이다.
H5(+): 정보보호 아노미에 대한 인식 수준은 조직원의 정보보호 규정 위반 행위에 긍정적인 영향을 미칠 것이다.
각 가설의 변수들에 대한 구조모형을 구성하였으며 이를 분석하기 위해 SmartPLS2.0을 이용하였다. 구조모형에 대한 적합성은 GoF(Goodness of Fit)인덱스를 통하여 검증하였으며, 그 결과 본 연구 모형은 구조적으로 적합한 것으로 분석되었다. 이러한 과정을 통해 얻은 주요한 결과를 정리하면 다음과 같다.
첫째, 가설 1, 4, 5는 통계적으로 유의한 것으로 분석되어 채택되었으며, ‘타인의 정보보호 행위에 대한 인식 수준은 조직원의 정보보호 아노미에 대한 인식 수준에 부정적인 영향을 미칠 것이다.’라는 가설4는 기각되었다. 또한 ‘정보보호 규범적 신념에 대한 인식 수준은 조직원의 정보보호 아노미에 대한 인식 수준에 부정적인 영향을 미칠 것이다.’라는 가설2는 수립된 가설의 방향성과 반대의 결과인 ‘+’로 나타나 기각되었다.
둘째, 정보보호 아노미의 인식 수준에 대한 매개효과를 검증하기 위해, 정보보호 아노미의 인식수준이 포함된 완전 모델과 정보보호 아노미의 인식수준이 제거된 감소모델의 Effect Size(f2)를 비교한 결과, 정보보호 아노미의 인식수준이 포함된 완전모델의 설명력이 더 높은 것으로 나타났고, 매개효과의 Effect Size는 판단기준의 중간효과 정도로 나타났다. 이는 정보보호 아노미의 인식수준이 포함된 본 연구의 모형이 포함되지 않은 모형보다 조금 더 구조적인 설명력을 지니는 것으로 해석할 수 있다.
셋째, 정보보호 아노미 인식 수준에 대한 매개효과를 좀더 구체적으로 알아보기 위해 채택된 가설을 중심으로 정보보호 규정 위반 행위에 대한 정보보호 아노미의 매개경로에 대해 분석한 결과, 정보보호 아노미 현상은 조직원의 정보보호 문화에 대한 인식 수준과 정보보호의 개인적 가치에 대한 인식 수준이 정보보호 규정 위반 행위에 미치는 영향에 있어서 매개효과가 있는 것으로 나타났다.
넷째, 성별, 연령, 업종, 근속년수, 직급의 특성에 따라 정보보호 규정 위반 행위에 차이가 있는지를 ANOVA를 통해 분석하였으며, 그 결과 성별은 p<0.05수준에서 정보보호 규정 위반 행위에 있어 집단간 차이가 있는 것으로 나타났으며, 근속년수는 p<0.10수준에서 유의한 차이가 있는 것으로 분석되었다.
마지막으로 통계적으로 유의한 값으로 나타났으나 가설의 방향성이 반대로 나타나 기각되었던 가설 2에 대한 원인을 파악하기 위해, 인구통계학적 변수들과 정보보호의 규범적 신념에 대한 인식 수준과의 상호작용에 대한 추가 분석을 실시하였으며, 금융사 직원들을 대상으로 심층 인터뷰를 수행하였다. 그 결과 연령, 직급과 정보보호의 규범적 신념에 대한 인식 수준은 상호작용효과가 나타나는 것으로 분석되었다. 즉, 연령과 직급이 높아질수록 정보보호의 규범적 신념에 대한 수준이 높게 나타나며 이는 결국 정보보호 아노미에 대한 인식 수준을 더 높이는 효과가 있는 것으로 해석할 수 있다. 또한 심층 인터뷰 결과, 조직에서 가장 기본적인 내부통제 즉 Check & Balance 기능이 제대로 운영되지 않는 원인으로 응답자의 70%가 직원 상호 간 견제와 불신에 익숙하지 않은 조직의 문화라고 답변하였다. 이러한 인식이 본 연구의 설문 조사에도 반영되어 정보보호의 규범적 신념에 대한 수준이 너무나 당연시되어 높게 나타나며, 이로 인해 정보보호 아노미에 대한 인식 수준도 높아지는 것으로 해석할 수 있다.
목차 (Table of Contents)
참고문헌 (Reference)
1. PLS Path Modeling, V.V.Esposito, C.Lauro, Tenenhaus, PLSpath modeling, , 2005
2. Causes of delinquency, Hirschi, Travis, University of California Press, , 1969
3. A theory of conformity, Bernheim, , 1994
4. From polices to culture, Solms, , 2004
5. 2010 국가정보화백서, 한국정보화진흥원, , 2010
6. 가치 중심의 리더십, Kuczmarski, Susan Smith, 학지사, , 1999
7. 2008 정보보호실태조사, 한국정보보호진흥원, , 2008
8. Institution. SmartPLS 2.0 Beta, Ringle,
9. Why incentive plans cannotwork, Kohn, Why incentive plans cannot work, , 1993
10. Incentives, rationality, society, Brennan, "Incentives, , 1994
1. PLS Path Modeling, V.V.Esposito, C.Lauro, Tenenhaus, PLSpath modeling, , 2005
2. Causes of delinquency, Hirschi, Travis, University of California Press, , 1969
3. A theory of conformity, Bernheim, , 1994
4. From polices to culture, Solms, , 2004
5. 2010 국가정보화백서, 한국정보화진흥원, , 2010
6. 가치 중심의 리더십, Kuczmarski, Susan Smith, 학지사, , 1999
7. 2008 정보보호실태조사, 한국정보보호진흥원, , 2008
8. Institution. SmartPLS 2.0 Beta, Ringle,
9. Why incentive plans cannotwork, Kohn, Why incentive plans cannot work, , 1993
10. Incentives, rationality, society, Brennan, "Incentives, , 1994
11. Intrinsic and extrinsic motivation, Staw, , 1975
12. Re-engineering enterprise security, Booker, , 2006
13. The human face of information loss, Bottom, , 2000
14. An economic modelof moral motivation, Brekke, , 2003
15. Why haven’t we mastered alignment?, Chen, , 2002
16. Information security manager-M&T Bank, Gupta, , 2005
17. Measuring and assessing organizations, Van de Ven, Andrew H, Wiley, Measuring and assessingorganizations, , 1980
18. Agency Theory:An Assessment and Review, Eisenhardt,K.M., Agency theory: An assessment and review, , 1989
19. Analysis of end user security behaviors, Stanto, , 2005
20. Effective IS security: An empirical study, Straub, , 1990
21. Toward a stewardship theory of management, Davis, Donaldson, Schoorman, , 1997
22. 2005 E-Crime watch survey summaryof findings, Center, , 2005
23. Crime, punishment, and the market for offenses, Ehrlich, "Crime, , 1996
24. Illegitimate means anomie, and deviantbehavior, Cloward, "Illegitimate means anomie, , 1959
25. A socio-economic theory of regulatorycompliance, Sutinen, , 1999
26. Control: Organizational and Economic Approaches, Ouchi, Control: Organizational and economicapproaches, , 1985
27. On the Evaluation of Structural Equation Models, Bagozzi, On the evaluation of structural equationmodels, , 1988
28. Issues and opinion on structure equationmodeling, Chin, , 1998
29. Enemy at the gate: threats to informationsecurity, Whitman, , 2003
30. The Hadley circulation of the Earth’satmosphere, Schneider, , 1975
31. The agent’s ethics in the principal-agent model, Bohren, , 1998
32. Towards information securitybehavioral compliance, Vroom, , 2004
33. Factors in Successful Occupational Safety Programs, Cohen, Factors in successful occupational safety programs, , 1977
34. Sociological paradigms and organizational analysis, Burrell, Morgan, Sociological Paradigms andOrganizational Analysis, , 1979
35. Taxonomy of compliant information securitybehavior, Padayachee, , 2012
36. The need for a new approach to informationsecurity, Hitchings, , 1994
37. 정보보호 거버넌스 이슈 및 연구 과제, 김정덕(Kim Jungduk), 홍기향(Hong Kihyang), 한국정보보호학회, "정보보호학회지, , 2007
38. Intrinsic motivation and optimal incentivecontracts, Murdock, , 2002
39. Managerial behavior, performance, and effectiveness, Campbell, John Paul, McGraw-Hill, , 1970
40. The interaction between norms and economicincentives, Kreps, , 1997
41. 허태열 “금융사고 84% 내부직원 소행”, 매일경제, , 2010
42. Coefficient alpha and the internal structure of tests, Cronbah, Coefficient Alpha and the Internal Structure ofTests, , 1951
43. Security-related behavior ofPC users in organizations, Frank, , 1991
44. Influence ofexperience on personal computer utilization, Thompson, , 1994
45. Key information issues facingmanagers: Software privacy, Straub, , 1990
46. Framing the frameworks: A reviewof IT governance research, Brown, , 2005
47. Principles of information systems security: Textand Cases, Dhillon, , 2007
48. Discovering and discipliningcomputer abuse in organization, Straub Jr, , 1990
49. Employees’ behaviortowards is security policy compliance, Pahnila, Pahnila, S., , 2007
50. IS Security Policy Violation: ARational Choice Perspective, Vance, , 2012
51. 새마을금고 잦은 금융사고 ‘어물전고양이?, 매일신문, , 2010
52. Software Piracy in the Workplace: A Model and Empirical Test, Peach, , 2003
53. Specifying Formative Constructs in Information Systems Research, Rai, Petter, Straub, Specifying formative constructsin information systems research, , 2007
54. Statistical power analysis for the behavioral sciences (2nd ed.), Cohen,J, Statistical power analysis for the behavioralsciences (2nd ed.), , 1988
55. Anintegrative study of information systems security effectiveness, Kankanhalli, Kankanhalli, A., A. Kankanhalli, , 2003
56. ISO 17799:’Best Practices’ ininformation security management?, Ma, , 2005
57. The influence of regulations oninnovation in information security, Khansa, , 2007
58. Issues Trends 2004: CSI/FBIComputer Abuse and Security Survey, CSI, Computer Security Institute, "Issues Trends 2004: CSI/FBIComputer Abuse and Security Survey, , 2004
59. Thinking about social theory and philosophy forinformation systems, Lee, , 2004
60. Deviant behavior and social structure: Continuitiesin social theory, Durbin, , 1959
61. Conventional wisdom on measurement: Astructural equation perspective, Bollen, Lennox, Conventional wisdom on measurement:A structural equation perspective, , 1991
62. Fighting computer crime : a new framework for protecting information, Parker, Donn B, John Wiley & Sons, , 1998
63. Information securityculture ? Validation of an assessment instrument, Veiga, , 2007
64. Common methods bias: Doescommon methods variance really bias results?, Doty, , 1998
65. Value-focused assessment ofinformation system security in organizations, Dhillon, , 2006
66. Information security governancearrangements: The devil is in the details, Rao, , 2007
67. 은행권 ‘툭하면’ 금융사고…내부통제시스템 ‘엉망, 조세일보, , 2010
68. Challenges and Strategies for Research in Information Systems Development, Senn, Cotterman, Challenges and strategies forresearch in information systems development, , 1992
69. Information systems securitygovernance research: A behavioral perspective, Mishra, , 2007
70. Privacy and monitoring in theworkplace: A debate on technology and ethics, Loch, , 1998
71. Corporate criminal law and organizationincentives: A managerial perspective, Garoupa, , 2000
72. The insider threat to information systems and the effectiveness of ISO17799, Theoharidou, S.Kokolakis, , 2005
73. Universitysystems security logging: who is doing it and how far can theygo?, Rezmierski, , 2002
74. Assessing IT securityculture: System administrator and end-user perspectives, Finch, , 2003
75. The development of access controlpolicies for information technology systems, Ward, , 2002
76. Structural equation modeling and regression: Guidelines for research practice, Straub, Gefen, Boudreau, Structural EquationModeling and Regression: Guidelines for Research Practice, , 2000
77. Crime by computer: correlates of softwarepiracy and unauthorized account access, Hollinger, , 1993
78. Examiningthe linkage between organizational commitment and information.security, Stanton, , 2003
79. Coping with systems risk: securityplanning models for management decition making, Straub D., , 1998
80. Applied MultipleRegression/Correlation Analysis for the Behavioral Science(3rded), Cohen, , 2002
81. Information securitymanagement objectives and practices: A parsimonious framework, Ma, , 2008
82. A practicalguideto factorialvalidity using PLS-GRAPH:Tutorial and annotated example, Gefen, A practical guide to factorial validityusing PLS-graph: Tutorial and annotated example, , 2005
83. Current directions in IS securityresearch: Towards socio-organizational perspectives, G. Dhillon, Dhillon, Dhillon, G., , 2001
84. Organizational Climate: It ' sMeasurement and Relat ionship to Work Group Performance, Beaty, Campbell, Organizational Climate: ItsMeasurement and Relationship to Work Group Performance, , 1971
85. Deterrence in the workplace:Perceived certainty perceived severity, and employee theft, Hollinger, "Deterrence in the workplace:Perceived certainty perceived severity, , 1983
86. Evaluating structural equation models with unobservable variables and measurement error, Fomell C. and Larcker D.F, Evaluating structural equationmodels with unobservable variables and measurement error, , 1981
87. MeasuringPerceptions of workplace safety: Development and validation ofwork safety scale, Trask, Hayes, , 1998
88. A preliminary model of end usersophistication for insider threat prediction in IT systems, Magklaras, , 2005
89. Real-time information integrity =system integrity + data integrity + continuous assurances, Flowerday, , 2005
90. 성공적인 정보보호 거버넌스 구현을 위한 핵심성공요인에 관한 연구, 김건우, 김정덕, 한국경영정보학회, 정보보호학회 추계학술대회, , 2009
91. Augmenting the theory of plannedbehavior: Roles for anticipated regret and descriptive norms, Sheeran, , 1999
92. Evaluating information securitytradeoffs: Restructuring access can interfere with user tasks, Post, , 2007
93. An integrative model of computer abuse based onsocial control and general deterrence theories, Lee, , 2004
94. Motivation and barriers to participation in virtual knowledge-sharing communities of practice, Ardichvilli, Wentling, , 2003
95. It is what one does: Why peopleparticipate and help others in electronic communities ofPractices, Wasko, , 2000
96. Rewards and punishments as selective incentivesfor collective action: Theoretical investigations, Oliver, , 1980
97. Information security management: Aninformation security retrieval and awareness model for industry, Kritzinger.E., , 2008
98. Violation of safeguards by trusted personnel andunderstanding related information security concerns, Dhillon, , 2001
99. Commonmethod biases in behavioral research: A critical review of the literature andrecommended remedies, Podsakoff, , 2003
100. Understanding and mitigatinguncertainty in on-line exchange relationships: A principal-agentperspective, Pavlou, , 2007
101. A Focus Theory of Normative Conduct: Recycling the Concept of Norms to Reduce Littering in Public Places, C.A.Kallgren, Cialdini, R.R.Reno, A focus theory ofnormative conduct: Recycling the concept of norms to reducelittering in public places, , 1990
102. An Empirical assessment of the effects ofaffective response in the measurement of organizational climate, Schnake, , 1983
103. Deficiencies of the traditional approach toinformation security and the requirements for a newmethodology, Hitchings, , 1995
104. Leadership and the Psychologyof Awareness : Three Theoretical Approaches to InformationSecurity Management, Holmberg, , 2012
105. Social conformity deviation, and opportunitystructure: A comment on the contributions of Durbin andCloward, Merton.R.K, "Social conformity deviation, , 1959
106. User behavior towardpreventive technologies cultural differences between the United.States and South Korea, Dinev, , 2006
107. Perceptions of Safety at Work:Developing a Model to Link Organizational Safety Climate andIndividual Behavior, Neal, , 1997
108. Perceptions of informationsecurity at the workplace: Linking information security climateto Compliant Behavior, Chan, , 2005
109. Creating conscientious cybercitizen: Anexamination of home computer user attitudes and intentionstowards security, Anderson.C, , 2005
110. Informationtechnology adoption across time: A cross-sectional comparisonof pro-adoption and post-adoption beliefs, Karahanna, , 1999
111. Encouraging information securitybehaviors in organizations: Role of penalties pressures andperceived effectiveness, Herath, , 2009
112. The Moderator-mediator Variable Distinction in Social Psychological Research: Conceptual, Strategic and Statistical Considerations, David A.Kenny, Reuben M.Baron, "The moderator-mediator variabledistinction in social psychological research; Conceptual, , 1986
113. Toward an integrationof an agent and activity centric approaches in organizationalprocess modeling: Incorporating incentive mechanisms, Raghu, , 2004
114. Understanding Information Systems Security PolicyCompliance: An Integration of the Theory of Planned Behavior and theProtection Motivation Theory, Ifinedo, Understanding information systems security policycompliance: An integration of the theory of planned behavior andthe protection motivation theory, , 2012