919
Views
6
CrossRef citations to date
0
Altmetric
Articles

Security Policy Opt-in Decisions in Bring-Your-Own-Device (BYOD) – A Persuasion and Cognitive Elaboration Perspective

, , , &
 

ABSTRACT

Bring-Your-Own-Device (BYOD) has gained increased popularity in organizations but may engender information security concerns. To address these concerns, employees are expected to opt-in and comply with organizational BYOD security policy. This study investigates the factors that affect employees’ opt-in decisions with BYOD security policy. Drawing on the theoretical lenses of persuasion and cognitive elaboration, we propose that employees’ cognitive elaborations of BYOD security policy could be affected by the valence of justification of the BYOD security policy, the stringency of BYOD security measures, and the sequence of the introduction of BYOD security policy in relation to employees’ use of personal devices to perform organizational tasks and such cognitive elaborations would in turn affect opt-in decisions. We conducted an experimental survey to test our propositions. The results indicate that positive BYOD security policy justification framing and post-task security policy exposure would lead to more positive cognitive elaboration, decision to opt-in, and compliance with the BYOD security policy. This research has significant implications for security management with respect to the design and implementation of BYOD security policy within an organization according to the nature of security policy and the task requirements.

Acknowledgments

This work was partially supported by grants from the National Natural Science Foundation of China (NSFC) (71572079, 71872086) and the Hong Kong Research Grants Council and City University of Hong Kong (Project No. CityU 11504417/9042571) and (Project No. 7004779).

Notes

1 Enterprises are Embracing BYOD, Despite Security Risks and Support Costs, By: Fred Donovan, May 18, 2014, http://www.fiercemobileit.com/story/enterprises-are-embracing-byod-despite-security-risks-and-support-costs/2014-05-18, retrieved on July 12, 2015.

2 Mobile devices: balancing security and morale, by Clint Merritt, http://www.computerweekly.com/opinion/Security-Zone-Mobile-Devices-Balancing-Security-and-Morale, retrieved on July 12, 2012.

3 Data security and mobile devices: How to make it work, by Bhavin Turakhia, May 2, 2017, https://www.helpnetsecurity.com/2017/05/02/data-security-mobile-devices/, retrieved on May 5, 2017.

4 Juniper Networks released the first mobile network security trust index. Jun 13, 2012, http://www.waybeta.com/news/174127/juniper-networks-released-the-first-mobile-network-security-trust-index./, retrieved on July 12, 2015.

5 Cisco: Enterprises Are Embracing BYOD, By: Jeffrey Burt, May 16, 2012, http://www.eweek.com/c/a/Enterprise-Networking/Cisco-Enterprises-are-Embracing-BYOD-252679/, retrieved on July 12, 2015.

6 MDM: Part of the mobile security solution? By George V. Hulme, March 19, 2012, http://www.csoonline.com/article/702418/mdm-part-of-the-mobile-security-solution-, retrieved on July 12, 2015.

Additional information

Funding

This work was supported by the National Natural Science Foundation of China [71572079; 71872086], Hong Kong Research Grants Council and City University of Hong Kong [CityU 11504417/9042571 and 7004779].

Notes on contributors

Xue Yang

Xue Yang is an Associate Professor in the Department of Marketing and Electronic Business, School of Business (Management), Nanjing University (NJU), China. She received her Ph.D. on Information Systems from National University of Singapore (NUS). Her current research interests include e-commerce and m-commerce, free trial software, spontaneous virtual team, and IT usage. Professor Yang’s research work has appeared in journals such as Decision Support Systems, Journal of the Association for Information Systems, Information & Management, IEEE Transaction on Engineering Management, Business Horizons, among others, as well as various conferences. She has been a member of Association of Information Systems (AIS) since 2004. Dr. Yang is currently Associate Editor for Information & Management, Electronic Commerce Research, Journal of Global Information Management, Asia Pacific Journal of Information Systems, and Nanjing University Business Review (Chinese). She has served as the Program Committee member, Track Chair, Associate Editor, or other positions for multiple international conferences such as ICIS, PACIS, CSWIM. She has been supported by the Youth Program and General Program of National Natural Science Foundation of China (NSFC).

Xinwei Wang

Xinwei Wang is a Lecturer in the Department of Information Systems and Operations Management at University of Auckland. She received her Ph.D. on Information Systems, National University of Singapore. Her research interest includes human cognition and behavior in complex digital environments, management of IT professionals, and individual and organizational adoption of innovative IT and IS. Dr. Wang’s studies have been published in journals such as Journal of the American Society for Information Science and Technology, Information & Management, Journal of Global Information Management, and proceedings of the International Conference on Information Systems, Academy of Management Meeting, European Conference on Information Systems, Americas Conference on Information Systems, and Hawaii International Conference on System Sciences.

Wei Thoo Yue

Wei Thoo Yue is an Associate Professor of Management Information Systems in the Department of Information Systems at the City University of Hong Kong. Dr. Yue received his Ph.D. in Management Information Systems from Purdue University. Prior to joining City University of Hong Kong, he was a faculty member at University of Texas, Dallas. His research interests focus on the economic and operational aspects of information security and information systems. Profesor Yue’s work has appeared in Management Science, Information Systems Research, Journal of Management Information Systems, Decision Support Systems, and other journals.

Choon Ling Sia

Choon Ling Sia is Professor at the City University of Hong Kong and AIS Fellow (2015). He received his Ph.D. degree from the National University of Singapore. He is Director of Center of Social Media Marketing and Business Intelligence at the City University of Hong Kong. He is serving, or has served, on the editorial boards of MIS Quarterly, Information Systems Research, Journal of the AIS, IEEE Transactions on Engineering Management, Journal of Global Information Management, Information and Management, and Journal of Database Management. Professor Sia’sresearch interests include electronic commerce, social media, cross-cultural issues in information systems, knowledge management, distributed work arrangements, and computer-mediated communication. His research work has been published in MIS Quarterly, Information Systems Research, Decision Support Systems, Journal of Management Information Systems, Information and Management, International Journal of Electronic Commerce, Journal of the American Society for Information Science and Technology, Communications of the ACM, IEEE Transactions on Engineering Management, IEEE Transactions on Systems, Man, and Cybernetics, Journal of International Business Studies, ACM Transactions on Computer-Human Interaction, International Journal of Human-Computer Studies, Internet Research, Information and Software Technology, and International Journal of Information Management, among others.

Xin (Robert) Luo

Xin (Robert) Luo is an Endowed Regent’s Professor and Full Professor of MIS and Information Assurance in the Anderson School of Management of the University of New Mexico. He is Director of International Programs for the Anderson School. He received his PhD in MIS from Mississippi State University. Professor Luo has published research papers in leading journals, including Decision Sciences, Decision Support Systems, European Journal of Information Systems, Journal of the AIS, Journal of Strategic Information Systems, Information & Management, and Information Systems Journal. He serves as an ad hoc associate editor for MIS Quarterly and an associate editor for Decision Sciences, European Journal of Information Systems, Electronic Commerce Research, and Journal of Electronic Commerce Research. He sits on the editorial board of the Journal of AIS. His research interests center around information assurance, innovative technologies for strategic decision-making, and global IT management. He is the coeditor-in-chief for International Journal of Accounting and Information Management.

Reprints and Corporate Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

To request a reprint or corporate permissions for this article, please click on the relevant link below:

Academic Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

Obtain permissions instantly via Rightslink by clicking on the button below:

If you are unable to obtain permissions via Rightslink, please complete and submit this Permissions form. For more information, please visit our Permissions help page.