Management Review ›› 2022, Vol. 34 ›› Issue (9): 208-220.

• Organizational Behavior and Human Resource Management • Previous Articles     Next Articles

The Impact of Organizational Control on Information Security Compliance Behavior: The Moderating Effects of Supervisor-Subordinate Guanxi and Organizational Commitment

Liu Chenhui1, Wang Nengmin2,3   

  1. 1. School of Public Policy and Administration, Xi'an Jiaotong University, Xi'an 710049;
    2. School of Management, Xi'an Jiaotong University, Xi'an 710049;
    3. ERC for Process Mining of Manufacturing Services in Shaanxi Province, Xi'an 710049
  • Received:2020-03-09 Online:2022-09-28 Published:2022-10-28

Abstract: With the frequent occurrence of organizational insiders’ misuse of information systems and data breaches, it has been a new challenge for information security management to ensure employees’ information security compliance. Drawing upon compliance theory and social exchange theory, this paper investigates the impact of organizational control on information security compliance behavior from the perspective of supervisor-subordinate guanxi and organizational commitment. We conduct a survey and 310 valid samples are collected, and the PLS method is applied to test the research model. Results indicate that punishment expectancy positively affects information security compliance behavior, whereas the main effect of reward expectancy on compliance behavior is not significant. Supervisor-subordinate guanxi positively moderates the relationship between reward expectancy and compliance behavior, which means that reward expectancy is a stronger determinant of compliance behavior when employees have high-quality guanxi with their supervisors. Organizational commitment not only has a positive effect on compliance behavior, but also plays a negative moderating role in the relationship between reward expectancy and compliance behavior, as well as the relationship between punishment expectancy and compliance behavior. Both reward and punishment expectancy have more positive impacts on low-commitment employees’ compliance behavior than they do for high-commitment employees. In the organizational context of China, this study reveals the working mechanisms of reward and punishment of organizational control in encouraging employees’ information security compliance behavior and provides suggestions for the system design and optimization of information security management.

Key words: supervisor-subordinate guanxi, information security compliance behavior, organizational commitment, reward expectancy, punishment expectancy