作者(英文):Wen-Wei Chao
論文名稱:組織成員資訊安全行為意圖影響因素之研究 - 以法院為例
論文名稱(英文):A Study on the Influencing Factors of Employee's Information Security Behavior Intention - Taking the Court as an Example
指導教授(英文):Hsi-Jui Wu
口試委員(英文):Cheng-I Chu
Dauw-Song Zhu
關鍵詞(英文):Degree of Information Security ControlTheory of Planned BehaviorOrganizational ClimateInformation Security Behavior Intention
The development of information technology has changed the habits and attitudes of people using data. While people own and enjoy the convenience and advantage of information technology, but also getting the problem of information security issue, such as computer virus risk. Therefore, the strengthening of information security management within the organization is the basic guarantee of information security.

Within the organization, people are the important asset and also are the key factor of information security. If the members of organization were unable to understand or comply with the information security behavior, then organization member will be the major threat and vulnerability for the defense of information security. Therefore, this research takes the degree of information security control and the theory of planned behavior to explain the theoretical basis of “organization member compliance with the information security behavior intention”, meanwhile, by way of the organizational climate to investigate the influence between “the theory of planned behavior” and “the intention of compliance with information security for organization member”. Therefore, the purpose of this study is to explore the information security behavior intention through the empirical method, hoping to help the government agencies in the Information security policy promotion and information security management operation.

The employees of domestic Section Court as the object of research, from “Degree of Information Security Control” and “Theory of Planned Behavior” to find out the behavior intention which will influence the compliance of information security of user. As the investigation result showed: there is positive relationship for “Degree of Information Security Control” and “Attitude”, ”Subjective Norm” and “Perceived Behavioral Control”. Meanwhile, “Attitude”, “Subjective Norm” and “Perceived Behavior Control” above 3 items are positive relationship with information security behavior intention as well. Secondary, according to the investigation result of the organizational climate regulation, it’s also showed the significant and non-significant effects for “Employee-Oriented Leadership”, “Human Communication”, “Procedure Norm” and “Responsibility Trend" 4 facets of responsibility ethos: “Attitude”, “Subjective Norm” and “Perceived Behavior Control” and “Information Security Behavior Intention”. Therefore, besides the contributing of practical aspects of information security management for government agency, the effect of organization member for information security behavior intention could be understood as well to avoid the hazards which caused by information security events.
第一章 緒論
第一節 研究背景與動機…………………………………………………………1
第二節 研究目的與研究問題……………………………………………………4
第三節 研究流程…………………………………………………………………5
第二章 文獻探討
第一節 資訊安全…………………………………………………………………7
第二節 行為理論模式……..……………………………………………………22
第三節 組織氣候..………………………………………………………………27
第三章 研究方法
第一節 研究對象..………………………………………………………………37
第二節 研究架構..………………………………………………………………39
第三節 研究假設..………………………………………………………………40
第四節 研究變項與操作性定義..………………………………………………44
第五節 測量模式之效度與信度..………………………………………………48
第六節 資料分析方法與工具..…………………………………………………50
第四章 研究結果與分析
第一節 樣本基本資料分析..……………………………………………………53
第二節 信度與效度分析..………………………………………………………61
第三節 整體模式模型檢測..……………………………………………………69
第四節 研究架構調節分析……..………………………………………………74
第五節 研究結果..………………………………………………………………81
第五章 結論與建議
第一節 研究結論..………………………………………………………………87
第二節 研究貢獻與管理意涵..…………………………………………………89
第三節 研究限制..………………………………………………………………93
第四節 研究建議.……………………………………………………………….95
王秋慶(2002)。員工的溝通滿足與組織氣候對其工作壓力、組織承諾與離職傾向的影響之研究 - 以嘉義縣市地政事務所為例。國立南華大學管理研究所碩士論文,未出版,嘉義縣。
李東峰(2003)。企業資訊安全控管決策之研究 - 從組織決策理論觀點探討。國立中央大學資訊管理學系,未出版,桃園縣。
林玫玫(1996)。領導風格對組織承諾之影響 - 以組織氣候及內外控為中介變項。國立中正大學企業管理研究所碩士論文,未出版,嘉義縣。
林營松(1993)。組織承諾及其影響因素對組織後果之研究 - 以楠梓加工出口區員工為例。國立中山大學企業管理研究所碩士論文,未出版,高雄市。
邱台生(2002)。組織氣候與工作投入關係之研究 - 以某醫學中心暨委託經營管理醫院為例。台北醫學院護理學研究所碩士論文,未出版,台北市。
張國銘(2004)。薪酬制度、組織氣候對工作績效影響之研究 - 以傳統紡織企業為例。國立中山大學人力資源管理研究所碩士論文,未出版,高雄市。
張瑞春(1998)。組織變革中組織氣候對工作投入、組織承諾及工作滿足影響之研究 - 以中國石油公司高雄營業處為例。國立中山大學人力資源管理研究所碩士論文,未出版,高雄市。

郭和杰(2012)。美國網路詐騙投訴案例連續三年超過30 萬件。取自:
陳靜怡(2002)。組織氣候認知、員工自我導向學習與工作投入之關係研究 - 以某國際快遞公司為例。國立中山大學人力資源管理研究所碩士論文,未出版,高雄市。
資安人科技網編輯部(2012)。駭客入侵各國銀行帳戶至少已竊取7,500萬美元。資安人科技網。取自:https://www.informationsecurity.com.tw/ article/
劉榮欽(2004)。領導行為、組織氣候及工作投入關係之研究 - 以某地區軍醫院為例。國立中山大學人力資源管理研究所碩士論文,未出版,高雄市。
欒志宏(2002)。How to develop InformationSecurity Policy講義。

Allen, B. (1968). Danger Ahead! Safeguard Your Computer. Harvard Business Review 46(6), 97-101.
Al-Shammari, M. M. (1992). Organization climate. Leadership and Organizational Development Journal, 13(6), 30-32.
Ajzen, I. (1985). From intention to actions: A theory of planned behavior. In J. Kuhl & J. Beckman (Eds.), Action control: From cognition to behavior. Berlin; New York: Springer-Verlag. 11-39.
Ajzen, I. (1989). Attitude structure and behavior. In A. R. Pratkanis, S. J. Breckler, & A. G. Greenwald (Eds.), Attitude structure and function . Hillsdale, N.J.: L. Erlbaum Associates. 241-274.
BS 7799-1 (2000). Information Security Management - Part 1: Code of Practice for Information Security Management. British Standards Institution, London.
BS 7799-2 (2002). Information Security Management - Part 2: Specification for Information Security Management. British Standards Institution, London.
Carter, D. L. and A. J. Katz (1996). Computer Crime and Security: the Perceptions and Experiences of Corporate Security Directors. Security Journal, 7, 101-108.
Chadha, N. K. (1989). School organizational climate and teacher job satisfaction, Social ScienceInternational. 5(1), 1-20.
Chapman, D.B. and E.D. Zwichy (1995). Building Internet Firewall. California, CA:O’reilly & Associates.
Churchill, J. G. A., Ford, N. M., & Walker, J. O. C. (1976). The psychological consequences of role conflict and ambiguity in the industrial sales force In K.L. Bernhardt (Ed.), Marketing (pp.1776-1976). Chicago: American Marketing Association.
Davidson, M. C. G. (2003). Does organizational climate add to service quality in hotels? International Journal of Contemporary Hospitality Management. 15(4/5): 206-214.
Davis, F. D., Bagozzi, R. P., & Warshaw, P. R. (1989). User acceptance of computer technology: A comparison of two theoretical models. Management Science, 35(8), 982-1003.
Dessler, G. (1976). Organizational and Management: A contingency approach. Englewood Geiffs, N.Y., Prentice-Hall, 63-69.
Fishbein, M., & Ajzen, I. (1975). Belief, attitude, intentions and behavior: an introduction to theory and research. Boston: Addison-Wesley.
Flynn, N. L. (2001). The E-Policy Handbook: Designing and Implementing Effective E-Mail, Internet, and Software Policies. American Management Association, New York.
Ford, R. C., and Richardson, W. D. (1994). Ethical Decision Making: A Review of the Empirical Literature. Journal of business ethics (13:3), 205-221.
Fornell, C., and Larcker, D. F. (1981). Evaluating structural equation models withunobservable variables andmeasurement error. Journal of Marketing Research, 18(1), 39-50.
Fung, A. R. W., K. J. Farn, and A. C. Lin (2003). Paper: a study on the certification of the information security management systems. Computer Standards and Interfaces, 25, 447-461.
Gaunt, N. (1998). Installing an Appropriate Information Security Policy. International Journal of Medical Informatics (49:1), 131-134.
Glendon, A. I., and Litherland, D. K. (2001). Safety Climate Factors, Group Differences and Safety Behavior in Road Construction. Safety Science (39:3), 157-188.
Glendon, A. I., and Stanton, N. A. (2000). Perspectives on Safety Culture. Safety Science (34:13), 193-214.
Gupta, Y. P. (1991). The Chief Executive Officer and the Chief Information Officer: The Strategic Partnership. Journal of Information Technology (6:3-4), 128-139.
Hair, J. F., Jr., Anderson, R. E., Thatam, R. L,. and Black, W. C. (1998). Multivariate Data Analysis, 5th ed. Prentice-Hall International, Inc.
Hair, J. F. Jr., Black, W. C., Babin, B. J. and Anderson, R. E. (2010). Multivariate Data Analysis (7th Ed.). Prentice-Hall, Upper Saddle River, NJ.
Halpin, A. W., & Croft, D. B. (1973). The organizational climate of school. Washington D.C.: U.S. Office of Education.
Harrington, S. J. (1996). The Effects of Codes of Ethics and Personal Denials ofResponsibility on Computer Abuse Judgments and Intentions. MIS Quarterly, 20(3), 257-278.
Hoffer, J. A., & Straub, D.W.Jr. (1989). The 9 to 5 Underground: Are You Policing Computer Crimes?. Sloan Management Review, 35-43.
Höne, K., and Eloff, J. H. P. (2002). Information Security Policy - What Do International Information Security Standards Say?. Computers & Security (21:5), 402-409.
Höne, K. & Eloff, J.H.P. (2002a). Information Security Policy - What do International Information Security Standards Say? . Computers & Security (21:5), 402-409.
Hong, K. S., Y. P. Chi, L. R. Chao, and J. H. Tang (2003). An integrated system theory of information security management. Information Management and Computer Security, 11(5), 243-248.
Hong, K.S., Chi, Y.P., Chao, L.R., and Tang, J.H. (2006). An Empirical Study of Information Security Policy on Information Security Elevation in Taiwan. Information Management& Computer Security (14:2), 104-115.
Horrocks, I. (2001). Security Training: Education for an Emerging Profession? Computers &Security (20:3), 219-226.
Hu, L. T. and Bentler, P. M. (1999). Cutoff criteria for fit indexes in covariance structure analysis: Conventional criteria versus new alternatives. Structural Equation Modeling: A Multidisciplinary Journal, 6(1), 1-55.
ISO/IEC 17799 (2000). Information technology - Code of practice for information security management. First edition 2000/12/01.
ISO/IEC 27001 (2005). International Organization for Standardization. Switzerland.
Karyda, M., Kiountouzis, E., and Kokolakis, S. (2005). Information Systems Security Policies: A Contextual Perspective. Computers & Security (24:3), 246-260.
Knapp, K. J. (2005). A Model of Managerial Effectiveness in Information Security: From Grounded Theory to Empirical Test. Doctoral Dissertation, Auburn University.
Knapp, K. J., Marshall, T. E., Rainer, R. K., and Ford, F. N. (2006). Information Security: Management's Effect on Culture and Policy. Information Management & Computer Security (14:1), 24-36.
Lee, J., & Lee, Y. (2002). A holistic model of computer abuse within organizations. Information Management & Computer Security, 10(2), 57-63.
Lewin, K. (1951). Field theory in social science. New York: Harper and Bros. Co.
Litwin, G. H., & Stringer, R. A. (1968). Motivation and organization climate. Boston: Harvard University Press.Word-of-mouth: The Adoption of Online Opinions in Online Customer Communities. Internet Research, 18(3), 229-247.
Loe, T. W., Ferrell, L., and Mansfield, P. (2000). A Review of Empirical Studies Assessing Ethical Decision Making in Business. Journal of business ethics (25:3), 185-204.
Masterson, S. S., & Stamper, C. L. (2003). Perceived organizational membership: An aggregate framework representing the employee organization relationship. Journal of Organizational Behavior, 24(5), 473-490.
McDonald, R. P. and Ho, M. R. (2002). Principles and practice in reporting structural equation analysis. Psychological Methods, 7(1), 64-82.
McMillan, D. W., & Chavis, D. M. (1986). Sense of community-A definition and a theory. Journal of Community Psychology, 14:6-23.
Neter, J., Kutner, M.H., Nachtsheim, C.J. and Wasserman, W. (1996). Applied Linear Statistical Models. 4th Edition, WCB McGraw-Hill, New York.
Neumann, P. G. (1995). Computer Related Risks. New York: ACM Press.
Palvia, P. C. (1996). A model and instrument for measuring small business user satisfaction with information technology. Information & Management, 31, 151-163.
Pfleeger C. P. (1996). Security in Computing, 2nd Eds. New Jersey: Prentice Hall PTR.
Rees, J. Bandyopadhyay, S., and Spafford, E. H. (2003). PFIRES: A Policy Framework for Information Security. Communications of the ACM (46:7), 101-106.
Robbins, S. P. (2001). Management (9th ed.). Englewood Cliffs, NJ:Prentice-Hall.
Robinson, J. P., & Shaver, P. R. (1973). Measures of Social Psychological Attitudes (Rev. ed.). Ann Arbor, MI: Institute for Social Research.
Simson, G. and Gene, S. (1991). Practical UNIX Security. O’Reilly & Associates, California.
Siponen, M. T. (2000). A Conceptual Foundation for Organizational Information Security Awareness. Information Management & Computer Security (8:1), 31-41.
Starling, G. (1998). Strategies for Policy Marking. Homewood. IL: The Dorsey Press.
Straub, D. W. (1990). Effective IS Security: An Empirical Study. Information Systems Research(1:3) , 255-276.
Thomson, K. L., and Von Solms, R. (2005). Information Security Obedience: A Definition. Computer & Security (24:1), 69-75.
Tudor, J. K. (2001). Information Security Architecture: An Integrated Approach to Security in the Organization. CRC Press, Boca Raton.
Wood, C. C. (1995). Writing InfoSec Policies. Computers & Security (14:8), 667-674.
