Information Security Behavior of IT Professionals (Role of Polices and Compliance)
Abstract
Information security seems to be a technical subject, but it is as behavioral as technical. Most of the security breaches occur due to the negligence of internal employees towards information security policy. Lack of compliance with information security policies is a multidimensional problem, and It requires technical and behavioral solutions. There is plenty of research available for behavioral information security, but most of the research is conducted upon non-IT (information technology) users or non- Specialized users. This research paper is a pilot study for testing the information security policy compliance of IT professionals. Hypotheses were formulated from the literature review, and a framework was developed. The framework consisted of organizational management constructs and two behavioral theories (protection motivation theory and theory of planned behavior). This pilot study showed that organizational management can enhance employees' protection motivation, which later cultivates good information security behavior towards information security policy compliance.

