Exploring the Relation between Information Security Policy Compliance and Cyber Resilience
Synopsis
Contemporary digital environments necessitate an increased organizational commitment to safeguarding the confidentiality, integrity and availability of information assets. An indispensable element of this endeavor lies in issuing and enforcing Information Security Policies (ISP) that delineate appropriate handling and use of the organization’s information assets. While prior research predominantly examined the impact of ISPs on employee cyber behavior, limited attention was given to the organizational-level effects of ISP compliance (ISPC). In particular, the extent to which ISPC and cyber resilience (CR) are interrelated is still insufficiently understood. In light thereof, this article explores mechanisms that can be implemented to increase ISPC, the general organizational-level effects of ISPC, and how ISPC relates to CR specifically. Drawing on an integrative literature review and a holistic case study, this article explores the role of ISPC in driving organizational CR.






