{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T01:44:42Z","timestamp":1769910282785,"version":"3.49.0"},"reference-count":41,"publisher":"Emerald","issue":"2","license":[{"start":{"date-parts":[[2018,6,11]],"date-time":"2018-06-11T00:00:00Z","timestamp":1528675200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ICS"],"published-print":{"date-parts":[[2018,6,11]]},"abstract":"<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title>\n<jats:p>The purpose of this paper is to investigate the occurrence of value conflicts between information security and other organizational values among white-collar workers. Further, analyzes are conducted of the relationship between white-collar workers\u2019 perceptions of the culture of their organizations and value conflicts involving information security.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title>\n<jats:p>Descriptive analyses and regression analyses were conducted on survey data gathered among two samples of white-collar workers in Sweden.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Findings<\/jats:title>\n<jats:p>Value conflicts regarding information security occur regularly among white-collar workers in the private and public sectors and within different business sectors. Variations in their occurrence can be understood partly as a function of employees\u2019 work situations and the sensitivity of the information handled in the organization. Regarding how perceived organizational culture affects the occurrence of value conflicts, multivariate regression analysis reveals that employees who perceive their organizations as having externally oriented, flexible cultures experience value conflicts more often.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Research limitations\/implications<\/jats:title>\n<jats:p>The relatively low share of explained variance in the explanatory models indicates the need to identify alternative explanations of the occurrence of value conflicts regarding information security.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Practical implications<\/jats:title>\n<jats:p>Information security managers need to recognize that value conflicts occur regularly among white-collar workers in different business sectors, more often among workers in organizations that handle sensitive information, and most often among white-collar workers who perceive the cultures of their organizations as being externally oriented and flexible.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title>\n<jats:p>The study addresses a gap in the information security literature by contributing to the understanding of value conflicts between information security and other organizational values. This study has mapped the occurrence of value conflicts regarding information security among white-collar professionals and shows that the occurrence of value conflicts is associated with work situation, information sensitivity and perceived organizational culture.<\/jats:p>\n<\/jats:sec>","DOI":"10.1108\/ics-08-2017-0058","type":"journal-article","created":{"date-parts":[[2018,4,25]],"date-time":"2018-04-25T19:18:22Z","timestamp":1524683902000},"page":"213-229","source":"Crossref","is-referenced-by-count":16,"title":["Perceptions of organizational culture and value conflicts in information security management"],"prefix":"10.1108","volume":"26","author":[{"given":"Martin","family":"Karlsson","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thomas","family":"Denk","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Joachim","family":"\u00c5str\u00f6m","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"issue":"3","key":"key2020092814433125000_ref001","doi-asserted-by":"crossref","first-page":"326","DOI":"10.1177\/000765039903800305","article-title":"Understanding research on values in business: a level of analysis framework","volume":"38","year":"1999","journal-title":"Business & Society"},{"key":"key2020092814433125000_ref002","article-title":"From intentions to actions: a theory of planned behavior","volume-title":"Action Control","year":"1985"},{"issue":"4","key":"key2020092814433125000_ref003","doi-asserted-by":"crossref","first-page":"276","DOI":"10.1016\/j.cose.2006.11.004","article-title":"A qualitative study of users\u2019 view on information security","volume":"26","year":"2007","journal-title":"Computers & Security"},{"key":"key2020092814433125000_ref004","article-title":"Information security versus post-bureaucracy","year":"2017"},{"issue":"7\/8","key":"key2020092814433125000_ref005","first-page":"7","article-title":"Introduction to \u2018secrecy and transparency\u2019 the politics of opacity and openness","volume":"28","year":"2011","journal-title":"Theory, Culture & Society"},{"key":"key2020092814433125000_ref006","volume-title":"Diagnosing and Changing Organisational Culture","year":"1999"},{"key":"key2020092814433125000_ref007","unstructured":"Cameron, K.S. and Quinn, R.E. (2002), \u201cOrganizational culture assessment instrument\u201d, available at: www.ocai-online.com\/userfiles\/file\/ocai_enterprise_example_report.pdf (accessed 7 December 2017)."},{"key":"key2020092814433125000_ref008","unstructured":"Cisco (2014), \u201cCisco 2014 annual security report\u201d, available at: www.cisco.com\/assets\/global\/UK\/pdfs\/executive_security\/sc-01_casr2014_cte_liq_en.pdf (accessed 7 December 2017)."},{"key":"key2020092814433125000_ref009","volume-title":"Foundations of Social Theory","year":"1990"},{"issue":"15","key":"key2020092814433125000_ref010","doi-asserted-by":"crossref","first-page":"1429","DOI":"10.1111\/j.1559-1816.1998.tb01685.x","article-title":"Extending the theory of planned behavior: a review and avenues for further research","volume":"28","year":"1998","journal-title":"Journal of Applied Social Psychology"},{"issue":"2","key":"key2020092814433125000_ref011","doi-asserted-by":"crossref","first-page":"196","DOI":"10.1016\/j.cose.2009.09.002","article-title":"A framework and assessment instrument for information security culture","volume":"29","year":"2010","journal-title":"Computers & Security"},{"issue":"9","key":"key2020092814433125000_ref012","doi-asserted-by":"crossref","first-page":"1143","DOI":"10.1177\/0010414009331724","article-title":"Context and causal mechanisms in political analysis","volume":"42","year":"2009","journal-title":"Comparative Political Studies"},{"key":"key2020092814433125000_ref013","volume-title":"Predicting and Changing Behavior: The Reasoned Action Approach","year":"2010"},{"key":"key2020092814433125000_ref014","volume-title":"Organizational Behavior","year":"2011"},{"issue":"4","key":"key2020092814433125000_ref015","doi-asserted-by":"crossref","first-page":"373","DOI":"10.1016\/j.jsis.2011.06.001","article-title":"Value conflicts for information security management","volume":"20","year":"2011","journal-title":"The Journal of Strategic Information Systems"},{"key":"key2020092814433125000_ref016","unstructured":"Intel Security (2014), \u201c! Net losses: estimating the global cost of cybercrime\u201d, available at: https:\/\/csis-prod.s3.amazonaws.com\/s3fs-public\/legacy_files\/files\/attachments\/140609_McAfee_PDF.pdf (accessed 7 December 2017)."},{"issue":"2","key":"key2020092814433125000_ref017","doi-asserted-by":"crossref","first-page":"285","DOI":"10.2307\/2392498","article-title":"Job demands, job decision latitude, and mental strain: implications for job redesign","volume":"24","year":"1979","journal-title":"Administrative Science Quarterly"},{"issue":"3","key":"key2020092814433125000_ref018","doi-asserted-by":"crossref","first-page":"279","DOI":"10.1108\/ICS-11-2016-0084","article-title":"Measuring employees\u2019 compliance \u2013 the importance of value pluralism","volume":"25","year":"2017","journal-title":"Information and Computer Security"},{"key":"key2020092814433125000_ref019","first-page":"25","article-title":"Organisationskulturens p\u00e5verkan p\u00e5 informationss\u00e4kerhetsarbetet","volume-title":"Informationss\u00e4kerhet Och Organisationskultur","year":"2017"},{"key":"key2020092814433125000_ref020","first-page":"253","article-title":"Flaws in the theory of reasoned action","volume-title":"The Theory of Reasoned Action: Its Applications to AIDS-Preventive Behaviour","author":"and","year":"1993"},{"key":"key2020092814433125000_ref021","first-page":"70","article-title":"\u2018Comply or die\u2019 is dead: long live security-aware principal agents","volume-title":"International Conference on Financial Cryptography and Data Security","year":"2013"},{"key":"key2020092814433125000_ref022","volume-title":"The Nature of Value Conflict and its Consequences for Public Opinion","year":"2004"},{"issue":"5","key":"key2020092814433125000_ref023","doi-asserted-by":"crossref","first-page":"1071","DOI":"10.1108\/MD-08-2012-0599","article-title":"Impact of perceived corporate culture on organizational commitment","volume":"51","year":"2013","journal-title":"Management Decision"},{"issue":"3","key":"key2020092814433125000_ref024","first-page":"8","article-title":"The second version of the Copenhagen psychosocial questionnaire","volume":"38","year":"2010","journal-title":"Scandinavian Journal of Public Health"},{"issue":"3","key":"key2020092814433125000_ref025","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1093\/her\/1.3.153","article-title":"Protection motivation theory and preventive health: beyond the health belief model","volume":"1","year":"1986","journal-title":"Health Education Research"},{"issue":"3","key":"key2020092814433125000_ref026","doi-asserted-by":"crossref","first-page":"363","DOI":"10.1287\/mnsc.29.3.363","article-title":"A spatial model of effectiveness criteria: towards a competing values approach to organizational analysis","volume":"29","year":"1983","journal-title":"Management Science"},{"issue":"2","key":"key2020092814433125000_ref027","doi-asserted-by":"crossref","first-page":"221","DOI":"10.1016\/j.cose.2011.12.001","article-title":"Unrealistic optimism on information security management","volume":"31","year":"2012","journal-title":"Computers & Security"},{"key":"key2020092814433125000_ref028","volume-title":"The Nature of Human Values","year":"1973"},{"issue":"4","key":"key2020092814433125000_ref029","doi-asserted-by":"crossref","first-page":"283","DOI":"10.1111\/j.1559-1816.1972.tb01280.x","article-title":"Self\u2010confrontation and confrontation with another as determinants of long\u2010term value change","volume":"2","year":"1972","journal-title":"Journal of Applied Social Psychology"},{"issue":"1","key":"key2020092814433125000_ref030","first-page":"70","article-title":"Information security policy compliance model in organizations","volume":"56","year":"2016","journal-title":"Computers & Security"},{"issue":"3","key":"key2020092814433125000_ref031","doi-asserted-by":"crossref","first-page":"293","DOI":"10.1002\/job.248","article-title":"Job demands, job resources, and their relationship with burnout and engagement: a multi-sample study","volume":"25","year":"2004","journal-title":"Journal of Organizational Behavior"},{"issue":"3","key":"key2020092814433125000_ref032","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1057\/ejis.2012.59","article-title":"Guidelines for improving the contextual relevance of field surveys: the case of information security policy violations","volume":"23","year":"2014","journal-title":"European Journal of Information Systems"},{"key":"key2020092814433125000_ref033","first-page":"257","article-title":"A review of the theory of planned behaviour in the context of information security policy compliance","volume-title":"IFIP International Information Security Conference","year":"2013"},{"issue":"2","key":"key2020092814433125000_ref034","doi-asserted-by":"crossref","first-page":"124","DOI":"10.1016\/j.cose.2004.07.001","article-title":"Analysis of end user security behaviors","volume":"24","year":"2005","journal-title":"Computers & Security"},{"issue":"4","key":"key2020092814433125000_ref035","doi-asserted-by":"crossref","first-page":"476","DOI":"10.1016\/j.cose.2009.10.005","article-title":"Information security culture: a management perspective","volume":"29","year":"2010","journal-title":"Computers & Security"},{"issue":"1","key":"key2020092814433125000_ref036","doi-asserted-by":"crossref","first-page":"21","DOI":"10.4018\/joeuc.2012010102","article-title":"IS security policy violations: a rational choice perspective","volume":"24","year":"2012","journal-title":"Journal of Organizational and End User Computing"},{"issue":"2","key":"key2020092814433125000_ref037","doi-asserted-by":"crossref","first-page":"179","DOI":"10.2307\/975629","article-title":"In defense of bureaucracy","volume":"40","year":"1980","journal-title":"Public Administration Review"},{"issue":"2","key":"key2020092814433125000_ref038","first-page":"139","article-title":"Bureaucratic hierarchy vs feudal hierarchy: a study on the organizational culture of China\u2019s SOEs","volume":"6","year":"2011","journal-title":"International Journal of Business and Management"},{"issue":"4","key":"key2020092814433125000_ref039","doi-asserted-by":"crossref","first-page":"303","DOI":"10.2307\/2786758","article-title":"Role identity and reasoned action in the prediction of repeated behavior","volume":"51","year":"1988","journal-title":"Social Psychology Quarterly"},{"issue":"14","key":"key2020092814433125000_ref040","first-page":"17","article-title":"The rise and demise of the new public management","volume":"33","year":"2005","journal-title":"Post-Autistic Economics Review"},{"issue":"3","key":"key2020092814433125000_ref041","doi-asserted-by":"crossref","first-page":"246","DOI":"10.1108\/ICS-05-2014-0033","article-title":"Information security culture \u2013 state-of-the-art review between 2000 and 2013","volume":"23","year":"2015","journal-title":"Information and Computer Security"}],"container-title":["Information &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-08-2017-0058\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-08-2017-0058\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T01:23:07Z","timestamp":1753406587000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/26\/2\/213-229\/189389"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,6,11]]},"references-count":41,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2018,6,11]]}},"alternative-id":["10.1108\/ICS-08-2017-0058"],"URL":"https:\/\/doi.org\/10.1108\/ics-08-2017-0058","relation":{},"ISSN":["2056-4961"],"issn-type":[{"value":"2056-4961","type":"print"}],"subject":[],"published":{"date-parts":[[2018,6,11]]}}}