Behavioral information systems security governance
emphasizes on management of people in an
organization. The aim of behavioral aspects of
security governance is to ensure that employees
show conformity with rules and policies. A system,
which punishes deviant behavior (people who do
not follow the rules) and takes strong deterrent
actions to ensure that procedures are followed
comes under the purview of behavioral information
security governance. After all, people are the
weakest link in information systems security [14].
Insider threats (i.e. threat to information systems
from within the organization) are high and the
majority of security breaches fall in this category
[46], [3], [16], [25], [34]. Organic nature of
organizations demands a continuing, dynamic and
real time information management system [2],
where “people” in organization are the drivers of
such ongoing security governance efforts.