Skip to main navigation Skip to search Skip to main content

Explaining opposing compliance motivations towards organizational information security policies

  • Paul Benjamin Lowry
  • , Greg D. Moody

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Lack of compliance with organizational information security policies (ISPOs) is a widespread organizational issue that increasingly bears very large direct and qualitative costs. The purpose of our study was to explain the causes of tensions within organizations to either comply with new ISPOs or react negatively against them. To do so, we proposed an innovative model, which pits organizational control theory, as a force that explains ISPO compliance, against reactance theory, as a force that explains ISPO noncompliance and anger toward organizations. To test the model, we used a sample of 320 working professionals in a variety of industries to examine the likely organizational outcomes when a new ISPO is delivered to employees in the form of a typical memo sent throughout an organization. We found support for our newly proposed model, which is an important contribution to research on organizational security practices. © 2012 IEEE.
Original languageEnglish
Title of host publicationProceedings of the Annual Hawaii International Conference on System Sciences
Pages2998-3007
DOIs
Publication statusPublished - 2013
Event46th Annual Hawaii International Conference on System Sciences, HICSS 2013 - Wailea, Maui, HI, United States
Duration: 7 Jan 201310 Jan 2013

Publication series

Name
ISSN (Print)1530-1605

Conference

Conference46th Annual Hawaii International Conference on System Sciences, HICSS 2013
PlaceUnited States
CityWailea, Maui, HI
Period7/01/1310/01/13

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 9 - Industry, Innovation, and Infrastructure
    SDG 9 Industry, Innovation, and Infrastructure

Fingerprint

Dive into the research topics of 'Explaining opposing compliance motivations towards organizational information security policies'. Together they form a unique fingerprint.

Cite this