Abstract
Lack of compliance with organizational information security policies (ISPOs) is a widespread organizational issue that increasingly bears very large direct and qualitative costs. The purpose of our study was to explain the causes of tensions within organizations to either comply with new ISPOs or react negatively against them. To do so, we proposed an innovative model, which pits organizational control theory, as a force that explains ISPO compliance, against reactance theory, as a force that explains ISPO noncompliance and anger toward organizations. To test the model, we used a sample of 320 working professionals in a variety of industries to examine the likely organizational outcomes when a new ISPO is delivered to employees in the form of a typical memo sent throughout an organization. We found support for our newly proposed model, which is an important contribution to research on organizational security practices. © 2012 IEEE.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the Annual Hawaii International Conference on System Sciences |
| Pages | 2998-3007 |
| DOIs | |
| Publication status | Published - 2013 |
| Event | 46th Annual Hawaii International Conference on System Sciences, HICSS 2013 - Wailea, Maui, HI, United States Duration: 7 Jan 2013 → 10 Jan 2013 |
Publication series
| Name | |
|---|---|
| ISSN (Print) | 1530-1605 |
Conference
| Conference | 46th Annual Hawaii International Conference on System Sciences, HICSS 2013 |
|---|---|
| Place | United States |
| City | Wailea, Maui, HI |
| Period | 7/01/13 → 10/01/13 |
UN SDGs
This output contributes to the following UN Sustainable Development Goals (SDGs)
-
SDG 9 Industry, Innovation, and Infrastructure
Fingerprint
Dive into the research topics of 'Explaining opposing compliance motivations towards organizational information security policies'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver