DocumentCode
1583294
Title
Explaining Opposing Compliance Motivations towards Organizational Information Security Policies
Author
Lowry, Paul Benjamin ; Moody, Greg D.
fYear
2013
Firstpage
2998
Lastpage
3007
Abstract
Lack of compliance with organizational information security policies (ISPOs) is a widespread organizational issue that increasingly bears very large direct and qualitative costs. The purpose of our study was to explain the causes of tensions within organizations to either comply with new ISPOs or react negatively against them. To do so, we proposed an innovative model, which pits organizational control theory, as a force that explains ISPO compliance, against reactance theory, as a force that explains ISPO noncompliance and anger toward organizations. To test the model, we used a sample of 320 working professionals in a variety of industries to examine the likely organizational outcomes when a new ISPO is delivered to employees in the form of a typical memo sent throughout an organization. We found support for our newly proposed model, which is an important contribution to research on organizational security practices.
Keywords
Context; Control theory; Employment; Information security; Meteorology; Organizations; compliance; information security; information security policies; reactance;
fLanguage
English
Publisher
ieee
Conference_Titel
System Sciences (HICSS), 2013 46th Hawaii International Conference on
Conference_Location
Wailea, HI, USA
ISSN
1530-1605
Print_ISBN
978-1-4673-5933-7
Electronic_ISBN
1530-1605
Type
conf
DOI
10.1109/HICSS.2013.5
Filename
6480205
Link To Document