The Experts below are selected from a list of 47031 Experts worldwide ranked by ideXlab platform
Jonas Hallberg - One of the best experts on this subject based on the ideXlab platform.
-
the theory of planned behavior and Information Security Policy compliance
Journal of Computer Information Systems, 2019Co-Authors: Teodor Sommestad, Henrik Karlzen, Jonas HallbergAbstract:ABSTRACTMuch of the research on Security Policy compliance has tested the relationships posited by the theory of planned behavior. This theory explains far from all of the measurable variance in Policy compliance intentions. However, it is associated with something called the sufficiency assumption, which essentially states that no variable is missing from the theory. This paper addresses this assumption in the context of Information Security Policy compliance. A meta-analysis of published tests on Information Security behavior and a review of the literature in related fields are used to identify variables that have the potential to improve the theory’s predictions. These results are tested using a random sample of 645 white-collar workers. The results suggest that the variables anticipated regret and habit improve the predictions. The variables increase the explained variance by 3.4 and 2.6 percentage points, respectively, when they are added individually, and by 5.4 percentage points when both are added.
-
the sufficiency of the theory of planned behavior for explaining Information Security Policy compliance
Information and Computer Security, 2015Co-Authors: Teodor Sommestad, Henrik Karlzen, Jonas HallbergAbstract:Purpose – This paper aims to challenge the assumption that the theory of planned behaviour (TPB) includes all constructs that explain Information Security Policy compliance and investigates if anticipated regret or constructs from the protection motivation theory add explanatory power. The TPB is an established theory that has been found to predict compliance with Information Security policies well. Design/methodology/approach – Responses from 306 respondents at a research organization were collected using a questionnaire-based survey. Extensions in terms of anticipated regret and constructs drawn from the protection motivation theory are tested using hierarchical regression analysis. Findings – Adding anticipated regret and the threat appraisal process results in improvements of the predictions of intentions. The improvements are of sufficient magnitude to warrant adjustments of the model of the TPB when it is used in the area of Information Security Policy compliance. Originality/value – This study is t...
-
variables influencing Information Security Policy compliance a systematic review of quantitative studies
Information Management & Computer Security, 2014Co-Authors: Teodor Sommestad, Jonas Hallberg, Kristoffer Lundholm, Johan BengtssonAbstract:Purpose – The purpose of this paper is to identify variables that influence compliance with Information Security policies of organizations and to identify how important these variables are. Design/methodology/approach – A systematic review of empirical studies described in extant literature is performed. This review found 29 studies meeting its inclusion criterion. The investigated variables in these studies and the effect size reported for them were extracted and analysed. Findings – In the 29 studies, more than 60 variables have been studied in relation to Security Policy compliance and incompliance. Unfortunately, no clear winners can be found among the variables or the theories they are drawn from. Each of the variables only explains a small part of the variation in people's behaviour and when a variable has been investigated in multiple studies the findings often show a considerable variation. Research limitations/implications – It is possible that the disparate findings of the reviewed studies can b...
-
a review of the theory of planned behaviour in the context of Information Security Policy compliance
Information Security Conference, 2013Co-Authors: Teodor Sommestad, Jonas HallbergAbstract:The behaviour of employees influences Information Security in virtually all organisations. To inform the employees regarding what constitutes desirable behaviour, an Information Security Policy can be formulated and communicated. However, not all employees comply with the Information Security Policy. This paper reviews and synthesises 16 studies related to the theory of planned behaviour. The objective is to investigate 1) to what extent the theory explains Information Security Policy compliance and violation and 2) whether reasonable explanations can be found when the results of the studies diverge. It can be concluded that the theory explains Information Security Policy compliance and violation approximately as well as it explains other behaviours. Some potential explanations can be found for why the results of the identified studies diverge. However, many of the differences in results are left unexplained.
Teodor Sommestad - One of the best experts on this subject based on the ideXlab platform.
-
the theory of planned behavior and Information Security Policy compliance
Journal of Computer Information Systems, 2019Co-Authors: Teodor Sommestad, Henrik Karlzen, Jonas HallbergAbstract:ABSTRACTMuch of the research on Security Policy compliance has tested the relationships posited by the theory of planned behavior. This theory explains far from all of the measurable variance in Policy compliance intentions. However, it is associated with something called the sufficiency assumption, which essentially states that no variable is missing from the theory. This paper addresses this assumption in the context of Information Security Policy compliance. A meta-analysis of published tests on Information Security behavior and a review of the literature in related fields are used to identify variables that have the potential to improve the theory’s predictions. These results are tested using a random sample of 645 white-collar workers. The results suggest that the variables anticipated regret and habit improve the predictions. The variables increase the explained variance by 3.4 and 2.6 percentage points, respectively, when they are added individually, and by 5.4 percentage points when both are added.
-
the sufficiency of the theory of planned behavior for explaining Information Security Policy compliance
Information and Computer Security, 2015Co-Authors: Teodor Sommestad, Henrik Karlzen, Jonas HallbergAbstract:Purpose – This paper aims to challenge the assumption that the theory of planned behaviour (TPB) includes all constructs that explain Information Security Policy compliance and investigates if anticipated regret or constructs from the protection motivation theory add explanatory power. The TPB is an established theory that has been found to predict compliance with Information Security policies well. Design/methodology/approach – Responses from 306 respondents at a research organization were collected using a questionnaire-based survey. Extensions in terms of anticipated regret and constructs drawn from the protection motivation theory are tested using hierarchical regression analysis. Findings – Adding anticipated regret and the threat appraisal process results in improvements of the predictions of intentions. The improvements are of sufficient magnitude to warrant adjustments of the model of the TPB when it is used in the area of Information Security Policy compliance. Originality/value – This study is t...
-
variables influencing Information Security Policy compliance a systematic review of quantitative studies
Information Management & Computer Security, 2014Co-Authors: Teodor Sommestad, Jonas Hallberg, Kristoffer Lundholm, Johan BengtssonAbstract:Purpose – The purpose of this paper is to identify variables that influence compliance with Information Security policies of organizations and to identify how important these variables are. Design/methodology/approach – A systematic review of empirical studies described in extant literature is performed. This review found 29 studies meeting its inclusion criterion. The investigated variables in these studies and the effect size reported for them were extracted and analysed. Findings – In the 29 studies, more than 60 variables have been studied in relation to Security Policy compliance and incompliance. Unfortunately, no clear winners can be found among the variables or the theories they are drawn from. Each of the variables only explains a small part of the variation in people's behaviour and when a variable has been investigated in multiple studies the findings often show a considerable variation. Research limitations/implications – It is possible that the disparate findings of the reviewed studies can b...
-
a review of the theory of planned behaviour in the context of Information Security Policy compliance
Information Security Conference, 2013Co-Authors: Teodor Sommestad, Jonas HallbergAbstract:The behaviour of employees influences Information Security in virtually all organisations. To inform the employees regarding what constitutes desirable behaviour, an Information Security Policy can be formulated and communicated. However, not all employees comply with the Information Security Policy. This paper reviews and synthesises 16 studies related to the theory of planned behaviour. The objective is to investigate 1) to what extent the theory explains Information Security Policy compliance and violation and 2) whether reasonable explanations can be found when the results of the studies diverge. It can be concluded that the theory explains Information Security Policy compliance and violation approximately as well as it explains other behaviours. Some potential explanations can be found for why the results of the identified studies diverge. However, many of the differences in results are left unexplained.
Izak Benbasat - One of the best experts on this subject based on the ideXlab platform.
-
Information Security Policy compliance: An empirical study of rationality-based beliefs and Information Security awareness
MIS Quarterly, 2010Co-Authors: Burcu Bulgurcu, Hasan Cavusoglu, Izak BenbasatAbstract:Many organizations recognize that their employees, who are often considered the weakest link in Information Security, can also be great assets in the effort to reduce risk related to Information Security. Since employees who comply with the Information Security rules and regulations of the organization are the key to strengthening Information Security, understanding compliance behavior is crucial for organizations that want to leverage their human capital. This research identifies the antecedents of employee compliance with the Information Security Policy (ISP) of an organization. Specifically, we investigate the rationality- based factors that drive an employee to comply with requirements of the ISP with regard to protecting the organization’s Information and technology resources. Drawing on the theory of planned behavior, we posit that, along with normative belief and self-efficacy, an employee’s attitude toward compliance determines intention to comply with the ISP. As a key contribution, we posit that an employee’s attitude is influenced by benefit of compliance, cost of compliance, and cost of noncompliance, which are beliefs about the overall assessment of consequences of compliance or noncom- pliance. We then postulate that these beliefs are shaped by the employee’s outcome beliefs concerning the events that follow compliance or noncompliance: benefit of compliance is shaped by intrinsic benefit, safety of resources, and rewards, while cost of compliance is shaped by work impediment; and cost of noncompliance is shaped by intrinsic cost, vulnerability of resources, and sanctions. We also investigate the impact of Information Security awareness (ISA) on outcome beliefs and an employee’s attitude toward compliance with the ISP. Our results show that an employee’s intention to comply with the ISP is significantly influenced by attitude, normative beliefs, and self-efficacy to comply. Outcome beliefs significantly affect beliefs about overall assessment of consequences, and they, in turn, significantly affect an employee’s attitude. Furthermore, ISA positively affects both attitude and outcome beliefs. As the importance of employees’ following their organizations’ Information Security rules and regulations increases, our study sheds light on the role of ISA and compliance-related beliefs in an organization’s efforts to encourage compliance.
-
roles of Information Security awareness and perceived fairness in Information Security Policy compliance
Americas Conference on Information Systems, 2009Co-Authors: Burcu Bulgurcu, Hasan Cavusoglu, Izak BenbasatAbstract:Drawing on the Theory of Planned Behavior (TPB), this research investigates two factors that drive an employee to comply with requirements of the Information Security Policy (ISP) of her organization with regards to protecting Information and technology resources: an employee’s Information Security awareness (ISA) and her perceived fairness of the requirements of the ISP. Our results, which is based on the PLS analysis of data collected from 464 participants, show that ISA and perceived fairness positively affect attitude, and in turn attitude positively affects intention to comply. ISA also has an indirect impact on attitude since it positively influences perceived fairness. As organizations strive to get their employees to follow their Information Security rules and regulations, our study sheds light on the role of an employee’s ISA and procedural fairness with regards to Security rules and regulations in the workplace.
Anthony Vance - One of the best experts on this subject based on the ideXlab platform.
-
the influence of professional subculture on Information Security Policy violations a field study in a healthcare context
Information Systems Research, 2020Co-Authors: Sumantra Sarkar, Anthony Vance, Balasubramaniam Ramesh, Menelaos DemestihasAbstract:The Influence of Professional Subculture on Information Security Policy Violations: A Field Study in a Healthcare Context
-
guidelines for improving the contextual relevance of field surveys the case of Information Security Policy violations
European Journal of Information Systems, 2014Co-Authors: Mikko Siponen, Anthony VanceAbstract:The Information systems (IS) field continues to debate the relative importance of rigor and relevance in its research. While the pursuit of rigor in research is important, we argue that further effort is needed to improve practical relevance, not only in terms of topics, but also by ensuring contextual relevance. While content validity is often performed rigorously, validated survey instruments may still lack contextual relevance and be out of touch with practice. We argue that IS behavioral research can improve its practical relevance without loss of rigor by carefully addressing a number of contextual issues in instrumentation design. In this opinion article, we outline five guidelines – relating to both rigor and relevance – designed to increase the contextual relevance of field survey research, using case examples from the area of IS Security. They are: (1) inform study respondents that a behavior is an ISP violation, (2) measure specific examples of ISP violations, (3) ensure that ISP violations are important ISP problems in practice, (4) ensure the applicability of IS Security violations to the organizational context, and (5) consider the appropriate level of specificity and generalizability for instrumentation. We review previous behavioral research on IS Security and show that no existing study meets more than three of these five guidelines. By applying these guidelines where applicable, IS scholars can increase the contextual relevance of their instrumentation, yielding results more likely to address important problems in practice.
-
What levels of moral reasoning and values explain adherence to Information Security rules? An empirical study
European Journal of Information Systems, 2009Co-Authors: Liisa Myyry, Seppo Pahnila, Tero Vartiainen, Mikko Siponen, Anthony VanceAbstract:It is widely agreed that employee non-adherence to Information Security policies poses a major problem for organizations. Previous research has pointed to the potential of theories of moral reasoning to better understand this problem. However, we find no empirical studies that examine the influence of moral reasoning on compliance with Information Security policies. We address this research gap by proposing a theoretical model that explains non-compliance in terms of moral reasoning and values. The model integrates two well-known psychological theories: the Theory of Cognitive Moral Development by Kohlberg and the Theory of Motivational Types of Values by Schwartz. Our empirical findings largely support the proposed model and suggest implications for practice and research on how to improve Information Security Policy compliance.
Mikko Siponen - One of the best experts on this subject based on the ideXlab platform.
-
toward a unified model of Information Security Policy compliance
Management Information Systems Quarterly, 2018Co-Authors: Gregory D Moody, Mikko Siponen, Seppo PahnilaAbstract:Information systems Security (ISS) behavioral research has produced different models to explain Security Policy compliance. This paper (1) reviews 11 theories that have served the majority of previous Information Security behavior models, (2) empirically compares these theories (Study 1), (3) proposes a unified model, called the unified model of Information Security Policy compliance (UMISPC), which integrates elements across these extant theories, and (4) empirically tests the UMISPC in a new study (Study 2), which provided preliminary empirical support for the model. The 11 theories reviewed are (1) the theory of reasoned action, (2) neutralization techniques, (3) the health belief model, (4) the theory of planned behavior, (5) the theory of interpersonal behavior, (6) the protection motivation theory, (7) the extended protection motivation theory, (8) deterrence theory and rational choice theory, (9) the theory of self-regulation, (10) the extended parallel processing model, and (11) the control balance theory. The UMISPC is an initial step toward empirically examining the extent to which the existing models have similar and different constructs. Future research is needed to examine to what extent the UMISPC can explain different types of ISS behaviors (or intentions thereof). Such studies will determine the extent to which the UMISPC needs to be revised to account for different types of ISS Policy violations and the extent to which the UMISPC is generalizable beyond the three types of ISS violations we examined. Finally, the UMISPC is intended to inspire future ISS research to further theorize and empirically demonstrate the important differences between rival theories in the ISS context that are not captured by current measures.
-
guidelines for improving the contextual relevance of field surveys the case of Information Security Policy violations
European Journal of Information Systems, 2014Co-Authors: Mikko Siponen, Anthony VanceAbstract:The Information systems (IS) field continues to debate the relative importance of rigor and relevance in its research. While the pursuit of rigor in research is important, we argue that further effort is needed to improve practical relevance, not only in terms of topics, but also by ensuring contextual relevance. While content validity is often performed rigorously, validated survey instruments may still lack contextual relevance and be out of touch with practice. We argue that IS behavioral research can improve its practical relevance without loss of rigor by carefully addressing a number of contextual issues in instrumentation design. In this opinion article, we outline five guidelines – relating to both rigor and relevance – designed to increase the contextual relevance of field survey research, using case examples from the area of IS Security. They are: (1) inform study respondents that a behavior is an ISP violation, (2) measure specific examples of ISP violations, (3) ensure that ISP violations are important ISP problems in practice, (4) ensure the applicability of IS Security violations to the organizational context, and (5) consider the appropriate level of specificity and generalizability for instrumentation. We review previous behavioral research on IS Security and show that no existing study meets more than three of these five guidelines. By applying these guidelines where applicable, IS scholars can increase the contextual relevance of their instrumentation, yielding results more likely to address important problems in practice.
-
What levels of moral reasoning and values explain adherence to Information Security rules? An empirical study
European Journal of Information Systems, 2009Co-Authors: Liisa Myyry, Seppo Pahnila, Tero Vartiainen, Mikko Siponen, Anthony VanceAbstract:It is widely agreed that employee non-adherence to Information Security policies poses a major problem for organizations. Previous research has pointed to the potential of theories of moral reasoning to better understand this problem. However, we find no empirical studies that examine the influence of moral reasoning on compliance with Information Security policies. We address this research gap by proposing a theoretical model that explains non-compliance in terms of moral reasoning and values. The model integrates two well-known psychological theories: the Theory of Cognitive Moral Development by Kohlberg and the Theory of Motivational Types of Values by Schwartz. Our empirical findings largely support the proposed model and suggest implications for practice and research on how to improve Information Security Policy compliance.
-
an Information Security meta Policy for emergent organizations
Logistics Information Management, 2002Co-Authors: Richard L Baskerville, Mikko SiponenAbstract:There is an increasing movement towards emergent organizations and an adaptation of Web‐based Information systems (IS). Such trends raise new requirements for Security Policy development. One such requirement is that Information Security Policy formulation must become federated and emergent. However, existing Security Policy approaches do not pay much attention to Policy formulation at all – much less IS Policy formulation for emergent organizations. To improve the situation, an Information Security meta‐Policy is put forth. The meta‐Policy establishes how policies are created, implemented and enforced in order to assure that all policies in the organization have features to ensure swift implementation and timely, ongoing validation.