Evaluating the explanatory power of theoretical frameworks on intention to comply with information security policies in higher education

被引:61
作者
Rajab, Majed [1 ]
Eydgahi, Ali [2 ]
机构
[1] Eastern Michigan Univ, Coll Technol, Ypsilanti, MI 48197 USA
[2] Eastern Michigan Univ, Sch Engn Technol, Ypsialnti, MI 48197 USA
关键词
Higher education; Compliance; Partial least squares; Information security; Theoretical frameworks; PROTECTION MOTIVATION; PLANNED BEHAVIOR; DETERRENCE;
D O I
10.1016/j.cose.2018.09.016
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Higher education institutions have invested heavily in their high-tech infrastructure to ensure the security and integrity of their information. Incompliance with information technology policies has shown to lead to mass information leaks, reputational damage and potential litigation. Little research has been conducted on the subject of employees' compliance with such sensitive protocols. This paper presents a comprehensive theoretical model based on Theory of Planned Behavior, Protection Motivation Theory, General Deterrence Theory and Organizational Theory for predicting intentions of higher education employees' compliance with information security policies. Utilizing a survey instrument and using Structural Equation Modeling-Partial Least Squares method, this study found that perceived vulnerability, response efficacy and response cost to be the most predictive indicators that are positively associated with intentions of information security compliance among university staff and faculty. But, little support was found for the General Deterrence Theory, Theory of Planned Behavior and Organizational Theory in explaining the variance of higher education staff intentions to comply with information security policies. Results indicated that the Protection Motivation Theory provides the best theoretical framework to understand higher education employees' behavior with respect to compliance with information security. Such results confirmed earlier empirical investigations attempting to understand the basic question of why do employees differ with respect to compliance with information security. Consistent with the prior research, severe sanctions, close management supervision, peers' pressure and attitudes towards information security do not matter as much as perceived vulnerability and response efficacy in ensuring higher levels of intentions to comply with ISPs in organizations. The study recommends universities and colleges to invest in applied information security training for their staff, as well as for the university overall community. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:211 / 223
页数:13
相关论文
共 42 条
[1]   THE THEORY OF PLANNED BEHAVIOR [J].
AJZEN, I .
ORGANIZATIONAL BEHAVIOR AND HUMAN DECISION PROCESSES, 1991, 50 (02) :179-211
[2]  
AlKalbani A., 2014, P 25 AUSTR C INF SYS, P1
[3]  
[Anonymous], AMCIS
[4]  
[Anonymous], UK ORG STILL FAIL PR
[5]  
[Anonymous], IS CLIMATE OVERALL P
[6]  
[Anonymous], DETECTION CERTAINTY
[7]  
[Anonymous], P PAC AS C INF SYST
[8]  
[Anonymous], DATA BREACH INVESTIG
[9]  
[Anonymous], WORLD POLIT
[10]  
[Anonymous], REV ESALUDCOM