Understanding Inconsistent Employee Compliance with Information Security Policies Through the Lens of the Extended Parallel Process Model

被引:54
作者
Chen, Yan [1 ]
Galletta, Dennis F. [2 ]
Lowry, Paul Benjamin [3 ]
Luo, Xin [4 ]
Moody, Gregory D. [5 ]
Willison, Robert [6 ]
机构
[1] Florida Int Univ, Coll Business, Miami, FL 33199 USA
[2] Univ Pittsburgh, Katz Grad Sch Business, Pittsburgh, PA 15260 USA
[3] Virginia Tech, Pamplin Coll Business, Blacksburg, VA 24061 USA
[4] Univ New Mexico, Anderson Sch Management, Albuquerque, NM 87131 USA
[5] Univ Nevada, Lee Business Sch, Las Vegas, NV 89154 USA
[6] Xian Jiaotong Liverpool Univ, Int Business Sch Suzhou, Suzhou 215123, Jiangsu, Peoples R China
关键词
information security; extended parallel processing model; protection motivation theory; organizational security; PROTECTION MOTIVATION; FEAR APPEALS; HEALTH-RISK; SYSTEMS; BEHAVIORS; DESIGN; DETERRENCE; THREATS; IMPACT; TRUST;
D O I
10.1287/isre.2021.1014
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Organizational information security (ISec) threats have exploded with advances in globalization and technology. Thus, organizations are scrambling to find both technical and behavioral approaches to shore up security. Whereas security technologies are crucial to these efforts, they are often rendered useless by employees' misunderstanding, carelessness, or deliberate disregard of ISec polices (ISPs). Accordingly, organizations are increasingly seeking ways to encourage employees to work as security allies. A key approach in many organizations is encouraging employees to better understand and comply with ISPs. Consequently, ISec research has leveraged several theories to identify the underlying reasons for ISP compliance behaviors among employees. However, most of this research focuses unilaterally on compliance without simultaneously considering noncompliance, as if noncompliance were caused by opposite factors. A pressing need thus exists for a theoretical foundation that can consider both common outcomes and whether there is an explainable tipping point that can explain when a normally compliant employee chooses to become noncompliant, and vice versa. In this study, we contextualize the extended parallel process model (EPPM) to ISP compliance by accounting for dual outcomes of compliance/noncompliance and dual roles of coping-problem-focused coping and emotion-focused coping. We further extend the EPPM to include response costs and maladaptive rewards to predict the two possible outcomes. Additionally, we employ a weighted discriminant value measurement approach to examine the tipping point between compliance and noncompliance. To test our resulting theoretical model and new measure, we conducted two separate empirical studies with 816 employees, using survey and scenario methodologies. The empirical results from these studies indicate that our contextualization and extension of EPPM better explain the gaps than alternative theories in the ISP literature.
引用
收藏
页码:1043 / 1065
页数:24
相关论文
共 115 条
  • [91] Proposing the online community self-disclosure model: the case of working professionals in France and the UK who use online communities
    Posey, Clay
    Lowry, Paul Benjamin
    Roberts, Tom L.
    Ellis, T. Selwyn
    [J]. EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2010, 19 (02) : 181 - 195
  • [92] Posey Clay., 2011, The Dewald Roode Workshop in Information Systems Security, P22
  • [93] Puhakainen P, 2010, MIS QUART, V34, P757
  • [94] Host country resource availability and information system control mechanisms in multinational corporations: An empirical test of resource dependence theory
    Rao, Madhu T.
    Brown, Carol V.
    Perkins, William C.
    [J]. JOURNAL OF MANAGEMENT INFORMATION SYSTEMS, 2007, 23 (04) : 11 - 28
  • [95] Rogers R. W., 1983, Social Psychophysiology: A Sourcebook, P153
  • [96] What are emotions? And how can they be measured?
    Scherer, KR
    [J]. SOCIAL SCIENCE INFORMATION SUR LES SCIENCES SOCIALES, 2005, 44 (04): : 695 - 729
  • [97] The Effectiveness of Abstract Versus Concrete Fear Appeals in Information Security
    Schuetz, Sebastian W.
    Benjamin Lowry, Paul
    Pienta, Daniel A.
    Bennett Thatcher, Jason
    [J]. JOURNAL OF MANAGEMENT INFORMATION SYSTEMS, 2020, 37 (03) : 723 - 757
  • [98] Using Design-Science Based Gamification to Improve Organizational Security Training and Compliance
    Silic, Mario
    Lowry, Paul Benjamin
    [J]. JOURNAL OF MANAGEMENT INFORMATION SYSTEMS, 2020, 37 (01) : 129 - 161
  • [99] Siponen M, 2010, MIS QUART, V34, P487
  • [100] Procedural justice to enhance compliance with non-work-related computing (NWRC) rules: Its determinants and interaction with privacy concerns
    Son, Jai-Yeol
    Park, Jongpil
    [J]. INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2016, 36 (03) : 309 - 321