The Role of Individual Characteristics on the Effectiveness of IS Security Countermeasures

John D’Arcy, Anat Hovav · Journal of the Association for Information Systems · 2004

General deterrence theory suggests that deterrent security countermeasures (e.g., security policies, security awareness programs, security software) can be used to control IS misuse in organizations.However, empirical studies that have examined the effectiveness of such techniques have produced inconclusive results.A limitation of these studies is that they ignore the impacts of sanction perceptions and individual characteristics on IS misuse behavior.The purpose of this paper is to reconcile the discrepant findings of prior research by introducing a conceptual model that proposes a relationship between deterrent security countermeasures, sanction perceptions, individual characteristics, and IS misuse.The model includes the following propositions: (i) deterrent security countermeasures increase perceived certainty and severity of sanctions, which leads to lower IS misuse intention; (ii) the relationship between deterrent countermeasures and perceived certainty and severity of sanctions is moderated by an individual's computer self-efficacy, computer experience, gender, age, risk propensity, and employment context.

Read the paper · More papers on PaperTik