A Cross Industry Study: Differences in Information Security Policy Compliance between the Banking Industry and Higher Education

Hwee Joo Kam, Pairin Katerattanakul, Greg Gogolin · 2013

This study adopts the Neo-Institutional Theory (NIT) to address the underlying differences in information security policy compliance between the banking industry and higher education. Drawing on the NIT, this study examines how regulative, normative, and cognitive expectations influence the internal organizational efforts of staying compliant across both industries. Using the Partial Least Square (PLS) method, the analysis results suggest that both industries rely on the normative expectation to propel their organizational efforts of attaining compliance. However, the main difference lies within cognitive expectation. In the institution of higher education, cognitive expectation has an indirect effect on information security policies compliance through regulative expectation. On the other hand, cognitive expectation reflects the severity of regulatory pressure in the banking industry. Given these findings, this study presents theoretical implication and provides suggestions to policy makers on the basis of managerial implication.

Read the paper · More papers on PaperTik