Empowerment or Control: Reconsidering Employee Security Policy Compliance in Terms of Authorization
Soohyun Jeon, Anat Hovav · 2015
Preventing security breaches against information asset is one of the key concerns that face an organization. Organizations create information security policies (ISP) to protect information assets against internal misuse. Yet, it is unclear how organizations motivate users to comply with such policies. While existing studies have focused on control-based (administrator controlled) ISP, our study examines user compliance with empowermentbased (user-controlled) ISP. The study aims to compare users' compliance determinants between control-based ISP and empowerment-based ISP. We propose a research model and report the results of a pilot test, expected findings, and study contributions.