A Self-Regulatory Approach to Behavioral Compliance with IS Security Policies - "Come on, Baby, do the Locomotion" Research-in-Progress
Michaela Luecke, Judith C. Simon · 2014
It has been widely accepted that the user of an information system (IS) is the weakest link in information security violations. The insider threat has become a topic of increasing interest for organizations as well as in the information security literature. While information security policies to enforce security procedures are being implemented, their long term effectiveness is unclear. Organizations do not follow standard procedures in controlling for employees’ compliance with security policies and past research has focused primarily on the prediction of compliance intention, not actual compliance behavior. We are addressing this problem by introducing the theory of self-regulation and the theory of self-determination to identify what factors cause some individuals to maintain compliance with security policies and others not, and what roles motivation and organizational reward and punishment structures play in the initiation and retention of security compliance behavior. We propose a longitudinal experiment to test our hypotheses.