Employee ISP Compliance Intentions: An Empirical Test of Empowerment

Yurita Yakimin Abdul Talib, Gurpreet S. Dhillon · International Conference on Information Systems · 2015

Incidents of computer abuse, proprietary information leaks and other security lapses have been on an increase. Most often, such security lapses are attributed to internal employees in organizations subverting established organizational information security policy (ISP). As employee compliance with ISP is the key to escalating information security breaches, understanding employee motivation for following ISP is critical. Using the Thomas and Velthouse’s (1990) intrinsic motivation model, we investigate the role of intrinsic motivation for ISP compliance. Through survey data collected from 289 participants, the study assesses how psychological empowerment, as derived from information security task, may impact the information security performance of the participants, which is measured by their compliance with ISP. The study demonstrates that the psychological empowerment has a positive impact on participants’ ISP compliance intention. Furthermore, the psychological empowerment can be predicted by structural empowerment practices, particularly security education, training, and awareness (SETA), access to information security strategy and goals, and participation in information security decision-making. In addition, the psychological empowerment may act as a mediator for the relations between structural empowerment practices and participants’ ISP compliance. Theoretical contributions, managerial implications, and directions for future research of this study are discussed.

Read the paper · More papers on PaperTik