Measuring employees’ compliance – the importance of value pluralism

Fredrik Karlsson, Martin Karlsson, Joachim Åström · Information and Computer Security · 2017

Purpose This paper aims to investigate two different types of compliance measures: the first measure is a value-monistic compliance measure, whereas the second is a value-pluralistic measure, which introduces the idea of competing organisational imperatives. Design/methodology/approach A survey was developed using two sets of items to measure compliance. The survey was sent to 600 white-collar workers and analysed through ordinary least squares. Findings The results suggest that when using the value-monistic measure, employees’ compliance was a function of employees’ intentions to comply, their self-efficacy and awareness of information security policies. In addition, compliance was not related to the occurrence of conflicts between information security and other organisational imperatives. However, when the dependent variable was changed to a value-pluralistic measure, the results suggest that employees’ compliance was, to a great extent, a function of the occurrence of conflicts between information security and other organisational imperatives, indirect conflicts with other organisational values. Research limitations/implications The results are based on small survey; yet, the findings are interesting and justify further investigation. The results suggest that relevant organisational imperatives and value systems, along with information security values, should be included in measures for employees’ compliance with information security policies. Practical implications Practitioners and researchers should be aware that there is a difference in measuring employees’ compliance using value monistic and value pluralism measurements. Originality/value Few studies exist that critically compare the two different compliance measures for the same population.

Read the paper · More papers on PaperTik