Benefit vs Cost:Examining Factors of Intention to Comply Information Security Policy

Norisan Abd Karim, Jasber Kaur, Muhammad Naquib Khalib · 2021

Cybersecurity risk remains a challenge since it's attributed from human negligence or error due to lack of compliance with policies and procedures. Information security policy underlines roles, responsibilities, guidelines and rules for employees to protect information and technological resources that encompass the intellectual capital of organizations. Information security policy protects knowledge and information in terms of confidentiality, integrity and availability. This study aims to investigate factors that influence compliance behaviour of information security policy in a public sector agency. Grounded from the theory of planned behaviour, rational choice and innovation diffusion theory, we derived a research model on employee's decision to comply (or not to comply) based on individual-based-belief. We adopted the quantitative design to gather data using survey questionnaire distributed to employees at the agency. The results of study shows that perceived cost of non-compliance and compliance significantly influence attitude towards compliance of information security policy. Future recommendation is further proposed at the end this paper.

Read the paper · More papers on PaperTik