INFORMATION SECURITY POLICY COMPLIANCE: THE ROLE OF FAIRNESS, COMMITMENT, AND COST BELIEFS
Burcu Bulgurcu, Hasan Cavusoglu, Izak Benbasat · Journal of the Association for Information Systems · 2011
This research aims to extend our knowledge of the factors that drive an employee to comply with requirements of the Information Security Policy (ISP) of her organization in regards to protecting its information and technology resources.In particular, this paper focuses on the organizational costs associated with an employee's ISP compliance and non-compliance.An employee's organizationbased cost beliefs-perceived organizational cost of compliance and perceived organizational cost of non-compliance-are posited to affect his attitude towards compliance.Furthermore, we discuss two organizational factors-ISP Fairness and Organizational Commitment-as moderators posited to change the strength of the impact of organization-based beliefs on attitude.Based on the regression analysis of data collected from 460 participants, the results show that organization-based employee beliefs significantly affect attitude, and as predicted, the strength of each belief-attitude relationship is affected by ISP fairness and organizational commitment.We also show that the proposed moderator factors have significant main affects on attitude.