The Role of Punishment and Task Dissonance in Information Security Policies Compliance

Mohammad I. Merhi, Punit Ahluwalia · Journal of the Association for Information Systems · 2014

This paper defines and empirically tests a new construct called “task dissonance.” In doing so, it bridges an important gap in the literature. Research on information security compliance has examined several factors and theories from many reference disciplines; however no study has presented this concept. The fact that information security policies increase the task complexity creates a mental dissonance in employees which negatively affects their compliance behavior. Organizational punishment factors namely certainty of control and severity are also examined in this research. The hypotheses are confirmed using ANOVA analytical procedures and the findings are reported. We discuss the results and their implications for researchers and practitioners.

Read the paper · More papers on PaperTik