Cognitive Elaboration on Potential Outcomes and Its Effects on Employees' Information Security Policy Compliance Intention-Exploring the Key Antecedents.

Xue Yang,Wei T. Yue,Choon Lin Sia
DOI: https://doi.org/10.1007/978-3-642-29873-8_17
2012-01-01
Abstract:IS security policy is one of the essential tools to ensure the secure use of information systems and technological assets. To enhance the effectiveness of policy implementation, organizations rely on security training, education and awareness (STEA) programs to help employees understand the IS security issues of the organization. However, different levels of STEA informativeness may have conflicting effects on employees' compliance decisions. In addition, the urgency of a task may also lead employees to abandon the compliance decision occasionally. The existing corporate information security policy (ISP) could also serve as a deterrence message that would influence compliance decisions. An experimental survey was conducted to examine this phenomenon and test the related hypotheses. The results of this study can be used to inform and guide researchers and practitioners as to how to better enforce an IS security policy through better implementation of STEA programs and improved design of ISP in different task scenarios.
What problem does this paper attempt to address?