Sanction Severity and Employees' Information Security Policy Compliance: Investigating Mediating, Moderating, and Control Variables

Xiaofeng Chen,Dazhong Wu,Liqiang Chen,Joe K. L. Teng
DOI: https://doi.org/10.1016/j.im.2018.05.011
IF: 10.328
2018-01-01
Information & Management
Abstract:Information security policy (ISP) plays a critical role in information systems security management. Past research using General Deterrence Theory (GDT) on employees’ compliance intention (CI) with ISP produced mixed results. We use survey data to investigate how other factors influence the relationship between sanction severity and employees’ CI. The results show that none of the investigated moderating variables interacts with sanction severity on employees’ ISP compliance intentions. However, the significant impact of sanction severity on employees’ ISP CI disappears when the investigated variables are included, and the impact of sanction severity is mediated by perceived efficacy and descriptive norm.
What problem does this paper attempt to address?