Factors That Influence Employees’ Security Policy Compliance: An Awareness-Motivation-Capability Perspective

Xiaofeng Chen,Liqiang Chen,Dazhong Wu
DOI: https://doi.org/10.1080/08874417.2016.1258679
2016-12-27
Journal of Computer Information Systems
Abstract:Information security policy (ISP) plays an important role in information security management in organizations. Past research investigated various factors that may impact employee behavior toward security policy compliance from the perspective of general deterrence theory (GDT), protection and motivation Theory (PMT), and rational choice theory (RCT). However, there is no unifying foundation/framework that examines all of those factors in a harmonic way so that the research findings can guide information security practices and research into the employee ISP compliance management context. Additionally, prior findings provided mixed results. This study proposes a research model based on the awareness-motivation-capability (AMC) framework, aiming to unify the factors to predict employee ISP compliance intention. We believe that a harmonic approach in managing employee ISP compliance can create optimal outcomes.
computer science, information systems
What problem does this paper attempt to address?