Original Article
European Journal of Information Systems (2009) 18, 106–125; doi:10.1057/ejis.2009.6; published online 21 April 2009
Protection motivation and deterrence: a framework for security policy compliance in organisations
Tejaswini Herath1 and H Raghav Rao2,3
- 1Department of Finance, Operations and Information Systems, Brock University, Canada
- 2Management Science and Systems, School of Management, The State University of New York at Buffalo, U.S.A.
- 3Computer Science and Engineering, College of Engineering, The State University of New York at Buffalo, U.S.A.
Correspondence: Tejaswini Herath, Department of Finance, Operations and Information Systems, Brock University, St. Catharines ON L2S 3A1, Canada. Tel: +905 688 5550, ext. 4179; Fax: +905 378 5723; E-mail: teju.herath@brocku.ca
Received 21 February 2008; Revised 15 August 2008; Re-revised 31 January 2009; Accepted 23 February 2009; Published online 21 April 2009.
Abstract
Enterprises establish computer security policies to ensure the security of information resources; however, if employees and end-users of organisational information systems (IS) are not keen or are unwilling to follow security policies, then these efforts are in vain. Our study is informed by the literature on IS adoption, protection-motivation theory, deterrence theory, and organisational behaviour, and is motivated by the fundamental premise that the adoption of information security practices and policies is affected by organisational, environmental, and behavioural factors. We develop an Integrated Protection Motivation and Deterrence model of security policy compliance under the umbrella of Taylor-Todd's Decomposed Theory of Planned Behaviour. Furthermore, we evaluate the effect of organisational commitment on employee security compliance intentions. Finally, we empirically test the theoretical model with a data set representing the survey responses of 312 employees from 78 organisations. Our results suggest that (a) threat perceptions about the severity of breaches and response perceptions of response efficacy, self-efficacy, and response costs are likely to affect policy attitudes; (b) organisational commitment and social influence have a significant impact on compliance intentions; and (c) resource availability is a significant factor in enhancing self-efficacy, which in turn, is a significant predictor of policy compliance intentions. We find that employees in our sample underestimate the probability of security breaches.
Keywords:
security policy compliance, protection motivation, deterrence, organisational commitment
MORE ARTICLES LIKE THIS
These links to content published by Palgrave Macmillan are automatically generated.
RESEARCH
Protection motivation and deterrence: a framework for security policy compliance in organisationsEuropean Journal of Information Systems Original Article
Threat or coping appraisal: determinants of SMB executives? decision to adopt anti-malware softwareEuropean Journal of Information Systems Original Article
If someone is watching, I'll do what I'm asked: mandatoriness, control, and information securityEuropean Journal of Information Systems Original Article
What levels of moral reasoning and values explain adherence to information security rules? An empirical studyEuropean Journal of Information Systems Original Article
See all 39 matches for Research


