{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,19]],"date-time":"2025-11-19T22:31:45Z","timestamp":1763591505984,"version":"3.40.3"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030335816"},{"type":"electronic","value":"9783030335823"}],"license":[{"start":{"date-parts":[[2019,11,2]],"date-time":"2019-11-02T00:00:00Z","timestamp":1572652800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-33582-3_76","type":"book-chapter","created":{"date-parts":[[2019,11,1]],"date-time":"2019-11-01T07:46:34Z","timestamp":1572594394000},"page":"810-818","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["A Model of Information Security Policy Compliance for Public Universities: A Conceptual Model"],"prefix":"10.1007","author":[{"family":"Angraini","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rose Alinda","family":"Alias","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"family":"Okfalisa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,11,2]]},"reference":[{"key":"76_CR1","doi-asserted-by":"publisher","first-page":"887","DOI":"10.1016\/j.im.2017.01.003","volume":"54","author":"F B\u00e9langer","year":"2017","unstructured":"B\u00e9langer, F., Collignon, S., Enget, K., Negangard, E.: Information & management determinants of early conformance with information security policies. Inf. Manag. 54, 887\u2013901 (2017)","journal-title":"Inf. Manag."},{"key":"76_CR2","doi-asserted-by":"publisher","first-page":"52","DOI":"10.1016\/j.cose.2016.12.016","volume":"66","author":"JY Han","year":"2017","unstructured":"Han, J.Y., Kim, Y.J., Kim, H.: An integrative model of information security policy compliance with psychological contract: examining a bilateral perspective. Comput. Secur. 66, 52\u201365 (2017)","journal-title":"Comput. Secur."},{"key":"76_CR3","doi-asserted-by":"crossref","unstructured":"Pahnila, S., Siponen, M., Mahmood, A.: Which factors explain employees\u2019 adherence to information security policies? An empirical study. In: Pacis 2007 Proceedings, pp. 438\u2013439 (2007)","DOI":"10.1007\/978-0-387-72367-9_12"},{"key":"76_CR4","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1016\/j.im.2013.08.006","volume":"51","author":"M Siponen","year":"2014","unstructured":"Siponen, M., Adam Mahmood, M., Pahnila, S.: Employees\u2019 adherence to information security policies: an exploratory field study. Inf. Manag. 51, 217\u2013224 (2014)","journal-title":"Inf. Manag."},{"key":"76_CR5","doi-asserted-by":"crossref","unstructured":"Nasir, A., Arshah, R.A., Ab Hamid, M.R.: Information security policy compliance behavior based on comprehensive dimensions of information security culture. In: Proceedings of 2017 International Conference on Information System and Data Mining. - ICISDM 2017, pp. 56\u201360 (2017)","DOI":"10.1145\/3077584.3077593"},{"key":"76_CR6","unstructured":"Abed, J., Dhillon, G., Ozkan, S.: Investigating continuous security compliance behavior\u202f: insights from information systems continuance model. In: Twenty-second Americas Conference on Information Systems, San Diego, pp. 1\u201310 (2016)"},{"key":"76_CR7","first-page":"311","volume":"5","author":"N Humaidi","year":"2015","unstructured":"Humaidi, N., Balakrishnan, V.: Leadership styles and information security compliance behavior: the mediator effect of information security awareness. Int. J. Inf. Educ. Technol. 5, 311\u2013318 (2015)","journal-title":"Int. J. Inf. Educ. Technol."},{"key":"76_CR8","doi-asserted-by":"publisher","first-page":"348","DOI":"10.1108\/ITP-08-2016-0194","volume":"31","author":"NF Doherty","year":"2018","unstructured":"Doherty, N.F., Tajuddin, S.T.: Towards a user-centric theory of value-driven information security compliance. Inf. Technol. People 31, 348\u2013367 (2018)","journal-title":"Inf. Technol. People"},{"key":"76_CR9","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1108\/OIR-11-2015-0358","volume":"41","author":"I Hwang","year":"2017","unstructured":"Hwang, I., Kim, D., Kim, T., Kim, S.: Why not comply with information security? An empirical approach for the causes of non-compliance. Online Inf. Rev. 41, 2\u201318 (2017)","journal-title":"Online Inf. Rev."},{"key":"76_CR10","volume-title":"Cyber Warfare Techniques, Tactics and Tools for Security Practitioners","author":"J Andress","year":"2014","unstructured":"Andress, J., Winterfeld, S.: Cyber Warfare Techniques, Tactics and Tools for Security Practitioners, vol. 2. Elsevier Inc., Waltham (2014)"},{"key":"76_CR11","doi-asserted-by":"publisher","first-page":"132","DOI":"10.1080\/19393551003657019","volume":"19","author":"C Gikas","year":"2010","unstructured":"Gikas, C.: A general comparison of FISMA, HIPAA, ISO 27000 and PCI-DSS standards. Inf. Secur. J. Glob. Perspect. 19, 132\u2013141 (2010)","journal-title":"Inf. Secur. J. Glob. Perspect."},{"key":"76_CR12","doi-asserted-by":"crossref","unstructured":"Katz, F.H.: The effect of a university information security survey on instruction methods in information security. In: Proceedings of 2nd Annual Conference on Information Security Curriculum Development, pp. 43\u201348 (2005)","DOI":"10.1145\/1107622.1107633"},{"key":"76_CR13","first-page":"85","volume":"11","author":"R Ayyagari","year":"2012","unstructured":"Ayyagari, R., Tyks, J.: Disaster at a university: a case study in information security. J. Inf. Technol. Educ. Innov. Pract. 11, 85\u201396 (2012)","journal-title":"J. Inf. Technol. Educ. Innov. Pract."},{"key":"76_CR14","unstructured":"BS ISO\/IEC: ISO 27001 - Information Technology Security Techniques Information Security Management Systems, Requirements (2005)"},{"key":"76_CR15","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1108\/IMCS-08-2012-0045","volume":"22","author":"T Sommestad","year":"2014","unstructured":"Sommestad, T., Hallberg, J., Lundholm, K., Bengtsson, J.: Variables influencing information security policy compliance: a systematic review of quantitative studies. Inf. Manag. Comput. Secur. 22, 42\u201375 (2014)","journal-title":"Inf. Manag. Comput. Secur."},{"key":"76_CR16","unstructured":"NIST: Glossary of Key Information Security Terms [NISTIR 7298 Rev 2] (2013)"},{"key":"76_CR17","volume-title":"It Governance an International Guide to Data Security and ISO 27001\/ISO27002","author":"A Calder","year":"2015","unstructured":"Calder, A., Watkins, S.: It Governance an International Guide to Data Security and ISO 27001\/ISO27002, vol. 6. Kopan Page, UK (2015)"},{"key":"76_CR18","volume-title":"Information Security Policy Development for Compliance","author":"L Barry","year":"2013","unstructured":"Barry, L.: Information Security Policy Development for Compliance. CRC Press\/Taylor & Francis Group, Boca Raton (2013)"},{"key":"76_CR19","doi-asserted-by":"crossref","unstructured":"Ross, R.S.: Assessing security and privacy controls in federal information systems and organizations: building effective assessment plans, pp. 1\u2013487. NIST Special Publication (2014)","DOI":"10.6028\/NIST.SP.800-53Ar4"},{"key":"76_CR20","first-page":"1","volume":"00","author":"T Sommestad","year":"2017","unstructured":"Sommestad, T., Karlz\u00e9n, H., Hallberg, J.: The theory of planned behavior and information security policy compliance. J. Comput. Inf. Syst. 00, 1\u201310 (2017)","journal-title":"J. Comput. Inf. Syst."},{"key":"76_CR21","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1016\/j.cose.2012.09.010","volume":"32","author":"RE Crossler","year":"2013","unstructured":"Crossler, R.E., Johnston, A.C., Lowry, P.B., Hu, Q., Warkentin, M., Baskerville, R.: Future directions for behavioral information security research. Comput. Secur. 32, 90\u2013101 (2013)","journal-title":"Comput. Secur."},{"key":"76_CR22","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1016\/j.cose.2004.01.012","volume":"23","author":"C Vroom","year":"2004","unstructured":"Vroom, C., Von Solms, R.: Towards information security behavioural compliance. Comput. Secur. 23, 191\u2013198 (2004)","journal-title":"Comput. Secur."},{"key":"76_CR23","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1016\/S0268-4012(02)00105-6","volume":"23","author":"A Kankanhalli","year":"2003","unstructured":"Kankanhalli, A., Teo, H.H., Tan, B.C.Y., Wei, K.K.: An integrative study of information systems security effectiveness. Int. J. Inf. Manag. 23, 139\u2013154 (2003)","journal-title":"Int. J. Inf. Manag."},{"key":"76_CR24","unstructured":"Chang, S.E.: Organizational factors to the effectiveness of implementing information security management (2006)"},{"issue":"3","key":"76_CR25","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1111\/isj.12063","volume":"25","author":"PB Lowry","year":"2015","unstructured":"Lowry, P.B., Posey, C., Bennett, R.B.J., Roberts, T.L.: Leveraging fairness and reactance theories to deter reactive computer abuse following enhanced organisational information security policies: an empirical study of the influence of counterfactual reasoning and organisational trust. Inf. Syst. J. 25(3), 193\u2013273 (2015)","journal-title":"Inf. Syst. J."},{"key":"76_CR26","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1108\/ICS-09-2016-0073","volume":"26","author":"KA Alshare","year":"2018","unstructured":"Alshare, K.A., Lane, P.L., Lane, M.R.: Information security policy compliance: a higher education case study. Inf. Comput. Secur. 26, 91\u2013108 (2018)","journal-title":"Inf. Comput. Secur."},{"key":"76_CR27","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1016\/j.ijinfomgt.2009.05.003","volume":"29","author":"NF Doherty","year":"2009","unstructured":"Doherty, N.F., Anastasakis, L., Fulford, H.: The information security policy unpacked: a critical study of the content of university policies. Int. J. Inf. Manag. 29, 449\u2013457 (2009)","journal-title":"Int. J. Inf. Manag."},{"key":"76_CR28","doi-asserted-by":"crossref","unstructured":"Hina, S., Dominic, D.D.: Information security policies: investigation of compliance in universities. In: 2016 3rd International Conference on Computer and Information Sciences. In: Proceedings, ICCOINS 2016, pp 564\u2013569 (2016)","DOI":"10.1109\/ICCOINS.2016.7783277"},{"key":"76_CR29","doi-asserted-by":"publisher","first-page":"264","DOI":"10.1177\/0013916502250134","volume":"35","author":"S Bamberg","year":"2003","unstructured":"Bamberg, S., Schmidt, P.: Incentives, morality, or habit? Predicting students\u2019 car use for University routes with the models of Ajzen, Schwartz, and Triandis. Environ. Behav. 35, 264\u2013285 (2003)","journal-title":"Environ. Behav."},{"key":"76_CR30","doi-asserted-by":"publisher","first-page":"285","DOI":"10.25300\/MISQ\/2018\/13853","volume":"42","author":"GD Moody","year":"2018","unstructured":"Moody, G.D., Siponen, M., Pahnila, S.: Toward a unified model of information security policy compliance. MIS Q. 42, 285\u2013311 (2018)","journal-title":"MIS Q."},{"key":"76_CR31","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cose.2015.10.006","volume":"56","author":"N Sohrabi Safa","year":"2016","unstructured":"Sohrabi Safa, N., Von Solms, R., Furnell, S.: Information security policy compliance model in organizations. Comput. Secur. 56, 1\u201313 (2016)","journal-title":"Comput. Secur."},{"key":"76_CR32","unstructured":"Gerber, N., McDermott, R., Volkamer, M., Vogt, J.: Understanding information security compliance - why goal setting and rewards might be a bad idea. In: International Symposium on Information Assurance and Security, HAISA 2016, vol. 10, pp. 145\u2013155 (2016)"},{"key":"76_CR33","doi-asserted-by":"publisher","first-page":"523","DOI":"10.2307\/25750690","volume":"34","author":"B Bulgurcu","year":"2010","unstructured":"Bulgurcu, B., Cavusoglu, H., Benbasat, I.: Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness. MIS Q. 34, 523\u2013548 (2010)","journal-title":"MIS Q."},{"key":"76_CR34","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1108\/ICS-09-2017-0066","volume":"26","author":"M Kajtazi","year":"2018","unstructured":"Kajtazi, M., Cavusoglu, H., Benbasat, I., Haftor, D.: Escalation of commitment as an antecedent to noncompliance with information security policy. Inf. Comput. Secur. 26, 171\u2013193 (2018)","journal-title":"Inf. Comput. Secur."},{"key":"76_CR35","doi-asserted-by":"crossref","unstructured":"Sharma, S., Warkentin, M.: Do I really belong? Impact of employment status on information security policy compliance. Comput. Secur. (2018)","DOI":"10.1016\/j.cose.2018.09.005"},{"key":"76_CR36","doi-asserted-by":"crossref","unstructured":"Sommestad, T.: Social groupings and information security obedience within organizations. In: International Federation for Information Processing, pp. 325\u2013338 (2015)","DOI":"10.1007\/978-3-319-18467-8_22"},{"key":"76_CR37","unstructured":"Arage, T., Belanger, F., Beshah, T.: Influence of national culture on employees\u2019 compliance with information systems security (ISS) policies: towards ISS culture in Ethiopian companies. In: AMCIS 2015 Proceedings, pp. 1\u20137 (2015)"},{"key":"76_CR38","doi-asserted-by":"publisher","first-page":"420","DOI":"10.1108\/ICS-09-2017-0063","volume":"26","author":"E Amankwa","year":"2018","unstructured":"Amankwa, E., Loock, M., Kritzinger, E.: Establishing information security policy compliance culture in organizations. Inf. Comput. Secur. 26, 420\u2013436 (2018)","journal-title":"Inf. Comput. Secur."},{"key":"76_CR39","doi-asserted-by":"crossref","unstructured":"Kajtazi, M., Bulgurcu, B., Cavusoglu, H., Benbasat, I.: Assessing sunk cost effect on employees\u2019 intentions to violate information security policies in organizations. In: Proceedings of Annual Hawaii International Conference on System Sciences, pp. 3169\u20133177 (2014)","DOI":"10.1109\/HICSS.2014.393"},{"key":"76_CR40","doi-asserted-by":"publisher","first-page":"200","DOI":"10.1108\/ICS-04-2014-0025","volume":"23","author":"T Sommestad","year":"2015","unstructured":"Sommestad, T., Karlz\u00e9n, H., Hallberg, J.: The sufficiency of the theory of planned behavior for explaining information security policy compliance. Inf. Comput. Secur. 23, 200\u2013217 (2015)","journal-title":"Inf. Comput. Secur."},{"key":"76_CR41","doi-asserted-by":"publisher","first-page":"218","DOI":"10.1016\/j.cose.2017.02.006","volume":"66","author":"S Aurigemma","year":"2017","unstructured":"Aurigemma, S., Mattson, T.: Privilege or procedure: evaluating the effect of employee status on intent to comply with socially interactive information security threats and controls. Comput. Secur. 66, 218\u2013234 (2017)","journal-title":"Comput. Secur."},{"key":"76_CR42","doi-asserted-by":"publisher","unstructured":"Sikolia, D., Twitchell, D., Sagers, G.: Employees\u2019 adherence to information security policies: a partial replication. In: Proceedings of the Americas Conference on Information Systems, pp. 1\u20139 (2016). \n                    https:\/\/doi.org\/10.1109\/ICMTMA.2009.433","DOI":"10.1109\/ICMTMA.2009.433"}],"container-title":["Advances in Intelligent Systems and Computing","Emerging Trends in Intelligent Computing and Informatics"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-33582-3_76","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,11,1]],"date-time":"2019-11-01T17:12:39Z","timestamp":1572628359000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-33582-3_76"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,11,2]]},"ISBN":["9783030335816","9783030335823"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-33582-3_76","relation":{},"ISSN":["2194-5357","2194-5365"],"issn-type":[{"type":"print","value":"2194-5357"},{"type":"electronic","value":"2194-5365"}],"subject":[],"published":{"date-parts":[[2019,11,2]]},"assertion":[{"value":"2 November 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"IRICT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference of Reliable Information and Communication Technology","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Johor","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Malaysia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 September 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"irict2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/irict.co\/irict2019\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}