{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T15:50:24Z","timestamp":1784735424778,"version":"3.55.0"},"reference-count":127,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2025,3,8]],"date-time":"2025-03-08T00:00:00Z","timestamp":1741392000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,3,8]],"date-time":"2025-03-08T00:00:00Z","timestamp":1741392000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Inf Syst Front"],"published-print":{"date-parts":[[2026,4]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Organizations continue to struggle with motivating employee compliance with information systems (IS) security protocols despite implementing technical and managerial strategies. This study examines the critical role of leadership behaviors in fostering security compliance among employees. We assert that effective leadership can significantly influence adherence to IS security controls. Grounded in expectancy theory, our research model investigates how task-oriented and relationship-oriented leadership behaviors impact perceived security efforts and performance, ultimately shaping expected security outcomes. Data were collected from 407 participants through a cross-sectional survey, and structural equation modeling was employed for analysis. The findings reveal that task-oriented leadership is particularly effective in motivating IS security compliance. Furthermore, individual-level analyses highlight task-oriented leadership as the sole behavior demonstrating a direct relationship with the expected security outcomes of compliance. These insights enrich our understanding of security compliance behaviors as primarily driven by extrinsic motivation. We encourage future research to explore the role of intrinsic motivators and the potential indirect effects of relationship-oriented leadership behaviors on IS security policy compliance. By illuminating the behavioral dynamics of leadership, this study paves the way for organizations to enhance their IS security programs and cultivate a culture of compliance.<\/jats:p>","DOI":"10.1007\/s10796-025-10592-4","type":"journal-article","created":{"date-parts":[[2025,3,8]],"date-time":"2025-03-08T02:14:40Z","timestamp":1741400080000},"page":"449-469","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Does Leadership Approach Matter? Examining Behavioral Influences of Leaders on Employees\u2019 Information Security Compliance"],"prefix":"10.1007","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3135-4699","authenticated-orcid":false,"given":"Gurvirender P.S.","family":"Tejay","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marcus","family":"Winkfield","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,3,8]]},"reference":[{"issue":"12","key":"10592_CR1","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1145\/322796.322806","volume":"42","author":"A Adams","year":"1999","unstructured":"Adams, A., & Sasse, M. A. (1999). Users are not the enemy. Communications of the ACM, 42(12), 40\u201346.","journal-title":"Communications of the ACM"},{"issue":"1","key":"10592_CR3","first-page":"1","volume":"14","author":"S Alter","year":"2004","unstructured":"Alter, S., & Sherer, S. (2004). A general, but readily adaptable model of information system risk. Communications of the Association for Information Systems, 14(1), 1\u201328.","journal-title":"Communications of the Association for Information Systems"},{"issue":"5","key":"10592_CR5","doi-asserted-by":"publisher","first-page":"732","DOI":"10.1037\/0021-9010.76.5.732","volume":"76","author":"JC Anderson","year":"1991","unstructured":"Anderson, J. C., & Gerbing, D. W. (1991). Predicting the performance of measures in a confirmatory factor analysis with a pretest assessment of their substantive validities. Journal of Applied Psychology, 76(5), 732.","journal-title":"Journal of Applied Psychology"},{"issue":"7","key":"10592_CR4","doi-asserted-by":"publisher","first-page":"104015","DOI":"10.1016\/j.im.2024.104015","volume":"61","author":"A Anderson","year":"2024","unstructured":"Anderson, A., Ahmad, A., & Shanton, C. (2024). Case-based learning for cybersecurity leaders: A systematic review and research agenda. Information & Management, 61(7), 104015.","journal-title":"Information & Management"},{"key":"10592_CR2","doi-asserted-by":"publisher","first-page":"437","DOI":"10.1016\/j.chb.2016.12.040","volume":"69","author":"M Anwar","year":"2017","unstructured":"Anwar, M., He, W., Ash, I., Yuan, X., Li, L., & Xu, L. (2017). Gender difference and employees\u2019 cybersecurity behaviors. Computers in Human Behavior, 69, 437\u2013443.","journal-title":"Computers in Human Behavior"},{"issue":"1","key":"10592_CR6","first-page":"19","volume":"22","author":"D Ashenden","year":"2013","unstructured":"Ashenden, D., & Sasse, M. A. (2013). The role of the CISO: A leadership perspective. Information Security Journal: A Global Perspective, 22(1), 19\u201331.","journal-title":"Information Security Journal: A Global Perspective"},{"issue":"1","key":"10592_CR7","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.ejor.2015.12.023","volume":"253","author":"T Aven","year":"2016","unstructured":"Aven, T. (2016). Risk assessment and risk management: Review of recent advances on their foundation. European Journal of Operational Research, 253(1), 1\u201313.","journal-title":"European Journal of Operational Research"},{"issue":"3","key":"10592_CR8","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1080\/08874417.2017.1318687","volume":"59","author":"P Balozian","year":"2019","unstructured":"Balozian, P., Leidner, D., & Warkentin, M. (2019). Managers\u2019 and employees\u2019 differing responses to security approaches. Journal of Computer Information Systems, 59(3), 197\u2013210.","journal-title":"Journal of Computer Information Systems"},{"key":"10592_CR9","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1016\/j.cose.2016.02.007","volume":"59","author":"KA Barton","year":"2016","unstructured":"Barton, K. A., Tejay, G., Lane, M., & Terrell, S. (2016). Information system security commitment: A study of external influences on senior management. Computers & Security, 59, 9\u201325.","journal-title":"Computers & Security"},{"issue":"2","key":"10592_CR10","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1057\/ejis.1991.20","volume":"1","author":"R Baskerville","year":"1991","unstructured":"Baskerville, R. (1991). Risk analysis: An interpretive feasibility tool in justifying information systems security. European Journal of Information Systems, 1(2), 121\u2013130.","journal-title":"European Journal of Information Systems"},{"issue":"5","key":"10592_CR11","doi-asserted-by":"publisher","first-page":"300","DOI":"10.1108\/09685221111188593","volume":"19","author":"D Bhattacharya","year":"2011","unstructured":"Bhattacharya, D. (2011). Leadership styles and information security in small businesses. Information Management & Computer Security, 19(5), 300\u2013312.","journal-title":"Information Management & Computer Security"},{"issue":"1","key":"10592_CR12","doi-asserted-by":"publisher","first-page":"152","DOI":"10.1006\/obhd.1993.1028","volume":"55","author":"G Blau","year":"1993","unstructured":"Blau, G. (1993). Operationalizing direction and level of effort and testing their relationships to individual job performance. Organizational Behavior and Human Decision Processes, 55(1), 152\u2013170.","journal-title":"Organizational Behavior and Human Decision Processes"},{"issue":"5","key":"10592_CR13","doi-asserted-by":"publisher","first-page":"413","DOI":"10.1016\/j.ijinfomgt.2008.02.002","volume":"28","author":"R Bojanc","year":"2008","unstructured":"Bojanc, R., & Bla\u017ei\u010d, B. (2008). An economic modelling approach to information security risk management. International Journal of Information Management, 28(5), 413\u2013422.","journal-title":"International Journal of Information Management"},{"issue":"2","key":"10592_CR14","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1057\/ejis.2009.8","volume":"18","author":"SR Boss","year":"2009","unstructured":"Boss, S. R., Kirsch, L. J., Angermeier, I., Shingler, R. A., & Boss, R. W. (2009). If someone is watching, i\u2019ll do what i\u2019m asked: Mandatoriness, control, and information security. European Journal of Information Systems, 18(2), 151\u2013164.","journal-title":"European Journal of Information Systems"},{"issue":"1","key":"10592_CR15","first-page":"5","volume":"1","author":"X Botong","year":"2021","unstructured":"Botong, X., Feng, X., Luo, X., & Warkentin, M. (2021). Ethical leadership and employee information security policy (ISP) violation: Exploring dual-mediation paths. Organizational Cybersecurity Journal: Practice Process and People, 1(1), 5\u201323.","journal-title":"Organizational Cybersecurity Journal: Practice Process and People"},{"issue":"3","key":"10592_CR16","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1016\/S1754-4548(11)70036-5","volume":"8","author":"D Bradbury","year":"2011","unstructured":"Bradbury, D. (2011). A day in the life of a CISO. Infosecurity, 8(3), 24\u201327.","journal-title":"Infosecurity"},{"issue":"3","key":"10592_CR17","doi-asserted-by":"publisher","first-page":"523","DOI":"10.2307\/25750690","volume":"34","author":"B Bulgurcu","year":"2010","unstructured":"Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523\u2013548.","journal-title":"MIS Quarterly"},{"issue":"6","key":"10592_CR18","doi-asserted-by":"publisher","first-page":"1187","DOI":"10.1111\/deci.12304","volume":"49","author":"AJ Burns","year":"2018","unstructured":"Burns, A. J., Roberts, T. L., Posey, C., Bennett, R. J., & Courtney, J. F. (2018). Intentions to comply versus intentions to protect: A VIE theory approach to Understanding the influence of insiders\u2019 awareness of organizational SETA efforts. Decisions Sciences, 49(6), 1187\u20131228.","journal-title":"Decisions Sciences"},{"issue":"3","key":"10592_CR19","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1080\/07421222.1992.11517973","volume":"9","author":"FG Burton","year":"1992","unstructured":"Burton, F. G., Chen, Y. N., Grover, V., & Stewart, K. A. (1992). An application of expectancy theory for assessing user motivation to utilize an expert system. Journal of Management Information Systems, 9(3), 183\u2013198.","journal-title":"Journal of Management Information Systems"},{"issue":"11\u201312","key":"10592_CR20","doi-asserted-by":"publisher","first-page":"887","DOI":"10.1023\/A:1018880706172","volume":"39","author":"SA Carless","year":"1998","unstructured":"Carless, S. A. (1998). Gender differences in transformational leadership: An examination of superior, leader, and subordinate perspectives. Sex Roles, 39(11\u201312), 887\u2013902.","journal-title":"Sex Roles"},{"key":"10592_CR21","doi-asserted-by":"publisher","first-page":"220","DOI":"10.1016\/j.chb.2014.05.043","volume":"38","author":"L Cheng","year":"2014","unstructured":"Cheng, L., Li, W., Zhai, Q., & Smyth, R. (2014). Understanding personal use of the internet at work: An integrated model of neutralization techniques and general deterrence theory. Computers in Human Behavior, 38, 220\u2013228.","journal-title":"Computers in Human Behavior"},{"issue":"7","key":"10592_CR22","doi-asserted-by":"publisher","first-page":"638","DOI":"10.3390\/su8070638","volume":"8","author":"M Choi","year":"2016","unstructured":"Choi, M. (2016). Leadership of information security manager on the effectiveness of information systems security for secure sustainable computing. Sustainability, 8(7), 638.","journal-title":"Sustainability"},{"key":"10592_CR23","unstructured":"Cleveland, S., & Cleveland, M. (2018). Towards cybersecurity leadership framework. Proceedings of MWAIS 2018, 49."},{"key":"10592_CR24","unstructured":"Coetsee, L. D. (2003). Peak performance and productivity: A practical guide for the creation of a motivating climate. Thomson Learning."},{"issue":"2","key":"10592_CR25","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1197\/jamia.M2195","volume":"14","author":"J Collmann","year":"2007","unstructured":"Collmann, J., & Cooper, T. (2007). Breaching The security of The Kaiser permanente internet patient portal: The organizational foundations of information security. Journal of the American Medical Informatics Association, 14(2), 239\u2013243.","journal-title":"Journal of the American Medical Informatics Association"},{"issue":"6","key":"10592_CR26","doi-asserted-by":"publisher","first-page":"1396","DOI":"10.1111\/isj.12460","volume":"33","author":"WA Cram","year":"2023","unstructured":"Cram, W. A., & D\u2019Arcy, J. (2023). What a waste of time\u2019: An examination of cybersecurity legitimacy. Information Systems Journal, 33(6), 1396\u20131422.","journal-title":"Information Systems Journal"},{"issue":"5","key":"10592_CR27","doi-asserted-by":"publisher","first-page":"474","DOI":"10.1108\/IMCS-08-2013-0057","volume":"22","author":"J D\u2019Arcy","year":"2014","unstructured":"D\u2019Arcy, J., & Greene, G. (2014). Security culture and the employment relationship as drivers of employees\u2019 security compliance. Information Management & Computer Security, 22(5), 474\u2013489.","journal-title":"Information Management & Computer Security"},{"issue":"2","key":"10592_CR28","doi-asserted-by":"publisher","first-page":"196","DOI":"10.1016\/j.cose.2009.09.002","volume":"29","author":"A Da Veiga","year":"2010","unstructured":"Da Veiga, A., & Eloff, J. H. (2010). A framework and assessment instrument for information security culture. Computers & Security, 29(2), 196\u2013207.","journal-title":"Computers & Security"},{"issue":"1","key":"10592_CR29","first-page":"52","volume":"22","author":"ML Dixon","year":"2010","unstructured":"Dixon, M. L., & Hart, L. K. (2010). The impact of path-goal leadership styles on work group effectiveness and turnover intention. Journal of Managerial Issues, 22(1), 52\u201369.","journal-title":"Journal of Managerial Issues"},{"issue":"3","key":"10592_CR30","doi-asserted-by":"publisher","first-page":"31","DOI":"10.4018\/jegr.2010070103","volume":"6","author":"K Dunkerley","year":"2010","unstructured":"Dunkerley, K., & Tejay, G. (2010). Theorizing information security success: Towards secure E-Government. International Journal of Electronic Government Research, 6(3), 31\u201341.","journal-title":"International Journal of Electronic Government Research"},{"key":"10592_CR31","doi-asserted-by":"crossref","unstructured":"Elahi, G., & Yu, E. (2007). A goal oriented approach for modeling and analyzing security trade-offs. Conceptual Modeling-ER 2007. Retrieved from https:\/\/link.springer.com\/chapter\/10.1007\/978-3-540-75563-0_26","DOI":"10.1007\/978-3-540-75563-0_26"},{"issue":"7","key":"10592_CR32","doi-asserted-by":"publisher","first-page":"4332","DOI":"10.1016\/j.asoc.2010.06.005","volume":"11","author":"N Feng","year":"2011","unstructured":"Feng, N., & Li, M. (2011). An information systems security risk assessment model under uncertain environment. Applied Soft Computing, 11(7), 4332\u20134340.","journal-title":"Applied Soft Computing"},{"issue":"5","key":"10592_CR33","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1080\/10658980701746577","volume":"16","author":"T Fitzgerald","year":"2007","unstructured":"Fitzgerald, T. (2007). Clarifying the roles of information security: 13 questions the CEO, CIO, and CISO must ask each other. Information Systems Security, 16(5), 257\u2013263.","journal-title":"Information Systems Security"},{"key":"10592_CR35","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1016\/j.cose.2016.01.004","volume":"59","author":"WR Flores","year":"2016","unstructured":"Flores, W. R., & Ekstedt, M. (2016). Shaping intention to resist social engineering through transformational leadership, information security culture and awareness. Computers & Security, 59, 26\u201344.","journal-title":"Computers & Security"},{"key":"10592_CR34","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1016\/j.cose.2014.03.004","volume":"43","author":"WR Flores","year":"2014","unstructured":"Flores, W. R., Antonsen, E., & Ekstedt, M. (2014). Information security knowledge sharing in organizations: Investigating the effect of behavioral information security governance and National culture. Computers & Security, 43, 90\u2013110.","journal-title":"Computers & Security"},{"issue":"2","key":"10592_CR36","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1361-3723(09)70019-3","volume":"2009","author":"S Furnell","year":"2009","unstructured":"Furnell, S., & Thomson, K. L. (2009). From culture to disobedience: Recognising the varying user acceptance of IT security. Computer Fraud & Security, 2009(2), 5\u201310.","journal-title":"Computer Fraud & Security"},{"issue":"4","key":"10592_CR37","doi-asserted-by":"publisher","first-page":"793","DOI":"10.1007\/s10997-016-9358-0","volume":"21","author":"L Georg","year":"2017","unstructured":"Georg, L. (2017). Information security governance: Pending legal responsibilities of non-executive boards. Journal of Management & Governance, 21(4), 793\u2013814.","journal-title":"Journal of Management & Governance"},{"issue":"2","key":"10592_CR38","doi-asserted-by":"publisher","first-page":"340","DOI":"10.1111\/isj.12202","volume":"29","author":"N Guhr","year":"2019","unstructured":"Guhr, N., Lebek, B., & Breitner, M. H. (2019). The impact of leadership on employees\u2019 intended information security behaviour: An examination of the full-range leadership theory. Information Systems Journal, 29(2), 340\u2013362.","journal-title":"Information Systems Journal"},{"key":"10592_CR39","unstructured":"HairJr., J. F., Black, W. C., Babin, B. J., & Anderson, R. E. (2009). Multivariate data analysis. Pearson Education."},{"issue":"1","key":"10592_CR40","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1108\/09685229610114178","volume":"4","author":"S Halliday","year":"1996","unstructured":"Halliday, S., Badenhorst, K., & Von Solms, R. (1996). A business approach to effective information technology risk analysis and management. Information Management & Computer Security, 4(1), 19\u201331.","journal-title":"Information Management & Computer Security"},{"issue":"2","key":"10592_CR41","doi-asserted-by":"publisher","first-page":"13","DOI":"10.2753\/MIS0742-1222240202","volume":"24","author":"IH Hann","year":"2007","unstructured":"Hann, I. H., Hui, K. L., Lee, S. Y. T., & Png, I. P. (2007). Overcoming online information privacy concerns: An information-processing theory approach. Journal of Management Information Systems, 24(2), 13\u201342.","journal-title":"Journal of Management Information Systems"},{"key":"10592_CR42","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1016\/j.ijinfomgt.2018.07.013","volume":"43","author":"H Haqaf","year":"2018","unstructured":"Haqaf, H., & Koyuncu, M. (2018). Understanding key skills for information security managers. International Journal of Information Management, 43, 165\u2013172.","journal-title":"International Journal of Information Management"},{"issue":"4","key":"10592_CR43","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1080\/2333696X.2008.10855849","volume":"4","author":"S Hazari","year":"2008","unstructured":"Hazari, S., Hargrave, W., & Clenney, B. (2008). An empirical investigation of factors influencing information security behavior. Journal of Information Privacy and Security, 4(4), 3\u201320.","journal-title":"Journal of Information Privacy and Security"},{"issue":"2","key":"10592_CR44","doi-asserted-by":"publisher","first-page":"154","DOI":"10.1016\/j.dss.2009.02.005","volume":"47","author":"T Herath","year":"2009","unstructured":"Herath, T., & Rao, H. R. (2009a). Encouraging information security behaviors in organizations: Role of penalties, pressures and perceived effectiveness. Decision Support Systems, 47(2), 154\u2013165.","journal-title":"Decision Support Systems"},{"issue":"2","key":"10592_CR45","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1057\/ejis.2009.6","volume":"18","author":"T Herath","year":"2009","unstructured":"Herath, T., & Rao, H. R. (2009b). Protection motivation and deterrence: A framework for security policy compliance in organisations. European Journal of Information Systems, 18(2), 106\u2013125.","journal-title":"European Journal of Information Systems"},{"key":"10592_CR127","doi-asserted-by":"crossref","unstructured":"Hinkin, T. R. (1998). A brief tutorial on the development of measures for use in survey questionnaires. Organizational Research Methods, 1, 104\u2013121.","DOI":"10.1177\/109442819800100106"},{"issue":"2","key":"10592_CR46","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1037\/0003-066X.45.2.179","volume":"45","author":"EP Hollander","year":"1990","unstructured":"Hollander, E. P., & Offermann, L. R. (1990). Power and leadership in organizations: Relationships in transition. American Psychologist, 45(2), 179.","journal-title":"American Psychologist"},{"issue":"1","key":"10592_CR47","first-page":"9","volume":"5","author":"JB Holloway","year":"2012","unstructured":"Holloway, J. B. (2012). Leadership behavior and organizational climate: An empirical study in a non-profit organization. Emerging Leadership Journeys, 5(1), 9\u201335.","journal-title":"Emerging Leadership Journeys"},{"key":"10592_CR48","unstructured":"Horenbeeck, M. (2017). The key to better cybersecurity: Keep employee rules simple. Harvard Business Review. Retrieved from https:\/\/hbr.org\/2017\/11\/the-key-to-better-cybersecurity-keep-employee-rules-simple"},{"issue":"3","key":"10592_CR49","doi-asserted-by":"publisher","first-page":"321","DOI":"10.2307\/2391905","volume":"16","author":"RJ House","year":"1971","unstructured":"House, R. J. (1971). A path-goal theory of leader effectiveness. Administrative Science Quarterly, 16(3), 321\u2013339.","journal-title":"Administrative Science Quarterly"},{"key":"10592_CR50","unstructured":"House, R. J., & Dessler, G. (1974). The path-goal theory of leadership: Some post hoc and a priori tests. In J. G. Hunt, & L. L. Larson (Eds.), Contingency approaches to leadership (pp. 29\u201355). Southern Illinois University."},{"issue":"6","key":"10592_CR51","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1145\/1953122.1953142","volume":"54","author":"Q Hu","year":"2011","unstructured":"Hu, Q., Xu, Z., Dinev, T., & Ling, H. (2011). Does deterrence work in reducing information security policy abuse by employees? Communications of the ACM, 54(6), 54\u201360.","journal-title":"Communications of the ACM"},{"issue":"4","key":"10592_CR52","doi-asserted-by":"publisher","first-page":"615","DOI":"10.1111\/j.1540-5915.2012.00361.x","volume":"43","author":"Q Hu","year":"2012","unstructured":"Hu, Q., Dinev, T., Hart, P., & Cooke, D. (2012). Managing employee compliance with information security policies: The critical role of top management and organizational culture. Decision Sciences, 43(4), 615\u2013660.","journal-title":"Decision Sciences"},{"issue":"4","key":"10592_CR53","doi-asserted-by":"publisher","first-page":"6","DOI":"10.1080\/07421222.2014.1001255","volume":"31","author":"Q Hu","year":"2015","unstructured":"Hu, Q., West, R., & Smarandescu, L. (2015). The role of Self-Control in information security violations: Insights from a cognitive neuroscience perspective. Journal of Management Information Systems, 31(4), 6\u201348.","journal-title":"Journal of Management Information Systems"},{"issue":"3","key":"10592_CR54","doi-asserted-by":"publisher","first-page":"755","DOI":"10.1111\/deci.12372","volume":"51","author":"Y Hua","year":"2020","unstructured":"Hua, Y., Cheng, X., Hou, T., & Luo, R. (2020). Monetary rewards, intrinsic motivators, and work engagement in the IT-Enabled sharing economy: A Mixed-Methods investigation of internet taxi drivers. Decision Sciences, 51(3), 755\u2013785.","journal-title":"Decision Sciences"},{"issue":"4","key":"10592_CR55","doi-asserted-by":"publisher","first-page":"311","DOI":"10.7763\/IJIET.2015.V5.522","volume":"5","author":"N Humaidi","year":"2015","unstructured":"Humaidi, N., & Balakrishnan, V. (2015). Leadership styles and information security compliance behavior: The mediator effect of information security awareness. International Journal of Information and Education Technology, 5(4), 311.","journal-title":"International Journal of Information and Education Technology"},{"issue":"1","key":"10592_CR56","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1016\/j.im.2013.10.001","volume":"51","author":"P Ifinedo","year":"2014","unstructured":"Ifinedo, P. (2014). Information systems security policy compliance: An empirical study of the effects of socialisation, influence, and cognition. Information & Management, 51(1), 69\u201379.","journal-title":"Information & Management"},{"key":"10592_CR57","unstructured":"Isaac, R. G., Zerbe, W. J., & Pitt, D. C. (2001). Leadership and motivation: The effective application of expectancy theory. Journal of Managerial Issues, 212\u2013226."},{"issue":"3","key":"10592_CR58","doi-asserted-by":"publisher","first-page":"549","DOI":"10.2307\/25750691","volume":"34","author":"AC Johnston","year":"2010","unstructured":"Johnston, A. C., & Warkentin, M. (2010). Fear appeals and information security behaviors: An empirical study. MIS Quarterly, 34(3), 549\u2013566.","journal-title":"MIS Quarterly"},{"issue":"1","key":"10592_CR59","doi-asserted-by":"publisher","first-page":"113","DOI":"10.25300\/MISQ\/2015\/39.1.06","volume":"39","author":"AC Johnston","year":"2015","unstructured":"Johnston, A. C., Warkentin, M., & Siponen, M. T. (2015). An enhanced fear appeal rhetorical framework: Leveraging threats to the human asset through sanctioning rhetoric. MIS Quarterly, 39(1), 113\u2013134.","journal-title":"MIS Quarterly"},{"issue":"2","key":"10592_CR60","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1016\/j.cose.2004.07.004","volume":"24","author":"B Karabacak","year":"2004","unstructured":"Karabacak, B., & Sogukpinar, I. (2004). ISRAM: Information security risk analysis method. Computers & Security, 24(2), 147\u2013159.","journal-title":"Computers & Security"},{"key":"10592_CR61","unstructured":"Kew, J., Stredwick, J., & Stredwick, J. (2007). Business environment: Managing in a strategic context. Kogan Page."},{"issue":"5","key":"10592_CR62","first-page":"66","volume":"13","author":"KJ Knapp","year":"2012","unstructured":"Knapp, K. J., & Ferrante, C. J. (2012). Policy awareness, enforcement and maintenance: Critical to information security effectiveness in organizations. Journal of Management Policy and Practice, 13(5), 66\u201380.","journal-title":"Journal of Management Policy and Practice"},{"issue":"1","key":"10592_CR63","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1108\/09685220610648355","volume":"14","author":"KJ Knapp","year":"2006","unstructured":"Knapp, K. J., Marshall, T. E., Rainer, K., R., & Ford, N., F (2006). Information security: Management\u2019s effect on culture and policy. Information Management & Computer Security, 14(1), 24\u201336.","journal-title":"Information Management & Computer Security"},{"key":"10592_CR64","first-page":"15","volume":"27","author":"IV Koskosas","year":"2011","unstructured":"Koskosas, I. V., & Asimopoulos, N. (2011). Information system security goals. International Journal of Advanced Science and Technology, 27, 15\u201326.","journal-title":"International Journal of Advanced Science and Technology"},{"key":"10592_CR65","unstructured":"Kotter, J. P. (1990). Force for change: How leadership differs from management. Simon and Schuster."},{"key":"10592_CR66","unstructured":"Kreitner, R., & Kinicki, A. (2007). Organizational behavior. McGraw-Hill Irwin."},{"issue":"4","key":"10592_CR67","doi-asserted-by":"publisher","first-page":"563","DOI":"10.1111\/j.1744-6570.1975.tb01393.x","volume":"28","author":"CH Lawshe","year":"1975","unstructured":"Lawshe, C. H. (1975). A quantitative approach to content validity 1. Personnel Psychology, 28(4), 563\u2013575.","journal-title":"Personnel Psychology"},{"key":"10592_CR68","unstructured":"Lebek, B., Guhr, N., & Breitner, M. (2014). Transformational Leadership and Employees\u2019 Information Security Performance: The Mediating Role of Motivation and Climate. ICIS 2014 Proceedings. Retrieved from http:\/\/aisel.aisnet.org\/icis2014\/proceedings\/ISSecurity\/21"},{"issue":"3","key":"10592_CR69","doi-asserted-by":"publisher","first-page":"739","DOI":"10.17705\/1jais.00678","volume":"22","author":"H Li","year":"2021","unstructured":"Li, H., Luo, X., & Chen, Y. (2021). Understanding information security policy violation from a situational action perspective. Journal of the Association for Information Systems, 22(3), 739\u2013772.","journal-title":"Journal of the Association for Information Systems"},{"issue":"4","key":"10592_CR70","doi-asserted-by":"publisher","first-page":"382","DOI":"10.1177\/02683962231181146","volume":"38","author":"N Liang","year":"2023","unstructured":"Liang, N., Hirschheim, R., Luo, X., & Hollingsworth, H. (2023). Identifying the idiosyncrasies of behavioral information security discourse and proposing future research directions: A foucauldian perspective. Journal of Information Technology, 38(4), 382\u2013415.","journal-title":"Journal of Information Technology"},{"issue":"2","key":"10592_CR71","first-page":"232","volume":"8","author":"SH Liu","year":"2007","unstructured":"Liu, S. H., Liao, H. L., & Zeng, Y. T. (2007). Why people blog: An expectancy theory analysis. Issues in Information Systems, 8(2), 232\u2013237.","journal-title":"Issues in Information Systems"},{"issue":"12","key":"10592_CR72","doi-asserted-by":"publisher","first-page":"43","DOI":"10.1109\/2.889092","volume":"33","author":"TA Longstaff","year":"2000","unstructured":"Longstaff, T. A., Chittister, C., Pethia, R., & Haimes, Y. Y. (2000). Are we forgetting the risks of information technology? Computer, 33(12), 43\u201351.","journal-title":"Computer"},{"issue":"6","key":"10592_CR73","doi-asserted-by":"publisher","first-page":"3757","DOI":"10.1109\/TEM.2020.2996175","volume":"69","author":"J Loonam","year":"2022","unstructured":"Loonam, J., Zwiegelaar, J., Kumar, V., & Booth, C. (2022). Cyber-resiliency for digital enterprises: A strategic leadership perspective. IEEE Transactions on Engineering Management, 69(6), 3757\u20133770.","journal-title":"IEEE Transactions on Engineering Management"},{"issue":"6","key":"10592_CR74","doi-asserted-by":"publisher","first-page":"1552","DOI":"10.17705\/1jais.00646","volume":"21","author":"X Luo","year":"2020","unstructured":"Luo, X., Li, H., Hu, Q., & Xu, H. (2020). Why individual employees commit malicious computer abuse: A routine activity theory perspective. Journal of the Association for Information Systems, 21(6), 1552\u20131593.","journal-title":"Journal of the Association for Information Systems"},{"issue":"3","key":"10592_CR75","doi-asserted-by":"publisher","first-page":"482","DOI":"10.1037\/a0018559","volume":"99","author":"JK Maner","year":"2010","unstructured":"Maner, J. K., & Mead, N. L. (2010). The essential tension between leadership and power: When leaders sacrifice group goals for the sake of self-interest. Journal of Personality and Social Psychology, 99(3), 482.","journal-title":"Journal of Personality and Social Psychology"},{"issue":"1","key":"10592_CR76","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1037\/0021-9010.66.1.54","volume":"66","author":"T Matsui","year":"1981","unstructured":"Matsui, T., Okada, A., & Mizuguchi, R. (1981). Expectancy theory prediction of the goal theory postulate: The harder the goals, the higher the performance. Journal of Applied Psychology, 66(1), 54.","journal-title":"Journal of Applied Psychology"},{"key":"10592_CR77","unstructured":"Merhi, M., & Ahluwalia, P. (2015). Top management can lower resistance toward information security compliance. ICIS 2015 Proceedings. Retrieved from http:\/\/aisel.aisnet.org\/icis2015\/proceedings\/SecurityIS\/3\/"},{"key":"10592_CR78","doi-asserted-by":"crossref","unstructured":"Miller, J., & Doyle, B. A. (1987). Measuring the effectiveness of computer-based information systems in the financial services sector. MIS Quarterly, 107\u2013124.","DOI":"10.2307\/248832"},{"issue":"2","key":"10592_CR79","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1177\/009102600903800203","volume":"38","author":"N Momeni","year":"2009","unstructured":"Momeni, N. (2009). The relation between managers\u2019 emotional intelligence and the organizational climate they create. Public Personnel Management, 38(2), 35\u201348.","journal-title":"Public Personnel Management"},{"issue":"1","key":"10592_CR80","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1093\/jopart\/mur024","volume":"22","author":"DP Moynihan","year":"2012","unstructured":"Moynihan, D. P., Pandey, S. K., & Wright, B. E. (2012). Setting the table: How transformational leadership fosters performance information use. Journal of Public Administration Research and Theory, 22(1), 143\u2013164.","journal-title":"Journal of Public Administration Research and Theory"},{"key":"10592_CR81","unstructured":"Mudd, S. R. (2024). Experiences of Information Security Risk Management Leaders While Building Human Behavioral Factors into Effective ISRM Processes. ProQuest Dissertations & Theses."},{"issue":"3","key":"10592_CR82","doi-asserted-by":"publisher","first-page":"430","DOI":"10.1037\/0033-2909.105.3.430","volume":"105","author":"SA Mulaik","year":"1989","unstructured":"Mulaik, S. A., James, L. R., Van Alstine, J., Bennett, N., Lind, S., & Stilwell, C. D. (1989). Evaluation of goodness-of-fit indices for structural equation models. Psychological Bulletin, 105(3), 430.","journal-title":"Psychological Bulletin"},{"key":"10592_CR83","unstructured":"Munteanu, A. (2006). Information security risk assessment: The qualitative versus quantitative dilemma. Managing Information in the Digital Economy: Issues & Solutions-Proceedings of the 6th International Business Information Management Association Conference."},{"issue":"2","key":"10592_CR84","doi-asserted-by":"publisher","first-page":"126","DOI":"10.1057\/ejis.2009.10","volume":"18","author":"L Myyry","year":"2009","unstructured":"Myyry, L., Siponen, M., Pahnila, S., Vartiainen, T., & Vance, A. (2009). What levels of moral reasoning and values explain adherence to information security rules? An empirical study. European Journal of Information Systems, 18(2), 126\u2013139.","journal-title":"European Journal of Information Systems"},{"key":"10592_CR85","unstructured":"Northouse, P. G. (2016). Leadership: Theory and practice. Sage."},{"key":"10592_CR86","unstructured":"Oladimeji, E. A., Supakkul, S., & Chung, L. (2006). Security threat modeling and analysis: A goal-oriented approach. Proceedings of the 10th IASTED International Conference on Software Engineering and Applications. Retrieved from https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=917767#"},{"issue":"5","key":"10592_CR87","doi-asserted-by":"publisher","first-page":"673","DOI":"10.1016\/j.cose.2012.04.004","volume":"31","author":"K Padayachee","year":"2012","unstructured":"Padayachee, K. (2012). Taxonomy of compliant information security behavior. Computers & Security, 31(5), 673\u2013680.","journal-title":"Computers & Security"},{"issue":"5","key":"10592_CR88","doi-asserted-by":"publisher","first-page":"879","DOI":"10.1037\/0021-9010.88.5.879","volume":"88","author":"PM Podsakoff","year":"2003","unstructured":"Podsakoff, P. M., MacKenzie, S. B., Lee, J. Y., & Podsakoff, N. P. (2003). Common method bias in behavioral research: A critical review of the literature and recommended remedies. Journal of Applied Psychology, 88(5), 879\u2013903.","journal-title":"Journal of Applied Psychology"},{"issue":"1","key":"10592_CR89","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1080\/07421222.1991.11517914","volume":"8","author":"RK Rainer Jr","year":"1991","unstructured":"RainerJr, R. K., Snyder, C. A., & Carr, H. H. (1991). Risk analysis for information technology. Journal of Management Information Systems, 8(1), 129\u2013147.","journal-title":"Journal of Management Information Systems"},{"key":"10592_CR90","doi-asserted-by":"publisher","first-page":"442","DOI":"10.1016\/j.chb.2015.12.037","volume":"57","author":"NS Safa","year":"2016","unstructured":"Safa, N. S., & Von Solms, R. (2016). An information security knowledge sharing model in organizations. Computers in Human Behavior, 57, 442\u2013451.","journal-title":"Computers in Human Behavior"},{"issue":"2","key":"10592_CR91","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1016\/S1361-3723(16)30017-3","volume":"2016","author":"NS Safa","year":"2016","unstructured":"Safa, N. S., Von Solms, R., & Futcher, L. (2016a). Human aspects of information security in organisations. Computer Fraud & Security, 2016(2), 15\u201318.","journal-title":"Computer Fraud & Security"},{"issue":"56","key":"10592_CR92","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1016\/j.cose.2015.10.006","volume":"2016","author":"NS Safa","year":"2016","unstructured":"Safa, N. S., Von Solms, R., & Futcher, L. (2016b). Information security policy compliance model in organizations. Computers & Security, 2016(56), 70\u201382.","journal-title":"Computers & Security"},{"issue":"3","key":"10592_CR93","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1057\/palgrave.jit.2000122","volume":"23","author":"H Salmela","year":"2008","unstructured":"Salmela, H. (2008). Analysing business losses caused by information systems risk: A business process analysis approach. Journal of Information Technology, 23(3), 185\u2013202.","journal-title":"Journal of Information Technology"},{"key":"10592_CR94","unstructured":"Schiff, J. (2013). 7 Biggest IT compliance headaches and how CIOs can cure them. CIO. Retrieved from https:\/\/www.cio.com\/article\/2382445\/compliance\/7-biggest-it-compliance-headaches-and-how-cios-can-cure-them.html"},{"key":"10592_CR95","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1016\/j.cose.2015.11.001","volume":"57","author":"A Shameli-Sendi","year":"2016","unstructured":"Shameli-Sendi, A., Aghababaei-Barzegar, R., & Cheriet, M. (2016). Taxonomy of information security risk assessment. Computers & Security, 57, 14\u201330.","journal-title":"Computers & Security"},{"key":"10592_CR96","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1016\/j.cose.2015.01.002","volume":"49","author":"J Shropshire","year":"2015","unstructured":"Shropshire, J., Warkentin, M., & Sharma, S. (2015). Personality, attitudes, and intentions: Predicting initial adoption of information security behavior. Computers & Security, 49, 177\u2013191.","journal-title":"Computers & Security"},{"key":"10592_CR97","doi-asserted-by":"crossref","unstructured":"Singleton, J. P., McLean, E. R., & Altman, E. N. (1988). Measuring information systems performance: Experience with the management by results system at security Pacific bank. MIS Quarterly, 325\u2013337.","DOI":"10.2307\/248857"},{"issue":"1","key":"10592_CR99","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1108\/09685220010371394","volume":"8","author":"MT Siponen","year":"2000","unstructured":"Siponen, M. T. (2000). A conceptual foundation for organizational information security awareness. Information Management & Computer Security, 8(1), 31\u201341.","journal-title":"Information Management & Computer Security"},{"key":"10592_CR98","doi-asserted-by":"crossref","unstructured":"Siponen, M. T., & Kajava, J. (1998). Ontology of organizational IT security awareness-from theoretical foundations to practical framework. WET ICE 1998 Proceedings. Retrieved from http:\/\/ieeexplore.ieee.org\/document\/725713\/","DOI":"10.1109\/ENABL.1998.725713"},{"key":"10592_CR100","doi-asserted-by":"crossref","unstructured":"Siponen, M., & Vance, A. (2010). Neutralization: New insights into the problem of employee information systems security policy violations. MIS Quarterly, 487\u2013502.","DOI":"10.2307\/25750688"},{"issue":"2","key":"10592_CR101","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1109\/MC.2010.35","volume":"43","author":"M Siponen","year":"2010","unstructured":"Siponen, M., Pahnila, S., & Mahmood, M. A. (2010). Compliance with information security policies: An empirical investigation. Computer, 43(2), 64\u201371.","journal-title":"Computer"},{"key":"10592_CR102","doi-asserted-by":"publisher","first-page":"41","DOI":"10.58729\/1941-6679.1522","volume":"Suppl. Special","author":"R Smit","year":"2021","unstructured":"Smit, R., Hagedoorn, J. M. J., van, Y., Versteeg, P., & Ravesteijn (2021). The soft skills business demands of the chief information security officer. Journal of International Technology and Information Management, Suppl. Special Edition \u2013 Conference Proceedings of IIMA 2021, 41\u201361.","journal-title":"Journal of International Technology and Information Management"},{"issue":"4","key":"10592_CR103","doi-asserted-by":"publisher","first-page":"499","DOI":"10.1111\/j.1540-5915.1994.tb01857.x","volume":"25","author":"KC Snead","year":"1994","unstructured":"Snead, K. C., & Harrell, A. M. (1994). An application of expectancy theory to explain a Manager\u2019s intention to use a decision support system. Decision Sciences, 25(4), 499\u2013510.","journal-title":"Decision Sciences"},{"issue":"7","key":"10592_CR104","doi-asserted-by":"publisher","first-page":"296","DOI":"10.1016\/j.im.2011.07.002","volume":"48","author":"JY Son","year":"2011","unstructured":"Son, J. Y. (2011). Out of fear or Desire?? Toward a better Understanding of employees\u2019 motivation to follow IS security policies. Information & Management, 48(7), 296\u2013302.","journal-title":"Information & Management"},{"key":"10592_CR105","doi-asserted-by":"crossref","unstructured":"Straub, D. W., & Welke, R. J. (1998). Coping with systems risk: Security planning models for management decision making. MIS Quarterly, 441\u2013469.","DOI":"10.2307\/249551"},{"key":"10592_CR106","first-page":"331","volume":"7","author":"MA Talib","year":"2012","unstructured":"Talib, M. A., Barachi, E., Khelif, M., A., & Ormandjieva, O. (2012). Guide to ISO 27001: UAE case study. Issues in Informing Science and Information Technology, 7, 331\u2013349.","journal-title":"Issues in Informing Science and Information Technology"},{"issue":"3","key":"10592_CR107","doi-asserted-by":"publisher","first-page":"103751","DOI":"10.1016\/j.im.2022.103751","volume":"60","author":"G Tejay","year":"2023","unstructured":"Tejay, G., & Mohammed, Z. (2023). Cultivating security culture for information security success: An investigation from anthropological perspective. Information & Management, 60(3), 103751.","journal-title":"Information & Management"},{"issue":"3","key":"10592_CR108","doi-asserted-by":"publisher","first-page":"573","DOI":"10.3390\/jcp2030029","volume":"2","author":"WJ Triplett","year":"2022","unstructured":"Triplett, W. J. (2022). Addressing human factors in cybersecurity leadership. Journal of Cybersecurity and Privacy, 2(3), 573\u2013586.","journal-title":"Journal of Cybersecurity and Privacy"},{"issue":"2","key":"10592_CR109","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1016\/j.jsis.2007.05.003","volume":"16","author":"E Vaast","year":"2007","unstructured":"Vaast, E. (2007). Danger is in the eye of the beholders: Social representations of information systems security in healthcare. The Journal of Strategic Information Systems, 16(2), 130\u2013152.","journal-title":"The Journal of Strategic Information Systems"},{"issue":"3","key":"10592_CR110","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1016\/j.im.2012.04.002","volume":"49","author":"A Vance","year":"2012","unstructured":"Vance, A., Siponen, M., & Pahnila, S. (2012). Motivating IS security compliance: Insights from habit and protection motivation theory. Information & Management, 49(3), 190\u2013198.","journal-title":"Information & Management"},{"issue":"2","key":"10592_CR111","doi-asserted-by":"publisher","first-page":"108","DOI":"10.17705\/1jais.00388","volume":"16","author":"T Verhagen","year":"2015","unstructured":"Verhagen, T., Van Den Hooff, B., & Meents, S. (2015). Toward a better use of the semantic differential in IS research: An integrative framework of suggested action. Journal of the Association for Information Systems, 16(2), 108.","journal-title":"Journal of the Association for Information Systems"},{"key":"10592_CR112","doi-asserted-by":"crossref","unstructured":"Vitale, M. R. (1986). The growing risks of information systems success. MIS Quarterly, 327\u2013334.","DOI":"10.2307\/249185"},{"key":"10592_CR113","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1016\/j.cose.2013.04.004","volume":"38","author":"R Von Solms","year":"2013","unstructured":"Von Solms, R., & Van Niekerk, J. (2013). From information security to cyber security. Computers & Security, 38, 97\u2013102.","journal-title":"Computers & Security"},{"key":"10592_CR114","unstructured":"Vroom, V. (1964). Work and motivation. John Wiley."},{"key":"10592_CR115","unstructured":"Vroom, V. (1995). Work and motivation. John Wiley."},{"issue":"1","key":"10592_CR116","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1016\/j.leaqua.2010.12.009","volume":"22","author":"H Wang","year":"2011","unstructured":"Wang, H., Tsui, A. S., & Xin, K. R. (2011). CEO leadership behaviors, organizational performance, and employees\u2019 attitudes. The Leadership Quarterly, 22(1), 92\u2013105.","journal-title":"The Leadership Quarterly"},{"key":"10592_CR117","doi-asserted-by":"publisher","first-page":"312","DOI":"10.1016\/j.iref.2018.04.003","volume":"58","author":"TS Wang","year":"2018","unstructured":"Wang, T. S., Lin, Y. M., Werner, E. M., & Chang, H. (2018). The relationship between external financing activities and earnings management: Evidence from enterprise risk management. International Review of Economics & Finance, 58, 312\u2013329.","journal-title":"International Review of Economics & Finance"},{"issue":"2","key":"10592_CR118","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1057\/ejis.2009.12","volume":"18","author":"M Warkentin","year":"2009","unstructured":"Warkentin, M., & Willison, R. (2009). Behavioral and policy issues in information systems security: The insider threat. European Journal of Information Systems, 18(2), 101.","journal-title":"European Journal of Information Systems"},{"issue":"3","key":"10592_CR119","first-page":"5","volume":"88","author":"GB Weathersby","year":"1999","unstructured":"Weathersby, G. B. (1999). Leadership vs. management. Management Review, 88(3), 5.","journal-title":"Management Review"},{"key":"10592_CR120","unstructured":"Werner, A. (2002). In P. S. Nel, P. D. Gerber, Van P. S. Dyk, G. D. Haasbroek, H. B. Schultz, T. Sono, & Werner (Eds.), Leadership. Oxford."},{"issue":"8","key":"10592_CR122","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1145\/859670.859675","volume":"46","author":"ME Whitman","year":"2003","unstructured":"Whitman, M. E. (2003). Enemy at the gate: Threats to information security. Communications of the ACM, 46(8), 91\u201395.","journal-title":"Communications of the ACM"},{"issue":"3","key":"10592_CR121","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1080\/08874417.2008.11646017","volume":"48","author":"D Whitten","year":"2008","unstructured":"Whitten, D. (2008). The chief information security officer: An analysis of the skills required for success. Journal of Computer Information Systems, 48(3), 15\u201319.","journal-title":"Journal of Computer Information Systems"},{"issue":"2","key":"10592_CR123","doi-asserted-by":"publisher","first-page":"127","DOI":"10.1057\/ejis.1994.13","volume":"3","author":"L Willcocks","year":"1994","unstructured":"Willcocks, L., & Margetts, H. (1994). Risk assessment and information systems. European Journal of Information Systems, 3(2), 127\u2013138.","journal-title":"European Journal of Information Systems"},{"issue":"1","key":"10592_CR124","doi-asserted-by":"publisher","first-page":"1","DOI":"10.25300\/MISQ\/2013\/37.1.01","volume":"37","author":"R Willison","year":"2013","unstructured":"Willison, R., & Warkentin, M. (2013). Beyond deterrence: An expanded view of employee computer abuse. MIS Quarterly, 37(1), 1\u201320.","journal-title":"MIS Quarterly"},{"key":"10592_CR125","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1016\/j.dss.2016.09.009","volume":"92","author":"A Yazdanmehr","year":"2016","unstructured":"Yazdanmehr, A., & Wang, J. (2016). Employees\u2019 information security policy compliance: A norm activation perspective. Decision Support Systems, 92, 36\u201346.","journal-title":"Decision Support Systems"},{"issue":"4","key":"10592_CR126","doi-asserted-by":"publisher","first-page":"10","DOI":"10.5120\/ijca2016910239","volume":"144","author":"D Zainudin","year":"2016","unstructured":"Zainudin, D., Hamid, T., & Ur-Rahman, A. (2016). Leadership by example in e-government security management system. International Journal of Computer Applications, 144(4), 10\u201317.","journal-title":"International Journal of Computer Applications"}],"container-title":["Information Systems Frontiers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10796-025-10592-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10796-025-10592-4","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10796-025-10592-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,25]],"date-time":"2026-05-25T08:02:15Z","timestamp":1779696135000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10796-025-10592-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,8]]},"references-count":127,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,4]]}},"alternative-id":["10592"],"URL":"https:\/\/doi.org\/10.1007\/s10796-025-10592-4","relation":{},"ISSN":["1387-3326","1572-9419"],"issn-type":[{"value":"1387-3326","type":"print"},{"value":"1572-9419","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,8]]},"assertion":[{"value":"15 February 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 March 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Authors received study-specific approval by the Institutional Review Board and informed consent from the research participants.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics Approval and Consent to Participate"}},{"value":"All authors give explicit consent to submit and publication of this work.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for Publication"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing Interests"}}]}}