{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T19:52:15Z","timestamp":1771876335445,"version":"3.50.1"},"reference-count":40,"publisher":"Emerald","issue":"6","license":[{"start":{"date-parts":[[2008,6,27]],"date-time":"2008-06-27T00:00:00Z","timestamp":1214524800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2008,6,27]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>This paper aims to improve understanding of individuals' awareness and perceptions of computer usage policies (CUPs) and why individuals elect not to read these policies.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>MBA students were asked to complete an online survey evaluating their behavioral intention to read CUPs, as well as their performance of this behavior. Factors contributing to the intention to read policies were also examined. The resulting data were analyzed with Smart PLS.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>Results suggest that three factors influence individual intention to read CUPs. These factors include attitude, apathy, and social trust. The model explained about 70 percent of individual intention to read CUPs and about 44 percent of the variability in actually reading these policies.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Research limitations\/implications<\/jats:title><jats:p>The sample is limited to MBA students from a single university.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>Although written policy statements are often considered the cornerstone of computer security, many individuals elect not to read these policies. Thus, other methods of communication must be used.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>This paper examines the reasons individuals elect not to read CUPs. Given the importance of these policies as deterrents to information systems misuse and computer crime, understanding why individuals fail to read policies is a critical first step in enhancing user knowledge of computer security.<\/jats:p><\/jats:sec>","DOI":"10.1108\/02635570810883969","type":"journal-article","created":{"date-parts":[[2008,8,16]],"date-time":"2008-08-16T07:45:23Z","timestamp":1218872723000},"page":"701-712","source":"Crossref","is-referenced-by-count":36,"title":["Why users (fail to) read computer usage policies"],"prefix":"10.1108","volume":"108","author":[{"given":"C.","family":"Bryan Foltz","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul H.","family":"Schwager","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"John E.","family":"Anderson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022021420132763800_b1","unstructured":"Ajzen, I. (1988), Attitudes, Personality, and Behavior, The Dorsey Press, Chicago, IL."},{"key":"key2022021420132763800_b2","doi-asserted-by":"crossref","unstructured":"Ajzen, I. (1991), \u201cThe theory of planned behavior\u201d, Organizational Behavior and Human Decision Processes, Vol. 50 No. 2, pp. 179\u2010211.","DOI":"10.1016\/0749-5978(91)90020-T"},{"key":"key2022021420132763800_b3","unstructured":"Anthes, G.H. (1996), \u201cHack attack: cyberthieves siphon millions from US firms\u201d, Computerworld, Vol. 30 No. 16, p. 81."},{"key":"key2022021420132763800_b4","unstructured":"Assembly Committee on Criminal Procedure (State of California) (1975), \u201cPublic knowledge of criminal penalties\u201d, in Henshel, R.L. and Silverman, R.A. (Eds), Perception in Criminology, Columbia University Press, New York, NY, pp. 74\u201090."},{"key":"key2022021420132763800_b5","doi-asserted-by":"crossref","unstructured":"Backhouse, J. and Dhillon, G. (1995), \u201cManaging computer crime: a research outlook\u201d, Computers and Security, Vol. 14 No. 7, pp. 645\u201051.","DOI":"10.1016\/0167-4048(95)00024-0"},{"key":"key2022021420132763800_b6","doi-asserted-by":"crossref","unstructured":"Beck, L. and Ajzen, I. (1991), \u201cPredicting dishonest actions using the theory of planned behavior\u201d, Journal of Research in Personality, Vol. 25 No. 3, pp. 285\u2010301.","DOI":"10.1016\/0092-6566(91)90021-H"},{"key":"key2022021420132763800_b7","unstructured":"Blumstein, A., Cohen, J. and Nagin, D. (Eds) (1978), Deterrence and Incapacitation: Estimating the Effects of Criminal Sanctions on Crime Rates, National Academy of Sciences, Washington, DC."},{"key":"key2022021420132763800_b8","unstructured":"Breakey, P. (2007), \u201cDelaware board sets computer\u2010use policy\u201d, Knight Ridder Tribune Business News, October 11, available at: www.thedailystar.com\/archivesearch\/local_story_ 284040041.html (accessed April 4, 2008)."},{"key":"key2022021420132763800_b9","unstructured":"Brodwater, T. (2007), \u201cFirefighters put on suspension: technician finds sexual images on Timberlake district's computers\u201d, Knight Ridder Tribune Business News, April 11, p. 1."},{"key":"key2022021420132763800_b10","unstructured":"Buikhuisen, W. (1974), \u201cGeneral deterrence: research and theory\u201d, Abstracts on Criminology and Penology, Vol. 14 No. 3, pp. 285\u20108."},{"key":"key2022021420132763800_b11","unstructured":"Cook, K.S. (Ed.) (2001), Trust in Society, Russell Sage Foundation, New York, NY."},{"key":"key2022021420132763800_b12","doi-asserted-by":"crossref","unstructured":"Doll, J. and Ajzen, I. (1992), \u201cAccessibility and stability of predictors in the theory of planned behavior\u201d, Journal of Personality and Social Psychology, Vol. 63 No. 5, pp. 754\u201064.","DOI":"10.1037\/0022-3514.63.5.754"},{"key":"key2022021420132763800_b13","doi-asserted-by":"crossref","unstructured":"Earle, T. and Cvetkovich, G. (1995), Social Trust: Toward a Cosmopolitan Society, Praeger, Westport, CT.","DOI":"10.5040\/9798216016113"},{"key":"key2022021420132763800_b14","unstructured":"Flickes, M. (2004), \u201cBehind the numbers: the FBI cyber\u2010crime survey results\u201d, Government Security web site, http:\/\/govtsecurity.com\/mag\/behind_numbers_fbi\/ (accessed August 1, 2004)."},{"key":"key2022021420132763800_b15","unstructured":"Foltz, C.B., Anderson, J.E. and Schwager, P.H. (2007), \u201cFactors influencing awareness of computer usage policies\u201d, Proceedings of the Southwest Decision Sciences Institute, San Diego, CA, pp. 243\u201052."},{"key":"key2022021420132763800_b16","unstructured":"Foltz, C.B., Cronan, T.P. and Jones, T.W. (2004), \u201cStudent awareness of university computer usage policies: is a single exposure enough?\u201d, Proceedings of the Southwest Decision Sciences Institute, Orlando, FL, pp. 293\u20109."},{"key":"key2022021420132763800_b17","doi-asserted-by":"crossref","unstructured":"Fornell, C. and Larcker, D. (1981), \u201cEvaluating structural equation models with unobservable variables and measurement error\u201d, Journal of Marketing Research, Vol. 18, pp. 89\u201098.","DOI":"10.2307\/3151312"},{"key":"key2022021420132763800_b18","unstructured":"Gordon, L.A., Loeb, M.P., Lucyshyn, W. and Richardson, R. (2006), \u201c2006 CSI\/FBI computer crime and security survey\u201d, Computer Security Journal, Vol. 22 No. 3, pp. 1\u201021."},{"key":"key2022021420132763800_b20","unstructured":"Heiser, J. (2002), \u201cGo figure\u201d, Information Security, April, p. 26."},{"key":"key2022021420132763800_b21","unstructured":"Holmes, J. (2003), \u201cFormulating an effective computer use policy\u201d, Information Strategy: The Executive's Journal, Vol. 20 No. 1, pp. 26\u201033."},{"key":"key2022021420132763800_b22","unstructured":"Klette, H. (1975), \u201cSome minimum requirements for legal sanctioning systems with special emphasis on detection\u201d, General Deterrence: A Conference on Current Research and Standpoints, National Swedish Council for Crime Prevention, Stockholm, pp. 12\u201059."},{"key":"key2022021420132763800_b23","doi-asserted-by":"crossref","unstructured":"Krause, M. and Tipton, H.F. (Eds) (1998), Handbook of Information Security Management, Auerbach, Boca Raton, FL.","DOI":"10.1201\/1079\/43275.26.3.19980901\/31739.5"},{"key":"key2022021420132763800_b24","doi-asserted-by":"crossref","unstructured":"Lee, J. and Lee, Y. (2002), \u201cA holistic model of computer abuse within organizations\u201d, Information Management & Computer Security, Vol. 10 No. 2, pp. 57\u201063.","DOI":"10.1108\/09685220210424104"},{"key":"key2022021420132763800_b25","doi-asserted-by":"crossref","unstructured":"Leonard, L.N.K. and Cronan, T.P. (2005), \u201cAttitude toward ethical behavior in computer use: a shifting model\u201d, Industrial Management & Data Systems, Vol. 105 No. 9, pp. 1150\u201071.","DOI":"10.1108\/02635570510633239"},{"key":"key2022021420132763800_b26","unstructured":"Lindquist, C.D. (2008), \u201cCommentary: use of employer's e\u2010mail in attorney\u2010client communication raises privilege concerns\u201d, Daily Record, January 3, p. 1."},{"key":"key2022021420132763800_b27","doi-asserted-by":"crossref","unstructured":"Madden, T.J., Ellen, P.S. and Ajzen, I. (1992), \u201cA comparison of the theory of planned behavior and the theory of reasoned action\u201d, Personality and Social Psychology Bulletin, Vol. 18 No. 1, pp. 3\u20109.","DOI":"10.1177\/0146167292181001"},{"key":"key2022021420132763800_b28","unstructured":"Nagin, D. (1978), \u201cGeneral deterrence: a review of the empirical evidence\u201d, Deterrence and Incapacitation: Estimating the Effects of Criminal Sanctions on Crime Rates, National Academy of Sciences, Washington, DC, pp. 93\u2010139."},{"key":"key2022021420132763800_b29","unstructured":"Nunnally, J. (1978), Psychometric Theory, 2nd ed., McGraw\u2010Hill, New York, NY."},{"key":"key2022021420132763800_b30","doi-asserted-by":"crossref","unstructured":"Robert, P.H., Clairet, S., Benoit, M., Koutaich, J., Bertogliati, C., Tible, O., Caci, H., Borg, M., Brocker, P. and Bedoucha, P. (2002), \u201cThe apathy inventory: assessment of apathy and awareness in Alzheimer's disease, Parkinson's disease and mild cognitive impairment\u201d, International Journal of Geriatric Psychiatry, Vol. 17 No. 12, pp. 1099\u2010105.","DOI":"10.1002\/gps.755"},{"key":"key2022021420132763800_b31","unstructured":"Romney, M. (1995), \u201cComputer fraud \u2013 what can be done about it?\u201d, The CPA Journal, Vol. 65 No. 5, pp. 30\u20103."},{"key":"key2022021420132763800_b32","doi-asserted-by":"crossref","unstructured":"Scott, T. and Voss, R. (1994), \u201cEthics and the 7 \u2018P's\u2019 of computer use policies\u201d, Proceedings of the Conference on Ethics in the Computer Age, Gatlinburg, TN, pp. 61\u20107.","DOI":"10.1145\/199544.199588"},{"key":"key2022021420132763800_b33","doi-asserted-by":"crossref","unstructured":"Siegrist, M. (2000), \u201cThe influence of trust and perceptions of risks and benefits on the acceptance of gene technology\u201d, Risk Analysis, Vol. 20 No. 2, pp. 195\u2010203.","DOI":"10.1111\/0272-4332.202020"},{"key":"key2022021420132763800_b34","doi-asserted-by":"crossref","unstructured":"Siegrist, M. and Cvetkovich, G. (2000), \u201cPerception of hazards: the role of social trust and knowledge\u201d, Risk Analysis, Vol. 20 No. 5, pp. 713\u20109.","DOI":"10.1111\/0272-4332.205064"},{"key":"key2022021420132763800_b35","doi-asserted-by":"crossref","unstructured":"Siegrist, M., Cvetkovich, G. and Roth, C. (2000), \u201cSalient value similarity, social trust, and risk\/benefit perception\u201d, Risk Analysis, Vol. 20 No. 3, pp. 353\u201062.","DOI":"10.1111\/0272-4332.203034"},{"key":"key2022021420132763800_b36","unstructured":"Straub, D.W. (1986), \u201cDeterring computer abuse: the effectiveness of deterrent countermeasures in the computer security environment\u201d, dissertation, Graduate School of Business, Indiana University, Bloomington, IN."},{"key":"key2022021420132763800_b37","unstructured":"Straub, D.W. (1987), \u201cControlling computer abuse: an empirical study of effective security countermeasures\u201d, Proceedings of the International Conference on Information Systems, pp. 277\u201089."},{"key":"key2022021420132763800_b38","doi-asserted-by":"crossref","unstructured":"Straub, D.W. and Nance, W.D. (1990), \u201cDiscovering and disciplining computer abuse in organizations: a field study\u201d, MIS Quarterly, Vol. 14 No. 1, pp. 45\u201060.","DOI":"10.2307\/249307"},{"key":"key2022021420132763800_b39","doi-asserted-by":"crossref","unstructured":"Taylor, S. and Todd, P.A. (1995), \u201cUnderstanding information technology usage: a test of competing models\u201d, Information Systems Research, Vol. 6 No. 2, pp. 144\u201076.","DOI":"10.1287\/isre.6.2.144"},{"key":"key2022021420132763800_b40","doi-asserted-by":"crossref","unstructured":"Vankatesh, V., Morris, M., Davis, G. and Davis, F. (2003), \u201cUser acceptance of information technology: toward a unified view\u201d, MIS Quarterly, Vol. 27 No. 3, pp. 425\u201078.","DOI":"10.2307\/30036540"},{"key":"key2022021420132763800_frd1","doi-asserted-by":"crossref","unstructured":"Haines, R. and Leonard, L.N.K. (2007), \u201cIndividual characteristics and ethical decision\u2010making in an IT context\u201d, Industrial Management & Data Systems, Vol. 107 No. 1, pp. 5\u201020.","DOI":"10.1108\/02635570710719025"}],"container-title":["Industrial Management &amp; Data Systems"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/02635570810883969","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/02635570810883969\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/02635570810883969\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T23:38:03Z","timestamp":1753400283000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/imds\/article\/108\/6\/701-712\/187112"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,6,27]]},"references-count":40,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2008,6,27]]}},"alternative-id":["10.1108\/02635570810883969"],"URL":"https:\/\/doi.org\/10.1108\/02635570810883969","relation":{},"ISSN":["0263-5577"],"issn-type":[{"value":"0263-5577","type":"print"}],"subject":[],"published":{"date-parts":[[2008,6,27]]}}}