{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T03:54:44Z","timestamp":1776830084973,"version":"3.51.2"},"reference-count":36,"publisher":"Emerald","issue":"4","license":[{"start":{"date-parts":[[2009,10,9]],"date-time":"2009-10-09T00:00:00Z","timestamp":1255046400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009,10,9]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>The purpose of this paper based on compensation theory, is to incorporate perceived technical security protection into the theory of planned behavior and examined factors affecting end\u2010user security behaviors, specifically, compliance with security policies.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>An online survey is conducted to validate the proposed research model. The survey is sent out to an industrial panel. A total of 176 usable responses are received and used in the data analysis.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>The results show that both perceived behavioral control (PBC) and attitude have significant impact on intention to comply with security policy. Perceived technical protection affects behavioral intentions both indirectly, through PBC, and directly. The negative direct effect (i.e. perceived high technical protection leads to low intention to comply with security policy) suggests possible risk compensation effects in the information security context.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>This result should be of interest to practitioners. In practice (e.g. during security training), the power and capability of technical protection mechanisms should not be exaggerated. Instead, its limitations and drawbacks should be emphasized, so that end\u2010users will adopt more cautious security practices and adhere to the requirements of the organization's security policies.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>This paper embeds risk compensation theory within the security policy compliance context and offers a useful starting point for further empirical examination of this theory in information security context.<\/jats:p><\/jats:sec>","DOI":"10.1108\/09685220910993980","type":"journal-article","created":{"date-parts":[[2009,10,5]],"date-time":"2009-10-05T11:12:04Z","timestamp":1254741124000},"page":"330-340","source":"Crossref","is-referenced-by-count":89,"title":["Impact of perceived technical protection on security behaviors"],"prefix":"10.1108","volume":"17","author":[{"given":"Jie","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Brian J.","family":"Reithel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Han","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022021020293023600_b1","unstructured":"Adams, J. (1999), Cars, Cholera, and Cows: The Management of Risk and Uncertainty, available at: www.cato.org\/pubs\/pas\/pa335.pdf (accessed April 6, 2009)."},{"key":"key2022021020293023600_b2","doi-asserted-by":"crossref","unstructured":"Ajzen, I. (1985), \u201cFrom intentions to action: a theory of planned behavior\u201d, in Kukl, J. and Beckman, J. (Eds), Action Control: From Cognitions to Behaviors, Springer, New York, NY, pp. 11\u201039.","DOI":"10.1007\/978-3-642-69746-3_2"},{"key":"key2022021020293023600_b3","doi-asserted-by":"crossref","unstructured":"Ajzen, I. (1991), \u201cThe theory of planned behavior\u201d, Organizational Behavior and Human Decision Processes, Vol. 50 No. 2, pp. 179\u2010211.","DOI":"10.1016\/0749-5978(91)90020-T"},{"key":"key2022021020293023600_b4","doi-asserted-by":"crossref","unstructured":"Ajzen, I. (2002), \u201cPerceived behavioral control, self\u2010efficacy, locus of control, and the theory of planned behavior\u201d, Journal of Applied Social Psychology, Vol. 32 No. 4, pp. 665\u201083.","DOI":"10.1111\/j.1559-1816.2002.tb00236.x"},{"key":"key2022021020293023600_b5","doi-asserted-by":"crossref","unstructured":"Armitage, C.J. and Conner, M. (1999a), \u201cDistinguishing perceptions of control from self\u2010efficacy: predicting consumption of a low\u2010fat diet using the theory of planned behavior\u201d, Journal of Applied Social Psychology, Vol. 29 No. 1, pp. 72\u201090.","DOI":"10.1111\/j.1559-1816.1999.tb01375.x"},{"key":"key2022021020293023600_b6","doi-asserted-by":"crossref","unstructured":"Armitage, C.J. and Conner, M. (1999b), \u201cThe theory of planned behaviour: assessment of predictive validity and \u2018perceived control\u2019\u201d, British Journal of Social Psychology, Vol. 38 No. 1, pp. 35\u201054.","DOI":"10.1348\/014466699164022"},{"key":"key2022021020293023600_b7","doi-asserted-by":"crossref","unstructured":"Bagozzi, R.P. and Yi, Y. (1988), \u201cOn the evaluation of structural equation models\u201d, Journal of the Academy of Marketing Science, Vol. 16 No. 1, pp. 74\u201094.","DOI":"10.1007\/BF02723327"},{"key":"key2022021020293023600_b8","doi-asserted-by":"crossref","unstructured":"Campbell, K., Gordon, L.A., Loeb, M.P. and Zhou, L. (2003), \u201cThe economic cost of publicly announced information security breaches: empirical evidence from the stock market\u201d, Journal of Computer Security, Vol. 11 No. 3, pp. 431\u201048.","DOI":"10.3233\/JCS-2003-11308"},{"key":"key2022021020293023600_b9","doi-asserted-by":"crossref","unstructured":"Chin, W.W., Marcolin, B.L. and Newsted, P.R. (2003), \u201cA partial least squares latent variable modeling approach for measuring interaction effects: results from a Monte Carlo simulation study and an electronic mail adoption study\u201d, Information Systems Research, Vol. 14 No. 2, pp. 189\u2010217.","DOI":"10.1287\/isre.14.2.189.16018"},{"key":"key2022021020293023600_b10","unstructured":"DTT (2009), Protecting What Matters: The 6th Annual Global Security Survey, available at: www.deloitte.com\/dtt\/cda\/doc\/content\/dtt_fsi_GlobalSecuritySurvey_0901.pdf (accessed April 6, 2009)."},{"key":"key2022021020293023600_b11","doi-asserted-by":"crossref","unstructured":"Fornell, C. and Larcker, D. (1981), \u201cEvaluating structural equation models with unobservable variables and measurement error\u201d, Journal of Marketing Research, Vol. 18 No. 1, pp. 39\u201050.","DOI":"10.1177\/002224378101800104"},{"key":"key2022021020293023600_b12","doi-asserted-by":"crossref","unstructured":"Fosser, S., Saetermo, I. and Sagberg, F. (1997), \u201cAn investigation of behavioral adaptation to airbags and antilock brakes among taxi drivers\u201d, Accident Analysis and Prevention, Vol. 29 No. 3, pp. 293\u2010302.","DOI":"10.1016\/S0001-4575(96)00083-8"},{"key":"key2022021020293023600_b13","doi-asserted-by":"crossref","unstructured":"Gefen, D. and Straub, D. (2005), \u201cA practical guide to factorial validity using PLS\u2010Graph: Tutorial and annotated example\u201d, Communications of the AIS, Vol. 16 No. 5, pp. 91\u2010109.","DOI":"10.17705\/1CAIS.01605"},{"key":"key2022021020293023600_b14","doi-asserted-by":"crossref","unstructured":"Hawkins, S., Yen, D.C. and Chou, D.C. (2000), \u201cAwareness and challenges of internet security\u201d, Information Management & Computer Security, Vol. 8 No. 3, pp. 131\u201043.","DOI":"10.1108\/09685220010372564"},{"key":"key2022021020293023600_b15","doi-asserted-by":"crossref","unstructured":"Hillhouse, J.J., Adler, C.M., Drinnon, J. and Turrist, R. (1997), \u201cApplication of Ajzen's theory of planned behavior to predict sunbathing, tanning salon use, and sunscreen use intentions and behaviors\u201d, Journal of Behavioral Medicine, Vol. 20 No. 4, pp. 365\u201078.","DOI":"10.1023\/A:1025517130513"},{"key":"key2022021020293023600_b16","doi-asserted-by":"crossref","unstructured":"Lau, V.C.S., Au, W.T. and Ho, J.M.C. (2003), \u201cA qualitative and quantitative review of antecedents of counterproductive behavior in organizations\u201d, Journal of Business and Psychology, Vol. 18 No. 1, pp. 73\u201099.","DOI":"10.1023\/A:1025035004930"},{"key":"key2022021020293023600_b17","doi-asserted-by":"crossref","unstructured":"Lee, J. and Lee, Y. (2002), \u201cA holistic model of computer abuse within organizations\u201d, Information Management & Computer Security, Vol. 10 No. 2, pp. 57\u201063.","DOI":"10.1108\/09685220210424104"},{"key":"key2022021020293023600_b19","unstructured":"McCumber, J. (1991), \u201cInformation systems security: a comprehensive model\u201d, Proceedings of the 14th National Computer Security Conference, Baltimore, MD."},{"key":"key2022021020293023600_b18","unstructured":"Maconachy, W.V., Schou, C.D., Ragsdale, D. and Welch, D. (2001), \u201cA model for information assurance: an integrated approach\u201d, Proceedings of the 2001 IEEE Workshop on Information Assurance and Security, United State Military Academy, IEEE, West Point, NY, pp. 306\u201010."},{"key":"key2022021020293023600_b20","doi-asserted-by":"crossref","unstructured":"Ng, B.Y., Kankanhalli, A. and Xu, Y.C. (2008), \u201cStudying users' computer security behavior: a health belief perspective\u201d, Decision Support Systems, Vol. 46 No. 4, pp. 815\u201025.","DOI":"10.1016\/j.dss.2008.11.010"},{"key":"key2022021020293023600_b21","doi-asserted-by":"crossref","unstructured":"Pahnila, S., Siponen, M. and Mahmood, A. (2007), \u201cEmployees' behavior towards IS security policy compliance\u201d, Proceedings of the 40th Hawaii International Conference on System Sciences, 2007, IEEE, Hawaii.","DOI":"10.1109\/HICSS.2007.206"},{"key":"key2022021020293023600_b22","unstructured":"Parker, D.B. (1983), Fighting Computer Crime, Scribner, New York, NY."},{"key":"key2022021020293023600_b23","doi-asserted-by":"crossref","unstructured":"Peltzman, S. (1975), \u201cThe effects of automobile safety regulation\u201d, Journal of Political Economy, Vol. 83 No. 4, pp. 677\u2010725.","DOI":"10.1086\/260352"},{"key":"key2022021020293023600_b24","doi-asserted-by":"crossref","unstructured":"Randall, D.M. and Gibson, A.M. (1991), \u201cEthical decision making in the medical profession: an application of the theory of planned behavior\u201d, Journal of Business Ethics, Vol. 10 No. 2, pp. 111\u201022.","DOI":"10.1007\/BF00383614"},{"key":"key2022021020293023600_b25","doi-asserted-by":"crossref","unstructured":"Schlarman, S. (2001), \u201cThe people, policy, technology (PPT) model: core elements of the security process\u201d, Information Security Journal, Vol. 10 No. 5, pp. 1\u20106.","DOI":"10.1201\/1086\/43315.10.5.20011101\/31719.6"},{"key":"key2022021020293023600_b26","doi-asserted-by":"crossref","unstructured":"Siponen, M.T. (2000), \u201cA conceptual foundation for organizational information security awareness\u201d, Information Management & Computer Security, Vol. 8 No. 1, pp. 31\u201041.","DOI":"10.1108\/09685220010371394"},{"key":"key2022021020293023600_b27","doi-asserted-by":"crossref","unstructured":"Siponen, M.T. (2001), \u201cFive dimensions of information security awareness\u201d, ACM SIGCAS Computers and Society, Vol. 31 No. 2, pp. 24\u20109.","DOI":"10.1145\/503345.503348"},{"key":"key2022021020293023600_b28","unstructured":"Spruit, M.E.M. (1998), \u201cCompeting against human failing\u201d, Proceedings of the IFIP TC11 14th International Conference on Information Security (SEC '98), Vienna\/Budapest."},{"key":"key2022021020293023600_b29","unstructured":"Stanton, J.M., Mastrangelo, P.R., Stam, K.R. and Jolton, J. (2004), \u201cBehavioral information security: two end user survey studies of motivation and security practices\u201d, Proceedings of the Tenth Americas Conference on Information Systems, New York, NY."},{"key":"key2022021020293023600_b30","doi-asserted-by":"crossref","unstructured":"Stewart, A. (2004), \u201cOn risk: perception and direction\u201d, Computers & Security, Vol. 23 No. 5, pp. 362\u201070.","DOI":"10.1016\/j.cose.2004.05.003"},{"key":"key2022021020293023600_b31","doi-asserted-by":"crossref","unstructured":"Thomson, M.E. and von Solms, R. (1998), \u201cInformation security awareness: educating your users effectively\u201d, Information Management & Computer Security, Vol. 6 No. 4, pp. 167\u201073.","DOI":"10.1108\/09685229810227649"},{"key":"key2022021020293023600_b32","unstructured":"van Ryn, M. and Vinokur, A.D. (1990), \u201cThe role of experimentally manipulated self\u2010efficacy in determining job\u2010search behavior among the unemployed\u201d, unpublished manuscript, Institute for Social Research, University of Michigan, Ann Arbor, MI."},{"key":"key2022021020293023600_b33","doi-asserted-by":"crossref","unstructured":"Venkatesh, V. and Davis, F.D. (2000), \u201cA theoretical extension of the technology acceptance model: four longitudinal field studies\u201d, Management Science, Vol. 46 No. 2, pp. 186\u2010204.","DOI":"10.1287\/mnsc.46.2.186.11926"},{"key":"key2022021020293023600_b34","doi-asserted-by":"crossref","unstructured":"von Solms, R. and von Solms, B. (2004), \u201cFrom policies to culture\u201d, Computers & Security, Vol. 23 No. 4, pp. 275\u20109.","DOI":"10.1016\/j.cose.2004.01.013"},{"key":"key2022021020293023600_b35","doi-asserted-by":"crossref","unstructured":"West, R. (2008), \u201cThe psychology of security\u201d, Communications of the ACM, Vol. 51 No. 4, pp. 34\u201040.","DOI":"10.1145\/1330311.1330320"},{"key":"key2022021020293023600_b36","doi-asserted-by":"crossref","unstructured":"Workman, M. and Gathegi, J. (2007), \u201cPunishment and ethics deterrents: a study of insider security contravention\u201d, Journal of the American Society for Information Science and Technology, Vol. 58 No. 2, pp. 212\u201022.","DOI":"10.1002\/asi.20474"}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/09685220910993980","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685220910993980\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685220910993980\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:09:10Z","timestamp":1753402150000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/17\/4\/330-340\/179714"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,10,9]]},"references-count":36,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2009,10,9]]}},"alternative-id":["10.1108\/09685220910993980"],"URL":"https:\/\/doi.org\/10.1108\/09685220910993980","relation":{},"ISSN":["0968-5227"],"issn-type":[{"value":"0968-5227","type":"print"}],"subject":[],"published":{"date-parts":[[2009,10,9]]}}}