{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T15:50:21Z","timestamp":1784735421484,"version":"3.55.0"},"reference-count":51,"publisher":"Emerald","issue":"4","license":[{"start":{"date-parts":[[2018,10,8]],"date-time":"2018-10-08T00:00:00Z","timestamp":1538956800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ICS"],"published-print":{"date-parts":[[2018,10,8]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title><jats:p>This paper aims to establish that employees\u2019 non-compliance with information security policy (ISP) could be addressed by nurturing ISP compliance culture through the promotion of factors such as supportive organizational culture, end-user involvement and compliance leadership to influence employees\u2019 attitudes and behaviour intentions towards ISP in organizations. This paper also aims to develop a testable research model that might be useful for future researchers in predicting employees\u2019 behavioural intentions.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title><jats:p>In view of the study\u2019s aim, a research model to show how three key constructs can influence the attitudes and behaviours of employees towards the establishment of security policy compliance culture (ISPCC) was developed and validated in an empirical field survey.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Findings<\/jats:title><jats:p>The study found that factors such as supportive organizational culture and end-user involvement significantly influenced employees\u2019 attitudes towards compliance with ISP. However, leadership showed the weakest influence on attitudes towards compliance. The overall results showed that employees\u2019 attitudes and behavioural intentions towards ISP compliance together influenced the establishment of ISPCC for ISP compliance in organizations.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Practical implications<\/jats:title><jats:p>Organizations should influence employees\u2019 attitudes towards compliance with ISP by providing effective ISP leadership, encouraging end-user involvement during the draft and update of ISP and nurturing a culture that is conducive for ISP compliance.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title><jats:p>The study provides some insights on how to effectively address the problem of non-compliance with ISP in organizations through the establishment of ISPCC, which has not been considered in any past research.<\/jats:p><\/jats:sec>","DOI":"10.1108\/ics-09-2017-0063","type":"journal-article","created":{"date-parts":[[2018,9,18]],"date-time":"2018-09-18T19:06:18Z","timestamp":1537297578000},"page":"420-436","source":"Crossref","is-referenced-by-count":38,"title":["Establishing information security policy compliance culture in organizations"],"prefix":"10.1108","volume":"26","author":[{"given":"Eric","family":"Amankwa","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marianne","family":"Loock","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Elmarie","family":"Kritzinger","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","reference":[{"key":"key2022100508503058400_ref001","doi-asserted-by":"crossref","first-page":"567","DOI":"10.1016\/j.chb.2015.03.054","article-title":"Design and validation of information security culture framework","volume":"49","year":"2015","journal-title":"Computers in Human Behavior"},{"issue":"2","key":"key2022100508503058400_ref002","first-page":"540","article-title":"A framework of information security culture change","volume":"64","year":"2014","journal-title":"Journal of Theoretical and Applied Information Technology"},{"issue":"2","key":"key2022100508503058400_ref003","doi-asserted-by":"crossref","first-page":"104","DOI":"10.7763\/IJSSH.2014.V4.327","article-title":"A conceptual model to understand information security culture","volume":"4","year":"2014","journal-title":"International Journal of Social Science and Humanity"},{"key":"key2022100508503058400_ref004","first-page":"352","article-title":"Information security policies: a review of challenges and influencing factors","volume-title":"The 11th International Conference for Internet Technology and Secured Transactions (ICITST-2016) Information","year":"2016"},{"issue":"4","key":"key2022100508503058400_ref005","first-page":"195","article-title":"Information security management: a human challenge?","volume":"13","year":"2009","journal-title":"Info. Secur. Tech. Rep"},{"key":"key2022100508503058400_ref006","first-page":"125","article-title":"User involvement in software development and system success: a systematic literature review","year":"2013"},{"issue":"3","key":"key2022100508503058400_ref007","doi-asserted-by":"crossref","first-page":"438","DOI":"10.1108\/02635570710734316","article-title":"Exploring organizational culture for information security management","volume":"107","year":"2007","journal-title":"Industrial Management and Data Systems"},{"issue":"2","key":"key2022100508503058400_ref008","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1287\/isre.14.2.189.16018","article-title":"A partial least squares latent variable modeling approach for measuring interaction effects: results from a monte carlo simulation study and an electronic-mail emotion\/adoption study","volume":"14","year":"2003","journal-title":"Information Systems Research"},{"key":"key2022100508503058400_ref009","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1016\/j.cose.2012.09.010","article-title":"Future directions for behavioural information security research","volume":"32","year":"2013","journal-title":"Computers and Security"},{"issue":"2","key":"key2022100508503058400_ref010","doi-asserted-by":"crossref","first-page":"139","DOI":"10.1108\/ICS-12-2015-0048","article-title":"Comparing the information security culture of employees who had read the information security policy and those who had not illustrated through an empirical study","volume":"24","year":"2016","journal-title":"Information and Computer Security"},{"issue":"2","key":"key2022100508503058400_ref011","doi-asserted-by":"crossref","first-page":"196","DOI":"10.1016\/j.cose.2009.09.002","article-title":"A framework and assessment instrument for information security culture","volume":"29","year":"2010","journal-title":"Computers and Security"},{"key":"key2022100508503058400_ref012","volume-title":"Information Security Culture and Information Protection Culture: A Validated Assessment Instrument","year":"2015"},{"issue":"1","key":"key2022100508503058400_ref013","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1177\/002224298905300102","article-title":"Organizational culture and marketing defining the research agenda","volume":"53","year":"1989","journal-title":"Journal of Marketing"},{"issue":"1","key":"key2022100508503058400_ref014","first-page":"39","article-title":"Evaluating structural equations models with unobservable variables and measurement error","volume":"8","year":"1981","journal-title":"Journal of Marketing Research"},{"issue":"2","key":"key2022100508503058400_ref015","doi-asserted-by":"crossref","first-page":"139","DOI":"10.2753\/MTP1069-6679190202","article-title":"PLS-SEM: indeed a silver bullet","volume":"19","year":"2011","journal-title":"Journal of Marketing Theory and Practice"},{"key":"key2022100508503058400_ref016","volume-title":"A Primer on Partial Least Squares Structural Equation Modeling (PLS-SEM)","year":"2017","edition":"2nd. ed."},{"issue":"1","key":"key2022100508503058400_ref017","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1007\/s11747-014-0403-8","article-title":"A new criterion for assessing discriminant validity in variance-based structural equation modeling","volume":"43","year":"2015","journal-title":"Journal of the Academy of Marketing Science"},{"issue":"2","key":"key2022100508503058400_ref019a","doi-asserted-by":"crossref","first-page":"106","DOI":"10.1057\/ejis.2009.6","article-title":"Protection motivation and deterrence: a framework for security policy compliance in organizations","volume":"18","year":"2009","journal-title":"European Journal of Information Systems"},{"issue":"1","key":"key2022100508503058400_ref018","doi-asserted-by":"crossref","first-page":"2","DOI":"10.1108\/OIR-11-2015-0358","article-title":"Why not comply with information security? An empirical approach for the causes of non-compliance","volume":"41","year":"2017","journal-title":"Online Information Review"},{"issue":"1","key":"key2022100508503058400_ref019","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1016\/j.cose.2011.10.007","article-title":"Understanding information systems security policy compliance: an integration of the theory of planned behaviour and the protection motivation theory","volume":"31","year":"2012","journal-title":"Computers and Security"},{"issue":"1","key":"key2022100508503058400_ref020","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1016\/j.im.2013.10.001","article-title":"Information systems security policy compliance: an empirical study of the effects of socialisation, influence, and cognition","volume":"51","year":"2014","journal-title":"Information and Management"},{"issue":"2","key":"key2022100508503058400_ref021","doi-asserted-by":"crossref","first-page":"208","DOI":"10.2307\/257093","article-title":"Effects of leadership style and followers\u2019 cultural orientation on performance in group and individual task conditions","volume":"42","year":"1999","journal-title":"Academy of Management Journal"},{"issue":"5","key":"key2022100508503058400_ref022","doi-asserted-by":"crossref","first-page":"496","DOI":"10.1108\/ICS-04-2016-0029","article-title":"Theorising on risk homeostasis in the context of information security behaviour","volume":"24","year":"2016","journal-title":"Information and Computer Security"},{"issue":"1","key":"key2022100508503058400_ref023","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1145\/2738210.2738216","article-title":"Shadow security\u201d as a tool for the learning organization","volume":"45","year":"2015","journal-title":"ACM SIGCAS Computers and Society"},{"issue":"7","key":"key2022100508503058400_ref024","doi-asserted-by":"crossref","first-page":"493","DOI":"10.1016\/j.cose.2009.07.001","article-title":"Information security policy: an organizational-level process model","volume":"28","year":"2009","journal-title":"Computers and Security"},{"key":"key2022100508503058400_ref025","unstructured":"Korovessis, P. (2015), \u201cEstablishing an Information Security Awareness and Culture\u201d. PhD Thesis, Plymouth University."},{"key":"key2022100508503058400_ref026","first-page":"88","article-title":"Exploring the relationship between organizational culture and information security culture","volume-title":"Proceedings of the 7th Australian Information Security Management Conference","year":"2009"},{"issue":"2017","key":"key2022100508503058400_ref027","first-page":"151","article-title":"Individual differences and information security awareness","volume":"69","year":"2017","journal-title":"Computers in Human Behavior"},{"key":"key2022100508503058400_ref028","article-title":"A role model of IS leadership","volume-title":"Americas Conference on Information Systems","year":"2003"},{"issue":"2014","key":"key2022100508503058400_ref029","first-page":"165","article-title":"Determining employee awareness using the human aspects of information security questionnaire (HAIS-Q)","volume":"42","year":"2014","journal-title":"Computers & Security"},{"issue":"2","key":"key2022100508503058400_ref030","doi-asserted-by":"crossref","first-page":"117","DOI":"10.1177\/1555343415575152","article-title":"The influence of organizational information security culture on information security decision making","volume":"9","year":"2015","journal-title":"Journal of Cognitive Engineering and Decision Making"},{"issue":"1","key":"key2022100508503058400_ref031","doi-asserted-by":"crossref","first-page":"80","DOI":"10.2307\/259225","article-title":"The nature and implications of contextual influences on transformational leadership: a conceptual examination","volume":"22","year":"1997","journal-title":"Academy of Management Review"},{"issue":"4","key":"key2022100508503058400_ref032","doi-asserted-by":"crossref","first-page":"531","DOI":"10.1177\/014920638601200408","article-title":"Self-Reports in organizational research: problems and prospects","volume":"12","year":"1986","journal-title":"Journal of Management"},{"key":"key2022100508503058400_ref033","unstructured":"Ponemon Institute (2016), \u201c2016 State of end point security\u201d, The Ponemon Institute LLC, available at: https:\/\/cdn2.hubspot.net\/hubfs\/150964\/2016_State_of_Endpoint_Report.pdf (accessed 12 May 2016)."},{"key":"key2022100508503058400_ref034","unstructured":"Ringle, C.M., Wende, S. and Becker, J.M. (2015), SmartPLS 3, SmartPLS GmbH, Boenningstedt, available at: www.smartpls.com"},{"issue":"1","key":"key2022100508503058400_ref035","doi-asserted-by":"crossref","first-page":"56","DOI":"10.1016\/j.cose.2006.10.008","article-title":"Organisational security culture: extending the end-user perspective","volume":"26","year":"2007","journal-title":"Computer and Security"},{"issue":"2","key":"key2022100508503058400_ref036","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1016\/S1361-3723(16)30017-3","article-title":"Human aspect of information security in organisations.pdf","volume":"2016","year":"2016","journal-title":"Computer Fraud and Security"},{"key":"key2022100508503058400_ref037","unstructured":"SANS (2014), \u201cInfonnation security policy templates\u201d, [Online], available at: www.sans.org\/security-resources\/policies\/general (accessed 17 June 2016)."},{"issue":"3","key":"key2022100508503058400_ref038","doi-asserted-by":"crossref","first-page":"154","DOI":"10.1016\/j.lrp.2014.02.007","article-title":"On the emancipation of PLS-SEM: a commentary on rigdon (2012)","volume":"47","year":"2014","journal-title":"Long Range Planning"},{"key":"key2022100508503058400_ref039","volume-title":"Organizational Culture and Leadership","year":"2004","edition":"3rd ed"},{"key":"key2022100508503058400_ref040","first-page":"436","article-title":"An identification of variables influencing the establishment of information security culture","volume-title":"The Human-Computer Interaction (HCI) Conference \u2013 Human Aspects of Information Security","year":"2015"},{"issue":"2","key":"key2022100508503058400_ref041","doi-asserted-by":"crossref","first-page":"217","DOI":"10.1016\/j.im.2013.08.006","article-title":"Information and management employees \u2018 adherence to information security policies: an exploratory field study","volume":"51","year":"2014","journal-title":"Information and Management"},{"issue":"10","key":"key2022100508503058400_ref042","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1016\/S1361-3723(06)70430-4","article-title":"Cultivating an organisational information security culture","volume":"2006","year":"2006","journal-title":"Computer Fraud and Security"},{"issue":"3\/4","key":"key2022100508503058400_ref043","first-page":"190","article-title":"Motivating IS security compliance: insights from habit and protection motivation theory","volume":"49","year":"2012","journal-title":"Inform Manage"},{"issue":"1","key":"key2022100508503058400_ref044","doi-asserted-by":"crossref","first-page":"134","DOI":"10.2307\/3069341","article-title":"Does leadership matter? CEO leadership attributes and profitability under conditions of perceived environmental uncertainty","volume":"44","year":"2001","journal-title":"Academy of Management Journal"},{"issue":"1","key":"key2022100508503058400_ref045","first-page":"1","article-title":"Partial least squares structural equation modeling (PLS-SEM) techniques using SmartPLS","volume":"24","year":"2013","journal-title":"Marketing Bulletin"},{"issue":"3","key":"key2022100508503058400_ref046","doi-asserted-by":"crossref","first-page":"523","DOI":"10.2307\/25750690","article-title":"Information security policy compliance: anempirical study of rationality-based beliefs and information security awareness","volume":"34","year":"2010","journal-title":"MIS Quarterly"},{"issue":"0","key":"key2022100508503058400_ref047","first-page":"59","article-title":"A good thing isn\u2019t always a good thing: dispositional attitudes predict non-normative judgements","volume":"75","year":"2015","journal-title":"Pers. Individ. Dif"},{"key":"key2022100508503058400_ref048","volume-title":"Causes of Delinquency","year":"1969"},{"key":"key2022100508503058400_ref049","first-page":"1","volume-title":"The Role of Situational Factors and Personality on Cybersecurity Policy Violation","year":"2012"},{"key":"key2022100508503058400_ref050","volume-title":"Leadership and Motivation","year":"1966"}],"container-title":["Information &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-09-2017-0063\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-09-2017-0063\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T01:23:11Z","timestamp":1753406591000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/26\/4\/420-436\/107914"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,10,8]]},"references-count":51,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2018,10,8]]}},"alternative-id":["10.1108\/ICS-09-2017-0063"],"URL":"https:\/\/doi.org\/10.1108\/ics-09-2017-0063","relation":{},"ISSN":["2056-4961"],"issn-type":[{"value":"2056-4961","type":"print"}],"subject":[],"published":{"date-parts":[[2018,10,8]]}}}