{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T22:36:50Z","timestamp":1786833410269,"version":"3.56.0"},"reference-count":113,"publisher":"Emerald","issue":"4","license":[{"start":{"date-parts":[[2022,3,23]],"date-time":"2022-03-23T00:00:00Z","timestamp":1647993600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ICS"],"published-print":{"date-parts":[[2022,10,20]]},"abstract":"<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title>\n<jats:p>This paper aims to examine the individual and combined effects of organisational and behavioural factors on employees\u2019 attitudes and intentions to establish an information security policy compliance culture (ISPCC) in organisations.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title>\n<jats:p>Based on factors derived from the organisational culture theory, social bond theory and accountability theory, a testable research model was developed and evaluated in an online survey that involves the use of a questionnaire to collect quantitative data from 313 employees, from ten different organisations in Ghana. The data collected were analysed using the partial least squares-structural equation modelling approach, involving the measurement and structural model tests.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Findings<\/jats:title>\n<jats:p>The study reveals that the individual measures of accountability \u2013 identifiability (2.4%), expectations of evaluation (38.8%), awareness of monitoring (55.7%) and social presence (\u221241.2%) \u2013 had weak to moderate effects on employees\u2019 attitudes towards information security policy compliance. However, the combined effect showed a significant influence. In addition, organisational factors \u2013 supportive organisational culture (15%), security compliance leadership (2%) and user involvement (63%) \u2013 showed positive effects on employees\u2019 attitudes. Further, employees\u2019 attitudes had a substantial influence (65%), while behavioural intentions demonstrated a weak effect (24%) on the establishment of an ISPCC in the organisation. The combined effect also had a substantial statistical influence on the establishment of an ISPCC in the organisation.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Practical implications<\/jats:title>\n<jats:p>Given the findings of the study, information security practitioners should implement organisational and behavioural factors that will have an impact on compliance, in tandem, with the organisational effort to build a culture of compliance for information security policies.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title>\n<jats:p>The study provides new insights on how to address the problem of non-compliance with regard to the information security policy in organisations through the combined application of organisational and behavioural factors to establish an information security policy compliance culture, which has not been considered in any past research.<\/jats:p>\n<\/jats:sec>","DOI":"10.1108\/ics-10-2021-0169","type":"journal-article","created":{"date-parts":[[2022,3,21]],"date-time":"2022-03-21T08:27:07Z","timestamp":1647851227000},"page":"583-614","source":"Crossref","is-referenced-by-count":14,"title":["The determinants of an information security policy compliance culture in organisations: the combined effects of organisational and behavioural factors"],"prefix":"10.1108","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7820-6709","authenticated-orcid":false,"given":"Eric","family":"Amankwa","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marianne","family":"Loock","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Elmarie","family":"Kritzinger","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","published-online":{"date-parts":[[2022,3,23]]},"reference":[{"key":"key2022102015354832200_ref001","first-page":"47","article-title":"Information security culture: a behaviour compliance conceptual framework","year":"2010"},{"key":"key2022102015354832200_ref002","doi-asserted-by":"publisher","first-page":"567","DOI":"10.1016\/j.chb.2015.03.054","article-title":"Design and validation of information security culture framework","volume":"49","year":"2015","journal-title":"Computers in Human Behavior"},{"key":"key2022102015354832200_ref003","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1109\/ICTS.2014.7010591","article-title":"A proposal of an organizational information security culture framework","year":"2014"},{"issue":"1","key":"key2022102015354832200_ref004","first-page":"212","article-title":"The mediating role of organizational identification between leadership and job security: a case of teachers in private institutions of Punjab-Pakistan","volume":"7","year":"2020","journal-title":"Journal of Management and Research (JMR)"},{"issue":"20","key":"key2022102015354832200_ref005","doi-asserted-by":"publisher","first-page":"1","DOI":"10.3390\/su12208576","article-title":"Organizational governance, social bonds and information security policy compliance: a perspective towards oil and gas employees","volume":"12","year":"2020","journal-title":"Sustainability"},{"key":"key2022102015354832200_ref006","doi-asserted-by":"publisher","first-page":"1216","DOI":"10.1016\/j.procs.2019.11.235","article-title":"Information security policy compliance: systematic literature information security policy compliance: Systematic literature review review","volume":"161","year":"2019","journal-title":"Procedia Computer Science"},{"key":"key2022102015354832200_ref07a","first-page":"5","article-title":"Proposed framework for understanding information security culture and practices in the Saudi context","year":"2009"},{"key":"key2022102015354832200_ref007","first-page":"352","article-title":"Information security policies: a review of challenges and influencing factors","year":"2016"},{"issue":"4","key":"key2022102015354832200_ref008","doi-asserted-by":"publisher","first-page":"420","DOI":"10.1108\/ICS-09-2017-0063","article-title":"Establishing information security policy compliance culture in organizations","volume":"26","year":"2018","journal-title":"Information and Computer Security"},{"issue":"4","key":"key2022102015354832200_ref009","doi-asserted-by":"publisher","first-page":"75","DOI":"10.4018\/ijthi.2021100105","article-title":"Information security policy compliance culture: examining the effects of accountability measures","volume":"17","year":"2021","journal-title":"International Journal of Technology and Human Interaction"},{"key":"key2022102015354832200_ref010","doi-asserted-by":"publisher","first-page":"826","DOI":"10.1007\/978-3-030-70713-2_75","article-title":"Affecting factors in information security policy compliance: combine organisational factors and user habits","year":"2021"},{"issue":"6","key":"key2022102015354832200_ref011","doi-asserted-by":"crossref","first-page":"387","DOI":"10.1016\/j.ijhcs.2011.01.003","article-title":"See-through techniques for referential awareness in collaborative virtual reality","volume":"69","year":"2011","journal-title":"International Journal of Human-Computer Studies"},{"issue":"4","key":"key2022102015354832200_ref012","first-page":"195","article-title":"Information security management: a human challenge?","volume":"13","year":"2009","journal-title":"Information Security Technical Report"},{"key":"key2022102015354832200_ref013","first-page":"518","article-title":"Student involvement: a developmental theory for higher education","volume":"40","year":"1999","journal-title":"Journal of College Student Personnel"},{"key":"key2022102015354832200_ref014","first-page":"125","article-title":"User involvement in software development and system success: a systematic literature review","year":"2013"},{"issue":"2","key":"key2022102015354832200_ref015","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1177\/0001839212453028","article-title":"The transparency paradox: a role for privacy in organizational learning and operational control","volume":"57","year":"2012","journal-title":"Administrative Science Quarterly"},{"key":"key2022102015354832200_ref016","first-page":"244","article-title":"Students\u2019 computers safety behaviors, under effects of cognition and socialization: When gender and job experience influence information","year":"2018"},{"issue":"2","key":"key2022102015354832200_ref017","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1057\/ejis.2009.8","article-title":"If someone is watching, I\u2019ll do what I\u2019m asked: mandatoriness, control, and information security","volume":"18","year":"2009","journal-title":"European Journal of Information Systems"},{"issue":"3","key":"key2022102015354832200_ref018","doi-asserted-by":"crossref","first-page":"523","DOI":"10.2307\/25750690","article-title":"Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness","volume":"34","year":"2010","journal-title":"MIS Quarterly"},{"key":"key2022102015354832200_ref019","volume-title":"Diagnosing and Changing Organizational Culture: Based on the Competing Values Framework","year":"2011"},{"key":"key2022102015354832200_ref020","article-title":"The influence of information security stress on security policy compliance: a protection motivation theory perspective the influence of information security stress on security policy compliance: a protection motivation theory perspective","year":"2018"},{"issue":"1","key":"key2022102015354832200_ref021","doi-asserted-by":"publisher","first-page":"39","DOI":"10.24205\/03276716.2020.6","article-title":"Effects of sanction on the mentality of information security policy compliance","volume":"29","year":"2020","journal-title":"Revista Argentina de Clinica Psicologica"},{"issue":"8","key":"key2022102015354832200_ref022","doi-asserted-by":"publisher","first-page":"1049","DOI":"10.1016\/j.im.2018.05.011","article-title":"Sanction severity and employees\u2019 information security policy compliance: investigating mediating, moderating, and control variables","volume":"55","year":"2018","journal-title":"Information and Management"},{"key":"key2022102015354832200_ref023","doi-asserted-by":"crossref","first-page":"447","DOI":"10.1016\/j.cose.2013.09.009","article-title":"Understanding the violation of is security policy in organizations: an integrated model based on social control and deterrence theory","volume":"39","year":"2013","journal-title":"Computers and Security"},{"key":"key2022102015354832200_ref024","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/ICEDEG52154.2021.9530849","article-title":"Using the theory of interpersonal behavior to predict information security policy compliance","year":"2021"},{"key":"key2022102015354832200_ref026a","doi-asserted-by":"publisher","first-page":"474","DOI":"10.1108\/IMCS-08-2013-0057","article-title":"Security culture and the employment relationship as drivers of employees\u2019 security compliance","year":"2014"},{"issue":"7","key":"key2022102015354832200_ref025","doi-asserted-by":"publisher","first-page":"103151","DOI":"10.1016\/j.im.2019.02.006","article-title":"Predicting employee information security policy compliance on a daily basis: the interplay of security-related stress, emotions, and neutralization","volume":"56","year":"2019","journal-title":"Information and Management"},{"issue":"1","key":"key2022102015354832200_ref026","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1287\/isre.1070.0160","article-title":"User awareness of security countermeasures and its impact on information systems misuse: a deterrence approach","volume":"20","year":"2009","journal-title":"Information Systems Research"},{"issue":"2","key":"key2022102015354832200_ref027","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1108\/ICS-12-2015-0048","article-title":"Comparing the information security culture of employees who had read the information security policy and those who had not - illustrated through an empirical study","volume":"24","year":"2016","journal-title":"Information and Computer Security"},{"issue":"5","key":"key2022102015354832200_ref028","doi-asserted-by":"publisher","first-page":"584","DOI":"10.1108\/ICS-08-2017-0056","article-title":"An approach to information security culture change combining ADKAR and the ISCA questionnaire to aid transition to the desired culture","volume":"26","year":"2018","journal-title":"Information and Computer Security"},{"issue":"2","key":"key2022102015354832200_ref029","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1016\/j.clsr.2015.01.005","article-title":"Information security culture and information protection culture: a validated assessment instrument","volume":"31","year":"2015","journal-title":"Computer Law and Security Review"},{"issue":"2017","key":"key2022102015354832200_ref030","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1016\/j.cose.2017.05.002","article-title":"Defining and identifying dominant information security cultures and subcultures","volume":"70","year":"2017","journal-title":"Computers and Security"},{"key":"key2022102015354832200_ref031","doi-asserted-by":"publisher","first-page":"101713","DOI":"10.1016\/j.cose.2020.101713","article-title":"Defining organisational information security culture \u2013 perspectives from academia and industry","volume":"92","year":"2020","journal-title":"Computers and Security"},{"issue":"3","key":"key2022102015354832200_ref032","doi-asserted-by":"crossref","first-page":"421","DOI":"10.1037\/apl0000085","article-title":"Performance appraisal and performance management: 100 years of progress?","volume":"102","year":"2017","journal-title":"Journal of Applied Psychology"},{"issue":"1","key":"key2022102015354832200_ref033","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1177\/002224298905300102","article-title":"Organizational culture and marketing defining the research agenda","volume":"53","year":"1989","journal-title":"Journal of Marketing"},{"issue":"4","key":"key2022102015354832200_ref034","doi-asserted-by":"publisher","first-page":"850","DOI":"10.2307\/259210","article-title":"A framework for linking culture and improvement initiatives in organizations","volume":"25","year":"2000","journal-title":"The Academy of Management Review"},{"key":"key2022102015354832200_ref037a","volume-title":"Principles of Information Systems Security","year":"2007"},{"issue":"2016","key":"key2022102015354832200_ref035","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1016\/j.cose.2015.10.001","article-title":"Interpreting information security culture: an organizational transformation case study","volume":"56","year":"2016","journal-title":"Computers and Security"},{"key":"key2022102015354832200_ref036","article-title":"How moral intensity and impulsivity moderate the influence of accountability on access policy violations in information systems","year":"2013"},{"issue":"2","key":"key2022102015354832200_ref037","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1361-3723(09)70019-3","article-title":"From culture to disobedience: recognising the varying user acceptance of IT security","volume":"2009","year":"2009","journal-title":"Computer Fraud and Security"},{"issue":"1","key":"key2022102015354832200_ref038","doi-asserted-by":"crossref","first-page":"251","DOI":"10.5465\/19416520903047269","article-title":"Pay and performance: individuals, groups, and executives","volume":"3","year":"2009","journal-title":"Academy of Management Annals"},{"key":"key2022102015354832200_ref039","first-page":"1","article-title":"Assessing the impact of security culture and the employee\u2013organization relationship on is security compliance","year":"2010"},{"key":"key2022102015354832200_ref040","first-page":"2025","article-title":"Unintentional insider threat: contributing factors, observables, and mitigation strategies","year":"2014"},{"issue":"2","key":"key2022102015354832200_ref041","doi-asserted-by":"publisher","first-page":"683","DOI":"10.1080\/07421222.2018.1451962","article-title":"The role of corporate reputation and crisis response strategies in data breach management","volume":"35","year":"2018","journal-title":"Journal of Management Information Systems"},{"issue":"2","key":"key2022102015354832200_ref042","doi-asserted-by":"publisher","first-page":"139","DOI":"10.2753\/MTP1069-6679190202","article-title":"PLS-SEM: indeed a silver bullet","volume":"19","year":"2011","journal-title":"Journal of Marketing Theory and Practice"},{"issue":"1","key":"key2022102015354832200_ref043","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1108\/EBR-11-2018-0203","article-title":"When to use and how to report the results of PLS-SEM","volume":"31","year":"2019","journal-title":"European Business Review"},{"issue":"6","key":"key2022102015354832200_ref044","doi-asserted-by":"publisher","first-page":"927","DOI":"10.1080\/14719037.2019.1679237","article-title":"The impact of accountability deficit on agency performance: performance-accountability regime","volume":"22","year":"2020","journal-title":"Public Management Review"},{"issue":"1","key":"key2022102015354832200_ref045","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1007\/s11747-014-0403-8","article-title":"A new criterion for assessing discriminant validity in variance-based structural equation modeling","volume":"43","year":"2015","journal-title":"Journal of the Academy of Marketing Science"},{"issue":"2","key":"key2022102015354832200_ref046","doi-asserted-by":"publisher","first-page":"154","DOI":"10.1016\/j.dss.2009.02.005","article-title":"Encouraging information security behaviors in organizations: role of penalties, pressures and perceived effectiveness","volume":"47","year":"2009","journal-title":"Decision Support Systems"},{"issue":"2","key":"key2022102015354832200_ref047","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1057\/ejis.2009.6","article-title":"Protection motivation and deterrence: a framework for security policy compliance in organisations","volume":"18","year":"2009","journal-title":"European Journal of Information Systems"},{"key":"key2022102015354832200_ref048","first-page":"1","article-title":"Information security policies: investigation of compliance in universities","year":"2016"},{"key":"key2022102015354832200_ref052a","volume-title":"Causes of Delinquency","year":"1969"},{"key":"key2022102015354832200_ref049","volume-title":"Leadership is What You Need: An Investigation into Information Security Culture","year":"2021"},{"key":"key2022102015354832200_ref054a","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1016\/j.cose.2011.10.007","article-title":"Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory","volume-title":"Computers & Security","year":"2012"},{"issue":"1","key":"key2022102015354832200_ref050","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1016\/j.im.2013.10.001","article-title":"Information systems security policy compliance: an empirical study of the effects of socialisation, influence, and cognition","volume":"51","year":"2014","journal-title":"Information and Management"},{"issue":"2","key":"key2022102015354832200_ref051","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1108\/ICS-08-2017-0058","article-title":"Perceptions of organizational culture and value conflicts in information security management","volume":"26","year":"2018","journal-title":"Information and Computer Security"},{"key":"key2022102015354832200_ref052","first-page":"70","article-title":"Comply or die\u2019 is dead: Long live security-aware principal agents","year":"2013"},{"issue":"1","key":"key2022102015354832200_ref053","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1145\/2738210.2738216","article-title":"Shadow security\u2019 as a tool for the learning organization","volume":"45","year":"2015","journal-title":"ACM SIGCAS Computers and Society"},{"issue":"7","key":"key2022102015354832200_ref054","doi-asserted-by":"publisher","first-page":"493","DOI":"10.1016\/j.cose.2009.07.001","article-title":"Information security policy: an organizational-level process model","volume":"28","year":"2009","journal-title":"Computers and Security"},{"issue":"1","key":"key2022102015354832200_ref055","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1080\/08874417.2019.1668738","article-title":"Information security policy compliance: leadership, trust, role values, and awareness","volume":"60","year":"2020","journal-title":"Journal of Computer Information Systems"},{"key":"key2022102015354832200_ref056","volume-title":"Establishing an Information Security Awareness and Culture","year":"2015"},{"issue":"2","key":"key2022102015354832200_ref057","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1037\/0033-2909.125.2.255","article-title":"Accounting for the effects of accountability accounting for the effects of accountability","volume":"125","year":"1999","journal-title":"Psychological Bulletin"},{"key":"key2022102015354832200_ref058","doi-asserted-by":"publisher","first-page":"88","DOI":"10.4225\/75\/57b4065130def","article-title":"Exploring the relationship between organizational culture and information security culture","year":"2009"},{"issue":"28","key":"key2022102015354832200_ref059","doi-asserted-by":"publisher","first-page":"102152","DOI":"10.1016\/j.ijinfomgt.2020.102152","article-title":"Motivating information security policy compliance: the critical role of supervisor-subordinate Guanxi and organizational commitment","volume":"54","year":"2020","journal-title":"International Journal of Information Management"},{"issue":"4","key":"key2022102015354832200_ref060","first-page":"165","article-title":"Privacy concerns versus desire for interpersonal awareness in driving the use of self-disclosure technologies: the case of instant messaging in two cultures","volume":"27","year":"2011","journal-title":"Journal of Management Information Systems"},{"issue":"3","key":"key2022102015354832200_ref061","doi-asserted-by":"crossref","first-page":"170","DOI":"10.17705\/1jais.00189","article-title":"Toward building self-sustaining groups in PCR-based tasks through implicit coordination: the case of heuristic evaluation","volume":"10","year":"2009","journal-title":"Journal of the Association for Information Systems"},{"issue":"2020","key":"key2022102015354832200_ref062","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1115\/JRC2017-2247","article-title":"Organizational culture","volume":"511","year":"2020","journal-title":"Advances in Social Science, Education and Humanities Research"},{"issue":"2017","key":"key2022102015354832200_ref063","first-page":"151","article-title":"Individual differences and information security awareness","volume":"69","year":"2017","journal-title":"Computers in Human Behavior"},{"key":"key2022102015354832200_ref064","first-page":"19","article-title":"What makes a good information security policy: a preliminary framework for evaluating security policy quality","year":"2006"},{"issue":"6","key":"key2022102015354832200_ref065","doi-asserted-by":"crossref","first-page":"819","DOI":"10.1068\/p6584","article-title":"The function and specificity of sensitivity to cues to facial identity: an individual-differences approach","volume":"39","year":"2010","journal-title":"Perception"},{"issue":"1","key":"key2022102015354832200_ref066","doi-asserted-by":"publisher","first-page":"285","DOI":"10.25300\/MISQ\/2018\/13853","article-title":"Toward a unified model of information security policy compliance","volume":"42","year":"2018","journal-title":"MIS Quarterly"},{"issue":"6","key":"key2022102015354832200_ref067","doi-asserted-by":"crossref","first-page":"479","DOI":"10.1111\/j.1365-2575.2010.00366.x","article-title":"Virtual worlds as knowledge management platform: a practice-perspective","volume":"21","year":"2011","journal-title":"Information Systems Journal"},{"issue":"3","key":"key2022102015354832200_ref068","doi-asserted-by":"publisher","first-page":"217","DOI":"10.48009\/3_iis_2020_217-226","article-title":"Impact of habits on information security policy compliance","volume":"21","year":"2020","journal-title":"Issues in Information Systems"},{"key":"key2022102015354832200_ref069","first-page":"63","article-title":"A conceptual information security culture framework for higher learning institutions","volume-title":"Human Aspects of Information Security and Assurance","year":"2021"},{"key":"key2022102015354832200_ref070","doi-asserted-by":"publisher","first-page":"101608","DOI":"10.1016\/j.cose.2019.101608","article-title":"State of the art in information security policy development","volume":"88","year":"2020","journal-title":"Computers and Security"},{"key":"key2022102015354832200_ref072","volume-title":"Human Factors and Information Security: Individual, Culture and Security Environment","year":"2010"},{"issue":"2","key":"key2022102015354832200_ref071","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1177\/1555343415575152","article-title":"The influence of organizational information security culture on information security decision making","volume":"9","year":"2015","journal-title":"Journal of Cognitive Engineering and Decision Making"},{"issue":"1","key":"key2022102015354832200_ref078a","doi-asserted-by":"crossref","first-page":"80","DOI":"10.2307\/259225","article-title":"The nature and implications of contextual influences on transformational leadership: a conceptual examination","volume":"22","year":"1997","journal-title":"Academy of Management Review"},{"key":"key2022102015354832200_ref073","volume-title":"he Second Annual Study on the Cyber Resilient Organisation: United Kingdom Independently conducted by Ponemon Institute Sponsored by Resilient Publication Date: February 2017","author":"Ponemon Institute","year":"2017"},{"key":"key2022102015354832200_ref074","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1016\/j.cose.2018.09.016","article-title":"Evaluating the explanatory power of theoretical frameworks on intention to comply with information security policies in higher education","volume":"80","year":"2019","journal-title":"Computers and Security"},{"key":"key2022102015354832200_ref081a","doi-asserted-by":"publisher","article-title":"From information security to cyber security cultures","year":"2014","DOI":"10.1109\/ISSA.2014.6950492"},{"key":"key2022102015354832200_ref075","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/ISSA.2014.6950493","article-title":"Information security culture: a general living systems theory perspective","year":"2014"},{"issue":"8","key":"key2022102015354832200_ref076","doi-asserted-by":"publisher","first-page":"816","DOI":"10.1016\/j.cose.2009.05.008","article-title":"Self-efficacy in information security: its influence on end users\u2019 information security practice behavior","volume":"28","year":"2009","journal-title":"Computers and Security"},{"key":"key2022102015354832200_ref077","article-title":"SmartPls 3","volume-title":"Partial Least Squares, Structural Equation Modelling (PLS-SEM) (3.2.6)","year":"2015"},{"issue":"1","key":"key2022102015354832200_ref078","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1016\/j.cose.2006.10.008","article-title":"Organisational security culture: extending the end-user perspective","volume":"26","year":"2007","journal-title":"Computers and Security"},{"key":"key2022102015354832200_ref079","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1016\/j.cose.2015.10.006","article-title":"Information security policy compliance model in organisations","volume":"56","year":"2016","journal-title":"Computers and Security"},{"issue":"2019","key":"key2022102015354832200_ref080","first-page":"587","article-title":"Deterrence and prevention-based model to mitigate information security insider threats in organizations","volume":"97","year":"2019","journal-title":"Future Generation Computer Systems"},{"key":"key2022102015354832200_ref081","doi-asserted-by":"publisher","first-page":"144","DOI":"10.1016\/j.ijinfomgt.2019.04.011","article-title":"Stakeholder perceptions of information security policy: analyzing personal constructs","volume":"50","year":"2020","journal-title":"International Journal of Information Management"},{"key":"key2022102015354832200_ref082","first-page":"1","article-title":"Contextualizing social power research within organizational behavior","volume-title":"The Self at Work: Fundamental Theory and Research. Organizational Frontiers Series of the Society for Industrial and Organizational Psychology","year":"2018"},{"key":"key2022102015354832200_ref090a","unstructured":"Schein, E. (1988), Organizational Culture, Sloan School of Management, available at: http:\/\/hdl.handle.net\/1721.1\/2224"},{"key":"key2022102015354832200_ref083","volume-title":"Organizational Culture and Leadership","year":"2004","edition":"3rd ed."},{"issue":"4","key":"key2022102015354832200_ref084","doi-asserted-by":"crossref","first-page":"539","DOI":"10.1016\/j.jesp.2006.05.010","article-title":"Motivated information processing and group decision-making: effects of process accountability on information processing and decision quality","volume":"43","year":"2007","journal-title":"Journal of Experimental Social Psychology"},{"key":"key2022102015354832200_ref085","first-page":"436","article-title":"An identification of variables influencing the establishment of information security culture","year":"2015"},{"issue":"2015","key":"key2022102015354832200_ref086","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1016\/j.cose.2015.01.002","article-title":"Personality, attitudes, and intentions: predicting initial adoption of information security behavior","volume":"49","year":"2015","journal-title":"Computers and Security"},{"issue":"2","key":"key2022102015354832200_ref087","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1016\/j.im.2013.08.006","article-title":"Employees\u2019 adherence to information security policies: an exploratory field study","volume":"51","year":"2014","journal-title":"Information and Management"},{"issue":"5","key":"key2022102015354832200_ref088","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1108\/ICS-08-2017-0054","article-title":"Work-related groups and information security policy compliance","volume":"26","year":"2018","journal-title":"Information and Computer Security"},{"issue":"8","key":"key2022102015354832200_ref089","doi-asserted-by":"publisher","first-page":"1737","DOI":"10.1111\/joms.12625","article-title":"Organizational culture and COVID-19","volume":"57","year":"2020","journal-title":"Journal of Management Studies"},{"issue":"5","key":"key2022102015354832200_ref090","doi-asserted-by":"publisher","DOI":"10.1108\/ICS-07-2016-0054","article-title":"Information security management and the human aspect in organizations","volume":"25","year":"2017","journal-title":"Information and Computer Security"},{"issue":"2","key":"key2022102015354832200_ref091","doi-asserted-by":"publisher","first-page":"1325","DOI":"10.33258\/birci.v3i2.980","article-title":"Sustainability of communication, organizational culture, cooperation, trust and leadership style for lecturer commitments in higher education","volume":"3","year":"2020","journal-title":"Budapest International Research and Critics Institute (Birci-Journal): Humanities and Social Sciences)"},{"issue":"2","key":"key2022102015354832200_ref092","doi-asserted-by":"publisher","DOI":"10.1007\/s10799-015-0252-2","article-title":"The impacts of organizational culture on information security culture: a case study","volume":"17","year":"2016","journal-title":"Information Technology and Management"},{"key":"key2022102015354832200_ref093","first-page":"3","article-title":"Implicit bias and accountability systems: what must organizations do to prevent discrimination?","volume":"3","year":"2009","journal-title":"Research in Organizational Behavior"},{"key":"key2022102015354832200_ref094","doi-asserted-by":"crossref","first-page":"138","DOI":"10.1016\/j.cose.2016.02.009","article-title":"Understanding online safety behaviors: a protection motivation theory perspective","volume":"59","year":"2016","journal-title":"Computers and Security"},{"key":"key2022102015354832200_ref095","doi-asserted-by":"publisher","first-page":"128","DOI":"10.1016\/j.cose.2015.04.006","article-title":"Analyzing the role of cognitive and cultural biases in the internalization of information security policies: Recommendations for information security awareness programs","volume":"52","year":"2015","journal-title":"Computers and Security"},{"issue":"1","key":"key2022102015354832200_ref096","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1080\/08874417.2017.1400928","article-title":"Organizational citizenship behavior regarding security: leadership approach perspective","volume":"60","year":"2020","journal-title":"Journal of Computer Information Systems"},{"issue":"4","key":"key2022102015354832200_ref097","doi-asserted-by":"crossref","first-page":"203","DOI":"10.4236\/jis.2013.44023","article-title":"Personality traits and cognitive determinants \u2014 an empirical investigation of the use of smartphone security measures","volume":"4","year":"2013","journal-title":"Journal of Information Security"},{"key":"key2022102015354832200_ref098","article-title":"Understanding information security culture: understanding information security culture","year":"2006"},{"issue":"4","key":"key2022102015354832200_ref099","doi-asserted-by":"publisher","first-page":"476","DOI":"10.1016\/j.cose.2009.10.005","article-title":"Information security culture: a management perspective","volume":"29","year":"2010","journal-title":"Computers and Security"},{"issue":"4","key":"key2022102015354832200_ref0100","doi-asserted-by":"crossref","first-page":"263","DOI":"10.2753\/MIS0742-1222290410","article-title":"Using accountability to reduce access policy violations in information systems","volume":"29","year":"2013","journal-title":"Journal of Management Information Systems"},{"key":"key2022102015354832200_ref0101","doi-asserted-by":"publisher","first-page":"101773","DOI":"10.1016\/j.marmicro.2019.101773","article-title":"Effects of sanctions, moral beliefs, and neutralization on information security policy violations across cultures","year":"2019","journal-title":"Information and Management"},{"issue":"2","key":"key2022102015354832200_ref0102","doi-asserted-by":"crossref","first-page":"345","DOI":"10.25300\/MISQ\/2015\/39.2.04","article-title":"A new approach to the problem of access policy violations: increasing perceptions of accountability through the user interface","volume":"39","year":"2015","journal-title":"MIS Quarterly"},{"issue":"12","key":"key2022102015354832200_ref0103","doi-asserted-by":"publisher","first-page":"1187","DOI":"10.17705\/1jais.00524","article-title":"A tale of two deterrents: considering the role of absolute and restrictive deterrence to inspire new directions in behavioral and organizational security research","volume":"19","year":"2018","journal-title":"Journal of the Association for Information Systems"},{"key":"key2022102015354832200_ref0112a","article-title":"Partial least squares structural equation modeling (PLS-SEM) techniques using SmartPLS","volume-title":"Marketing Bulletin","year":"2013"},{"key":"key2022102015354832200_ref0104","volume-title":"Statistics, an Introductory Analysis","year":"1967","edition":"2nd ed."}],"container-title":["Information &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-10-2021-0169\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-10-2021-0169\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T01:23:16Z","timestamp":1753406596000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/30\/4\/583-614\/107897"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,23]]},"references-count":113,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2022,3,23]]},"published-print":{"date-parts":[[2022,10,20]]}},"alternative-id":["10.1108\/ICS-10-2021-0169"],"URL":"https:\/\/doi.org\/10.1108\/ics-10-2021-0169","relation":{},"ISSN":["2056-4961","2056-4961"],"issn-type":[{"value":"2056-4961","type":"print"},{"value":"2056-4961","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,23]]}}}