{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T00:07:27Z","timestamp":1787011647089,"version":"3.56.0"},"reference-count":64,"publisher":"Emerald","issue":"1","license":[{"start":{"date-parts":[[2019,12,4]],"date-time":"2019-12-04T00:00:00Z","timestamp":1575417600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IMDS"],"published-print":{"date-parts":[[2019,12,4]]},"abstract":"<jats:sec>\n                    <jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title>\n                    <jats:p>The purpose of this paper is to build an awareness-centered information security policy (ISP) compliance model, asserting that awareness is the key to ISP compliance and that awareness depends upon several variables that influence successful ISP compliance.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title>\n                    <jats:p>The authors built a model with seven constructs, i.e., leadership, trusting beliefs, information security issues awareness (ISIA), ISP awareness, understanding resource vulnerability, self-efficacy (SE) and intention to comply. Seven hypotheses were stated. A sample of 285 non-management employees was used from various organizations in the USA. The authors used path modeling to analyze the data.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title content-type=\"abstract-subheading\">Findings<\/jats:title>\n                    <jats:p>The findings indicated that IS awareness depends on effective organizational leadership and elevated employees\u2019 trusting beliefs. The understanding of resource vulnerability (URV) and SE are influenced by IS awareness resulting from effective leadership and elevated employees\u2019 trusting beliefs which guide employees to comply with ISP requirements.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title content-type=\"abstract-subheading\">Practical implications<\/jats:title>\n                    <jats:p>Practical implications were aimed at organizations embracing an awareness-centered information security compliance program to secure organizations\u2019 assets against threats by implementing various security education and training awareness programs.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title>\n                    <jats:p>This paper asserts that awareness is central to ISP compliance. Leadership and trusting beliefs variables play significant roles in the information security awareness which in turn positively affect employees\u2019 URV and SE variables leading employees to comply with the ISP requirements.<\/jats:p>\n                  <\/jats:sec>","DOI":"10.1108\/imds-07-2019-0412","type":"journal-article","created":{"date-parts":[[2020,1,10]],"date-time":"2020-01-10T04:29:13Z","timestamp":1578630553000},"page":"231-247","source":"Crossref","is-referenced-by-count":35,"title":["Building an awareness-centered information security policy compliance model"],"prefix":"10.1108","volume":"120","author":[{"given":"Alex","family":"Koohang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonathan","family":"Anderson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jeretta Horn","family":"Nord","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Joanna","family":"Paliszkiewicz","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","reference":[{"issue":"2","key":"key2020011009265754300_ref001","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1016\/0749-5978(91)90020-T","article-title":"The theory of planned behavior","volume":"50","year":"1991","journal-title":"Organizational Behavior and Human Decision Processes"},{"issue":"4","key":"key2020011009265754300_ref002","doi-asserted-by":"crossref","first-page":"432","DOI":"10.1016\/j.cose.2009.12.005","article-title":"Improving information security awareness and behaviour through dialogue, participation and collective reflection: an intervention study","volume":"29","year":"2010","journal-title":"Computer and Security"},{"issue":"3","key":"key2020011009265754300_ref003","doi-asserted-by":"crossref","first-page":"613","DOI":"10.2307\/25750694","article-title":"Practicing safe computing: a multimedia empirical examination of home computer user security behavioral intentions","volume":"34","year":"2010","journal-title":"MIS Quarterly"},{"issue":"1","key":"key2020011009265754300_ref004","doi-asserted-by":"crossref","first-page":"74","DOI":"10.1007\/BF02723327","article-title":"On the evaluation of structural equation models","volume":"16","year":"1988","journal-title":"Journal of the Academy of Marketing Science"},{"key":"key2020011009265754300_ref005","unstructured":"Bandura, A. (1994), \u201cSelf-efficacy\u201d, in Ramachaudran, V.S. (Ed.), Encyclopedia of Human Behavior, Vol. 4, Academic Press, New York, NY, pp. 71-81, (reprinted in H. Friedman (Ed.), Encyclopedia of Mental Health, Academic Press, San Diego, CA, 1998)."},{"issue":"8","key":"key2020011009265754300_ref006","first-page":"689","article-title":"Don\u2019t even think about it! The effects of antineutralization, informational, and normative communication on information security compliance","volume":"19","year":"2018","journal-title":"Journal of the Association for Information Systems"},{"issue":"1","key":"key2020011009265754300_ref007","first-page":"523","article-title":"Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness","volume":"34","year":"2010","journal-title":"MIS Quarterly"},{"issue":"6","key":"key2020011009265754300_ref008","doi-asserted-by":"crossref","first-page":"1187","DOI":"10.1111\/deci.12304","article-title":"Intentions to comply versus intentions to protect: a VIE theory approach to understanding the influence of insiders\u2019 awareness of organizational SETA efforts","volume":"49","year":"2018","journal-title":"Decision Sciences"},{"issue":"4","key":"key2020011009265754300_ref009","doi-asserted-by":"crossref","first-page":"312","DOI":"10.1080\/08874417.2016.1258679","article-title":"Factors that influence employees\u2019 security policy compliance: an awareness-motivation-capability perspective","volume":"58","year":"2018","journal-title":"Journal of Computer Information Systems"},{"issue":"1","key":"key2020011009265754300_ref010","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1287\/isre.1070.0160","article-title":"User awareness of security countermeasures and its impact on information systems misuse: a deterrence approach","volume":"20","year":"2009","journal-title":"Information Systems Research"},{"key":"key2020011009265754300_ref011","doi-asserted-by":"crossref","first-page":"73","DOI":"10.1016\/j.cose.2006.10.009","article-title":"Phishing for user security awareness","volume":"26","year":"2007","journal-title":"Computers & Security"},{"issue":"1","key":"key2020011009265754300_ref012","doi-asserted-by":"crossref","first-page":"67","DOI":"10.2307\/41166154","article-title":"Management\u2019s role in information security in a cyber-economy","volume":"45","year":"2002","journal-title":"California Management Review"},{"issue":"4","key":"key2020011009265754300_ref013","first-page":"1","article-title":"The positive outcomes of information security awareness training in companies \u2013 a case study","volume":"4","year":"2010","journal-title":"Information Security Technical Report"},{"key":"key2020011009265754300_ref014","volume-title":"A Primer for Soft Modeling","year":"1992"},{"key":"key2020011009265754300_ref015","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1016\/j.cose.2016.01.004","article-title":"Shaping intention to resist social engineering through transformational leadership, information security culture and awareness","volume":"59","year":"2016","journal-title":"Computers & Security"},{"issue":"1","key":"key2020011009265754300_ref016","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1177\/002224378101800104","article-title":"Evaluating structural equation models with unobservable variables and measurement error","volume":"18","year":"1981","journal-title":"Journal of Marketing Research"},{"issue":"1","key":"key2020011009265754300_ref017","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1177\/1059601109354801","article-title":"Examination organizational justice, trustworthiness, and trust: a multi-foci examination","volume":"35","year":"2010","journal-title":"Group Organization Management"},{"issue":"3","key":"key2020011009265754300_ref018","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1016\/S1361-3723(12)70053-2","article-title":"Understanding the influences on information security behaviour","volume":"2012","year":"2012","journal-title":"Computer Fraud & Security"},{"key":"key2020011009265754300_ref019","doi-asserted-by":"crossref","first-page":"52","DOI":"10.1016\/j.cose.2016.12.016","article-title":"An integrative model of information security policy compliance with psychological contract: examining a bilateral perspective","volume":"66","year":"2017","journal-title":"Computers & Security"},{"issue":"1","key":"key2020011009265754300_ref020","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1007\/s11747-014-0403-8","article-title":"A new criterion for assessing discriminant validity in variance-based structural equation modeling","volume":"43","year":"2015","journal-title":"Journal of the Academy of Marketing Science"},{"issue":"4","key":"key2020011009265754300_ref021","doi-asserted-by":"crossref","first-page":"615","DOI":"10.1111\/j.1540-5915.2012.00361.x","article-title":"Managing employee compliance with information security policies: the critical role of top management and organizational culture","volume":"43","year":"2012","journal-title":"Decision Sciences"},{"issue":"2","key":"key2020011009265754300_ref022","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1002\/(SICI)1097-0266(199902)20:2<195::AID-SMJ13>3.0.CO;2-7","article-title":"Use of partial least squares (PLS) in strategic management research: a review of four recent studies","volume":"20","year":"1999","journal-title":"Strategic Management Journal"},{"issue":"1","key":"key2020011009265754300_ref023","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1016\/j.cose.2011.10.007","article-title":"Understanding information systems security policy compliance: an integration of the theory of planned behavior and the protection motivation theory","volume":"31","year":"2012","journal-title":"Computers & Security"},{"issue":"1","key":"key2020011009265754300_ref024","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1016\/j.im.2013.10.001","article-title":"Information systems security policy compliance: an empirical study of the effects of socialisation, influence, and cognition","volume":"51","year":"2014","journal-title":"Information & Management"},{"issue":"1","key":"key2020011009265754300_ref025","doi-asserted-by":"crossref","first-page":"53","DOI":"10.4018\/IRMJ.2018010103","article-title":"Roles of organizational climate, social bonds, and perceptions of security threats on IS security policy compliance intentions","volume":"31","year":"2018","journal-title":"Information Resources Management Journal"},{"issue":"4","key":"key2020011009265754300_ref026","first-page":"549","article-title":"Fear appeals and information security behaviors","volume":"34","year":"2010","journal-title":"Management Information Systems Quarterly"},{"issue":"8","key":"key2020011009265754300_ref027","first-page":"1343","article-title":"Toward a new meta-theory for designing information systems (is) security training approaches","volume":"12","year":"2011","journal-title":"Journal of the Association for Information Systems"},{"issue":"3","key":"key2020011009265754300_ref028","first-page":"2012","article-title":"Effective information security requires a balance of social and technology factors","volume":"9","year":"2010","journal-title":"MIS Quarterly Executive"},{"issue":"4","key":"key2020011009265754300_ref029","doi-asserted-by":"crossref","first-page":"986","DOI":"10.1108\/JKM-08-2016-0353","article-title":"The effect of compliance knowledge and compliance support systems on information security compliance behavior","volume":"21","year":"2017","journal-title":"Journal of Knowledge Management"},{"key":"key2020011009265754300_ref030","doi-asserted-by":"crossref","unstructured":"Kirlappos, I. and Sasse, M.A. (2014), \u201cWhat usable security really means: trusting and engaging users\u201d, in Tryfonas, T. and Askoxylakis, I. (Eds), Human Aspects of Information Security, Privacy, and Trust, Springer, Bristol, pp. 69-78.","DOI":"10.1007\/978-3-319-07620-1_7"},{"issue":"2","key":"key2020011009265754300_ref031","doi-asserted-by":"crossref","first-page":"37","DOI":"10.4018\/jisp.2007040103","article-title":"Information security effectiveness: conceptualization and validation of a theory","volume":"1","year":"2007","journal-title":"International Journal of Information Security and Privacy"},{"issue":"3","key":"key2020011009265754300_ref032","doi-asserted-by":"crossref","first-page":"521","DOI":"10.1108\/IMDS-02-2016-0072","article-title":"The impact of leadership on trust, knowledge management, and organizational performance: a research model","volume":"117","year":"2017","journal-title":"Industrial Management & Data Systems"},{"issue":"3","key":"key2020011009265754300_ref300","doi-asserted-by":"crossref","first-page":"521","DOI":"10.1108\/JKM-10-2016-0463","article-title":"The mediating role of trust in stimulating the relationship between transformational leadership and knowledge sharing processes","volume":"22","year":"2018","journal-title":"Journal of Knowledge Management"},{"issue":"2\/3","key":"key2020011009265754300_ref033","first-page":"57","article-title":"A holistic model of computer abuse within organizations","volume":"10","year":"2002","journal-title":"Information Management and Computer Security"},{"issue":"3","key":"key2020011009265754300_ref034","doi-asserted-by":"crossref","first-page":"334","DOI":"10.1287\/isre.13.3.334.81","article-title":"Developing and validating trust measures for e-commerce: an integrative typology","volume":"13","year":"2002","journal-title":"Information Systems Research"},{"issue":"1","key":"key2020011009265754300_ref035","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1037\/0021-9010.84.1.123","article-title":"The effect of the performance appraisal system on trust for management: a field quasi-experiment","volume":"84","year":"1999","journal-title":"Journal of Applied Psychology"},{"issue":"5","key":"key2020011009265754300_ref036","doi-asserted-by":"crossref","first-page":"874","DOI":"10.5465\/amj.2005.18803928","article-title":"Trust in management and performance: who minds the shop while the employees watch the boss?","volume":"48","year":"2005","journal-title":"Academy of Management Journal"},{"issue":"3","key":"key2020011009265754300_ref037","doi-asserted-by":"crossref","first-page":"709","DOI":"10.5465\/amr.1995.9508080335","article-title":"An integrative model of organizational trust","volume":"20","year":"1995","journal-title":"The Academy of Management Review"},{"issue":"1","key":"key2020011009265754300_ref038","doi-asserted-by":"crossref","first-page":"285","DOI":"10.25300\/MISQ\/2018\/13853","article-title":"Toward a unified model of information security policy compliance","volume":"42","year":"2018","journal-title":"MIS Quarterly"},{"issue":"4","key":"key2020011009265754300_ref301","doi-asserted-by":"crossref","first-page":"815","DOI":"10.1016\/j.dss.2008.11.010","article-title":"Studying users\u2019 computer security behavior: a health belief perspective","volume":"46","year":"2009","journal-title":"Decision Support Systems"},{"key":"key2020011009265754300_ref039","unstructured":"Nieles, M., Dempsey, K. and Pillitteri, V. (2017), \u201cAn introduction to information security\u201d, NIST Special Publication 800-12 Revision 1, available at: https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-12r1.pdf (accessed May 12, 2019)."},{"key":"key2020011009265754300_ref040","volume-title":"Leadership: Theory and Practice","year":"2010","edition":"5th ed."},{"issue":"5","key":"key2020011009265754300_ref041","doi-asserted-by":"crossref","first-page":"673","DOI":"10.1016\/j.cose.2012.04.004","article-title":"Taxonomy of compliant information security behavior","volume":"31","year":"2012","journal-title":"Computers & Security"},{"issue":"3","key":"key2020011009265754300_ref042","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1080\/08874417.2019.1571459","article-title":"Information security policy compliance: leadership and trust","volume":"59","year":"2019","journal-title":"Journal of Computer Information Systems"},{"key":"key2020011009265754300_ref043","volume-title":"Information Security Risk Analysis","year":"2005"},{"issue":"5","key":"key2020011009265754300_ref044","doi-asserted-by":"crossref","first-page":"551","DOI":"10.1016\/j.im.2014.03.009","article-title":"Bridging the divide: a qualitative comparison of information security thought patterns between information security professionals and ordinary organizational 176 insiders","volume":"51","year":"2014","journal-title":"Information & Management"},{"issue":"4","key":"key2020011009265754300_ref045","doi-asserted-by":"crossref","first-page":"757","DOI":"10.2307\/25750704","article-title":"Improving employees\u2019 compliance through information systems security training: an action research study","volume":"34","year":"2010","journal-title":"MIS Quarterly"},{"key":"key2020011009265754300_ref302","volume-title":"SmartPLS 3.0","year":"2005"},{"key":"key2020011009265754300_ref046","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1016\/j.cose.2015.10.006","article-title":"Information security policy compliance model in organizations","volume":"56","year":"2016","journal-title":"Computers & Security"},{"issue":"1","key":"key2020011009265754300_ref047","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1016\/j.compedu.2008.06.011","article-title":"The impact of information richness on information security awareness training effectiveness","volume":"52","year":"2009","journal-title":"Computers & Education"},{"issue":"1","key":"key2020011009265754300_ref048","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1108\/09685220010371394","article-title":"A conceptual foundation for organizational information security awareness","volume":"8","year":"2000","journal-title":"Information Management & Computer Security"},{"issue":"3","key":"key2020011009265754300_ref049","doi-asserted-by":"crossref","first-page":"487","DOI":"10.2307\/25750688","article-title":"Neutralization: new insights into the problem of employee information systems security policy violations","volume":"34","year":"2010","journal-title":"MIS Quarterly"},{"issue":"5","key":"key2020011009265754300_ref050","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1016\/j.im.2008.12.007","article-title":"Information security management standards: problems and solutions","volume":"46","year":"2009","journal-title":"Information & Management"},{"issue":"2","key":"key2020011009265754300_ref051","doi-asserted-by":"crossref","first-page":"217","DOI":"10.1016\/j.im.2013.08.006","article-title":"Employees\u2019 adherence to information security policies: an exploratory field study","volume":"51","year":"2014","journal-title":"Information & Management"},{"issue":"1","key":"key2020011009265754300_ref052","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1145\/1216218.1216224","article-title":"A review of information security issues and respective research contributions","volume":"38","year":"2007","journal-title":"ACM SIGMIS Database: The DATABASE for Advances in Information Systems"},{"issue":"4","key":"key2020011009265754300_ref053","doi-asserted-by":"crossref","first-page":"167","DOI":"10.1108\/09685229810227649","article-title":"Information security awareness: educating your users effectively","volume":"6","year":"1998","journal-title":"Information Management & Computer Security"},{"issue":"5","key":"key2020011009265754300_ref054","doi-asserted-by":"crossref","first-page":"556","DOI":"10.1108\/00483480310488333","article-title":"Trust within organizations","volume":"32","year":"2003","journal-title":"Personnel Review"},{"issue":"3","key":"key2020011009265754300_ref055","first-page":"190","article-title":"Motivating IS security compliance: insights from habit and protection motivation theory","volume":"49","year":"2012","journal-title":"Information & Management"},{"issue":"5","key":"key2020011009265754300_ref056","doi-asserted-by":"crossref","first-page":"371","DOI":"10.1016\/j.cose.2004.05.002","article-title":"The 10 deadly sins of information security management","volume":"23","year":"2004","journal-title":"Computers & Security"},{"issue":"4","key":"key2020011009265754300_ref057","doi-asserted-by":"crossref","first-page":"52","DOI":"10.1080\/15536548.2013.10845690","article-title":"Control-related motivations and information security policy compliance: the role of autonomy and efficacy","volume":"9","year":"2013","journal-title":"Journal of Information Privacy & Security"},{"key":"key2020011009265754300_ref058","volume-title":"Measuring Electronic Word-of-Mouth Effectiveness","year":"2017"},{"issue":"4","key":"key2020011009265754300_ref059","doi-asserted-by":"crossref","first-page":"360","DOI":"10.1016\/j.ijinfomgt.2010.10.006","article-title":"Factors influencing information security management in small and medium-sized enterprises: a case study from Turkey","volume":"31","year":"2011","journal-title":"International Journal of Information Management"},{"key":"key2020011009265754300_ref060","doi-asserted-by":"crossref","first-page":"107","DOI":"10.1016\/j.dss.2018.02.009","article-title":"Exploring the influence of flow and psychological ownership on security education, training and awareness effectiveness and security compliance","volume":"108","year":"2018","journal-title":"Decision Support Systems"},{"issue":"1","key":"key2020011009265754300_ref061","first-page":"245","article-title":"Empirical evaluation of information security planning and integration","volume":"26","year":"2010","journal-title":"Communications of the Association for Information Systems"}],"container-title":["Industrial Management &amp; Data Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/IMDS-07-2019-0412\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/IMDS-07-2019-0412\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T21:52:48Z","timestamp":1753393968000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/imds\/article\/120\/1\/231-247\/185163"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,12,4]]},"references-count":64,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,12,4]]}},"alternative-id":["10.1108\/IMDS-07-2019-0412"],"URL":"https:\/\/doi.org\/10.1108\/imds-07-2019-0412","relation":{},"ISSN":["0263-5577"],"issn-type":[{"value":"0263-5577","type":"print"}],"subject":[],"published":{"date-parts":[[2019,12,4]]}}}