Proposing the control‐reactance compliance model (CRCM) to explain opposing motivations to comply with organisational information security policies

Authors: Lowry, Paul Benjamin; Moody, Gregory D.

Journal: Information Systems Journal (2015)

DOI: 10.1111/isj.12043

<jats:title>Abstract</jats:title><jats:p>Organisations increasingly rely on information and related systems, which are also a source of risk. Unfortunately, employees represent the greatest risk to organisational information because they are the most frequent source of information security breaches. To address this ‘weak link’ in organisational security, most organisations have strict information security policies (ISPs) designed to thwart employee information abuses. Regrettably, these ISPs are only partially effective because employees often ignore them, circumvent them or even do the opposite of what management desires. Research on attempts to increase ISP compliance has produced similarly mixed results. Lack of compliance with ISPs is a widespread organisational issue that increasingly bears disproportionately large direct and qualitative costs that undermine strategy.</jats:p><jats:p>Consequently, the purpose of our study was to contribute to the understanding of both motivations to comply with new ISPs and motivations to react negatively against them. To do so, we proposed an innovative model, the control‐reactance compliance model (CRCM), which combines organisational contr…

View in Otero