Proposing the Control-Reactance Compliance Model (CRCM) to Explain Opposing Motivations to Comply with Organisational Information Security Policies

Information Systems Journal, vol. 25(5), pp. 433-463 (2015)

51 Pages Posted: 9 Jun 2014 Last revised: 1 Aug 2015

See all articles by Paul Benjamin Lowry

Paul Benjamin Lowry

Virginia Tech - Pamplin College of Business

Gregory D Moody

University of Nevada, Las Vegas - College of Business

Date Written: July 31, 2015

Abstract

Organisations increasingly rely on information and related systems, which are also a source of risk. Unfortunately, employees represent the greatest risk to organisational information, because they are the most frequent source of information security breaches. To address this ‘weak link’ in organisational security, most organisations have strict information security policies (ISPs) designed to thwart employee information abuses. Regrettably, these ISPs are only partially effective, because employees often ignore them, circumvent them, or even do the opposite of what management desires. Research on attempts to increase ISP compliance has produced similarly mixed results. Lack of compliance with ISPs is a widespread organisational issue that increasingly bears disproportionately large direct and qualitative costs that undermine strategy.

Consequently, the purpose of our study was to contribute to the understanding of both motivations to comply with new ISPs and motivations to react negatively against them. To do so, we proposed an innovative model, the control-reactance compliance model (CRCM), which combines organisational control theory — a model that explains ISP compliance — with reactance theory — a model used to explain ISP noncompliance. To test CRCM, we used a sample of 320 working professionals in a variety of industries to examine the likely organisational outcomes of the delivery of a new ISP to employees in the form of a typical memo sent throughout an organisation. We largely found support for CRCM, and this study concludes with an explanation of the model’s contributions to research and practice related to organisational ISP compliance.

Keywords: Organisation security, Control theory, Reactance theory, Reactance, Compliance, Information security policies, Policy compliance, Organisational deviance, Threats to freedom, Boomerang effects

Suggested Citation

Lowry, Paul Benjamin and Moody, Gregory Daniel, Proposing the Control-Reactance Compliance Model (CRCM) to Explain Opposing Motivations to Comply with Organisational Information Security Policies (July 31, 2015). Information Systems Journal, vol. 25(5), pp. 433-463 (2015), Available at SSRN: https://ssrn.com/abstract=2447354

Paul Benjamin Lowry (Contact Author)

Virginia Tech - Pamplin College of Business ( email )

1016 Pamplin Hall
Blacksburg, VA 24061
United States

Gregory Daniel Moody

University of Nevada, Las Vegas - College of Business ( email )

4505 S. Maryland Parkway
Las Vegas, NV 89154
United States

HOME PAGE: http://https://faculty.unlv.edu/wpmu/gmoody/

Do you have negative results from your research you’d like to share?

Paper statistics

Downloads
118
Abstract Views
752
Rank
428,299
PlumX Metrics