What is it about?
This study examines the impact of deterrence and inertia on information security policy changes. Corporations recognize the need to prioritize information security which sometimes involves designing and implementing new security measures or policies. Using an online survey, we investigate the effect of deterrent sanctions and inertia on respondents' intentions to comply with modifications to company information security policies. We find that certainty and celerity associated with deterrent sanctions increases compliance intentions, while inertia decreases respondents' compliance intentions related to modified information security policies. Therefore, organizations must work to overcome employees' reluctance to change in order to improve compliance with security policy modifications. They may also consider implementing certain and timely sanctions for non-compliance.
Featured Image
Read the Original
This page is a summary of: Impact of Deterrence and Inertia on Information Security Policy Changes, Journal of Information Systems, March 2019, American Accounting Association,
DOI: 10.2308/isys-52400.
You can read the full text:
Contributors
The following have contributed to this page







