Understanding the Antecedents of Information Security Awareness - An Empirical Study
Felix Haeussinger, Johann J. Kranz
Abstract
Felix Haeussinger, Johann J. Kranz
Abstract
Employees’ information security awareness (ISA) is a key antecedent of information security behavior. However, to date we know very little about the factors that are responsible for some employees having a higher level of ISA than others. Our study addresses this gap. We propose a model that comprises institutional, individual, and environmental factors preceding ISA. The model was empirically tested with survey data gathered from 475 employees of different organizations and industries. The model was found to explain a substantial proportion (.53) of the variance. The results indicate that providing employees with comprehensible and readily accessible information security policies and improving employees’ IT knowledge are the two most influential antecedents of ISA. The findings will help refining researchers’ understanding of ISA and will be useful for diverse stakeholders interested in encouraging employees’ information security policy compliant behavior.
OpenAlex reports 13 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Employees’ information security awareness (ISA) is a key antecedent of information security behavior. However, to date we know very little about the factors that are responsible for some employees having a higher level of ISA than others. Our study addresses this gap. We propose a model that comprises institutional, individual, and environmental factors preceding ISA. The model was empirically tested with survey data gathered from 475 employees of different organizations and industries. The model was found to explain a substantial proportion (.53) of the variance. The results indicate that providing employees with comprehensible and readily accessible information security policies and improving employees’ IT knowledge are the two most influential antecedents of ISA. The findings will help refining researchers’ understanding of ISA and will be useful for diverse stakeholders interested in encouraging employees’ information security policy compliant behavior.
Key concepts: Information security, Empirical research, Computer security, Computer science, Internet privacy, Knowledge management, Information security management, Business