vix.ing · top · new · best · stats · spec

What levels of moral reasoning and values explain adherence to information security rules? An empirical study

2009/04/01 by Liisa Myyry, Mikko Siponen, Seppo Pahnila +2 · 2 citations
Computer Science · #Cybercrime and Law Enforcement Studies #Hate Speech and Cyberbullying Detection #Information and Cyber Security

paper · doi:10.1057/ejis.2009.10

openalex publication_date 2009/04/01 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/29

Abstract

It is widely agreed that employee non-adherence to information security policies poses a major problem for organizations. Previous research has pointed to the potential of theories of moral reasoning to better understand this problem. However, we find no empirical studies that examine the influence of moral reasoning on compliance with information security policies. We address this research gap by proposing a theoretical model that explains non-compliance in terms of moral reasoning and values. The model integrates two well-known psychological theories: the Theory of Cognitive Moral Development by Kohlberg and the Theory of Motivational Types of Values by Schwartz. Our empirical findings largely support the proposed model and suggest implications for practice and research on how to improve information security policy compliance.

Citations

Cited by

Related