Toward a Theory of Information Systems Security Behaviors of Organizational Employees: A Dialectical Process Perspective
Published Online:5 Jun 2019https://doi.org/10.1287/isre.2018.0827
References
- (2010) Improving information security awareness and behaviour through dialogue, participation and collective reflection. An intervention study. Comput. Security 29(4):432–445.Crossref, Google Scholar
- (2004) Tension between institutional and individual views of marriage. J. Marriage Family 66(4):959–965.Crossref, Google Scholar
- (1983) Central perspectives and debates in organization theory. Admin. Sci. Quart. 28(2):245–273.Crossref, Google Scholar
- (1992) Organization science, managers, and language games. Organ. Sci. 3(4):443–460.Link, Google Scholar
- (2014) An emote opportunity model of computer abuse. Inform. Tech. People 27(2):155–181.Crossref, Google Scholar
- (2004) Reflexivity and managerial practice. Comm. Monographs 71(1):27–53.Crossref, Google Scholar
- (1988) A dialectical perspective on communication strategies in relationship development. Duck S, ed. Handbook of Personal Relationships (Wiley, New York), 257–273.Google Scholar
- (2016) Dialectical tensions in relationships. BergerCR, Roloff ME, eds. The International Encyclopedia of Interpersonal Communication (John Wiley & Sons, New York), 1–5.Google Scholar
- (1977) Organizations: A dialectical view. Admin. Sci. Quart. 22(1):1–21.Crossref, Google Scholar
- (2013) Grounded theory method in information systems research: Its nature, diversity and opportunities. Eur. J. Inform. Systems 22(1):1–8.Crossref, Google Scholar
- (2015) What do systems users have to fear? Using fear appeals to engender threats and fear that motivate protective security behaviors. MIS Quart. 39(4):837–864.Crossref, Google Scholar
- (2013) Organizational values: A dynamic perspective. Organ. Stud. 34(4):495–514.Crossref, Google Scholar
- (2016) Dialectics between suspicion and trust. Stasis 4(2):98–113.Crossref, Google Scholar
- (2010a) Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quart. 34(3):523–548.Crossref, Google Scholar
- (2012) Dialectics of collective minding: Contradictory appropriations of information technology in a high-risk project. MIS Quart. 36(4):1081–1108.Crossref, Google Scholar
- (2010) An exploration into the process of requirements elicitation: A grounded approach. J. Assoc. Inform. Syst. 11(4):212–249.Google Scholar
- (2006) Constructing Grounded Theory: A Practical Guide Through Qualitative Analysis (Sage, Thousand Oaks, CA).Google Scholar
- (2000) Grounded theory: Objectivist and constructivist methods. Denzin NK, Lincoln YS, eds. Handbook of Qualitative Research (Sage Publications, Thousand Oaks, CA), 509–535.Google Scholar
- (2007) Dialectics of resilience: A multi-level analysis of a telehealth innovation. J. Inform. Tech. 22(1):24–35.Crossref, Google Scholar
- CISCO (2008) Data leakage worldwide: Common risks and mistakes employees make. White paper. Accessed January 2, 2019, http://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/data-loss-prevention/white_paper_c11-499060.pdf.Google Scholar
- CompTIA (2015) Trends in IT information security. Accessed January 2, 2019, https://www.comptia.org.Google Scholar
- (2013) Future directions for behavioral information security research. Comput. Security 32:90–101.Crossref, Google Scholar
- (2004) A dual-motor, constructive process model of organizational transition. Organ. Stud. 25(2):229–260.Crossref, Google Scholar
- (2012) Breaking rules for the right reasons? An investigation of pro-social rule breaking. J. Organ. Behav. 33(1):21–42.Crossref, Google Scholar
- (2012) Affect and information processing. In: Hodgkinson GP, Starbuck WH, eds., The Oxford Handbook of Organizational Decision Making (Oxford University Press, Oxford), 325–341.Google Scholar
- (2011) A review and analysis of deterrence theory in the IS security literature: Making sense of the disparate findings. Eur. J. Inform. Syst. 20(6):643–658.Crossref, Google Scholar
- (2004) On the dialectics of strategic alliances. Organ. Sci. 15(1):56–69.Link, Google Scholar
- (2006) Managing the right tension. Harvard Bus. Rev. 84(12):62–74.Google Scholar
- (2009) The information security policy unpacked: A critical study of the content of university policies. Internat. J. Inform. Management 29(6):449–457.Crossref, Google Scholar
- (1964) Historical explanation: The Popper-Hempel theory reconsidered. History Theory 4(1):3–26.Crossref, Google Scholar
- (1991) Keeping an eye on the mirror: Image and identity in organizational adaptation. Acad. Management J. 34(3):517–554.Crossref, Google Scholar
- (1991) Legal ambiguity and the politics of compliance: Affirmative action officers’ dilemma. Law Policy 13(1):73–97.Crossref, Google Scholar
- (1989) Building theories from case study research. Acad. Management Rev. 14(4):532–550.Crossref, Google Scholar
- (2002) The dialectics of institutional development in emerging and turbulent fields: The history of pricing conventions in the on-line database industry. Acad. Management J. 45(5):848–874.Crossref, Google Scholar
- (2009) Dialectical tensions of small group leadership. Comm. Stud. 60(5):409–425.Crossref, Google Scholar
- (2003) Trust, control and the role of interorganizational systems in electronic partnerships. Inform. Systems J. 13(2):159–190.Crossref, Google Scholar
- (2009) Dialectics in a global software team: Negotiating tensions across time, space, and culture. Human Relations 62(6):905–935.Crossref, Google Scholar
- (1978) Theoretical Sensitivity: Advances in the Methodology of Grounded Theory (Sociology Press, Mill Valley, CA).Google Scholar
- (2006) The nature of theory in information systems. MIS Quart. 30(3):611–642.Crossref, Google Scholar
- (2006) Institutional entrepreneurship in mature fields: The big five accounting firms. Acad. Management J. 49(1):27–48.Crossref, Google Scholar
- (2012) Applying an extended model of deterrence across cultures: An investigation of information systems misuse in the U.S. and South Korea. Inform. Management 49(2):99–110.Crossref, Google Scholar
- (2015) How extra-role behaviors can improve information security policy effectiveness. Inform. Systems Res. 26(2):282–300.Link, Google Scholar
- (2005) A longitudinal study of information system threat categories: The enduring problem of human error. Database Adv. Inform. Systems 36(4):68–79.Crossref, Google Scholar
- (1990) Evolving interpretations as a change unfolds: How managers construe key organizational events. Acad. Management J. 33(1):7–41.Crossref, Google Scholar
- PricewaterhouseCoopers (2010) Information Security Breaches Survey 2010. Technical report. Accessed January 2, 2019, http://pwc.blogs.com/files/isbs-2010-report-final.pdf.Google Scholar
- (1991) The development of conceptually independent subscales in the measurement of modes of problem solving. Ed. Psych. Measurement 51:975–983.Crossref, Google Scholar
- (1996) Interpretive sociology and the dialectic of structure and agency. Theory Culture Soc. 13(1):119–128.Crossref, Google Scholar
- (2009) Improving multiple-password recall: An empirical study. Eur. J. Inform. Systems 18(2):165–176.Crossref, Google Scholar
- (2006) The essential impact of context on organizational behavior. Acad. Management Rev. 31(2):386–408.Crossref, Google Scholar
- (2006) Legitimacy as a social process. Annual Rev. Sociol. 32:53–78.Crossref, Google Scholar
- (2010) Fear appeals and information security behaviors: An empirical study. MIS Quart. 34(3):549–566.Crossref, Google Scholar
- (2015) An enhanced fear appeal rhetorical framework: Leveraging threats to the human asset through sanctioning rhetoric. MIS Quart. 39(1):113–134.Crossref, Google Scholar
- (2011) Toward a new meta-theory for designing information systems (IS) security training approaches. J. Assoc. Inform. Systems 12(8):518–555.Google Scholar
- (1981) The Philosophy of Moral Development, Essays on Moral Development, vol. I (Harper & Row, San Francisco).Google Scholar
- (2015) Elasticity and the dialectic tensions of organizational identity: How can we hold together while we are pulling apart? Acad. Management J. 58(4):981–1011.Crossref, Google Scholar
- (2010) Introducing perspectives on process organization studies. Hernes T, Maitlis S, eds. Process, Sensemaking & Organizing. Perspectives in Process Organization Studies (Oxford University Press, Oxford, UK), 213–241.Crossref, Google Scholar
- (1983) The demise of the demarcation problem. Cohen RS, Laudan L, eds. Physics, Philosophy and Psychoanalysis: Essays in Honor of Adolf Grünbaum. Boston Studies in the Philosophy of Science, vol. 76 (Springer, Dordrecht, Netherlands), 111–127.Crossref, Google Scholar
- (1991) Integrating positivist and interpretive approaches to organizational research. Organ. Sci. 2(4):342–365.Link, Google Scholar
- (2009) Selectivity in organizational rule violations. Acad. Management Rev. 34(4):643–657.Crossref, Google Scholar
- (2006) Review: A review of culture in information systems research: Toward a theory of information technology culture conflict. MIS Quart. 30(2):357–399.Crossref, Google Scholar
- (2006) Code. Version 2.0 (Basic Books, New York). Accessed January 2, 2019, http://cyber.law.harvard.edu/ptc2010/sites/ptc2010/images/Lessig_Code_Excerpts.pdf.Google Scholar
- (1999) Code: And Other Laws of Cyberspace (Basic Books, New York).Google Scholar
- (2008) Innovating or doing as told? Status differences and overlapping boundaries in offshore collaboration. MIS Quart. 32(2):307–332.Crossref, Google Scholar
- (2014) Exploring the effects of organizational justice, personal ethics, and sanctions on Internet use policy compliance. Inform. Systems J. 24(6):479–502.Crossref, Google Scholar
- (2008) Determinism. Psillos S, Curd M, eds. The Routledge Companion to Philosophy of Science (Routledge, Abingdon, UK), 327–336.Google Scholar
- (1975) A dialectical analysis of organizational conflict. Admin. Sci. Quart. 20:489–508.Crossref, Google Scholar
- (1988) Information technology and organizational change: Causal structure in theory and research. Management Sci. 34(5):583–598.Link, Google Scholar
- (1995) Synthesizing the implementation literature: The ambiguity-conflict model of policy implementation. J. Public Admin. Res. Theory 5(2):145–174.Google Scholar
- (2004) Compliance motivations: Affirmative and negative bases. Law Soc. Rev. 38(1):41–68.Crossref, Google Scholar
- (2018) Toward a unified model of information security policy compliance. MIS Quart. 42(1):285–311.Crossref, Google Scholar
- (2006) Doing the job well: An investigation of pro-social rule breaking. J. Management 32(1):5–28.Crossref, Google Scholar
- (2005) Theorizing resistance in organization studies: A dialectical approach. Management Comm. Quart. 19(1):19–44.Crossref, Google Scholar
- (2007) The qualitative interview in IS research: Examining the craft. Inform. Organ. 17(1):2–26.Crossref, Google Scholar
- (2015) Intergroup reconciliation: Instrumental and socio-emotional processes and the needs-based model. Eur. Rev. Soc. Psych. 26(1):93–125.Crossref, Google Scholar
- (2006) Implementing enterprise content management: From evolution through strategy to contradictions out-of-the-box. Eur. J. Inform. Systems 15(6):648–662.Crossref, Google Scholar
- (1991) Studying information technology in organizations: Research approaches and assumptions. Inform. Systems Res. 2(1):1–28.Link, Google Scholar
- (1990) Qualitative Evaluation and Research Methods (Sage Publications, Thousand Oaks, CA).Google Scholar
- (1999) Building process theory with narrative: From description to explanation. Acad. Management Rev. 24(4):711–724.Crossref, Google Scholar
- (2007) Radical change accidentally: The emergence and amplification of small change. Acad. Management J. 50(3):515–543.Crossref, Google Scholar
- Ponemon Institute (2014a) 2014: A year of megabreaches. Accessed January 2, 2019, https://www.ponemon.org/local/upload/file/2014%20The%20Year%20of%20the%20Mega%20Breach%20FINAL_3.pdf.Google Scholar
- Ponemon Institute (2014b) 2014 cost of data breach study: Global analysis. Accessed January 2, 2019, https://www.ibm.com/security/data-breach.Google Scholar
- (1997) Cognition and Emotion: From Order to Disorder (Psychology Press, Hove, UK).Google Scholar
- (2008) Microfoundations of institutional theory. Greenwood R, Oliver C, Suddaby R, Sahlin K, eds. The SAGE Handbook of Organizational Institutionalism (Sage Publications Ltd., Los Angeles), 276–298.Crossref, Google Scholar
- (2000) Ambivalent feelings in organizational relationships. Fineman S, ed. Emotion in Organization (Sage, London), 204–226.Crossref, Google Scholar
- (2010) Improving employee’s compliance through IS security training: An action research study. MIS Quart. 34(4):757–778.Crossref, Google Scholar
- (1974) On the “corroboration” of theories. Schilpp PA, ed. The Philosophy of Karl Popper, vol. 1 (Open Court, La Salle, IL), 121–137.Google Scholar
- (2004) Dialectical tensions and rhetorical tropes in negotiations. Organ. Stud. 25(1):35–53.Crossref, Google Scholar
- (2010/2011) CSI computer crime and security survey. Accessed January 2, 2019, https://cours.etsmtl.ca/gti619/documents/divers/CSIsurvey2010.pdf.Google Scholar
- (1993) Narrative Analysis. Qualitative Research Methods Series, no. 30 (Sage, Newbury Park, CA).Google Scholar
- (1992) Sociological Theory (McGraw-Hill, New York).Google Scholar
- (2002) Learning to implement enterprise systems: An exploratory study of the dialectics of change. J. Management Inform. Systems 19(1):17–46.Crossref, Google Scholar
- (2011) Exploring users’ appropriation and post-implementation managerial intervention in the context of industry IOIS. Inform. Systems J. 21(3):223–248.Crossref, Google Scholar
- (2003) Persistence and change in system development: A dialectical view. J. Inform. Tech. 18:69–92.Crossref, Google Scholar
- SafeNet (2014) Customer sentiment survey. Accessed January 2, 2019, http://www.safenet-inc.com/news/2014/data-breaches-impact-on-customer-loyalty-survey/#sthash.VfTVqGI5.dpuf.Google Scholar
- (1989) Four Decades of Scientific Explanation (University of Minnesota Press, Minneapolis).Google Scholar
- (2006) Does the use of computer-based BPC tools contribute to redesign effectiveness? Insights from a hermeneutic study. IEEE Trans. Engrg. Management 53(1):130–145.Crossref, Google Scholar
- (2003) Understanding virtual team development: An interpretive study. J. Assoc. Inform. Systems 4(1):247–282.Google Scholar
- (2001) Using an adapted grounded theory approach for inductive theory building about virtual team development. Database Adv. Inform. Systems 32(1):38–56.Crossref, Google Scholar
- (2013) Guest editorial: Qualitative studies in information systems: A critical review and some guiding principles. MIS Quart. 37(4):iii–xviii.Google Scholar
- (2008) Modeling health behavior change: How to predict and modify the adoption and maintenance of health behaviors. Appl. Psych. 57(1):1–29.Crossref, Google Scholar
- (1994) Determinants of innovative behavior: A path model of individual innovation in the workplace. Acad. Management J. 37(3):580–607.Crossref, Google Scholar
- (2007) Rule-bending. Can prudential judgment affect rule compliance and values in the workplace? Public Integrity 9(3):225–243.Crossref, Google Scholar
- (2002) Institutional contradictions, praxis and institutional change: A dialectical perspective. Acad. Management Rev. 27(2):222–247.Crossref, Google Scholar
- (2010) To explain or to predict. Statist. Sci. 25(3):289–310.Crossref, Google Scholar
- (2018) Intervention effect rates as a path to research relevance: Information systems security example. J. Assoc. Inform. Systems 19(4):247–265.Google Scholar
- (2018) Demystifying the influential IS legends of positivism. J. Assoc. Inform. Systems 19(7):600–617.Google Scholar
- (2014) Guidelines for improving the contextual relevance of field surveys: The case of information security policy violations. Eur. J. Inform. Systems 23(3):289–305.Crossref, Google Scholar
- (2010) Neutralization: New insight into the problem of employee information systems security policy violations. MIS Quart. 34(3):487–502.Crossref, Google Scholar
- (2003) Searching for the structure of coping: A review and critique of category systems for classifying ways of coping. Psych. Bull. 129(2):216–269.Crossref, Google Scholar
- (2011) Out of fear or desire? Toward a better understanding of employees’ motivation to follow IS security policies. Inform. Management 48(7):296–302.Crossref, Google Scholar
- (1999) Tax professionals’ interpretations of ambiguity in compliance and planning decision contexts. J Amer. Taxation Assoc. 21(2):75–89.Crossref, Google Scholar
- (2002) Context dependence and aggregation in disaggregate choice analysis. Marketing Lett. 13(3):195–205.Crossref, Google Scholar
- (2010) When policy meets practice: Colliding logics and the challenges of ‘mode 2’ initiatives in the translation of academic knowledge. Organ. Stud. 31(9&10): 1311–1340.Crossref, Google Scholar
- (2011) An integrative model of legitimacy judgments. Acad. Management Rev. 36(4):686–710.Crossref, Google Scholar
- (2004) Dialectic, contradiction, or double bind? Analyzing and theorizing employee reactions to organizational tension. J. Appl. Comm. Res. 32(2):119–146.Crossref, Google Scholar
- (2006) Why People Obey the Law (Princeton University Press, Princeton, NJ).Crossref, Google Scholar
- (2005) Can businesses effectively regulate employee conduct? The antecedents of rule following in work settings. Acad. Management J. 48(6):1143–1158.Crossref, Google Scholar
- (2013) Using grounded theory method in information systems: The researcher as blank slate and other myths. J. Inform. Tech. 28(3):224–236.Crossref, Google Scholar
- (2010) Putting the “theory” back into grounded theory: Guidelines for grounded theory studies in information systems. Inform. Systems J. 20(4):357–381.Crossref, Google Scholar
- (2014) On the way to attestation: Trust and suspicion in Ricoeur’s hermeneutics. Internat. J. Philos. Theology 75(2):129–141.Crossref, Google Scholar
- (1995) Explaining development and change in organizations. Acad. Management Rev. 20(3):510–540.Crossref, Google Scholar
- (1979) Reclaiming qualitative methods for organizational research: A preface. Admin. Sci. Quart. 24(4): 520–526.Crossref, Google Scholar
- (2006) Doing interpretive research. Eur. J. Inform. Systems 15(3):320–330.Crossref, Google Scholar
- (1995) Interpretive case studies in IS research: Nature and method. Eur. J. Inform. Systems 4(2):74–81.Crossref, Google Scholar
- (2012) Motivating IS security compliance: Insights from habit and protection motivation theory. Inform. Management 49(3-4):190–198.Crossref, Google Scholar
- (2014) Ethical climate and pro-social rule breaking in the workplace. Human Resource Management Rev. 24(1):108–118.Crossref, Google Scholar
- (2004) Misbehavior in Organizations: Theory, Research and Management (Lawrence Erlbaum, Mahwah, NJ).Google Scholar
- (2007) Toward a dialectic perspective on formalization in interorganizational relationships: How alliance managers capitalize on the duality inherent in contracts, rules and procedures. Organ. Stud. 28(4):437–466.Crossref, Google Scholar
- (1995) Sensemaking in Organizations (Sage, Thousand Oaks, CA).Google Scholar
- (1998) Stage theories of health behavior: Conceptual and methodological issues. Health Psych. 17(3):290–299.Crossref, Google Scholar
- (2001) Motivations for compliance with environmental regulations. J. Policy Anal. Management 20(4):675–689.Crossref, Google Scholar
- (2008) Security lapses and the omission of information security measures: A threat control model and empirical test. Comput. Human Behav. 24(6):2799–2816.Crossref, Google Scholar

