Going Beyond Deterrence: A Middle-Range Theory of Motives and Controls for Insider Computer Abuse

Published Online:https://doi.org/10.1287/isre.2022.1133

References

  • Ambrose ML, Seabright MA, Schminke M (2002) Sabotage in the workplace: The role of organizational injustice. Organ. Behav. Human Decision Processes 89(1):947–965.CrossrefGoogle Scholar
  • Andrews DA, Bonta J (2010) The Psychology of Criminal Conduct (Matthew Bender & Company, New Providence, NJ).Google Scholar
  • Aquino K, Reed AII (2002) The self-importance of moral identity. J. Personality Soc. Psych. 83(6):1423–1440.CrossrefGoogle Scholar
  • Ariely D, Wertenbroch K (2002) Procrastination, deadlines, and performance: Self-control by precommitment. Psych. Sci. 13(3):219–224.CrossrefGoogle Scholar
  • Avgerou C (2001) The significance of context in information systems and organizational change. Inform. Systems J. 11(1):43–63.CrossrefGoogle Scholar
  • Barbuto JE (2005) Motivation and transactional, charismatic, and transformational leadership: A test of antecedents. J. Leadership Organ. Stud. 11(4):26–40.CrossrefGoogle Scholar
  • Bennett RJ, Robinson SL (2000) Development of a measure of workplace deviance. J. Appl. Psych. 85(3):349–360.CrossrefGoogle Scholar
  • Bentham J (1988) An Introduction to the Principles of Morals and Legislation (Prometheus Books, New York).Google Scholar
  • Bordia P, Restubog SLD, Tang RL (2008) When employees strike back: Investigating mediating mechanisms between psychological contract breach and workplace deviance. J. Appl. Psych. 93(5):1104–1117.CrossrefGoogle Scholar
  • Boss SR, Galletta DF, Lowry PB, Moody GD, Polak P (2015) What do systems users have to fear? Using fear appeals to engender threats and fear that motivate protective security behaviors. MIS Quart. 39(4):837–864.CrossrefGoogle Scholar
  • Boss SR, Kirsch LJ, Angermeier I, Shingler RA, Boss RW (2009) If someone is watching, I’ll do what I’m asked: Mandatoriness, control, and information security. Eur. J. Inform. Systems 18(2):151–164.CrossrefGoogle Scholar
  • Brennan G, Hamlin A (1998) Expressive voting and electoral equilibrium. Public Choice 95(1):149–175.CrossrefGoogle Scholar
  • Breward M, Hassanein K, Head M (2017) Understanding consumers’ attitudes toward controversial information technologies: A contextualization approach. Inform. Systems Res. 28(4):760–774.LinkGoogle Scholar
  • Bulgurcu B, Cavusoglu H, Benbasat I (2010) Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quart. 34(4):523–548.CrossrefGoogle Scholar
  • Burns AJ, Posey C, Roberts TL, Lowry PB (2017) Examining the relationship of organizational insiders’ psychological capital with information security threat and coping appraisals. Comput. Human Behav. 68(March):190–209.CrossrefGoogle Scholar
  • Burns AJ, Roberts TL, Posey C, Bennett RJ, Courtney JF (2018) Intentions to comply vs. intentions to protect: A VIE theory approach to understanding the influence of insiders’ awareness of organizational SETA efforts. Decision Sci. 49(6):1187–1228.CrossrefGoogle Scholar
  • Chatterjee S, Sarker S, Valacich JS (2015) The behavioral roots of information systems security: Exploring key factors related to unethical IT use. J. Management Inform. Systems 31(4):49–87.CrossrefGoogle Scholar
  • Chen Y, Ramamurthy K, Wen KW (2012) Organizations’ information security policy compliance: Stick or carrot approach? J. Management Inform. Systems 29(3):157–188.CrossrefGoogle Scholar
  • Chin WW, Thatcher JB, Wright RT, Steel D (2013) Controlling for common method variance in PLS analysis: The measured latent marker variable approach. Abdi H, Chin WW, Vinzi VE, Russolillo G, Trinchera L, eds. New Perspectives in Partial Least Squares and Related Methods (Springer, New York), 231–239.CrossrefGoogle Scholar
  • Chiu SF, Peng JC (2008) The relationship between psychological contract breach and employee deviance: The moderating role of hostile attributional style. J. Vocational Behav. 73(3):426–433.CrossrefGoogle Scholar
  • Cohen J (1988) Statistical Power Analysis for the Behavioral Sciences, 2nd ed. (Lawrence Erlbaum Associates, Hillsdale, NJ).Google Scholar
  • Crossler RE, Johnston AC, Lowry PB, Hu Q, Warkentin M, Baskerville R (2013) Future directions for behavioral information security research. Comput. Security 32(February):90–101.CrossrefGoogle Scholar
  • D’Arcy J, Herath T (2011) A review and analysis of deterrence theory in the IS security literature: Making sense of the disparate findings. Eur. J. Inform. Systems 20(6):643–658.CrossrefGoogle Scholar
  • D’Arcy J, Hovav A (2007) Deterring internal information systems misuse. Comm. ACM 50(10):113–117.CrossrefGoogle Scholar
  • D’Arcy J, Lowry PB (2019) Cognitive‐affective drivers of employees’ daily compliance with information security policies: A multilevel, longitudinal study. Inform. Systems J. 29(1):43–69.CrossrefGoogle Scholar
  • D’Arcy J, Herath T, Shoss M (2014) Understanding employee responses to stressful information security requirements: A coping perspective. J. Management Inform. Systems 31(2):285–318.CrossrefGoogle Scholar
  • D’Arcy J, Hovav A, Galletta D (2009) User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach. Inform. Systems Res. 20(1):79–98.LinkGoogle Scholar
  • Dalal RS (2005) A meta-analysis of the relationship between organizational citizenship behavior and counterproductive work behavior. J. Appl. Psych. 90(6):1241–1255.CrossrefGoogle Scholar
  • Davison RM, Martinsons MG (2016) Context is king! Considering particularism in research design and reporting. J. Inform. Tech. 31(3):241–249.CrossrefGoogle Scholar
  • Dey D, Ghoshal A, Lahiri A (2021) Circumventing circumvention: An economic analysis of the role of education and enforcement. Management Sci., ePub ahead of print August 11, 2021, https://doi.org/10.1287/mnsc.2021.4027.Google Scholar
  • Feshbach S (1964) The function of aggression and the regulation of aggressive drive. Psych. Rev. 71(4):257–272.CrossrefGoogle Scholar
  • Fornell C, Bookstein FL (1982) Two structural equation models: LISREL and PLS applied to consumer exit-voice theory. J. Marketing Res. 19(4):440–452.CrossrefGoogle Scholar
  • Fornell C, Larcker DF (1981) Evaluating structural equation models with unobservable variables and measurement error. J. Marketing Res. 18(1):39–50.CrossrefGoogle Scholar
  • Foth M (2016) Factors influencing the intention to comply with data protection regulations in hospitals: Based on gender differences in behaviour and deterrence. Eur. J. Inform. Systems 25(2):91–109.CrossrefGoogle Scholar
  • Gerbing DW, Anderson JC (1988) An updated paradigm for scale development incorporating unidimensionality and its assessment. J. Marketing Res. 25(2):186–192.CrossrefGoogle Scholar
  • Gino F, Schweitzer ME, Mead NL, Ariely D (2011) Unable to resist temptation: How self-control depletion promotes unethical behavior. Organ. Behav. Human Decision Processes 115(2):191–203.CrossrefGoogle Scholar
  • Gottfredson MR (2011) Sanctions, situations, and agency in control theories of crime. Eur. J. Criminology 8(2):128–143.CrossrefGoogle Scholar
  • Gottfredson M (2017) Self-control theory and crime. Oxford Research Encyclopedia of Criminology. Retrieved September 6, https://oxfordre.com/criminology/view/10.1093/acrefore/9780190264079.001.0001/acrefore-9780190264079-e-252.Google Scholar
  • Gottfredson M, Hirschi T (1990) A General Theory of Crime (Stanford University Press, Stanford, CA).CrossrefGoogle Scholar
  • Greenberg A (2020) A Tesla employee thwarted an alleged ransomware plot. Wired (August 27), https://www.wired.com/story/tesla-ransomware-insider-hack-attempt/.Google Scholar
  • Gregor S (2006) The nature of theory in information systems. MIS Quart. 30(3):611–642.CrossrefGoogle Scholar
  • Grover V, Lyytinen K (2015) New state of play in information systems research: The push to the edges. MIS Quart. 39(2):271–296.CrossrefGoogle Scholar
  • Guo KH, Yuan Y, Archer NP, Connelly CE (2011) Understanding nonmalicious security violations in the workplace: A composite behavior model. J. Management Inform. Systems 28(2):203–236.CrossrefGoogle Scholar
  • Hagger MS, Wood C, Stiff C, Chatzisarantis NLD (2010) Ego depletion and the strength model of self-control: A meta-analysis. Psych. Bull. 136(4):495–525.CrossrefGoogle Scholar
  • Hair JF, Hult GTM, Ringle CM, Sarstedt M (2017) A Primer on Partial Least Squares Structural Equations Modeling (PLS-SEM), 2nd ed. (SAGE, Thousand Oaks, CA).Google Scholar
  • Han J, Kim YJ, Kim H (2017) An integrative model of information security policy compliance with psychological contract: Examining a bilateral perspective. Comput. Security 66(May):52–65.CrossrefGoogle Scholar
  • Harrington SJ (1996) The effect of codes of ethics and personal denial of responsibility on computer abuse judgments and intentions. MIS Quart. 20(3):257–278.CrossrefGoogle Scholar
  • Hassan NR, Lowry PB (2015) Seeking middle-range theories in information systems research. Proc. Internat. Conf. Inform. Systems, December 13–18 (ICIS, Fort Worth, TX).Google Scholar
  • Hassan NR, Mathiassen L, Lowry PB (2019) The process of information systems theorizing as a discursive practice. J. Inform. Tech. 34(3):198–220.CrossrefGoogle Scholar
  • Henseler J, Chin WW (2010) A comparison of approaches for the analysis of interaction effects between latent variables using partial least squares path modeling. Structural Equation Model. 17(1):82–109.CrossrefGoogle Scholar
  • Henseler J, Ringle CM, Sarstedt M (2015) A new criterion for assessing discriminant validity in variance-based structural equation modeling. J. Acad. Marketing Sci. 43(1):115–135.CrossrefGoogle Scholar
  • Henseler J, Dijkstra TK, Sarstedt M, Ringle CM, Diamantopoulos A, Straub DW, Ketchen DJ, Hair JF, Hult GTM, Calantone RJ (2014) Common beliefs and reality about PLS: Comments on Rönkkö and Evermann (2013). Organ. Res. Methods 17(2):182–209.CrossrefGoogle Scholar
  • Herath T, Rao HR (2009) Protection motivation and deterrence: A framework for security policy compliance in organisations. Eur. J. Inform. Systems 18(2):106–125.CrossrefGoogle Scholar
  • Hirschi T (2017) Causes of Delinquency (Routledge, New York).CrossrefGoogle Scholar
  • Holtfreter K, Reisig MD, Pratt TC (2008) Low self-control, routine activities, and fraud victimization. Criminology 46(1):189–220.CrossrefGoogle Scholar
  • Hong W, Chan FKY, Thong JYL, Chasalow LC, Dhillon G (2014) A framework and guidelines for context-specific theorizing in information systems research. Inform. Systems Res. 25(1):111–136.LinkGoogle Scholar
  • Hu L, Bentler PM (1999) Cutoff criteria for fit indexes in covariance structure analysis: Conventional criteria vs. new alternatives. Structural Equation Model. 6(1):1–55.CrossrefGoogle Scholar
  • Hu Q, West R, Smarandescu L (2015) The role of self-control in information security violations: Insights from a cognitive neuroscience perspective. J. Management Inform. Systems 31(4):6–48.CrossrefGoogle Scholar
  • Hu Q, Xu Z, Dinev T, Ling H (2011) Does deterrence work in reducing information security policy abuse by employees? Comm. ACM 54(6):54–60.CrossrefGoogle Scholar
  • IBM (2021) Cost of a data breach report 2021, Accessed November 11, 2021, https://www.ibm.com/security/data-breach.Google Scholar
  • Jensen ML, Dinger M, Wright RT, Thatcher JB (2017) Training to mitigate phishing attacks using mindfulness techniques. J. Management Inform. Systems 34(2):597–626.CrossrefGoogle Scholar
  • Johnson RE, Lin SH, Lee HW (2018) Self-control as the fuel for effective self-regulation at work: Antecedents, consequences, and boundary conditions of employee self-control. Elliot AJ, ed. Advances in Motivation Science, vol. 5 (Elsevier, Cambridge, MA), 87–128.Google Scholar
  • Johnston AC, Warkentin M (2010) Fear appeals and information security behaviors: An empirical study. MIS Quart. 34(3):549–566.CrossrefGoogle Scholar
  • Johnston AC, Warkentin M, Siponen M (2015) An enhanced fear appeal rhetorical framework: Leveraging threats to the human asset through sanctioning rhetoric. MIS Quart. 39(1):113–134.CrossrefGoogle Scholar
  • Johnston AC, Warkentin M, McBride M, Carter L (2016) Dispositional and situational factors: Influences on information security policy violations. Eur. J. Inform. Systems 25(3):231–251.CrossrefGoogle Scholar
  • Jones S, Lynam DR (2009) In the eye of the impulsive beholder: The interaction between impulsivity and perceived informal social control on offending. Criminal Justice Behav. 36(3):307–321.CrossrefGoogle Scholar
  • Kays K, Gathercoal K, Buhrow W (2012) Does survey format influence self-disclosure on sensitive question items? Comput. Human Behav. 28(1):251–256.CrossrefGoogle Scholar
  • Khansa L, Kuem J, Siponen M, Kim SS (2017) To cyberloaf or not to cyberloaf: The impact of the announcement of formal organizational controls. J. Management Inform. Systems 34(1):141–176.CrossrefGoogle Scholar
  • Kunze M, Gower K (2012) The influence of subordinate affect and self-monitoring on multiple dimensions of leader-member exchange. Internat. J. Management Marketing Res. 5(3):83–100.Google Scholar
  • Lee SM, Lee SG, Yoo S (2004) An integrative model of computer abuse based on social control and general deterrence theories. Inform. Management 41(6):707–718.CrossrefGoogle Scholar
  • Leidner D, Tona O (2021) The CARE theory of dignity amid personal data digitalization. MIS Quart. 45(1b):343–370.CrossrefGoogle Scholar
  • Leonard NH, Beauvais LL, Scholl RW (1999) Work motivation: The incorporation of self-concept-based processes. Human Relations 52(8):969–998.CrossrefGoogle Scholar
  • Li H, Luo XR, Chen Y (2021) Understanding information security policy violation from a situational action perspective. J. Assoc. Inform. Systems 22(3):5.Google Scholar
  • Li H, Luo X, Zhang J, Sarathy R (2018) Self-control, organizational context, and rational choice in internet abuses at work. Inform. Management 55(3):358–367.CrossrefGoogle Scholar
  • Lian H, Brown DJ, Ferris DL, Liang LH, Keeping LM, Morrison R (2014) Abusive supervision and retaliation: A self-control framework. Acad. Management J. 57(1):116–139.CrossrefGoogle Scholar
  • Liang H, Saraf N, Hu Q, Xue Y (2007) Assimilation of enterprise systems: The effect of institutional pressures and the mediating role of top management. MIS Quart. 31(1):59–87.CrossrefGoogle Scholar
  • Lin TC, Huang SL, Chiang SC (2018) User resistance to the implementation of information systems: A psychological contract breach perspective. J. Assoc. Inform. Systems 19(4):306–332.Google Scholar
  • Locke EA (1981) Goal setting and task performance: 1969–1980. Psych. Bull. 90(1):125–152.CrossrefGoogle Scholar
  • Lowry PB, Gaskin J (2014) Partial least squares (PLS) structural equation modeling (SEM) for building and testing behavioral causal theory: When to choose it and how to use it. IEEE Trans. Professional Comm. 57(2):123–146.CrossrefGoogle Scholar
  • Lowry PB, Dinev T, Willison R (2017a) Why security and privacy research lies at the centre of the information systems (IS) artefact: Proposing a bold research agenda. Eur. J. Inform. Systems 26(6):546–563.CrossrefGoogle Scholar
  • Lowry PB, Moody GD, Chatterjee S (2017b) Using IT design to prevent cyberbullying. J. Management Inform. Systems 34(3):863–901.CrossrefGoogle Scholar
  • Lowry PB, D’Arcy J, Hammer B, Moody GD (2016a) “Cargo cult” science in traditional organization and information systems survey research: A case for using nontraditional methods of data collection, including Mechanical Turk and online panels. J. Strategic Inform. Systems 25(3):232–240.CrossrefGoogle Scholar
  • Lowry PB, Moody G, Galletta D, Vance A (2013a) The drivers in the use of online whistle-blowing reporting systems. J. Management Inform. Systems 30(1):153–189.CrossrefGoogle Scholar
  • Lowry PB, Posey C, Bennett RJ, Roberts TL (2015) Leveraging fairness and reactance theories to deter reactive computer abuse following enhanced organisational information security policies: An empirical study of the influence of counterfactual reasoning and organisational trust. Inform. Systems J. 25(3):193–273.CrossrefGoogle Scholar
  • Lowry PB, Posey C, Roberts TL, Bennett RJ (2013b) Is your banker leaking your personal information? The roles of ethics and individual-level cultural characteristics in predicting organizational computer abuse. J. Bus. Ethics 121(3):385–401.CrossrefGoogle Scholar
  • Lowry PB, Zhang J, Wang C, Siponen M (2016b) Why do adults engage in cyberbullying on social media? An integration of online disinhibition and deindividuation effects with the social structure and social learning model. Inform. Systems Res. 27(4):962–986.LinkGoogle Scholar
  • Lowry PB, Zhang J, Moody GD, Chatterjee S, Wang C, Wu T (2019) An integrative theory addressing cyberharassment in the light of technology-based opportunism. J. Management Inform. Systems 36(4):1142–1178.CrossrefGoogle Scholar
  • Luo XR, Li H, Hu Q, Xu H (2020) Why individual employees commit malicious computer abuse: A routine activity theory perspective. J. Assoc. Inform. Systems 21(6):1552–1593.Google Scholar
  • Meier RF, Johnson WT (1977) Deterrence as social control: The legal and extralegal production of conformity. Amer. Sociol. Rev. 42(2):292–304.CrossrefGoogle Scholar
  • Menard P, Warkentin M, Lowry PB (2018) The impact of collectivism and psychological ownership on protection motivation: A cross-cultural examination. Comput. Security 75(June):147–166.CrossrefGoogle Scholar
  • Merton RK (1968) Social Theory and Social Structure (Free Press, New York).Google Scholar
  • Miller S (2018) 2017 U.S. state of cybercrime highlights. SEI Blog (January 17), https://insights.sei.cmu.edu/insider-threat/2018/01/2017-us-state-of-cybercrime-highlights.html.Google Scholar
  • Moody GD, Siponen M, Pahnila S (2018) Toward a unified model of information security policy compliance. MIS Quart. 42(1):285–311.CrossrefGoogle Scholar
  • Morrison EW, Robinson SL (1997) When employees feel betrayed: A model of how psychological contract violation develops. Acad. Management Rev. 22(1):226–256.CrossrefGoogle Scholar
  • Murray KT, Kochanska G (2002) Effortful control: Factor structure and relation to externalizing and internalizing behaviors. J. Abnormal Child Psych. 30(5):503–514.CrossrefGoogle Scholar
  • Myyry L, Siponen M, Pahnila S, Vartiainen T, Vance A (2009) What levels of moral reasoning and values explain adherence to information security rules? An empirical study. Eur. J. Inform. Systems 18(2):126–139.CrossrefGoogle Scholar
  • Nagin DS (1998) Deterrence and incapacitation. Tonry M, ed. The Handbook of Crime and Punishment (Oxford University Press, New York), 345–368.Google Scholar
  • Nagin DS, Paternoster R (1993) Enduring individual differences and rational choice theories of crime. Law Soc. Rev. 27(3):467–496.CrossrefGoogle Scholar
  • Nagin DS, Pogarsky G (2001) Integrating celerity, impulsivity, and extralegal sanction threats into a model of general deterrence: Theory and evidence. Criminology 39(4):865–892.CrossrefGoogle Scholar
  • Nunnally J (1978) Psychometric Theory (McGraw-Hill, New York).Google Scholar
  • Park Y, El Sawy OA, Fiss P (2017) The role of business intelligence and communication technologies in organizational agility: A configurational approach. J. Assoc. Inform. Systems 18(9):648–686.Google Scholar
  • Parsons T, Bales RF (1955) Family, Socialization and Interaction Process (Free Press, Glencoe, IL).Google Scholar
  • Pavlou PA, Gefen D (2005) Psychological contract violation in online marketplaces: Antecedents, consequences, and moderating role. Inform. Systems Res. 16(4):372–399.LinkGoogle Scholar
  • Petter S, Straub DW, Rai A (2007) Specifying formative constructs in information systems research. MIS Quart. 31(4):623–656.CrossrefGoogle Scholar
  • Piquero AR, Paternoster R, Pogarsky G, Loughran T (2011) Elaborating the individual difference component in deterrence theory. Annu. Rev. Law Soc. Sci. 7(1):335–360.CrossrefGoogle Scholar
  • Podsakoff PM, MacKenzie SB, Lee JY, Podsakoff NP (2003) Common method biases in behavioral research: a critical review of the literature and recommended remedies. J. Appl. Psych. 88(5):879–903.CrossrefGoogle Scholar
  • Ponemon Institute (2018) 2018 cost of a data breach report: Global overview. accessed April 18, 2019, https://www.ibm.com/downloads/cas/861MNWN2.Google Scholar
  • Posey C, Bennett RJ, Roberts TL (2011) Understanding the mindset of the abusive insider: An examination of insiders’ causal reasoning following internal security changes. Comput. Security 30(6):486–497.CrossrefGoogle Scholar
  • Posey C, Roberts TL, Lowry PB (2015) The impact of organizational commitment on insiders’ motivation to protect organizational information assets. J. Management Inform. Systems 32(4):179–214.CrossrefGoogle Scholar
  • Posey C, Roberts TL, Lowry PB, Bennett RJ, Courtney JF (2013) Insiders’ protection of organizational information assets: Development of a systematics-based taxonomy and theory of diversity for protection-motivated behaviors. MIS Quart. 37(4):1189–1210.CrossrefGoogle Scholar
  • PWC (2014) Managing cyber risks in an interconnected world: Key findings from the Global State of Information Security Survey 2015. Acccessed December 12, 2014, https://www.pwc.com/gx/en/consulting-services/information-security-survey/assets/the-global-state-of-information-security-survey-2015.pdf.Google Scholar
  • Qin X, Huang M, Johnson RE, Hu Q, Ju D (2018) The short-lived benefits of abusive supervisory behavior for actors: An investigation of recovery and work engagement. Acad. Management J. 61(5):1951–1975.CrossrefGoogle Scholar
  • Restubog SLD, Bordia P, Tang RL (2006) Effects of psychological contract breach on performance of IT employees: The mediating role of affective commitment. J. Occupational Organ. Psych. 79(2):299–306.CrossrefGoogle Scholar
  • Ringle CM, Wende S, Becker JM (2015) SmartPLS3. SmartPLS GmbH, Bönningstedt, Germany.Google Scholar
  • Rivard S (2021) Theory building is neither an art nor a science: It is a craft. J. Inform. Tech. 36(3):316–328.CrossrefGoogle Scholar
  • Robinson SL, Bennett RJ (1995) A typology of deviant workplace behaviors: A multidimensional scaling study. Acad. Management J. 38(2):555–572.CrossrefGoogle Scholar
  • Robinson SL, Bennett RJ (1997) Workplace deviance: Its definition, its manifestations, and its causes. Lewicki RJ, Bies RJ, Sheppard BH, eds. Research on Negotiations in Organizations, vol. 6 (Elsevier, Amsterdam), 3–27.Google Scholar
  • Robinson SL, Morrison EW (2000) The development of psychological contract breach and violation: A longitudinal study. J. Organ. Behav. 21(5):525–546.CrossrefGoogle Scholar
  • Robinson SL, O’Leary-Kelly AM (1998) Monkey see, monkey do: The influence of work groups on the antisocial behavior of employees. Acad. Management J. 41(6):658–672.CrossrefGoogle Scholar
  • Rousseau DM (1989) Psychological and implied contracts in organizations. Employee Responsibilities Rights J. 2(2):121–139.CrossrefGoogle Scholar
  • Rousseau DM (2004) Psychological contracts in the workplace: Understanding the ties that motivate. Acad. Management Perspect. 18(1):120–127.CrossrefGoogle Scholar
  • Schreck CJ (1999) Criminal victimization and low self-control: An extension and test of a general theory of crime. Justice Quart. 16(3):633–654.CrossrefGoogle Scholar
  • Schreck CJ, Stewart EA, Osgood DW (2008) A reappraisal of the overlap of violent offenders and victims. Criminology 46(4):871–906.CrossrefGoogle Scholar
  • Schwarz A, Rizzuto T, Carraher-Wolverton C, Roldán JL, Barrera-Barrera R (2017) Examining the impact and detection of the urban legend of common method bias. ACM SIGMIS Database 48(1):93–119.CrossrefGoogle Scholar
  • Siponen M, Vance A (2010) Neutralization: New insights into the problem of employee information systems security policy violations. MIS Quart. 34(3):487–502.CrossrefGoogle Scholar
  • Sojer M, Alexy O, Kleinknecht S, Henkel J (2014) Understanding the drivers of unethical programming behavior: The inappropriate reuse of Internet-accessible code. J. Management Inform. Systems 31(3):287–325.CrossrefGoogle Scholar
  • Soper D (2019) Post-hoc statistical power calculator for hierarchical multiple regression, version 4.0, Accessed January 16, 2019, https://www.danielsoper.com/statcalc/calculator.aspx?id=17.Google Scholar
  • Storrod ML, Densley JA (2017) “Going viral” and “Going country”: The expressive and instrumental activities of street gangs on social media. J. Youth Stud. 20(6):677–696.CrossrefGoogle Scholar
  • Straub DW (1990) Effective IS security. Inform. Systems Res. 1(3):255–276.LinkGoogle Scholar
  • Straub DW, Nance W (1990) Discovering and disciplining computer abuse in organizations: A field study. MIS Quart. 14(1):45–60.CrossrefGoogle Scholar
  • Sutton G, Griffin MA (2004) Integrating expectations, experiences, and psychological contract violations: A longitudinal study of new professionals. J. Occupational Organ. Psych. 77(4):493–514.CrossrefGoogle Scholar
  • Tangney JP, Baumeister RF, Boone AL (2004) High self-control predicts good adjustment, less pathology, better grades, and interpersonal success. J. Personality 72(2):271–324.CrossrefGoogle Scholar
  • Tekleab AG, Takeuchi R, Taylor MS (2005) Extending the chain of relationships among organizational justice, social exchange, and employee reactions: The role of contract violations. Acad. Management J. 48(1):146–157.CrossrefGoogle Scholar
  • Tibbetts SG, Gibson CL (2002) Individual propensities and rational decision-making: Recent findings and promising approaches. Piquero AR, Tibbetts SG, eds. Rational Choice and Criminal Behavior Recent Research and Future Challenges (Routledge, New York), 3–24.Google Scholar
  • Tiwana A (2009) Governance-knowledge fit in systems development projects. Inform. Systems Res. 20(2):180–197.LinkGoogle Scholar
  • Tiwana A (2015) Evolutionary competition in platform ecosystems. Inform. Systems Res. 26(2):266–281.LinkGoogle Scholar
  • Turanovic JJ, Pratt TC (2014) “Can’t stop, won’t stop”: Self-control, risky lifestyles, and repeat victimization. J. Quant. Criminol. 30(1):29–56.CrossrefGoogle Scholar
  • Vance A, Lowry PB, Eggett D (2013) Using accountability to reduce access policy violations in information systems. J. Management Inform. Systems 29(4):263–289.CrossrefGoogle Scholar
  • Vardi Y (2001) The effects of organizational and ethical climates on misconduct at work. J. Bus. Ethics 29(4):325–337.CrossrefGoogle Scholar
  • Vroom V (1964) Work and Motivation (Wiley, Oxford, UK).Google Scholar
  • Wachi T, Watanabe K, Yokota K, Suzuki M, Hoshino M, Sato A, Fujita G (2007) Offender and crime characteristics of female serial arsonists in Japan. J. Investigative Psych. Offender Profiling 4(1):29–52.CrossrefGoogle Scholar
  • Wang M, Liao H, Zhan Y, Shi J (2011) Daily customer mistreatment and employee sabotage against customers: Examining emotion and resource perspectives. Acad. Management J. 54(2):312–334.CrossrefGoogle Scholar
  • Wehrt W, Casper A, Sonnentag S (2020) Beyond depletion: Daily self‐control motivation as an explanation of self‐control failure at work. J. Organ. Behav. 41(9):931–947.CrossrefGoogle Scholar
  • Wetzels M, Odekerken-Schroder G, Van Oppen C (2009) Using PLS path modeling for assessing hierarchical construct models: Guidelines and empirical illustration. MIS Quart. 33(1):177–196.CrossrefGoogle Scholar
  • Willison R, Lowry PB (2018) Disentangling the motivations for organizational insider computer abuse through the rational choice and life course perspectives. ACM SIGMIS Database 49(S1):81–102.CrossrefGoogle Scholar
  • Willison R, Warkentin M (2013) Beyond deterrence: An expanded view of employee computer abuse. MIS Quart. 37(1):1–20.CrossrefGoogle Scholar
  • Willison R, Lowry PB, Paternoster R (2018a) A tale of two deterrents: Considering the role of absolute and restrictive deterrence in inspiring new directions in behavioral and organizational security. J. Assoc. Inform. Systems 19(12):1187–1216.Google Scholar
  • Willison R, Warkentin M, Johnston AC (2018b) Examining employee computer abuse intentions: Insights from justice, deterrence and neutralization perspectives. Inform. Systems J. 28(2):266–293.CrossrefGoogle Scholar
  • Xu B, Xu Z, Li D (2016) Internet aggression in online communities: A contemporary deterrence perspective. Inform. Systems J. 26(6):641–667.CrossrefGoogle Scholar
  • Youngs D, Ioannou M, Eagles J (2016) Expressive and instrumental offending: Reconciling the paradox of specialisation and versatility. Internat. J. Offender Therapy Comparative Criminology 60(4):397–422.CrossrefGoogle Scholar
  • Yu J (1994) Punishment celerity and severity: Testing a specific deterrence model on drunk driving recidivism. J. Criminal Justice 22(4):355–366.CrossrefGoogle Scholar
  • Zhao H, Wayne SJ, Glibkowski BC, Bravo J (2007) The impact of psychological contract breach on work‐related outcomes: A meta‐analysis. Personnel Psych. 60(3):647–680.CrossrefGoogle Scholar
INFORMS site uses cookies to store information on your computer. Some are essential to make our site work; Others help us improve the user experience. By using this site, you consent to the placement of these cookies. Please read our Privacy Statement to learn more.