International Journal of Applied Information Systems |
Foundation of Computer Science (FCS), NY, USA |
Volume 12 - Number 33 |
Year of Publication: 2020 |
Authors: Erick. O. Otieno, Agnes N. Wausi, Andrew M. Kahonge |
10.5120/ijais2020451879 |
Erick. O. Otieno, Agnes N. Wausi, Andrew M. Kahonge . A Theoretical Model for Information Security Policy Compliance Culture. International Journal of Applied Information Systems. 12, 33 ( September 2020), 6-14. DOI=10.5120/ijais2020451879
This paper provides a different perspective on information security management by investigating information security policy compliance culture. The results in this paper are drawn from the thesis in which the researchers sought to address the gap by employing a mixed method in developing a theoretical model. The resulting theoretical model was then subjected to a validation process through Confirmatory Factor Analysis using JASP-analytical software. Hypotheses were derived from the emergent model that formed the basis of developing the questionnaire instrument. This paper, therefore, presents the results of the validation process and synthesizes the final theoretical model constructs that explain information security policy compliance culture. The results validated the theoretical model with factor loading all above (0.5) thresholds and significance of (p < 0.001). The resulting model showed that information security managers should consider organizational, behavioral, and external factors while developing information security policy compliance culture strategies.