Information security policy (ISP) is a critical pillar of the organization's protection arsenal. However, failure to comply with information security policies remains a significant challenge. The potential damage that such behavior could cause is significant. Despite noncompliant behavior having been extensively researched, it is still a challenge due to human factors. The purpose of this study is to investigate the primary factors influencing compliance behavior by employing the theory of interpersonal behavior as a theoretical scaffold in an educational setting, particularly in the context of university students.
To empirically test the conceptual model, a study surveying 238 students in a higher education institution in Saudi Arabia was undertaken. The collected data were then analyzed using structural equation modeling to examine the variable correlations.
The findings highlight that affect, habitual behavior and intentional behavior significantly influence actual compliance with ISP within this population. They also identify the limited role of facilitating conditions and perceived consequences in predicting compliance.
The findings emphasize the need for organizations to customize their cybersecurity strategies in accordance with local cultural norms and social standards. This approach ensures that security measures are not only effective but also culturally and contextually relevant by aligning them with employees' communication styles, power distance expectations, risk tolerance levels and privacy attitudes. Overall, the findings offer valuable insight to researchers, stakeholders, organizational executives and legislators.
