TableĀ 3

Distinctions between compliance and violation

FeatureCompliance (policy adherence)Violation (policy breach)
Behavioral natureAdherence: Execution of a mandated protocol. This includes commission (e.g. attending training, using MFA) and omission (e.g. refraining from prohibited websites)Transgression: Breaking a rule (e.g. using unlicensed applications) or bypassing control (e.g. sharing passwords)
MotivationValue-alignedRisk-benefit driven, situational opportunity
Psychological focusPromotional focus: Achieving a state of security alignmentPrevention focus: Avoiding a state of risk, detection, and subsequent punishment
Primary intentConstructive: Driven by the desire to fulfill obligations, protect the organization, or maintain professional normsInstrumental/Deviant: Driven by the desire to bypass obstacles, gain convenience, or achieve personal ends
Enforcement signalAdministrative: Typically, high visibility and easy to audit (high celerity)Investigative: Often technical or hidden; harder to detect and prove (low celerity)
Examples in IS literatureUsing encrypted drives, changing passwords regularly, performing software updates, attending required training, etc.Unauthorized data downloading, use of shadow IT, visiting prohibited websites, etc.

or Create an Account

Close subscription notice
Close access options