Distinctions between compliance and violation
| Feature | Compliance (policy adherence) | Violation (policy breach) |
|---|---|---|
| Behavioral nature | Adherence: Execution of a mandated protocol. This includes commission (e.g. attending training, using MFA) and omission (e.g. refraining from prohibited websites) | Transgression: Breaking a rule (e.g. using unlicensed applications) or bypassing control (e.g. sharing passwords) |
| Motivation | Value-aligned | Risk-benefit driven, situational opportunity |
| Psychological focus | Promotional focus: Achieving a state of security alignment | Prevention focus: Avoiding a state of risk, detection, and subsequent punishment |
| Primary intent | Constructive: Driven by the desire to fulfill obligations, protect the organization, or maintain professional norms | Instrumental/Deviant: Driven by the desire to bypass obstacles, gain convenience, or achieve personal ends |
| Enforcement signal | Administrative: Typically, high visibility and easy to audit (high celerity) | Investigative: Often technical or hidden; harder to detect and prove (low celerity) |
| Examples in IS literature | Using encrypted drives, changing passwords regularly, performing software updates, attending required training, etc. | Unauthorized data downloading, use of shadow IT, visiting prohibited websites, etc. |
| Feature | Compliance (policy adherence) | Violation (policy breach) |
|---|---|---|
| Behavioral nature | Adherence: Execution of a mandated protocol. This includes commission (e.g. attending training, using MFA) and omission (e.g. refraining from prohibited websites) | Transgression: Breaking a rule (e.g. using unlicensed applications) or bypassing control (e.g. sharing passwords) |
| Motivation | Value-aligned | Risk-benefit driven, situational opportunity |
| Psychological focus | Promotional focus: Achieving a state of security alignment | Prevention focus: Avoiding a state of risk, detection, and subsequent punishment |
| Primary intent | Constructive: Driven by the desire to fulfill obligations, protect the organization, or maintain professional norms | Instrumental/Deviant: Driven by the desire to bypass obstacles, gain convenience, or achieve personal ends |
| Enforcement signal | Administrative: Typically, high visibility and easy to audit (high celerity) | Investigative: Often technical or hidden; harder to detect and prove (low celerity) |
| Examples in IS literature | Using encrypted drives, changing passwords regularly, performing software updates, attending required training, etc. | Unauthorized data downloading, use of shadow IT, visiting prohibited websites, etc. |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.