Information security policy compliance behaviour model for Malaysian federal public sector agencies

Organizations leverage information security policies (ISP) to prevent information security incidents, but employees often fail to comply with them. as such, the Malaysian public sector has a comprehensive ISP in the form of circulars, policies, procedures, frameworks, and strategic plans. however, I...

Full description

Saved in:
Bibliographic Details
Main Author: Kuppusamy, Puspadevi
Format: Thesis
Language:English
Published: 2022
Subjects:
Online Access:http://eprints.utm.my/id/eprint/102431/1/PuspadewiKuppusamyPRAZAK2022.pdf
Tags: Add Tag
No Tags, Be the first to tag this record!
id my-utm-ep.102431
record_format uketd_dc
spelling my-utm-ep.1024312023-08-28T06:34:21Z Information security policy compliance behaviour model for Malaysian federal public sector agencies 2022 Kuppusamy, Puspadevi H Social Sciences (General) T Technology (General) Organizations leverage information security policies (ISP) to prevent information security incidents, but employees often fail to comply with them. as such, the Malaysian public sector has a comprehensive ISP in the form of circulars, policies, procedures, frameworks, and strategic plans. however, ISP compliance among Malaysian public sector employees remains low, with limited studies found in extant research. hence, this research aims to develop and validate a new model of factors that influence ISP compliance behaviour among Malaysian federal public sector agency employees. the research started with the identification of problems through conducting interviews with the relevant agencies and knowledge gaps by reviewing existing isp literature. then, a systematic literature review (SLR) was performed and analysed to identify the influencing factors of ISP compliance behaviour. a conceptual model was developed using factors from the theory of planned behaviour, social bond theory, protection motivation theory, and several other factors from literatures. next, the survey instrument items were developed, their content validated by nine experts, and a pilot test was conducted with 30 respondents. subsequently, data collection was conducted through email among 27 federal agency employees in Putrajaya and Kuala Lumpur, Malaysia. as a result, 360 valid responses were analysed to validate the conceptual model using ‘partial least square-structured equation modelling’ analysis. the model validation revealed that ‘attitude’, ‘perceived behavioural control’, ‘perceived response efficacy’, ‘perceived punishment severity’, ‘attachment’, ‘commitment’, ‘belief’, and ‘perceived benefit’ have positive effects on ISP compliance intention with p-value < 0.05. however, five factors, namely ‘subjective norm’, ‘threat severity’, ‘threat vulnerability’, ‘awareness training’ and ‘involvement’ were found to be non-significant towards ISP compliance intention with p-value > 0.05. these research findings were used to develop ISP compliance guidelines for the Malaysian public sector. the ISP compliance guidelines were reviewed by three ISP practitioners. overall, this research contributes theoretically, contextually, and practically towards ISP compliance, especially in the context of the Malaysian federal public sector agencies. 2022 Thesis http://eprints.utm.my/id/eprint/102431/ http://eprints.utm.my/id/eprint/102431/1/PuspadewiKuppusamyPRAZAK2022.pdf application/pdf en public http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:151690 phd doctoral Universiti Teknologi Malaysia, Razak Faculty of Technology and Informatics Razak Faculty of Technology and Informatics
institution Universiti Teknologi Malaysia
collection UTM Institutional Repository
language English
topic H Social Sciences (General)
T Technology (General)
spellingShingle H Social Sciences (General)
T Technology (General)
Kuppusamy, Puspadevi
Information security policy compliance behaviour model for Malaysian federal public sector agencies
description Organizations leverage information security policies (ISP) to prevent information security incidents, but employees often fail to comply with them. as such, the Malaysian public sector has a comprehensive ISP in the form of circulars, policies, procedures, frameworks, and strategic plans. however, ISP compliance among Malaysian public sector employees remains low, with limited studies found in extant research. hence, this research aims to develop and validate a new model of factors that influence ISP compliance behaviour among Malaysian federal public sector agency employees. the research started with the identification of problems through conducting interviews with the relevant agencies and knowledge gaps by reviewing existing isp literature. then, a systematic literature review (SLR) was performed and analysed to identify the influencing factors of ISP compliance behaviour. a conceptual model was developed using factors from the theory of planned behaviour, social bond theory, protection motivation theory, and several other factors from literatures. next, the survey instrument items were developed, their content validated by nine experts, and a pilot test was conducted with 30 respondents. subsequently, data collection was conducted through email among 27 federal agency employees in Putrajaya and Kuala Lumpur, Malaysia. as a result, 360 valid responses were analysed to validate the conceptual model using ‘partial least square-structured equation modelling’ analysis. the model validation revealed that ‘attitude’, ‘perceived behavioural control’, ‘perceived response efficacy’, ‘perceived punishment severity’, ‘attachment’, ‘commitment’, ‘belief’, and ‘perceived benefit’ have positive effects on ISP compliance intention with p-value < 0.05. however, five factors, namely ‘subjective norm’, ‘threat severity’, ‘threat vulnerability’, ‘awareness training’ and ‘involvement’ were found to be non-significant towards ISP compliance intention with p-value > 0.05. these research findings were used to develop ISP compliance guidelines for the Malaysian public sector. the ISP compliance guidelines were reviewed by three ISP practitioners. overall, this research contributes theoretically, contextually, and practically towards ISP compliance, especially in the context of the Malaysian federal public sector agencies.
format Thesis
qualification_name Doctor of Philosophy (PhD.)
qualification_level Doctorate
author Kuppusamy, Puspadevi
author_facet Kuppusamy, Puspadevi
author_sort Kuppusamy, Puspadevi
title Information security policy compliance behaviour model for Malaysian federal public sector agencies
title_short Information security policy compliance behaviour model for Malaysian federal public sector agencies
title_full Information security policy compliance behaviour model for Malaysian federal public sector agencies
title_fullStr Information security policy compliance behaviour model for Malaysian federal public sector agencies
title_full_unstemmed Information security policy compliance behaviour model for Malaysian federal public sector agencies
title_sort information security policy compliance behaviour model for malaysian federal public sector agencies
granting_institution Universiti Teknologi Malaysia, Razak Faculty of Technology and Informatics
granting_department Razak Faculty of Technology and Informatics
publishDate 2022
url http://eprints.utm.my/id/eprint/102431/1/PuspadewiKuppusamyPRAZAK2022.pdf
_version_ 1776100921359466496