The Influence of Institutional Forces on Employee Compliance with Information Security Policies

Ye Hou, Ping Gao, Richard Heeks


Information Security is an issue of growing concern to organisations, typically addressed by development of information security policies. However, policies are only effective if organizational employees comply with them. This paper reviews literature related to employees’ security behaviour and information security policy compliance and presents research gaps from literature review on influencing employees’ compliance behaviour with information security policy. Here, we analyse the institutional factors that shape employee behaviour towards information security policy compliance. Applying institutional theory, we posit that an employee’s compliance behaviour with information security policy is positively influenced by regulative, normative and culture-cognitive forces in organisations.


