Management Information Systems Quarterly
Abstract
Securing information assets against cyberattacks requires organizations to bolster employees’ security behaviors, including compliance with information security policies (ISPs). A strong information security climate (ISC) has been found to be a powerful determinant of such behaviors. However, the ISC does not exist in isolation, and its effect on ISP compliance can be impacted by other (in)congruent organizational climates that coexist within an organization, as simultaneously perceived by employees. Drawing on the competing values framework, this research investigates the joint influences of the ISC and coexisting climates on ISP compliance. Specifically, we analyze the interplay between the ISC and other coexisting climates, considering their complementary or competing nature, and the extent to which employees perceive these climates to have similar (i.e., aligned) or discrepant (i.e., misaligned) magnitudes of intensity within the organization. Using polynomial regression and response surface analysis, we examine how each (mis)aligned condition is associated with ISP compliance. The results highlight the interplay of the ISC with coexisting climates and provide nuanced insights into complex and nonlinear relationships among these climates.