Paper Type

Short

Paper Number

PACIS2026-1920

Description

Information security policies (ISP) are essential organizational mechanisms for managing security risks, yet their demands may shape employees' security-related behaviors in complex ways. Drawing on the challenge–hindrance stressor framework and job demands–resources theory, this study develops a theoretical model to examine how challenge and hindrance ISP demand stressors relate to employees' security-related precaution taking. We further introduce organizational security climate and security mindfulness as job and personal resources that condition these relationships. By focusing on precaution taking, this study moves beyond compliance-centered perspectives and captures both prescribed and discretionary protective actions through which employees contribute to organizational information security. This study contributes to information systems security research by offering a more nuanced understanding of ISP demands and by explaining how organizational and individual resources may shape employees' responses to ISP implementation.

Comments

17-General

Share

COinS
 
Jul 5th, 12:00 AM

Differential Effects of Challenge versus Hindrance Information Security Policy Demands on Employees' Security-related Precaution Taking Behaviors

Information security policies (ISP) are essential organizational mechanisms for managing security risks, yet their demands may shape employees' security-related behaviors in complex ways. Drawing on the challenge–hindrance stressor framework and job demands–resources theory, this study develops a theoretical model to examine how challenge and hindrance ISP demand stressors relate to employees' security-related precaution taking. We further introduce organizational security climate and security mindfulness as job and personal resources that condition these relationships. By focusing on precaution taking, this study moves beyond compliance-centered perspectives and captures both prescribed and discretionary protective actions through which employees contribute to organizational information security. This study contributes to information systems security research by offering a more nuanced understanding of ISP demands and by explaining how organizational and individual resources may shape employees' responses to ISP implementation.