Paper Type
Short
Paper Number
PACIS2026-1920
Description
Information security policies (ISP) are essential organizational mechanisms for managing security risks, yet their demands may shape employees' security-related behaviors in complex ways. Drawing on the challenge–hindrance stressor framework and job demands–resources theory, this study develops a theoretical model to examine how challenge and hindrance ISP demand stressors relate to employees' security-related precaution taking. We further introduce organizational security climate and security mindfulness as job and personal resources that condition these relationships. By focusing on precaution taking, this study moves beyond compliance-centered perspectives and captures both prescribed and discretionary protective actions through which employees contribute to organizational information security. This study contributes to information systems security research by offering a more nuanced understanding of ISP demands and by explaining how organizational and individual resources may shape employees' responses to ISP implementation.
Recommended Citation
Tong, Hao; Shou, Minghuan; Jia, Furong; Yu, Jie (Joseph); and Yao, Zeng, "Differential Effects of Challenge versus Hindrance Information Security Policy Demands on Employees' Security-related Precaution Taking Behaviors" (2026). PACIS 2026 Proceedings. 17.
https://aisel.aisnet.org/pacis2026/general_topic/general_topic/17
Differential Effects of Challenge versus Hindrance Information Security Policy Demands on Employees' Security-related Precaution Taking Behaviors
Information security policies (ISP) are essential organizational mechanisms for managing security risks, yet their demands may shape employees' security-related behaviors in complex ways. Drawing on the challenge–hindrance stressor framework and job demands–resources theory, this study develops a theoretical model to examine how challenge and hindrance ISP demand stressors relate to employees' security-related precaution taking. We further introduce organizational security climate and security mindfulness as job and personal resources that condition these relationships. By focusing on precaution taking, this study moves beyond compliance-centered perspectives and captures both prescribed and discretionary protective actions through which employees contribute to organizational information security. This study contributes to information systems security research by offering a more nuanced understanding of ISP demands and by explaining how organizational and individual resources may shape employees' responses to ISP implementation.
Comments
17-General