Skip to main navigation Skip to search Skip to main content

Beyond compliance: information security policy demands and their multi-dimensional employee outcomes

  • Hao Tong

Student thesis: PhD Thesis

Abstract

This thesis examines how information security policy (ISP) implementation, understood as an ongoing compliance process rather than merely a behavioral endpoint, shapes employee outcomes beyond traditional compliance-related behaviors. Prior ISP research has largely focused on explaining or predicting employees' compliance, noncompliance, or violation, while offering much less insight into how complying with ISP affects employees' broader work experiences and security-related behaviors. Addressing this gap, the thesis treats ISP compliance not simply as a behavioral endpoint, but as an ongoing organizational process that generates demands, elicits employee responses, and produces wider work and behavioral consequences.

The thesis is structured as three complementary studies. The first study provides the conceptual foundation by conducting a systematic literature review of prior ISP research using the PRISMA procedure. This review synthesizes the current landscape of ISP research to answer what employee outcomes exist beyond traditional compliance, noncompliance, or violation. The identified research can be categorized into four distinct domains: psychological and emotional outcomes, extra-role and proactive security behaviors, unintended coping and reactive behaviors, and job performance and utility tradeoffs. These findings establish the theoretical foundation for the subsequent empirical studies by highlighting that ISP compliance has broader employee implications than the dominant compliance-centered literature has recognized.

Building on this review, the second study investigates one pathway through which ISP compliance affects employee job outcomes. Using survey data from 266 employees and drawing on the transactional model of stress and coping, it examines how security-related overload, as a form of security-related stress triggered by complying with ISP, influences job engagement and job burnout through employees' coping responses. The results show that active coping is associated with higher job engagement and lower job burnout, whereas passive coping is associated with the opposite pattern. By identifying these psychological pathways, the study clarifies why stringent ISP requirements often lead to perceived performance degradation. The findings further suggest that leadership modes shape how employees cope with security-related overload, while these effects vary across coping responses.

The third study extends the thesis to employees' positive security contributions beyond formal compliance. Using survey data from 297 employees and drawing on job demands-resources theory and the challenge-hindrance stressor framework, it examines how different types of ISP demands influence security-related precaution taking. The results show that when ISP demands are perceived as challenge stressors, they can actively promote precaution taking behaviors, whereas perception as hindrance stressors impedes such actions. The findings also indicate that the effects of ISP demands are conditioned by personal and job resources, although the strength and statistical support of these boundary effects differ across resource types.

Collectively, this thesis contributes to information security (ISec) research by developing an integrated framework that explains the complex and dual-natured consequences of ISP implementation for employees. Moving beyond the traditional focus on employees' ISP compliance, noncompliance, or violation, it advances a more nuanced socio-organizational perspective by showing that ISP implementation can lead not only to negative job-related consequences but also to positive extra-role security behaviors. These findings also offer practical insights for organizations by suggesting that effective ISec management should balance security protection with employee well-being and productivity, reducing unnecessary burden while fostering conditions that support proactive security contributions. Future research may build on this work by examining additional beyond-compliance outcomes, longitudinal processes, and cross-level organizational influences, as well as exploring how emerging technologies such as artificial intelligence may reshape security-related demands and employee responses.
Date of Award19 Jul 2026
Original languageEnglish
Awarding Institution
  • University of Nottingham
SupervisorJie YU (Supervisor), Jin Chen (Supervisor) & Weiwei Ye (Supervisor)

Free Keywords

  • Information Security Policies (ISP)
  • (SRS), Security-related Precau
  • Security-related Precaution Taking

Cite this

'