Strategic Information Technology lesson 8

profileEthan76
out1StrategicInformationTechnology.pdf

Is Your Banker Leaking Your Personal Information? The Roles of Ethics and Individual-Level Cultural Characteristics in Predicting Organizational Computer Abuse

Paul Benjamin Lowry • Clay Posey •

Tom L. Roberts • Rebecca J. Bennett

Received: 29 November 2010 / Accepted: 3 April 2013 / Published online: 25 April 2013

� Springer Science+Business Media Dordrecht 2013

Abstract Computer abuse (CA) by employees is a criti-

cal concern for managers. Misuse of an organization’s

information assets leads to costly damage to an organiza-

tion’s reputation, decreases in sales, and impositions of

fines. We use this opportunity to introduce and expand the

theoretic framework proffered by Thong and Yap (1998) to

better understand the factors that lead individuals to com-

mit CA in organizations. The study uses a survey of 449

respondents from the banking, financial, and insurance

industries. Our results indicate that individuals who adhere

to a formalist ethical perspective are significantly less

likely to engage in CA activities than those following a

utilitarian ethical framework. In addition, the results provide

evidence that employees with individualistic natures are

linked to increased CA incidents, whereas collectivist ten-

dencies are associated with decreases in CA behaviors. Our

results also show that collectivism acts as a strong moderator

that further decreases the relationships between formalism

and CA, and utilitarianism and CA. Finally, we offer

detailed suggestions on how organizations and researchers

can leverage our findings to decrease CA occurrences.

Keywords Culture � Computer abuse � Deontological evaluations � Ethics � Formalism � Information security � Organizational security � Teleological evaluations � Utilitarianism � Collectivism � Individualism

Abbreviations

CA Computer abuse

CMD Cognitive moral development theory

IS Information systems

IT Information technology

Introduction

An organizational issue of increasing importance is

employees abusing their access to computers and organi-

zational information assets, a phenomenon known as

computer abuse (CA) (Posey et al. 2011; Straub 1990),

which spreads in scope and impact as technology is used

more widely. Straub (1990) formally defined CA as ‘‘the

unauthorized and deliberate misuse of assets of the local

organization information system by individuals’’ (p. 257).

CA is a critical problem requiring corporate leadership to

resolve (D’Arcy and Hovav 2007; Lee et al. 2004; Peace

et al. 2003; Posey et al. 2011): In one study, nearly half of

Electronic supplementary material The online version of this article (doi:10.1007/s10551-013-1705-3) contains supplementary material, which is available to authorized users.

P. B. Lowry (&) College of Business, City University of Hong Kong, P7912,

Academic Building I, 83 Tat Chee Avenue, Hong Kong, China

e-mail: [email protected]

C. Posey

Information Systems, Statistics and Management Science,

Culverhouse College of Commerce, The University of Alabama,

Box 870226, Tuscaloosa, AL 35487, USA

e-mail: [email protected]

T. L. Roberts � R. J. Bennett Department of Management and Information Systems, College

of Business, Louisiana Tech University, P.O. Box 10318,

Ruston, LA 71272, USA

e-mail: [email protected]

R. J. Bennett

e-mail: [email protected]

123

J Bus Ethics (2014) 121:385–401

DOI 10.1007/s10551-013-1705-3

the participants involved were aware of CA in their orga-

nizations (Hilton 2000); in another, approximately 30 % of

business professionals admitted to pirating their employers’

software (Haines and Leonard 2007). Many organizations

have also had to discipline employees for downloading

pornography at work or abusing email (Haines and Leonard

2007). Disgruntled employees rank second to outside

hackers as sources of system attacks (Haines and Leonard

2007); clearly, internal CA is a critical problem facing

organizations today (D’Arcy and Hovav 2007; Lee et al.

2004; Peace et al. 2003; Posey et al. 2011).

The negative impact of CA can be accounted for in the

loss of hundreds of billions of dollars caused by lost effi-

ciency, software piracy, security leaks, privacy violations,

legal liabilities, and the like (Culnan and Williams 2009;

Douglas et al. 2007; Gan and Koh 2006; Moores and

Dhaliwal 2004; Siponen and Vartiainen 2007; Son and Kim

2008; Thong and Yap 1998). However, many of the cata-

strophic losses are hard to calculate as they can affect the

core of an organization’s business in complex and profound

ways (Wang et al. 2008) such as lost reputation, lost sales,

and legal liabilities (Son and Kim 2008).

The ethical and cultural issues surrounding CA are of

unprecedented importance to organizations and thus are

management not just technical issues (Posey et al. 2011;

Ransbotham and Mitra 2009). The many ethical gray areas

and issues surrounding CA are particularly problematic

(Calluzzo and Cante 2004) because such issues often

involve moral hazard. 1

Moral hazard has increased as

computer use has increased (Tuttle et al. 1997) because of

the ability to hide privately held information or the often

inaccurate belief that one can hide such information. Even

when no moral hazard exists, many forms of CA do not

have clear right and wrong implications for the abusers,

and thus, they have no ethical or moral incentive to not

commit the abuse (Calluzzo and Cante 2004; Cohen and

Cornwell 1989). Therefore, CA has strong ethical and

cultural foundations.

Given the serious management and organizational

issues caused by CA, and its expansive interrelationship

with ethics and culture, the purpose of this paper is

twofold: (1) to examine the degree to which one’s dis-

position toward ethical formalism or utilitarianism affects

one’s propensity to commit CA and (2) to examine the

degree to which one’s individual-level characteristics of

collectivism and individual influence one’s propensity to

commit CA.

Background on Investigating Computer Abuse

in Organizations

Due to the growing importance of CA-related issues in the

ethical use of IS, researchers have investigated various

methods to address these issues. The most traditional

approach to preventing CA has been to try to directly block

negative employee behaviors with technical measures.

Some of these approaches have included authentication and

identification (Wang et al. 2009; Zviran and Erlich 2006),

passwords and pass phrases (Keith et al. 2009; Zhang et al.

2009), firewalls (Cavusoglu et al. 2009), intrusion detection

(Cavusoglu et al. 2009; Hansen et al. 2007; Ransbotham

and Mitra 2009), rights management, countermeasures

(Ransbotham and Mitra 2009), and system controls (Rao

et al. 2007). Additional approaches include the use of

policies and procedures, computer monitoring (Ariss

2002), audit trails, IT audits (Merhout and Havelka 2008),

IS risk analyses (Sutton et al. 2008), IS security counter-

measures (Hansen et al. 2007; Straub and Welke 1998),

and general violation-prevention strategies (D’Arcy et al.

2009).

Other approaches have innovatively coupled psychology

with traditional approaches. These integrated methods

include using fear appeals (Johnston and Warkentin 2010),

leveraging employee perceptions of IT policy so policies

appear more mandatory (Boss et al. 2009), countering

neutralization techniques (Siponen and Vance 2010), and

using general deterrence theory (Herath and Rao 2009b;

Lee et al. 2004; Straub 1990) or related penalty-oriented

techniques (Herath and Rao 2009a).

Although these approaches have shown some efficacy,

the results are highly mixed. We posit that one possible

reason is that such studies have largely ignored individual-

level ethical and cultural characteristics that likely impact

one’s decisions about various kinds of CA. Thus, we assert

that both considerations need further examination.

The Case for Studying Individual-Level Ethics

in Computer Abuse

Ethics have long been acknowledged as a key individual-

level consideration in IT use. IT studies have used ethics-

based approaches in reviewing situational ethics (Banerjee

et al. 1998), IT development (Chatterjee et al. 2009),

decision making and moral reasoning relating to IT use

(Calluzzo and Cante 2004; Cohen and Cornwell 1989;

Davison et al. 2009; Harrington 1996; Leonard and Cronan

2001; Leonard et al. 2004; Loch and Conger 1995; Myyry

et al. 2009; Smith and Hasnas 1999), and reporting or not

reporting bad IT news (Smith and Keil 2003; Smith et al.

2001). Yet little research addresses ethics and CA. The

1 Moral hazard occurs when there is ‘‘an incentive to act in one’s

self-interest in conflict with the organization’s overall goals while

being able to hide those actions through privately held information’’

(Tuttle et al. 1997, p. 7).

386 P. B. Lowry et al.

123

primary examples of ethics and CA studies include specific

contexts of software piracy (Gan and Koh 2006; Moores

and Chang 2006; Moores and Dhaliwal 2004) and avoiding

privacy violations (Culnan and Williams 2009), but no

studies have applied ethics to the broader construct of CA.

Furthermore, an opportunity exists in studying the effect

of ethical dispositions themselves. Haines and Leonard

(2007) noted two approaches to studying ethics: one based

on dispositions and traits and the other based on the deci-

sion-making process. The IT literature is replete with

studies that examine the decision-making process in rela-

tion to appropriate and inappropriate technology-based

individual behaviors, yet little research has been conducted

in terms of individual ethical dispositions and traits. For

example, Winter et al. (2004) studied on Machiavellianism

and ethical idealism. A much more common research

perspective on ethical dispositions and traits, which has

produced several promising non-technology-related studies

in the management literature (Brady and Dunn 1995; Brady

and Wheeler 1996; Hunt and Vitell 1986; Schminke et al.

1997), involves the study of formalism and utilitarianism.

The promise of studying the effects of individual ethical

dispositions on CA yields our first research question:

RQ1 In what way(s) do individuals’ ethical tendencies

toward formalism or utilitarianism predict the individuals

propensity to commit CA in the workplace?

The Case for Studying Individual-Level Cultural

Characteristics in Computer Abuse

Husted and Allen (2008) indicated that researchers still

understand little about how culture affects perception and

evaluation of abusive practices such as software piracy and

other behaviors. Worse still, how cultural dimensions

might affect CA more broadly—particularly culture at the

individual level—has yet to be fully examined. This limi-

tation is a glaring gap because increased globalization and

heterogeneity in organizations make cultural consider-

ations of ethical decisions all the more important, espe-

cially because cultural differences—primarily based on the

collectivism and individualism dimensions—have been

consistently shown to promote substantial differences in

ethical decision making (Bailey and Spicer 2007; Beekun

et al. 2008; Davison et al. 2009; Husted and Allen 2008;

Husted et al. 1996; Patel and Schaefe 2009; Ralston et al.

2008; Robertson and Crittenden 2002; Schlegelmilch and

Robertson 1995).

The few studies that have addressed forms of CA from a

cultural perspective have looked at software piracy at an

exploratory national culture level. For example, studies

have shown that software piracy is less frequent in the U.S.

than in Asia (Donaldson 1996; Swinyard et al. 1990).

Husted (2000) found that software piracy is correlated to

national GNP per capita, income inequality, and collec-

tivism. More recently, another study found substantial

differences in software piracy and related corruption

practices at the national culture level (Robertson et al.

2008). Davison et al. (2009) applied CMD theory to IT

professionals working in Japan and China, and showed that

the ethical reasoning in these two national cultures had

notable differences.

These studies suggest that the cultural dimensions of

collectivism and individualism may play a key role in

ethical decision making. The conceptualization of culture

on the national level conforms to the traditional view of

culture and is most often seen in studies comparing indi-

vidualistic societies (e.g., US) and collectivistic societies

(e.g., China) (Chen and Li 2005; Hofstede 1984, 1991,

2001; Tsui and Windsor 2001; Zhang et al. 2008). The

national-level perspective has been traditionally used in

ethics research. Some studies have shown that moral and

ethical reasoning differs across national cultures, but have

done so primarily as exploratory research without a strong

theoretic basis or explanation (Robertson et al. 2002; Tsui

and Windsor 2001). Other studies have proposed an even

stronger theoretic basis that national culture can be a

determinant of ethical differences (Robertson and Fadil

1999; Tavakoli et al. 2003; Vitell et al. 1993).

However, there are several research concerns about

national-level cultural studies, particularly in comparing

individualism and collectivism (e.g., Earley 1989; Fiske

2002; McCoy et al. 2005; Srite and Karahanna 2006; Tri-

andis and Gelfand 1998). The chief limitation of national-

level studies is that increasingly, in a globalized world,

national cultures are becoming highly heterogeneous, and

thus, multiple cultural perspectives can be found within

cultures (McCoy et al. 2005). Thus, applying national-level

cultural characteristics to predict an individual’s behavior

can result in inaccurate and misleading stereotyping and

can be too dichotomous (Triandis and Gelfand 1998).

For instance, a 2002 meta-analysis evaluating the con-

struct of individualism–collectivism across 82 studies

compared cross-national and within-United States studies

of individualism–collectivism and found that the Japanese

sample scored significantly lower on collectivism than the

U.S. sample did and that the Korean sample was not dif-

ferent from the U.S. sample (Oyserman et al. 2002). This,

of course, is consistent with Hofstede’s (1984, 2001) caveat

that national cultural values may change over time; how-

ever, it calls into question the methodology of assuming

that nations have the same culture now as they did 40 years

ago when Hofstede characterized them. Oyserman et al.’s

(2002) meta-analysis demonstrated a between-group effect

(for the U.S. samples) for ethnicity on individualism, with

Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 387

123

European Americans the most individualistic; however, the

effect was present only in comparison with Asian Ameri-

can groups and that effect was small. Similarly, recent

research demonstrates that individuals hold nationally

espoused cultural values to vastly different degrees, and

thus, the individual level of measurement of analysis is

more accurate and appropriate (Srite and Karahanna 2006).

Importantly, using individual-level cultural measures for

predicting individual behavior helps researchers avoid

ecological fallacies widely found in cultural research. That

is, per Hofstede (2002), country scores should not be used

to predict individual behavior. ‘‘Doing so is to commit

ecological fallacy, which assumes that one can validly use

ecological correlations (which apply to collective entities

such as groups) to substitute for individual correlations’’

(Srite and Karahanna 2006, p. 681). Subsequent research

shows that it is valid to study culture at the national,

organizational, and individual levels, but that the key is

using the proper level of measurement (Fischer et al. 2005).

Consequently, for this study, rather than use a 40-year-

old assessment of between-country differences on indi-

vidualism–collectivism or using respondents’ ethnicity as a

proxy for individualism–collectivism, we followed the

approach of many other researchers and measured indi-

vidualism and collectivism directly, at the individual level

(Earley 1989; McCoy et al. 2005; Srite and Karahanna

2006; Triandis and Gelfand 1998). This decision leads to

our second and last research question:

RQ2 To what extent do individuals’ tendencies toward

collectivism or individualism predict individuals’ propen-

sity to commit CA in the workplace?

Theoretic Model and Hypotheses

The thrust of the theoretic work in ethics-based outcomes has

focused primarily on the decision-making process, with less

focus on how dispositions and traits affect the outcomes. One

notable exception to this gap was a study by Winter et al.

(2004) that reviewed IT ethics in terms of Machiavellianism

and ethical idealism and found that those who lean toward

Machiavellianism were more likely to violate intellectual

property and privacy rights than those with ethical idealism.

However, a more prominent and accepted theoretic per-

spective is a body of theory and research that shows that an

individual’s disposition toward a moral philosophy based on

deontological or teleological evaluation maps directly to

one’s ethical dispositions toward formalism and utilitarian-

ism, respectively (Brady and Dunn 1995; Brady and Wheeler

1996; Hunt and Vitell 1986; Schminke et al. 1997). Yet this

well-accepted theoretic approach has not been applied in a

CA context. We do so here.

When employees commit CA in the workplace, they

knowingly violate implicit or explicit ethical rules of

conduct. Ethics can be defined ‘‘as an inquiry into the

nature and grounds of morality where morality is taken to

mean moral judgments, standards, and rules of conduct’’

(Thong and Yap 1998, p. 215). Accordingly, we follow the

standard raised by other computer-based ethics studies in

conducting research based on moral philosophies (e.g.,

Gattiker and Kelley 1999; Thong and Yap 1998). The use

of moral philosophies can provide a systematic perspective

for assessing the ethical appropriateness of individual

behavior, also called normative ethics theory (Thong and

Yap 1998).

Our theoretic model builds on Thong and Yap’s (1998)

ethical decision-making model, which is based on Hunt and

Vitell’s ethical decision-making theory (1986). Thong and

Yap (1998) describe a theory of ethical decision making in

a systems context that accounts for deontological and tel-

eological evaluations. A key assumption in their model is

that before people can perform either evaluation, they must

first recognize the situation as an ethical problem. Once a

person perceives an ethical problem, he or she then enga-

ges in a process of ethical evaluation, which is either

deontological or teleological. This evaluation determines

the basis of their ethical judgment, which predicts moral

intention and, ultimately, moral behavior. They also pro-

pose that various situational factors can directly impact

moral intention, which then impacts moral behavior.

Normative ethics theory is typically discussed in two

categories: theories that are rules based, or deontological,

and theories that are consequences based, or teleological

(Thong and Yap 1998). These are not just theoretic per-

spectives, but perspectives that individuals choose implic-

itly when engaging in ethical reasoning (Brady and

Wheeler 1996; Hunt and Vitell 1986). Thong and Yap

(1998) explain that the key distinction of a deontological

perspective is the theory or belief that there are universal

rules guiding right and wrong. As long as an individual can

clearly interpret the rules based on religion, intuition, or

esthetic belief, his or her action in any given situation is

‘‘predefined, without reference to possible consequences’’

(Thong and Yap 1998, p. 216). Also, ‘‘fundamental to the

deontological perspective is the fundamental rightness of

the behavior. No action can be considered right in accor-

dance with personal duty if it disregards the ultimate worth

of another human being’’ (Thong and Yap 1998, p. 216). A

formalistic perspective is typical in deontological per-

spectives (see the next section).

Conversely, a teleological perspective of ethical issues

determines whether an action is right or wrong depending

on the social consequences of the action (Brady and

Wheeler 1996; Thong and Yap 1998). Consequently, a

universal set of principles is not followed, and what should

388 P. B. Lowry et al.

123

be done depends on a calculation of the likely outcome of a

given situation. A utilitarian perspective is typical in tele-

ological evaluation, ‘‘which emphasizes creating the max-

imum benefits for the largest number of people, while

incurring the least amount of damages. A social cost-ben-

efit analysis is carried out and, if the net result is positive,

then the act is considered morally acceptable’’ (Thong and

Yap 1998, p. 216).

To propose testable hypotheses, we simplify the Thong

and Yap (1998) model by eliminating all the intermediary

processes of evaluation, judgment, and intention. Instead,

we focus on the direct connection between our independent

variables (IVs) and actual confessed CA behaviors because

actual behaviors are often much more salient than inten-

tions (Sutton 1998). We propose our hypotheses for for-

malism and utilitarianism, followed by those for

collectivism and individualism.

Predictions for CA Based on Ethical Formalism

and Utilitarianism

In congruence with Thong and Yap’s (1998) model, we

also assume that people perform either deontological or

teleological evaluations in making ethical decisions on

whether to commit CA. We also concur that social norms

toward deontological and teleological viewpoints signifi-

cantly influence both deontological and teleological eval-

uation. The literature indicates that people have various

predispositions toward how they make ethical evaluations

(Brady and Dunn 1995; Brady and Wheeler 1996). We

likewise argue that the strength of individuals’ dispositions

toward a given moral philosophy is likely to bias the degree

to which they will use a given philosophy to inform their

ethical judgments.

Our predictions address the kinds of ethical dispositions

likely to affect deontological and teleological evaluations.

Although the actual ethical evaluation is difficult to

observe, an individual’s disposition toward a particular

evaluation style is easy to capture through self-report and

can thus be used for prediction. Although the literature has

multiple terms for dispositions that map to deontological

and teleological perspectives, these dispositions are often

grouped into two traditional types in the literature, which

we adopt in our paper (Brady and Dunn 1995; Brady and

Wheeler 1996; Hunt and Vitell 1986; Schminke et al.

1997): (1) formalism 2

and (2) utilitarianism. 3

Both ethical

dispositions have been explicitly defined and measured in

the literature as independent subdimensions (Brady and

Dunn 1995; Brady and Wheeler 1996; Schminke et al.

1997; Schminke and Wells 1999). Therefore, our predic-

tions assume that the degree to which individuals lean

toward formalism positively increases the likelihood that

they will engage in deontological evaluation, and the

degree to which individuals lean toward utilitarianism

positively increases the likelihood that they will engage in

teleological evaluation.

We argue that because ethical formalism relies on uni-

versal principles of a belief in inherently right and wrong

behaviors, this philosophy will be more effective in pre-

venting new and ambiguous opportunities to commit CA.

That is, if a potential CA act feels even partially wrong, it

would typically be considered wrong. Hence, someone

with this perspective is more likely to consider an ambig-

uously wrong (or clearly wrong) opportunity to commit CA

(e.g., snoop data) as wrong and, therefore, will not engage

in the deviant activity. This perspective is important

because there are many ambiguities and complexities

involved with computer use and CA (Calluzzo and Cante

2004; Gattiker and Kelley 1999; Posey et al. 2011; Sproull

and Kiesler 1991).

H1 Ethical formalism will be associated with decreased

individual CA.

In contrast, the weakness of a utilitarian perspective in

thwarting CA is that for new or ambiguous ethical dilem-

mas, it can be quite difficult to calculate social costs

effectively. CA and computer use dilemmas are often

ambiguous, making it difficult for people to assess potential

harm in these situations (Calluzzo and Cante 2004; Gatti-

ker and Kelley 1999; Posey et al. 2011; Sproull and Kiesler

1991). A utilitarian perspective in the context of CA can

result in the incorrect determination that ‘‘victimless

abuse’’ has occurred and that the abuse is okay. Con-

versely, if one engages in a teleological evaluation, one is

still likely to recognize a potential ethical issue (Thong and

Yap 1998). Thus, a utilitarian viewpoint will result in

decreased CA, but not as strongly as a formalistic

viewpoint.

H2 Ethical utilitarianism will be associated with

decreased individual CA.

H3 The decrease in individual CA from ethical formal-

ism will be greater than the decrease in individual CA from

ethical utilitarianism.

2 Formalism refers to individuals with a disposition to make ethical

decisions from a deontological (rules-based) point of view, and thus

they determine whether actions are either ethical or unethical based

on a set of predetermined rules (Brady and Wheeler 1996; Schminke

et al. 1997).

3 Utilitarianism refers to individuals with a disposition to make

ethical decisions from a teleological (outcome-based) point of view,

meaning they make ethical decisions based on a cost–benefit analysis

to maximize the positive outcomes (Brady and Wheeler 1996;

Schminke et al. 1997).

Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 389

123

Predictions for CA Based on Individual-Level

Collectivism and Individualism

Thong and Yap (1998) propose that other factors can

directly affect moral intention, which then influences moral

behavior. Again, we believe a critical factor to consider in

a CA context is culture, 4

especially one’s characteristics

regarding individualism and collectivism. 5

Culture is a

particularly important consideration given the increased

globalization and diversity in the workplace. In our case,

we are primarily concerned about individual-level culture

as opposed to cultural behaviors that are shared with a fixed

group or nation. Because of the high relevance to decision

making, individualism and collectivism are the most

studied and common cultural elements in the IS/IT litera-

ture (Shin et al. 2007). Importantly, initial evidence sug-

gests these dimensions are highly relevant to ethical

decision making (Husted and Allen 2008).

We use the individual-level characteristics of these

cultural inclinations (Oyserman et al. 2002; Srite and Ka-

rahanna 2006). Thus, in referring to individualism in this

paper, we refer to the degree to which one’s individual

characteristics exhibit individualistic values. Likewise,

collectivism refers to the degree to which one’s individual

characteristics exhibit collectivistic values.

It has been argued that ‘‘ethical decision making is

affected by individualism and collectivism because they

deal with beliefs about the priority of individual versus

group interests’’ (Husted and Allen 2008, p. 294). A recent

meta-analysis indicated that differences between individ-

ualism and collectivism do indeed impact one’s values

(Oyserman and Lee 2008). Husted and Allen (2008)

emphasize that the ethical connections with individualism

are uniqueness and independence, whereas the ethical

connections with collectivism are based on ‘‘duty to the in-

group and, in cross-national contexts, maintenance of

harmony’’ where the in-group refers to ‘‘a group of people

sharing similar beliefs and interests and which typically

excludes outsiders (Chen and Li 2005),’’ as cited in Husted

and Allen (2008, p. 295). Similarly, Oyserman (2006)

shows that individualists are decontextualized and inde-

pendent of others, whereas collectivists are prone to exhibit

more restraint in their expression. As a result of these

differences, individualists are seen as more self-serving

than collectivists (Tavakoli et al. 2003) and tend to not

work as well with people as do collectivists (Chen and Li

2005). Namely, ‘‘people who emphasize group goals over

individual goals resolve conflicts and optimize benefits in

very different ways than people who emphasize individual

goals’’ (Husted and Allen 2008, p. 295). Thus, collectivists

tend to consider others, group goals, and organizational

goals more than individualists.

Given these basic differences, we predict that one’s

degree of individualism and collectivism directly impacts

moral intention. We also predict that because individualists

as a whole are more self-serving and less reserved in their

behavior and expression, they are more likely to engage in

unethical behaviors than collectivists. To clarify, self-

serving does not equate to being stupid or careless. A

person who is a strong individualist and who understands

the potential behavior is unethical and has potential dire

consequences will not likely engage in the behavior for the

sake of self-preservation or self-interest. However, we

predict individualists are more likely to engage in unethical

behavior than a strong collectivist if they believe they are

in an ethically gray area, see the benefits as being greater

than the costs to self, and can get away with it. As sup-

ported, these gray areas of high ambiguity are pervasive in

computer use and CA scenarios (Calluzzo and Cante 2004;

Gattiker and Kelley 1999; Posey et al. 2011; Sproull and

Kiesler 1991).

H4 An individual’s increased tendency toward individu-

alism will be associated with increased incidents of the

individual committing CA.

H5 An individual’s increased tendency toward collec-

tivism will be associated with decreased incidents of the

individual committing CA.

Finally, we explore possible moderation relationships in

our model. In H5, we predicted that an individual’s pro-

pensity toward collectivism should be associated with

decreased CA. In H1 and H2, we predicted the same for

formalism and utilitarianism, respectively. Thus, three

factors decrease CA: formalism, utilitarianism, and col-

lectivism. We thus wonder what happens when formalism

and collectivism interact, and when utilitarianism and

collectivism interact. Because these are all in the same

predicted direction, we have reason to suspect that col-

lectivism could play a strong positive moderation role in

the model.

H6 Collectivism acts as a moderator that strengthens the

negative relationship between formalism and individual

CA.

H7 Collectivism acts as a moderator that strengthens the

negative relationship between utilitarianism and individual

CA.

4 Culture is ‘‘a system of implicit and explicit beliefs, values, norms,

preferences, and behaviors that are stable over time’’ (Zhang and

Lowry 2008, p. 64). 5

Traditionally, on a national level, individualism describes cultures

‘‘in which the ties between individuals are loose,’’ and collectivism

describes cultures ‘‘in which people are integrated into strong,

cohesive groups that protect individuals in exchange for unquestion-

ing loyalty’’ (Hofstede 1991; Zhang and Lowry 2008, p. 65).

390 P. B. Lowry et al.

123

Research Methods

Data Collection

We used an anonymous online panel composed of 449 full-

time employees from the banking, financial, and insurance

industries to obtain data for testing our research model.

Survey items were presented in a randomized fashion to

assist in reducing possible common method biases (Pod-

sakoff et al. 2003). For the survey administration, we used

SurveyMonkey, a third-party, online survey administration

and market research company. SurveyMonkey has an

international database of millions of pre-qualified potential

respondents who work directly in various business fields,

allowing us to reach a large sample of interest. These

respondents are compensated directly by SurveyMonkey.

Collecting data over the Internet via an organization like

SurveyMonkey offers particular advantages as well as

challenges (Fraley 2007). The primary challenge is ensur-

ing that a representative sample matching the needs of the

study is attained. We met this challenge by using a panel

provider that has market research expertise and a huge set

of pre-qualified candidates. We were thus able to target

directly only those who met our demographic needs, and

we used automatic filters to capture our sample population

of interest (Fraley 2007). Panel participation was restricted

to those over 18 years of age who were employed full time

in the financial, banking, and/or insurance or related

industries in the United States. All respondents also had to

use their organization’s computer systems in fulfilling their

daily work.

One clear advantage is that data collected over the Internet

via a panel of respondents is more reflective of the broader

population than data collected in more restricted settings

(e.g., college classroom, college alumni, one organization)

(Birnbaum 2004; Fraley 2007). Moreover, the Internet panel

allows researchers examining topics of a sensitive nature

(e.g., internal CA) to receive responses less inhibited by

social desirability effects as anonymity is ensured (Bennett

and Robinson 2000; Posey et al. 2011). Online panelists were

guaranteed that their identities would not be released by

SurveyMonkey to the researchers, thus protecting the pan-

elists from any repercussions from their organizations from

the reported CA incidents. Table 1 summarizes several key

demographic data points from these respondents.

This study was approved by the appropriate institutional

review board for human subject studies and was fully

performed in accordance with the related established

ethical standards. All participants in the pilot study and

the online panel study gave informed consent before being

included in the study. All data were also gathered

under true anonymity and were analyzed at the aggregate

level only.

Construct Measurement

The IVs used in this study included degree of ethical for-

malism, degree of ethical utilitarianism, degree of collectiv-

ism, and degree of individualism. The dependent variable

(DV) used in this study was personal CA. Four covariates were

also used: computer experience, level of education, age, and

income. Responses were captured on a seven-point Likert-

type scale with anchors ranging from never to very frequently.

Appendix 1 details the measurement items. In addition to

similar items directly adapted from the literature, a pretest and

pilot test on the items were performed, using specific guide-

lines (Boudreau et al. 2001; Straub 1989). For the pretest, eight

faculty members and doctoral students from a large South-

eastern university and one faculty member from a large

Midwestern university analyzed the survey instrument for

content validity. Following the review, appropriate changes

were made to the survey instrument, after which the pilot test

was conducted. A pilot test was conducted using our instru-

ment with a large bank in the Southwestern United States. In

all, 47 employees responded to the Web-based survey for an

approximate response rate of 19 % over a period of 1 month.

The results from the pilot test suggested only minor changes to

item wording.

Analysis and Results

We first conducted extensive pre-analysis and data vali-

dation with partial least-squares regression (PLS)—a form

of structural equation modeling—for four purposes: (1) to

establish the factorial validity of the measures through

convergent and discriminant validity, (2) to establish that

multicollinearity was not a problem with any of the mea-

sures, (3) to check for common methods bias, as estab-

lished in Liang et al. (2007), and (4) to establish strong

internal consistencies.

Factorial validity for reflective constructs is established

by establishing convergent validity 6

and discriminant

validity, 7

two highly interrelated concepts that must coexist.

To establish the factorial validity of our reflective constructs,

we followed procedures by Gefen and Straub (2005)

and Kock (2010), and further demonstrated in Lowry et al.

6 Convergent validity is the basic idea that measurement items that

should be related are related. It is established ‘‘when items thought to

reflect a construct converge, or show significant, high correlations

with one another, particularly when compared to the convergence of

items relevant to other constructs, irrespective of method’’ (Straub

et al. 2004, p. 391). 7

Discriminant validity is the idea that items that should not be

related are in fact not related. It can be established when items

thought to diverge show insignificant, low correlations with one

another, particularly when compared to items in other constructs

(Straub et al. 2004).

Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 391

123

(2008, 2009). For an especially conservative analysis, we

used two established techniques to assess convergent and

discriminant validity.

First, we examined the outer model loadings. Following

Gefen and Straub (2005), convergent validity can be established

when the t-values are significant and the outer model loadings

are large. All items were significant; however, three collectivism

items had substantial order of magnitude lower weights. Thus,

these were dropped to increase validity. See Table A2.1 in

Appendix 2 in the electronic supplementary material.

Second, we correlated the latent variable scores against

the indicators as a form of factor loadings and then

examined the indicator loadings and cross-loadings to

establish convergent validity through confirmatory factor

analysis inherent in SEM. Though this approach is typi-

cally used to establish discriminant validity (Gefen and

Straub 2005), convergent validity and discriminant validity

are inter-dependent and help establish each other (Straub

et al. 2004). Thus, following (Kock 2010), convergent

validity is also established when each loading for a latent

variable is substantially higher than those for other latent

variables. All items converged as expected within each

latent variable, and thus, no items were dropped. See Table

A2.2 in the electronic supplementary material.

We also used two approaches to establish discriminant

validity, as described in Gefen and Straub (2005) and

demonstrated in Lowry et al. (2008, 2009). First, as with

convergent validity, we examined the factor loadings, but

this time to ensure significant overlap did not exist between

the constructs. No latent variables overlapped (again see

Table A2.2 in the electronic supplementary material).

Second, we used examined the square roots of the average

variances extracted (AVEs) described in Gefen and Straub

(2005) compared to the correlations of the latent variables. 8

Table 1 Sample demographics (N = 449)

# % # %

Age Computer use (in an average workday)

Between 20 and 24 3 0.7 Less than 45 % 33 7.3

Between 25 and 29 25 5.6 Between 45 and 54 % 27 6.0

Between 30 and 34 32 7.1 Between 55 and 64 % 17 3.8

Between 35 and 39 54 12.0 Between 65 and 74 % 48 10.7

Between 40 and 44 59 13.1 Between 75 and 84 % 69 15.4

Between 45 and 49 67 14.9 Between 85 and 94 % 98 21.8

Between 50 and 54 70 15.6 Greater than 95 % 157 35.0

Between 55 and 59 81 18.0 Organization size

Between 60 and 64 42 9.4 Small organization—1–100 computers 111 24.7

Older than 65 16 3.6 Medium organization—100–1,000 computers 66 14.7

Gender Large organization—1,000–10,000 computers 100 22.2

Female 270 60.1 Very large organization—more than 10,000 computers 167 37.2

Male 179 39.9 Not reported 5 1.1

Income Manager

Less than $25,000 23 5.1 Yes 153 34.1

Between $25,000 and $49,999 144 32.1 No 296 65.9

Between $50,000 and $74,999 116 25.8 IS/IT employee?

Between $75,000 and $99,999 73 16.3 Yes 59 13.1

Between $100,000 and $124,999 51 11.4 No 387 86.2

Greater than $125,000 38 8.5 Industry

Not reported 4 0.92 Banking 112 25.0

Education Financial services 87 19.4

High school 46 10.2 Insurance 146 32.5

Some college 143 31.9 Other financial 104 23.2

Undergraduate degree 188 41.9

Master’s degree 58 12.9

Doctorate/professional degree 13 2.9

Not reported 1 0.2

8 The basic standard followed here is that the square root of the AVE

for any given construct (latent variable) should be higher than any of

the correlations involving the construct (Fornell and Larcker 1981;

Staples et al. 1999).

392 P. B. Lowry et al.

123

Strong discriminant validity was shown for all subcon-

structs. All of the AVE thresholds were met. We combined

these results with the measurement model statistics, as

shown in Table 2. In Table 2, the AVEs are shown in the

diagonal for each construct (bold and underlined).

Aside from factorial validity, the biggest potential issue

that must be addressed in SEM is multicollinearity (Cenfe-

telli and Bassellier 2009). We thus assessed the possibility of

multicollinearity among all the indicators in the model.

Variance inflation factors (VIFs) less than 10 are tradition-

ally viewed as justification for a model’s lack of multicol-

linearity, with 5.0 being ideal for reflective constructs, but

some methodologists have recently called for a more strin-

gent cutoff of less than 3.3 to be used (Cenfetelli and Bas-

sellier 2009; Diamantopoulos and Siguaw 2006; Petter et al.

2007). Very low multicollinearity was seen among all of the

latent variables, with the highest value 1.352. We thus con-

clude that multicollinearity was not a threat to our study.

To diminish the likelihood of common methods bias

occurring in our data collection, we randomized items

within the instrument so that participants would be less apt

to detect underlying constructs, a potential source of

common method bias (Cook and Campbell 1979; Straub

et al. 2004). However, all data were collected using a

similar-looking online survey; thus, we tested for common

method bias to establish that it is not a likely negative

factor in the data remaining for our analysis. To do so, we

used three approaches of increasing validity and rigor.

The first approach was the Harmon’s factor test, which

is increasingly in dispute (Podsakoff et al. 2003). This was

analyzed by conducting an unrotated factor analysis and

determining how many factors exist in the model. A total

of 26 factors were created, with the largest factor only

accounting for 24.48 % of the variance, indicating mono-

method bias was unlikely.

The second approach was to simply examine a corre-

lation matrix of the constructs and to determine if any of

the correlations were above 0.90, which is evidence that

common methods bias may exist (Pavlou et al. 2007).

These correlations are observed in the measurement model

statistics in Table 2—all of which are far below the 0.90

threshold.

Our third and most rigorous approach to testing common

method bias was to conduct an extensive form of testing for

mono-method bias for PLS, as established in Liang et al.

(2007). This approach was suggested by Podsakoff et al.

(2003) who criticize simpler approaches. The objective of

this technique is to measure the influence of a common latent

method factor on each individual indicator in the model

versus the influence of each indicator’s corresponding con-

struct. 9

This analysis indicated the average substantive factor

loading was 0.736 and the average variance explained for the

substantive factor loading was 54.14 %. The average method

factor loading was 0.000, and the average variance explained

for the method factor loading was 1.07 %—making a ratio of

more than 50:1. Finally, most of the relationships between

the items and the method bias construct were insignificant,

whereas all of the relationships between the items and their

corresponding latent variables were highly significant. We

thus conclude that method-based variance is not a concern

for this study. See Table A2.3 in the electronic supplemen-

tary material for more details.

As a product of our rigorous pre-analysis, all of our

reflective subconstructs exhibited high levels of internal

consistency. 10

To establish this consistency, PLS computes

a composite reliability score as part of the integrated model

analysis. This score is a more accurate measurement of

internal consistency than Cronbach’s alpha because it does

not assume the loadings or error terms of the items to be

equal (Chin et al. 2003). However, as a conservative check,

Table 2 Results of AVE analysis and measurement model statistics

Latent variable Mean SD (1) (2) (3) (4) (5)

Formalism (1) 6.39 0.55 0.721

Utilitarianism (2) 5.56 0.74 0.506** 0.740

Individualism (3) 3.92 1.16 (-0.029)(n/s) 0.308** 0.780

Collectivism (4) 5.45 0.85 0.471** 0.408** 0.045(n/s) 0.762

CA (5) 5.56 1.77 -0.228** -0.183** 0.052(n/s) -0.257** 0.695

n/s non-significant

*** p \ 0.001, ** p \ 0.01, * p \ 0.05

9 To do this in PLS, constructs of the theoretic model and their

relationships are modeled as is normally conducted with two major

additions: (1) A single-indicator construct is created for each indicator

in the measurement model. Each subconstruct is then linked to each

of the single-indicator constructs that comprise the subconstruct. This

effectively makes each subconstruct in the model a second-order

reflective construct. (2) A construct representing the method is

created, reflectively composed of all indicators of the instrument. The

method construct (the latent method factor) is then linked to each

single-item construct. 10

Reliability refers to the degree to which a scale yields consistent

and stable measures over time (Straub 1989). Because of the nature of

formative measures, reliability checks cannot be reasonably made for

formative measures (Diamantopoulos and Winklhofer 2001). How-

ever, reliabilities of first-order reflective constructs that make up

second-order constructs can be established individually.

Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 393

123

Cronbach’s alpha can also be used as a basis of comparison

(Fornell and Larcker 1981; Kock 2010; Nunnally and

Bernstein 1994). We thus applied the two most conserva-

tive criteria to establish consistency of our reflective sub-

constructs: The composite reliability and the Cronbach’s

alpha coefficients should be C0.70 (Fornell and Larcker

1981; Kock 2010; Nunnally and Bernstein 1994). Table 3

summarizes the computed internal consistency values, all

of which are strong.

Summarizing this section, our pre-analyses show that

our data exhibit strong factorial validity of the reflective

and formative constructs, little multicollinearity, strong

reliabilities, and that they lack mono-method bias. The

results of our validation procedures show that our model

data meet or exceed the rigorous validation standards

expected in SEM analysis (Straub et al. 2004)—particu-

larly for PLS analysis for reflective constructs (Cenfetelli

and Bassellier 2009; Diamantopoulos and Siguaw 2006;

Gefen and Straub 2005; Petter et al. 2007).

Again, we used PLS regression, using SmartPLS version

2.0 (Ringle et al. 2005) for model analysis because PLS is

especially adept at validating preliminary prediction-based

models and is thus is more appropriate than covariance-

based SEM techniques such as LISREL or AMOS (Chin

et al. 1996, 2003; Gefen and Straub 2005). In addition, PLS

does not require data with normal distributions (as do

covariance-based SEM techniques), which is important with

our data because many respondents will not have committed

CA. To do so, we generated a bootstrap with 600 resamples.

Given our rigorous background analysis, we finalized our

tested model. Table 4 summarizes the hypotheses, path

coefficients, and p-values for the hypotheses.

The one hypothesis that could not be fully tested with PLS

analysis was H3, which hypothesized that the decrease in

individual CA from ethical formalism would be greater than

the decrease in individual CA from ethical utilitarianism. In

visually examining the b’s of these relationships—before and after moderation is added to the model—it is clear that

meaningful differences do exist as predicted by H3. To test

this observation statistically, we followed Chin et al. (2003) to

perform a pseudo F-test. 11

Comparing these paths for the

model before moderators were added resulted in an F-statistic

of 60.92 (p \ 0.001); adding the moderator resulted in an F- statistic of 491.91 (p \ 0.001). We thus conclude that H3 is strongly supported.

Summary of Results

Summarizing the results, we found that before the collectiv-

ism moderator was added to the model, formalism was neg-

atively related to CA (H1 supported) and utilitarianism had no

relationship to CA (H2 not supported). However, after the

collectivism moderator was added, there was a large increase

in the negative relationship between formalism and CA (H1

more strongly supported); importantly, a large, significant

negative relationship between utilitarianism and CA emerged

(H2 supported). There is likely a meaningful effect in adding

collectivism as a moderator. Directly testing the moderation

relationships to the model, we found that collectivism

increased the strength of the negative relationships between

formalism and CA (H6 supported) and utilitarianism and CA

(H7 supported). We also found that formalism was associated

with a stronger decrease in CA than was utilitarianism—with

or without the collectivism moderator (H3 supported). We

found a positive relationship between individualism and CA

(H4 supported) and a negative relationship between collec-

tivism and CA (H5 supported). No significant relationships

were found with our exploratory covariates and CA.

In terms of descriptive analysis, 219 (48.8 %) of the

respondents in our sample confessed to having committed

at least one of our listed forms of CA in the workplace,

which is virtually the same rate from an earlier, unrelated

study (Hilton 2000). Finally, 359 (80.0 %) of the respon-

dents reported having observed at least one incident of CA

committed by another person at their workplace. These

statistics from full-time professionals in the financial ser-

vices industry pinpoint why CA should be of grave concern

to research and practice.

Contributions to Theory

Our primary theoretic contribution is that by using original

extensions based on the ethical dimensions of formalism–

utilitarianism and the individual cultural characteristics of

collectivism–individualism, we successfully extended

Thong and Yap’s (1998) ethical decision-making model for

predicting CA. This and other contributions are further

discussed in terms of the two research questions that gui-

ded our study.

Table 3 Latent variable internal consistencies

Latent

variable

Number of

items

Cronbach’s

alpha (a) Composite

reliability

Formalism 6 0.815 0.866

Utilitarianism 7 0.868 0.893

Collectivism 5 0.818 0.872

Individualism 3 0.765 0.819

CA 9 0.867 0.892

11 Per Chin et al. (2003), the pseudo F-test is obtained by first

calculating the effect size using the following formula: (path a - path

b)/(1 - path a). The pseudo F-statistic was then calculated by

multiplying the effect size by (n – k - 1), where n is the sample size

(449) and k is the number of independent variables (in this case 2,

because we are comparing two paths only).

394 P. B. Lowry et al.

123

RQ1 In what way do individuals’ ethical tendencies

toward formalism or utilitarianism predict the individuals’

propensity to commit CA in the workplace?

Our hypotheses were largely supported. The results give

preliminary support to our theoretic extensions of Thong

and Yap’s (1998) ethical decision-making model. To

simplify the operationalization of the theory, and because

we were using survey data based on actual confessed

events, we tested the direct association between formalism

and utilitarianism and moral behavior. To test the gener-

alizability and applicability of the extensions, we used the

two major forms of ethical tendencies that are especially

relevant in the workplace today.

Our first theoretic extension proposed that an individ-

ual’s propensity toward ethical formalism or utilitarianism

would directly affect whether one chooses deontological or

teleological evaluation, which then directly affects one’s

ethical judgment, moral intention, and, ultimately, moral

behavior. We showed a stronger relationship in decreased

CA from a formalism perspective than from a utilitarianism

perspective.

RQ2 To what extent do individuals’ tendencies toward

collectivism or individualism predict the individuals’ pro-

pensity to commit CA in the workplace?

Our second theoretic extension proposed that key situ-

ational factors capable of directly impacting moral inten-

tion are an employee’s cultural tendencies. Given today’s

increasingly global and heterogeneous workforce, these

tendencies are increasingly relevant. We specifically

examined individual tendencies toward individualism or

collectivism, and we showed that collectivism is associated

with decreased CA, and individualism was associated with

increased CA. Collectivism acted to further strengthen the

relationships between formalism and utilitarianism with

CA. Thus, an employee who is strong in collectivism and

formalism is the one least likely to commit CA. These

results make sense as people who are oriented toward

collectivism tend to emphasize sociability and common

goals with others (Husted and Allen 2008; Triandis and

Gelfand 1998). People who are oriented toward individu-

alism tend to be status-oriented, competitive with others,

and anxious to distinguish themselves from others (Chen

and Li 2005; Husted and Allen 2008; Triandis and Gelfand

1998).

In all, our extensions and empirical testing support the

notions that one’s ethical dispositions likely have an impact

on actual ethical behavior, including the detrimental

activity of CA.

Applying Results in Practice

Promoting Formalism in Organizations

We now suggest how these findings can be applied in

practice. First, as mentioned, one of the particularly trou-

bling issues with CA is that it is often ambiguous, and

employees frequently do not understand the potential

Table 4 Results of hypotheses testing with PLS

Hypothesis/path Beta coefficient (b) t-statistic from PLS (n = 449) Supported?

Direct path results for H1, H2, H4, and H5 before collectivism moderator was added to model

H1. Formalism ? (–) CA (-0.180) 2.56* Yes

H2. Utilitarianism ? (–) CA (-0.068) 1.52(n/s) No

H4. Individualism ? CA 0.108 3.40*** Yes

H5. Collectivism ? (–) (-0.175) 2.05* Yes

Results after collectivism moderator was added to model:

H1. Formalism ? (–) CA (-0.728) 4.08*** Yes

H2. Utilitarianism ? (–) CA (-0.428) 2.38* Yes

H4. Individualism ? CA 0.105 2.16* Yes

H5. Collectivism ? (–) CA (-1.767) 5.63*** Yes

H6. Collectivism X formalism ? CA 1.540 3.83*** Yes

H7. Collectivism X utilitarianism ? CA 0.642 2.34* Yes

Covariates of CA:

Computer experience ? CA (-0.066) 1.46(n/s) No

Education ? CA (-0.024) 0.53(n/s) No

Income ? CA (-0.040) 0.81(n/s) No

Age ? CA (-0.024) 0.51(n/s) No

n/s non-significant

*** p \ 0.001, ** p \ 0.01, * p \ 0.05

Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 395

123

negative ramifications of CA (Calluzzo and Cante 2004).

(This may partially explain why nearly half of the

employees in our study confessed to committing CA.)

Thus, providing training on CA’s implications would be an

important first step in any organization (Calluzzo and

Cante 2004; Cohen and Cornwell 1989).

Based on the ethics literature, we posit that the key to

promoting formalism is to provide formal training on eth-

ical decision making and moral reasoning related to IT use

(Calluzzo and Cante 2004; Cohen and Cornwell 1989;

Davison et al. 2009; Harrington 1996; Leonard and Cronan

2001; Leonard et al. 2004; Loch and Conger 1995; Myyry

et al. 2009; Smith and Hasnas 1999). This kind of training

requires employers to provide explicit examples that

encompass the wide range of behaviors they wish to avoid.

If explicit examples are not provided and discussed, man-

agers cannot assume that their employees understand what

an acceptable behavior is. Moreover, managers should not

expect ethical discussions and the associated underlying

principles on one behavior (e.g., the proper use of email) to

naturally transfer to the employees’ appropriate engage-

ment in another activity (e.g., the proper use of instant

messaging). Preliminary research shows that teaching

about unethical IS/IT practices can be effective in shifting

attitudes against such abuses (Cohen and Cornwell 1989).

Because the decision-making process can depend on the

ethical situation itself, Haines and Leonard (2007) suggest

that training efforts should focus not only on outcomes but

also on the ethical decision-making process of recognizing

the importance of IT ethical abuse, judging something to be

wrong, feeling an obligation to do something, and then

doing something about the violation.

Most recently, Chatterjee et al. (2009) provided a criti-

cal ethical perspective on IS development, suggesting that

IS failure could be avoided by focusing on ethics and moral

responsibility in the IT project development process. They

provide useful suggestions for how the focus on morals and

ethics can be better integrated into such projects and even

taught to students. We believe their suggestions apply well

to CA prevention. Likewise, Culnan and Williams (2009)

suggest how formal training in ethical decision making can

help curb the rampant privacy abuses within organizations.

Research has also shown that the design of an organi-

zation can have a strong effect on ethical decision making

within an organization (Jones and Ryan 1997); these con-

cepts could be extended to help prevent CA. For example,

organizations need to be careful about the leadership style

and incentives they provide as these can directly affect

whether employees embrace a more formalistic or utili-

tarian viewpoint in their work. Schminke and Wells (1999)

showed that ‘‘groups exert a powerful influence on indi-

viduals’ ethical frameworks, and that the patterns of these

influences differ depending on the type of ethical

framework involved. Individuals’ ethical utilitarianism [is]

affected by both leadership style and group cohesiveness.

Ethical formalism [is] most affected by the leadership style

in the group’’ (p. 367).

Promoting Collectivism in Organizations

We now turn to ways that individual-level collectivism can

be promoted within an organization. Our research shows

that employees in the financial services industry who have

more individualistic tendencies commit more CA than their

collectivist counterparts. What can realistically be done to

curb these individualistic cultural tendencies? Traditional

research on culture emphasizes the characteristics of col-

lectivism–individualism as something highly ingrained

within a person (e.g., Hofstede 1991). However, recent

research has shown that these tendencies can be manipu-

lated and primed in group and organizational settings.

Research has suggested that incentives provided within an

organization can encourage collectivistic behavior and dis-

courage individualistic behavior (Chen and Li 2005; Husted

and Allen 2008, p. 295; Voronov and Singer 2002). If an

organization wants individualistic behavior in its employees,

managers then need to manage people as individualists ‘‘based

upon individual skills’’ (Tavakoli et al. 2003, p. 52), which

would include an emphasis on rewarding individual behavior

(e.g., raises and bonuses based solely on individual perfor-

mance). This approach, for example, could also be structured

in preference for individualized emails for communication

over group instant-messaging chat. If an organization desires

collectivist behaviors, managers can lead employees as groups

and make employment- and promotion-related decisions

‘‘based upon group membership and group achievement’’

(Tavakoli et al. 2003, p. 52), which could be further enhanced

by group measurement and rewards (e.g., raises and bonuses

primarily based on group achievement). Aside from group

instant-messaging chat, collectivism could also be fostered by

other forms of collaborative technologies that promote shar-

ing, group awareness, group consensus building, group deci-

sion making, and group file exchange (e.g., Groove, Dropbox,

and Skype). These recommendations could also be transferred

to individual or group incentives and rewards based on the

occurrence (or lack thereof) of behaviors deemed detrimental

to the security of an organization’s IS.

As a promising recent development, a meta-analysis of

individualism–collectivism indicates that individuals’ pro-

pensities toward individualism–collectivism can be primed

in group settings (Oyserman and Lee 2008). This result is

particularly exciting because it allows interventions—often

of a simple nature—to be used in work groups and in the

workplace generally in ways that can prime the positive

aspects of collectivism in individuals to help prevent CA.

Three approaches can be used as this ‘‘primer’’ (Oyserman

396 P. B. Lowry et al.

123

and Lee 2008): (1) emphasizing ‘‘we’’ language to focus on

the collective itself; (2) focusing on specific salient aspects

of the collective, such as individual obligation to and

similarity with the group; (3) emphasizing integration or

connections to others, such as using the word ‘‘connect’’ to

describe interrelationships. This recent work further sup-

ports the previous argument that the collectivism–individ-

ualism dimensions are not inherent qualities of culture but

manifestations of attributes that arise according to a given

context (Husted and Allen 2008; Oyserman 2006; Oyser-

man et al. 2002; Torelli 2006).

Limitations and Future Research

A potential problem when surveying individuals about sen-

sitive topics such as CA is response distortion caused by the

respondents’ desire to provide socially desirable answers

(Cheng et al. 1997; Moores and Chang 2006). However, our

use of an Internet panel allows researchers examining topics of

a sensitive nature to receive responses less inhibited by social

desirability effects as anonymity is ensured (Bennett and

Robinson 2000; Posey et al. 2011). Online panelists were

guaranteed that their identities would not be released by

SurveyMonkey to the researchers, thus protecting the

respondents from repercussions from their organizations from

the reported CA incidents. Nonetheless, anonymity does not

guarantee that social desirability will not occur to some

degree. One way to potentially increase the accuracy of these

results is to use an indirect questioning method (Anderson

1978), which can help reduce socially desirable responding

(Fisher 1993). For example, this methodology requires the

rephrasing of measurement items from ‘‘I…’’ to ‘‘One or more of my co-workers…’’ or ‘‘Individuals in my work group…’’

Similar to individuals engaged in other ‘‘dark side variables’’

(Mick 1996), individuals committing CA may be more likely

to project their own socially undesirable activity to hide

behind others’ activity. The development of methods to more

accurately evoke confessions of CA would be a substantial

contribution to the research because many abuses may never

be discovered by other means. Anonymity remains one of the

more promising routes for achieving this goal.

Probably the most important limitation of this study is that

it is based on data from a survey. Consequently, the results

are not causal and do not lend themselves to providing causal

insights into the decision-making process of those commit-

ting CA. As noted, there are two approaches to studying

ethics in the literature: one based on dispositions and traits

and one based on the decision-making process (Haines and

Leonard 2007). We follow the former, which has been

addressed much less frequently in the IS/IT literature than

models based on the ethical decision-making process. Even

still, we argue that most of the IS research attempts involving

the ethical decision-making process examine outcomes at

one point in time and do not truly delve into the inner cog-

nitive processes involved in decision making. Future IS

research would be greatly benefited by two steps: first, by

creating a more comprehensive model that involves our

dispositional extensions of Thong and Yap’s (1998) model

along with extending their decision-making framework with

more recent IS decision-making models; second, by empir-

ically examining the ethics decision-making process rather

than just the outcome.

Appendix 1

See Table 5.

Table 5 Measurement items

Construct Items Notes

Formalism F1. Principled

F2. Dependable

F3. Trustworthy

F4. Honest

F5. Noted for integrity

F6. Law abiding

These were interspersed with the utilitarian items

and dummy items that were thrown out.

The following prompt preceded these items:

‘‘To what extent is each of the following

character traits important to you?’’ All items

from Schminke and Wells (1999)

Utilitarianism U1. Utilitarian

U2. Resourceful

U3. Effective

U4. Influential

U5. Results-oriented

U6. Productive

U7. A winner

See notes on formalism. All items from

Schminke and Wells (1999)

Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 397

123

References

Anderson, J. C. (1978). The validity of Haire’s shopping list

projective technique. Journal of Marketing Research, 15(4),

644–649.

Ariss, S. S. (2002). Computer monitoring: Benefits and pitfalls facing

management. Information & Management, 39(7), 553–558.

Bailey, W. J., & Spicer, A. (2007). When does national identity

matter? Convergence and divergence in international business

ethics. Academy of Management Journal, 50(6), 1462–1480.

Banerjee, D., Cronan, T. P., & Jones, T. M. (1998). Modeling IT

ethics: A study in situational ethics. MIS Quarterly, 22(1),

31–60.

Beekun, R. I., Hamdy, R., Westerman, J. W., & HassabElnaby, H. R.

(2008). An exploration of ethical decision-making processes in

the United States and Egypt. Journal of Business Ethics, 82(3),

587–605.

Bennett, R. J., & Robinson, S. L. (2000). Development of a measure

of workplace deviance. Journal of Applied Psychology, 85(3),

349–360.

Birnbaum, M. H. (2004). Human research and data collection via the

internet. Annual Reviews of Psychology, 55, 803–832.

Table 5 continued

Construct Items Notes

Computer

abuse

CA1. I have damaged computer property belonging to my

employer (e.g., hardware, software, data files, etc.)

CA2. I have deliberately bent or broken a computer-related

rule or policy

CA3. I have adjusted data in the computer system to make my

activity appear more in line with organizational computer

guidelines, policies, and/or rules

CA4. I have gone against management decisions regarding

what management deems appropriate computer system use

CA5. I have sabotaged portions of the computer system

CA6. I have intentionally made errors in the computer system

CA7. I have covered up mistakes in the computer system

CA8. I have taken computer system resources without proper

approval (e.g., hardware, software, data files)

CA9. I have misused my computer system access privilege(s)

The following prompt preceded these items: ‘‘Since the most

recent internal computer-system security policies,

procedures, and/or rules referred to above were implemented,

how often have you engaged in the activities listed below?’’

Items 1 and 2 are from Robinson and O’Leary-Kelly (1998).

Item 3 is from Jaworski and MacInnis (1989). Item 4 is from

Vardi (2001). Items 5 through 9 are from Robinson and

Bennett (1995)

Individualism I1. I would rather depend on myself than others*

I2. I rely on myself most of the time; I rarely rely on others*

I3. I often do ‘‘my own thing’’*

I4. My personal identity, independent of others, is very

important to me*

I5. It is important that I do my job better than others*

I6. Winning is everything

I7. Competition is the law of nature

I8. When another person does better than I do, I get tense and

aroused

All individualism items are from Triandis and Gelfand (1998)

Collectivism C1. If a coworker gets a prize, I would feel proud

C2. The well-being of my coworkers is important to me

C3. To me, pleasure is spending time with others

C4. I feel good when I cooperate with others

C5. Parents and children must stay together as much as

possible*

C6. It is my duty to take care of my family, even when I have

to sacrifice what I want*

C7. Family members should stick together, no matter what

sacrifices are required*

C8. It is important to me that I respect the decisions made by

my groups

All collectivism items are from Triandis and Gelfand (1998)

* Dropped to improve factorial validity

398 P. B. Lowry et al.

123

Boss, S. R., Kirsch, L. J., Angermeier, I., Shingler, R. A., & Boss, R.

W. (2009). If someone is watching, I’ll do what I’m asked:

Mandatoriness, control, and information security. European

Journal of Information Systems, 18(2), 151–164.

Boudreau, M. C., Gefen, D., & Straub, D. W. (2001). Validation in

information systems research: A state-of-the-art assessment. MIS

Quarterly, 25(1), 1–16.

Brady, F. N., & Dunn, C. P. (1995). Business meta-ethics: An analysis

of two theories. Business Ethics Quarterly, 3, 5.

Brady, F. N., & Wheeler, G. E. (1996). An empirical study of ethical

predispositions. Journal of Business Ethics, 15(9), 927–940.

Calluzzo, V. J., & Cante, C. J. (2004). Ethics in information

technology and software use. Journal of Business Ethics, 51(3),

301–312.

Cavusoglu, H., Raghunathan, S., & Cavusoglu, H. (2009). Configura-

tion of and interaction between information security technologies:

The case of firewalls and intrusion detection systems. Information

Systems Research, 20(2), 198–217.

Cenfetelli, R. T., & Bassellier, G. (2009). Interpretation of formative

measurement in information systems research. MIS Quarterly,

33(4), 689–707.

Chatterjee, S., Sarker, S., & Fuller, M. (2009). Ethical information

systems development: A Baumanian postmodernist perspective.

Journal of the Association for Information Systems, 10(11),

787–815.

Chen, X. P., & Li, S. (2005). Cross-national differences in cooper-

ative decision-making in mixed-motive business contexts: The

mediating effect of vertical and horizontal individualism.

Journal of International Business Studies, 36, 622–636.

Cheng, H. K., Sims, R. R., & Teegen, H. (1997). To purchase or to

pirate software: An empirical study. Journal of Management

Information Systems, 13(4), 49–60.

Chin, W. W., Marcolin, B. L., & Newsted, P. R. (1996, December

16–18). A partial least squares latent variable modeling

approach for measuring interaction effects: Results from a

Monte Carlo simulation study and voice mail emotion/adoption

study. Paper presented at the 17th International conference on

information systems, Cleveland, OH, USA.

Chin, W., Marcolin, B., & Newsted, P. (2003). A partial least squares

latent variable modeling approach for measuring interaction

effects: Results from a Monte Carlo simulation study and an

electronic mail emotion/adoption study. Information Systems

Research, 14(2), 189–217.

Cohen, E., & Cornwell, L. (1989). A question of ethics: Developing

information system ethics. Journal of Business Ethics, 8(6),

431–437.

Cook, T. D., & Campbell, D. T. (1979). Quasi-experimentation:

Design and analysis for field settings. Chicago: Rand McNally.

Culnan, M., & Williams, C. (2009). How ethics can enhance

organizational privacy: Lessons from the ChoicePoint and TJX

data breaches. MIS Quarterly, 33(4), 673–686.

D’Arcy, J., & Hovav, A. (2007). Deterring internal information

systems misuse. Communications of the ACM, 50(10), 113–117.

D’Arcy, J., Hovav, A., & Galletta, D. F. (2009). User awareness of

security countermeasures and its impact on information systems

misuse: A deterrence approach. Information Systems Research,

20(1), 79–98.

Davison, R. M., Martinsons, M. G., Ou, C. X. J., Murata, K.,

Drummond, D., Li, Y., et al. (2009). The ethics of IT

professionals in Japan and China. Journal of the Association

for Information Systems, 10(11), 834–859.

Diamantopoulos, A., & Siguaw, J. A. (2006). Formative versus

reflective indicators in organizational measure development: A

comparison and empirical illustration. British Journal of Man-

agement, 17(2006), 263–282.

Diamantopoulos, A., & Winklhofer, H. M. (2001). Index construction

with formative indicators: An alternative to scale development.

Journal of Marketing Research, 38(2), 269–277.

Donaldson, T. (1996). Values in tension: Ethics away from home.

Harvard Business Review, 74(5), 48–62.

Douglas, D. E., Cronan, T. P., & Behel, J. D. (2007). Equity

perceptions as a deterrent to software piracy behavior. Informa-

tion & Management, 44(5), 503–512.

Earley, P. C. (1989). Social loafing and collectivism. Administrative

Science Quarterly, 34, 565–581.

Fischer, R., Ferreira, M. C., Assmar, E. M. L., Redford, P., & Harb, C.

(2005). Organizational behaviour across cultures: Theoretical

and methodological issues for developing multi-level frame-

works involving culture. International Journal of Cross Cultural

Management, 5(1), 27–48.

Fisher, R. J. (1993). Social desirability bias and the validity of indirect

questioning. Journal of Consumer Research, 20(2), 303–315.

Fiske, A. P. (2002). Using individualism and collectivism to compare

cultures—A critique of the validity and measurement of the

constructs: Comment on Oyserman et al. (2002). Psychological

Bulletin, 128(1), 78–88.

Fornell, C., & Larcker, D. F. (1981). Evaluating structural equation

models with unobservable variables and measurement error.

Journal of Marketing Research, 18(1981), 39–50.

Fraley, R. C. (2007). Using the internet for personality research: What

can be done, how to do it, and some concerns. In R. W. Robins,

R. C. Fraley, & R. F. Krueger (Eds.), Methods in personality

psychology (pp. 130–148). New York: Guilford.

Gan, L. L., & Koh, H. C. (2006). An empirical study of software

piracy among tertiary institutions in Singapore. Information &

Management, 43(5), 640–649.

Gattiker, U. E., & Kelley, H. (1999). Morality and computers:

Attitudes and differences in moral judgments. Information

Systems Research, 10(3), 233–254.

Gefen, D., & Straub, D. W. (2005). A practical guide to factorial

validity using PLS-Graph: Tutorial and annotated example.

Communications of the Association for Information Systems,

16(5), 91–109.

Haines, R., & Leonard, L. N. K. (2007). Situational influences on

ethical decision-making in an IT context. Information &

Management, 44(3), 313–320.

Hansen, J. V., Lowry, P. B., Meservy, R., & McDonald, D. (2007).

Genetic programming for prevention of cyberterrorism through

dynamic and evolving intrusion detection. Decision Support

Systems, 43(4), 1362–1374.

Harrington, S. J. (1996). The effect of codes of ethics and personal

denial of responsibility on computer abuse judgments and

intentions. MIS Quarterly, 20(3), 257–278.

Herath, T., & Rao, H. R. (2009a). Encouraging information security

behaviors in organizations: Role of penalties, pressures and

perceived effectiveness. Decision Support Systems, 47(2),

154–165.

Herath, T., & Rao, H. R. (2009b). Protection motivation and

deterrence: A framework for security policy compliance in

organisations. European Journal of Information Systems, 18(2),

106–125.

Hilton, T. (2000). Information systems ethics: A practitioner survey.

Journal of Business Ethics, 28(4), 279–284.

Hofstede, G. (1984). Culture’s consequences: International differ-

ences in work related values. London: Sage.

Hofstede, G. (1991). Cultures and organizations: Software of the

mind. Berkshire: McGraw-Hill Book Company Europe.

Hofstede, G. (2001). Culture’s consequences—Comparing values, behav-

iors, institutions, and organizations across nations (2nd ed.).

London: Sage.

Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 399

123

Hofstede, G. (2002). The pitfalls of cross-national survey research: A

reply to the article by Spector et al. on the psychometric

properties of the Hofstede value survey module 1994. Applied

Psychology: An International Review, 51(1), 170–178.

Hunt, S. D., & Vitell, S. J. (1986). A general theory of marketing

ethics. Journal of Macromarketing, 6(Spring), 5–16.

Husted, B. W. (2000). The impact of national culture on software

piracy. Journal of Business Ethics, 26(3), 197–211.

Husted, B., & Allen, D. (2008). Toward a model of cross-cultural

business ethics: The impact of individualism and collectivism on

the ethical decision-making process. Journal of Business Ethics,

82(2), 293–305.

Husted, B. W., Dozier, J. B., McMahon, J. T., & Kattan, M. W.

(1996). The impact of cross-national carriers of business ethics

on attitudes about questionable practices and form of moral

reasoning. Journal of International Business Studies, 27(2),

391–411.

Jaworski, B. J., & MacInnis, D. J. (1989). Marketing jobs and

management controls: Toward a framework. Journal of Market-

ing Research, 26, 406–419.

Johnston, A. C., & Warkentin, M. (2010). Fear appeals and

information security behaviors: An empirical study. MIS Quar-

terly, 34, 549–566.

Jones, T. M., & Ryan, L. V. (1997). The link between ethical

judgment and action in organizations: A moral approbation

approach. Organization Science, 8(6), 663–680.

Keith, M., Shao, B., & Steinbart, P. (2009). A behavioral analysis of

passphrase design and effectiveness. Journal of the Association

for Information Systems, 10(2), 63–89.

Kock, N. (2010). WarpPLS 1.0 user manual. Laredo, TX: ScriptWarp

Systems.

Lee, S. M., Lee, S. G., & Yoo, S. (2004). An integrative model of

computer abuse based on social control and general deterrence

theories. Information & Management, 41, 707–718.

Leonard, L. N. K., & Cronan, T. P. (2001). Illegal, inappropriate, and

unethical behavior in an information technology context: A

study to explain influences. Journal of the Association for

Information Systems, 1(12), 1–31.

Leonard, L. N. K., Cronan, T. P., & Kreie, J. (2004). What influences

IT ethical behavior intentions—Planned behavior, reasoned

action, perceived importance, or individual characteristics?

Information & Management, 42(2004), 143–158.

Liang, H., Saraf, N., Hu, Q., & Xue, Y. (2007). Assimilation of

enterprise systems: The effect of institutional pressures and the

mediating role of top management. MIS Quarterly, 31(1), 59–87.

Loch, K. D., & Conger, S. (1995). Evaluating ethical decision making

and computer use. Communications of the ACM, 39(7), 74–83.

Lowry, P. B., Romano, N. C., Jenkins, J. L., & Guthrie, R. W. (2009). The

CMC interactivity model: How interactivity enhances communi-

cation quality and process satisfaction in lean-media groups.

Journal of Management Information Systems, 26(1), 159–200.

Lowry, P. B., Vance, A., Moody, G., Beckman, B., & Read, A.

(2008). Explaining and predicting the impact of branding

alliances and web site quality on initial consumer trust of

e-commerce web sites. Journal of Management Information

Systems, 24(4), 199–224.

McCoy, S., Galletta, D. F., & King, W. R. (2005). Integrating national

culture into IS research: The need for current individual-level

measures. Communications of the AIS, 15, 211–224.

Merhout, J. W., & Havelka, D. (2008). Information technology

auditing: A value-added IT governance partnership between IT

management and audit. Communications of the Association for

Information Systems, 23(26), 463–482.

Mick, D. G. (1996). Are studies of dark side variables confounded by

socially desirable responding? The case of materialism. Journal

of Consumer Research, 23(2), 106–111.

Moores, T. T., & Chang, J. C.-J. (2006). Ethical decision making in

software piracy: Initial development and test of a four-compo-

nent model. MIS Quarterly, 30(1), 167–180.

Moores, T. T., & Dhaliwal, J. (2004). A reversed context analysis of

software piracy issues in Singapore. Information & Manage-

ment, 41(8), 1037–1042.

Myyry, L., Siponen, M., Pahnila, S., Vartiainen, T., & Vance, A.

(2009). What levels of moral reasoning and values explain

adherence to information security rules? An empirical study.

European Journal of Information Systems, 18(2), 126–139.

Nunnally, J. C., & Bernstein, I. H. (1994). Psychometric theory. New

York: McGraw-Hill.

Oyserman, D. (2006). High power, low power, and equality: Culture

beyond individualism and collectivism. Journal of Consumer

Psychology, 16(4), 352–356.

Oyserman, D., Coon, M., & Kemmelmeier, M. (2002). Rethinking

individualism and collectivism: Evaluation of the theoretical

assumptions and meta-analysis. Psychological Bulletin, 128(1),

3–72.

Oyserman, D., & Lee, S. W. S. (2008). Does culture influence what

and how we think? Effects of priming individualism and

collectivism. Psychological Bulletin, 134(2), 311–342.

Patel, T., & Schaefe, A. (2009). Making sense of the diversity of

ethical decision making in business: An illustration of the Indian

context. Journal of Business Ethics, 90(2), 171–186.

Pavlou, P., Liang, H., & Xue, Y. (2007). Understanding and

mitigating uncertainty in online exchange relationships: A

principal-agent perspective. MIS Quarterly, 31(1), 105–136.

Peace, A. G., Galletta, D. F., & Thong, J. Y. L. (2003). Software

piracy in the workplace: A model and empirical test. Journal of

Management Information Systems, 20(1), 153–177.

Petter, S., Straub, D. W., & Rai, A. (2007). Specifying formative

constructs in information systems research. MIS Quarterly,

31(4), 623–656.

Podsakoff, P. M., MacKenzie, S. B., Lee, J. Y., & Podsakoff, N. P.

(2003). Common method biases in behavioral research: A

critical review of the literature and recommended remedies.

Journal of Applied Psychology, 88(5), 879–903.

Posey, C., Bennett, R., Roberts, T. L., & Lowry, P. B. (2011). When

computer monitoring backfires: Invasion of privacy and organi-

zational injustice as precursors to computer abuse. Journal of

Information System Security, 7(1), 24–47.

Ralston, D. A., Holt, D. H., Terpstra, R. H., & Kai-Cheng, Y. (2008).

The impact of national culture and economic ideology on

managerial work values: A study of the United States, Russia,

Japan, and China. Journal of International Business Studies,

39(1), 8–26.

Ransbotham, S., & Mitra, S. (2009). Choice and chance: A conceptual

model of paths to information security compromise. Information

Systems Research, 20(1), 121–139.

Rao, M. T., Brown, C. V., & Perkins, W. C. (2007). Host country

resource availability and information system control mechanisms

in multinational corporations: An empirical test of resource

dependence theory. Journal of Management Information Sys-

tems, 23(4), 11–28.

Ringle, C. M., Wende, S., & Will, S. (2005). SmartPLS 2.0 (M3) Beta.

Retrieved September 17, 2010, from http://www.smartpls.de.

Robertson, C. J., & Crittenden, W. F. (2002). Mapping moral

philosophies: Strategic implications for multinational firms.

Strategic Management Journal, 24(4), 327–338.

Robertson, C., Crittenden, W., Brady, M., & Hoffman, J. (2002).

Situational ethics across borders: A multicultural examination.

Journal of Business Ethics, 38(4), 327–338.

Robertson, C., & Fadil, P. A. (1999). Ethical decision making in

multinational organizations: A culture-based model. Journal of

Business Ethics, 19(4), 385–392.

400 P. B. Lowry et al.

123

Robertson, C., Gilley, K., & Crittenden, W. (2008). Trade liberaliza-

tion, corruption, and software piracy. Journal of Business Ethics,

78(4), 623–634.

Robinson, S. L., & Bennett, R. J. (1995). A typology of deviant

workplace behaviors: A multidimensional scaling study. Acad-

emy of Management Journal, 38(2), 555–572.

Robinson, S. L., & O’Leary-Kelly, A. M. (1998). Monkey see,

monkey do: The influence of work groups on the antisocial

behavior of employees. Academy of Management Journal, 41(6),

658–672.

Schlegelmilch, B. B., & Robertson, D. C. (1995). The influence of

country and industry on ethical perceptions of senior executives

in the U.S. and Europe. Journal of International Business

Studies, 26(4), 859–881.

Schminke, M., Ambrose, M. L., & Noel, T. W. (1997). The effect of

ethical frameworks on perceptions of organizational justice.

Academy of Management Journal, 40(5), 1190–1207.

Schminke, M., & Wells, D. (1999). Group processes and performance

and their effects on individuals’ ethical frameworks. Journal of

Business Ethics, 18(4), 367–381.

Shin, S. K., Ishman, M., & Sanders, G. L. (2007). An empirical

investigation of socio-cultural factors of information sharing in

China. Information & Management, 44(2), 165–174.

Siponen, M., & Vance, A. (2010). Neutralization: New insights into

the problem of employee information systems security policy

violations. MIS Quarterly, 34, 487–502.

Siponen, M., & Vartiainen, T. (2007). Unauthorized copying of

software and levels of moral development: A literature analysis

and its implications for research and practice. Information

Systems Journal, 14(4), 387–407.

Smith, H. J., & Hasnas, J. (1999). Ethics and information systems:

The corporate domain. MIS Quarterly, 23(1), 109–127.

Smith, H. J., & Keil, M. (2003). The reluctance to report bad news on

troubled software projects: A theoretical model. Information

Systems Journal, 13(1), 69–95.

Smith, H. J., Keil, M., & Depledge, G. (2001). Keeping mum as the

project goes under: Toward an explanatory model. Journal of

Management Information Systems, 18(2), 189–227.

Son, J.-Y., & Kim, S. S. (2008). Internet users’ information privacy-

protective responses: A taxonomy and a nomological model.

MIS Quarterly, 32(3), 503–529.

Sproull, L., & Kiesler, S. (1991). Connections. Boston: MIT Press.

Srite, M., & Karahanna, E. (2006). The role of espoused national

cultural values in technology acceptance. MIS Quarterly, 30(3),

679–704.

Staples, D. S., Hulland, J. S., & Higgins, C. A. (1999). A self-efficacy

theory explanation for the management of remote workers in

virtual organizations. Organization Science, 10(6), 758–776.

Straub, D. W. (1989). Validating instruments in MIS research. MIS

Quarterly, 13(2), 147–169.

Straub, D. W. (1990). Effective IS security: An empirical study.

Information Systems Research, 1(3), 255–276.

Straub, D. W., Boudreau, M. C., & Gefen, D. (2004). Validation

guidelines for IS positivist research. Communications of the

Association for Information Systems, 14(2004), 380–426.

Straub, D. W., & Welke, R. J. (1998). Coping with systems risk:

Security planning models for management decision making. MIS

Quarterly, 22(4), 441–469.

Sutton, S. (1998). Predicting and explaining intentions and behavior:

How well are we doing? Journal of Applied Social Psychology,

28(15), 1317–1338.

Sutton, S. G., Khazanchi, D., Hampton, C., & Arnold, V. (2008). Risk

analysis in extended enterprise environments: Identification of

critical risk factors in B2B e-commerce relationships. Journal of

the Association for Information Systems, 9(3/4), 151–174.

Swinyard, W. R., Rinne, H., & Kau, A. K. (1990). The morality of

software piracy: A cross-cultural analysis. Journal of Business

Ethics, 9(8), 655–664.

Tavakoli, A. A., Keenan, J. P., & Crnjak-Karanovic, B. (2003).

Culture and whistleblowing an empirical study of Croatian and

United States managers utilizing Hofstede’s cultural dimensions.

Journal of Business Ethics, 43(1/2), 49–64.

Thong, J. Y. L., & Yap, C.-s. (1998). Testing an ethical decision-

making theory: The case of softlifting. Journal of Management

Information Systems, 15(1), 213–237.

Torelli, C. J. (2006). Individuality or conformity? The effects of

independent and interdependent self-concepts on public judg-

ments. Journal of Consumer Research, 16(3), 240–248.

Triandis, H. C., & Gelfand, M. J. (1998). Converging measurement of

horizontal and vertical individualism and collectivism. Journal

of Personality and Social Psychology, 74, 118–128.

Tsui, J., & Windsor, C. (2001). Some cross-cultural evidence on

ethical reasoning. Journal of Business Ethics, 31(2), 143–150.

Tuttle, B., Harrell, A., & Harrison, P. (1997). Moral hazard, ethical

considerations, and the decision to implement an information

system. Journal of Management Information Systems, 13(4), 7–27.

Vardi, Y. (2001). The effects of organizational and ethical climates on

misconduct at work. Journal of Business Ethics, 29, 325–337.

Vitell, S. J., Nwachukwu, S. L., & Barnes, J. H. (1993). The effects of

culture on ethical decision-making: An application of Hofstede’s

typology. Journal of Business Ethics, 12(10), 753–760.

Voronov, M., & Singer, J. A. (2002). The myth of individualism-

collectivism: A critical review. Journal of Social Psychology,

142(4), 461–480.

Wang, J., Chaudhury, A., & Rao, H. R. (2008). A value-at-risk

approach to information security investment. Information Systems

Research, 19(1), 106–123.

Wang, J., Chen, R., Herath, T., & Rao, H. R. (2009). Visual e-mail

authentication and identification services: An investigation of the

effects on e-mail use. Decision Support Systems, 48(1), 92–102.

Winter, S., Stylianou, A., & Giacalone, R. (2004). Case of Machi-

avellianism and ethical ideology. Journal of Business Ethics,

54(3), 279–301.

Zhang, D., & Lowry, P. B. (2008). Issues, limitations, and opportunities

in cross-cultural research on collaborative software in information

systems. Journal of Global Information Management, 16(1), 61–92.

Zhang, D., Lowry, P. B., Zhou, L., & Fu, X. (2008). The impact of

individualism-collectivism, social presence, and group diversity

on group decision making under majority influence. Journal of

Management Information Systems, 23(4), 53–80.

Zhang, J., Luo, X., Akkaladevi, S., & Ziegelmayer, J. (2009).

Improving multiple-password recall: An empirical study. Euro-

pean Journal of Information Systems, 18(2), 165–176.

Zviran, M., & Erlich, Z. (2006). Identification and authentication:

Technology and implementation issues. Communications of the

Association for Information Systems, 17(4), 90–105.

Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 401

123

Reproduced with permission of the copyright owner. Further reproduction prohibited without permission.

  • c.10551_2013_Article_1705.pdf
    • Is Your Banker Leaking Your Personal Information? The Roles of Ethics and Individual-Level Cultural Characteristics in Predicting Organizational Computer Abuse
      • Abstract
      • Introduction
      • Background on Investigating Computer Abuse in Organizations
      • The Case for Studying Individual-Level Ethics in Computer Abuse
      • The Case for Studying Individual-Level Cultural Characteristics in Computer Abuse
      • Theoretic Model and Hypotheses
        • Predictions for CA Based on Ethical Formalism and Utilitarianism
        • Predictions for CA Based on Individual-Level Collectivism and Individualism
      • Research Methods
        • Data Collection
        • Construct Measurement
      • Analysis and Results
        • Summary of Results
        • Contributions to Theory
        • Applying Results in Practice
          • Promoting Formalism in Organizations
          • Promoting Collectivism in Organizations
      • Limitations and Future Research
      • Appendix 1
      • References