Strategic Information Technology lesson 8
Is Your Banker Leaking Your Personal Information? The Roles of Ethics and Individual-Level Cultural Characteristics in Predicting Organizational Computer Abuse
Paul Benjamin Lowry • Clay Posey •
Tom L. Roberts • Rebecca J. Bennett
Received: 29 November 2010 / Accepted: 3 April 2013 / Published online: 25 April 2013
� Springer Science+Business Media Dordrecht 2013
Abstract Computer abuse (CA) by employees is a criti-
cal concern for managers. Misuse of an organization’s
information assets leads to costly damage to an organiza-
tion’s reputation, decreases in sales, and impositions of
fines. We use this opportunity to introduce and expand the
theoretic framework proffered by Thong and Yap (1998) to
better understand the factors that lead individuals to com-
mit CA in organizations. The study uses a survey of 449
respondents from the banking, financial, and insurance
industries. Our results indicate that individuals who adhere
to a formalist ethical perspective are significantly less
likely to engage in CA activities than those following a
utilitarian ethical framework. In addition, the results provide
evidence that employees with individualistic natures are
linked to increased CA incidents, whereas collectivist ten-
dencies are associated with decreases in CA behaviors. Our
results also show that collectivism acts as a strong moderator
that further decreases the relationships between formalism
and CA, and utilitarianism and CA. Finally, we offer
detailed suggestions on how organizations and researchers
can leverage our findings to decrease CA occurrences.
Keywords Culture � Computer abuse � Deontological evaluations � Ethics � Formalism � Information security � Organizational security � Teleological evaluations � Utilitarianism � Collectivism � Individualism
Abbreviations
CA Computer abuse
CMD Cognitive moral development theory
IS Information systems
IT Information technology
Introduction
An organizational issue of increasing importance is
employees abusing their access to computers and organi-
zational information assets, a phenomenon known as
computer abuse (CA) (Posey et al. 2011; Straub 1990),
which spreads in scope and impact as technology is used
more widely. Straub (1990) formally defined CA as ‘‘the
unauthorized and deliberate misuse of assets of the local
organization information system by individuals’’ (p. 257).
CA is a critical problem requiring corporate leadership to
resolve (D’Arcy and Hovav 2007; Lee et al. 2004; Peace
et al. 2003; Posey et al. 2011): In one study, nearly half of
Electronic supplementary material The online version of this article (doi:10.1007/s10551-013-1705-3) contains supplementary material, which is available to authorized users.
P. B. Lowry (&) College of Business, City University of Hong Kong, P7912,
Academic Building I, 83 Tat Chee Avenue, Hong Kong, China
e-mail: [email protected]
C. Posey
Information Systems, Statistics and Management Science,
Culverhouse College of Commerce, The University of Alabama,
Box 870226, Tuscaloosa, AL 35487, USA
e-mail: [email protected]
T. L. Roberts � R. J. Bennett Department of Management and Information Systems, College
of Business, Louisiana Tech University, P.O. Box 10318,
Ruston, LA 71272, USA
e-mail: [email protected]
R. J. Bennett
e-mail: [email protected]
123
J Bus Ethics (2014) 121:385–401
DOI 10.1007/s10551-013-1705-3
the participants involved were aware of CA in their orga-
nizations (Hilton 2000); in another, approximately 30 % of
business professionals admitted to pirating their employers’
software (Haines and Leonard 2007). Many organizations
have also had to discipline employees for downloading
pornography at work or abusing email (Haines and Leonard
2007). Disgruntled employees rank second to outside
hackers as sources of system attacks (Haines and Leonard
2007); clearly, internal CA is a critical problem facing
organizations today (D’Arcy and Hovav 2007; Lee et al.
2004; Peace et al. 2003; Posey et al. 2011).
The negative impact of CA can be accounted for in the
loss of hundreds of billions of dollars caused by lost effi-
ciency, software piracy, security leaks, privacy violations,
legal liabilities, and the like (Culnan and Williams 2009;
Douglas et al. 2007; Gan and Koh 2006; Moores and
Dhaliwal 2004; Siponen and Vartiainen 2007; Son and Kim
2008; Thong and Yap 1998). However, many of the cata-
strophic losses are hard to calculate as they can affect the
core of an organization’s business in complex and profound
ways (Wang et al. 2008) such as lost reputation, lost sales,
and legal liabilities (Son and Kim 2008).
The ethical and cultural issues surrounding CA are of
unprecedented importance to organizations and thus are
management not just technical issues (Posey et al. 2011;
Ransbotham and Mitra 2009). The many ethical gray areas
and issues surrounding CA are particularly problematic
(Calluzzo and Cante 2004) because such issues often
involve moral hazard. 1
Moral hazard has increased as
computer use has increased (Tuttle et al. 1997) because of
the ability to hide privately held information or the often
inaccurate belief that one can hide such information. Even
when no moral hazard exists, many forms of CA do not
have clear right and wrong implications for the abusers,
and thus, they have no ethical or moral incentive to not
commit the abuse (Calluzzo and Cante 2004; Cohen and
Cornwell 1989). Therefore, CA has strong ethical and
cultural foundations.
Given the serious management and organizational
issues caused by CA, and its expansive interrelationship
with ethics and culture, the purpose of this paper is
twofold: (1) to examine the degree to which one’s dis-
position toward ethical formalism or utilitarianism affects
one’s propensity to commit CA and (2) to examine the
degree to which one’s individual-level characteristics of
collectivism and individual influence one’s propensity to
commit CA.
Background on Investigating Computer Abuse
in Organizations
Due to the growing importance of CA-related issues in the
ethical use of IS, researchers have investigated various
methods to address these issues. The most traditional
approach to preventing CA has been to try to directly block
negative employee behaviors with technical measures.
Some of these approaches have included authentication and
identification (Wang et al. 2009; Zviran and Erlich 2006),
passwords and pass phrases (Keith et al. 2009; Zhang et al.
2009), firewalls (Cavusoglu et al. 2009), intrusion detection
(Cavusoglu et al. 2009; Hansen et al. 2007; Ransbotham
and Mitra 2009), rights management, countermeasures
(Ransbotham and Mitra 2009), and system controls (Rao
et al. 2007). Additional approaches include the use of
policies and procedures, computer monitoring (Ariss
2002), audit trails, IT audits (Merhout and Havelka 2008),
IS risk analyses (Sutton et al. 2008), IS security counter-
measures (Hansen et al. 2007; Straub and Welke 1998),
and general violation-prevention strategies (D’Arcy et al.
2009).
Other approaches have innovatively coupled psychology
with traditional approaches. These integrated methods
include using fear appeals (Johnston and Warkentin 2010),
leveraging employee perceptions of IT policy so policies
appear more mandatory (Boss et al. 2009), countering
neutralization techniques (Siponen and Vance 2010), and
using general deterrence theory (Herath and Rao 2009b;
Lee et al. 2004; Straub 1990) or related penalty-oriented
techniques (Herath and Rao 2009a).
Although these approaches have shown some efficacy,
the results are highly mixed. We posit that one possible
reason is that such studies have largely ignored individual-
level ethical and cultural characteristics that likely impact
one’s decisions about various kinds of CA. Thus, we assert
that both considerations need further examination.
The Case for Studying Individual-Level Ethics
in Computer Abuse
Ethics have long been acknowledged as a key individual-
level consideration in IT use. IT studies have used ethics-
based approaches in reviewing situational ethics (Banerjee
et al. 1998), IT development (Chatterjee et al. 2009),
decision making and moral reasoning relating to IT use
(Calluzzo and Cante 2004; Cohen and Cornwell 1989;
Davison et al. 2009; Harrington 1996; Leonard and Cronan
2001; Leonard et al. 2004; Loch and Conger 1995; Myyry
et al. 2009; Smith and Hasnas 1999), and reporting or not
reporting bad IT news (Smith and Keil 2003; Smith et al.
2001). Yet little research addresses ethics and CA. The
1 Moral hazard occurs when there is ‘‘an incentive to act in one’s
self-interest in conflict with the organization’s overall goals while
being able to hide those actions through privately held information’’
(Tuttle et al. 1997, p. 7).
386 P. B. Lowry et al.
123
primary examples of ethics and CA studies include specific
contexts of software piracy (Gan and Koh 2006; Moores
and Chang 2006; Moores and Dhaliwal 2004) and avoiding
privacy violations (Culnan and Williams 2009), but no
studies have applied ethics to the broader construct of CA.
Furthermore, an opportunity exists in studying the effect
of ethical dispositions themselves. Haines and Leonard
(2007) noted two approaches to studying ethics: one based
on dispositions and traits and the other based on the deci-
sion-making process. The IT literature is replete with
studies that examine the decision-making process in rela-
tion to appropriate and inappropriate technology-based
individual behaviors, yet little research has been conducted
in terms of individual ethical dispositions and traits. For
example, Winter et al. (2004) studied on Machiavellianism
and ethical idealism. A much more common research
perspective on ethical dispositions and traits, which has
produced several promising non-technology-related studies
in the management literature (Brady and Dunn 1995; Brady
and Wheeler 1996; Hunt and Vitell 1986; Schminke et al.
1997), involves the study of formalism and utilitarianism.
The promise of studying the effects of individual ethical
dispositions on CA yields our first research question:
RQ1 In what way(s) do individuals’ ethical tendencies
toward formalism or utilitarianism predict the individuals
propensity to commit CA in the workplace?
The Case for Studying Individual-Level Cultural
Characteristics in Computer Abuse
Husted and Allen (2008) indicated that researchers still
understand little about how culture affects perception and
evaluation of abusive practices such as software piracy and
other behaviors. Worse still, how cultural dimensions
might affect CA more broadly—particularly culture at the
individual level—has yet to be fully examined. This limi-
tation is a glaring gap because increased globalization and
heterogeneity in organizations make cultural consider-
ations of ethical decisions all the more important, espe-
cially because cultural differences—primarily based on the
collectivism and individualism dimensions—have been
consistently shown to promote substantial differences in
ethical decision making (Bailey and Spicer 2007; Beekun
et al. 2008; Davison et al. 2009; Husted and Allen 2008;
Husted et al. 1996; Patel and Schaefe 2009; Ralston et al.
2008; Robertson and Crittenden 2002; Schlegelmilch and
Robertson 1995).
The few studies that have addressed forms of CA from a
cultural perspective have looked at software piracy at an
exploratory national culture level. For example, studies
have shown that software piracy is less frequent in the U.S.
than in Asia (Donaldson 1996; Swinyard et al. 1990).
Husted (2000) found that software piracy is correlated to
national GNP per capita, income inequality, and collec-
tivism. More recently, another study found substantial
differences in software piracy and related corruption
practices at the national culture level (Robertson et al.
2008). Davison et al. (2009) applied CMD theory to IT
professionals working in Japan and China, and showed that
the ethical reasoning in these two national cultures had
notable differences.
These studies suggest that the cultural dimensions of
collectivism and individualism may play a key role in
ethical decision making. The conceptualization of culture
on the national level conforms to the traditional view of
culture and is most often seen in studies comparing indi-
vidualistic societies (e.g., US) and collectivistic societies
(e.g., China) (Chen and Li 2005; Hofstede 1984, 1991,
2001; Tsui and Windsor 2001; Zhang et al. 2008). The
national-level perspective has been traditionally used in
ethics research. Some studies have shown that moral and
ethical reasoning differs across national cultures, but have
done so primarily as exploratory research without a strong
theoretic basis or explanation (Robertson et al. 2002; Tsui
and Windsor 2001). Other studies have proposed an even
stronger theoretic basis that national culture can be a
determinant of ethical differences (Robertson and Fadil
1999; Tavakoli et al. 2003; Vitell et al. 1993).
However, there are several research concerns about
national-level cultural studies, particularly in comparing
individualism and collectivism (e.g., Earley 1989; Fiske
2002; McCoy et al. 2005; Srite and Karahanna 2006; Tri-
andis and Gelfand 1998). The chief limitation of national-
level studies is that increasingly, in a globalized world,
national cultures are becoming highly heterogeneous, and
thus, multiple cultural perspectives can be found within
cultures (McCoy et al. 2005). Thus, applying national-level
cultural characteristics to predict an individual’s behavior
can result in inaccurate and misleading stereotyping and
can be too dichotomous (Triandis and Gelfand 1998).
For instance, a 2002 meta-analysis evaluating the con-
struct of individualism–collectivism across 82 studies
compared cross-national and within-United States studies
of individualism–collectivism and found that the Japanese
sample scored significantly lower on collectivism than the
U.S. sample did and that the Korean sample was not dif-
ferent from the U.S. sample (Oyserman et al. 2002). This,
of course, is consistent with Hofstede’s (1984, 2001) caveat
that national cultural values may change over time; how-
ever, it calls into question the methodology of assuming
that nations have the same culture now as they did 40 years
ago when Hofstede characterized them. Oyserman et al.’s
(2002) meta-analysis demonstrated a between-group effect
(for the U.S. samples) for ethnicity on individualism, with
Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 387
123
European Americans the most individualistic; however, the
effect was present only in comparison with Asian Ameri-
can groups and that effect was small. Similarly, recent
research demonstrates that individuals hold nationally
espoused cultural values to vastly different degrees, and
thus, the individual level of measurement of analysis is
more accurate and appropriate (Srite and Karahanna 2006).
Importantly, using individual-level cultural measures for
predicting individual behavior helps researchers avoid
ecological fallacies widely found in cultural research. That
is, per Hofstede (2002), country scores should not be used
to predict individual behavior. ‘‘Doing so is to commit
ecological fallacy, which assumes that one can validly use
ecological correlations (which apply to collective entities
such as groups) to substitute for individual correlations’’
(Srite and Karahanna 2006, p. 681). Subsequent research
shows that it is valid to study culture at the national,
organizational, and individual levels, but that the key is
using the proper level of measurement (Fischer et al. 2005).
Consequently, for this study, rather than use a 40-year-
old assessment of between-country differences on indi-
vidualism–collectivism or using respondents’ ethnicity as a
proxy for individualism–collectivism, we followed the
approach of many other researchers and measured indi-
vidualism and collectivism directly, at the individual level
(Earley 1989; McCoy et al. 2005; Srite and Karahanna
2006; Triandis and Gelfand 1998). This decision leads to
our second and last research question:
RQ2 To what extent do individuals’ tendencies toward
collectivism or individualism predict individuals’ propen-
sity to commit CA in the workplace?
Theoretic Model and Hypotheses
The thrust of the theoretic work in ethics-based outcomes has
focused primarily on the decision-making process, with less
focus on how dispositions and traits affect the outcomes. One
notable exception to this gap was a study by Winter et al.
(2004) that reviewed IT ethics in terms of Machiavellianism
and ethical idealism and found that those who lean toward
Machiavellianism were more likely to violate intellectual
property and privacy rights than those with ethical idealism.
However, a more prominent and accepted theoretic per-
spective is a body of theory and research that shows that an
individual’s disposition toward a moral philosophy based on
deontological or teleological evaluation maps directly to
one’s ethical dispositions toward formalism and utilitarian-
ism, respectively (Brady and Dunn 1995; Brady and Wheeler
1996; Hunt and Vitell 1986; Schminke et al. 1997). Yet this
well-accepted theoretic approach has not been applied in a
CA context. We do so here.
When employees commit CA in the workplace, they
knowingly violate implicit or explicit ethical rules of
conduct. Ethics can be defined ‘‘as an inquiry into the
nature and grounds of morality where morality is taken to
mean moral judgments, standards, and rules of conduct’’
(Thong and Yap 1998, p. 215). Accordingly, we follow the
standard raised by other computer-based ethics studies in
conducting research based on moral philosophies (e.g.,
Gattiker and Kelley 1999; Thong and Yap 1998). The use
of moral philosophies can provide a systematic perspective
for assessing the ethical appropriateness of individual
behavior, also called normative ethics theory (Thong and
Yap 1998).
Our theoretic model builds on Thong and Yap’s (1998)
ethical decision-making model, which is based on Hunt and
Vitell’s ethical decision-making theory (1986). Thong and
Yap (1998) describe a theory of ethical decision making in
a systems context that accounts for deontological and tel-
eological evaluations. A key assumption in their model is
that before people can perform either evaluation, they must
first recognize the situation as an ethical problem. Once a
person perceives an ethical problem, he or she then enga-
ges in a process of ethical evaluation, which is either
deontological or teleological. This evaluation determines
the basis of their ethical judgment, which predicts moral
intention and, ultimately, moral behavior. They also pro-
pose that various situational factors can directly impact
moral intention, which then impacts moral behavior.
Normative ethics theory is typically discussed in two
categories: theories that are rules based, or deontological,
and theories that are consequences based, or teleological
(Thong and Yap 1998). These are not just theoretic per-
spectives, but perspectives that individuals choose implic-
itly when engaging in ethical reasoning (Brady and
Wheeler 1996; Hunt and Vitell 1986). Thong and Yap
(1998) explain that the key distinction of a deontological
perspective is the theory or belief that there are universal
rules guiding right and wrong. As long as an individual can
clearly interpret the rules based on religion, intuition, or
esthetic belief, his or her action in any given situation is
‘‘predefined, without reference to possible consequences’’
(Thong and Yap 1998, p. 216). Also, ‘‘fundamental to the
deontological perspective is the fundamental rightness of
the behavior. No action can be considered right in accor-
dance with personal duty if it disregards the ultimate worth
of another human being’’ (Thong and Yap 1998, p. 216). A
formalistic perspective is typical in deontological per-
spectives (see the next section).
Conversely, a teleological perspective of ethical issues
determines whether an action is right or wrong depending
on the social consequences of the action (Brady and
Wheeler 1996; Thong and Yap 1998). Consequently, a
universal set of principles is not followed, and what should
388 P. B. Lowry et al.
123
be done depends on a calculation of the likely outcome of a
given situation. A utilitarian perspective is typical in tele-
ological evaluation, ‘‘which emphasizes creating the max-
imum benefits for the largest number of people, while
incurring the least amount of damages. A social cost-ben-
efit analysis is carried out and, if the net result is positive,
then the act is considered morally acceptable’’ (Thong and
Yap 1998, p. 216).
To propose testable hypotheses, we simplify the Thong
and Yap (1998) model by eliminating all the intermediary
processes of evaluation, judgment, and intention. Instead,
we focus on the direct connection between our independent
variables (IVs) and actual confessed CA behaviors because
actual behaviors are often much more salient than inten-
tions (Sutton 1998). We propose our hypotheses for for-
malism and utilitarianism, followed by those for
collectivism and individualism.
Predictions for CA Based on Ethical Formalism
and Utilitarianism
In congruence with Thong and Yap’s (1998) model, we
also assume that people perform either deontological or
teleological evaluations in making ethical decisions on
whether to commit CA. We also concur that social norms
toward deontological and teleological viewpoints signifi-
cantly influence both deontological and teleological eval-
uation. The literature indicates that people have various
predispositions toward how they make ethical evaluations
(Brady and Dunn 1995; Brady and Wheeler 1996). We
likewise argue that the strength of individuals’ dispositions
toward a given moral philosophy is likely to bias the degree
to which they will use a given philosophy to inform their
ethical judgments.
Our predictions address the kinds of ethical dispositions
likely to affect deontological and teleological evaluations.
Although the actual ethical evaluation is difficult to
observe, an individual’s disposition toward a particular
evaluation style is easy to capture through self-report and
can thus be used for prediction. Although the literature has
multiple terms for dispositions that map to deontological
and teleological perspectives, these dispositions are often
grouped into two traditional types in the literature, which
we adopt in our paper (Brady and Dunn 1995; Brady and
Wheeler 1996; Hunt and Vitell 1986; Schminke et al.
1997): (1) formalism 2
and (2) utilitarianism. 3
Both ethical
dispositions have been explicitly defined and measured in
the literature as independent subdimensions (Brady and
Dunn 1995; Brady and Wheeler 1996; Schminke et al.
1997; Schminke and Wells 1999). Therefore, our predic-
tions assume that the degree to which individuals lean
toward formalism positively increases the likelihood that
they will engage in deontological evaluation, and the
degree to which individuals lean toward utilitarianism
positively increases the likelihood that they will engage in
teleological evaluation.
We argue that because ethical formalism relies on uni-
versal principles of a belief in inherently right and wrong
behaviors, this philosophy will be more effective in pre-
venting new and ambiguous opportunities to commit CA.
That is, if a potential CA act feels even partially wrong, it
would typically be considered wrong. Hence, someone
with this perspective is more likely to consider an ambig-
uously wrong (or clearly wrong) opportunity to commit CA
(e.g., snoop data) as wrong and, therefore, will not engage
in the deviant activity. This perspective is important
because there are many ambiguities and complexities
involved with computer use and CA (Calluzzo and Cante
2004; Gattiker and Kelley 1999; Posey et al. 2011; Sproull
and Kiesler 1991).
H1 Ethical formalism will be associated with decreased
individual CA.
In contrast, the weakness of a utilitarian perspective in
thwarting CA is that for new or ambiguous ethical dilem-
mas, it can be quite difficult to calculate social costs
effectively. CA and computer use dilemmas are often
ambiguous, making it difficult for people to assess potential
harm in these situations (Calluzzo and Cante 2004; Gatti-
ker and Kelley 1999; Posey et al. 2011; Sproull and Kiesler
1991). A utilitarian perspective in the context of CA can
result in the incorrect determination that ‘‘victimless
abuse’’ has occurred and that the abuse is okay. Con-
versely, if one engages in a teleological evaluation, one is
still likely to recognize a potential ethical issue (Thong and
Yap 1998). Thus, a utilitarian viewpoint will result in
decreased CA, but not as strongly as a formalistic
viewpoint.
H2 Ethical utilitarianism will be associated with
decreased individual CA.
H3 The decrease in individual CA from ethical formal-
ism will be greater than the decrease in individual CA from
ethical utilitarianism.
2 Formalism refers to individuals with a disposition to make ethical
decisions from a deontological (rules-based) point of view, and thus
they determine whether actions are either ethical or unethical based
on a set of predetermined rules (Brady and Wheeler 1996; Schminke
et al. 1997).
3 Utilitarianism refers to individuals with a disposition to make
ethical decisions from a teleological (outcome-based) point of view,
meaning they make ethical decisions based on a cost–benefit analysis
to maximize the positive outcomes (Brady and Wheeler 1996;
Schminke et al. 1997).
Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 389
123
Predictions for CA Based on Individual-Level
Collectivism and Individualism
Thong and Yap (1998) propose that other factors can
directly affect moral intention, which then influences moral
behavior. Again, we believe a critical factor to consider in
a CA context is culture, 4
especially one’s characteristics
regarding individualism and collectivism. 5
Culture is a
particularly important consideration given the increased
globalization and diversity in the workplace. In our case,
we are primarily concerned about individual-level culture
as opposed to cultural behaviors that are shared with a fixed
group or nation. Because of the high relevance to decision
making, individualism and collectivism are the most
studied and common cultural elements in the IS/IT litera-
ture (Shin et al. 2007). Importantly, initial evidence sug-
gests these dimensions are highly relevant to ethical
decision making (Husted and Allen 2008).
We use the individual-level characteristics of these
cultural inclinations (Oyserman et al. 2002; Srite and Ka-
rahanna 2006). Thus, in referring to individualism in this
paper, we refer to the degree to which one’s individual
characteristics exhibit individualistic values. Likewise,
collectivism refers to the degree to which one’s individual
characteristics exhibit collectivistic values.
It has been argued that ‘‘ethical decision making is
affected by individualism and collectivism because they
deal with beliefs about the priority of individual versus
group interests’’ (Husted and Allen 2008, p. 294). A recent
meta-analysis indicated that differences between individ-
ualism and collectivism do indeed impact one’s values
(Oyserman and Lee 2008). Husted and Allen (2008)
emphasize that the ethical connections with individualism
are uniqueness and independence, whereas the ethical
connections with collectivism are based on ‘‘duty to the in-
group and, in cross-national contexts, maintenance of
harmony’’ where the in-group refers to ‘‘a group of people
sharing similar beliefs and interests and which typically
excludes outsiders (Chen and Li 2005),’’ as cited in Husted
and Allen (2008, p. 295). Similarly, Oyserman (2006)
shows that individualists are decontextualized and inde-
pendent of others, whereas collectivists are prone to exhibit
more restraint in their expression. As a result of these
differences, individualists are seen as more self-serving
than collectivists (Tavakoli et al. 2003) and tend to not
work as well with people as do collectivists (Chen and Li
2005). Namely, ‘‘people who emphasize group goals over
individual goals resolve conflicts and optimize benefits in
very different ways than people who emphasize individual
goals’’ (Husted and Allen 2008, p. 295). Thus, collectivists
tend to consider others, group goals, and organizational
goals more than individualists.
Given these basic differences, we predict that one’s
degree of individualism and collectivism directly impacts
moral intention. We also predict that because individualists
as a whole are more self-serving and less reserved in their
behavior and expression, they are more likely to engage in
unethical behaviors than collectivists. To clarify, self-
serving does not equate to being stupid or careless. A
person who is a strong individualist and who understands
the potential behavior is unethical and has potential dire
consequences will not likely engage in the behavior for the
sake of self-preservation or self-interest. However, we
predict individualists are more likely to engage in unethical
behavior than a strong collectivist if they believe they are
in an ethically gray area, see the benefits as being greater
than the costs to self, and can get away with it. As sup-
ported, these gray areas of high ambiguity are pervasive in
computer use and CA scenarios (Calluzzo and Cante 2004;
Gattiker and Kelley 1999; Posey et al. 2011; Sproull and
Kiesler 1991).
H4 An individual’s increased tendency toward individu-
alism will be associated with increased incidents of the
individual committing CA.
H5 An individual’s increased tendency toward collec-
tivism will be associated with decreased incidents of the
individual committing CA.
Finally, we explore possible moderation relationships in
our model. In H5, we predicted that an individual’s pro-
pensity toward collectivism should be associated with
decreased CA. In H1 and H2, we predicted the same for
formalism and utilitarianism, respectively. Thus, three
factors decrease CA: formalism, utilitarianism, and col-
lectivism. We thus wonder what happens when formalism
and collectivism interact, and when utilitarianism and
collectivism interact. Because these are all in the same
predicted direction, we have reason to suspect that col-
lectivism could play a strong positive moderation role in
the model.
H6 Collectivism acts as a moderator that strengthens the
negative relationship between formalism and individual
CA.
H7 Collectivism acts as a moderator that strengthens the
negative relationship between utilitarianism and individual
CA.
4 Culture is ‘‘a system of implicit and explicit beliefs, values, norms,
preferences, and behaviors that are stable over time’’ (Zhang and
Lowry 2008, p. 64). 5
Traditionally, on a national level, individualism describes cultures
‘‘in which the ties between individuals are loose,’’ and collectivism
describes cultures ‘‘in which people are integrated into strong,
cohesive groups that protect individuals in exchange for unquestion-
ing loyalty’’ (Hofstede 1991; Zhang and Lowry 2008, p. 65).
390 P. B. Lowry et al.
123
Research Methods
Data Collection
We used an anonymous online panel composed of 449 full-
time employees from the banking, financial, and insurance
industries to obtain data for testing our research model.
Survey items were presented in a randomized fashion to
assist in reducing possible common method biases (Pod-
sakoff et al. 2003). For the survey administration, we used
SurveyMonkey, a third-party, online survey administration
and market research company. SurveyMonkey has an
international database of millions of pre-qualified potential
respondents who work directly in various business fields,
allowing us to reach a large sample of interest. These
respondents are compensated directly by SurveyMonkey.
Collecting data over the Internet via an organization like
SurveyMonkey offers particular advantages as well as
challenges (Fraley 2007). The primary challenge is ensur-
ing that a representative sample matching the needs of the
study is attained. We met this challenge by using a panel
provider that has market research expertise and a huge set
of pre-qualified candidates. We were thus able to target
directly only those who met our demographic needs, and
we used automatic filters to capture our sample population
of interest (Fraley 2007). Panel participation was restricted
to those over 18 years of age who were employed full time
in the financial, banking, and/or insurance or related
industries in the United States. All respondents also had to
use their organization’s computer systems in fulfilling their
daily work.
One clear advantage is that data collected over the Internet
via a panel of respondents is more reflective of the broader
population than data collected in more restricted settings
(e.g., college classroom, college alumni, one organization)
(Birnbaum 2004; Fraley 2007). Moreover, the Internet panel
allows researchers examining topics of a sensitive nature
(e.g., internal CA) to receive responses less inhibited by
social desirability effects as anonymity is ensured (Bennett
and Robinson 2000; Posey et al. 2011). Online panelists were
guaranteed that their identities would not be released by
SurveyMonkey to the researchers, thus protecting the pan-
elists from any repercussions from their organizations from
the reported CA incidents. Table 1 summarizes several key
demographic data points from these respondents.
This study was approved by the appropriate institutional
review board for human subject studies and was fully
performed in accordance with the related established
ethical standards. All participants in the pilot study and
the online panel study gave informed consent before being
included in the study. All data were also gathered
under true anonymity and were analyzed at the aggregate
level only.
Construct Measurement
The IVs used in this study included degree of ethical for-
malism, degree of ethical utilitarianism, degree of collectiv-
ism, and degree of individualism. The dependent variable
(DV) used in this study was personal CA. Four covariates were
also used: computer experience, level of education, age, and
income. Responses were captured on a seven-point Likert-
type scale with anchors ranging from never to very frequently.
Appendix 1 details the measurement items. In addition to
similar items directly adapted from the literature, a pretest and
pilot test on the items were performed, using specific guide-
lines (Boudreau et al. 2001; Straub 1989). For the pretest, eight
faculty members and doctoral students from a large South-
eastern university and one faculty member from a large
Midwestern university analyzed the survey instrument for
content validity. Following the review, appropriate changes
were made to the survey instrument, after which the pilot test
was conducted. A pilot test was conducted using our instru-
ment with a large bank in the Southwestern United States. In
all, 47 employees responded to the Web-based survey for an
approximate response rate of 19 % over a period of 1 month.
The results from the pilot test suggested only minor changes to
item wording.
Analysis and Results
We first conducted extensive pre-analysis and data vali-
dation with partial least-squares regression (PLS)—a form
of structural equation modeling—for four purposes: (1) to
establish the factorial validity of the measures through
convergent and discriminant validity, (2) to establish that
multicollinearity was not a problem with any of the mea-
sures, (3) to check for common methods bias, as estab-
lished in Liang et al. (2007), and (4) to establish strong
internal consistencies.
Factorial validity for reflective constructs is established
by establishing convergent validity 6
and discriminant
validity, 7
two highly interrelated concepts that must coexist.
To establish the factorial validity of our reflective constructs,
we followed procedures by Gefen and Straub (2005)
and Kock (2010), and further demonstrated in Lowry et al.
6 Convergent validity is the basic idea that measurement items that
should be related are related. It is established ‘‘when items thought to
reflect a construct converge, or show significant, high correlations
with one another, particularly when compared to the convergence of
items relevant to other constructs, irrespective of method’’ (Straub
et al. 2004, p. 391). 7
Discriminant validity is the idea that items that should not be
related are in fact not related. It can be established when items
thought to diverge show insignificant, low correlations with one
another, particularly when compared to items in other constructs
(Straub et al. 2004).
Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 391
123
(2008, 2009). For an especially conservative analysis, we
used two established techniques to assess convergent and
discriminant validity.
First, we examined the outer model loadings. Following
Gefen and Straub (2005), convergent validity can be established
when the t-values are significant and the outer model loadings
are large. All items were significant; however, three collectivism
items had substantial order of magnitude lower weights. Thus,
these were dropped to increase validity. See Table A2.1 in
Appendix 2 in the electronic supplementary material.
Second, we correlated the latent variable scores against
the indicators as a form of factor loadings and then
examined the indicator loadings and cross-loadings to
establish convergent validity through confirmatory factor
analysis inherent in SEM. Though this approach is typi-
cally used to establish discriminant validity (Gefen and
Straub 2005), convergent validity and discriminant validity
are inter-dependent and help establish each other (Straub
et al. 2004). Thus, following (Kock 2010), convergent
validity is also established when each loading for a latent
variable is substantially higher than those for other latent
variables. All items converged as expected within each
latent variable, and thus, no items were dropped. See Table
A2.2 in the electronic supplementary material.
We also used two approaches to establish discriminant
validity, as described in Gefen and Straub (2005) and
demonstrated in Lowry et al. (2008, 2009). First, as with
convergent validity, we examined the factor loadings, but
this time to ensure significant overlap did not exist between
the constructs. No latent variables overlapped (again see
Table A2.2 in the electronic supplementary material).
Second, we used examined the square roots of the average
variances extracted (AVEs) described in Gefen and Straub
(2005) compared to the correlations of the latent variables. 8
Table 1 Sample demographics (N = 449)
# % # %
Age Computer use (in an average workday)
Between 20 and 24 3 0.7 Less than 45 % 33 7.3
Between 25 and 29 25 5.6 Between 45 and 54 % 27 6.0
Between 30 and 34 32 7.1 Between 55 and 64 % 17 3.8
Between 35 and 39 54 12.0 Between 65 and 74 % 48 10.7
Between 40 and 44 59 13.1 Between 75 and 84 % 69 15.4
Between 45 and 49 67 14.9 Between 85 and 94 % 98 21.8
Between 50 and 54 70 15.6 Greater than 95 % 157 35.0
Between 55 and 59 81 18.0 Organization size
Between 60 and 64 42 9.4 Small organization—1–100 computers 111 24.7
Older than 65 16 3.6 Medium organization—100–1,000 computers 66 14.7
Gender Large organization—1,000–10,000 computers 100 22.2
Female 270 60.1 Very large organization—more than 10,000 computers 167 37.2
Male 179 39.9 Not reported 5 1.1
Income Manager
Less than $25,000 23 5.1 Yes 153 34.1
Between $25,000 and $49,999 144 32.1 No 296 65.9
Between $50,000 and $74,999 116 25.8 IS/IT employee?
Between $75,000 and $99,999 73 16.3 Yes 59 13.1
Between $100,000 and $124,999 51 11.4 No 387 86.2
Greater than $125,000 38 8.5 Industry
Not reported 4 0.92 Banking 112 25.0
Education Financial services 87 19.4
High school 46 10.2 Insurance 146 32.5
Some college 143 31.9 Other financial 104 23.2
Undergraduate degree 188 41.9
Master’s degree 58 12.9
Doctorate/professional degree 13 2.9
Not reported 1 0.2
8 The basic standard followed here is that the square root of the AVE
for any given construct (latent variable) should be higher than any of
the correlations involving the construct (Fornell and Larcker 1981;
Staples et al. 1999).
392 P. B. Lowry et al.
123
Strong discriminant validity was shown for all subcon-
structs. All of the AVE thresholds were met. We combined
these results with the measurement model statistics, as
shown in Table 2. In Table 2, the AVEs are shown in the
diagonal for each construct (bold and underlined).
Aside from factorial validity, the biggest potential issue
that must be addressed in SEM is multicollinearity (Cenfe-
telli and Bassellier 2009). We thus assessed the possibility of
multicollinearity among all the indicators in the model.
Variance inflation factors (VIFs) less than 10 are tradition-
ally viewed as justification for a model’s lack of multicol-
linearity, with 5.0 being ideal for reflective constructs, but
some methodologists have recently called for a more strin-
gent cutoff of less than 3.3 to be used (Cenfetelli and Bas-
sellier 2009; Diamantopoulos and Siguaw 2006; Petter et al.
2007). Very low multicollinearity was seen among all of the
latent variables, with the highest value 1.352. We thus con-
clude that multicollinearity was not a threat to our study.
To diminish the likelihood of common methods bias
occurring in our data collection, we randomized items
within the instrument so that participants would be less apt
to detect underlying constructs, a potential source of
common method bias (Cook and Campbell 1979; Straub
et al. 2004). However, all data were collected using a
similar-looking online survey; thus, we tested for common
method bias to establish that it is not a likely negative
factor in the data remaining for our analysis. To do so, we
used three approaches of increasing validity and rigor.
The first approach was the Harmon’s factor test, which
is increasingly in dispute (Podsakoff et al. 2003). This was
analyzed by conducting an unrotated factor analysis and
determining how many factors exist in the model. A total
of 26 factors were created, with the largest factor only
accounting for 24.48 % of the variance, indicating mono-
method bias was unlikely.
The second approach was to simply examine a corre-
lation matrix of the constructs and to determine if any of
the correlations were above 0.90, which is evidence that
common methods bias may exist (Pavlou et al. 2007).
These correlations are observed in the measurement model
statistics in Table 2—all of which are far below the 0.90
threshold.
Our third and most rigorous approach to testing common
method bias was to conduct an extensive form of testing for
mono-method bias for PLS, as established in Liang et al.
(2007). This approach was suggested by Podsakoff et al.
(2003) who criticize simpler approaches. The objective of
this technique is to measure the influence of a common latent
method factor on each individual indicator in the model
versus the influence of each indicator’s corresponding con-
struct. 9
This analysis indicated the average substantive factor
loading was 0.736 and the average variance explained for the
substantive factor loading was 54.14 %. The average method
factor loading was 0.000, and the average variance explained
for the method factor loading was 1.07 %—making a ratio of
more than 50:1. Finally, most of the relationships between
the items and the method bias construct were insignificant,
whereas all of the relationships between the items and their
corresponding latent variables were highly significant. We
thus conclude that method-based variance is not a concern
for this study. See Table A2.3 in the electronic supplemen-
tary material for more details.
As a product of our rigorous pre-analysis, all of our
reflective subconstructs exhibited high levels of internal
consistency. 10
To establish this consistency, PLS computes
a composite reliability score as part of the integrated model
analysis. This score is a more accurate measurement of
internal consistency than Cronbach’s alpha because it does
not assume the loadings or error terms of the items to be
equal (Chin et al. 2003). However, as a conservative check,
Table 2 Results of AVE analysis and measurement model statistics
Latent variable Mean SD (1) (2) (3) (4) (5)
Formalism (1) 6.39 0.55 0.721
Utilitarianism (2) 5.56 0.74 0.506** 0.740
Individualism (3) 3.92 1.16 (-0.029)(n/s) 0.308** 0.780
Collectivism (4) 5.45 0.85 0.471** 0.408** 0.045(n/s) 0.762
CA (5) 5.56 1.77 -0.228** -0.183** 0.052(n/s) -0.257** 0.695
n/s non-significant
*** p \ 0.001, ** p \ 0.01, * p \ 0.05
9 To do this in PLS, constructs of the theoretic model and their
relationships are modeled as is normally conducted with two major
additions: (1) A single-indicator construct is created for each indicator
in the measurement model. Each subconstruct is then linked to each
of the single-indicator constructs that comprise the subconstruct. This
effectively makes each subconstruct in the model a second-order
reflective construct. (2) A construct representing the method is
created, reflectively composed of all indicators of the instrument. The
method construct (the latent method factor) is then linked to each
single-item construct. 10
Reliability refers to the degree to which a scale yields consistent
and stable measures over time (Straub 1989). Because of the nature of
formative measures, reliability checks cannot be reasonably made for
formative measures (Diamantopoulos and Winklhofer 2001). How-
ever, reliabilities of first-order reflective constructs that make up
second-order constructs can be established individually.
Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 393
123
Cronbach’s alpha can also be used as a basis of comparison
(Fornell and Larcker 1981; Kock 2010; Nunnally and
Bernstein 1994). We thus applied the two most conserva-
tive criteria to establish consistency of our reflective sub-
constructs: The composite reliability and the Cronbach’s
alpha coefficients should be C0.70 (Fornell and Larcker
1981; Kock 2010; Nunnally and Bernstein 1994). Table 3
summarizes the computed internal consistency values, all
of which are strong.
Summarizing this section, our pre-analyses show that
our data exhibit strong factorial validity of the reflective
and formative constructs, little multicollinearity, strong
reliabilities, and that they lack mono-method bias. The
results of our validation procedures show that our model
data meet or exceed the rigorous validation standards
expected in SEM analysis (Straub et al. 2004)—particu-
larly for PLS analysis for reflective constructs (Cenfetelli
and Bassellier 2009; Diamantopoulos and Siguaw 2006;
Gefen and Straub 2005; Petter et al. 2007).
Again, we used PLS regression, using SmartPLS version
2.0 (Ringle et al. 2005) for model analysis because PLS is
especially adept at validating preliminary prediction-based
models and is thus is more appropriate than covariance-
based SEM techniques such as LISREL or AMOS (Chin
et al. 1996, 2003; Gefen and Straub 2005). In addition, PLS
does not require data with normal distributions (as do
covariance-based SEM techniques), which is important with
our data because many respondents will not have committed
CA. To do so, we generated a bootstrap with 600 resamples.
Given our rigorous background analysis, we finalized our
tested model. Table 4 summarizes the hypotheses, path
coefficients, and p-values for the hypotheses.
The one hypothesis that could not be fully tested with PLS
analysis was H3, which hypothesized that the decrease in
individual CA from ethical formalism would be greater than
the decrease in individual CA from ethical utilitarianism. In
visually examining the b’s of these relationships—before and after moderation is added to the model—it is clear that
meaningful differences do exist as predicted by H3. To test
this observation statistically, we followed Chin et al. (2003) to
perform a pseudo F-test. 11
Comparing these paths for the
model before moderators were added resulted in an F-statistic
of 60.92 (p \ 0.001); adding the moderator resulted in an F- statistic of 491.91 (p \ 0.001). We thus conclude that H3 is strongly supported.
Summary of Results
Summarizing the results, we found that before the collectiv-
ism moderator was added to the model, formalism was neg-
atively related to CA (H1 supported) and utilitarianism had no
relationship to CA (H2 not supported). However, after the
collectivism moderator was added, there was a large increase
in the negative relationship between formalism and CA (H1
more strongly supported); importantly, a large, significant
negative relationship between utilitarianism and CA emerged
(H2 supported). There is likely a meaningful effect in adding
collectivism as a moderator. Directly testing the moderation
relationships to the model, we found that collectivism
increased the strength of the negative relationships between
formalism and CA (H6 supported) and utilitarianism and CA
(H7 supported). We also found that formalism was associated
with a stronger decrease in CA than was utilitarianism—with
or without the collectivism moderator (H3 supported). We
found a positive relationship between individualism and CA
(H4 supported) and a negative relationship between collec-
tivism and CA (H5 supported). No significant relationships
were found with our exploratory covariates and CA.
In terms of descriptive analysis, 219 (48.8 %) of the
respondents in our sample confessed to having committed
at least one of our listed forms of CA in the workplace,
which is virtually the same rate from an earlier, unrelated
study (Hilton 2000). Finally, 359 (80.0 %) of the respon-
dents reported having observed at least one incident of CA
committed by another person at their workplace. These
statistics from full-time professionals in the financial ser-
vices industry pinpoint why CA should be of grave concern
to research and practice.
Contributions to Theory
Our primary theoretic contribution is that by using original
extensions based on the ethical dimensions of formalism–
utilitarianism and the individual cultural characteristics of
collectivism–individualism, we successfully extended
Thong and Yap’s (1998) ethical decision-making model for
predicting CA. This and other contributions are further
discussed in terms of the two research questions that gui-
ded our study.
Table 3 Latent variable internal consistencies
Latent
variable
Number of
items
Cronbach’s
alpha (a) Composite
reliability
Formalism 6 0.815 0.866
Utilitarianism 7 0.868 0.893
Collectivism 5 0.818 0.872
Individualism 3 0.765 0.819
CA 9 0.867 0.892
11 Per Chin et al. (2003), the pseudo F-test is obtained by first
calculating the effect size using the following formula: (path a - path
b)/(1 - path a). The pseudo F-statistic was then calculated by
multiplying the effect size by (n – k - 1), where n is the sample size
(449) and k is the number of independent variables (in this case 2,
because we are comparing two paths only).
394 P. B. Lowry et al.
123
RQ1 In what way do individuals’ ethical tendencies
toward formalism or utilitarianism predict the individuals’
propensity to commit CA in the workplace?
Our hypotheses were largely supported. The results give
preliminary support to our theoretic extensions of Thong
and Yap’s (1998) ethical decision-making model. To
simplify the operationalization of the theory, and because
we were using survey data based on actual confessed
events, we tested the direct association between formalism
and utilitarianism and moral behavior. To test the gener-
alizability and applicability of the extensions, we used the
two major forms of ethical tendencies that are especially
relevant in the workplace today.
Our first theoretic extension proposed that an individ-
ual’s propensity toward ethical formalism or utilitarianism
would directly affect whether one chooses deontological or
teleological evaluation, which then directly affects one’s
ethical judgment, moral intention, and, ultimately, moral
behavior. We showed a stronger relationship in decreased
CA from a formalism perspective than from a utilitarianism
perspective.
RQ2 To what extent do individuals’ tendencies toward
collectivism or individualism predict the individuals’ pro-
pensity to commit CA in the workplace?
Our second theoretic extension proposed that key situ-
ational factors capable of directly impacting moral inten-
tion are an employee’s cultural tendencies. Given today’s
increasingly global and heterogeneous workforce, these
tendencies are increasingly relevant. We specifically
examined individual tendencies toward individualism or
collectivism, and we showed that collectivism is associated
with decreased CA, and individualism was associated with
increased CA. Collectivism acted to further strengthen the
relationships between formalism and utilitarianism with
CA. Thus, an employee who is strong in collectivism and
formalism is the one least likely to commit CA. These
results make sense as people who are oriented toward
collectivism tend to emphasize sociability and common
goals with others (Husted and Allen 2008; Triandis and
Gelfand 1998). People who are oriented toward individu-
alism tend to be status-oriented, competitive with others,
and anxious to distinguish themselves from others (Chen
and Li 2005; Husted and Allen 2008; Triandis and Gelfand
1998).
In all, our extensions and empirical testing support the
notions that one’s ethical dispositions likely have an impact
on actual ethical behavior, including the detrimental
activity of CA.
Applying Results in Practice
Promoting Formalism in Organizations
We now suggest how these findings can be applied in
practice. First, as mentioned, one of the particularly trou-
bling issues with CA is that it is often ambiguous, and
employees frequently do not understand the potential
Table 4 Results of hypotheses testing with PLS
Hypothesis/path Beta coefficient (b) t-statistic from PLS (n = 449) Supported?
Direct path results for H1, H2, H4, and H5 before collectivism moderator was added to model
H1. Formalism ? (–) CA (-0.180) 2.56* Yes
H2. Utilitarianism ? (–) CA (-0.068) 1.52(n/s) No
H4. Individualism ? CA 0.108 3.40*** Yes
H5. Collectivism ? (–) (-0.175) 2.05* Yes
Results after collectivism moderator was added to model:
H1. Formalism ? (–) CA (-0.728) 4.08*** Yes
H2. Utilitarianism ? (–) CA (-0.428) 2.38* Yes
H4. Individualism ? CA 0.105 2.16* Yes
H5. Collectivism ? (–) CA (-1.767) 5.63*** Yes
H6. Collectivism X formalism ? CA 1.540 3.83*** Yes
H7. Collectivism X utilitarianism ? CA 0.642 2.34* Yes
Covariates of CA:
Computer experience ? CA (-0.066) 1.46(n/s) No
Education ? CA (-0.024) 0.53(n/s) No
Income ? CA (-0.040) 0.81(n/s) No
Age ? CA (-0.024) 0.51(n/s) No
n/s non-significant
*** p \ 0.001, ** p \ 0.01, * p \ 0.05
Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 395
123
negative ramifications of CA (Calluzzo and Cante 2004).
(This may partially explain why nearly half of the
employees in our study confessed to committing CA.)
Thus, providing training on CA’s implications would be an
important first step in any organization (Calluzzo and
Cante 2004; Cohen and Cornwell 1989).
Based on the ethics literature, we posit that the key to
promoting formalism is to provide formal training on eth-
ical decision making and moral reasoning related to IT use
(Calluzzo and Cante 2004; Cohen and Cornwell 1989;
Davison et al. 2009; Harrington 1996; Leonard and Cronan
2001; Leonard et al. 2004; Loch and Conger 1995; Myyry
et al. 2009; Smith and Hasnas 1999). This kind of training
requires employers to provide explicit examples that
encompass the wide range of behaviors they wish to avoid.
If explicit examples are not provided and discussed, man-
agers cannot assume that their employees understand what
an acceptable behavior is. Moreover, managers should not
expect ethical discussions and the associated underlying
principles on one behavior (e.g., the proper use of email) to
naturally transfer to the employees’ appropriate engage-
ment in another activity (e.g., the proper use of instant
messaging). Preliminary research shows that teaching
about unethical IS/IT practices can be effective in shifting
attitudes against such abuses (Cohen and Cornwell 1989).
Because the decision-making process can depend on the
ethical situation itself, Haines and Leonard (2007) suggest
that training efforts should focus not only on outcomes but
also on the ethical decision-making process of recognizing
the importance of IT ethical abuse, judging something to be
wrong, feeling an obligation to do something, and then
doing something about the violation.
Most recently, Chatterjee et al. (2009) provided a criti-
cal ethical perspective on IS development, suggesting that
IS failure could be avoided by focusing on ethics and moral
responsibility in the IT project development process. They
provide useful suggestions for how the focus on morals and
ethics can be better integrated into such projects and even
taught to students. We believe their suggestions apply well
to CA prevention. Likewise, Culnan and Williams (2009)
suggest how formal training in ethical decision making can
help curb the rampant privacy abuses within organizations.
Research has also shown that the design of an organi-
zation can have a strong effect on ethical decision making
within an organization (Jones and Ryan 1997); these con-
cepts could be extended to help prevent CA. For example,
organizations need to be careful about the leadership style
and incentives they provide as these can directly affect
whether employees embrace a more formalistic or utili-
tarian viewpoint in their work. Schminke and Wells (1999)
showed that ‘‘groups exert a powerful influence on indi-
viduals’ ethical frameworks, and that the patterns of these
influences differ depending on the type of ethical
framework involved. Individuals’ ethical utilitarianism [is]
affected by both leadership style and group cohesiveness.
Ethical formalism [is] most affected by the leadership style
in the group’’ (p. 367).
Promoting Collectivism in Organizations
We now turn to ways that individual-level collectivism can
be promoted within an organization. Our research shows
that employees in the financial services industry who have
more individualistic tendencies commit more CA than their
collectivist counterparts. What can realistically be done to
curb these individualistic cultural tendencies? Traditional
research on culture emphasizes the characteristics of col-
lectivism–individualism as something highly ingrained
within a person (e.g., Hofstede 1991). However, recent
research has shown that these tendencies can be manipu-
lated and primed in group and organizational settings.
Research has suggested that incentives provided within an
organization can encourage collectivistic behavior and dis-
courage individualistic behavior (Chen and Li 2005; Husted
and Allen 2008, p. 295; Voronov and Singer 2002). If an
organization wants individualistic behavior in its employees,
managers then need to manage people as individualists ‘‘based
upon individual skills’’ (Tavakoli et al. 2003, p. 52), which
would include an emphasis on rewarding individual behavior
(e.g., raises and bonuses based solely on individual perfor-
mance). This approach, for example, could also be structured
in preference for individualized emails for communication
over group instant-messaging chat. If an organization desires
collectivist behaviors, managers can lead employees as groups
and make employment- and promotion-related decisions
‘‘based upon group membership and group achievement’’
(Tavakoli et al. 2003, p. 52), which could be further enhanced
by group measurement and rewards (e.g., raises and bonuses
primarily based on group achievement). Aside from group
instant-messaging chat, collectivism could also be fostered by
other forms of collaborative technologies that promote shar-
ing, group awareness, group consensus building, group deci-
sion making, and group file exchange (e.g., Groove, Dropbox,
and Skype). These recommendations could also be transferred
to individual or group incentives and rewards based on the
occurrence (or lack thereof) of behaviors deemed detrimental
to the security of an organization’s IS.
As a promising recent development, a meta-analysis of
individualism–collectivism indicates that individuals’ pro-
pensities toward individualism–collectivism can be primed
in group settings (Oyserman and Lee 2008). This result is
particularly exciting because it allows interventions—often
of a simple nature—to be used in work groups and in the
workplace generally in ways that can prime the positive
aspects of collectivism in individuals to help prevent CA.
Three approaches can be used as this ‘‘primer’’ (Oyserman
396 P. B. Lowry et al.
123
and Lee 2008): (1) emphasizing ‘‘we’’ language to focus on
the collective itself; (2) focusing on specific salient aspects
of the collective, such as individual obligation to and
similarity with the group; (3) emphasizing integration or
connections to others, such as using the word ‘‘connect’’ to
describe interrelationships. This recent work further sup-
ports the previous argument that the collectivism–individ-
ualism dimensions are not inherent qualities of culture but
manifestations of attributes that arise according to a given
context (Husted and Allen 2008; Oyserman 2006; Oyser-
man et al. 2002; Torelli 2006).
Limitations and Future Research
A potential problem when surveying individuals about sen-
sitive topics such as CA is response distortion caused by the
respondents’ desire to provide socially desirable answers
(Cheng et al. 1997; Moores and Chang 2006). However, our
use of an Internet panel allows researchers examining topics of
a sensitive nature to receive responses less inhibited by social
desirability effects as anonymity is ensured (Bennett and
Robinson 2000; Posey et al. 2011). Online panelists were
guaranteed that their identities would not be released by
SurveyMonkey to the researchers, thus protecting the
respondents from repercussions from their organizations from
the reported CA incidents. Nonetheless, anonymity does not
guarantee that social desirability will not occur to some
degree. One way to potentially increase the accuracy of these
results is to use an indirect questioning method (Anderson
1978), which can help reduce socially desirable responding
(Fisher 1993). For example, this methodology requires the
rephrasing of measurement items from ‘‘I…’’ to ‘‘One or more of my co-workers…’’ or ‘‘Individuals in my work group…’’
Similar to individuals engaged in other ‘‘dark side variables’’
(Mick 1996), individuals committing CA may be more likely
to project their own socially undesirable activity to hide
behind others’ activity. The development of methods to more
accurately evoke confessions of CA would be a substantial
contribution to the research because many abuses may never
be discovered by other means. Anonymity remains one of the
more promising routes for achieving this goal.
Probably the most important limitation of this study is that
it is based on data from a survey. Consequently, the results
are not causal and do not lend themselves to providing causal
insights into the decision-making process of those commit-
ting CA. As noted, there are two approaches to studying
ethics in the literature: one based on dispositions and traits
and one based on the decision-making process (Haines and
Leonard 2007). We follow the former, which has been
addressed much less frequently in the IS/IT literature than
models based on the ethical decision-making process. Even
still, we argue that most of the IS research attempts involving
the ethical decision-making process examine outcomes at
one point in time and do not truly delve into the inner cog-
nitive processes involved in decision making. Future IS
research would be greatly benefited by two steps: first, by
creating a more comprehensive model that involves our
dispositional extensions of Thong and Yap’s (1998) model
along with extending their decision-making framework with
more recent IS decision-making models; second, by empir-
ically examining the ethics decision-making process rather
than just the outcome.
Appendix 1
See Table 5.
Table 5 Measurement items
Construct Items Notes
Formalism F1. Principled
F2. Dependable
F3. Trustworthy
F4. Honest
F5. Noted for integrity
F6. Law abiding
These were interspersed with the utilitarian items
and dummy items that were thrown out.
The following prompt preceded these items:
‘‘To what extent is each of the following
character traits important to you?’’ All items
from Schminke and Wells (1999)
Utilitarianism U1. Utilitarian
U2. Resourceful
U3. Effective
U4. Influential
U5. Results-oriented
U6. Productive
U7. A winner
See notes on formalism. All items from
Schminke and Wells (1999)
Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 397
123
References
Anderson, J. C. (1978). The validity of Haire’s shopping list
projective technique. Journal of Marketing Research, 15(4),
644–649.
Ariss, S. S. (2002). Computer monitoring: Benefits and pitfalls facing
management. Information & Management, 39(7), 553–558.
Bailey, W. J., & Spicer, A. (2007). When does national identity
matter? Convergence and divergence in international business
ethics. Academy of Management Journal, 50(6), 1462–1480.
Banerjee, D., Cronan, T. P., & Jones, T. M. (1998). Modeling IT
ethics: A study in situational ethics. MIS Quarterly, 22(1),
31–60.
Beekun, R. I., Hamdy, R., Westerman, J. W., & HassabElnaby, H. R.
(2008). An exploration of ethical decision-making processes in
the United States and Egypt. Journal of Business Ethics, 82(3),
587–605.
Bennett, R. J., & Robinson, S. L. (2000). Development of a measure
of workplace deviance. Journal of Applied Psychology, 85(3),
349–360.
Birnbaum, M. H. (2004). Human research and data collection via the
internet. Annual Reviews of Psychology, 55, 803–832.
Table 5 continued
Construct Items Notes
Computer
abuse
CA1. I have damaged computer property belonging to my
employer (e.g., hardware, software, data files, etc.)
CA2. I have deliberately bent or broken a computer-related
rule or policy
CA3. I have adjusted data in the computer system to make my
activity appear more in line with organizational computer
guidelines, policies, and/or rules
CA4. I have gone against management decisions regarding
what management deems appropriate computer system use
CA5. I have sabotaged portions of the computer system
CA6. I have intentionally made errors in the computer system
CA7. I have covered up mistakes in the computer system
CA8. I have taken computer system resources without proper
approval (e.g., hardware, software, data files)
CA9. I have misused my computer system access privilege(s)
The following prompt preceded these items: ‘‘Since the most
recent internal computer-system security policies,
procedures, and/or rules referred to above were implemented,
how often have you engaged in the activities listed below?’’
Items 1 and 2 are from Robinson and O’Leary-Kelly (1998).
Item 3 is from Jaworski and MacInnis (1989). Item 4 is from
Vardi (2001). Items 5 through 9 are from Robinson and
Bennett (1995)
Individualism I1. I would rather depend on myself than others*
I2. I rely on myself most of the time; I rarely rely on others*
I3. I often do ‘‘my own thing’’*
I4. My personal identity, independent of others, is very
important to me*
I5. It is important that I do my job better than others*
I6. Winning is everything
I7. Competition is the law of nature
I8. When another person does better than I do, I get tense and
aroused
All individualism items are from Triandis and Gelfand (1998)
Collectivism C1. If a coworker gets a prize, I would feel proud
C2. The well-being of my coworkers is important to me
C3. To me, pleasure is spending time with others
C4. I feel good when I cooperate with others
C5. Parents and children must stay together as much as
possible*
C6. It is my duty to take care of my family, even when I have
to sacrifice what I want*
C7. Family members should stick together, no matter what
sacrifices are required*
C8. It is important to me that I respect the decisions made by
my groups
All collectivism items are from Triandis and Gelfand (1998)
* Dropped to improve factorial validity
398 P. B. Lowry et al.
123
Boss, S. R., Kirsch, L. J., Angermeier, I., Shingler, R. A., & Boss, R.
W. (2009). If someone is watching, I’ll do what I’m asked:
Mandatoriness, control, and information security. European
Journal of Information Systems, 18(2), 151–164.
Boudreau, M. C., Gefen, D., & Straub, D. W. (2001). Validation in
information systems research: A state-of-the-art assessment. MIS
Quarterly, 25(1), 1–16.
Brady, F. N., & Dunn, C. P. (1995). Business meta-ethics: An analysis
of two theories. Business Ethics Quarterly, 3, 5.
Brady, F. N., & Wheeler, G. E. (1996). An empirical study of ethical
predispositions. Journal of Business Ethics, 15(9), 927–940.
Calluzzo, V. J., & Cante, C. J. (2004). Ethics in information
technology and software use. Journal of Business Ethics, 51(3),
301–312.
Cavusoglu, H., Raghunathan, S., & Cavusoglu, H. (2009). Configura-
tion of and interaction between information security technologies:
The case of firewalls and intrusion detection systems. Information
Systems Research, 20(2), 198–217.
Cenfetelli, R. T., & Bassellier, G. (2009). Interpretation of formative
measurement in information systems research. MIS Quarterly,
33(4), 689–707.
Chatterjee, S., Sarker, S., & Fuller, M. (2009). Ethical information
systems development: A Baumanian postmodernist perspective.
Journal of the Association for Information Systems, 10(11),
787–815.
Chen, X. P., & Li, S. (2005). Cross-national differences in cooper-
ative decision-making in mixed-motive business contexts: The
mediating effect of vertical and horizontal individualism.
Journal of International Business Studies, 36, 622–636.
Cheng, H. K., Sims, R. R., & Teegen, H. (1997). To purchase or to
pirate software: An empirical study. Journal of Management
Information Systems, 13(4), 49–60.
Chin, W. W., Marcolin, B. L., & Newsted, P. R. (1996, December
16–18). A partial least squares latent variable modeling
approach for measuring interaction effects: Results from a
Monte Carlo simulation study and voice mail emotion/adoption
study. Paper presented at the 17th International conference on
information systems, Cleveland, OH, USA.
Chin, W., Marcolin, B., & Newsted, P. (2003). A partial least squares
latent variable modeling approach for measuring interaction
effects: Results from a Monte Carlo simulation study and an
electronic mail emotion/adoption study. Information Systems
Research, 14(2), 189–217.
Cohen, E., & Cornwell, L. (1989). A question of ethics: Developing
information system ethics. Journal of Business Ethics, 8(6),
431–437.
Cook, T. D., & Campbell, D. T. (1979). Quasi-experimentation:
Design and analysis for field settings. Chicago: Rand McNally.
Culnan, M., & Williams, C. (2009). How ethics can enhance
organizational privacy: Lessons from the ChoicePoint and TJX
data breaches. MIS Quarterly, 33(4), 673–686.
D’Arcy, J., & Hovav, A. (2007). Deterring internal information
systems misuse. Communications of the ACM, 50(10), 113–117.
D’Arcy, J., Hovav, A., & Galletta, D. F. (2009). User awareness of
security countermeasures and its impact on information systems
misuse: A deterrence approach. Information Systems Research,
20(1), 79–98.
Davison, R. M., Martinsons, M. G., Ou, C. X. J., Murata, K.,
Drummond, D., Li, Y., et al. (2009). The ethics of IT
professionals in Japan and China. Journal of the Association
for Information Systems, 10(11), 834–859.
Diamantopoulos, A., & Siguaw, J. A. (2006). Formative versus
reflective indicators in organizational measure development: A
comparison and empirical illustration. British Journal of Man-
agement, 17(2006), 263–282.
Diamantopoulos, A., & Winklhofer, H. M. (2001). Index construction
with formative indicators: An alternative to scale development.
Journal of Marketing Research, 38(2), 269–277.
Donaldson, T. (1996). Values in tension: Ethics away from home.
Harvard Business Review, 74(5), 48–62.
Douglas, D. E., Cronan, T. P., & Behel, J. D. (2007). Equity
perceptions as a deterrent to software piracy behavior. Informa-
tion & Management, 44(5), 503–512.
Earley, P. C. (1989). Social loafing and collectivism. Administrative
Science Quarterly, 34, 565–581.
Fischer, R., Ferreira, M. C., Assmar, E. M. L., Redford, P., & Harb, C.
(2005). Organizational behaviour across cultures: Theoretical
and methodological issues for developing multi-level frame-
works involving culture. International Journal of Cross Cultural
Management, 5(1), 27–48.
Fisher, R. J. (1993). Social desirability bias and the validity of indirect
questioning. Journal of Consumer Research, 20(2), 303–315.
Fiske, A. P. (2002). Using individualism and collectivism to compare
cultures—A critique of the validity and measurement of the
constructs: Comment on Oyserman et al. (2002). Psychological
Bulletin, 128(1), 78–88.
Fornell, C., & Larcker, D. F. (1981). Evaluating structural equation
models with unobservable variables and measurement error.
Journal of Marketing Research, 18(1981), 39–50.
Fraley, R. C. (2007). Using the internet for personality research: What
can be done, how to do it, and some concerns. In R. W. Robins,
R. C. Fraley, & R. F. Krueger (Eds.), Methods in personality
psychology (pp. 130–148). New York: Guilford.
Gan, L. L., & Koh, H. C. (2006). An empirical study of software
piracy among tertiary institutions in Singapore. Information &
Management, 43(5), 640–649.
Gattiker, U. E., & Kelley, H. (1999). Morality and computers:
Attitudes and differences in moral judgments. Information
Systems Research, 10(3), 233–254.
Gefen, D., & Straub, D. W. (2005). A practical guide to factorial
validity using PLS-Graph: Tutorial and annotated example.
Communications of the Association for Information Systems,
16(5), 91–109.
Haines, R., & Leonard, L. N. K. (2007). Situational influences on
ethical decision-making in an IT context. Information &
Management, 44(3), 313–320.
Hansen, J. V., Lowry, P. B., Meservy, R., & McDonald, D. (2007).
Genetic programming for prevention of cyberterrorism through
dynamic and evolving intrusion detection. Decision Support
Systems, 43(4), 1362–1374.
Harrington, S. J. (1996). The effect of codes of ethics and personal
denial of responsibility on computer abuse judgments and
intentions. MIS Quarterly, 20(3), 257–278.
Herath, T., & Rao, H. R. (2009a). Encouraging information security
behaviors in organizations: Role of penalties, pressures and
perceived effectiveness. Decision Support Systems, 47(2),
154–165.
Herath, T., & Rao, H. R. (2009b). Protection motivation and
deterrence: A framework for security policy compliance in
organisations. European Journal of Information Systems, 18(2),
106–125.
Hilton, T. (2000). Information systems ethics: A practitioner survey.
Journal of Business Ethics, 28(4), 279–284.
Hofstede, G. (1984). Culture’s consequences: International differ-
ences in work related values. London: Sage.
Hofstede, G. (1991). Cultures and organizations: Software of the
mind. Berkshire: McGraw-Hill Book Company Europe.
Hofstede, G. (2001). Culture’s consequences—Comparing values, behav-
iors, institutions, and organizations across nations (2nd ed.).
London: Sage.
Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 399
123
Hofstede, G. (2002). The pitfalls of cross-national survey research: A
reply to the article by Spector et al. on the psychometric
properties of the Hofstede value survey module 1994. Applied
Psychology: An International Review, 51(1), 170–178.
Hunt, S. D., & Vitell, S. J. (1986). A general theory of marketing
ethics. Journal of Macromarketing, 6(Spring), 5–16.
Husted, B. W. (2000). The impact of national culture on software
piracy. Journal of Business Ethics, 26(3), 197–211.
Husted, B., & Allen, D. (2008). Toward a model of cross-cultural
business ethics: The impact of individualism and collectivism on
the ethical decision-making process. Journal of Business Ethics,
82(2), 293–305.
Husted, B. W., Dozier, J. B., McMahon, J. T., & Kattan, M. W.
(1996). The impact of cross-national carriers of business ethics
on attitudes about questionable practices and form of moral
reasoning. Journal of International Business Studies, 27(2),
391–411.
Jaworski, B. J., & MacInnis, D. J. (1989). Marketing jobs and
management controls: Toward a framework. Journal of Market-
ing Research, 26, 406–419.
Johnston, A. C., & Warkentin, M. (2010). Fear appeals and
information security behaviors: An empirical study. MIS Quar-
terly, 34, 549–566.
Jones, T. M., & Ryan, L. V. (1997). The link between ethical
judgment and action in organizations: A moral approbation
approach. Organization Science, 8(6), 663–680.
Keith, M., Shao, B., & Steinbart, P. (2009). A behavioral analysis of
passphrase design and effectiveness. Journal of the Association
for Information Systems, 10(2), 63–89.
Kock, N. (2010). WarpPLS 1.0 user manual. Laredo, TX: ScriptWarp
Systems.
Lee, S. M., Lee, S. G., & Yoo, S. (2004). An integrative model of
computer abuse based on social control and general deterrence
theories. Information & Management, 41, 707–718.
Leonard, L. N. K., & Cronan, T. P. (2001). Illegal, inappropriate, and
unethical behavior in an information technology context: A
study to explain influences. Journal of the Association for
Information Systems, 1(12), 1–31.
Leonard, L. N. K., Cronan, T. P., & Kreie, J. (2004). What influences
IT ethical behavior intentions—Planned behavior, reasoned
action, perceived importance, or individual characteristics?
Information & Management, 42(2004), 143–158.
Liang, H., Saraf, N., Hu, Q., & Xue, Y. (2007). Assimilation of
enterprise systems: The effect of institutional pressures and the
mediating role of top management. MIS Quarterly, 31(1), 59–87.
Loch, K. D., & Conger, S. (1995). Evaluating ethical decision making
and computer use. Communications of the ACM, 39(7), 74–83.
Lowry, P. B., Romano, N. C., Jenkins, J. L., & Guthrie, R. W. (2009). The
CMC interactivity model: How interactivity enhances communi-
cation quality and process satisfaction in lean-media groups.
Journal of Management Information Systems, 26(1), 159–200.
Lowry, P. B., Vance, A., Moody, G., Beckman, B., & Read, A.
(2008). Explaining and predicting the impact of branding
alliances and web site quality on initial consumer trust of
e-commerce web sites. Journal of Management Information
Systems, 24(4), 199–224.
McCoy, S., Galletta, D. F., & King, W. R. (2005). Integrating national
culture into IS research: The need for current individual-level
measures. Communications of the AIS, 15, 211–224.
Merhout, J. W., & Havelka, D. (2008). Information technology
auditing: A value-added IT governance partnership between IT
management and audit. Communications of the Association for
Information Systems, 23(26), 463–482.
Mick, D. G. (1996). Are studies of dark side variables confounded by
socially desirable responding? The case of materialism. Journal
of Consumer Research, 23(2), 106–111.
Moores, T. T., & Chang, J. C.-J. (2006). Ethical decision making in
software piracy: Initial development and test of a four-compo-
nent model. MIS Quarterly, 30(1), 167–180.
Moores, T. T., & Dhaliwal, J. (2004). A reversed context analysis of
software piracy issues in Singapore. Information & Manage-
ment, 41(8), 1037–1042.
Myyry, L., Siponen, M., Pahnila, S., Vartiainen, T., & Vance, A.
(2009). What levels of moral reasoning and values explain
adherence to information security rules? An empirical study.
European Journal of Information Systems, 18(2), 126–139.
Nunnally, J. C., & Bernstein, I. H. (1994). Psychometric theory. New
York: McGraw-Hill.
Oyserman, D. (2006). High power, low power, and equality: Culture
beyond individualism and collectivism. Journal of Consumer
Psychology, 16(4), 352–356.
Oyserman, D., Coon, M., & Kemmelmeier, M. (2002). Rethinking
individualism and collectivism: Evaluation of the theoretical
assumptions and meta-analysis. Psychological Bulletin, 128(1),
3–72.
Oyserman, D., & Lee, S. W. S. (2008). Does culture influence what
and how we think? Effects of priming individualism and
collectivism. Psychological Bulletin, 134(2), 311–342.
Patel, T., & Schaefe, A. (2009). Making sense of the diversity of
ethical decision making in business: An illustration of the Indian
context. Journal of Business Ethics, 90(2), 171–186.
Pavlou, P., Liang, H., & Xue, Y. (2007). Understanding and
mitigating uncertainty in online exchange relationships: A
principal-agent perspective. MIS Quarterly, 31(1), 105–136.
Peace, A. G., Galletta, D. F., & Thong, J. Y. L. (2003). Software
piracy in the workplace: A model and empirical test. Journal of
Management Information Systems, 20(1), 153–177.
Petter, S., Straub, D. W., & Rai, A. (2007). Specifying formative
constructs in information systems research. MIS Quarterly,
31(4), 623–656.
Podsakoff, P. M., MacKenzie, S. B., Lee, J. Y., & Podsakoff, N. P.
(2003). Common method biases in behavioral research: A
critical review of the literature and recommended remedies.
Journal of Applied Psychology, 88(5), 879–903.
Posey, C., Bennett, R., Roberts, T. L., & Lowry, P. B. (2011). When
computer monitoring backfires: Invasion of privacy and organi-
zational injustice as precursors to computer abuse. Journal of
Information System Security, 7(1), 24–47.
Ralston, D. A., Holt, D. H., Terpstra, R. H., & Kai-Cheng, Y. (2008).
The impact of national culture and economic ideology on
managerial work values: A study of the United States, Russia,
Japan, and China. Journal of International Business Studies,
39(1), 8–26.
Ransbotham, S., & Mitra, S. (2009). Choice and chance: A conceptual
model of paths to information security compromise. Information
Systems Research, 20(1), 121–139.
Rao, M. T., Brown, C. V., & Perkins, W. C. (2007). Host country
resource availability and information system control mechanisms
in multinational corporations: An empirical test of resource
dependence theory. Journal of Management Information Sys-
tems, 23(4), 11–28.
Ringle, C. M., Wende, S., & Will, S. (2005). SmartPLS 2.0 (M3) Beta.
Retrieved September 17, 2010, from http://www.smartpls.de.
Robertson, C. J., & Crittenden, W. F. (2002). Mapping moral
philosophies: Strategic implications for multinational firms.
Strategic Management Journal, 24(4), 327–338.
Robertson, C., Crittenden, W., Brady, M., & Hoffman, J. (2002).
Situational ethics across borders: A multicultural examination.
Journal of Business Ethics, 38(4), 327–338.
Robertson, C., & Fadil, P. A. (1999). Ethical decision making in
multinational organizations: A culture-based model. Journal of
Business Ethics, 19(4), 385–392.
400 P. B. Lowry et al.
123
Robertson, C., Gilley, K., & Crittenden, W. (2008). Trade liberaliza-
tion, corruption, and software piracy. Journal of Business Ethics,
78(4), 623–634.
Robinson, S. L., & Bennett, R. J. (1995). A typology of deviant
workplace behaviors: A multidimensional scaling study. Acad-
emy of Management Journal, 38(2), 555–572.
Robinson, S. L., & O’Leary-Kelly, A. M. (1998). Monkey see,
monkey do: The influence of work groups on the antisocial
behavior of employees. Academy of Management Journal, 41(6),
658–672.
Schlegelmilch, B. B., & Robertson, D. C. (1995). The influence of
country and industry on ethical perceptions of senior executives
in the U.S. and Europe. Journal of International Business
Studies, 26(4), 859–881.
Schminke, M., Ambrose, M. L., & Noel, T. W. (1997). The effect of
ethical frameworks on perceptions of organizational justice.
Academy of Management Journal, 40(5), 1190–1207.
Schminke, M., & Wells, D. (1999). Group processes and performance
and their effects on individuals’ ethical frameworks. Journal of
Business Ethics, 18(4), 367–381.
Shin, S. K., Ishman, M., & Sanders, G. L. (2007). An empirical
investigation of socio-cultural factors of information sharing in
China. Information & Management, 44(2), 165–174.
Siponen, M., & Vance, A. (2010). Neutralization: New insights into
the problem of employee information systems security policy
violations. MIS Quarterly, 34, 487–502.
Siponen, M., & Vartiainen, T. (2007). Unauthorized copying of
software and levels of moral development: A literature analysis
and its implications for research and practice. Information
Systems Journal, 14(4), 387–407.
Smith, H. J., & Hasnas, J. (1999). Ethics and information systems:
The corporate domain. MIS Quarterly, 23(1), 109–127.
Smith, H. J., & Keil, M. (2003). The reluctance to report bad news on
troubled software projects: A theoretical model. Information
Systems Journal, 13(1), 69–95.
Smith, H. J., Keil, M., & Depledge, G. (2001). Keeping mum as the
project goes under: Toward an explanatory model. Journal of
Management Information Systems, 18(2), 189–227.
Son, J.-Y., & Kim, S. S. (2008). Internet users’ information privacy-
protective responses: A taxonomy and a nomological model.
MIS Quarterly, 32(3), 503–529.
Sproull, L., & Kiesler, S. (1991). Connections. Boston: MIT Press.
Srite, M., & Karahanna, E. (2006). The role of espoused national
cultural values in technology acceptance. MIS Quarterly, 30(3),
679–704.
Staples, D. S., Hulland, J. S., & Higgins, C. A. (1999). A self-efficacy
theory explanation for the management of remote workers in
virtual organizations. Organization Science, 10(6), 758–776.
Straub, D. W. (1989). Validating instruments in MIS research. MIS
Quarterly, 13(2), 147–169.
Straub, D. W. (1990). Effective IS security: An empirical study.
Information Systems Research, 1(3), 255–276.
Straub, D. W., Boudreau, M. C., & Gefen, D. (2004). Validation
guidelines for IS positivist research. Communications of the
Association for Information Systems, 14(2004), 380–426.
Straub, D. W., & Welke, R. J. (1998). Coping with systems risk:
Security planning models for management decision making. MIS
Quarterly, 22(4), 441–469.
Sutton, S. (1998). Predicting and explaining intentions and behavior:
How well are we doing? Journal of Applied Social Psychology,
28(15), 1317–1338.
Sutton, S. G., Khazanchi, D., Hampton, C., & Arnold, V. (2008). Risk
analysis in extended enterprise environments: Identification of
critical risk factors in B2B e-commerce relationships. Journal of
the Association for Information Systems, 9(3/4), 151–174.
Swinyard, W. R., Rinne, H., & Kau, A. K. (1990). The morality of
software piracy: A cross-cultural analysis. Journal of Business
Ethics, 9(8), 655–664.
Tavakoli, A. A., Keenan, J. P., & Crnjak-Karanovic, B. (2003).
Culture and whistleblowing an empirical study of Croatian and
United States managers utilizing Hofstede’s cultural dimensions.
Journal of Business Ethics, 43(1/2), 49–64.
Thong, J. Y. L., & Yap, C.-s. (1998). Testing an ethical decision-
making theory: The case of softlifting. Journal of Management
Information Systems, 15(1), 213–237.
Torelli, C. J. (2006). Individuality or conformity? The effects of
independent and interdependent self-concepts on public judg-
ments. Journal of Consumer Research, 16(3), 240–248.
Triandis, H. C., & Gelfand, M. J. (1998). Converging measurement of
horizontal and vertical individualism and collectivism. Journal
of Personality and Social Psychology, 74, 118–128.
Tsui, J., & Windsor, C. (2001). Some cross-cultural evidence on
ethical reasoning. Journal of Business Ethics, 31(2), 143–150.
Tuttle, B., Harrell, A., & Harrison, P. (1997). Moral hazard, ethical
considerations, and the decision to implement an information
system. Journal of Management Information Systems, 13(4), 7–27.
Vardi, Y. (2001). The effects of organizational and ethical climates on
misconduct at work. Journal of Business Ethics, 29, 325–337.
Vitell, S. J., Nwachukwu, S. L., & Barnes, J. H. (1993). The effects of
culture on ethical decision-making: An application of Hofstede’s
typology. Journal of Business Ethics, 12(10), 753–760.
Voronov, M., & Singer, J. A. (2002). The myth of individualism-
collectivism: A critical review. Journal of Social Psychology,
142(4), 461–480.
Wang, J., Chaudhury, A., & Rao, H. R. (2008). A value-at-risk
approach to information security investment. Information Systems
Research, 19(1), 106–123.
Wang, J., Chen, R., Herath, T., & Rao, H. R. (2009). Visual e-mail
authentication and identification services: An investigation of the
effects on e-mail use. Decision Support Systems, 48(1), 92–102.
Winter, S., Stylianou, A., & Giacalone, R. (2004). Case of Machi-
avellianism and ethical ideology. Journal of Business Ethics,
54(3), 279–301.
Zhang, D., & Lowry, P. B. (2008). Issues, limitations, and opportunities
in cross-cultural research on collaborative software in information
systems. Journal of Global Information Management, 16(1), 61–92.
Zhang, D., Lowry, P. B., Zhou, L., & Fu, X. (2008). The impact of
individualism-collectivism, social presence, and group diversity
on group decision making under majority influence. Journal of
Management Information Systems, 23(4), 53–80.
Zhang, J., Luo, X., Akkaladevi, S., & Ziegelmayer, J. (2009).
Improving multiple-password recall: An empirical study. Euro-
pean Journal of Information Systems, 18(2), 165–176.
Zviran, M., & Erlich, Z. (2006). Identification and authentication:
Technology and implementation issues. Communications of the
Association for Information Systems, 17(4), 90–105.
Individual Ethics and Cultural Characteristics in Predicting Computer Abuse 401
123
Reproduced with permission of the copyright owner. Further reproduction prohibited without permission.
- c.10551_2013_Article_1705.pdf
- Is Your Banker Leaking Your Personal Information? The Roles of Ethics and Individual-Level Cultural Characteristics in Predicting Organizational Computer Abuse
- Abstract
- Introduction
- Background on Investigating Computer Abuse in Organizations
- The Case for Studying Individual-Level Ethics in Computer Abuse
- The Case for Studying Individual-Level Cultural Characteristics in Computer Abuse
- Theoretic Model and Hypotheses
- Predictions for CA Based on Ethical Formalism and Utilitarianism
- Predictions for CA Based on Individual-Level Collectivism and Individualism
- Research Methods
- Data Collection
- Construct Measurement
- Analysis and Results
- Summary of Results
- Contributions to Theory
- Applying Results in Practice
- Promoting Formalism in Organizations
- Promoting Collectivism in Organizations
- Limitations and Future Research
- Appendix 1
- References