Question Title

*                              Participant Letter for Anonymous Surveys
      Nova Southeastern University Consent to be in a Research Study Entitled                  

Orientation and Social Influences Matter: An Expansion of Neutralization Model

The person doing this study is Frank King with the College of Engineering and Computing, Nova Southeastern University under the guidance of  Dr. Souren Paul. 

You are being asked to take part in this research study because you are associated in one of the following industries: Academia, Corporate, or Information Technology Professionals.

The purpose of this study is to find a better understanding of employee’s cognitive rationalization when making decisions from both a business and ethical orientation. Employees are seen as the number one threat to an organization’s security, and as a result, employees fall into neutralization techniques and commit information security policy violations. This research will provide an explanation to employee’s cognitive thinking that enable them to make either business or ethical decisions to accept neutralization techniques and ultimately commit information security violations. As a result, this research will help practitioners, information security managers, and information security scholars in writing information security policy which may aid in reducing violations and ultimately protect sensitive data.

If you are willing to participate and you are 18 years of age and older, this will be a one-time, anonymous survey. The survey will take approximately 12 minutes to complete. Responses to this survey are completely anonymous and no personal identifiable information (PII) will be collected.

This research study involves minimal risk to you. To the best of our knowledge, the things you will be doing have no more risk of harm than you would have in everyday life.

You can decide not to participate in this research, and it will not be held against you. You can exit the survey at any time. Participation in this study is completely voluntary.

There is no cost for participation in this study. Participation is voluntary and no payment will be provided.

Your responses are anonymous. Information we learn about you in this research study will be handled in a confidential manner, within the limits of the law. This data will be available to the researcher, the Institutional Review Board (IRB) and other representatives of this institution, and any granting agencies (if applicable). All confidential data will be kept securely. Data will be kept with a secure cloud service provider and all data will be kept for 36 months from the end of the study. All records must be kept for a minimum of 36 months. After that time, all data will be erased and permanently deleted and destroyed. All data collected will be cleared from databases and all backup copies will be deleted and destroyed.   

If you have questions, you can contact Frank King at 202-841-6195 Monday thru Friday from 9am – 6pm EST or via e-mail fk145@mynsu.nova.edu

If you have questions about the study but want to talk to someone else who is not a part of the study, you can call the Nova Southeastern University Institutional Review Board (IRB) at (954) 262-5369 or toll free at 1-866-499-0790 or email at IRB@nova.edu.

If you have read the above information and voluntarily wish to participate in this research study, you may proceed to the survey below:




Question Title

*

In our organization our commitment to serving customer needs is closely monitored

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
BO1

Question Title

* In our organization it is important that customer satisfaction is frequently assessed

  Strongly disagree Disagree Somewhat Disagree Neither agree or disagree Somewhat agree Agree Strongly agree
BO2

Question Title

* In our organization we achieve rapid response to competitive actions

  Strongly Disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
BO4

Question Title

* In our organization business functions are integrated to serve market needs

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
BO6

Question Title

* A person should make certain that their actions never intentionally harm another even to a small degree

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
EO2

Question Title

* Risks to another should never be tolerated, irrespective of how small the risks might be

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
EO3

Question Title

* I like my job

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SI4

Question Title

* I respect the opinion and views of my co-workers

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SI5

Question Title

* I have a good relationship with my co-workers

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SI6

Question Title

* I am loyal to my organization

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SI7

Question Title

* I am very involved within my workplace

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SI8

Question Title

* I feel my job is important

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SI10

Question Title

*

My organization believes that I should follow the organization’s information security policy.

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SP1

Question Title

* My co-workers believe I should not violate information security policy

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SP3

Question Title

* My organization’s IT Information Security personnel are of opinion that I should comply with the information security policies

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SP4

Question Title

* My supervisors are of the opinion that I should comply to information security policies

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SP5

Question Title

* I believe most of the employees in my organization comply with IS security policy

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
SP6

Question Title

* Please use the scale from (0) Not likely at all (10) Extremely likely

Hypothetical Scenario 1


Seija is a middle-level manager in a medium-sized company where she was recently hired. Her department uses an inventory procurement software application program to make inventory purchases. To ensure that only authorized individuals make inventory purchases, the company has a firm policy that employees must log out or lock their computer workstation when not in use. However, to make work more convenient, Seija’s manager directs her to leave her user account logged-in for other employees to freely use. Seija expects that keeping her user account logged-in could save her company time. She also knows that keeping the workstation logged-in is a common practice in the industry and an employee recently was reprimanded for leaving the workstation logged-in. Seija leaves the workstation logged-in when she is finished.

What  is the likelihood that you would do as Seija

  Not at all Likely 1 2 3 4 Neutral 6 7 8 9 Extremely Likely
Scenario 1

Question Title

* Hypothetical Scenario 2

Hannu is a low-level manager in a small company where he was recently hired. His company has a strong policy that each computer workstation must be password-protected and that passwords are not to be shared. However, Hannu is on a business trip and one of his co-workers needs a file on his computer. Hannu expects that sharing his password could save his company a lot of time. He also knows that the firm has mandatory information security training. Hannu shares his password with his co-worker.

What is the likelihood you would do as Hannu

  Not at all likely 1 2 3 4 Neutral 6 7 8 9 Extremely likely
Scenario 2

Question Title

*

It is OK to violate the organizational information security policy to get the job done

  Strongly disagree Disgree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly Agree
N1

Question Title

* It is ok to violate the organizational information security policy under circumstances where it seems like you have little to no choice

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
N2

Question Title

* It is ok to violate organizational information security policy when you are in a hurry

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat argee Agree Strongly agree
N3

Question Title

* I feel my general adherence to organization information security policy compensates for occasionally violating information security policy

  Strongly Disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
N4

Question Title

* I feel my hard work compensates for occasionally violating information security policy

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
N5

Question Title

* It is not wrong to violate information security policy that is unreasonable

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
N6

Question Title

* It is not wrong to violate information security policy that requires too much time to comply

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat argee Agree Strongly agree
N7

Question Title

* It is ok to violate information security policy if it does not harm the organization

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
N8

Question Title

* It is ok to violate information security policy if no one gets hurt

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
N9

Question Title

* It is OK to violate the organization’s information security policy if you are not aware of what it is

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
N10

Question Title

* It is ok to violate the organization’s information security policy if it is not advertised

  Strongly disagree Disagree Somewhat disagree Neither agree or disagree Somewhat agree Agree Strongly agree
N11

Question Title

* Demographic Information

Which principal industry best describe your organization or work profession?

Question Title

* What are the approximate total number of employees for your organization

Question Title

* Gender

T