Knowing is doing: An empirical validation of the relationship between managerial information security awareness and action

Namjoo Choi, Dan Kim, Jahyun Goo, Andy Whitmore

Research output: Contribution to journalArticlepeer-review

45 Scopus citations


Purpose - The purpose of this paper is to empirically validate the conjectural relationship between managerial information security awareness (MISA) and managerial actions toward information security (MATIS). Design/methodology/approach - A model is developed and the relationship between MISA and MATIS is tested using a large set of empirical data collected across different types and sizes of enterprises. The hypotheses of the research model are tested with regression analysis. Findings - The results of the study provide empirical support that MATIS is directly and positively related to MISA. Research limitations/implications - The R2, an estimate of the proportion of the total variation in the data set that is explained by the model, is relatively low. This fact implies that there are other constructs in addition to MISA that play a crucial role in determining MATIS. The paper suggests that intention to act and the risk-cost tradeoff of the MATIS are other possible constructs that should be incorporated into future research. The conceptual model employed as a theoretical basis also suggests that other factors such as the environment in which an organization operates (e.g. industry) also plays a major role in determining information security decisions independently of MISA. Other possible limitations include the use of secondary data in the study. Practical implications - The results indicate that developing strategies to raise an organization's MISA should impact MATIS and thus improve information security performance. Originality/value - The study provides empirical evidence supporting the unproven link between MISA and MATIS.

Original languageEnglish
Pages (from-to)484-501
Number of pages18
JournalInformation Management and Computer Security
Issue number5
StatePublished - 2008


  • Data security
  • Information systems
  • Management strategy

ASJC Scopus subject areas

  • Management Information Systems
  • Business and International Management
  • Management Science and Operations Research
  • Library and Information Sciences


Dive into the research topics of 'Knowing is doing: An empirical validation of the relationship between managerial information security awareness and action'. Together they form a unique fingerprint.

Cite this