{"id":{"repo_id":"alabama","oai_identifier":"oai:ir.ua.edu:123456789/17087"},"canonical_url":"https://search.dev.ndltd.org/etd/alabama/oai:ir.ua.edu:123456789/17087","repository":{"repo_id":"alabama","name":"University of Alabama","base_url":"https://ir-api.ua.edu/oai/request"},"display":{"title":"Effective Cognitive Modes for Compliance with Information Security Policies over Time","abstract":"Compliance with information security policies (ISPC) has long been conceptualized as rational and intention-driven behavior. However, recent scholarship suggests that individuals' reasoning strategies in security contexts are far more dynamic and context-dependent. This dissertation seeks to reframe how ISPC is understood by emphasizing the role of cognitive adaptation, i.e., how individuals shift between intuitive, quasirational, and analytical modes in response to environmental, task-related, and psychological factors. In this two-essay dissertation, we pursue three broad goals. In Essay 1, we achieve two objectives. First, we conduct a systematic literature review to explore how ISPC has been cognitively framed and behaviorally measured across prior information security research. This review identifies three limitations: 1) an overreliance on rational-choice and intention-based decision making; 2) insufficient attention to adaptive reasoning strategies; and 3) limited consideration of both cognitive and behavioral change in empirical measurement. In response, we develop five cognitive-behavioral reasoning chains that represent distinct processes of how employees navigate security decisions. Then, we conduct semi-structured interviews to validate these chains by providing empirical support for a cognitive framework that accommodates real-world complexity and dynamics. In Essay 2, we empirically examine cognitive and behavioral change in ISPC through a longitudinal study with an experience sampling method that captures real-time observations from participants over multiple workdays. This study demonstrates that employees' cognitive modes fluctuate in response to factors such as task complexity, decision fatigue, and task familiarity. Results show that analytical mode supports stronger compliance, task familiarity enhances analytical engagement, and decision fatigue increases intuitive but less secure behavior. This dissertation introduces a cognitively adaptive model of compliance behavior, provides empirical evidence of within-person variability, and offers actionable guidance for designing interventions that support security behavior in contextually sensitive ways.","abstract_html":"Compliance with information security policies (ISPC) has long been conceptualized as rational and intention-driven behavior. However, recent scholarship suggests that individuals&#x27; reasoning strategies in security contexts are far more dynamic and context-dependent. This dissertation seeks to reframe how ISPC is understood by emphasizing the role of cognitive adaptation, i.e., how individuals shift between intuitive, quasirational, and analytical modes in response to environmental, task-related, and psychological factors. In this two-essay dissertation, we pursue three broad goals. In Essay 1, we achieve two objectives. First, we conduct a systematic literature review to explore how ISPC has been cognitively framed and behaviorally measured across prior information security research. This review identifies three limitations: 1) an overreliance on rational-choice and intention-based decision making; 2) insufficient attention to adaptive reasoning strategies; and 3) limited consideration of both cognitive and behavioral change in empirical measurement. In response, we develop five cognitive-behavioral reasoning chains that represent distinct processes of how employees navigate security decisions. Then, we conduct semi-structured interviews to validate these chains by providing empirical support for a cognitive framework that accommodates real-world complexity and dynamics. In Essay 2, we empirically examine cognitive and behavioral change in ISPC through a longitudinal study with an experience sampling method that captures real-time observations from participants over multiple workdays. This study demonstrates that employees&#x27; cognitive modes fluctuate in response to factors such as task complexity, decision fatigue, and task familiarity. Results show that analytical mode supports stronger compliance, task familiarity enhances analytical engagement, and decision fatigue increases intuitive but less secure behavior. This dissertation introduces a cognitively adaptive model of compliance behavior, provides empirical evidence of within-person variability, and offers actionable guidance for designing interventions that support security behavior in contextually sensitive ways.","abstract_has_math":false,"creators":["Zhao, Weijie"],"institution":"University of Alabama Libraries","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Siponen, Mikko","Luo, Xin (Robert)","Bott, Gregory","Tian, Chuan (Annie)"],"advisors":["Johnston, Allen C."],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025","date_published":"2025","updated_at":"2026-07-27T18:44:07Z","subjects":["cognitive continuum","cognitive mode","compliance","experience sampling method","information security policy"],"languages":["en_US","English"],"rights":["All rights reserved by the author unless otherwise indicated."],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier.other","label":"Dc Identifier Other","values":["1177685"],"render_values":[{"text":"1177685","href":null,"code":true}]}]},"links":{"outbound_url":"https://ir.ua.edu/handle/123456789/17087","outbound_label":"Repository record","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Siponen, Mikko","Luo, Xin (Robert)","Bott, Gregory","Tian, Chuan (Annie)"]},{"key":"dc:contributor.advisor","label":"Advisor","values":["Johnston, Allen C."]},{"key":"dc:creator","label":"Author","values":["Zhao, Weijie"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2025-09-04T16:14:47Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2025-09-04T16:14:47Z"]},{"key":"dc:date.issued","label":"Date","values":["2025"]},{"key":"dc:publisher","label":"Institution","values":["University of Alabama Libraries"]},{"key":"dc:type","label":"Dc Type","values":["thesis","text"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["cognitive continuum","cognitive mode","compliance","experience sampling method","information security policy"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["English"]},{"key":"dc:language.iso","label":"Language (ISO)","values":["en_US"]},{"key":"dc:rights","label":"Dc Rights","values":["All rights reserved by the author unless otherwise indicated."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.other","label":"Dc Identifier Other","values":["1177685"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://ir.ua.edu/handle/123456789/17087"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Electronic Thesis or Dissertation"]},{"key":"dc:description.abstract","label":"Abstract","values":["Compliance with information security policies (ISPC) has long been conceptualized as rational and intention-driven behavior. However, recent scholarship suggests that individuals' reasoning strategies in security contexts are far more dynamic and context-dependent. This dissertation seeks to reframe how ISPC is understood by emphasizing the role of cognitive adaptation, i.e., how individuals shift between intuitive, quasirational, and analytical modes in response to environmental, task-related, and psychological factors. In this two-essay dissertation, we pursue three broad goals. In Essay 1, we achieve two objectives. First, we conduct a systematic literature review to explore how ISPC has been cognitively framed and behaviorally measured across prior information security research. This review identifies three limitations: 1) an overreliance on rational-choice and intention-based decision making; 2) insufficient attention to adaptive reasoning strategies; and 3) limited consideration of both cognitive and behavioral change in empirical measurement. In response, we develop five cognitive-behavioral reasoning chains that represent distinct processes of how employees navigate security decisions. Then, we conduct semi-structured interviews to validate these chains by providing empirical support for a cognitive framework that accommodates real-world complexity and dynamics. In Essay 2, we empirically examine cognitive and behavioral change in ISPC through a longitudinal study with an experience sampling method that captures real-time observations from participants over multiple workdays. This study demonstrates that employees' cognitive modes fluctuate in response to factors such as task complexity, decision fatigue, and task familiarity. Results show that analytical mode supports stronger compliance, task familiarity enhances analytical engagement, and decision fatigue increases intuitive but less secure behavior. This dissertation introduces a cognitively adaptive model of compliance behavior, provides empirical evidence of within-person variability, and offers actionable guidance for designing interventions that support security behavior in contextually sensitive ways."]},{"key":"dc:format.medium","label":"Dc Format Medium","values":["electronic"]},{"key":"dc:format.mimetype","label":"Dc Format Mimetype","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Effective Cognitive Modes for Compliance with Information Security Policies over Time"]}]}],"canonical_facts":{"dc:contributor":["Siponen, Mikko","Luo, Xin (Robert)","Bott, Gregory","Tian, Chuan (Annie)"],"dc:contributor.advisor":["Johnston, Allen C."],"dc:creator":["Zhao, Weijie"],"dc:date.accessioned":["2025-09-04T16:14:47Z"],"dc:date.available":["2025-09-04T16:14:47Z"],"dc:date.issued":["2025"],"dc:description":["Electronic Thesis or Dissertation"],"dc:description.abstract":["Compliance with information security policies (ISPC) has long been conceptualized as rational and intention-driven behavior. However, recent scholarship suggests that individuals' reasoning strategies in security contexts are far more dynamic and context-dependent. This dissertation seeks to reframe how ISPC is understood by emphasizing the role of cognitive adaptation, i.e., how individuals shift between intuitive, quasirational, and analytical modes in response to environmental, task-related, and psychological factors. In this two-essay dissertation, we pursue three broad goals. In Essay 1, we achieve two objectives. First, we conduct a systematic literature review to explore how ISPC has been cognitively framed and behaviorally measured across prior information security research. This review identifies three limitations: 1) an overreliance on rational-choice and intention-based decision making; 2) insufficient attention to adaptive reasoning strategies; and 3) limited consideration of both cognitive and behavioral change in empirical measurement. In response, we develop five cognitive-behavioral reasoning chains that represent distinct processes of how employees navigate security decisions. Then, we conduct semi-structured interviews to validate these chains by providing empirical support for a cognitive framework that accommodates real-world complexity and dynamics. In Essay 2, we empirically examine cognitive and behavioral change in ISPC through a longitudinal study with an experience sampling method that captures real-time observations from participants over multiple workdays. This study demonstrates that employees' cognitive modes fluctuate in response to factors such as task complexity, decision fatigue, and task familiarity. Results show that analytical mode supports stronger compliance, task familiarity enhances analytical engagement, and decision fatigue increases intuitive but less secure behavior. This dissertation introduces a cognitively adaptive model of compliance behavior, provides empirical evidence of within-person variability, and offers actionable guidance for designing interventions that support security behavior in contextually sensitive ways."],"dc:format.medium":["electronic"],"dc:format.mimetype":["application/pdf"],"dc:identifier.other":["1177685"],"dc:identifier.uri":["https://ir.ua.edu/handle/123456789/17087"],"dc:language":["English"],"dc:language.iso":["en_US"],"dc:publisher":["University of Alabama Libraries"],"dc:rights":["All rights reserved by the author unless otherwise indicated."],"dc:subject":["cognitive continuum","cognitive mode","compliance","experience sampling method","information security policy"],"dc:title":["Effective Cognitive Modes for Compliance with Information Security Policies over Time"],"dc:type":["thesis","text"]},"updated_at":"2026-07-27T18:44:07Z"}