{"id":"https://openalex.org/W3209396513","doi":"https://doi.org/10.1145/3466689","title":"Machine Learning and Survey-based Predictors of InfoSec Non-Compliance","display_name":"Machine Learning and Survey-based Predictors of InfoSec Non-Compliance","publication_year":2021,"publication_date":"2021-10-18","ids":{"openalex":"https://openalex.org/W3209396513","doi":"https://doi.org/10.1145/3466689","mag":"3209396513"},"language":"en","primary_location":{"id":"doi:10.1145/3466689","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3466689","pdf_url":null,"source":{"id":"https://openalex.org/S4210170305","display_name":"ACM Transactions on Management Information Systems","issn_l":"2158-656X","issn":["2158-656X","2158-6578"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Management Information Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5060334609","display_name":"Byron Marshall","orcid":"https://orcid.org/0000-0001-7109-6095"},"institutions":[{"id":"https://openalex.org/I131249849","display_name":"Oregon State University","ror":"https://ror.org/00ysfqy60","country_code":"US","type":"education","lineage":["https://openalex.org/I131249849"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Byron Marshall","raw_affiliation_strings":["Oregon State University, Corvallis, OR, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Oregon State University, Corvallis, OR, USA","institution_ids":["https://openalex.org/I131249849"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5112408634","display_name":"Michael Curry","orcid":null},"institutions":[{"id":"https://openalex.org/I131249849","display_name":"Oregon State University","ror":"https://ror.org/00ysfqy60","country_code":"US","type":"education","lineage":["https://openalex.org/I131249849"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Michael Curry","raw_affiliation_strings":["Oregon State University, Corvallis, OR, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Oregon State University, Corvallis, OR, USA","institution_ids":["https://openalex.org/I131249849"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5090489133","display_name":"Robert E. Crossler","orcid":"https://orcid.org/0000-0002-8179-9138"},"institutions":[{"id":"https://openalex.org/I72951846","display_name":"Washington State University","ror":"https://ror.org/05dk0ce17","country_code":"US","type":"education","lineage":["https://openalex.org/I72951846"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Robert E. Crossler","raw_affiliation_strings":["Washington State University, Pullman, WA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Washington State University, Pullman, WA, USA","institution_ids":["https://openalex.org/I72951846"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5057459704","display_name":"John Correia","orcid":"https://orcid.org/0000-0002-9766-3542"},"institutions":[{"id":"https://openalex.org/I119888943","display_name":"Gonzaga University","ror":"https://ror.org/03ze70h02","country_code":"US","type":"education","lineage":["https://openalex.org/I119888943"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"John Correia","raw_affiliation_strings":["Gonzaga University, Spokane, WA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Gonzaga University, Spokane, WA, USA","institution_ids":["https://openalex.org/I119888943"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.4225,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.86105063,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":97},"biblio":{"volume":"13","issue":"2","first_page":"1","last_page":"20"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9962000250816345,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9922999739646912,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6055318713188171},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5608538389205933},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.5511083006858826},{"id":"https://openalex.org/keywords/compliance","display_name":"Compliance (psychology)","score":0.5141528248786926},{"id":"https://openalex.org/keywords/selection","display_name":"Selection (genetic algorithm)","score":0.434059739112854},{"id":"https://openalex.org/keywords/feature-selection","display_name":"Feature selection","score":0.41530752182006836},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3972011208534241},{"id":"https://openalex.org/keywords/knowledge-management","display_name":"Knowledge management","score":0.38138651847839355},{"id":"https://openalex.org/keywords/risk-analysis","display_name":"Risk analysis (engineering)","score":0.3448914885520935},{"id":"https://openalex.org/keywords/data-science","display_name":"Data science","score":0.3413487672805786},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.30785828828811646},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.28397971391677856},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.15587785840034485},{"id":"https://openalex.org/keywords/social-psychology","display_name":"Social psychology","score":0.12661105394363403}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6055318713188171},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5608538389205933},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.5511083006858826},{"id":"https://openalex.org/C2781460075","wikidata":"https://www.wikidata.org/wiki/Q1399332","display_name":"Compliance (psychology)","level":2,"score":0.5141528248786926},{"id":"https://openalex.org/C81917197","wikidata":"https://www.wikidata.org/wiki/Q628760","display_name":"Selection (genetic algorithm)","level":2,"score":0.434059739112854},{"id":"https://openalex.org/C148483581","wikidata":"https://www.wikidata.org/wiki/Q446488","display_name":"Feature selection","level":2,"score":0.41530752182006836},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3972011208534241},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.38138651847839355},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.3448914885520935},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.3413487672805786},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.30785828828811646},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.28397971391677856},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.15587785840034485},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.12661105394363403},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3466689","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3466689","pdf_url":null,"source":{"id":"https://openalex.org/S4210170305","display_name":"ACM Transactions on Management Information Systems","issn_l":"2158-656X","issn":["2158-656X","2158-6578"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Management Information Systems","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9","score":0.5699999928474426}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":63,"referenced_works":["https://openalex.org/W129912261","https://openalex.org/W324885528","https://openalex.org/W429766147","https://openalex.org/W433644524","https://openalex.org/W1276866904","https://openalex.org/W1588086203","https://openalex.org/W1602619638","https://openalex.org/W1721421031","https://openalex.org/W1728842521","https://openalex.org/W1772700132","https://openalex.org/W1901616594","https://openalex.org/W1970809283","https://openalex.org/W1993734008","https://openalex.org/W2002964284","https://openalex.org/W2005459083","https://openalex.org/W2010902645","https://openalex.org/W2012614739","https://openalex.org/W2017785078","https://openalex.org/W2020718911","https://openalex.org/W2020989719","https://openalex.org/W2025001960","https://openalex.org/W2033213440","https://openalex.org/W2036389121","https://openalex.org/W2042403281","https://openalex.org/W2056847254","https://openalex.org/W2059528567","https://openalex.org/W2060010505","https://openalex.org/W2081526168","https://openalex.org/W2091261347","https://openalex.org/W2099233982","https://openalex.org/W2099647042","https://openalex.org/W2100826189","https://openalex.org/W2107528096","https://openalex.org/W2121945561","https://openalex.org/W2124330866","https://openalex.org/W2136451344","https://openalex.org/W2137130182","https://openalex.org/W2156438052","https://openalex.org/W2164777277","https://openalex.org/W2167277498","https://openalex.org/W2419049983","https://openalex.org/W2603281533","https://openalex.org/W2732916693","https://openalex.org/W2768849025","https://openalex.org/W2782420259","https://openalex.org/W2784097977","https://openalex.org/W2786705330","https://openalex.org/W2801347047","https://openalex.org/W2912168694","https://openalex.org/W2915536369","https://openalex.org/W2917355511","https://openalex.org/W2944872739","https://openalex.org/W2980442347","https://openalex.org/W2997057290","https://openalex.org/W2997683334","https://openalex.org/W2998484370","https://openalex.org/W2999930990","https://openalex.org/W3005993375","https://openalex.org/W3126055879","https://openalex.org/W3151685851","https://openalex.org/W4240429374","https://openalex.org/W4248734920","https://openalex.org/W4300870773"],"related_works":["https://openalex.org/W2410395228","https://openalex.org/W3125941065","https://openalex.org/W2484615095","https://openalex.org/W4366449942","https://openalex.org/W4366371796","https://openalex.org/W4366371752","https://openalex.org/W1489027086","https://openalex.org/W4205440829","https://openalex.org/W2339265919","https://openalex.org/W4205338588"],"abstract_inverted_index":{"Survey":[0],"items":[1,138,165,190,237],"developed":[2],"in":[3,13,148,184,242],"behavioral":[4,240],"Information":[5],"Security":[6],"(InfoSec)":[7],"research":[8],"should":[9],"be":[10],"practically":[11],"useful":[12,204],"identifying":[14,217],"individuals":[15,222],"who":[16],"are":[17,65,255],"likely":[18],"to":[19,24,99,114,122,150,260],"create":[20],"risk":[21,93],"by":[22,68,94,127],"failing":[23],"comply":[25],"with":[26,174],"InfoSec":[27,55,69,142,241],"guidance.":[28],"The":[29,177,230],"literature":[30],"shows":[31],"that":[32,253,263],"attitudes,":[33],"beliefs,":[34],"and":[35,40,60,102,163,168,188,246,251],"perceptions":[36],"drive":[37],"compliance":[38],"behavior":[39],"has":[41],"influenced":[42],"the":[43,77,96,128,140,220,224,228,233,239],"creation":[44],"of":[45,48,79,106,117,160,172,206,219,227,235],"a":[46],"multitude":[47],"training":[49,244],"programs":[50,245],"focused":[51],"on":[52],"improving":[53],"ones\u2019":[54],"behaviors.":[56],"While":[57],"automated":[58],"controls":[59],"directly":[61],"observable":[62],"technical":[63],"indicators":[64],"generally":[66],"preferred":[67],"practitioners,":[70],"difficult-to-monitor":[71],"user":[72],"actions":[73],"can":[74],"still":[75],"compromise":[76],"effectiveness":[78],"automatic":[80],"controls.":[81],"For":[82],"example,":[83,213],"despite":[84],"prohibition,":[85],"doubtful":[86],"or":[87,109],"skeptical":[88],"employees":[89],"often":[90],"increase":[91],"organizational":[92],"using":[95,185,199],"same":[97],"password":[98],"authenticate":[100],"corporate":[101],"external":[103],"services.":[104],"Analysis":[105],"network":[107],"traffic":[108],"device":[110],"configurations":[111],"is":[112],"unlikely":[113],"provide":[115],"evidence":[116],"these":[118],"vulnerabilities":[119],"but":[120],"responses":[121],"well-designed":[123],"surveys":[124],"might.":[125],"Guided":[126],"relatively":[129],"new":[130],"IPAM":[131],"model,":[132],"this":[133],"study":[134],"administered":[135],"96":[136],"survey":[137],"from":[139,238],"Behavioral":[141],"literature,":[143],"across":[144,191],"three":[145],"separate":[146],"points":[147],"time,":[149],"217":[151],"respondents.":[152],"Using":[153],"systematic":[154],"feature":[155,178],"selection":[156,179],"techniques,":[157],"manageable":[158],"subsets":[159],"29,":[161],"20,":[162],"15":[164],"were":[166,197,209],"identified":[167],"tested":[169],"as":[170,257],"predictors":[171],"non-compliance":[173],"security":[175,267],"policy.":[176],"process":[180],"validates":[181],"IPAM's":[182],"innovation":[183],"nuanced":[186],"self-efficacy":[187],"planning":[189],"multiple":[192],"time":[193],"frames.":[194],"Prediction":[195],"models":[196,216,262],"trained":[198],"several":[200],"ML":[201],"algorithms.":[202],"Practically":[203],"levels":[205],"prediction":[207],"accuracy":[208],"achieved":[210],"with,":[211],"for":[212,266],"ensemble":[214],"tree":[215],"69%":[218],"riskiest":[221],"within":[223],"top":[225],"25%":[226],"sample.":[229],"findings":[231],"indicate":[232],"usefulness":[234],"psychometric":[236],"guiding":[243],"other":[247],"cybersecurity":[248],"control":[249],"activities":[250],"demonstrate":[252],"they":[254],"promising":[256],"additional":[258],"inputs":[259],"AI":[261],"monitor":[264],"networks":[265],"events.":[268]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
