We showed that attitude toward compliance can be traced back to cognitive beliefs, which are modeled in two levels. Our
results indicate that beliefs about overall assessment of consequences are the immediate antecedents of attitude. Further,
we identified seven outcome beliefs that provide the foundation for an employee’s beliefs about overall assessment of
consequences, so our results suggest that factors that motivate
employees to comply with the information security policy extend beyond instruments
such as sanctions and rewards.