First, the extant literature has investigated factors rooted in deterrence theory and protection motivation theory to explain the information security policy compliance but, to the best of our knowledge, this is the first study that, drawing on RCT, offers a theoretical explanation and empirical support for the impact of an employee’s beliefs about the consequences of compliance and noncompliance with the information security policy on attitude toward compliance with the information security policy