suggested that organizations use three security countermeasures—user awareness of
security policies; security education, training, and awareness
(SETA) programs; and computer monitoring—to reduce
user’s IS misuse.
They showed that users’ awareness of
countermeasures impacts perceptions on organizational sanc-
tions, which in turn reduces users’ IS misuse intention. Still,
to the best of our knowledge, the direct and indirect roles of
information security awareness on an employee’s compliance
behavior have not yet been studied. Beyond showing the
direct influence of ISA on an employee’s attitude toward
compliance,