Skip to main content
QUICK REVIEW

[Paper Review] A Model for the Adoption Process of Information System Security Innovations in Organisations: A Theoretical Perspective

Mumtaz Abdul Hameed, Nalin Asanka Gamagedara Arachchilage|arXiv (Cornell University)|Jan 1, 2016
Technology Adoption and User Behaviour23 references12 citations
TL;DR

This paper proposes a comprehensive theoretical model integrating Diffusion of Innovation (DOI), Technology Acceptance Model (TAM), Theory of Planned Behaviour (TPB), and Technology-Organisation-Environment (TOE) framework to explain the multi-stage adoption process of Information System (IS) security innovations in organisations. The model uniquely combines organisational adoption decisions with user-level acceptance behaviour, identifying key technological, organisational, environmental, and behavioural factors influencing successful IS security implementation.

ABSTRACT

In this paper, we develop a theoretical model for the adoption process of Information System Security innovations in organisations. The model stemmed from the Diffusion of Innovation theory (DOI), the Technology Acceptance Model (TAM), the Theory of Planned Behaviour (TPB) and the Technology-Organisation-Environment (TOE) framework. The model portrays Information System Security adoption process progressing in a sequence of stages. The study considers the adoption process from the initiation stage until the acquisition of innovation as an organisational level judgement while the process of innovation assimilation and integration is assessed in terms of the user behaviour within the organisation. The model also introduces several factors that influence the Information System Security innovation adoption. By merging the organisational adoption and user acceptance of innovation in a single depiction, this research contributes to IS security literature a more comprehensive model for IS security adoption in organisation, compare to any of the past representations.

Motivation & Objective

  • To address the gap in existing literature by developing a holistic model that captures both organisational adoption and user acceptance of IS security innovations.
  • To synthesise established theories—DOI, TAM, TPB, and TOE—into a single integrated framework for IS security adoption.
  • To identify and map key determinants influencing IS security innovation adoption across technological, organisational, environmental, and user behavioural dimensions.
  • To provide a systematic, stage-based representation of the IS security adoption process from initiation to integration and sustained use.
  • To offer a theoretical foundation for future empirical research and practical guidance for organisations aiming to improve IS security adoption outcomes.

Proposed method

  • Theoretical synthesis of four major frameworks: DOI for innovation diffusion stages, TOE for organisational context, TAM and TPB for user-level technology acceptance.
  • Systematic literature review to identify and extract relevant constructs and relationships from prior studies on IS innovation adoption and user acceptance.
  • Integration of constructs into a unified model where organisational adoption (pre-adoption, adoption-decision, post-adoption) is mapped to TOE and DOI, while user acceptance is modelled via TAM and TPB.
  • Staged representation of the adoption process: initiation → organisational decision-making → acquisition → user integration and sustained use.
  • Identification of mediating and moderating factors across technology, organisation, environment, and user behaviour domains.
  • Use of conceptual mapping to illustrate causal relationships between determinants and adoption outcomes, without empirical validation due to theoretical focus.

Experimental results

Research questions

  • RQ1How can existing theories of innovation adoption and technology acceptance be integrated to model the full IS security innovation adoption process in organisations?
  • RQ2What are the key organisational, technological, environmental, and user behavioural factors that influence the adoption of IS security innovations?
  • RQ3How do the stages of innovation adoption (initiation, decision, integration) interact with user acceptance and organisational commitment to ensure successful implementation?
  • RQ4In what ways does combining organisational adoption and user acceptance in a single model improve the comprehensiveness of IS security adoption frameworks compared to previous models?
  • RQ5What are the critical determinants that facilitate or hinder the successful integration and sustained use of IS security innovations in organisational settings?

Key findings

  • The proposed model successfully integrates DOI, TOE, TAM, and TPB into a single, stage-based framework that captures both organisational adoption and user-level acceptance of IS security innovations.
  • The model identifies four key determinant domains—technological, organisational, environmental, and user behavioural—that collectively influence the success of IS security innovation adoption.
  • Organisational adoption is framed as a sequential process from initiation to acquisition, guided by TOE and DOI, while user acceptance is modelled through TAM and TPB to reflect individual behavioural intentions.
  • The integration of organisational and individual-level processes in one model provides a more comprehensive and systematic depiction of IS security adoption than previous models.
  • The model highlights that successful IS security adoption depends not only on organisational decisions but also on sustained user compliance and behavioural integration.
  • The study identifies a significant research gap in empirical validation, noting that the model's predictive power and causal relationships require future testing through quantitative and qualitative research.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.