Exploring Demographic Determinants of Information Systems Security Policy Compliance in Tanzanian Public Higher Learning Institution
DOI:
https://doi.org/10.59645/tji.v5i1.709Keywords:
Information Systems Security Policies, Compliance Behavior, Demographic Factors, Higher Learning InstitutionsAbstract
Information Systems Security Policies (ISSPs) are critical for safeguarding digital infrastructures in higher education institutions. However, compliance remains inconsistent, particularly in developing contexts where demographic diversity may influence user behavior. While prior research has addressed general security challenges, limited empirical evidence exists on how specific demographic factors shape ISSP compliance in Tanzanian public universities. This study addressed that gap by examining the effects of age, education level, and work experience on compliance behavior. Guided by the Theory of Planned Behavior (TPB), a quantitative cross-sectional design was adopted, targeting a population of 2,727 employees across eight public higher learning institutions. A stratified random sample of 436 respondents was drawn, and data were analyzed using SPSS v26 through descriptive statistics, Chi-Square tests, and Automatic Linear Modeling (ALM). Results indicated that age and education were significant predictors of compliance behavior, particularly among mid-aged and higher-educated respondents, while work experience had no statistically significant effect. These findings underscore the need to tailor cybersecurity policies and training to demographic realities, emphasizing that compliance is better fostered through targeted awareness and professional development rather than institutional tenure alone. The study recommends that policymakers and institutional leaders adopt demographic-sensitive and behaviorally informed strategies to improve compliance and reduce institutional risk.
Downloads
References
Ahmed, A. A. A., & Abas, H. (2024). Factors influencing information security policy compli ance behavior in higher education institutions: Systematic literature review. Advances in Social Sciences Research Journal, 11(7), 260–273. https://doi.org/10.14738/assrj.117.17308
Ajzen, I. (1991). The theory of planned behavior. Organizational Behavior and Human Deci sion Processes, 50(2), 179–211. https://doi.org/10.1016/0749-5978(91)90020-T
Almuqrin, A., Mutambik, I., Alomran, A., & Zhang, J. Z. (2023). Enforcing information sys-tem security: Policies and procedures for employee compliance. International Journal on Semantic Web and Information Systems, 19(1), 1–17. https://doi.org/10.4018/IJSWIS.331396
Badreddine, S., Alwada’n, T., & Razzaque, M. A. (2025). Cybersecurity attitudes in higher education institutions: A behavioural analysis of faculty and staff in the United Arab Emirates. Applied Sciences and Technology, 9(10), 439–453. https://ideas.repec.org/a/ajp/edwast/v9y2025i10p439-453id10445.html
Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548.
Cochran, W. G. (1977). Sampling techniques (3rd ed.). Wiley.
Cohen, J. (1992). A power primer. Psychological Bulletin, 112(1), 155–159. https://doi.org/10.1037/0033-2909.112.1.155
Dunn, T. J., Baguley, T., & Brunsden, V. (2014). From alpha to omega: A practical solution to the pervasive problem of internal consistency estimation. British Journal of Psychol ogy, 105(3), 399–412. https://doi.org/10.1111/bjop.12046
Field, A. (2018). Discovering statistics using IBM SPSS statistics (5th ed.). Sage.
Hair, J. F., Black, W. C., Babin, B. J., & Anderson, R. E. (2019). Multivariate data analysis (8th ed.). Cengage.
Harrell, F. E., Jr. (2015). Regression modeling strategies (2nd ed.). Springer. https://doi.org/10.1007/978-3-319-19425-7
Herath, T., & Rao, H. R. (2009). Protection motivation and deterrence: A framework for secu rity policy compliance. Decision Support Systems, 47(2), 154–165. https://doi.org/10.1016/j.dss.2009.02.013
Ifinedo, P. (2012). Understanding information systems security policy compliance: An integra tion of the theory of planned behavior and the protection motivation theory. Comput-ers & Security, 31(1), 83–95. https://doi.org/10.1016/j.cose.2011.10.007
Kabanda, M. (2024). Information security awareness in sub-Saharan African schools: The role of educational leadership in turbulent times. SSRN. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4821616
Kline, R. B. (2016). Principles and practice of structural equation modeling (4th ed.). Guil-ford.
Kombo, F. S., Mwakalinga, P. G., Kumbo, L. I., Edward, L. M., & Bhalalusesa, N. P. (2023). Information security risk management practices in Tanzanian higher education institut tions. East African Journal of Education and Social Sciences, 4(3), Article eajess2023v04i03.0294. https://doi.org/10.46606/eajess2023v04i03.0294
Lakens, D. (2013). Calculating and reporting effect sizes to facilitate cumulative science: A practical primer for t-tests and ANOVAs. Frontiers in Psychology, 4, 863. https://doi.org/10.3389/fpsyg.2013.00863
Ligaya, R. S., & Semlambo, A. A. (2024). Safeguarding digital frontiers: A study on cyberse curity threat mitigation in Tanzanian local governments. African Conference of Applied Informatics. https://journals.iaa.ac.tz/index.php/acai/article/view/369
Lubua, E. W., Semlambo, A. A., & Mkude, C. G. (2021). Factors affecting the security of information systems in Africa: A literature review. University of Dar es Salaam Li-brary Journal, 17(2), 121–138. https://doi.org/10.4314/udslj.v17i2.7
Maharani, W., Wulansari, P., & Sari, P. K. (2024). Indirect effect of transformational and trans actional leadership toward information security compliance behavior: A conceptual ap proach an healthcare. In Proceedings of the 2024 International Conference on Infor mation Technology and Cybersecurity. IEEE. https://ieeexplore.ieee.org/document/10913294
Mjema, L. H., Mgawe, B. S., & Dida, M. A. (2025). Innovating cybersecurity in Tanzanian academia: A mobile tool for combatting social engineering threats. Journal of Infor mation Security and Innovation, 1(2), Article 1034. https://www.journal-isi.journal-computing.org/index.php/isi/article/view/1034
Nunnally, J. C., & Bernstein, I. H. (1994). Psychometric theory (3rd ed.). McGraw-Hill.
Podsakoff, P. M., MacKenzie, S. B., Lee, J.-Y., & Podsakoff, N. P. (2003). Common method biases in behavioral research: A critical review of the literature and recommended rem edies. Journal of Applied Psychology, 88(5), 879–903. https://doi.org/10.1037/0021-9010.88.5.879
Rogers, R. W. (1975). A protection motivation theory of fear appeals and attitude change. The Journal of Psychology, 91(1), 93–114. https://doi.org/10.1080/00223980.1975.9915803
Rogers, R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. Cacioppo & R. Petty (Eds.), Social Psychophysiology: A Sourcebook (pp. 153–176). Guilford Press.
Semlambo, A. A., & Shalua, N. S. (2024). Strengthening Tanzania’s digital infrastructure: As sessing cyber threats to the government e-payment gateway for national security. Inter national Journal of Multidisciplinary and Current Educational Research, 6(4), 192–205. https://www.ijmcer.com/wp-content/uploads/2024/07/IJMCER_O0640192205.pdf
Vance, A., Siponen, M., & Pahnila, S. (2020). Motivating IS security compliance: Insights from protection motivation theory. Information & Management, 57(2), 103208. https://doi.org/10.1016/j.im.2019.103208


