Exploring Demographic Determinants of Information Systems Security Policy Compliance in Tanzanian Public Higher Learning Institution

Authors

  • Adam Semlambo Institute of Accountancy Arusha (IAA)

DOI:

https://doi.org/10.59645/tji.v5i1.709

Keywords:

Information Systems Security Policies, Compliance Behavior, Demographic Factors, Higher Learning Institutions

Abstract

Information Systems Security Policies (ISSPs) are critical for safeguarding digital infrastructures in higher education institutions. However, compliance remains inconsistent, particularly in developing contexts where demographic diversity may influence user behavior. While prior research has addressed general security challenges, limited empirical evidence exists on how specific demographic factors shape ISSP compliance in Tanzanian public universities. This study addressed that gap by examining the effects of age, education level, and work experience on compliance behavior. Guided by the Theory of Planned Behavior (TPB), a quantitative cross-sectional design was adopted, targeting a population of 2,727 employees across eight public higher learning institutions. A stratified random sample of 436 respondents was drawn, and data were analyzed using SPSS v26 through descriptive statistics, Chi-Square tests, and Automatic Linear Modeling (ALM). Results indicated that age and education were significant predictors of compliance behavior, particularly among mid-aged and higher-educated respondents, while work experience had no statistically significant effect. These findings underscore the need to tailor cybersecurity policies and training to demographic realities, emphasizing that compliance is better fostered through targeted awareness and professional development rather than institutional tenure alone. The study recommends that policymakers and institutional leaders adopt demographic-sensitive and behaviorally informed strategies to improve compliance and reduce institutional risk.

Downloads

Download data is not yet available.

References

Ahmed, A. A. A., & Abas, H. (2024). Factors influencing information security policy compli ance behavior in higher education institutions: Systematic literature review. Advances in Social Sciences Research Journal, 11(7), 260–273. https://doi.org/10.14738/assrj.117.17308

Ajzen, I. (1991). The theory of planned behavior. Organizational Behavior and Human Deci sion Processes, 50(2), 179–211. https://doi.org/10.1016/0749-5978(91)90020-T

Almuqrin, A., Mutambik, I., Alomran, A., & Zhang, J. Z. (2023). Enforcing information sys-tem security: Policies and procedures for employee compliance. International Journal on Semantic Web and Information Systems, 19(1), 1–17. https://doi.org/10.4018/IJSWIS.331396

Badreddine, S., Alwada’n, T., & Razzaque, M. A. (2025). Cybersecurity attitudes in higher education institutions: A behavioural analysis of faculty and staff in the United Arab Emirates. Applied Sciences and Technology, 9(10), 439–453. https://ideas.repec.org/a/ajp/edwast/v9y2025i10p439-453id10445.html

Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548.

Cochran, W. G. (1977). Sampling techniques (3rd ed.). Wiley.

Cohen, J. (1992). A power primer. Psychological Bulletin, 112(1), 155–159. https://doi.org/10.1037/0033-2909.112.1.155

Dunn, T. J., Baguley, T., & Brunsden, V. (2014). From alpha to omega: A practical solution to the pervasive problem of internal consistency estimation. British Journal of Psychol ogy, 105(3), 399–412. https://doi.org/10.1111/bjop.12046

Field, A. (2018). Discovering statistics using IBM SPSS statistics (5th ed.). Sage.

Hair, J. F., Black, W. C., Babin, B. J., & Anderson, R. E. (2019). Multivariate data analysis (8th ed.). Cengage.

Harrell, F. E., Jr. (2015). Regression modeling strategies (2nd ed.). Springer. https://doi.org/10.1007/978-3-319-19425-7

Herath, T., & Rao, H. R. (2009). Protection motivation and deterrence: A framework for secu rity policy compliance. Decision Support Systems, 47(2), 154–165. https://doi.org/10.1016/j.dss.2009.02.013

Ifinedo, P. (2012). Understanding information systems security policy compliance: An integra tion of the theory of planned behavior and the protection motivation theory. Comput-ers & Security, 31(1), 83–95. https://doi.org/10.1016/j.cose.2011.10.007

Kabanda, M. (2024). Information security awareness in sub-Saharan African schools: The role of educational leadership in turbulent times. SSRN. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4821616

Kline, R. B. (2016). Principles and practice of structural equation modeling (4th ed.). Guil-ford.

Kombo, F. S., Mwakalinga, P. G., Kumbo, L. I., Edward, L. M., & Bhalalusesa, N. P. (2023). Information security risk management practices in Tanzanian higher education institut tions. East African Journal of Education and Social Sciences, 4(3), Article eajess2023v04i03.0294. https://doi.org/10.46606/eajess2023v04i03.0294

Lakens, D. (2013). Calculating and reporting effect sizes to facilitate cumulative science: A practical primer for t-tests and ANOVAs. Frontiers in Psychology, 4, 863. https://doi.org/10.3389/fpsyg.2013.00863

Ligaya, R. S., & Semlambo, A. A. (2024). Safeguarding digital frontiers: A study on cyberse curity threat mitigation in Tanzanian local governments. African Conference of Applied Informatics. https://journals.iaa.ac.tz/index.php/acai/article/view/369

Lubua, E. W., Semlambo, A. A., & Mkude, C. G. (2021). Factors affecting the security of information systems in Africa: A literature review. University of Dar es Salaam Li-brary Journal, 17(2), 121–138. https://doi.org/10.4314/udslj.v17i2.7

Maharani, W., Wulansari, P., & Sari, P. K. (2024). Indirect effect of transformational and trans actional leadership toward information security compliance behavior: A conceptual ap proach an healthcare. In Proceedings of the 2024 International Conference on Infor mation Technology and Cybersecurity. IEEE. https://ieeexplore.ieee.org/document/10913294

Mjema, L. H., Mgawe, B. S., & Dida, M. A. (2025). Innovating cybersecurity in Tanzanian academia: A mobile tool for combatting social engineering threats. Journal of Infor mation Security and Innovation, 1(2), Article 1034. https://www.journal-isi.journal-computing.org/index.php/isi/article/view/1034

Nunnally, J. C., & Bernstein, I. H. (1994). Psychometric theory (3rd ed.). McGraw-Hill.

Podsakoff, P. M., MacKenzie, S. B., Lee, J.-Y., & Podsakoff, N. P. (2003). Common method biases in behavioral research: A critical review of the literature and recommended rem edies. Journal of Applied Psychology, 88(5), 879–903. https://doi.org/10.1037/0021-9010.88.5.879

Rogers, R. W. (1975). A protection motivation theory of fear appeals and attitude change. The Journal of Psychology, 91(1), 93–114. https://doi.org/10.1080/00223980.1975.9915803

Rogers, R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. Cacioppo & R. Petty (Eds.), Social Psychophysiology: A Sourcebook (pp. 153–176). Guilford Press.

Semlambo, A. A., & Shalua, N. S. (2024). Strengthening Tanzania’s digital infrastructure: As sessing cyber threats to the government e-payment gateway for national security. Inter national Journal of Multidisciplinary and Current Educational Research, 6(4), 192–205. https://www.ijmcer.com/wp-content/uploads/2024/07/IJMCER_O0640192205.pdf

Vance, A., Siponen, M., & Pahnila, S. (2020). Motivating IS security compliance: Insights from protection motivation theory. Information & Management, 57(2), 103208. https://doi.org/10.1016/j.im.2019.103208

Downloads

Published

2025-12-27

How to Cite

Semlambo, A. (2025). Exploring Demographic Determinants of Information Systems Security Policy Compliance in Tanzanian Public Higher Learning Institution. The Journal of Informatics, 5(1). https://doi.org/10.59645/tji.v5i1.709

Issue

Section

Articles