[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-56435-en":3,"doc-seo-56435-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},56435,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Reducing Fraud in Organizations Through Information Security Policy Compliance: An Information Security Controls Perspective","Digitization increases misuse of computer resources for fraudulent activity, with trusted insiders causing substantial damage compared with external actors. The study investigates how compliance with organizations’ technology controls, focusing on information security, affects computer-based occupational fraud. Drawing on general deterrence and fraud triangle theories, it models information security control proficiency (ISCP) as the combined quality of information security policy and its enforcement. Empirical results show compliance mediates ISCP’s effect, and stronger policy compliance reduces fraud.","Computers & Security 144 (2024) 103958  \nContents lists available at ScienceDirect Computers & Security  \njournal [homepage: www.elsevier.com/locate/cose](homepage: www.elsevier.com/locate/cose)  \n| Reducing fraud in organizations through information security policy compliance: An information security controls perspective\u003Cbr>*\u003Cbr>Dennis Brown , Gunjan Batra , Humayun Zafar , Khawaja Saeed\u003Cbr>Kennesaw State University, Kennesaw, GA, USA |  |  |  |\n| --- | --- | --- | --- |\n| A R T I C L E I N F O |  | A B S T R A C T |  |\n| Keywords:\u003Cbr>Information security control proficiency\u003Cbr>Information security policy quality\u003Cbr>Information security Enforcement\u003Cbr>Computer based occupational fraud Information security policy compliance |  | As more business processes and information assets are digitized, computer resources are increasingly being misused to perpetrate fraudulent activities. Research shows that fraud committed by (or with) trusted insiders (called occupational fraud or internal organizational fraud) is responsible for significantly more damage than that committed by external actors (for example, cyber fraud). Current fraud research has primarily focused on the person perpetuating the fraud instead of the internal mechanisms organizations can employ in reducing fraud. The study examines the relationship between compliance with organizations’ technology controls (primarily focused on information security) and its impact on computer-based occupational fraud. Based on general deterrence and fraud triangle theories, the study proposes information security control proficiency (ISCP) modeled as an integration of the quality of information security policy and its enforcement as a key factor that influences information security policy compliance. We further postulate that compliance with information security policy mediates the relationship between information security control proficiency and computer-basedoccupational fraud. Empirical assessment supports the structure of the information security control proficiency construct. Model testing shows that information security control proficiency positively impacts information security policy compliance, which further deters the use of a company’s computer systems and resources to conduct fraudulent activities. Thus, if an organization establishes high-quality information security policies and supports the policies with effective enforcement, it correspondingly leads to better compliance. Furthermore, less fraud is committed when compliance with information security controls is high. We offer various managerial implications and future research extension ideas. |  |\n\n1. Introduction  \nFraud makes up 63 % of all white-collar crimes in the United States (Crimestats, 2022). Among different fraud types, occupational fraud has a higher occurrence, which, with increasing digitization, is primarily occurring as computer-based occupational fraud. This occurs when an employee, manager, or executive of the organization deceives the organization for personal gains, using its computer resources. Association of Certified Fraud Examiners (ACFE) report states that organizations lose about 5 % of their revenue to occupational fraud every year ($4.7 trillion dollars/year globally) (ACFE, 2022), nearly 50 % of which occurred due to internal control weaknesses (see Appendix 1) highlighting the importance of internal controls as a mechanism to tackle fraud. Scandals such as Enron and Worldcom resulted in the enactment of the Sarbanes Oxley Act of 2002 (SOX), which enacted requirements for internal controls for financial reporting and financial information systems in  \norganizations to reduce the possibility of corporate misconduct and to curtail corporate insider’s ability to do fraud and financial corruption (Gorshunov et al., 2020).  \nProficiency in the internal audit function enables organizations to improve oversight of processes and implement internal controls to reduce fraud (Sarens, 2006; Steinbart et","cbCaieBU2qQbTYEr","https://ap.wps.com/l/cbCaieBU2qQbTYEr","pdf",1185081,3,1,17,"English","en",105,"# Introduction\n## Background and Motivation\n## Research Gap and Study Focus\n## Key Theoretical Lens and Objectives","[{\"question\":\"What problem does the study address?\",\"answer\":\"The study addresses the rise of computer-based occupational fraud and the limited empirical evidence on how internal controls tied to security policies and enforcement reduce fraud in organizations.\"},{\"question\":\"How does the study define information security control proficiency (ISCP)?\",\"answer\":\"ISCP is modeled as an integration of the quality of an organization’s information security policy and the effectiveness of its enforcement.\"},{\"question\":\"What is the relationship between ISCP, policy compliance, and occupational fraud?\",\"answer\":\"Information security control proficiency increases information security policy compliance, and this compliance further helps deter fraudulent use of company computer systems and resources; compliance mediates the ISCP–fraud relationship.\"}]",1783892017,43,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"reducing-fraud-in-organizations-through-information-security-policy-compliance-an-information-security-controls-perspective","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/reducing-fraud-in-organizations-through-information-security-policy-compliance-an-information-security-controls-perspective/56435/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-20","2026-07-12",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the study address?","Question",{"text":75,"@type":76},"The study addresses the rise of computer-based occupational fraud and the limited empirical evidence on how internal controls tied to security policies and enforcement reduce fraud in organizations.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the study define information security control proficiency (ISCP)?",{"text":80,"@type":76},"ISCP is modeled as an integration of the quality of an organization’s information security policy and the effectiveness of its enforcement.",{"name":82,"@type":73,"acceptedAnswer":83},"What is the relationship between ISCP, policy compliance, and occupational fraud?",{"text":84,"@type":76},"Information security control proficiency increases information security policy compliance, and this compliance further helps deter fraudulent use of company computer systems and resources; compliance mediates the ISCP–fraud relationship.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]