VLDB 2026 Research / reviewers in the wild / expert
Allen C. Johnston
dblp:84/2377
· DBLP profile ↗
16ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0003-0301-4187ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 7 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Understanding surveillance stress in cybersecurity professionals: A stage model perspective
Tripti Singh, Allen C. Johnston, Matthew Hudnall, Gregory Bott |
Comput. Secur. | 2 |
| 2026 | Empowering health, integrating privacy: a value-reflexive examination of smart health technologiesabstractA long-standing assumption in health information technology research is that health empowerment comes at the expense of privacy, a trade-off that has shaped how Smart Health Monitoring Systems (SHMSs) are designed, adopted, and studied. Yet, this framing overlooks the growing need to design technologies that enable empowerment without eroding trust, obscuring how privacy and empowerment can be integrated rather than opposed. In this study, we challenge the trade-off model by conducting a value-reflexive examination of SHMS use, grounded in a Value Sensitive Design ontological perspective. We reconceptualise privacy not as a constraint but as an embedded dimension of autonomy, solidarity, and authenticity that constitute empowerment. Through a mixed-methods study of SHMS users, we show that privacy concerns vary by life stage and health context, and that privacy-preserving features can strengthen empowerment. Our findings advance a value-integrated model of SHMS adoption that embeds privacy as a constitutive element of empowerment. Farkhondeh Hassandoust, Allen C. Johnston |
Eur. J. Inf. Syst. | 3 |
| 2025 | From cyber benign to cyber malicious: unveiling the evolution of insider cyber maliciousness from a stage theory perspectiveabstractInsider cyber maliciousness presents a significant challenge to organizational security. Existing research has focused on identifying determinants of malicious cyber behavior but has not accounted for the progression insiders go through in arriving at the point where they look to harm their employers. This knowledge gap prevents organizations from potentially derailing acts of cyber maliciousness through timely interventions. Based on interviews with a cross-industry sample of organizational insiders, this study adopts a stage theory development approach to explore the progression of insiders from cyber benign to cyber malicious. Stage theories are useful frameworks that help explain how individuals’ perceptions, emotions, and/or behaviors progress through distinct and qualitatively different stages of development. By uncovering the initial, subsequent, and recurring perceptions and emotions that drive insiders to engage in malicious cyber activities, this research contributes to a deeper understanding of the phenomenon. Our findings establish a new basis for understanding insider cyber maliciousness, presenting it as an evolutionary progression. As such, our findings also reorient the focus of malicious insider interventions toward strain-reducing or strain-relieving interventions based on the initial, subsequent, or recurring strain experiences. Allen C. Johnston, Sanjay Goel, Kevin J. Williams |
Eur. J. Inf. Syst. | 1 |
| 2023 | Seeking rhetorical validity in fear appeal research: An application of rhetorical theory
Allen C. Johnston, Paul M. Di Gangi, France Bélanger, Robert E. Crossler, Mikko Siponen, Merrill Warkentin, Tripti Singh |
Comput. Secur. | 1 |
| 2022 | A neo-institutional perspective on the establishment of information security knowledge sharing practices
Farkhondeh Hassandoust, Maduka Subasinghage, Allen C. Johnston |
Inf. Manag. | 3 |
| 2022 | Exposing the darkness within: A review of dark personality traits, models, and measures and their relationship to insider threats
P. D. Harms, Alexander Marbut, Allen C. Johnston, Paul Lester, Tyler Fezzey |
J. Inf. Secur. Appl. | 3 |
| 2021 | Individuals' privacy concerns and adoption of contact tracing mobile applications in a pandemic: A situational privacy calculus perspectiveabstractOBJECTIVE: The study sought to develop and empirically validate an integrative situational privacy calculus model for explaining potential users' privacy concerns and intention to install a contact tracing mobile application (CTMA). MATERIALS AND METHODS: A survey instrument was developed based on the extant literature in 2 research streams of technology adoption and privacy calculus. Survey participants (N = 853) were recruited from all 50 U.S. states. Partial least squares structural equation modeling was used to validate and test the model. RESULTS: Individuals' intention to install a CTMA is influenced by their risk beliefs, perceived individual and societal benefits to public health, privacy concerns, privacy protection initiatives (legal and technical protection), and technology features (anonymity and use of less sensitive data). We found only indirect relationships between trust in public health authorities and intention to install CTMA. Sex, education, media exposure, and past invasion of privacy did not have a significant relationship either, but interestingly, older people were slightly more inclined than younger people to install a CTMA. DISCUSSION: Our survey results confirm the initial concerns about the potentially low adoption rates of CTMA. Our model provides public health agencies with a validated list of factors influencing individuals' privacy concerns and beliefs, enabling them to systematically take actions to address these identified issues, and increase CTMA adoption. CONCLUSIONS: Developing CTMAs and increasing their adoption is an ongoing challenge for public health systems and policymakers. This research provides an evidence-based and situation-specific model for a better understanding of this theoretically and pragmatically important phenomenon. Farkhondeh Hassandoust, Saeed Akhlaghpour, Allen C. Johnston |
J. Am. Medical Informatics Assoc. | 3 |
| 2016 | Continuance of protective security behavior: A longitudinal study
Merrill Warkentin, Allen C. Johnston, Jordan Shropshire, William D. Barnett |
Decis. Support Syst. | 2 |
| 2016 | Dispositional and situational factors: influences on information security policy violationsabstractInsiders represent a major threat to the security of an organization’s information resources. Previous research has explored the role of dispositional and situational factors in promoting compliant behavior, but these factors have not been studied together. In this study, we use a scenario-based factorial survey approach to identify key dispositional and situational factors that lead to information security policy violation intentions. We obtained 317 observations from a diverse sample of insiders. The results of a general linear mixed model indicate that dispositional factors (particularly two personality meta-traits, Stability and Plasticity) serve as moderators of the relationships between perceptions derived from situational factors and intentions to violate information security policy. This study represents the first information security study to identify the existence of these two meta-traits and their influence on information security policy violation intentions. More importantly, this study provides new knowledge of how insiders translate perceptions into intentions based on their unique personality trait mix. Allen C. Johnston, Merrill Warkentin, Maranda E. McBride, Lemuria D. Carter |
Eur. J. Inf. Syst. | 1 |
| 2013 | Future directions for behavioral information security research
Robert E. Crossler, Allen C. Johnston, Paul Benjamin Lowry, Qing Hu 0003, Merrill Warkentin, Richard L. Baskerville |
Comput. Secur. | 2 |
| 2011 | The influence of the informal social learning environment on information privacy policy compliance efficacy and intentionabstractThroughout the world, sensitive personal information is now protected by regulatory requirements that have translated into significant new compliance oversight responsibilities for IT managers who have a legal mandate to ensure that individual employees are adequately prepared and motivated to observe policies and procedures designed to ensure compliance. This research project investigates the antecedents of information privacy policy compliance efficacy by individuals. Using Health Insurance Portability and Accountability Act compliance within the healthcare industry as a practical proxy for general organizational privacy policy compliance, the results of this survey of 234 healthcare professionals indicate that certain social conditions within the organizational setting (referred to as external cues and comprising situational support, verbal persuasion, and vicarious experience) contribute to an informal learning process. This process is distinct from the formal compliance training procedures and is shown to influence employee perceptions of efficacy to engage in compliance activities, which contributes to behavioural intention to comply with information privacy policies. Implications for managers and researchers are discussed. Merrill Warkentin, Allen C. Johnston, Jordan Shropshire |
Eur. J. Inf. Syst. | 2 |
| 2010 | Impact of Negative Message Framing on Security Adoption
Jordan Shropshire, Merrill Warkentin, Allen C. Johnston |
J. Comput. Inf. Syst. | 3 |
| 2008 | Information privacy compliance in the healthcare industryabstractPurpose The Health Insurance Portability and Accountability Act (HIPAA) is US legislation aimed at protecting patient information privacy, but it imposes a significant burden on healthcare employees, especially since the privacy provisions are still evolving and healthcare organizations are still struggling to meet compliance criteria. This study seeks to illuminate characteristics of both the environment (organization) and the individual (healthcare professional) and their relevant influence on compliance intentions by leveraging theories from the domains of social psychology, management, and information systems. Design/methodology/approach A study of 208 healthcare professionals located at healthcare facilities throughout the USA were surveyed as to their perceptions regarding HIPAA compliance and the underlying organizational and individual factors that influence said compliance. Findings The findings indicate that perceptions of organizational support and self‐efficacy (SE) leading to HIPAA compliance vary based on organizational and occupational characteristics. Furthermore, these perceptions of organizational support and SE explain some of the differences in their intent to comply with this legislation. Research limitations/implications For healthcare managers, the findings of this research may serve to validate HIPAA compliance initiatives. Through increased attention and resources dedicated to providing a supportive environment for HIPAA compliance, healthcare managers can increase the likelihood of compliance success by improving employee SE. Originality/value This paper represents the first empirical study to account for environmental factors and their influence on individual intentions to comply with HIPAA. Allen C. Johnston, Merrill Warkentin |
Inf. Manag. Comput. Secur. | 1 |
| 2008 | Information security management objectives and practices: a parsimonious frameworkabstractPurpose As part of their continuing efforts to establish effective information security management (ISM) practices, information security researchers and practitioners have proposed and developed many different information security standards and guidelines. Building on these previous efforts, the purpose of this study is to put forth a framework for ISM. Design/methodology/approach This framework is derived from the development of an a priori set of objectives and practices as suggested by literature, standards, and reports found in academia and practice; the refinement of these objectives and practices based on survey data obtained from 354 certified information security professionals; and the examination of interrelationships between the objectives and practices. Findings The empirical analysis suggests: four factors (information integrity, confidentiality, accountability, and availability) serve as critical information security objectives; most of the security areas and items covered under ISO 17799 are valid with one new area – “external” or “inter‐organizational information security”; and for moderately information‐sensitive organizations, “confidentiality” has the highest correlation with ISM practices; for highly information‐sensitive organizations, “confidentiality”, “accountability”, and “integrity” are the major ISM objectives. The most important contributor to information security objectives is “access control”. Research limitations/implications This study contributes to the domain of information security research by developing a parsimonious set of security objectives and practices grounded in the findings of previous works in academia and practical literature. Practical implications These findings provide insights for business managers and information security professionals attempting to implement ISM programs within their respective organizational settings. Originality/value This paper fulfills a need in the information security community for a parsimonious set of objectives and practices based on the many guidelines and standards available in both academia and practice. Qingxiong Ma, Allen C. Johnston, J. Michael Pearson |
Inf. Manag. Comput. Secur. | 2 |
| 2008 | A Cross-Cultural Comparison of U.S. and Chinese Computer Security AwarenessabstractDespite the recent increased attention afforded malware by the popular press, there appears to be a dearth in user awareness and understanding of certain aspects of the security paradigm. This article presents a comparison of user awareness levels of rootkits, spyware, and viruses between U.S. and Chinese users. The results of a survey of 210 U.S. respondents and 278 Chinese respondents indicate that respondents’ awareness and knowledge of rootkits is well below that of spyware and viruses. Data analysis further reveals that there are significant differences in Chinese and U.S. user perceptions with regard to spyware and computer viruses. However, there is no difference in cross-cultural awareness with regard to rootkits. Due to the ubiquitous nature of the Internet, rootkits and other malware do not yield at transnational borders. An important step to mitigate the threats posed by malware, such as rootkits, is to raise awareness levels of users worldwide. Mark B. Schmidt, Allen C. Johnston, Kirk P. Arnett, Jim Q. Chen, Suichen Li |
J. Glob. Inf. Manag. | 2 |
| 2007 | Rootkits and What we Know: Assessing US and Korean Knowledge and PerceptionsabstractRespondents from eight Korean and US higher education institutions were surveyed as to their knowledge and experience with various forms of computer malware. The surveys provide insight into knowledge of rootkits that have become coffee lounge discussion following the once secretive Sony rootkit news break in late 2005 and then the rash of accusations and acknowledgments of other rootkits that followed. The surveys provide an empirical assessment of perceptions between students in the two countries with regard to various forms of malware. The two groups are similar in many respects, but they exhibit significant differences in self-reported perceptions of rootkit familiarity. US respondents report higher levels of familiarity for all assessed malware types, including the fictional “Trilobyte” virus. A timeline-based comparison between virus and rootkit knowledge reveals that relatively little is known about rootkits today. This highlights dangers related to existing knowledge levels but presents hope for solutions and an accelerated rootkit awareness curve to improve worldwide malware protection. Kirk P. Arnett, Mark B. Schmidt, Allen C. Johnston, Jongki Kim, Ha Jin Hwang |
Int. J. Inf. Secur. Priv. | 3 |