Allen C. Johnston

dblp:84/2377 · DBLP profile ↗
← Back
7ranked-venue papers in the field
2as first author
3since 2021 · last 2026
0000-0003-0301-4187ORCID · corroborated

Domains — venue-derived; a paper can count in several

Knowledge Engineering, Semantic Web & Information Systems · 7 (2 first)
YearPublicationVenuePosition
2026 Empowering health, integrating privacy: a value-reflexive examination of smart health technologies
abstract
A long-standing assumption in health information technology research is that health empowerment comes at the expense of privacy, a trade-off that has shaped how Smart Health Monitoring Systems (SHMSs) are designed, adopted, and studied. Yet, this framing overlooks the growing need to design technologies that enable empowerment without eroding trust, obscuring how privacy and empowerment can be integrated rather than opposed. In this study, we challenge the trade-off model by conducting a value-reflexive examination of SHMS use, grounded in a Value Sensitive Design ontological perspective. We reconceptualise privacy not as a constraint but as an embedded dimension of autonomy, solidarity, and authenticity that constitute empowerment. Through a mixed-methods study of SHMS users, we show that privacy concerns vary by life stage and health context, and that privacy-preserving features can strengthen empowerment. Our findings advance a value-integrated model of SHMS adoption that embeds privacy as a constitutive element of empowerment.
Farkhondeh Hassandoust, Allen C. Johnston
Eur. J. Inf. Syst.3
2025 From cyber benign to cyber malicious: unveiling the evolution of insider cyber maliciousness from a stage theory perspective
abstract
Insider cyber maliciousness presents a significant challenge to organizational security. Existing research has focused on identifying determinants of malicious cyber behavior but has not accounted for the progression insiders go through in arriving at the point where they look to harm their employers. This knowledge gap prevents organizations from potentially derailing acts of cyber maliciousness through timely interventions. Based on interviews with a cross-industry sample of organizational insiders, this study adopts a stage theory development approach to explore the progression of insiders from cyber benign to cyber malicious. Stage theories are useful frameworks that help explain how individuals’ perceptions, emotions, and/or behaviors progress through distinct and qualitatively different stages of development. By uncovering the initial, subsequent, and recurring perceptions and emotions that drive insiders to engage in malicious cyber activities, this research contributes to a deeper understanding of the phenomenon. Our findings establish a new basis for understanding insider cyber maliciousness, presenting it as an evolutionary progression. As such, our findings also reorient the focus of malicious insider interventions toward strain-reducing or strain-relieving interventions based on the initial, subsequent, or recurring strain experiences.
Allen C. Johnston, Sanjay Goel, Kevin J. Williams
Eur. J. Inf. Syst.1
2022 A neo-institutional perspective on the establishment of information security knowledge sharing practices
Farkhondeh Hassandoust, Maduka Subasinghage, Allen C. Johnston
Inf. Manag.3
2016 Dispositional and situational factors: influences on information security policy violations
abstract
Insiders represent a major threat to the security of an organization’s information resources. Previous research has explored the role of dispositional and situational factors in promoting compliant behavior, but these factors have not been studied together. In this study, we use a scenario-based factorial survey approach to identify key dispositional and situational factors that lead to information security policy violation intentions. We obtained 317 observations from a diverse sample of insiders. The results of a general linear mixed model indicate that dispositional factors (particularly two personality meta-traits, Stability and Plasticity) serve as moderators of the relationships between perceptions derived from situational factors and intentions to violate information security policy. This study represents the first information security study to identify the existence of these two meta-traits and their influence on information security policy violation intentions. More importantly, this study provides new knowledge of how insiders translate perceptions into intentions based on their unique personality trait mix.
Allen C. Johnston, Merrill Warkentin, Maranda E. McBride, Lemuria D. Carter
Eur. J. Inf. Syst.1
2011 The influence of the informal social learning environment on information privacy policy compliance efficacy and intention
abstract
Throughout the world, sensitive personal information is now protected by regulatory requirements that have translated into significant new compliance oversight responsibilities for IT managers who have a legal mandate to ensure that individual employees are adequately prepared and motivated to observe policies and procedures designed to ensure compliance. This research project investigates the antecedents of information privacy policy compliance efficacy by individuals. Using Health Insurance Portability and Accountability Act compliance within the healthcare industry as a practical proxy for general organizational privacy policy compliance, the results of this survey of 234 healthcare professionals indicate that certain social conditions within the organizational setting (referred to as external cues and comprising situational support, verbal persuasion, and vicarious experience) contribute to an informal learning process. This process is distinct from the formal compliance training procedures and is shown to influence employee perceptions of efficacy to engage in compliance activities, which contributes to behavioural intention to comply with information privacy policies. Implications for managers and researchers are discussed.
Merrill Warkentin, Allen C. Johnston, Jordan Shropshire
Eur. J. Inf. Syst.2
2010 Impact of Negative Message Framing on Security Adoption
Jordan Shropshire, Merrill Warkentin, Allen C. Johnston
J. Comput. Inf. Syst.3
2008 A Cross-Cultural Comparison of U.S. and Chinese Computer Security Awareness
abstract
Despite the recent increased attention afforded malware by the popular press, there appears to be a dearth in user awareness and understanding of certain aspects of the security paradigm. This article presents a comparison of user awareness levels of rootkits, spyware, and viruses between U.S. and Chinese users. The results of a survey of 210 U.S. respondents and 278 Chinese respondents indicate that respondents’ awareness and knowledge of rootkits is well below that of spyware and viruses. Data analysis further reveals that there are significant differences in Chinese and U.S. user perceptions with regard to spyware and computer viruses. However, there is no difference in cross-cultural awareness with regard to rootkits. Due to the ubiquitous nature of the Internet, rootkits and other malware do not yield at transnational borders. An important step to mitigate the threats posed by malware, such as rootkits, is to raise awareness levels of users worldwide.
Mark B. Schmidt, Allen C. Johnston, Kirk P. Arnett, Jim Q. Chen, Suichen Li
J. Glob. Inf. Manag.2