Personality traits in security user acceptance

TL;DR

There is a potential relationship between a user’s personality traits, as defined in the established ‘big-five’ psychological constructs (e.g., neuroticism, extraversion, openness to experience, agreeableness, conscientiousness), and the constructs ‘Trust’ and ‘Perceived Usefulness’ of intention to engage in mobile commerce, while the second study highlighted the potential that user awareness of security policy provides a significant driver for both ‘Perceived Usefulness’ (PU) and ‘Perceived Ease of Use’ (PEU). Perhaps a further union of constructs, expanded and altered for the uniqueness of security professionals as a group, could provide a more accurate model to test. This new model could replace ‘intention to engage in mobile commerce’ with ‘intention of implement a security control’ for security practitioners, ‘intention to implement known security best practices into an organization’s security program’ for security managers, and ‘intention follow security policy despite seniority’ for security executives. These, or possibly other behavioral intentions, would drive the development of survey questions and possibly establish a relationship between personality traits, security practice awareness, the standard TAMs constructs of ‘Perceived Usefulness’ (PU) and ‘Perceived Ease of Use’ (PEU), and new behavioral intentions.

Full Text

To understand of the implications of psychology on security control acceptance of security practitioners, a valid review of how personality traits are related is acceptable and could provide new insights. A model and study, outlined in an article entitled “The Effects of Personality Traits on User Acceptance of Mobile Commerce” by Tao Zhou and Yaobin Lu of the Hangzhou Dianzi University, provides potential method foundations (Zhou, T., & Lu, Y., 2011). The research described in the article reviews how the researchers examined the effects of the ‘big five’ personality traits with relation to user adoption of commerce on mobile devices, namely neuroticism, extraversion, openness to experience, agreeableness, and conscientiousness. The researchers examined previous literature which proposed a correlation between perceptions of technology and the behavioral drivers of Perceived Usefulness (PU), Perceived Ease of Use (PEOU), and Perceived Compatibility (PC). Continuing with this understanding, the researchers successfully showed a positive connection between extraversion and trust, and a negative connection between both neuroticism and perceived usefulness.

The H1 hypothesis, proposing a relationship between personality traits and security acceptance, is directly related to the subject and considerations reviewed in this method. There are differences in the target population of the article, mobile device users, and security practitioners’ interactions with security implementations. Any correlation showed between personality traits and technology acceptance provides relevant insight into how security acceptance could similarly be influenced.

How and Why

Tao’s research centered on a model demonstrating a relationship between the “big five” personality traits on both ‘Trust’ and ‘Perceived Usefulness’ which influence influence behavioral intention; as established in the Technology Acceptance Model, (Venkatesh, V., & Bala, H., 2008). The researchers developed a questionnaire which ensured each factor was measured with multiple questions. The items measured three aspects of each of the five personality traits. Since the model provides expansions beyond the typical use of the technology acceptance models, the researchers integrated components from previous mobile device acceptance research. ‘Trust’ measures were adopted from Lee (2005) to reflect the ability, integrity, and benevolence of the mobile service provider. They also took items to measure intention from Lee (2005) for continued usage, recommendation, and positive comments. The survey used a seven-point Likert scale.

The target population comprised randomly choosing users in the service halls for the two operators for mobile telecommunications, China Mobile and China Unicom. As this study focused on mobile commerce, the target populations where appropriate. The data collection resulted in 268 questionnaires with appropriately distributed demographics.

The results of the data collected through survey were potentially subject to misattribution because of ‘common method variance’ (CMV). The researchers identified this and tested for it using two methods 1) the Harmon’s single-factor test (Podsakoff, MacKenzie, Lee, &Podsakoff, 2003) and 2) modeling indicators as items of factors with the ‘common methods effects’ (Malhotra, Kim, & Patil, 2006). As a result, the researchers claim that common method variance (CMV) was not significant to research outcomes.

Once the researchers collected data, and common method variance (CMV) discounted, they began a two-step analysis. The initial step involved testing the reliability of and validity of their model. They tested for convergent and discriminant validities. The authors presented standardized loadings, t values, average variance extracted, composite reliability, and Cronbach’s alpha findings. Survey results were determined to be reliable, convergently valid, and discriminately valid by the tests. The researchers examined the structural model with ‘partial least squares’ (PLS) because of the study being explorative and targeting a medium sample (268 participants).

After analysis, they concluded that out of the “big five” personality traits, conscientiousness does not play a significant role, however, ‘trust’ is significantly influenced by extraversion, agreeableness, openness to new experience, and neuroticism. Also, perceived usefulness is significantly affected by neuroticism and agreeableness, and that trust strongly affects perceived usefulness and both influence behavioral intention.

Strengths

The study provides clear indications that the concept of studying the relationship between technology acceptance and personality traits is not only valid but supported by solid scientific method principles. In examining the potential use of this study’s methods for researching the potential link between personality traits and security acceptance, the primary strengths include relevance, sample outcome of interest, and provides approaches to validate results.

Relevance. The study followed a common pattern of hypothesis generations, model development, data collection through surveys, validation of data integrity and finally examination of results to provide a useful finding. Develop of the initial hypothesis and models were built on existing research into technology acceptance. Both its introduction of ‘Trust’ as a component of intention and behavior and its direct reference to the TAM’s perceived usefulness help lend support that similar models of security acceptance, also founded on TAM, can be examined to discover personality traits connections.

Sample outcome of interest. Perhaps the most significant outcome of interest is the conclusion proposed by the researchers that, because of the study findings, acceptance behavior for users higher in neuroticism could be affected by mitigation controls which are designed to improve the neurotic user’s trust levels. They suggested controls like a trial period, allowing cancellation of subscriptions at will, and providing outside, 3rd party, verification of service. This encourages the idea that for security professionals who are high in neuroticism (the tendency to experience negative feelings), security acceptance controls could be developed to increase that user’s trust in the program and / or implementation. I directly related this potential finding to the intended research to establish a relationship between security professionals and acceptance behaviors. For example, perhaps a security practitioner who is tasked with security control implementation could be provided a lab environment and the time needed to test the validity of the implementation to allow him or her to better trust the security control. Or the security practitioner may need to be allowed the time and opportunity to develop a trusted relationship with his or her security manager to improve the likelihood of acceptance.

Approaches to validate results. Because of the successful outcomes of the research results, future use of its methods could follow the provided template for testing structural reliability and validity of measurements. Additional literature review uncovers that this same pattern is employed across similar qualitative research studies. Referencing the analysis mechanism followed by the research provides a likely appropriate pattern for measurement model validation.

Limitations

Although similar in foundation and execution, this study focuses on different constructs than a security acceptance study, and the methods contain limitations. These limitations do, however, provide cautionary details which can improve the results of similar studies.

  1. The data collection methods involved in-person survey distribution and contacted participants at random. Although the target location was considered rich in mobile users, there were no proper controls implemented to provide certainty regarding that criterion.
  2. The study did not discriminate beyond participant location. No additional filter was applied to further ensure respondents included qualitative categorizations relevant to mobile commerce (e.g., level of current mobile use, length of time having a mobile device).
  3. A comparative study into personality traits and security practitioner acceptance behaviors would require either a broader survey approach through online platforms or locations, like security conferences, filtering participants based on inclusion in security program implementations.

Scientific Method Components

  1. Qualitative variables: Personality traits, extraversion, agreeableness, openness to new experience, and neuroticism.
  2. Non-experimentally clarified relationships between variables: “Among the five personality traits, extraversion, agreeableness, openness to new experience, and neuroticism have significant effects on trust, whereas agreeableness and neuroticism significantly affect perceived usefulness. Trust strongly affects perceived usefulness and both factors determine behavioral intention.” (Zhou, T., & Lu, Y., 2011).
  3. Control for confounds and prevent extraneous variables from influencing the findings: The surveyed population was targeted by location; the service halls of China Mobile and China Unicom. However, the authors observed that 1) most participants where young users, possibly influencing outcomes, 2) The Chinese mobile markets were relatively new, and that studies in other markets would provide cross-control for market types.
  4. Reasonably be extendable to test one or both proposed hypotheses. Someone could reasonably alter the study to measure security professionals’ willingness to adopt a security program (H1).

Ethics

 The study into personality traits of mobile commerce users did not include discussions or considerations for the ethics of the study. However, the study contains implied ethical considerations. Ethical principles of voluntary participation, informed consent, anonymity, confidentiality, potential for harm, and results communication where inherent in the public form participation outlined in the article’s review of how the study was conducted. Participants knew survey answers would be collected and used in the research. There is no indication that researches hid this intent from participants and so there is an implied consent. As researchers did not collect identity information from participants, both anonymity and confidentiality were maintained. The nature of the questions and survey data collection method can be reliability assumed to pose no physical or psychological harm to participants. And finally, the results of the survey are public and therefore available to participants. These factors establish that these research methods adhere to ethical codes of conduct appropriate for data collection and analysis.

Conclusion

The study focused on a potential relationship between a user’s personality traits, as defined in the established ‘big-five’ psychological constructs (e.g., neuroticism, extraversion, openness to experience, agreeableness, conscientiousness), and the constructs ‘Trust’ and ‘Perceived Usefulness’ of intention to engage in mobile commerce, while the second study highlighted the potential that user awareness of security policy provides a significant driver for both ‘Perceived Usefulness’ (PU) and ‘Perceived Ease of Use’ (PEU). Perhaps a further union of constructs, expanded and altered for the uniqueness of security professionals as a group, could provide a more accurate model to test. This new model could replace ‘intention to engage in mobile commerce’ with ‘intention of implement a security control’ for security practitioners, ‘intention to implement known security best practices into an organization’s security program’ for security managers, and ‘intention follow security policy despite seniority’ for security executives. These, or possibly other behavioral intention, would drive the development of survey questions and possibly establish a relationship between personality traits, security practice awareness, the standard TAMs constructs of ‘Perceived Usefulness’ (PU) and ‘Perceived Ease of Use’ (PEU), and new behavioral intentions.

The personality traits ‘extraversion’ and ‘neuroticism’ of security professionals likely influence their ‘Trust’ in an organization’s security program. Admittedly, this ‘Trust’ construct could relate more to:

  1. The competency of an organization’s:
    • security leadership, for practitioners.
    • executive leadership, for security management and executives.
  2. The quality of outcome for the security program or particular security control.

The personality trait ‘neuroticism’ may influence a security professionals’ perceived usefulness of the security controls to be implemented. The personality traits model should develop three security professional surveys (e.g., practitioners, managers, and executives) tailored to focus on trust in one’s leadership, trust in the security program / control, and perceived usefulness of the security program / control. Validated results could provide significant insights into a connection between personality traits and security professionals’ behaviors.

References:

Crossler, R. E., Johnston, A. C., Lowry, P. B., Hu, Q., Warkentin, M., & Baskerville, R. (2013). Future directions for behavioral information security research. Computers & Security, 32, 90-101. https://doi.org/https://doi.org/10.1016/j.cose.2012.09.010

Zhou, T., & Lu, Y. (2011). The Effects of Personality Traits on User Acceptance of Mobile Commerce. International Journal of Human–Computer Interaction, 27(6), 545-561. https://doi.org/10.1080/10447318.2011.555298

Related Post

Leave a Reply

Discover more from kobaltfox Labs

Subscribe now to keep reading and get access to the full archive.

Continue reading