Scott Boss
- Associate Professor, Accounting
- SIGASYS Vice President - Region 1, Association for Information Systems
- SIGASYS AMCIS Program Chair, AIS
- Treasurer, Association for Information Systems (AIS)
- Ph.D. in Information Systems, University of Pittsburgh
- MAcc in Information Systems, Brigham Young University
- B.S. in Accounting, Brigham Young University
Teaching Interests
AIS
Systems Audit
Information Security
Research Interests
Control
Computer Security
Information Systems
Cybercrime
Information Systems Development
Bio
Scott Boss joined the Bentley Accountancy department after receiving his Ph.D. in Information Systems from the University of Pittsburgh in 2007. His research concentrates on information security, controls, and cybercrime and his work has been published in the European Journal of Information Systems and in Group and Organization Management.
Professional Memberships
Decision Sciences Institute 2011-11-01 - PresentInternational Federation for Information Processing WG 8.11/11.13 2009-05-01 - PresentAwards and Honors
Best Paper, International Symposium on Accounting Information SystemsAIS/SET Midyear Best Education Award, American Accounting AssociationGeorge Krull/Grant Thornton 2020 Teaching Innovation Award, American Institute of CPAsPhilip D. Cooper Award, North American Case Research AssociationValente Center Fellowship, Valente Center, Bentley University$600 Katz Doctoral Student Research GrantAMCIS Doctoral Consortium AttendeeICIS Doctoral Consortium AttendeeScholarly Contributions and Creative Productions
Journal Articles
Galletta, D., Moody, G., Lowry, P., Willison, R., Boss, S., Chen, Y., Luo, X., Pienta, D., Polak, P., Schuetz, S., Thatcher, J. (2025). Balancing Fear and Confidence: A Strategic Approach to Mitigating Human Risk in Cybersecurity. MIS Quarterly Executive, (24) Issue 1 (Link)Boss, S. R., Gray, J., Janvrin, D. (2022). Accountants, Cybersecurity isn't just for 'Techies': Incorporating Cybersecurity into the Accounting Curriculum. Issues in Accounting Education, (37) 3 73-89. Boss, S. R., Gray, J., Sarkar, S. (2021). Pedagogical Practices of Accounting Departments Addressing AACSB Technology Requirements. Issues In Accounting Education, (36) 4 59-85. Sumantra, S., Gray, J., Boss, S. R., Daly, E. (2021). Developing Institutional Skills for Addressing Big Data: Experiences in Implementation of AACSB Standard 5. Journal of Accounting Education Hunter, K. E., Alberti, C. T., Boss, S. R., Thibodeau, J. C. (2020). Intelliclean: A Teaching Case Designed to Integrate Data Cleaning and Spreadsheet Skills into the Audit Curriculum. Journal of Emerging Technologies in Accounting, (17) 2 7-Jan. Hunter, K., Alberti, C., Boss, S., Thibodeau, J. (2020). Intelliclean: A teaching case designed to integrate data cleaning and spreadsheet skills into the audit curriculum. Journal of Emerging Technologies in Accounting, (17) Issue 2 (Link)Dunn, C. L., Gerard, G. J., Grabski, S. V., Boss, S. R. (2017). Asymmetry in Identification of Multiplicity Errors. Journal of Information Systems (JIS) Boss, S. R. (2017). Asymmetry in Identification of Multiplicity Errors in Conceptual Models of Business Processes. Journal of Information Systems, (31) 1 21-39. (Link)Dunn, C. L., Gerard, G. J., Grabski, S. V., Boss, S. R. (2016). Asymmetry in Identification of Multiplicity Errors. Journal of Information Systems (JIS), (31) 1 21-39. Boss, S. R., Galletta, D., Moody, G., Lowrey, P. B., Polak, P. (2015). What Do Users Have to Fear? Using Fear Appeals to Engender Threats and Fear that Motivate Protective Behaviors in Users. MIS Quarterly, (39) 4 837-864. (Link)Chircu, A. M., Gogan, J. L., Boss, S. R., Baxter, R. J. (2013). Medication Errors, Handoff Processes and Information Quality: A Community Hospital Case Study. Business Process Management Journal, (19) 2 201-216. Gogan, J. L., Baxter, R. J., Boss, S. R., Chircu, A. M. (2013). Handoff Processes, Information Quality and Patient Safety: A Trans-Disciplinary Literature Review. Business Process Management Journal, (19) 1 70-94. Smith, A. L., Baxter, R. J., Boss, S. R., Hunton, J. E. (2012). The Dark Side of Online Knowledge Sharing. Journal of Information Systems. Journal of Information Systems, (26) 2 71-91. Abdolmohammadi, M. J., Boss, S. R. (2010). Factors associated with IT audits by internal audit functions. International Journal of Accounting Information Systems, (11) 3 140-151. Abdolmohammadi, M., Boss, S. (2010). Factors Associated with IT Audits by the Internal Audit Function. International Journal of Accounting Information Systems, (11) Issue 3 (Link)Boss, S. R., Kirsch, L. J., Angermeier, I., Shingler, R., Boss, R. W. (2009). If someone is watching, I'll do what I'm asked: Mandatoriness, Control, and Information Security. European Journal of Information Systems, (18) 2 151-164. Zagenczyk, T. J., Gibney, R., Murrell, A. J., Boss, S. R. (2008). Friends Don't Make Friends Perform OCB, But Advisors Do. Group and Organization Management Journal, (33) 6 760-780. Bagranoff, N., Boss, S. R. Sydney Building Supplies: A Cybersecurity System and Organization Controls (SOC) 2 Case. Issues in Accounting Education (In Progress)Boss, S. R., Gray, J., Janvrin, D. Be an Expert: Examining High Profile Cybersecurity Breaches. Issues in Accounting Education (Forthcoming)Gray, J., Boss, S. R. Hybrid Professions: The Case of Internal Auditors. Journal of Information Systems (In Progress)Schermann, M., Boss, S. R. The White-Collar Hacking Contest: A Case Study Approach to Teach Forensic Investigations in a Digital World. IFIP WG8.11/WG11.13 (In Progress)Lowrey, P. B., Galletta, D., Greg, G., Boss, S. R., Willison, R. From Rhetoric to Reality: What is The Rightful Place of Fear and Fear Appeals in Organizational Security Research and Practice?. MIS Quarterly (In Progress)Boss, S. R. Preventing Adverse Drug Events: Can Accounting Control Theory Help?. (In Progress)Lowrey, P. B., Moody, G., Galletta, D., Boss, S. R. Combining the Strengths of Protection Motivation Theory and the Extended Parallel Processing Model to Improve the Explanation of Organizational Information Security Intentions and Behaviors. JMIS (Link) (In Progress)Boss, S. R. Familiarity Breeds Content: How Fear of Cybercrime Influences Individual Precaution-Taking Behavior.. (In Progress)Boss, S. R. How to Convince Users to Protect Themselves Against Cybersecurity Threats. MIS Quarterly Executive (Forthcoming)Case Studies
Boss, S. R., Hunter, K. E. A Comprehensive Auditing Case Series: IntelliClean Risk Assessment and Audit Planning. (In Progress)Conference Proceedings
Boss, S. R., Janvrin, D., Wang, D., Reynolds, T., Conrad, C. F. (2026). “Real-Time Risk: Cybersecurity Materiality and Disclosure under the SEC’s New Rule” International AIS Symposium Melbourn, Australia Janvrin, D., Gray, J., Boss, S. (2020). “Accountants, Cybersecurity isn't just for 'Techies': Incorporating Cybersecurity into the Accounting Curriculum” 26th Americas Conference on Information Systems Atlanta, GA Dunn, C. L., Gerard, G. J., Grabski, S. V., Boss, S. R. (2013). “Asymmetry in Identification of Multiplicity Errors” Association for Information Systems Milan, Italy Boss, S. R., D'Arcy, J., Yezegel, A., Boss, R. W. (2012). “Security Profiling in the Organization: Examining Employment Relationship Effects on Information Security” IFIP Provo, UT Boss, S. R., D'Arcy, J., Galletta, D. (2011). “Examining Employment Relationship Effects on Information Security” Decision Sciences Institute Boston, MA Gogan, J. L., Boss, S. R., Sankaranarayanan, B., Linderman, J. L. (2011). “Controls in the NICU” North American Case Research Association San Antonio, Texas Chircu, A. M., Gogan, J. L., Baxter, R. J., Boss, S. R. (2011). “Handoffs and Medication Errors: A Community Hospital Case Study” Boss, S., Gogan, J. (2008). “Controls in the NICU” 30th International Conference on Information Systems,Slaughter, S., Ma, L., Diamant, E., Kirsch, L., Boss, S., Haney, M. (2007). “The formation and evolution of faultlines in large-scale, multi-party information systems development” 28th International Conference on Information Systems, 28th International Conference on Information Systems Montreal, Quebec, Canada Boss, S., Kirsch, L. (2007). “The last line of defense: Motivating employees to follow corporate security guidelines” 28th International Conference on Information Systems Montreal, Quebec, Canada Boss, S. (2005). “Control, risk, and information security precautions” 11th Americas Conference on Information Systems Omaha, NE Other Scholarly Work
Boss, S. R. (2014). The White-Collar Hacking Contest: A Novel Approach to Teach Fraud Investigations in a Digital World. Association for Information Systems (AIS), (SIGASYS Pre-conference Workshop of the International Conference on Information Systems (ICIS)) (Forthcoming).Boss, S. R. (2014). The White-Collar Hacking Contest: A Novel Approach to Teach Forensic Investigations in a Digital World. IFIP WG8.11/WG11.13, (Dewald Rood International Workshop on IS Security Research) (Forthcoming).Galletta, D.Targeting Information Security Efforts: Developing a User Profile of Security Effectiveness. (In Progress).Vance, A.The Multidimensionality of Information Security Precautions as a Dependent Variable. (In Progress).Boss, S. R. Common Company Settings in Accounting Education. (In Progress).Boss, S. R. Data Cleaning Case Study. (In Progress).Presentations
Boss, S. R. (1964). “Colonial Pipeline: An Instructional Case Involving Ransomware in the Energy Sector” Presented at the American Accounting Association American Accounting Association AIS/SET Midyear Meeting Boca Raton, FL Boss, S. R. (1964). “Cybersecurity: Challenges with Determining “Materiality"” Presented at the American Accounting Association American Accounting Association AIS/SET Midyear Meeting Boca Raton, FL Bagranoff, N., Boss, S. R. (2024). “Sydney Building Supplies A Cybersecurity System and Organization Controls (SOC)2 Case” Presented at the American Accounting Association AIS/SET Joint Midyear Conference Atlanta, GA Boss, S. R. (1964). “Cybersecurity in the Accounting Curriculum” Presented at the American Accounting Association American Accounting Association Annual Meeting Washington D.C. Boss, S. R. (1964). “How to Convince Users to Protect Themselves Against Cybersecurity Threats” Presented at the Association for Information Systems International Conference on Information Systems Hyderabad, India Boss, S. R., Gray, J., Janvrin, D. (2022). “Accountants, Cybersecurity isn‚Äôt just for ‚ÄòTechies‚Äô: Incorporating Cybersecurity into the Accounting Curriculum” Presented at the American Accounting Association AAA weARE WebinarGray, J., Boss, S. R., Janvrin, D. (2022). “How Would You Respond to High Profile Cybersecurity Breaches? Examining the Capital One, Equifax, and Target Frauds” Presented at the American Accounting Association AIS Bootcamp 2022 Chicago, IL Boss, S., Gray, J., Janvrin, D. (2021). “How Would You Respond to High Profile Cybersecurity Breaches? Evaluating the Capital One, Equifax, and Target Attacks” Presented at the American Accounting Association AIS/SET MidyearBoss, S. R. (2020). “Cybercrime and Information Security” Presented at the Bentley University Bentley University Cybersecurity Lectures Waltham, MA Boss, S. R., Gray, J., Janvrin, D. (2020). “How Would You Respond to High Profile Cybersecurity Breaches? Examining the Capital One, Equifax, and Target Frauds” Presented at the Brigham Young University BYU Accounting Research Symposium Provo, UT Boss, S. R., Gray, J., Janvrin, D. (2020). “Accountants, Cybersecurity isn‚Äôt just for ‚ÄòTechies‚Äô: Incorporating Cybersecurity into the Accounting Curriculum” Presented at the Association for Information Systems America's Conference on Information SystemsBoss, S. R., Gray, J., Janvrin, D. (2020). “Accountants, Cybersecurity isn't just for 'Techies:' Incorporating Cybersecurity into the Accounting Curriculum” Presented at the American Accounting Association American Accounting Association Annual MeetingBoss, S. R. (2019). “Cybercrime & Information Security” Presented at the Bentley Information Systems Department Cybersecurity Lunch & Learn Bentley University Gray, J., Boss, S. R., Abdolmohammadi, M. J., Sarens, G. (2019). “Correlates of Internal Audit‚Äôs Information Technology Audit Strategy” Presented at the European Academic Conference on Internal Audit and Corporate Governance Paris, France Sumantra, S., Gray, J., Boss, S. R., Daly, E. (2018). “Teaching Analytics in AIS ‚Äì the buzzword” Presented at the Association for Information Systems, SIGASYS International Conference on Information Systems 2018 Pre-Conference Sessions San Francisco, CA Gray, J., Abdolmohammadi, M. J., Boss, S. R., Sarens, G. (2018). “Hybrid Professions: The Case of Internal Auditors” Presented at the European Academic Conference on Internal Audit and Corporate Governance Parthenope University of Naples Gray, J., Boss, S. R. (2018). “Hybrid Professions: The Case of Internal Auditors” Presented at the Bentley University Scholarly Activities Bentley University Gray, J., Boss, S. R. (2017). “Hybrid Professions: The Case of Internal Auditors” Presented at the Bentley University 2017 Research Colloquium: The Future of Work Waltham, MA Gray, J., Abdolmohammadi, M. J., Boss, S. R., Sarens, G. (2017). “The Integrated Information Technology Audit in Internal Audit: Correlates of Internal Audit‚Äôs IT/ICT Strategy” Presented at the American Accounting Association AIS/SET Joint Midyear Conference Orlando, FL Schermann, M., Boss, S. R. (2014). “The White-Collar Hacking Contest: A Novel Approach to Teach Forensic Investigations in a Digital World” Presented at the Association for Information Systems SIGASYS Pre-conference Workshop of the International Conference on Information Systems (ICIS) Auckland, NZ Boss, S. R., Schermann, M. (2014). “The White-Collar Hacking Contest: A Novel Approach to Teach Forensic Investigations in a Digital World” Presented at the IFIP WG8.11/WG11.13 Dewald Rood International Workshop on IS Security Research Newcastle, UK Dunn, C. L., Gerard, G. J., Grabski, S. V., Boss, S. R. (2013). “Asymmetry in Identification of Multiplicity Errors” Presented at the Association for Information Systems SIGASYS Pre-conference Workshop of the International Conference on Information Systems (ICIS) Milan, Italy Boss, S. R., D'Arcy, J., Yezegel, A., Boss, R. W. (2012). “Security Profiling in the Organization: Examining Employment Relationship Effects on Information Security” Presented at the IFIP IFIP WG8.11/WG11.13 Dewald Rood International Workshop on IS Security Research Provo, UT Smith, A. L., Baxter, R. J., Boss, S. R., Hunton, J. E. (2012). “Will Programmers Circumvent Internal Control By Disclosing Proprietary Information Through Electronic Networks of Practice?” Presented at the American Accounting Association Information Systems Section Midyear Meeting Scottsdale, AZ Boss, S. R., D'Arcy, J., Galletta, D. (2011). “Examining Employment Relationship Effects on Information Security” Presented at the Decision Sciences Institute DSI Annual Meeting Boston, MA Gogan, J. L., Boss, S. R., Sankaranarayanan, B., Linderman, J. L. (2011). “Controls in the NICU” Presented at the North American Case Research Association North American Case Research Association (NACRA) Annual Meeting San Antonio, Texas Smith, A. L., Baxter, R. J., Boss, S. R., Hunton, J. E. (2011). “Will Programmers Circumvent Internal Control By Disclosing Proprietary Information Through Electronic Networks of Practice?” Presented at the Brigham Young University Accounting Research Symposium Provo, UT Boss, S. R., D'Arcy, J. (2010). “Targeting Information Security Efforts: The Influences of Job and Pay Satisfaction on Information Security Effectiveness” Presented at the AIS International Conference on Information Systems/MISQ Editors Pre-ICIS Workshop Saint Louis, MO Fedorowicz, J., Boss, S. R. (2010). “Federal support for information assurance education: Opportunities for accounting information systems programs” Presented at the AAA Information Systems Section Mid-year Meeting Clearwater Beach, FL Boss, S. R., Gogan, J. L. (2009). “Controls in the NICU” Presented at the International Conference on Information Systems Phoenix, AZ Abdolmohammadi, M. J., Boss, S. R. (2009). “Factors associated with IT audits by internal audit functions” Presented at the Information integrity Information Systems Integrity Toronto, CA (presented by co-author) Abdolmohammadi, M. J., Boss, S. R. (2009). “Factors associated with IT audits by internal audit functions” Presented at the University of Waterloo Information integrity Conference Waterloo, ON, Canada Boss, S. R., Kirsch, L. K., Angermeier, I., Shingler, R., Boss, R. W. (2009). “Familiarity Breeds Content: How Fear of Cybercrime Influences Individual Precaution-Taking Behavior” Presented at the IFIP TC8 International Workshop on IS Security Research Cape Town, South Africa Boss, S. R., Galletta, D. (2008). “Scared Straight: An Empirical Comparison of Two Major Theoretical Models Explaining User Backups” Presented at the International Research Symposium on Accounting Information Systems 2008 Pre-ICIS Conference Paris, France Boss, S. R., Gogan, J. L., Hunton, J. E. (2008). “A clinical information quality proposal” Presented at the MIT Information Quality Industry Symposium Boston, MA Kirsch, L. J., Slaughter, S. A., Haney, M. H., Boss, S. R., Ma, L., Doumpoulaki, E. (2007). “The Formulation and Evolution of Faultlines in Large Scale, Multi-Party Information Systems Development” Presented at the International Conference on Information Systems Montreal, Quebec, Canada Boss, S. R., Kirsch, L. J. (2007). “The Last Line of Defense: Motivating Employees to Follow Corporate Security Guidelines” Presented at the International Conference on Information Systems Montreal, Quebec, Canada Boss, S. R. (2006). “Control, Perceived Risk and Information Security Precautions: Developing a Theoretical Framework” Presented at the Academy of Management Annual Meeting Atlanta, GA Boss, S. R. (2006). “Empirical Evidence of Control and Risk Impacts on Intentions to Engage in Information Security Precautions” Presented at the Conference on Information Systems and Technology Pittsburgh, PA Zagenczyk, T. J., Murrell, A. J., Boss, S. R., Ptazsenski, M. (2005). “The Mediating Role of Job Involvement in the Relationship Between Social Networks and Organizational Citizenship Behavior” Presented at the Eastern Academy of Management Springfield, MA Gibbons, D. E., Butler, B. S., Boss, S. R. (2004). “When Shall I Tell? Relational Promotion and Timing of Information Technology Diffusion” Presented at the DIGIT Pre-Conference Workshop - ICIS 2004 Annual Conference Washington DC Service
Service: Department
Committee Member for Faculty Information Technology Advisory Group 2023-12-01 - PresentCommittee Member for MSAA Task Force 2016-09-01 - 2020-12-31Task Force Chair for MSA Task Force 2015-01-01 - 2016-09-30Task Force Member for MSA Task Force 2014-11-01 - 2016-09-30Committee Chair for Accountancy Strategy Committee 2012-09-01 - 2014-12-31Committee Member for Audit/AIS Coordination Committee 2007-09-01 - PresentService: Professional
Officer, Treasurer for Association for Information Systems 2022-08-01 - PresentOfficer, Vice President for Association for Information Systems 2017-01-01 - PresentEditor (Associate), Journal for Information Systems Frontiers 2015-01-01 - PresentConference/Workshop Track Chair for Americas Conference on Information Systems 2014-09-01 - PresentAAA Information Systems Section Member at Large for American Accounting Association 2010-01-01 - 2012-08-31Service: Ph.D. Advising
Supervisor 2020/04 - 2021/03Committee Member 2014/04 - 2017/01Service: University
University Senate for Faculty Senate 2015-09-01 - 2019-09-30Committee Member for Salary & Benefits 2014-05-01 - 2019-09-30