Title :
Security Usability Principles for Vulnerability Analysis and Risk Assessment
Author :
Josang, Audun ; Alfayyadh, Bander ; Grandison, Tyrone ; Alzomai, Mohammed ; McNamara, Judith
Author_Institution :
QUT, Brisbane
Abstract :
Usability is the weakest link in the security chain of many prominent applications. A set of security usability principles should therefore be considered when designing and engineering IT security solutions. When improving the usability of existing security applications, it is necessary to examine the underlying security technologies used to build them, and consider whether they need to be replaced by totally new security technologies that provide a better basis for good usability. This paper examines a set of security usability principles, proposes how they can be incorporated into the risk management process, and discusses the benefits of applying these principles and process to existing and future security solutions.
Keywords :
risk management; security of data; IT security solution; risk assessment; risk management process; security usability principle; vulnerability analysis; Application software; Australia; Computer hacking; Computer security; Humans; Information analysis; Information security; Risk analysis; Risk management; Usability;
Conference_Titel :
Computer Security Applications Conference, 2007. ACSAC 2007. Twenty-Third Annual
Conference_Location :
Miami Beach, FL
Print_ISBN :
978-0-7695-3060-4
DOI :
10.1109/ACSAC.2007.14