DocumentCode
2529952
Title
Security Usability Principles for Vulnerability Analysis and Risk Assessment
Author
Josang, Audun ; Alfayyadh, Bander ; Grandison, Tyrone ; Alzomai, Mohammed ; McNamara, Judith
Author_Institution
QUT, Brisbane
fYear
2007
fDate
10-14 Dec. 2007
Firstpage
269
Lastpage
278
Abstract
Usability is the weakest link in the security chain of many prominent applications. A set of security usability principles should therefore be considered when designing and engineering IT security solutions. When improving the usability of existing security applications, it is necessary to examine the underlying security technologies used to build them, and consider whether they need to be replaced by totally new security technologies that provide a better basis for good usability. This paper examines a set of security usability principles, proposes how they can be incorporated into the risk management process, and discusses the benefits of applying these principles and process to existing and future security solutions.
Keywords
risk management; security of data; IT security solution; risk assessment; risk management process; security usability principle; vulnerability analysis; Application software; Australia; Computer hacking; Computer security; Humans; Information analysis; Information security; Risk analysis; Risk management; Usability;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Security Applications Conference, 2007. ACSAC 2007. Twenty-Third Annual
Conference_Location
Miami Beach, FL
ISSN
1063-9527
Print_ISBN
978-0-7695-3060-4
Type
conf
DOI
10.1109/ACSAC.2007.14
Filename
4412995
Link To Document