• DocumentCode
    2529952
  • Title

    Security Usability Principles for Vulnerability Analysis and Risk Assessment

  • Author

    Josang, Audun ; Alfayyadh, Bander ; Grandison, Tyrone ; Alzomai, Mohammed ; McNamara, Judith

  • Author_Institution
    QUT, Brisbane
  • fYear
    2007
  • fDate
    10-14 Dec. 2007
  • Firstpage
    269
  • Lastpage
    278
  • Abstract
    Usability is the weakest link in the security chain of many prominent applications. A set of security usability principles should therefore be considered when designing and engineering IT security solutions. When improving the usability of existing security applications, it is necessary to examine the underlying security technologies used to build them, and consider whether they need to be replaced by totally new security technologies that provide a better basis for good usability. This paper examines a set of security usability principles, proposes how they can be incorporated into the risk management process, and discusses the benefits of applying these principles and process to existing and future security solutions.
  • Keywords
    risk management; security of data; IT security solution; risk assessment; risk management process; security usability principle; vulnerability analysis; Application software; Australia; Computer hacking; Computer security; Humans; Information analysis; Information security; Risk analysis; Risk management; Usability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2007. ACSAC 2007. Twenty-Third Annual
  • Conference_Location
    Miami Beach, FL
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3060-4
  • Type

    conf

  • DOI
    10.1109/ACSAC.2007.14
  • Filename
    4412995