• DocumentCode
    3708342
  • Title

    A technique for using employee perception of security to support usability diagnostics

  • Author

    Simon Parkin;Sanket Epili

  • Author_Institution
    Department of Computer Science, University College London, London, United Kingdom
  • fYear
    2015
  • fDate
    7/1/2015 12:00:00 AM
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Problems of unusable security in organisations are widespread, yet security managers tend not to listen to employees´ views on how usable or beneficial security controls are for them in their roles. Here we provide a technique to drive management of security controls using end-user perceptions of security as supporting data. Perception is structured at the point of collection using Analytic Hierarchy Process techniques, where diagnostic rules filter user responses to direct remediation activities, based on recent research in the human factors of information security. The rules can guide user engagement, and support identification of candidate controls to maintain, remove, or learn from. The methodology was incorporated into a prototype dashboard tool, and a preliminary validation conducted through a walk-through consultation with a security manager in a large organisation. It was found that user feedback and suggestions would be useful if they can be structured for review, and that categorising responses would help when revisiting security policies and identifying problem controls.
  • Keywords
    "Interviews","Usability","Analytic hierarchy process","Human factors","Information security","Measurement"
  • Publisher
    ieee
  • Conference_Titel
    Socio-Technical Aspects in Security and Trust (STAST), 2015 Workshop on
  • Electronic_ISBN
    2325-1697
  • Type

    conf

  • DOI
    10.1109/STAST.2015.9
  • Filename
    7351970