A Stealth Approach to Usable Security: Helping IT Security Managers to Identify Workable Security Solutions
- Lookup NU author(s)
- Dr Simon Parkin
- Professor Aad van Moorsel
|
|
|
|
| Author(s) | | Parkin S, van Moorsel A, Inglesant P, Sasse MA |
| Editor(s) | | |
| Publication type | | Conference Proceedings (inc. Abstract) |
| Conference Name | | New Security Paradigms Workshop (NSPW) |
| Conference Location | | Concord, Massachusetts, USA |
| Year of Conference | | 2010 |
| Date | | 21-23 September 2010 |
| Volume | | |
| Pages | | 33-49 |
| ISBN | | 9781450304153 |
| |  |
|
|
|
| Full text for this publication is not currently held within this repository. Alternative links are provided below where available. |
|
|
|
|
| Recent advances in the research of usable security have produced many new security mechanisms that improve usability. However, these mechanisms have not been widely adopted in practice. In most organisations, IT security managers decide on security policies and mechanisms, seemingly without considering usability. IT security managers consider risk reduction and the business impact of information security controls, but not the impact that controls have on users. Rather than trying to remind security managers of usability, we present a new paradigm -- a stealth approach which incorporates the impact of security controls on users' productivity and willingness to comply into business impact and risk reduction. During two 2-hour sessions, 3 IT security managers discussed with us mock-up tool prototypes that embody these principles, alongside a range of potential usage scenarios (e.g. cloud-based password-cracking attacks and "hot-desking" initiatives). Our tool design process elicits findings to help develop mechanisms to visualise these tradeoffs. |
|
|
|
| Publisher | | ACM |
| Actions | |  |
| Library holdings | | Search Newcastle University Library for this item |