Title :
A technique for using employee perception of security to support usability diagnostics
Author :
Simon Parkin;Sanket Epili
Author_Institution :
Department of Computer Science, University College London, London, United Kingdom
fDate :
7/1/2015 12:00:00 AM
Abstract :
Problems of unusable security in organisations are widespread, yet security managers tend not to listen to employees´ views on how usable or beneficial security controls are for them in their roles. Here we provide a technique to drive management of security controls using end-user perceptions of security as supporting data. Perception is structured at the point of collection using Analytic Hierarchy Process techniques, where diagnostic rules filter user responses to direct remediation activities, based on recent research in the human factors of information security. The rules can guide user engagement, and support identification of candidate controls to maintain, remove, or learn from. The methodology was incorporated into a prototype dashboard tool, and a preliminary validation conducted through a walk-through consultation with a security manager in a large organisation. It was found that user feedback and suggestions would be useful if they can be structured for review, and that categorising responses would help when revisiting security policies and identifying problem controls.
Keywords :
"Interviews","Usability","Analytic hierarchy process","Human factors","Information security","Measurement"
Conference_Titel :
Socio-Technical Aspects in Security and Trust (STAST), 2015 Workshop on
Electronic_ISBN :
2325-1697
DOI :
10.1109/STAST.2015.9