REWERSE-RP-2007-157

Almut Herzog, Nahid Shahmehri:
Usable Set-up of Runtime Security Policies.


In:
Information Management & Computer Security 15 (5), 394-407, July 2007
© Emerald Group Publishing Limited

Abstract
Purpose - This paper aims to present concrete and verified guidelines for enhancing the usability and security of software that delegates security decisions to lay users and captures these user decisions as a security policy. Design/methodology/approach - This work is an exploratory study. The authors hypothesised that existing tools for runtime set-up of security policies are not sufficient. As this proved true, as shown in earlier work, they apply usability engineering with user studies to advance the state-of-the-art. Findings - Little effort has been spent on how security policies can be set up by the lay users for whom they are intended. This work identifies what users want and need for a successful runtime set-up of security policies. Practical implications - Concrete and verified guidelines are provided for designers who are faced with the task of delegating security decisions to lay users. Originality/value - The devised guidelines focus specifically on the set-up of runtime security policies and therefore on the design of alert windows.

URL:
http://rewerse.net/publications/rewerse-publications.html#REWERSE-RP-2007-157

BibTeX:

@article{REWERSE-RP-2007-157,
	author = {Almut Herzog and Nahid Shahmehri},
	title = {Usable Set-up of Runtime Security Policies},
	journal = {Information Management & Computer Security},
	year = {2007},
	volume = {15},
	number = {5},
	pages = {394--407},
	url = {http://rewerse.net/publications/rewerse-publications.html#REWERSE-RP-2007-157}
}