Matches in SemOpenAlex for { <https://semopenalex.org/work/W4373063> ?p ?o ?g. }
- W4373063 abstract "The aim of the thesis is to investigate the relationship between human behaviour and effective security in order to develop tools and methods for supporting decision makers in the field of information security. A review of the literature of information security, Human Computer Interaction (HCI), and the economics of security reveals that role of users in delivering effective security has largely been neglected. Security designers working without an understanding of the limitations of human cognition implement systems that, by their nature, offer perverse incentives to the user. The result is the adoption of insecure behaviour by the users in order to cope with the burdens placed upon them. Despite HCI identifying the need for increased usability in security, much of the research in the field of HCI Security (HCISec) still focuses on improving the usability of the interface to security systems, rather than the underlying system itself. In addition, while the impact of user non-compliance on the effectiveness of security has been demonstrated, most security design methods still rely on technical measures and controls to achieve their security aims. In recent years the need to incorporate human factors into security decision making has been recognised but this process is not supported by appropriate tools or methodologies. The traditional CIA framework used to express security goals lacks the flexibility and granularity to support the analysis of the trade-offs that are taking place. The research gap is therefore not so much one of knowledge (for much of the required information does exist in the fields of security and HCI) but rather how to combine this knowledge to form an effective decision making framework. This gap is addressed by combining the fields of security and HCI with economics in order to provide a utility-based approach that allows the effective balancing and management of human factors alongside more technical measures and controls. The need to consider human effort as a limited resource is shown by highlighting the negative consequences of neglecting this axis of resource measurement. This need is expressed through the Compliance Budget model which treats users as perceptive actors conducting a cost/benefit analysis when faced with compliance decisions. Through the use of the qualitative data analysis methodology Grounded Theory, a set of semi-structured interviews were analysed to provide the basis for this model. Passwords form a running example throughout the thesis. The need to provide decision makers with empirical data grounded in the real world is recognised and addressed through a combination of data gathering techniques. A laboratory study and a field trial were conducted to gather performance data with two password policies. In order to make optimal use of this data, a unified approach to decision making is necessary. Alongside this, the usefulness of systems models as tools for simulation and analysis is recognised. An economically motivated framework is therefore presented that organises and expresses security goals with the methods required to fulfil them. The role of the user is fully represented in this framework which is structured in such a way as to allow a smooth transition from data gathering to systems modelling. This unified approach to optimising security decision making provides key insights into the requirements for making more effective real-world decisions in the field of information security and is a useful foundation for improving current practices in this area." @default.
- W4373063 created "2016-06-24" @default.
- W4373063 creator A5040188332 @default.
- W4373063 date "2013-09-28" @default.
- W4373063 modified "2023-09-24" @default.
- W4373063 title "Optimising information security decision making" @default.
- W4373063 cites W111619716 @default.
- W4373063 cites W128619364 @default.
- W4373063 cites W142213678 @default.
- W4373063 cites W1483280370 @default.
- W4373063 cites W1485200701 @default.
- W4373063 cites W1496144403 @default.
- W4373063 cites W1511039991 @default.
- W4373063 cites W1531869710 @default.
- W4373063 cites W1559155956 @default.
- W4373063 cites W1559498407 @default.
- W4373063 cites W1563185315 @default.
- W4373063 cites W1582830784 @default.
- W4373063 cites W1587049735 @default.
- W4373063 cites W1588904986 @default.
- W4373063 cites W164190891 @default.
- W4373063 cites W1651701101 @default.
- W4373063 cites W1658908529 @default.
- W4373063 cites W1729578042 @default.
- W4373063 cites W1972325829 @default.
- W4373063 cites W1983629106 @default.
- W4373063 cites W1991691398 @default.
- W4373063 cites W1997501517 @default.
- W4373063 cites W2010573758 @default.
- W4373063 cites W2042720915 @default.
- W4373063 cites W2045591401 @default.
- W4373063 cites W2056075452 @default.
- W4373063 cites W2074646350 @default.
- W4373063 cites W2084044852 @default.
- W4373063 cites W2097457752 @default.
- W4373063 cites W2097719378 @default.
- W4373063 cites W2106247215 @default.
- W4373063 cites W2107589078 @default.
- W4373063 cites W2119545418 @default.
- W4373063 cites W2124686424 @default.
- W4373063 cites W2128089745 @default.
- W4373063 cites W2132317998 @default.
- W4373063 cites W2136136174 @default.
- W4373063 cites W2150341374 @default.
- W4373063 cites W2151905266 @default.
- W4373063 cites W2157289187 @default.
- W4373063 cites W2168549506 @default.
- W4373063 cites W2169889946 @default.
- W4373063 cites W2170089455 @default.
- W4373063 cites W2171920515 @default.
- W4373063 cites W2172029077 @default.
- W4373063 cites W2303413189 @default.
- W4373063 cites W2369295637 @default.
- W4373063 cites W2394809607 @default.
- W4373063 cites W2397932998 @default.
- W4373063 cites W2397959131 @default.
- W4373063 cites W2400906922 @default.
- W4373063 cites W2402859497 @default.
- W4373063 cites W2626788661 @default.
- W4373063 cites W2739383818 @default.
- W4373063 cites W2912944677 @default.
- W4373063 cites W31171651 @default.
- W4373063 cites W59090339 @default.
- W4373063 cites W1511801995 @default.
- W4373063 cites W2031210270 @default.
- W4373063 cites W2396816275 @default.
- W4373063 hasPublicationYear "2013" @default.
- W4373063 type Work @default.
- W4373063 sameAs 4373063 @default.
- W4373063 citedByCount "0" @default.
- W4373063 crossrefType "dissertation" @default.
- W4373063 hasAuthorship W4373063A5040188332 @default.
- W4373063 hasConcept C103377522 @default.
- W4373063 hasConcept C105795698 @default.
- W4373063 hasConcept C107457646 @default.
- W4373063 hasConcept C111919701 @default.
- W4373063 hasConcept C112930515 @default.
- W4373063 hasConcept C114869243 @default.
- W4373063 hasConcept C121822524 @default.
- W4373063 hasConcept C144133560 @default.
- W4373063 hasConcept C148976360 @default.
- W4373063 hasConcept C162324750 @default.
- W4373063 hasConcept C170130773 @default.
- W4373063 hasConcept C175444787 @default.
- W4373063 hasConcept C184842701 @default.
- W4373063 hasConcept C195518309 @default.
- W4373063 hasConcept C2780598303 @default.
- W4373063 hasConcept C29122968 @default.
- W4373063 hasConcept C29983905 @default.
- W4373063 hasConcept C33923547 @default.
- W4373063 hasConcept C38652104 @default.
- W4373063 hasConcept C41008148 @default.
- W4373063 hasConcept C527648132 @default.
- W4373063 hasConcept C56739046 @default.
- W4373063 hasConcept C62913178 @default.
- W4373063 hasConcept C6353995 @default.
- W4373063 hasConcept C79974875 @default.
- W4373063 hasConceptScore W4373063C103377522 @default.
- W4373063 hasConceptScore W4373063C105795698 @default.
- W4373063 hasConceptScore W4373063C107457646 @default.