Usability is the weakest link in the security chain of many prominent applications. A set of security usability prin- ciples should therefore be considered when designing and engineering IT security solutions. When improving the us- ability of existing security applications, it is necessary to examine the underlying security technologies used to build them, and consider whether they need to be replaced by to- tally new security technologies that provide a better basis for good usability. This paper examines a set of security usability principles, proposes how they can be incorporated into the risk management process, and discusses the bene- fits of applying these principles and process to existing and future security solutions.
Citation:
Audun J?sang, Bander AlFayyadh, Tyrone Grandison, Mohammed AlZomai, Judith McNamara, "Security Usability Principles for Vulnerability Analysis and Risk Assessment," acsac, pp.269-278, Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007), 2007