Deciding between information security and usability: Developing value based objectives

被引:33
作者
Dhillon, Gurpreet [1 ]
Oliveira, Tiago [2 ]
Susarapu, Santa [3 ]
Caldeira, Mario [4 ]
机构
[1] Virginia Commonwealth Univ, Sch Business, 301 West Main St, Richmond, VA 23284 USA
[2] NOVA, Informat Management Sch, Campus Campolide, P-1070312 Lisbon, Portugal
[3] KPMG, New York, NY USA
[4] Univ Lisbon, ISEG, Rua Miguel Lupi 20, P-1249078 Lisbon, Portugal
关键词
Security values; Usability values; Value focused-thinking; Qualitative methods; Instrument development; Quantitative methods; DATA QUALITY; USER; PERCEPTIONS; VALIDATION; PRIVACY; IMPACT; MODEL;
D O I
10.1016/j.chb.2016.03.068
中图分类号
B84 [心理学];
学科分类号
04 ; 0402 ;
摘要
Deciding between security and usability of systems remains an important topic among managers and academics. One of the fundamental problems is to balance the conflicting requirements of security and usability. We argue that definition of objectives for security and usability allows for deciding about the right balance between security and usability. To this effect we propose two instruments for assessing security and usability of systems, and develop them in three phases. In Phase 1 we identified 16 clusters of means and 8 clusters of fundamental objectives using the value-focused thinking approach and interviews with 35 experts. Based on phase 1, in the second phase we collected a sample of 201 users to purify, and ensure reliability and unidimensionality of the two instruments. In the third phase, based on a sample of 418 users we confirmed and validated the two instruments found in Phase 2. This resulted in 14 means objectives organized into four categories (minimize system interruptions and licensing restrictions, maximize information retrieval, maximize system aesthetics, and maximize data quality), and 10 fundamental objectives grouped into four categories (maximize standardization and integration, maximize ease of use, enhance system related communication, and maximize system capability). The objectives offer a useful basis for assessing the extent to which security and usability has been achieved in systems. The objectives also provide a decision basis for balancing security and usability. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:656 / 666
页数:11
相关论文
共 50 条
  • [1] Users are not the enemy
    Adams, A
    Sasse, MA
    [J]. COMMUNICATIONS OF THE ACM, 1999, 42 (12) : 41 - 46
  • [2] Security, Privacy and Usability - A Survey of Users' Perceptions and Attitudes
    Al Abdulwahid, Abdulwahid
    Clarke, Nathan
    Stengel, Ingo
    Furnell, Steven
    Reich, Christoph
    [J]. TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, 2015, 9264 : 153 - 168
  • [3] AlpAlparr G., 2013, J INFORM SYSTEM SECU, V9, P23
  • [4] A study on usability and security features of the Android pattern lock screen
    Andriotis, Panagiotis
    Oikonomou, George
    Mylonas, Alexios
    Tryfonas, Theo
    [J]. INFORMATION AND COMPUTER SECURITY, 2016, 24 (01) : 53 - 72
  • [5] [Anonymous], USENIX SECURITY
  • [6] [Anonymous], 1996, APPL MULTIVARIATE TE
  • [7] [Anonymous], 1978, Psychometric theory
  • [8] Defining and improving data quality in medical registries: A literature review, case study, and generic framework
    Arts, DGT
    de Keizer, NF
    Scheffer, GJ
    [J]. JOURNAL OF THE AMERICAN MEDICAL INFORMATICS ASSOCIATION, 2002, 9 (06) : 600 - 611
  • [9] Baskerville R.L., 1988, DESIGNING INFORM SYS
  • [10] A unified model of IT continuance: three complementary perspectives and crossover effects
    Bhattacherjee, Anol
    Lin, Chieh-Peng
    [J]. EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2015, 24 (04) : 364 - 373