论文标题
让用户快速了解安全性:使用有说服力的工具包90分钟来促进信息安全问题解决的结果
Getting Users Smart Quick about Security: Results from 90 Minutes of Using a Persuasive Toolkit for Facilitating Information Security Problem Solving by Non-Professionals
论文作者
论文摘要
用户需要安全合规的需求与他们通常无法将大部分时间和精力用于该安全性的事实之间存在冲突。由于业务观点和安全性观点之间的优先级差异,很难实现平衡的用户参与度。我们试图找到一种方法来最少而有效地吸引用户吸引用户,以便他们既提高其安全意识,又可以提供必要的反馈,以改善安全设计师。我们已经开发了一个有说服力的软件工具包,以使用户对公司中的安全漏洞进行结构化讨论以及解决这些问题的潜在干预措施。在工具包中,我们通过常规预防犯罪的框架改编并整合了一个既定的框架。在这里报道的研究中,我们研究了非营利组织如何通过短期使用该工具包感知的安全问题。我们介绍了一项试点实验室研究的看法,在该研究中,随机招募的参与者不得不使用该工具包分析精心设计的内部威胁问题。结果表明,研究参与者能够成功识别原因,提出干预措施并从事有关拟议干预措施的反馈。随后的访谈表明,参与者对信息安全问题和解决这些问题的框架有了更大的认识,在真正的环境中,这最终将为组织带来重大利益。这些结果表明,当结构良好的短期参与度足以使用户有意义地参加复杂的安全讨论并深入了解安全的理论原理。
There is a conflict between the need for security compliance by users and the fact that commonly they cannot afford to dedicate much of their time and energy to that security. A balanced level of user engagement in security is difficult to achieve due to difference of priorities between the business perspective and the security perspective. We sought to find a way to engage users minimally, yet efficiently, so that they would both improve their security awareness and provide necessary feedback for improvement purposes to security designers. We have developed a persuasive software toolkit to engage users in structured discussions about security vulnerabilities in their company and potential interventions addressing these. In the toolkit we have adapted and integrated an established framework from conventional crime prevention. In the research reported here we examine how non-professionals perceived security problems through a short-term use of the toolkit. We present perceptions from a pilot lab study in which randomly recruited participants had to analyze a crafted insider threat problem using the toolkit. Results demonstrate that study participants were able to successfully identify causes, propose interventions and engage in providing feedback on proposed interventions. Subsequent interviews show that participants have developed greater awareness of information security issues and the framework to address these, which in a real setting would lead ultimately to significant benefits for the organization. These results indicate that when well-structured such short-term engagement is sufficient for users to meaningfully take part in complex security discussions and develop in-depth understanding of theoretical principles of security.