Usability challenges in security and privacy policy-authoring interfaces

被引:0
|
作者
Reeder, Robert W. [1 ]
Karat, Clare-Marie [2 ]
Karat, John [2 ]
Brodie, Carolyn [2 ]
机构
[1] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
[2] IBM Corp, T J Watson Res Ctr, Hawthorne, NY 10532 USA
关键词
policy; policy-authoring; privacy; security; usability;
D O I
暂无
中图分类号
G2 [信息与知识传播];
学科分类号
05 ; 0503 ;
摘要
Policies, sets of rules that govern permission to access resources, have long been used in computer security and online privacy management; however, the usability of authoring methods has received limited treatment from usability experts. With the rise in networked applications, distributed data storage, and pervasive computing, authoring comprehensive and accurate policies is increasingly important, and is in creasingly performed by relatively novice and occasional users. Thus, the need for highly usable policy-authoring interfaces across a variety of policy domains is growing. This paper presents a definition of the security and privacy policy-authoring task in general and presents the results of a user study intended to discover some usability challenges that policy authoring presents. The user study employed SPARCLE, an enterprise privacy policy-authoring application. The usability challenges found include supporting object grouping, enforcing consistent terminology, making default policy rules clear, communicating and enforcing rule structure, and preventing rule conflicts. Implications for the design of SPARCLE and of user interfaces in other policy-authoring domains are discussed.
引用
收藏
页码:141 / +
页数:3
相关论文
共 50 条
  • [1] The Challenges,the Threats and Policy Implications to a Compromised Privacy and Security
    Shahata, Nader
    2018 INTERNATIONAL CONFERENCE ON NETWORKING AND NETWORK APPLICATIONS (NANA), 2018, : 314 - 317
  • [2] Usability of Policy Authoring Tools: A Layered Approach
    Weinhardt, Stephanie
    Omolola, Olamide
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2019, : 301 - 308
  • [3] Security and Privacy Concerns in Information Usability
    Yang, Liang-Chih
    2024 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION WORKSHOPS, WACVW 2024, 2024, : 679 - 684
  • [4] Security, Privacy, and Usability in Continuous Authentication: A Survey
    Baig, Ahmed Fraz
    Eskeland, Sigurd
    SENSORS, 2021, 21 (17)
  • [5] Analysis of an ehealth app: Privacy, security and usability
    Alturki R.
    AlGhamdi M.J.
    Gay V.
    Awan N.
    Kundi M.
    Alshehri M.
    International Journal of Advanced Computer Science and Applications, 2020, 11 (04): : 209 - 214
  • [6] Analysis of an eHealth app: Privacy, Security and Usability
    Alturki, Ryan
    AlGhamdi, Mohammed J.
    Awan, Nabeela
    Kundi, Mehwish
    Gay, Valerie
    Alshehri, Mohammad
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (04) : 209 - 214
  • [7] A Usability Study on The Privacy Policy Visualization Model
    Albalawi, Tahani
    Ghazinour, Kambiz
    2016 IEEE 14TH INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, 14TH INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, 2ND INTL CONF ON BIG DATA INTELLIGENCE AND COMPUTING AND CYBER SCIENCE AND TECHNOLOGY CONGRESS (DASC/PICOM/DATACOM/CYBERSC, 2016, : 578 - 585
  • [8] A usability study of security policy management
    Herzog, Almut
    Shahmehri, Nahid
    SECURITY AND PRIVACY IN DYNAMIC ENVIRONMENTS, 2006, 201 : 296 - +
  • [9] Security, Privacy, and Policy Roundup
    Garber, Lee
    IEEE SECURITY & PRIVACY, 2012, 10 (03) : 12 - 13
  • [10] Security, Privacy and Usability - A Survey of Users' Perceptions and Attitudes
    Al Abdulwahid, Abdulwahid
    Clarke, Nathan
    Stengel, Ingo
    Furnell, Steven
    Reich, Christoph
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, 2015, 9264 : 153 - 168