Usability challenges in security and privacy policy-authoring interfaces

被引:0
|
作者
Reeder, Robert W. [1 ]
Karat, Clare-Marie [2 ]
Karat, John [2 ]
Brodie, Carolyn [2 ]
机构
[1] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
[2] IBM Corp, T J Watson Res Ctr, Hawthorne, NY 10532 USA
关键词
policy; policy-authoring; privacy; security; usability;
D O I
暂无
中图分类号
G2 [信息与知识传播];
学科分类号
05 ; 0503 ;
摘要
Policies, sets of rules that govern permission to access resources, have long been used in computer security and online privacy management; however, the usability of authoring methods has received limited treatment from usability experts. With the rise in networked applications, distributed data storage, and pervasive computing, authoring comprehensive and accurate policies is increasingly important, and is in creasingly performed by relatively novice and occasional users. Thus, the need for highly usable policy-authoring interfaces across a variety of policy domains is growing. This paper presents a definition of the security and privacy policy-authoring task in general and presents the results of a user study intended to discover some usability challenges that policy authoring presents. The user study employed SPARCLE, an enterprise privacy policy-authoring application. The usability challenges found include supporting object grouping, enforcing consistent terminology, making default policy rules clear, communicating and enforcing rule structure, and preventing rule conflicts. Implications for the design of SPARCLE and of user interfaces in other policy-authoring domains are discussed.
引用
收藏
页码:141 / +
页数:3
相关论文
共 50 条
  • [31] Designing natural language and structured entry methods for privacy policy authoring
    Karat, J
    Karat, CM
    Brodie, C
    Feng, JJ
    HUMAN-COMPUTER INTERACTION - INTERACT 2005, PROCEEDINGS, 2005, 3585 : 671 - 684
  • [32] Study of Usability of Security and Privacy in Context Aware Mobile Applications
    Pattan, Neha
    Madamanchi, Deepthi
    MOBILE COMPUTING, APPLICATIONS AND SERVICES, 2010, 35 : 326 - 330
  • [33] Evaluating Security, Privacy and Usability Features of QR Code Readers
    Wahsheh, Heider A. M.
    Luccio, Flaminia L.
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2019, : 266 - 273
  • [34] Developing and Validating a Set of Usability and Security Metrics for ATM Interfaces
    Falconi, Fiorella
    Moquillaza, Arturo
    Aguirre, Joel
    Paz, Freddy
    DESIGN, USER EXPERIENCE, AND USABILITY: UX RESEARCH AND DESIGN, DUXU 2021, PT I, 2021, 12779 : 225 - 241
  • [35] Automotive repairs, data accessibility, and privacy and security challenges: A stakeholder analysis and proposed policy solutions
    Hemphill, Thomas A.
    Longstreet, Phil
    Banerjee, Syagnik
    TECHNOLOGY IN SOCIETY, 2022, 71
  • [36] Cyber security challenges in Smart Cities: Safety, security and privacy
    Elmaghraby, Adel S.
    Losavio, Michael M.
    JOURNAL OF ADVANCED RESEARCH, 2014, 5 (04) : 491 - 497
  • [37] Usability, Security and Healthcare Systems: Design, Challenges and Perspectives
    Baklanoff, Tanya Ann
    Padath, Anish Abraham
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2012, 7 (06): : 366 - 376
  • [38] The seven flaws of identity management - Usability and security challenges
    Dhamija, Rachna
    Dusseault, Lisa
    IEEE SECURITY & PRIVACY, 2008, 6 (02) : 24 - 29
  • [39] Security and privacy in vehicular communications: Challenges and opportunities
    Bernardini, Cesar
    Asghar, Muhammad Rizwan
    Crispo, Bruno
    VEHICULAR COMMUNICATIONS, 2017, 10 : 13 - 28
  • [40] Big Data Analytics: Security and Privacy Challenges
    Gahi, Youssef
    Guennoun, Mouhcine
    Mouftah, Hussein T.
    2016 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2016, : 952 - 957