A Human Factors Vulnerability Evaluation Method for Computer and Information Security

There is a current lack of human factors identification and analysis methods in computer and information security. Previous research has focused on micro-level issues, such as task analyses and usability studies of security methods such as smart cards, passwords, and biometric devices. The purpose o...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Proceedings of the Human Factors and Ergonomics Society Annual Meeting 2003-10, Vol.47 (12), p.1389-1393
Hauptverfasser: Kraemer, Sara, Carayon, Pascale
Format: Artikel
Sprache:eng
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:There is a current lack of human factors identification and analysis methods in computer and information security. Previous research has focused on micro-level issues, such as task analyses and usability studies of security methods such as smart cards, passwords, and biometric devices. The purpose of this research is to develop a framework for identifying human factors and organizational issues contributing to computer and information security vulnerabilities and breaches. This framework is applied in conjunction with technical security audits. The purpose of this research is to test, develop, and refine the proposed methodology. This study examines the methodology with known computer and information technical vulnerabilities through semi-structured interviews with network administrators. These interviews yielded results in the form of methodology refinements and developments and two case studies of technical security vulnerabilities, using what is called the Human Factors Vulnerability Analysis, or HFVA.
ISSN:1541-9312
1071-1813
2169-5067
DOI:10.1177/154193120304701202