Sciweavers

CHIMIT
2007
ACM

Looking for trouble: understanding end-user security management

13 years 8 months ago
Looking for trouble: understanding end-user security management
End users are often cast as the weak link in computer security; they fall victim to social engineering and tend to know very little about security technology and policies. This paper challenges this view as derogatory and unconstructive, arguing that users, as agents of organizations, often have sophisticated strategies regarding sensitive data, and are quite cautious. Existing work on user security practice has failed to consider how users view security; this paper provides content on and analysis of end user perspectives on security management. We suggest that properly designed systems would bridge the knowledge gap (where necessary) and mask levels of detail (where possible), allowing users to manage their security needs in synchrony with the needs of the organization. The evidence for our arguments comes from a set of in-depth interviews with users with no special training on, knowledge of, or interest in computer security. We conclude with guidelines for security and privacy tool...
Joshua B. Gross, Mary Beth Rosson
Added 13 Aug 2010
Updated 13 Aug 2010
Type Conference
Year 2007
Where CHIMIT
Authors Joshua B. Gross, Mary Beth Rosson
Comments (0)