首页> 外文期刊>South African Computer Journal >Towards a framework for online information security applications development: A socio-technical approach
【24h】

Towards a framework for online information security applications development: A socio-technical approach

机译:建立在线信息安全应用程序开发的框架:一种社会技术方法

获取原文
       

摘要

The paper presents a validated socio-technical information security (STInfoSec) framework for the development of online information security (InfoSec) applications. The framework addresses both social and technical aspects of InfoSec design. The preliminary framework was developed using a mixed methods research design that collected data from 540 surveys by online banking users and six interviews with online banking personnel. The preliminary framework was presented in another publication and it is beyond the scope of this paper. The scope of this paper is limited to the validation findings of the evaluation process that involves seven evaluators. In the socio-technical context, the STInfoSec framework facilitates acceptance and usability of online applications based on online banking as a case study. The authors argue that usability of online InfoSec applications such as online banking significantly affects the adoption and continued use of such applications. As such, the paper investigates design principles for usable security and proposes a validated STInfoSec framework that consists of 12 usable security design principles. The design principles have been validated through heuristic evaluation by seven field experts for inclusion in the final STInfoSec framework. The development of InfoSec applications can be improved by applying these design principles.
机译:本文提出了一种经过验证的社会技术信息安全(STInfoSec)框架,用于开发在线信息安全(InfoSec)应用程序。该框架涉及InfoSec设计的社会和技术方面。初步框架是使用混合方法研究设计开发的,该设计从在线银行用户的540次调查中收集了数据,并进行了六次在线银行人员访谈。该初步框架已在另一出版物中提出,这超出了本文的范围。本文的范围限于涉及七个评估人员的评估过程的验证结果。在社会技术背景下,STInfoSec框架可促进基于在线银行业务的在线应用程序的接受和可用性。作者认为,在线银行等在线InfoSec应用程序的可用性极大地影响了此类应用程序的采用和持续使用。因此,本文研究了可用安全设计原则,并提出了一个经过验证的STInfoSec框架,该框架包含12种可用安全设计原则。设计原则已经通过七位专家的启发式评估得到验证,可以纳入最终的STInfoSec框架。通过应用这些设计原则,可以改进InfoSec应用程序的开发。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号