Guidelines for designing IT security management tools
Pooya Jaferian,David Botta,Fahimeh Raja,Kirstie Hawkey,Konstantin Beznosov +4 more
- 14 Nov 2008
- pp 7
TL;DR: A survey of design guidelines for IT security management tools is presented and a framework of guidelines can be used by those developing IT security tools, as well as by practitioners and managers evaluating tools.
read more
Abstract: An important factor that impacts the effectiveness of security systems within an organization is the usability of security management tools. In this paper, we present a survey of design guidelines for such tools. We gathered guidelines and recommendations related to IT security management tools from the literature as well as from our own prior studies of IT security management. We categorized and combined these into a set of high level guidelines and identified the relationships between the guidelines and challenges in IT security management. We also illustrated the need for the guidelines, where possible, with quotes from additional interviews with five security practitioners. Our framework of guidelines can be used by those developing IT security tools, as well as by practitioners and managers evaluating tools.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Hackers vs. Testers: A Comparison of Software Vulnerability Discovery Processes
Daniel Votipka,Rock Stevens,Elissa M. Redmiles,Jeremy Hu,Michelle L. Mazurek +4 more
- 20 May 2018
TL;DR: A semi-structured interview study with both testers and hackers, focusing on how each group finds vulnerabilities, how they develop their skills, and the challenges they face, suggests that hackers and testers follow similar processes, but get different results due largely to differing experiences.
Guidelines for usable cybersecurity: Past and present
Jason R. C. Nurse,Sadie Creese,Michael Goldsmith,Koen Lamberts +3 more
- 24 Oct 2011
TL;DR: This paper aims to contribute to the field by consolidating a number of existing design guidelines and defining an initial core list for future reference, and provides an up-to-date review of pertinent cybersecurity usability issues and evaluation techniques applied to date.
•Proceedings Article
A Human Capital Model for Mitigating Security Analyst Burnout
Sathya Chandran Sundaramurthy,Alexandru G. Bardas,Jacob Case,Xinming Ou,Michael Wesch,John McHugh,S. Raj Rajagopalan +6 more
- 01 Jan 2015
TL;DR: The model indicates that burnout is a human capital management problem resulting from the cyclic interaction of a number of human, technical, and managerial factors and multiple vicious cycles connecting the factors affecting the morale of the analysts are identified.
•Proceedings Article
Turning Contradictions into Innovations or: How We Learned to Stop Whining and Improve Security Operations
Sathya Chandran Sundaramurthy,John McHugh,Xinming Ou,Michael Wesch,Alexandru G. Bardas,S. Raj Rajagopalan +5 more
- 01 Jan 2016
TL;DR: This analysis provides evidence of the importance of conflict resolution as a prerequisite for operations improvement and helps to see a potentially successful and repeatable mechanism for introducing new technologies to future SOCs.
Heuristics for Evaluating IT Security Management Tools
Pooya Jaferian,Kirstie Hawkey,Andreas Sotirakopoulos,Maria C. Velez-Rojas,Konstantin Beznosov +4 more
TL;DR: This article explores how domain specific heuristics are created by examining prior research in the area of heuristic and guideline creation by describing the approach of creating usability heuristic for ITSM tools, which is based on guidelines for ITSm tools that are interpreted and abstracted with activity theory.
References
•Book
Qualitative inquiry and research design: choosing among five traditions.
John W. Creswell
- 01 Jan 1998
TL;DR: Creswell as mentioned in this paper explores the philosophical underpinnings, history and key elements of five qualitative inquiry traditions: biography, phenomenology, grounded theory, ethnography and case study.
26.2K
Ecological interface design: theoretical foundations
Kim J. Vicente,Jens Rasmussen +1 more
- 01 Jul 1992
TL;DR: A theoretical framework for designing interfaces for complex human-machine systems, based on the skills, rules, and knowledge taxonomy of cognitive control, is proposed, and three prescriptive design principles are suggested to achieve this objective.
Guidelines for using multiple views in information visualization
Michelle Q. Wang Baldonado,Allison Woodruff,Allan Kuchinsky +2 more
- 01 May 2000
TL;DR: Based on a workshop discussion of multiple views, and based on the authors' own design and implementation experience with these systems, eight guidelines for the design of multiple view systems are presented.
•Book
Security and Usability: Designing Secure Systems that People Can Use
Lorrie Faith Cranor,Simson L. Garfinkel +1 more
- 25 Aug 2005
TL;DR: Covered in: ICS 243G, Ch.
661
System guidelines for co-located, collaborative work on a tabletop display
Stacey D. Scott,Karen D. Grant,Regan L. Mandryk +2 more
- 14 Sep 2003
TL;DR: A critical analysis of the current state-of-the-art in digital tabletop systems research is presented, targeted at discovering how user requirements for collaboration are currently being met and uncovering areas requiring further development.
