Usable Security Flashcards

1
Q

What is Usable Security?

A

Design systems that make it easy for humans to keep it secure, looking at user’s needs
- What people are trying to do
- What else they need to do

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do we make Security Usable?

A
  • Make the secure path the most convenient one
  • Consider non-technical
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 3 things in Usable Security?

A

Focus on one, you have to compromise on the other two
- Security
- Usability
- Functionality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is 3 main principles when looking at UX vs Security?

A
  • Security that is difficult to use won’t be used
  • Security that gets in the way will be subverted
  • Security that is misunderstood will be misapplied
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is meant by Malicious Insiders?

A

People who intentionally attack or damage a system
- Disgruntled employees
- Employees seeking material gain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is meant by Accidental Insiders?

A

People who unintentionally cause harm
- Unmotivated employees
- Ignorant employees
- Genuine accident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is meant by User Behaviour?

A

Users may try to comply with security policies but fail, and may still lead to insecure behaviours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly