Systematic Decision Making in Security Management: Modelling Password Usage and Support

David J. Pym, Simon Arnell, Adam Beautement, Philip Inglesant, Brian Monahan, Angela Sasse

Research output: Chapter in Book/Report/Conference proceedingPublished conference contribution

Abstract

We demonstrate the use of a systematic decision-making methodology to support an informed choice of a password policy. Our approach uses an executable system model, grounded in empirical data, to compare, using simulations, two different policy options. The problem is framed economically, with the basis of the comparison being a notion of organizational utility. We quantify utility in this case by considering breaches of system security, users' productivity, and investment in support operations. Using our results, we are able to explore trade-offs between these factors and thus determine the optimal policy configuration given the initial conditions.
Original languageEnglish
Title of host publicationHP Laboratories Technical Reports
PublisherHP Laboratories
Number of pages12
Publication statusPublished - 21 Mar 2011
EventQASA 2012 International Workshop on Quantitative Aspects in Security Assurance: Affiliated workshop with ESORICS - Pisa, Italy
Duration: 14 Sept 201214 Sept 2012

Conference

ConferenceQASA 2012 International Workshop on Quantitative Aspects in Security Assurance: Affiliated workshop with ESORICS
Country/TerritoryItaly
CityPisa
Period14/09/1214/09/12

Keywords

  • security analytics
  • security management
  • economics
  • password

Fingerprint

Dive into the research topics of 'Systematic Decision Making in Security Management: Modelling Password Usage and Support'. Together they form a unique fingerprint.

Cite this