Usable Security and E-Banking: ease of use vis-a-vis security

Electronic banking must be secure and easy to use. An evaluation of six Danish web-based electronic banking systems indicates that the systems have serious weaknesses with respect to ease of use. Our analysis of the weaknesses suggests that security requirements are among their causes and that the w...

Full description

Bibliographic Details
Main Authors: Morten Hertzum, Niels Jørgensen, Mie Nørgaard
Format: Article
Language:English
Published: Australasian Association for Information Systems 2004-05-01
Series:Australasian Journal of Information Systems
Subjects:
Online Access:http://journal.acs.org.au/index.php/ajis/article/view/124
id doaj-0cad111d847a419f9a0a9f9cc0d8a36c
record_format Article
spelling doaj-0cad111d847a419f9a0a9f9cc0d8a36c2021-08-02T08:44:37ZengAustralasian Association for Information SystemsAustralasian Journal of Information Systems1449-86181449-86182004-05-0111210.3127/ajis.v11i2.124100Usable Security and E-Banking: ease of use vis-a-vis securityMorten HertzumNiels JørgensenMie NørgaardElectronic banking must be secure and easy to use. An evaluation of six Danish web-based electronic banking systems indicates that the systems have serious weaknesses with respect to ease of use. Our analysis of the weaknesses suggests that security requirements are among their causes and that the weaknesses may in turn cause decreased security. We view the conflict between ease of use and security in the context of usable security, a concept that is intended to match security principles and demands against user knowledge and motivation. Automation, instruction, and understanding can be identified as different approaches to usable security. Instruction is the main approach of the systems evaluated; automation relieves the user from involvement in security, as far as possible; and understanding goes beyond step-by-step instructions, to enable users to act competently and safely in situations that transcend preconceived instructions. We discuss the pros and cons of automation and understanding as alternative approaches to the design of web-based e-banking systems.http://journal.acs.org.au/index.php/ajis/article/view/124OZCHIsecuritybankingecommerceDenmark
collection DOAJ
language English
format Article
sources DOAJ
author Morten Hertzum
Niels Jørgensen
Mie Nørgaard
spellingShingle Morten Hertzum
Niels Jørgensen
Mie Nørgaard
Usable Security and E-Banking: ease of use vis-a-vis security
Australasian Journal of Information Systems
OZCHI
security
banking
ecommerce
Denmark
author_facet Morten Hertzum
Niels Jørgensen
Mie Nørgaard
author_sort Morten Hertzum
title Usable Security and E-Banking: ease of use vis-a-vis security
title_short Usable Security and E-Banking: ease of use vis-a-vis security
title_full Usable Security and E-Banking: ease of use vis-a-vis security
title_fullStr Usable Security and E-Banking: ease of use vis-a-vis security
title_full_unstemmed Usable Security and E-Banking: ease of use vis-a-vis security
title_sort usable security and e-banking: ease of use vis-a-vis security
publisher Australasian Association for Information Systems
series Australasian Journal of Information Systems
issn 1449-8618
1449-8618
publishDate 2004-05-01
description Electronic banking must be secure and easy to use. An evaluation of six Danish web-based electronic banking systems indicates that the systems have serious weaknesses with respect to ease of use. Our analysis of the weaknesses suggests that security requirements are among their causes and that the weaknesses may in turn cause decreased security. We view the conflict between ease of use and security in the context of usable security, a concept that is intended to match security principles and demands against user knowledge and motivation. Automation, instruction, and understanding can be identified as different approaches to usable security. Instruction is the main approach of the systems evaluated; automation relieves the user from involvement in security, as far as possible; and understanding goes beyond step-by-step instructions, to enable users to act competently and safely in situations that transcend preconceived instructions. We discuss the pros and cons of automation and understanding as alternative approaches to the design of web-based e-banking systems.
topic OZCHI
security
banking
ecommerce
Denmark
url http://journal.acs.org.au/index.php/ajis/article/view/124
work_keys_str_mv AT mortenhertzum usablesecurityandebankingeaseofusevisavissecurity
AT nielsjørgensen usablesecurityandebankingeaseofusevisavissecurity
AT mienørgaard usablesecurityandebankingeaseofusevisavissecurity
_version_ 1721237248205127680