Adam Shostack: Usable Security


Adam Shostack is a cybersecurity professional with decades of experience in the industry. As such, Adam Shostack understands some of the prominent aspects of getting users to appreciate and easily understand the various issues of security. Indeed, usability is one of the overlooked aspects of security, as any controls built into a system that hinders a users' ability to accomplish their goals will either be ignored or bypassed in one way or another.
Security engineers have to build systems with their users in mind, and by building usable security functions, they help in making the system a secure one. One of the reasons why application security problems are common is because many deployed security measures are not exactly user-friendly. By thinking about how to make security usable, various security mechanisms will have a hard time gaining acceptance.
According to Adam Shostack, Security can be made usable in a number of ways. For starters, it can be understood so that users can actually realize they face a threat. A browser address bar turning red when accessing an insecure website is an example of this. Additionally, users can also be trained to recognize actual risks and how to deal with them.

Comments

Popular posts from this blog

A Review of Adam Shostack’s “Threat Modeling”

Learning Threat Modeling for Security Professionals, Course by: Adam Shostack

Adam Shostack: Passionate Professional