Divide and conquer: the role of trust and assurance in the design of secure socio-technical systems

  • Authors:
  • Ivan Flechais;Jens Riegelsberger;M. Angela Sasse

  • Affiliations:
  • Oxford University Computing, UK - Oxford;University College London, UK - London;University College London, UK - London

  • Venue:
  • NSPW '05 Proceedings of the 2005 workshop on New security paradigms
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

In order to be effective, secure systems need to be both correct (i.e. effective when used as intended) and dependable (i.e. actually being used as intended). Given that most secure systems involve people, a strategy for achieving dependable security must address both people and technology. Current research in Human-Computer Interactions in Security (HCISec) aims to increase dependability of the human element by reducing mistakes (e.g. through better user interfaces to security tools). We argue that a successful strategy also needs to consider the impact of social interaction on security, and in this respect trust is a central concept. We compare the understanding of trust in secure systems with the more differentiated models of trust in social science research. The security definition of "trust" turns out to map onto strategies that would be correctly described as "assurance" in the more differentiated model. We argue that distinguishing between trust and assurance yields a wider range of strategies for ensuring dependability of the human element in a secure socio-technical system. Furthermore, correctly placed trust can also benefit an organisation's culture and performance. We conclude by presenting design principles to help security designers decide "when to trust" and "when to assure", and give examples of how both strategies would be implemented in practice.