CIS 524 Week 7 Case Study 3 Submission
Running Head: CASE STUDY 3: SECURITY 1
CASE STUDY 3: SECURITY 6
Case Study 3: Security
CIS 524 – Computer Interaction and Design
Dr. William Jett
Strayer University
May 18, 2019
Case Study 3: Security
Introduction
Security is a hot topic in technology, and it has been so for a while. Since the time that there had been something worth securing, there has been an effort in making it better and preventing from unauthorized access by users. It is becoming popular to talk about dealing with people as a factor in security these days. Any security professional that only concerns himself with strictly technical decisions to secure a system, and ignores the social factors of security, is not doing his job (Perrin, 2008). As interface designers, it is our job to understand the user, to design a better interface that will work for both the user and the security policies that needs to implement. The design does not make a user safe proof or smart enough to understand the concept of security; we must only design as viewing the user as our weakest link in security.
At the same time, a culture of security needs to be cultivated for it to work as a whole; a culture with a strong, positive emphasis on security helps people recognize the importance of following good security practices and adhering to policies (Perrin, 2008). As a goal, the case study will provide a framework in which the analysis of a newly installed register system will be performed to identify any design issues associated with the system. It will also provide ways to improve the system and relationship between security and usability by the user.
New System and Design Issues
Characteristics of the New System
· Each cashier has a user id and password combination to log in to the register.
· Allows the incorrect password to be entered four (4) times before the register would lock and require a manager to unlock it with a key card.
· Register lock after three (3) minutes if the screen was not touched.
· When locked, only the cashier who was logged in before it locking could unlock the register without a system restart.
· Enables the cashier to process transactions rapidly on an automated system using a touch screen interface.
At first, glance, because the system is fulfilling a business need, due to the growth in consumers it seems like a great fit for the fast food restaurant. Not only it is benefiting cashiers and the ability to work faster, but it is also making customer lines move faster. The system authentication control measures are also ideal for a situation where high traffic and money handling is an issue. With that said, there are indeed some design flaws or issues with the system.
Design Issues with the System
· The amount of time spent unlocking the registers.
· Cashiers were forgetting their user Id and password so that other cashiers would log in for them.
· Button layout makes it easy to key incorrect password.
· Reboot required if cashier stays logged in and register locks; creates a three to five (3-5) minute process to reboot the system and change user.
· Grease builds up on the touch screens, making them less responsive.
Correcting Design Issues
The first thing that we need to take into consideration when redesigning an interface to take care of user issues is the fact that even with the redesign, there will always be user conflicts on the design. Let's face it; humans are not perfect. Therefore they will not be perfect when interacting with a computer, and there will always be a set amount of environmental factor that will determine how a user works or interacts with the interface. With that said, considering human factors will improve security; it translates into higher acceptance of a system and fewer errors. Respecting user and his needs will gain cooperation since people like to be treated with respect (Vogt). One must also point that training and get used to the system will go a long way in gaining user acceptance and comfortability with the new processes in place. The case states that the users presented these conflicts just after a few days of use, and perhaps a larger trial period will mitigate the errors, giving the cashiers and managers to get used to the system.
But there are in fact improvements that could be done to address the presented issues. Following is the proposed solution for the points of conflicts presented above.
· The amount of time spent unlocking the registers: this situation is presented when the cashier tries to key in the password and does it incorrectly four times when login in. Even though there is not much a manager can do to have a cashier remember the password, there is a solution to the interface that would help. The use of key cards, instead of a keyboard to punch in a password, will completely remove the need for a cashier to remember a code or combination. These key cards can be enabled for cashier used, and it is assumed that the bar reader it is in place already, since there is already functionality for managers to unlock the register with a manager key card.
· Cashiers forgetting their user Id and password so that other cashiers would log in for them: the solution presented above, cashiers using key cards, will completely address this issue. With the use of a swipe card, there is no need for cashiers to remember the password. An option to key in manually might be a solution for cashiers that have forgotten to bring a card. As an alternative, these cards can be kept in the restaurant location to avoid cashiers forgetting to bring them every shift.
· Button layout makes it easy to key incorrect password: also addressed by the use of swipe cards. The layout of keys would not have to be redesigned to address this issue since the only interaction of it with the cashier login in will be in the event of the card not been present. In that case, the cashier is most likely to remember the password, and even though he doesn’t the situation will be minimal if the cards are kept in the restaurant.
· Reboot required if cashier stays logged in and register locks: this to me was the biggest flaw in the design above any. Not only it does create a waiting period were no interaction is done with the interface, otherwise known as workflow interruption, but it also forces for the restarting of the system. A simple option for the manger to be able to swipe his card to unlock the system and been able to log off any inactive cashiers account needs to be implemented. There is no reason for the interface to be rebooted, other than system maintenance or end of day process. Training is important to go to the cause of this issue as well. Cashiers need to be aware of their login status and must be aware of the severity of leaving a register locked.
· Grease builds up on the touch screens, making them less responsive: this issue, in my opinion, is unavoidable. Not only there is environmental grease associated with any fast food restaurant, but also the natural grease in the fingers of the human being. Having a swipe card will limit contact with the screen when login in or unlocking the screen, but the whole system is based on touch screen procedures for regular use. There are some solutions that will minimize the buildup, but it will not address it completely since cleaning the screen regularly is the only way that will keep it clean. Scratches, finger grease, dust, chemicals, and ultraviolet light can affect the performance of your touchscreen; a few things you can do to help protect the screen is to clean frequently and keep it covered (Microsoft, 2016). Applying a screen protector may go a long way, but cleaning it frequently as per manufacturers direction is the best solution.
Design Plan for Interface Improvements
The implementation of the new register in the fast food restaurant revealed a few things about it. In a nutshell, it was great in the point of view of security, since it tackled good security access control aspects like authentication and authorization. At the same time, the usability was affected since it was not widely accepted by all users, hence giving it a lower usability rate than desired. Hence the proposition of the design or redesign plans to address the gap between the two: security and usability. Remember as discussed before, even though we know the user is the weakest link, the interface needs to provide the balance so that the user does not feel threatened or disrespected, and simultaneously improving usability. The following tasks are needed to address the issues:
1. Employee Feedback: Questioners and interviews to collet concerns amongst the users, both cashiers and managers. Even though the concerns have been presented and that is the reason for the re-design, these concerns need to be documented to have a starting point. This process may also discover any other hidden conflicts that the designers are not aware. Questioners will be handled by users, and the system logs will be monitored to collect data pertinent to the system, for example, login and error logs. A two weeks period will be assigned for the completion of this task.
2. Initiation Phase: meetings with all the stakeholders to gather all resource information pertaining the project, including but not limited to team selection, financial cost, and schedule. One day to schedule and perform the meetings should be enough for this task.
3. Designing: Perform a research on the consumption of resources. Ten days will be allocated for research and twelve days to develop, test and document any significant changes to the current design. During these twelve days, the network, hardware, software, and security design of the new system will be performed. An analysis of the new button layout and compare with alternative screens will be performed. This task will enable the redesign team to be able to determine the best button layout of the interface that minimizes entering error.
4. Implementation: The installation and development of the system design, into an up and running state. The phase is estimated to be completed in three days. The new menu bar in the interface will have the option to reset the system in a situation when the cashier leaves without logging out or forget the access card.
5. Monitor Control Phase: It is used to provide continuous monitoring of the scheduled time, ensuring that the project is on schedule and informing management and stakeholders of progress. The phase is estimated to be completed in ten days.
6. Test Phase: Making sure the new system components are functioning as requested by the customers. The phase is estimated to be completed in two days.
7. Close Phase – Transfer of the new system over to the customer's trained staff with best practices, support requirements, and on hand training team. The phase is estimated to be completed in two days.
Security vs. Usability
According to Woods, security without usability does not work. Putting all effort in security solutions is only half the battle. To win the game of security, you must tackle hard problems such as usability, business process maturity and consistency, user training, network design, and optimization of your portfolio of applications. In other words, security without usability leads to failure (Woods, 2013). That is exactly what we are accomplishing with the redesign of the interface of this design. The system had security enabled, and it was focused on it, but there was no usability balance since the users were complaining only a few days after installed.
The new system incorporates security access control with the utilization of authentication with swipe cards. This ensures that only an authorized cashier can have access to the register and prevents another cashier from performing an uncontrolled transaction with someone else’ authentication. Because of authentication, the system becomes more usable to the user and accountability can be tracked through the system logs. Since there is no need for cashiers to remember or memorize passwords, the system becomes more usable as well. Another aspect of the system that incorporates security and usability is the automatic log out of the register after 3 minutes. The measure is effective since it prevents unauthorized users from accessing the register to perform a false transaction.
Changes to Improve Security and Usability of the System
There are a few changes that can be done to the system to increase usability but not necessarily affect security. One of the obvious once is to elevate the amount of time of automatically log off after inactivity. Currently, the system is automatically locking at three minutes, but increasing the amount to five or maybe eight minutes, will not affect security but will enhance system usability. Adding a way for the user to be unlocked if not present, not by a manager, but maybe by a power user or another team members credentials will be effective since there is no tradeoff between security and usability of the system. The system automatically will lock at eight minutes making it already secured, and it allows a different user to log in without having to wait for a manager. Changing the access control from password authentication to electronic card authentication was already a great step in leveraging usability vs. security. It does neither to affect security or usability, but the fact that cashiers will no longer have to memorize password eliminates one of the biggest conflicts presented initially.
Proposed Interface
Figure 1: Graphical Representation of Proposed Interface
Conclusion
There is a general convention that a secure system is a complicated and not a user-friendly or easy to use one. Through the propositions and research on this paper, we were able to determine that idea as a wrong one. A system can be both secure and highly usable, and the more focus on user-centric, and usable security, the more secure a system will be. The idea is to find the correct balance, to meet security standards as well as general user acceptance.
References
Microsoft. (2016). Clean and care for your Surface. Retrieved from Microsoft: https://www.microsoft.com/surface/en-us/support/performance-and-maintenance/clean-and-care-for-your-surface?os=windows-10&=undefined
Perrin, C. (2008, Jan 11). Interface design is security design. Retrieved from TechRepublic: http://www.techrepublic.com/blog/it-security/interface-design-is-security-design/
Vogt, T. (n.d.). User Interface vs. Security. Retrieved November 2016, from Lemuria: http://www.lemuria.org/security/UI_vs_Security.pdf
Woods, D. (2013, March 11). Why Security Without Usability Leads To Failure. Retrieved from Forbes: http://www.forbes.com/sites/danwoods/2013/03/11/why-security-without-usability-leads-to-failure/#3951060b7e19