Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Hur autentiseringsregler kan bli användarvänliga: En systematisk litteraturstudie inom autentiseringsreglers användarvänlighet
Jönköping University, School of Engineering.
Jönköping University, School of Engineering.
2024 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesisAlternative title
How authentication policies can become user friendly (English)
Abstract [en]

The human factor often plays a significant role in cyberattacks targeted against organisations. Therefore, controlling user behaviour is critical to companies’ cybersecurity strengthening efforts. A method used by companies for this is information security policies (ISP). User compliance is required for policies to be able to regulate user behaviour, but research suggests that compliance is often low.

This study aims to improve authentication rules in ISP development by executing a systematic literature review. It does this by providing recommendations on how to better capture the user perspective based on the reviewed literature and the collected policies from the public sector. 

First a database search was conducted then backwards snowballing, which left us with 61 accepted articles that then underwent coding and ultimately a thematic analysis. This process identified eight key themes: authentication stress, password strength, password changing, password sharing, password reuse, password storage, user guidance and policy design. With these themes in hand, each area could be analysed and compared to corresponding area from the collected policies. This revealed discrepancies between the research and the organizational policies, enabling recommendations on how to improve policies from a user-based perspective to be put forward.

The study is limited to authentication rules found in information security policies and excludes rules that might be found in different documents. Additionally, the systematic literature review is limited to digital databases.

Place, publisher, year, edition, pages
2024. , p. 64
Keywords [en]
Information Security Policy (ISP), Policy Development, Authentication Policy, Information Security, Literature Review, User-centric, Recommendations
Keywords [sv]
Informationssäkerhetspolicy (ISP), Policyutveckling, Autentiseringspolicy, Lösenord, Informationssäkerhet, Litteraturstudie, Användarbaserad, Rekommendationer
National Category
Information Systems
Identifiers
URN: urn:nbn:se:hj:diva-65124OAI: oai:DiVA.org:hj-65124DiVA, id: diva2:1873575
Supervisors
Examiners
Available from: 2024-07-02 Created: 2024-06-19 Last updated: 2025-10-13Bibliographically approved

Open Access in DiVA

fulltext(948 kB)304 downloads
File information
File name FULLTEXT01.pdfFile size 948 kBChecksum SHA-512
a04ba774115aa768eff447f97da045cd9aa213e6d71305a41dacb09a3254eb1144d4d792389829ddd4f0e5266e3618269e3c17ff547118c3d17f59b0465a587f
Type fulltextMimetype application/pdf

By organisation
School of Engineering
Information Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 307 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 1803 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf