Australian Computer Society: ACS Digital Library
Not a member yet
884 research outputs found
Sort by
User Behaviours Associated with Password Security and Management
Control mechanisms established on the boundary of an information system are an important preliminary step to minimising losses from security breaches. The primary function of such controls is to restrict the use of information systems and resources to authorized users. Password-based systems remain the predominant method of user authentication despite the many sophisticated and viable security alternatives that have emerged from research and development. However, the literature shows that passwords are often compromised through the poor security and management practices of users. This paper examines user password composition and security practices for email accounts. The results of a survey that examines user practice in creating and using passwords are reported. The results show that many users know about the risks of hackers, viruses and so on and take preliminary steps to combat them such as having passwords longer than eight characters. However, this appears to be as far as many users are willing to accede to the probability that their information and computing resources can be compromised. This paper makes some recommendations for the education of users in creating and maintaining their passwords. The responsibility for these educational programs can be shared between governments, organisations, educational institutions at all levels, and software vendors
Penetration Testing Professional Ethics: a conceptual model and taxonomy
In an environment where commercial software is continually patched to correct security flaws, penetration testing can provide organisations with a realistic assessment of their security posture. Penetration testing uses the same principles as criminal hackers to penetrate corporate networks and thereby verify the presence of software vulnerabilities. Network administrators can use the results of a penetration test to correct flaws and improve overall security. The use of hacking techniques, however, raises several ethical questions that centre on the integrity of the tester to maintain professional distance and uphold the profession. This paper discusses the ethics of penetration testing and presents our conceptual model and revised taxonomy
Demonstrations of the Activity Theory Framework for Research in Information Systems
The holistic and insightful nature of the (cultural-historical) Activity Theory has led to its use by several researchers as a suitable vehicle for understanding and analysis in many areas of IS research and practice. This paper demonstrates the application of Activity Theory to the study of socio-technical systems which mediate complex, collective activities in the modern workplace and in everyday life. Vignettes from five ongoing research projects are reported in order to illustrate not only the explanatory power of the Activity Theory research framework but also its use in determining appropriate methods used to manage the data collection and analysis processes as well as its interpretation., The paper demonstrates the variety of IS topics where an Activity Theory based approach is able to add richness and insight
Recognition as a Distinguishing Criterion of IS Journals
The number of journals publishing information systems (IS) research has grown dramatically over the past few decades. This has resulted in an environment where authors have a wider choice of journals in which to place articles. Electronic journals are now as readily recognised by authorities as print journals. This paper provides firm evidence in support of the assertion that the number of journals publishing IS research has increased. The paper also examines the Australian context where the selection of a journal in which to place an article is influenced by recognition from the Department of Education Science and Training (DEST). In Australia, obtaining DEST recognition as a recognised research journal is not an onerous task, and yet a significant number of IS journals have not done this. Publishing in a DEST recognised journal is essential for Australian researchers to contribute to their organisation’s research quantum and hence research funding. Attention is drawn to an increasing number of IS journals not recognised by DEST, and consequent action is recommended
Assessing Joint Service Opportunities through a Consideration of the Motivating and Constraining Factors
In a wide range of industries services are increasingly being developed, or evolving, to support groups of organisations. Not all such joint service initiatives though have been successful. The paper aims to highlight potential issues that need to be addressed when investigating the introduction of a joint service by identifying the motivators and constraints. The approach outlined draws upon network externality theory to provide the motivation for a joint service, and resource based and dependency theories to highlight the constraining factors. Three instances of joint services – in the Banking, Telecommunications and Travel sectors – are subsequently examined. It is concluded that as well as providing externality benefits joint service initiatives can also improve the terms of access to a service – in particular through realising economies of scale. Furthermore it would appear that organisations will have to think carefully about the best way to create, structure and manage a joint service initiative – including who to partner with – given their own particular circumstances, as multiple alternative approaches, with potentially differing ramifications, are available
The State of Information Systems in Australian Universities - Tasmanian Report
This paper examines Information Systems at the University of Tasmania. The study draws upon a theoretical framework reported earlier. In common with studies conducted elsewhere in the region, this investigation utilised data collected on five themes. The study aimed to characterise Information Systems at the University of Tasmania, as well as to investigate the relationship between the impact of local contingencies on a discipline and its degree of professionalism, within the Tasmanian context. Data were collected through a qualitative survey with seven influential academics associated with the discipline at the University, and from statistical sources. The findings suggest that an inverse relationship exists between the impact of local factors and the degree of professionalism in this IS setting. A surprising finding was that the relationship found varied for research and teaching issues
A Review of Information Systems Programs in Universities in Victoria
This paper outlines the current situation of Information Systems (IS) programs within the State of Victoria, Australia. It reports on how Victorian Universities are addressing the challenges associated with reducing local and international student demand, and hence enrolments, at a time when IS in particular and ICT in general are seen by the business sector as necessary components contributing to organisational success. Transcripts of interviews with 14 academicians at nine universities throughout Victoria are analysed to give a current profile of IS programs and identify the trends in their development over time. First, a profile of the State of Victoria, its education system and its ICT industry is provided to place this work in context. Next, the interview sample is described and a number of relevant topics of interest are identified and discussed, comparing and contrasting the various programs. Finally, a summary of the findings is provided in light of the framework used to guide all of the studies of the Australian IS programs described in this special issue
Demystifying a Hermeneutic Approach to IS Research
While hermeneutics is firmly embedded in social science research and has proven merit as a qualitative research philosophy and data analysis technique, the majority of IS researchers continue to be hermeneutic neophytes. This paper seeks to promote and demystify this valuable but challenging tool, exploring the evolution of hermeneutics and its different approaches, presenting a brief overview of previous IS hermeneutic research, as reported in the literature and describing the applicability of hermeneutics to qualitative IS research In illustration, and in an attempt to smooth the way for other novice “hermeneuts”, it presents the choice and application of one hermeneutic approach based on the work of Ricoeur and Gadamer, in a research in progress. The paper concludes with a reflection on the value of the hermeneutic approach that was adopted in the research process and its contribution to IS research
An Empirical Study of Relationships Between Traditional Usability
Task performance data and subjective assessment data are widely used as usability measures in the human-computer interaction (HCI) field. Recently, physiology has also been explored as a metric for evaluating usability. However, it is not clear how physiological measures relate to traditional usability evaluation indexes. In this paper, we investigate the relationships among three kinds of data: task performance, subjective assessment and physiological measures. We found evidence that physiological data correlate with task performance data in a video game: with a decrease of the task performance level, the normalized galvanic skin response (GSR) increases. In addition, physiological data are mirrored in subjective reports assessing stress level. The research provides an initial step toward using physiology as a complementary or an independent usability measure for HCI evaluation