论文标题
从高等教育组织中的2FA中学到的教训
Lessons Learnt from a 2FA roll out within a higher education organisation
论文作者
论文摘要
在组织中推出新的安全机制需要计划,良好的沟通,用户的采用,反思对所经历的挑战以及如何克服的反思。我们的案例研究引起了用户的看法,以反思我们在高等教育组织中推出的两个因素身份验证(2FA)机制的采用和使用。这是使用混合方法研究方法实现的。我们使用内容和主题编码的定性分析表明,最初SMS是最受欢迎的“第二个因素”,而2FA的主要可用性问题是使Authenticator应用程序正常工作。 IT团队意外的结果是出乎意料的,并导致了随后推出该技术的方式,以使Authenticator App成为默认的主要第二个因素。了解了用户所需的信息的一些课程;这包括如何在不同方案中使用技术,以及更广泛地了解为什么该技术对用户和组织有益。案例研究还强调了使用IT服务请求指标衡量组织的安全姿势的积极影响。
Rolling out a new security mechanism in an organisation requires planning, good communication, adoption from users, iterations of reflection on the challenges experienced and how they were overcome. Our case study elicited users' perceptions to reflect on the adoption and usage of the two factor authentication (2FA) mechanism being rolled out within our higher education organisation. This was achieved using a mixed method research approach. Our qualitative analysis, using content and thematic coding, revealed that initially SMS was the most popular 'second factor' and the main usability issue with 2FA was the getting the authenticator app to work; this result was unexpected by the IT team and led to a change in how the technology was subsequently rolled out to make the authenticator app the default primary second factor. Several lessons were learnt about the information users needed; this included how to use the technology in different scenarios and also a wider appreciation of why the technology was beneficial to a user and the organisation. The case study also highlighted a positive impact on the security posture of the organisation which was measure using IT service request metrics.