
The number and range of organisations developing a Web site is growing rapidly. Many of these Web sites are developed in-house, even though the skills and resources required for developing a successful site may not be available. It is argued that some of the limitations, in terms of resources and skills, inherent in the small-scale, in-house development environment can be overcome through the adoption of an informal Web site development model and suitable usability methods. Presents an informal development model synthesised from a review of development case studies and published Web research literature. This model identifies the main stages and tasks of development. A review of information gathering and usability methods currently being employed is integrated into the model. The importance of understanding user and information provider needs is discussed. A number of common usability methods are then examined in greater detail. The appropriateness of the model and methods for the small-scale, in-house development environment is considered.
Reports on the first‐ever nationwide quantitative survey of academic staff use of the Internet. After briefly noting reasons for adopting a mailed‐out survey, the article discusses some of the results obtained. These include daily use of e‐mail, access to the Internet via remote dial‐in services and technical support provided to academics. More than one‐third of respondents seem in need of more training in Net use and time limitations and lack of training are typical barriers to effective use. The study concludes with opportunities for further research at both national and international levels and discusses possible implications for university administrators. The full report of the study is published as Academics Online (Auslib Press, Adelaide, 1998). The research team also included Edna Sharpe of the Australian Quarantine and Inspection Service.
Even though the human component has been recognized to have a crucial role in information systems (IS) security, the human issues have not received much attention. Recently a few approaches aimed at minimizing human‐related faults in the area of IS security have been put forward. This paper analyses different approaches aimed at minimizing user‐related faults. The existing approaches will be analysed from the viewpoint of their theoretical background, the research approaches employed, the research objectives and the organizational role of IS security. As a result, a new taxonomy, a comparison and critical analyses of the strengths and weaknesses of state‐of‐the‐art approaches shall be presented. Moreover, several issues that future research should explore and practitioners should consider when applying the results of the existing research are suggested.
A secure electronic marketplace involves a significant number of real‐time transactions between remote systems, either for commercial or for authentication purposes. The underlying infrastructure of choice to support these transactions seems to be a distributed component architecture. Distributed component software (DCS) is the natural convergence of client/server network computing and object oriented technology in a mix providing reusability, scaleability and maintainability for software constructs. In DCS a client acquires references to objects provided by components located to remote machines and invokes methods of them as if they were located in its native environment. One implementation also provides the ability to pass objects by value, an approach recently examined also by others. The three major models in the distributed component software industry are OMG’s CORBA, Sun’s Enterprise Java Beans, and Microsoft’s DCOM. Besides these, we will discuss the progress for interoperable DCS systems performed in TINA, an open architecture for telecommunications services based on CORBA distributed components. In this paper the security models of each architecture are described and their efficiency and flexibility are evaluated in a comparative manner. Finally, upcoming extensions are discussed.
The continuously increasing need for de‐centralized information systems offering data to the people who need them irrespective of their physical location, as well as the requirement for exchanging information between different but interoperable systems, make the system’s architectural and functional design more complex and in many cases extremely vulnerable in respect to its security attributes. The concept of a “secure portable information file”, that can nowadays be easily implemented through the available smart card technology, can significantly ease information management and ensure maximum data protection in respect to their integrity, confidentiality and availability. This paper presents the use of smart cards in an educational environment as a case‐study example for demonstrating the above mentioned benefits, focussing on the utilization of the smart card’s cryptographic functions for implementing mechanisms capable of providing an extremely secure operational framework in terms of user and application provider authenticity, management of access privileges and data integrity and confidentiality.