Prioritization also helps in establishing ranking lev-
els or classes of satisfaction levels that helps not just
in understanding the bank web portal current status
relative to other portals but also in encouraging the
bank to elevate to a more mature level through a set
of well-defined steps. The evaluation will be used as
an integral part of planning and hence should serve
their stakeholders. The evaluation framework should
be tailored to the evaluation purpose and stakehold-
ers intended objectives that include banks, customers,
and regulators. In fact, each evaluation framework
must have an associated set of well designed steps to
guide evaluation processes and activities.
Unfortunately, the current security and usability
frameworkneglects the web portal back-end solutions
which might play a key role in securing the online
banking services. The back-end solutions include the
adopted database servers, DMZ architecture, and core
network infrastructure components (e.g., firewall and
routers). All these solutions are integrated to form
the final system that provides the online banking ser-
vices to the customers. Furthermore, the used pro-
cesses during product and service development and
through service establishment, management, and de-
livery are not considered in the evaluation although
they are de facto components that affect the security
and usability of the final product or service. In short,
the framework is oriented towards the final product
rather than the used processes.
4 FURTHER DISCUSSION AND
FUTURE WORK
It is important to realize that the security and usabil-
ity are correlated and that it is preferable to evaluate
them as one block rather than separately in order to
capture their effects on each other. The evaluation
framework must be tailored to serve the needs of the
stakeholders without strong bias towards one over the
other. The stakeholders should be involve in all eval-
uation phases and should be part of any resolution.
Although such evaluations are considered milestones
for any quality improvement process, they should be
designed and tested within the quality improvement
process in order to ensure their coherence with other
parts in the process. With the online banking portals
evolving as an essential source for banking services
that are used by a majority of people, a more mature
security and usability evaluation framework is indeed
a necessity. In fact, in order to obtain an effective on-
line banking security and usability evaluation frame-
work, we need to leverage not just the existing frame-
works in the literature and the existing standards of
security best practices (such as NIST and ISO), but
also the feedback gathered by engaging the online
banking development and operational entities and the
corresponding stakeholders. Driven by the existing
needs and lessons learned from the conducted exper-
iment and the literature, we are looking to develop a
new effective and comprehensive framework that en-
compasses both essential and key evaluation security
and usability metrics.
ACKNOWLEDGEMENTS
We thank Mashael Almeatani, Nouf Alnufaie, Mona
Alsemayen, Njoud Alshehri, and Nora Alswailem for
helping in conducting the evaluation. We also thank
the anonymous reviewers for their comments which
helped improve this paper to its present form. This
work was supported in part by KACST.
REFERENCES
Aladwani, A. M. (2001). Online banking: a field study
of drivers, development challenges, and expectations.
International Journal of Information Management,
21(3):213–225.
Braz, C., Seffah, A., and M’Raihi, D. (2007). Designing
a trade-off between usability and security: A metrics
based-model. In Proceedings of the INTERACT07,
pages 114–126. Springer.
Casalo, L. V., Flavi´an, C., and Guinal´ıu, M. (2007). The
role of security, privacy, usability and reputation in the
development of online banking. Online Information
Review, 31(5):583–603.
Gutmann, P. and Grigg, I. (2005). Security usability. Secu-
rity Privacy, IEEE, 3(4):56–58.
Laukkanen, P., Sinkkonen, S., and Laukkanen, T. (2008).
Consumer resistance to internet banking: postpon-
ers, opponents and rejectors. International Journal of
Bank Marketing, 26(6):440–455.
Lichtenstein, S. and Williamson, K. (2006). Understanding
consumer adoption of internet banking: an interpre-
tive study in the australian banking context. Journal
of Electronic Commerce Research, 7(2):50–66.
Mannan, M. and van Oorschot, P. C. (2008). Security and
usability: the gap in real-world online banking. In
Proceedings of the 2007 Workshop on New Security
Paradigms, pages 1–14. ACM.
Seffah, A., Donyaee, M., Kline, R., and Padda, H. (2006).
Usability metrics: A roadmap for a consolidated
model. Journal of Software Quality, 14(2).
Subsorn, P. and Limwiriyakul, S. (2011). A comparative
analysis of the security of internet banking in aus-
tralia: A customer perspective.
WEBIST2015-11thInternationalConferenceonWebInformationSystemsandTechnologies
146