Evaluating information security core human error causes (IS-CHEC) technique in public sector and comparison with the private sector

被引:22
作者
Evans, Mark [1 ]
He, Ying [1 ]
Maglaras, Leandros [1 ]
Yevseyeva, Iryna [1 ]
Janicke, Helge [1 ]
机构
[1] De Montfort Univ, Cyber Secur Ctr, Leicester, Leics, England
关键词
Information security; Human error assessment and reduction technique (HEART); Information security core human error causes (IS-CHEC); Human error related information security incidents; Human reliability analysis (HRA); POLICY COMPLIANCE; PROTECTION MOTIVATION; HEALTH-CARE; SYSTEMS; VIOLATIONS; BEHAVIORS; DETERRENCE; INSIGHTS; VALIDATION; ADHERENCE;
D O I
10.1016/j.ijmedinf.2019.04.019
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Background: The number of reported public sector information security incidents has significantly increased recently including 22% related to the UK health sector. Over two thirds of these incidents pertain to human error, but despite this, there are limited published related works researching human error as it affects information security. Method: This research conducts an empirical case study into the feasibility and implementation of the Information Security Core Human Error Causes (IS-CHEC) technique which is an information security adaptation of Human Error Assessment and Reduction Technique (HEART). We analysed 12 months of reported information security incidents for a participating public sector organisation providing healthcare services and mapped them to the IS-CHEC technique. Results: The results show that the IS-CHEC technique is applicable to the field of information security but identified that the underpinning HEART human error probability calculations did not align to the recorded incidents. The paper then proposes adaptation of the IS-CHEC technique based on the feedback from users during the implementation. We then compared the results against those of a private sector organisation established using the same approach. Conclusions: The research concluded that the proportion of human error is far higher than reported in current literature. The most common causes of human error within the participating public sector organisation were lack of time for error detection and correction, no obvious means of reversing an unintended action and people performing repetitious tasks.
引用
收藏
页码:109 / 119
页数:11
相关论文
共 62 条
[1]   Design and validation of information security culture framework [J].
AlHogail, Areej .
COMPUTERS IN HUMAN BEHAVIOR, 2015, 49 :567-575
[2]  
[Anonymous], 2017, 2017 COST DAT BREACH
[3]  
[Anonymous], P 12 INT C HUM ASP I
[4]  
[Anonymous], USER MANUAL HEART HU
[5]   Modeling Human Errors in Security Protocols [J].
Basin, David ;
Radomirovic, Sasa ;
Schmid, Lara .
2016 IEEE 29TH COMPUTER SECURITY FOUNDATIONS SYMPOSIUM (CSF 2016), 2016, :325-340
[6]  
Bell J, 2009, HEAL SAF LAB, V78
[7]   Example of a Human Factors Engineering approach to a medication administration work system: Potential impact on patient safety [J].
Beuscart-Zephir, Marie-Catherine ;
Pelayo, Sylvia ;
Bernonville, Stephanie .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2010, 79 (04) :E43-E57
[8]  
Bordessa E., 2018, ICO DATA SECURITY ST
[9]   If someone is watching, I'll do what I'm asked: mandatoriness, control, and information security [J].
Boss, Scott R. ;
Kirsch, Laurie J. ;
Angermeier, Ingo ;
Shingler, Raymond A. ;
Boss, R. Wayne .
EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2009, 18 (02) :151-164
[10]  
Bulgurcu B, 2010, MIS QUART, V34, P523