首页> 外文会议>10th IET System Safety and Cyber-Security Conference 2015 >CHEAT, an approach to incorporating human factors in cyber security assessments
【24h】

CHEAT, an approach to incorporating human factors in cyber security assessments

机译:CHEAT,一种将人为因素纳入网络安全评估的方法

获取原文
获取原文并翻译 | 示例

摘要

The human element has been identified as a contributing factor in over 95% of all security incidents. Current technical risk assessment methodologies, such as the IS1-2 Supplement, go some way to quantifying the characteristics of a non-malicious insider attacks, based on a historical understanding of the user group, organisational security culture and past security breaches. However, the approaches don't fully consider the Psychological motivations that give rise to human error in cyber-security scenarios. Applied knowledge of human limitations and cognitive biases was used to derive a structured approach to capturing typical human errors as part of cyber-security assessments. By recognising the Psychological root causes behind human errors in cyber-security scenarios we can identify appropriate risk management and mitigating strategies; in the same way that Human Reliability Analysis (HRA) tools, such as the Human Error Assessment and Reduction Technique (HEART), are crucial in mitigating human error as part of safety case evidence. This paper presents the Cyber Human Error Assessment Tool (CHEAT); a structured approach to address HF considerations in cyber-security assessments.
机译:在超过95%的所有安全事件中,人为因素已被确定为一个促成因素。当前的技术风险评估方法,例如IS1-2增补,基于对用户组的历史了解,组织安全文化和过去的安全漏洞,在某种程度上量化了非恶意内部攻击的特征。但是,这些方法没有完全考虑在网络安全场景中引起人为错误的心理动机。利用人类局限性和认知偏见的应用知识,可以得出一种结构化的方法来捕获典型的人为错误,作为网络安全评估的一部分。通过识别网络安全场景中人为错误背后的心理根源,我们可以确定适当的风险管理和缓解策略;以与人类可靠性分析(HRA)工具(例如人为错误评估和减少技术(HEART))相同的方式,对于缓解人为错误(作为安全案例证据的一部分)至关重要。本文介绍了网络人为错误评估工具(CHEAT);一种解决网络安全评估中高频因素的结构化方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号