...
首页> 外文期刊>Procedia Manufacturing >How Management Goes Wrong? – The Human Factor Lessons Learned from a Cyber Incident Handling Exercise
【24h】

How Management Goes Wrong? – The Human Factor Lessons Learned from a Cyber Incident Handling Exercise

机译:管理如何出错? –从网络事件处理练习中学到的人为因素教训

获取原文

摘要

A cybersecurity hazard in a Critical Infrastructure (CI) is not only about computer malfunction, but is also affecting safety and business continuity of CI. The study on human contribution to cyber resilience is unexplored terrain in the field of critical infrastructure security. So far cyber resilience has been discussed as an extension of the IT security research. Although cybersecurity training is a common measure to implement because of its low cost, most of the training courses aim at improving security awareness of employees, in order to prevent the human-error. However, this approach does not address resilience in handling a cyber incident. The authors conducted observations in a full-scale adversarial cyber security training for CI, where participants are divided into an offensive and a defensive team. The latter acts as one organization and its members play assigned roles such as manager, factory operator and IT administrator. From our observations, some tendencies are found in the defensive team's negative social behaviors and the management issues that lead to malfunction of the team. In fact, these behaviors are perceived in every group of participants, regardless of the variation in their experience and in knowledge on the field. In this paper, the findings from the above mentioned observations are presented as possible challenges in real-world cyber incident management.
机译:关键基础架构(CI)中的网络安全隐患不仅与计算机故障有关,而且还影响CI的安全性和业务连续性。关于人类对网络弹性的贡献的研究是关键基础设施安全领域中尚未探索的领域。到目前为止,已经讨论了网络弹性作为IT安全研究的扩展。尽管由于成本低廉,网络安全培训是一种常见的实施措施,但是大多数培训课程旨在提高员工的安全意识,以防止人为错误。但是,这种方法不能解决在处理网络事件中的弹性。作者在针对CI的全面对抗性网络安全培训中进行了观察,参与者分为攻击性团队和防御性团队。后者充当一个组织,其成员扮演指定的角色,例如经理,工厂操作员和IT管理员。根据我们的观察,在防御团队的负面社交行为和导致团队故障的管理问题中发现了一些趋势。实际上,这些行为在每组参与者中都会被感知,无论他们的经验和现场知识的变化如何。在本文中,来自上述观察的发现被提出为现实世界网络事件管理中的可能挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号