...
首页> 外文期刊>International journal of medical informatics >Evaluating information security core human error causes (IS-CHEC) technique in public sector and comparison with the private sector
【24h】

Evaluating information security core human error causes (IS-CHEC) technique in public sector and comparison with the private sector

机译:评估信息安全核心人为错误导致公共部门的技术(IS-CHEC)技术并与私营部门的比较

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Background: The number of reported public sector information security incidents has significantly increased recently including 22% related to the UK health sector. Over two thirds of these incidents pertain to human error, but despite this, there are limited published related works researching human error as it affects information security.Method: This research conducts an empirical case study into the feasibility and implementation of the Information Security Core Human Error Causes (IS-CHEC) technique which is an information security adaptation of Human Error Assessment and Reduction Technique (HEART). We analysed 12 months of reported information security incidents for a participating public sector organisation providing healthcare services and mapped them to the IS-CHEC technique.Results: The results show that the IS-CHEC technique is applicable to the field of information security but identified that the underpinning HEART human error probability calculations did not align to the recorded incidents. The paper then proposes adaptation of the IS-CHEC technique based on the feedback from users during the implementation. We then compared the results against those of a private sector organisation established using the same approach.Conclusions: The research concluded that the proportion of human error is far higher than reported in current literature. The most common causes of human error within the participating public sector organisation were lack of time for error detection and correction, no obvious means of reversing an unintended action and people performing repetitious tasks.
机译:背景:最近报道的公共部门信息安全事件的数量明显增加,其中包括与英国卫生部门有关的22%。超过三分之二的事件涉及人为错误,但尽管如此,存在有限的发布相关工程,研究人为错误,因为它影响信息安全。方法:本研究对信息安全核心人类的可行性和实施进行了实证案例研究错误原因(IS-Chec)技术是人为错误评估和减少技术的信息安全调整(心脏)。我们分析了12个月的报告信息安全事件,为参与的公共部门组织提供保健服务,并将其映射到IS-Chec技术。结果表明,IS-Chec技术适用于信息安全领域,但确定了支撑心脏人为错误概率计算与记录的事件没有对齐。然后,该文件提出了基于实施期间用户的反馈来适应IS-Chec技术。然后,我们将结果与使用相同方法建立的私营部门组织的结果进行了比较。结论:该研究得出的结论是人类误差的比例远远高于当前文献中报告的。参与公共部门组织内部人为错误的最常见原因是错误检测和更正的时间,没有明显的方式扭转意外行动和执行重复的任务的人。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号