Real-Time Information Security Incident Management: A Case Study Using the IS-CHEC Technique

Real-Time Information Security Incident Management: A Case Study Using the IS-CHEC Technique
复制标题

实时信息安全事件管理:使用 IS-CHEC 技术的案例研究

DOI:
10.1109/access.2019.2944615
复制
发表时间:
2019-01-01
期刊:
影响因子:
3.9
通讯作者:
Maglaras, Leandros A.
Maglaras, Leandros A.
中科院分区:
计算机科学3区
文献类型:
--
作者:
Evans, Mark;He, Ying;Maglaras, Leandros A.

文献摘要

被引文献

相似文献

信息安全认识到人是最薄弱的环节。尽管有许多国际或特定行业的标准和框架,但信息安全社区尚未采用正式机制来管理导致信息安全破坏的人为错误。然而,这些技术已经建立在安全领域,其中人类可靠性分析(HRA)技术被广泛应用。在以前的工作中,我们开发了信息安全核心人为错误原因(IS-CHEC)来填补这一空白。本案例研究展示了实证研究,在两个参与的公共和私营部门组织中使用IS-CHEC超过12个月的时间,以观察和了解IS-CHEC信息安全HRA技术的实施如何影响各自的组织。IS-CHEC技术的应用使我们能够了解与人为错误相关的信息安全事件的比例,以及这些事件的潜在原因。这项研究透过半结构化访谈,收集了事件的细节,包括最常见的根本原因、补救和预防措施的选择、报告的资讯保安事件数量、人为错误的比例、事件发生时所执行的常见任务,以及参与机构主要人员的看法。该研究证实,在这两种情况下,绝大多数报告的信息安全事件都与人为错误有关,尽管涉及两个参与组织的人为错误相关事件的数量在12个月期间有所波动,但人为错误的比例始终是主要的根本原因。
Information security recognised the human as the weakest link. Despite numerous international or sector-specific standards and frameworks, the information security community has not yet adopted formal mechanisms to manage human errors that cause information security breaches. Such techniques have been however established within the safety field where human reliability analysis (HRA) techniques are widely applied. In previous work we developed Information Security Core Human Error Causes (IS-CHEC) to fill this gap. This case study presents empirical research that uses IS-CHEC over a 12 month period within two participating public and private sector organisations in order to observe and understand how the implementation of the IS-CHEC information security HRA technique affected the respective organisations. The application of the IS-CHEC technique enabled the proportions of human error related information security incidents to be understood as well as the underlying causes of these incidents. The study captured the details of the incidents in terms of the most common underlying causes, selection of remedial and preventative measures, volumes of reported information security incidents, proportions of human error, common tasks undertaken at the time the incident occurred, as well as the perceptions of key individuals within the participating organisations through semi-structured interviews. The study confirmed in both cases that the vast majority of reported information security incidents relate to human error, and although the volumes of human error related incidents pertaining to both participating organisations fluctuated over the 12 month period, the proportions of human error remained consistently as the majority root cause.