Evaluating information security core human error causes (IS-CHEC) technique in public sector and comparison with the private sector. (July 2019)
- Record Type:
- Journal Article
- Title:
- Evaluating information security core human error causes (IS-CHEC) technique in public sector and comparison with the private sector. (July 2019)
- Main Title:
- Evaluating information security core human error causes (IS-CHEC) technique in public sector and comparison with the private sector
- Authors:
- Evans, Mark
He, Ying
Maglaras, Leandros
Yevseyeva, Iryna
Janicke, Helge - Abstract:
- Highlights: This research identified that human error proportions are higher than currently understood in the literature. The IS-CHEC technique is applicable to information security, in a participating public sector organisation providing healthcare services. The majority of information security incidents pertain to human error. The use of IS-CHEC technique provides insight into the common causes of human error. The IS-CHEC technique has been improved based upon a comparison of case study findings within public and private sector organisations. Abstract: Background: The number of reported public sector information security incidents has significantly increased recently including 22% related to the UK health sector. Over two thirds of these incidents pertain to human error, but despite this, there are limited published related works researching human error as it affects information security. Method: This research conducts an empirical case study into the feasibility and implementation of the Information Security Core Human Error Causes (IS-CHEC) technique which is an information security adaptation of Human Error Assessment and Reduction Technique (HEART). We analysed 12 months of reported information security incidents for a participating public sector organisation providing healthcare services and mapped them to the IS-CHEC technique. Results: The results show that the IS-CHEC technique is applicable to the field of information security but identified that the underpinningHighlights: This research identified that human error proportions are higher than currently understood in the literature. The IS-CHEC technique is applicable to information security, in a participating public sector organisation providing healthcare services. The majority of information security incidents pertain to human error. The use of IS-CHEC technique provides insight into the common causes of human error. The IS-CHEC technique has been improved based upon a comparison of case study findings within public and private sector organisations. Abstract: Background: The number of reported public sector information security incidents has significantly increased recently including 22% related to the UK health sector. Over two thirds of these incidents pertain to human error, but despite this, there are limited published related works researching human error as it affects information security. Method: This research conducts an empirical case study into the feasibility and implementation of the Information Security Core Human Error Causes (IS-CHEC) technique which is an information security adaptation of Human Error Assessment and Reduction Technique (HEART). We analysed 12 months of reported information security incidents for a participating public sector organisation providing healthcare services and mapped them to the IS-CHEC technique. Results: The results show that the IS-CHEC technique is applicable to the field of information security but identified that the underpinning HEART human error probability calculations did not align to the recorded incidents. The paper then proposes adaptation of the IS-CHEC technique based on the feedback from users during the implementation. We then compared the results against those of a private sector organisation established using the same approach. Conclusions: The research concluded that the proportion of human error is far higher than reported in current literature. The most common causes of human error within the participating public sector organisation were lack of time for error detection and correction, no obvious means of reversing an unintended action and people performing repetitious tasks. … (more)
- Is Part Of:
- International journal of medical informatics. Volume 127(2019)
- Journal:
- International journal of medical informatics
- Issue:
- Volume 127(2019)
- Issue Display:
- Volume 127, Issue 2019 (2019)
- Year:
- 2019
- Volume:
- 127
- Issue:
- 2019
- Issue Sort Value:
- 2019-0127-2019-0000
- Page Start:
- 109
- Page End:
- 119
- Publication Date:
- 2019-07
- Subjects:
- Information security -- Human error assessment and reduction technique (HEART) -- Information security core human error causes (IS-CHEC) -- Human error related information security incidents -- Human reliability analysis (HRA)
Medical informatics -- Periodicals
Information science -- Periodicals
Computers -- Periodicals
Medical technology -- Periodicals
Medical Informatics -- Periodicals
Technology, Medical -- Periodicals
Computers
Information science
Medical informatics
Medical technology
Electronic journals
Periodicals
Electronic journals
610.285 - Journal URLs:
- http://www.sciencedirect.com/science/journal/13865056 ↗
http://www.clinicalkey.com/dura/browse/journalIssue/13865056 ↗
http://www.clinicalkey.com.au/dura/browse/journalIssue/13865056 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.ijmedinf.2019.04.019 ↗
- Languages:
- English
- ISSNs:
- 1386-5056
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4542.345250
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 10453.xml