Human Error And Information Security

Introductionnumber 4 for the top 10 information security
In this article I would like to discuss the fact thatthreats of 2010 their survey stated the following:
careless and uneducated computer users are aCareless and untrained insiders will continue to be
leading cause of breaches in information security.a very serious threat to organizations in 2010.
Simple controls and informing end users couldInsiders can be broken down into three
greatly reduce the financial losses experienced bycategories: careless & untrained employees,
businesses and home users.employees that are duped or fall prey to social
Discussionengineering type attacks, and malicious employees.
In the past few years the number of viruses andProtecting a network and critical and sensitive
worms on the internet has increaseddata is done very differently for each type.
tremendously. Credit card fraud, identity theft,Policies, procedures, training and a little technology
information breaches, and social engineering arecan make a world of difference in reducing an
occurring more and more every year.  Asorganization's risk to careless insiders (Top 10
information systems and computers continue toInformation Security Threats for 2010).
become more and more complex, the number ofAnother factor contributing to user error is lack
human errors increases.of common computer knowledge. Many computer
Information security has primarily been thought ofusers today only know the very basics of using a
as securing hardware and software. But recentlycomputer such as, writing documents, sending
statistics have shown that 80% of informationemails, and checking the weather online. These
breaches are caused by human factors such asusers don't even know that they are supposed to
inadequate information assurance knowledge,have anti-virus software installed or how or why
improper training, and failure to follow securityto install updates. These users are the main
procedures (Bean). These frequently overlookedtarget of malicious software programmers. This
threats often lead to costly financial losses fortype of user omission can even lead to a
companies and even private computer users.computer being compromised and used to host
Many companies and organizations tend to focusthe malicious software to other unprotected
primarily on technological controls while ignoringcomputers.
that human error can just as easily lead toNot only do uneducated computer users cause
breaches of information security. Technicalerrors but sometime even the programmers
solutions are a direct and very importantmake mistakes in their code that can be exploited
approach to controlling security but these solutionsby hackers. These errors made by programmers
don't account for ignorance or omission of theare usually used by hackers to gain control of the
people that use the systems. While theaffected application. These errors are usually
administrators and technicians discuss securityfound and patched, but again what about that
issues and concerns, these conversations do notuser that doesn't know to install security patches?
educate the end users.Application
While studying Information and ComputerThere are many different ways that uneducated
Technologies in college, I worked with the studentand irresponsible computer users may cause
computer support center, performing tasks suchbreaches of information, but what are some
as removing malicious software or troubleshootingstrategies that we could use to encourage end
network issues. After working there for severalusers to follow proper procedures to ensure data
weeks I began to realize that most computerconfidentiality and integrity? What are some ways
users don't even care about their security. Theywe can inform and encourage people to learn
just want the computer to work and when amore about security?
virus gets to the point of corrupting theirA past study conducted by the Computing
operating system and rendering it inoperable theyTechnology Industry Association (CompTIA) has
finally seek help only to return several weeks orshown that when a company trains one in every
even days later with the same problem. Thisfour IT employees in information assurance
attitude creates havoc for network administratorsfundamentals, it is 20 percent less likely to
and encourages people that make viruses.encounter a security breach (Bean). This study
According to a survey conducted by AOL, thereshows that if a company spends a little more
is a gap between users' perceptions and themoney on training employees it could save money
prevalence of actual threats on the internet. Thisin the long run. Companies can also keep their
causes many home computer users to ignoreemployees up to date and more involved with
typical security precautions such as anti-virus andcurrent security concerns.
firewall software, which threatens sensitiveAs for the personal computer users there needs
personal and financial information (Roberts).to be drastic measures taken to better inform
Not only do private computer users deal withand mold users into security aware computer
these problems but businesses and corporationsusers. This should be the responsibility of the
lose millions of dollars due to security breachesmaker of the operating systems. They could
and most of these are linked back to a humanpossibly implement a "wizard" type process that
error that there was no technical defense in placewill first question the user for current security
to prevent. Regardless of all the money spent forknowledge. Once the user's level of knowledge is
physical and software security measures mostknown, certain safeguards could be put into place.
organizations are still vulnerable to some of theA simple training tool could also be implemented to
most basic security risks. In order to preventspread user awareness.
these risks from happening we must firstIf simple steps are taken to inform and educate
recognize the different types of human error andend users, it could lead to a more secure internet
inform the users of the possible risks and how tofor every one. The human factors of information
avoid them.security should be a very important concern for
Human Factorsall IT systems and viewed as equivalent to
Human errors can be made in several differenttechnical concerns.
ways.Sources
- CarelessnessBean, Martin. "Human Error at the Center of IT
- Lack of computer knowledgeSecurity Breaches." 04 February 2008. 01 April
- Technical errors2010 .
Carelessness can be linked to many differentHuman Factors in Information Security. 22
causes of security breaches. Such as when a userFebruary 2010. 04 April 2010 .
writes his or her password on a sticky note andIncrease User Awareness to Bolster Security. 13
leaves it on the keyboard, when a browser warnsMay 2005. 11 April 2010 .
of a potentially harmful website and the userRoberts, Paul. AOL survey finds home user
continues anyway without reading, or when aningnorant to online threats. 27 October 2004. 04
employee fails to follow proper security policies orApril 2010 .
procedures.  In a survey conducted by Help NetTop 10 Information Security Threats for 2010. 14
Security, employee carelessness is rated asJanuary 2010. 04 April 2010 .