[Paper Review] Human Behaviour as an aspect of Cyber Security Assurance
This paper proposes a human-centric framework for cyber security assurance by integrating human reliability assessment and statistical quality control into security processes. It argues that human behavior significantly impacts security posture and calls for repeatable, quantifiable metrics to improve assurance, especially in mitigating human-induced vulnerabilities through structured evaluation methods.
There continue to be numerous breaches publicised pertaining to cyber security despite security practices being applied within industry for many years. This article is intended to be the first in a number of articles as research into cyber security assurance processes. This article is compiled based on current research related to cyber security assurance and the impact of the human element on it. The objective of this work is to identify elements of cyber security that would benefit from further research and development based on the literature review findings. The results outlined in this article present a need for the cyber security field to look in to established industry areas to benefit from effective practices such as human reliability assessment, along with improved methods of validation such as statistical quality control in order to obtain true assurance. The article proposes the development of a framework that will be based upon defined and repeatable quantification, specifically relating to the range of human aspect tasks that provide, or are intended not to negatively affect cyber security posture.
Motivation & Objective
- To identify gaps in current cyber security assurance practices related to human behavior.
- To address the persistent issue of security breaches despite established security measures.
- To advocate for integrating human reliability assessment and statistical quality control into cyber security assurance frameworks.
- To develop a repeatable, quantifiable method for evaluating human aspects of cyber security.
Proposed method
- Conducting a literature review on cyber security assurance and human factors.
- Drawing on established practices from industry sectors such as nuclear and aviation for human reliability assessment.
- Proposing a framework based on defined, repeatable quantification of human tasks affecting security.
- Integrating statistical quality control techniques to validate security processes.
- Focusing on tasks where human actions can positively or negatively affect cyber security posture.
- Using empirical findings to guide the design of a measurable assurance model.
Experimental results
Research questions
- RQ1How does human behavior influence the effectiveness of cyber security assurance processes?
- RQ2What existing industry practices can be adapted to improve human-related security assurance?
- RQ3How can human reliability be quantified and validated within cyber security frameworks?
- RQ4What methods can ensure repeatable and measurable assessment of human aspects in security?
- RQ5What role does statistical quality control play in enhancing cyber security assurance?
Key findings
- Human behavior is a critical, often overlooked factor in cyber security breaches despite established security practices.
- Current assurance methods lack systematic evaluation of human factors, leading to inconsistent outcomes.
- Human reliability assessment techniques from high-risk industries can be adapted to improve cyber security assurance.
- Statistical quality control offers a viable method for validating security processes and ensuring consistency.
- There is a clear need for repeatable, quantifiable metrics to assess human contributions to security posture.
- The integration of human-centric evaluation into assurance frameworks can significantly enhance overall security effectiveness.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.