Recommend Solutions to Aid User Defenses and Reduce Evolving Information Risks
RESEARCH ARTICLE
Human behaviour as an aspect of cybersecurity assurance Mark Evans, Leandros A. Maglaras*, Ying He and Helge Janicke
School of Computer Science and Informatics, De Montfort University, Leicester, U.K.
ABSTRACT
There continue to be numerous breaches publicised pertaining to cybersecurity despite security practices being applied within industry for many years. This paper is intended to be the first in a number of papers as research into cybersecurity assurance processes. This paper is compiled based on current research related to cybersecurity assurance and the impact of the human element on it. The objective of this work is to identify elements of cybersecurity that would benefit from further research and development based on the literature review findings. The results outlined in this paper present a need for the cybersecurity field to look in to established industry areas to benefit from effective practices such as human reliability assessment, along with improved methods of validation such as statistical quality control in order to obtain true assurance. The paper proposes the development of a framework that will be based upon defined and repeatable quantification, specifically relating to the range of human aspect tasks that provide or are intended not to negatively affect cybersecurity assurance. Copyright © 2016 John Wiley & Sons, Ltd.
KEYWORDS
cybersecurity assurance; information security management; human factors; human reliability assesment
*Correspondence
Leandros A. Maglaras, School of Computer Science and Informatics, De Montfort University, Leicester, U.K. E-mail: leandros.maglaras@dmu.ac.uk
1. INTRODUCTION
Information security management has grown significantly over the last 25 years and is now a common and regular item within the public domain. With buzz words such as hacking and cybersecurity being included within headlines and being a common topic of conversation amongst everyday technology users, information security is at the forefront of people’s minds. The National Initiative for Cybersecurity Careers and Studies [1] defines cybersecu- rity within its glossary as ‘the activity or process, ability, or capability or state whereby information and communica- tions systems and the information contained therein are protected from and/or defended against damage, unauthorised use or modification, or exploitation’. These security-related terms have changed over the years as information security community leaders pushed the terms information security management through to information assurance up the agenda and eventually bursting into the public domain, including under its current guise of cybersecurity specifically addressing electronic aspects. However, the objectives have always been the same, which is to primarily protect information that we process and are
responsible for. Also, equally importantly there appears to be a lack of understanding within the security community as to what cybersecurity actually is. For example, Health Information Trust Alliance [2] states that ‘cybersecurity does not address non-malicious human threat actors, such as a well-meaning but misguided employee’. Based on this observation, this paper focusses on the human factor of cybersecurity assurance.
However, despite the huge surge in interest and accep- tance of information security management, incorporating cybersecurity, there still appear to be gaps and weaknesses within industry and practice. This is evident due to the large numbers of significant security incidents and data breaches that are being publicised on a regular basis including recent incidents affecting Carphone Warehouse in August 2015, TalkTalk in October 2015, Vtech in November 2015, and inadvertent email disclosure by the Bank of England in May 2015.
As a result of the continuing publication of high-profile security breaches, organisations are increasing focus [3] and looking for ways to improve their assurance in order to protect their brand and reputation, as well as to prevent or reduce the associated financial impacts [4]. This
SECURITY AND COMMUNICATION NETWORKS Security Comm. Networks 2016; 9:4667–4679
Published online 20 October 2016 in Wiley Online Library (wileyonlinelibrary.com). DOI: 10.1002/sec.1657
Copyright © 2016 John Wiley & Sons, Ltd. 4667
generates a picture of the inadequacy of current assurance methods for both industry and society. Assurance tech- niques and approaches, in addition to technology, are required which will protect organisations and the public as a whole from continuing costly cybersecurity breaches. There are technology-related breaches occurring due to malicious individuals exploiting vulnerabilities in technol- ogy on a regular basis, and these are expected to continue [5] as these security hacks are now quick to appear in the media due to general public interest. Interestingly, and per- haps surprisingly to those outside the security community, 50% of the worst breaches in the last year were caused by inadvertent human error, rising from 31% the previous year [5]. Therefore, half of significant security incidents that are occurring are due to a particular element, which has not been changed since the inception of information security management. That element is people and the unin- tentional mistakes and errors that they make.
1.1. Motivation
The motivation for this paper is to take a holistic look at the current status of cybersecurity based upon published re- search and recognised survey results in order to identify areas of weakness and propose areas of further research that would advance the field of cybersecurity and therefore benefit wider society. This paper intends to look outside of the current practices within cybersecurity and identify in- formation and research from specialised fields and industry sectors, that are established and proved to be effective, that could be potentially applied and assessed to understand whether positive improvements could be realised.
1.2. Contributions
This paper makes the following contributions:
(1) identifies current cybersecurity assurance gaps pertaining to the human factor;
(2) proposes a novel framework for cybersecurity as- surance through the embedding of the Human Error Assessment and Reduction Technique (HEART) human reliability assessment (HRA) technique within the Plan-Do-Study-Act (PDSA) cycle; and
(3) demonstrates application of HEART within cyber- security assurance and proposes further research utilising HRA techniques.
The paper from this point forward will be structured as follows. The paper will look in to publicised cybersecurity data breaches and then move on to defining assurance. It will subsequently identify current assurance methods and standards currently adopted by organisations. The docu- ment will then progress on to human factor statistics pertaining to cybersecurity assurance and related human behaviour that underpins these statistics. The paper then moves on to mechanisms for measurement and assessment used outside of the cybersecurity field that could benefit
the current state of cybersecurity based on the negative aspects earlier captured within the paper.
2. PUBLICISED CYBERSECURITY DATA BREACHES
There have been significant volumes of serious healthcare- related data breaches [6] despite the introduction of the In- formation Governance Toolkit (IGT) with 7255 NHS data breaches between 2011 and 2014 [7] and showing a trend of volume increases whereby there was a 101% increase from 2013 to 2014 [8]. Outside of the UK, the trend con- tinues with unintentional exposure of private or sensitive information being 83% higher for healthcare organisations than other industries but the lowest performing industry in incident response [9]. Dunn [8] also reported that 93% of breaches were due to human error and 95% of data loss in the UK is due to the cultural factors of people [10].
The UK Government 2015 security breaches survey [5] found that there had been an increase in the number of se- curity breaches from 81% of large organisations to 90% in- dicating why security breaches are perceived to continue and be an expected element of business now and in the future that cannot be completely eradicated. The survey also identified that nearly 9 out of 10 large organisations surveyed now suffer some form of security breach suggest- ing that these incidents are now a near certainty. The report also stated that businesses should ensure that they are man- aging the risk accordingly, and despite the increase in staff awareness training, people are as likely to cause a breach as viruses and other types of malicious software. Interest- ingly, the survey found that the levels of security aware- ness delivered had gone up compared to the previous year even though staff-related breaches had also risen. The survey showed that 72% of large organisations now deliver ongoing security awareness training to their staff compared with 68% the previous year. This highlights that simply pushing out standard security awareness informa- tion to the employees of an organisation is not an effective means of cybersecurity assurance in relation to human behaviour (Table I).
3. ASSURANCE DEFINITION
According to the National Institute of Standards and Tech- nology [11], assurance is defined as being ‘Grounds for confidence that the other four security goals (integrity, availability, confidentiality, and accountability) have been adequately met by a specific implementation. Therefore, having that in mind, it is difficult for responsible people residing at the top of the organisational hierarchy such as chief executive officers, boards, managing directors, owners, and senior managers to have confidence or guaran- tee that the information that their respective organisation is responsible for processing is adequately secured. This is- sue has been compounded by the change of terminology
Human behaviour as an aspect of cybersecurity assurance M. Evans et al.
4668 Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
used over the years including utilisation of the term assur- ance incorrectly where it is actually referring to the under- pinning controls or countermeasures being applied.
Communications Electronics Security Group (CESG) [12] identified four elements of assurance within an assur- ance model. These four elements were intrinsic assurance, extrinsic assurance, implementation assurance, and opera- tional assurance. Based on the published cybersecurity in- cidents and breaches in the areas of operational assurance and extrinsic assurance within the field of cybersecurity, this paper will focus on those areas. CESG [12] defines op- erational assurance as the activities necessary to maintain the product, system, or service’s security functionality once it has entered operational use. Extrinsic assurance is also defined as any activity independent of the develop- ment environment, which provides a level of trust in the product, system, or service.
3.1. Assurance methods
There seems to be a current position within common stan- dards whereby security assurance programmes need to be flexible [13] and require the organisation to determine what needs to be monitored and the method of monitoring as stated within clauses 9.1a and 9.1b by the British Stan- dards Institution [14]. Standard assurance activities have been static for some time and not evolved at the pace of technology and cybersecurity. It is essential to have an ag- ile security assurance framework in place to meet the needs of differing organisations and bodies. However, the current frameworks are very broad and despite being in existence for some time does not appear to be fully addressing cyber- security specific assurance requirements as the breaches and statistics outlined in this paper have shown. According to PWC [5] the most common form of cyber risk assurance is information/cybersecurity risk assessment with 64% of organisations adopting this method. This position entirely relies upon the level of experience available to the organi- sation to interpret requirements, quantify findings effec- tively, develop and source assurance methods and tools, and finally communicate the cybersecurity status. This lack of consistency and clarity means that very few applications of cybersecurity assurance are the same, and therefore, the industry could benefit from a more prescriptive hierarchy of standards. These standards should offer greater practical
guidance to organisations and providing clear quantifica- tion mechanisms for vulnerabilities associated with the hu- man aspects of cybersecurity as are currently in place for technical vulnerabilities using the Common Vulnerability Scoring System (CVSS). This survey response shows that methods of assurance in relation to cybersecurity have not changed in order to match the current climate.
Despite schemes being developed to provide assurance for Internet-facing technology such as the CESG Cyber Essentials Scheme [15], there is no wider assurance equiv- alent and also no published methodology addressing the assurance required relating to the human factors of cyber- security. This includes clear quantification, enabling levels of cybersecurity effectiveness to be applied and acted upon in a consistent manner. These factors are very important as human interaction is still an essential element of cyberse- curity despite the ever-changing technologies being made available to support assurance goals. These human activi- ties include routine processing of electronic confidential or sensitive data through to the regular implementation and configuration of technical changes by computer system support personnel. This is a diverse range of cybersecurity- related activity that are essential but in isolation to not enable oversight and assurance.
Based on published scientific papers and technical re- ports, there appears to be a heavy focus on implementing the underpinning security controls. Although essential, this does not include the confirmation that that these controls have been applied correctly or as intended in order to attain assurance. This again makes the point that greater emphasis needs to be applied to assurance activities rather than just application of controls. An example of this is the McCumber cube [16], which has been, and continues to be, heavily utilised and enhanced within in- formation security practices, but the application of these security controls must be encapsulated within formal as- surance activity as shown within Figure 1. This required
Table I. Publicised data breach findings and associated percentages.
Publicised data breach finding Percentage
Increase in UK healthcare data breaches from 2013 to 2014 [8]
101%
Reported breaches due to human error [8] 93% Data loss in the UK due to cultural factors of people [10]
95%
Large organisations affected by security breaches [5]
90%
Figure 1. Conceptual model presenting cybersecurity assur- ance requirements encompassing applied security controls.
Human behaviour as an aspect of cybersecurity assuranceM. Evans et al.
4669Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
assurance activity is essential to validate the effectiveness of the applied controls.
3.2. Common standards
There are a number of mechanisms in existence and oper- ation currently which support cybersecurity assurance [17]. These include risk assessment, risk treatment, risk manage- ment, security testing, and auditing. Despite these numer- ous mechanisms, news of high-profile security breaches are occurring and being publicised on a continuing frequent basis [18] and the impact of these breaches in financial terms doubled from 2013 to 2014 [19].
Research has shown that ISO/IEC 27001 remains the leading general standard for security management [5], and from a health perspective, the key security standards underpinning the NHS IGT are ISO/IEC 27001/2 [20]. Also, interestingly, the main driver for securing sensitive data was compliance with standards [9] rather than a pri- mary desire to protect the data for the right ethical reasons. Research identified that 51 of the 63 Information Security Assurance requirements within the UK Health and Social Care Information Centre IGT originated from the ISO27000 series of standards including ISO/IEC 27001:2013, ISO 27002:2013, and 27005:2009 and associ- ated applicable controls. The other most prominent re- quirement origins included the Data Protection Act 1998, Caldicott Report and Principles, and the NHS Information Security Code of Practice.
Cherdantseva and Hilton [21] state ‘an attempt to cover the entire knowledge area forces decisions to be taken that may launch a polemic’. This suggests that the current broad standards based on the principles of confidentiality, integrity, and availability are too broad and therefore not effective specifically in relation to cybersecurity, which is a view supported by the number of publicised cybersecu- rity data breaches. Originally, the ISO/IEC 27001 standard, initially known as BS 7799-2, was utilised to address busi- ness continuity planning and disaster recovery testing due to the fact that no accepted standard covering this area was available. Now with ISO 22301, Business Continuity Management, being utilised this has allowed security pro- fessions to quite rightly focus on the security aspects of these areas rather than them in both entirety falling within the availability principle. With other overlapping standards that can be certified against such as ISO/IEC 20000- 1:2011, Information Technology—Service Management, covering security management aspects such as change management, release management, asset management, and also BS 10012, Personal Information Management, used to develop a personal information management sys- tem in accordance with Data Protection legislation. Given the current statistics captured within this paper, therefore, there is a need to develop a framework and hierarchy whereby formal certification and assurance in relation to cybersecurity should be both re-scoped and also made more stringent in order to provide effective assurance. This
would also include specific assurance for the human aspect of cybersecurity.
4. CURRENT CYBER SECURITY HUMAN FACTOR STATISTICS
There have been a number of studies and surveys under- taken relating to varying aspects of cybersecurity; the SANS Healthcare Cyber Security Survey [9], The Insider Threat Spotlight Report 2015 [22], Department for Busi- ness Innovation and Skills, 2014 Information Security Breaches Survey [19], and the PWC US Cybercrime survey [23] to name but a few. The Insider Threat Spotlight Report 2015 [22] stated that companies were more concerned by inadvertent insider threat data leak breaches than malicious data breaches. However, there is no evidence of this level of concern in industry and the cybersecurity community in terms of change of practice. According to the SANS Healthcare Cyber Security Survey [9], 51% considered the negligent insider as the chief threat. Yet within the ‘Looking Forward’ section of the document, there was no mention of human security testing and in fact [23] states that only 28% of organisations are conducting employee monitoring.
The very informative PWC 2015 Information Security Breaches Survey [5] highlighted significant statistics and information pertaining to staff-related breaches, which featured notably in the survey. Key findings included that three-quarters of large organisations suffered a staff-related breach and nearly one-third of small organisations had a similar occurrence, which had risen up from 58% for large organisations and 22% for small organisations compared to the previous year. These statistics show the difficulty of applying cybersecurity controls concerning human behav- iour and interaction with confidential and sensitive informa- tion. Within larger organisations, there are more processes to assure and a smaller number of information security per- sonnel per employee. To support this finding, it was also found within the survey that 72% of companies where the security policy was poorly understood had staff related breaches, which again could be down to the low ratio of information security personnel to employees to be able to clearly communicate the policy to all staff. The PricewaterhouseCoopers LLP, US cybercrime: Rising risks, reduced readiness key findings from the 2014 US State of Cybercrime Survey [23] found that for health care, the num- ber of respondents who reported unintentional exposure of private or sensitive information was 83% higher than overall respondents and a critical shortcoming for a highly regu- lated industry that deals in sensitive personal information.
The continued evolution of technology is hugely bene- ficial globally and in all areas of life. However, these advances in technology, including a focus on ease of use and communication have brought with them significant changes to the cybersecurity landscape including broader opportunities for people within organisations at all levels access to information. It has also made it easier to collate, remove, and circulate vast volumes of sensitive data [24]
Human behaviour as an aspect of cybersecurity assurance M. Evans et al.
4670 Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
at the touch of a button with very little organisational dili- gence and assurance. Research found that 92% of organisa- tions allowed access to calendar and email via mobile devices. However, 52% also allow respondents to access health records information from mobile devices [9]. It was also publicised that 15% of large organisations had a secu- rity or data breach in the last year involving smartphones or tablets which is up from 7% the previous year [5].
Whilst the Internet and email has revolutionised how people communicate in the workplace, the rise of technol- ogy designed to improve collaboration, productivity, and innovation has been matched by a rise of employee-related breaches affecting organisations. It was stated that commu- nications and collaboration applications are most vulnera- ble to insider attack and that the perceived increase in insider attacks is due to three areas: awareness/training, data on mobile devices, and lack of data protection strategy or solution [22]. The PWC Information Security Breaches Survey [5] also reported that people are the main vulnera- bilities to a secure enterprise. The survey respondents believe that inadvertent human error (48%), lack of staff awareness (33%), and weaknesses in vetting individuals (17%) were all contributing factors in causing the single worst breach that organisations suffered. Regardless of the motivation of an insider, be it a deliberate act of theft or designed to embarrass an organisation, or if the breach was inadvertent due to a lack of internal controls, the threat from ‘insiders’ has not diminished across the UK [5].
Delving a little deeper into the statistics reveals that inadvertent human error caused half of the single worst security breaches for all respondents in 2015. This was a marked increase of over 60% year on year and continues the trend since 2013 where accidental or inadvertent action by individuals was the main cause for the single worst breach [5]. The cybersecurity incidents that typically fly under the media radar are insider events. It was found that 28% of respondents pointed the finger at insiders, which includes trusted parties such as current and former em- ployees, service providers, and contractors [23].
Although there is evidence of empirical studies that have taken place, research found that only few have been performed in terms of IT governance [25] but also further research is required relating to human behaviour and the relationship between social influence and behavioural in- tent [26]. Shahri, Ismail, and Rahim [10] also highlighted that improving security within the healthcare organisation by adequate education and training can increase the basic knowledge and judgement of users about information security, and it can help to prevent the human errors and carelessness, but little empirical evidence supported these claims.
5. HUMAN BEHAVIOUR
Research suggests that human behaviour is not consistent and can be strongly influenced by relationships; there is also a general naïve belief that bad things only happen to
other people [26]. Research also found that people were willing to undertake risky practices. Individuals were actually rewarded as they were seen as helpful for allowing an event to take place without applying security controls or practice [27].
During the literature review, research into other aspects of assurance and human behaviour were also investigated. These included the use of fear appeals and also user perceptions of risky behaviour pertaining to computer security.
Fear appeals are persuasive communications that in- clude an element of fear in order to receive an outcome desired by management [26]. A positive fear appeal would promote a ‘danger control process’, which can lead to a successful outcome as the message recipient undertakes a cognitive process to avert a threat. Fear appeals are tradi- tionally used within healthcare and marketing such as to promote anti-smoking. Johnston and Warkentin [26] also outlined a Fear Appeals Model incorporating components such as perceived threat severity, perceived threat suscepti- bility, response efficacy, self-efficacy, and social influence which then leads to behavioural intent. Johnston and Warkentin [26] also states that the study aids the practice of information security management by exposing the inherent dangers of user autonomy and that end users are not consistent in their behaviours, which is why a ‘one-size fits all’ approach to cybersecurity awareness and training does not offer adequate assurance. A view that is backed up by the current incident statistics highlighted earlier in this paper.
Also associated with the human conduct aspect of cybersecurity was the undertaking of risky behaviour whereby people would undertake activity despite a known risk associated with the action. Johnston and Warkentin [26] state that individuals exhibit a rather naïve belief that bad things only happen to other people, and Aytes and Connolly [27] commented that the self-image of sophisti- cated, security-savvy users does not track very well with their training and actual behaviours. In addition, there is a very interesting concept included by Aytes and Connolly [27], which stated: ‘The vast majority of the time, users can share passwords, open e-mail attachments without checking them for viruses, and so forth, with no negative consequences. They are in fact rewarded in this behaviour, because they are either seen as helpful (in the case of sharing passwords) or they save time (by not scanning for viruses).
In relation to the fear appeal mechanism highlighted within this paper, it has been shown that fear appeals [26] in isolation do not provide effective or adequate assur- ance, as per its definition and organisations should not rely upon this mechanism. The message could be misunder- stood, forgotten, or even ignored based on perceptions, re- lationships, and social influence. Therefore, this approach should be used as an alerting mechanism only and in order to introduce assurance requires feedback to the fear appeal sender to confirm compliance. This could be a return con- firmation message, scan, assessment, report, test, or audit.
Human behaviour as an aspect of cybersecurity assuranceM. Evans et al.
4671Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
A good analogy here would be the use of TCP in computer networking to confirm/guarantee delivery as set out later in this paper. Defined assurance is essential for effective information security management as Aytes and Connolly [27] state: ‘The findings suggest that it is unlikely that computer users will significantly change their behaviour in response to simply being provided with additional infor- mation regarding computing risks and practices/and ‘… likely that organisations will have to enforce compliance when the risks warrant it’.
6. MEASUREMENT AND ASSESSMENT
Metrics within cybersecurity are very important as it en- ables current state to be quantified and subsequently enable understandable and repeatable results to be communicated. It also allows organisations to understand, or set, what is or is not tolerable or acceptable. An example of this is the use of the CVSS [28], which is used to establish the severity of known technical security vulnerabilities within computer systems and software. This allows organisations, following a technical assessment, to identify the current vulnerabil- ities faced, confirm what is an acceptable level of exposure and address findings based on priority. However, there is no equivalent to this with regard to human behaviour within mainstream cybersecurity practices despite security incidents and breaches pertaining to insiders equalling those relating to external threat actors. An example of a measurement technique used within some areas of industry is statistical quality control (SQC).
Service organisations have lagged behind manufactur- ing firms in their use of SQC. The reason for this that SQC requires measurement and it is difficult to measure quality of a service [29], which is the primary reason why there is currently no consistent cybersecurity ap- proach, quantification technique, nor associated accepted value with regard to human behaviour and its vulnerabil- ities. This information is essential to enable organisations to make quality decisions. For example, Rauscher and Cox [30] stated “My board has no way of knowing what we should be spending on cybersecurity. I could ask for 10 times as much or half of my budget”. Also, “…every successful quality revolution has included the participation of upper management. We know of no exceptions”. The PWC Information Security Breaches Survey [5] also found that 14% of respondents have never briefed their board on security risks, and in addition to this statistic 21% of organisations have not briefed their board in the last year showing a significant shortcoming in terms of business leaders being able to provide the assurance required as outlined earlier in this paper. It was also commented that some activities, whereby direct results cannot be measured, or feedback will be delayed, rendered it ineffective as management information. An example of this could be the handling of patient identifiable information or other protected or classified material [31].
As already stated, currently within the cybersecurity community, there are defined mechanisms for assessing threats, vulnerabilities, and risks in relation to tangible aspects such as computer systems and physical environ- ments. With regard to human behaviour, the cybersecurity community generally appears to be accepting of the fact that there is no mainstream mechanism for assessment and quantification. However, within some industries, this has been addressed through the use of HRA and numerous underpinning techniques that have been developed. HRA involves the use of qualitative and quantitative methods to assess the human contribution to risk and has been used within high reliability industries such as petro-chemical, nuclear, and aviation [32]. According to Gu et al. [33], human reliability is a term used to describe human perfor- mance such as the ability of a human to complete a given task without any errors in given conditions in a given time period. Gu et al. [33] also states that the human factors of people involved in information security can be categorised into cognition, physiology, psychology, and ability and also demonstrates how incorporating HRA in to the risk as- sessment function significantly affects the risk assessment output. This could subsequently affect the resultant activity taken by an organisation and again emphasises the impor- tance of reliable assurance activities and information. French et al. [34] support this view as they state that effective HRA not only complements sound technical risk analysis of the physical systems but also helps organisa- tions develop their safety culture and manage their overall risk. Indeed, arguably, it is through this that HRA achieves its greatest effect. There are many varied methods available for HRA, and one of these is called HEART, which is a first-generation HRA developed in 1985 with subsequent techniques further developed and adapted from HEART.
HEART is a well-validated error analysis and quantifi- cation technique [32] utilised in order to provide proac- tive quantification of human behaviour. It is intended to be a fast and easy method for identifying the risks associated with human error. Therefore, HEART should be a technique that is applicable to any situation or industry where human reliability is important, such as cybersecurity.
HEART matches the identified task to one of nine generic task types (GTT) [35]. These are the following:
(A) Totally unfamiliar, performed at speed with no idea of likely consequences.
(B) Shift or restore system to a new or original state on a single attempt without supervision or procedures.
(C) Complex task requiring high level of comprehen- sion and skill.
(D) Fairly simple task performed rapidly or given scant attention.
(E) Routine, highly practiced, rapid task involving rel- atively low level of skill.
(F) Restore or shift a system to original or new state following procedures, with some checking.
Human behaviour as an aspect of cybersecurity assurance M. Evans et al.
4672 Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
(G) Completely familiar, well designed, highly prac- ticed routine task occurring several times per hour, performed to highest possible standards by highly motivated, highly trained, and experienced person, totally aware of implications of failure, with time to correct potential error, but without the benefit of significant job aids.
(H) Respond correctly to system command even when there is an augmented or automated supervisory system providing accurate interpretation of system state
(I) Miscellaneous task for which no description can be found
The HEART process then requires the analyst or asses- sor to identify the applicable error-producing conditions (EPCs) from a list of options ranging from ‘little or no in- dependent checking or testing of output’ through to ‘oper- ator inexperience’. From this information, calculations and formulae embedded within HEART are used to establish an overall human error probability value to the identified task. The HEART technique key elements within the quan- tification process are shown in Figure 2.
HEART is an established first-generation technique for predicting human reliability and identifying ways of reduc- ing human error. It should be possible based on the HEART process to relatively easily apply this technique to the cybersecurity field for cybersecurity affecting tasks performed by people. The HEART methodology takes in to account the task and the person performing the task rather than the technical process. However, the scope and error focus of the assessment may be too narrow [34] through the application of a first generation technique. Second-generation and third-generation HRA techniques consider wider contexts in terms of the environment and human emotion. The assessment must take into account the aggregated effect of people performing multiple tasks, which may introduce greater likelihood of a cybersecurity breach or incident.
7. THE PROPOSED FRAMEWORK
Due to the large number of data breach cybersecurity inci- dents, it is evident that further research needs to be under- taken to establish why such a large number of security incidents are due to human behaviour. The lack of formal cybersecurity assurance relating to human behaviour set
out within this paper is a significant area of concern. There is use of the term assurance, but in some cases, this appears to be entirely focussed upon the underpinning security controls with greater emphasis on the technical elements. This approach does not provide real assurance. Activities including assessment, quantification, and reporting are essential to provide confirmation that these controls, including those implemented to address the risk of human error, have been applied correctly or as intended.
As shown by the publicised cybersecurity incidents and breaches, it is evident that the current common security standards leveraged by organisations to adequately cater for human error and the associated vulnerabilities, despite current prominent reports and surveys, require enhanced focus and attention relating to human behaviour and error aspect of cybersecurity. For example, one of the 35 main security categories outlined within BS ISO/IEC 27002:2013 specifically addresses technical security weak- nesses (12.6 Technical Vulnerability Management), but there is no equivalent within the standard pertaining to hu- man factor vulnerabilities. Key cybersecurity areas should be defined and refined through a separate modular certifi- cation approach rather than rely upon standards such as BS ISO/IEC 27002:2013. These standards are too broad and overlap with other related standards as outlined in this paper. Effective modular assurance could be achieved through separate certification for cybersecurity practices based on the distinct differences in current incidents and breaches.
Given the volumes of human factor-related cybersecu- rity breaches and incidents, it is evident that the use of cybersecurity awareness training is important, but organisations should consider how effective this approach is in isolation. If the number of these breaches and inci- dents continue to increase, it would show that awareness alone is not effective in the current climate and this should be enhanced through cybersecurity HRA. Boards and se- nior management should consider whether they are taking sufficient steps to ensure a culture of strict and effective se- curity pertaining to human error as internal, accidental fac- tors remain the largest cause of cybersecurity breaches [5].
A technology scenario where return confirmation rather than a one-way communication, as a form of assurance, has been applied is the use of the Transmission Control Protocol (TCP) within TCP/IP (Internet Protocol) com- puter networking. TCP is one of the main protocols in TCP/IP networks. Whereas the IP protocol deals only with packets, TCP enables two hosts to establish a connection
Figure 2. HEART quantification process.
Human behaviour as an aspect of cybersecurity assuranceM. Evans et al.
4673Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
and exchange streams of data. TCP guarantees delivery of data and also guarantees that packets will be delivered in the same order, in which they were sent. Without the use of TCP, there would just be an assumption that the connec- tion had been successfully established and data delivered. Another computer networking protocol, which does not undertake message receipt confirmation, is the User Datagram Protocol (UDP), a connectionless protocol that provides a direct way to send and receive data and is used primarily for broadcasting messages over a computer network. Therefore, a cybersecurity analogy using these protocols would be as follows:
• TCP - Security manager of an organisation sends out an email alert to staff asking them to remove all client personal data from their desktop computer hard drives and store it on networked file servers where the data are secured and backed up on a regular basis. How- ever, the security manager also asks the message recipients to acknowledge receipt and understanding of the instruction and confirm when the task has been completed.
• UDP – Security manager of an organisation sends out a broadcast email alert to staff asking them to remove all client personal data from their desktop computer hard drives and store it on networked file servers where the data are secured and backed up on a regular basis.
Obviously, the UDP form of confirmation is much quicker and requires less management and interaction; however, the Security Manager in the scenario above would not be able to provide assurance that the task had been completed or even the instruction received by the intended recipients. Whereas, the TCP form would require confirmation to be sent to the security manager that would allow a greater degree of assurance that the instruction had been received by the intended recipient, understood, and that the staff members believe they have complied with the requirement. In order to attain full assurance, a form of independent testing would need to be undertaken with results checked and communicated. Only then could the organisation really provide assurance that all personal data had been moved on to the central server as per the instruction.
Organisations generally now understand that they should be measuring and monitoring their security controls through common channels. This includes penetration testing, vulnerability assessment, risk assessment, audit, patching reports, incident statistics, and anti-virus software updates and coverage with internal audit and information/ cyber risk assessment being the most common [5]. These forms of assurance are definitely required and essential, but when the management information they are providing is analysed, they are ultimately retrospective and technol- ogy focussed. Therefore, the human error with regard to cybersecurity has been found to be too difficult, unable to provide financial reward, or not required despite the
headlines we are often faced with. Human reliability as- sessment methodologies and techniques have been devel- oped and implemented within other industries but not cybersecurity to date. Methodologies such as HEART were developed approximately 20 years ago but still have not flowed in to mainstream information security practice in addition to the use of formal measurement techniques such as SQC, which are common in manufacturing envi- ronments [29]. The difficulties of quantifying human reli- ability within cybersecurity have not been developed and is not currently within mainstream information security practice. The cybersecurity community should include a greater focus on quantification of all areas, including human reliability, to provide clear quality management information to boards and senior management within orga- nisations, which in turn will allow greater cybersecurity assurance to be attained.
With some technique modification, including adjusting evaluation focus to the human error potential pertaining to the use of, and concurrent access to, multiple data stores and applications which could result in cybersecu- rity incidents and breaches, the adaption of HEART or another HRA technique could benefit the cybersecurity community.
In order to provide real assurance, there must be a cyclic, or return flow, of information between the instigator and elements within scope of the activity, but in many cases, this is not the case. For example, in order to provide assurance, an instruction must be communicated, a change implemented, analysis of the effectiveness of the change undertaken, the results of the analysis acted upon, and confirmed against the initial instruction and intention. This can be seen below in Figure 3, which aligns to the PDSA model presented by Dr W. Edwards Deming in 1993 [36].
This paper has shown that a defined assurance model is required that interconnects with the models already devel- oped such as the McCumber cube in order to enhance cy- bersecurity as shown in Figure 1. Following the literature review, an assurance framework is proposed that integrates HRA, SQC, and a vulnerability scoring system that
Figure 3. Basic assurance aligned to the PDSA cycle.
Human behaviour as an aspect of cybersecurity assurance M. Evans et al.
4674 Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
pertains to human rather than technical vulnerabilities. It is proposed that the human error assessment components of HEART should be embedded within all of the PDSA ele- ments of the PDSA cycle presented in Figure 3. The frame- work should also be suitable for all cybersecurity affecting tasks performed by humans from routine processing of personal data through to technical application of security updates by administrative personnel. Further research and development in this area should be undertaken, and looking at the actual framework should also research methods of completion that could potentially ease the resourcing burden associated with the task. A cybersecu- rity human error analysis and testing framework is proposed to provide improved cybersecurity assurance. Research is proposed to establish the comparable accuracy of the assessment being performed by a security
professional, non-security personnel, and also employee self-assessment. A conceptual high-level model of the pro- posed assurance framework is shown in Figure 4.
There is an overhead associated with the proposed assurance framework in that organisations are required to invest in applying greater resources and time to meeting assurance requirements. This will therefore require greater focus, attention, and expenditure within cybersecurity as- surance as this framework is not looking to introduce effi- ciencies but to enhance effectiveness, which at this time comes with increased resource obligations. These resource requirements could come from internal resources or be external independent resources as undertaken currently as part of technical security testing techniques.
It is proposed that the HEART HRA technique be mapped to existing cybersecurity affecting tasks that are
Figure 4. Proposed high-level cybersecurity human vulnerability assurance framework.
Human behaviour as an aspect of cybersecurity assuranceM. Evans et al.
4675Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
being performed creating a Cyber Security HEART tech- nique. For example, the GTTs identified within HEART could be aligned to cybersecurity affecting tasks ranging from routine processing of information through to imple- mentation of IT management tasks such as implementing changes to the rule base applied within perimeter network firewall devices. Once the GTT has been identified, then the relevant EPCs can be established as well as using the maximum predicted nominal amount within the HEART technique to weight impact, which actually would act as an equivalent to the technical CVSS scores applied to security vulnerabilities. However, the HEART technique requires that each EPC has an assessed effect, which means that the weighting is directly related to the task being analysed and not independent as per CVSS scoring (Table II).
To show how HEART can be applied, there are two fic- tional scenarios below indicating an initial assessment and then a follow-up assessment once identified error reduction controls have been applied. Subsequent papers on this topic intend to utilise live data taken from information se- curity incident registers from both public and private sector organisations. As shown in Figure 2, there is a process within the HEART technique that must be followed.
Within the HEART technique, each selected GTT or EPC has a validated nominal amount, which can be seen in the scenario below. Each nominal amount is embedded within set formulae required to establish the final human error probability (Tables III and IV).
The above scenarios clearly show how HEART can be used to apply validated mathematical calculations to estab- lish the probability of human error occurring which can support local risk quantification and subsequent manage- ment in accordance with organisational risk tolerance de- fined within policy.
In order for the proposed adoption of HEART within cybersecurity practices to be proved to be effective, then there is a need for further research to be undertaken to val- idate the inbuilt HEART calculations against actual cyber- security tasks that have not been completely successfully leading to cybersecurity incidents occuring. It is proposed that this validation is completed by analysing cybersecurity incident statistics over a period of time against the fre- quency of the cybersecurity affecting tasks being per- formed. Subsequent of the validation exercise, it would then be possible to apply the error reduction element of the technique and measure any benefit realised by applying the technique.
Table II. Mapping of HEART GTTs to example cybersecurity affecting tasks.
HEART generic task Potential cyber security affecting task
(A) Totally unfamiliar, performed at speed with no real idea of likely consequences
IT support employee making changes to an IT system that they are not familiar with as part of an urgent project, change, or incident.
(B) Shift or restore system to a new or original state on a single attempt without supervision or procedures
Independent application of changes to IT systems such as changes to policy or rules which are applied infrequently.
(C) Complex task requiring high level of comprehension and skill
Performing of security risk assessments or implementing IT solutions to business change requests.
(D) Fairly simple task performed rapidly or given scant attention
Creation of new IT system user accounts for large environments with large numbers of users. This could also be the communication of confidential information via email, which is a common human error.
(E) Routine, highly practised, rapid task involving relatively low level of skill
Change of account or system passwords.
(F) Restore or shift a system to original or new state following procedures, with some checking
Application of changes to IT systems such as changes to policy or rules that are applied as part of wider change approval procedures.
(G) Completely familiar, well-designed, highly practised, routine task occurring several times per hour, performed to highest possible standards by highly motivated, highly trained, and experienced person, totally aware of implications of failure, with time to correct potential error, but without the benefit of significant job aids
Review of system security activity logs or alerts by qualified operational cybersecurity professionals.
(H) Respond correctly to system command even when there is an augmented or automated supervisory system providing accurate interpretation of system state
Response to network intrusion prevention system alerts generated for the awareness of qualified operational cybersecurity professionals.
(M) Miscellaneous task for which no description can be found Miscellaneous cybersecurity affecting task
Human behaviour as an aspect of cybersecurity assurance M. Evans et al.
4676 Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
8. CONCLUSION
As outlined within this paper, organisations and society continue to be affected by both regular and similar cyberse- curity breaches. These breaches pertain to technical implementations as well as routine processing of confiden- tial electronic information. Despite this range of activities, it has been proven that half of these have human error at their core. Therefore, there should be increased empirical and theoretical research in to human aspects of cybersecu- rity based on the volumes of human error-related incidents in order to establish ways in which mainstream cybersecu- rity practice can benefit. It is intended in subsequent papers on this topic to validate the scenarios outlined
in this paper based on real-world cybersecurity incident data analysed within participating public and private sector organisations.
This paper has demonstrated that there is further re- search required in to cybersecurity assurance and quantifi- cation in relation to human factors to develop an effective assurance framework. This approach would benefit the field of cybersecurity as a common useable solution is not currently available and organisations are relying upon independent skills and knowledge of individuals. It is pro- posed that a specific framework is developed based upon defined and repeatable quantification specifically relating to the range of human aspect tasks that provide or are intended not to negatively affect cybersecurity posture.
Table III. Mapping of HEART GTTs, scenario 1.
Scenario A Junior Network Engineer works independently and is required to amend rules on perimeter firewalls in a very busy and high pressured environment.
Generic Task Type (see Table II)
B Nominal human unreliability (amount allocated to the selected GTT within HEART)
0.26
Error-producing conditions EPC (selected from 38 conditions within HEART)
Predicted nominal amount of unreliability (set value allocated to each EPC within HEART)
Assessed proportion of affect (amount identified and allocated by the assessor)
Assessed affect (HEART technique calculation)
2 - A shortage of time available for error detection and correction
x 11 0.3 (11-1) × 0.3 + 1 = 4.0
15 - Operator inexperience x 3 0.2 (3-1) × 0.2 + 1 = 1.4 17 - Little or no independent checking or testing of output
x 3 0.3 (3-1) × 0.3 + 1 = 1.6
Human error probability of task failure leading to a cybersecurity incident.
0.26 × 4.0 × 1.4 × 1.6 = 2.32 (1.0).
Note: a total probability cannot exceed 1.0. Where this is the case, then the probability of failure must be recorded as 1.0, showing that an error is certain to
happen.
Table IV. Mapping of HEART GTTs, scenario 1.
Scenario Two Junior Network Engineers work under supervision and are required to amend
rules on perimeter firewalls in a very busy and high pressured environment.
Generic Task Type (see Table II) F Nominal human unreliability (amount allocated to the selected GTT within HEART)
0.003
Error-producing conditions EPC (selected from 38 conditions within HEART)
Predicted nominal amount of unreliability (set value allocated to each EPC within HEART)
Assessed proportion of affect (amount identified and allocated by the assessor)
Assessed affect (HEART technique calculation)
15 - Operator inexperience x 3 0.2 (3-1) × 0.2 + 1 = 1.4 Human error probability of task failure leading to a cybersecurity incident 0.003 × 1.4 = 0.0042
Human behaviour as an aspect of cybersecurity assuranceM. Evans et al.
4677Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
Techniques that this framework should be built upon include HRA, SQC, and a cybersecurity human aspect vul- nerability scoring system. In conclusion, the cybersecurity community should continue to progress and develop, but it must not forget its roots and the obvious statistics that indi- cate we have not yet addressed the risks associated with the one consistent element of cybersecurity, the human error.
REFERENCES
1. National Initiative for Cybersecurity Careers and Studies. Explore terms: a glossary of common cybersecurity terminology [Online] https://niccs. us-cert.gov. Available from: https://niccs.us-cert.gov/ glossary [Accessed 03/12/2015].
2. Health Information Trust Alliance. Healthcare’s model approach to critical infrastructure cybersecurity. 2014. https://hitrustalliance.net.
3. KPMG. “Cyber security: are consumer companies up to the challenge?”. 2014. http://www.kpmg.com
4. Cabinet Office. Cost of cyber crime study 2011. https://www.gov.uk
5. PWC. 2015 Information security breaches survey. https://www.gov.uk/government
6. Murphy M. NHS tops the list for serious data breaches last year [Online] ComputerworldUK.com. Available from:http://www.computerworlduk.com/security/nhs- tops-list-for-serious-data-breaches-last-year-3607138/ [Accessed 06/06/2015]
7. Big Brother Watch. NHS Data Breaches. 2014. http:// www.bigbrotherwatch.org.uk/wp-content/
8. Dunn J. Data breaches in UK healthcare sector double since 2013, ICO numbers show. 2014. [Online] Computerworld UK.com. Available from: http:// www.computerworlduk.com/news/security/data- breaches-in-uk-healthcare-sector-double-since-2013- ico-numbers-show-3589814/ [Accessed 06/06/2015]
9. Filkins B. New threats drive improved practices: state of cybersecurity in health care organizations. 2014. https://www.sans.org/reading-room. SANS Institute.
10. Shahri A, Ismail Z, Rahim N. Security effectiveness in health information system: through improving the human factors by education and training. Australian Journal of Basic and Applied Sciences 2012; 6 (12):226–233.
11. National Institute of Standards and Technology. NISTIR 7298, revision 2, glossary of key information security terms. 2013. http://csrc.nist.gov/publications: National Institute of Standards and Technology Interagency or Internal Report 7298r2.
12. CESG. Good practice guide no. 30 Assurance of ICT systems and services. 2012. CESG Information Assurance Portal.
13. Information Security Forum. Information security assurance—an overview for implementing an information assurance programme. 2010. https:// www.isflive.org
14. British Standards Institution. BS ISO/IEC 27001: 2013 Information Technology—Security Techniques—Infor- mation Security Management Systems—Requirements. London: British Standards Institution (BSI).
15. CESG. Cyber Essentials [Online] cesg.gov.uk. Avail- able from: https://www.cesg.gov.uk/servicecatalogue/ cyber-essentials/Pages/cyber-essentials.aspx[Accessed 03/12/2015]
16. Maconachy W, Schou C, Ragsdale D, Welch D. A model for information assurance: an integrated ap- proach. Proceedings of the 2001 IEEE, Workshop on Information Assurance and Security, United States Military Academy, West Point, NY.
17. Department for Business Innovation and Skills. UK cyber security research report. 2013. https://www. gov.uk
18. HM Government. FTSE 350 cyber governance health check tracker. 2013. https://www.gov.uk
19. Department for business innovation and skills. 2014 Information security breaches survey. https://www. gov.uk
20. Health and Social care Information Centre. Checklist guidance for reporting, managing and investigating information governance and cyber security serious incidents requiring investigation v5.1. 2015. https:// www.igt.hscic.gov.uk
21. Cherdantseva Y, Hilton J. A reference model of infor- mation assurance & security. In Availability, Reliabil- ity and Security (ARES) 2013 Eighth International Conference on IEEE, 2013; 546–555.
22. Information Security Community on LinkedIn. Insider threat spotlight report 2015. Crowd Research Partners.
23. PricewaterhouseCoopers LLP. US cybercrime: rising risks, reduced readiness Key findings from the 2014 US State of Cybercrime Survey. http://www.pwc.com
24. Department for Communities and Local Government. Understanding local cyber resilience. 2015. www. gov.uk/dclg
25. Brown AE, Grant GG. Framing the frameworks: a review of IT governance research. Communications of the Association for Information Systems 2005; 15:696–712.
26. Johnston A, Warkentin M. Fear appeals and informa- tion security behaviours: an empirical study. MIS Quarterly 2010; 34(3). http://www.uab.edu/cas
27. Aytes K, Connolly T. Computer security and risky computing practices: a rational choice perspective. Journal of Organizational and End User Computing 2004; 16. 3(1):22–40.
Human behaviour as an aspect of cybersecurity assurance M. Evans et al.
4678 Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
28. FIRST.ORG. About CVSS [Online] first.org. 2015. Available from: http://www.first.org/cvss [Accessed 13/12/2015].
29. Reid RD, Sanders NR. Operations management: an integrated approach. 5th, International student version. edn, John Wiley & Sons: Singapore, 2013; 204.
30. Rauscher K, Cox E. Measuring the Cyber Security Problem. EastWest Institute: New York, 2013. ISBN:978-0-9856824-3-9.
31. Brotby W. Information Security Management: A Definitive Guide to Effective Security Monitoring and Measurement. Auerbach Publications: Boston, MA, 2009.
32. Lyons M, Adams S, Woloshynowych M, Vincent C. Human reliability analysis in healthcare: a review of techniques. International Journal of Risk & Safety in Medicine 2004; 16:223–237.
33. Gu T, Li L, Lu M, Li J. Research on the calculation method of information security risk assessment consid- ering human reliability. In 2014 International Confer- ence on Reliability, Maintainability and Safety (ICRMS), August 2014. Guangzhou, China: Curran Associates, Inc. 2015: 457–462.
34. French S, Bedford T, Pollard SJT, Soane E. Human reliability analysis : a critique and review for managers. Safety Science 2011; 49(6):753–763 ISSN 0925-7535.
35. Kirwan B. The validation of three human reliability quantification techniques—THERP, HEART and JHEDI: Part I—Technique descriptions and validation issues. Applied Ergonomics 1996; 27(6):359–373.
36. Tang J. The implementation of Deming’s system model to improve security management: A case study. International Journal of Management 2008; 25:25–54.
Human behaviour as an aspect of cybersecurity assuranceM. Evans et al.
4679Security Comm. Networks 2016; 9:4667–4679 © 2016 John Wiley & Sons, Ltd. DOI: 10.1002/sec
Copyright of Security & Communication Networks is the property of Wiley-Blackwell and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.
Copyright of Security & Communication Networks is the property of Hindawi Limited and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.