1 / 13100%
1
Running Head: HUMAN FACTOR ENGINEERING
HUMAN FACTOR ENGINEERING
CARLA GINART
LIBERTY UNIVERSITY
CSCI612_B01_202420
FEBRUARY 7, 2024
HUMAN FACTOR ENGINEERING
2
Introduction
The application of human factors techniques has spread to other fields, such as cybersecurity.
Since its definition in the late 1920s, human factors engineering (HFE) has existed as a field of
study and a profession. Although during that time HFE and ergonomics were used
interchangeably, the field has since changed. It is my belief that human factor engineering plays
a huge role in cybersecurity principles. Human error is one of the biggest reasons that cyber-
attacks are successful. It is also something that is not easy to control. No matter how much
training, or information you give to employees, you cannot take away the risk of human error
happening and causing a cyber-attack. Organizations may benefit greatly from integrating
cybersecurity and human factors disciplines. The academic community has long conducted
study on human factors, covering topics such as cognitive burdens and security awareness
training. Researchers like Dykstra, Nobles, and Cunningham have advanced the field and
produced sufficient data to demonstrate its value. However, the lack of full utilization of this
study by private and public sector companies to incorporate human aspects security into their
existing cybersecurity initiatives may limit their potential for growth and development. Insider
threat, behavioral analysis, Security Operations Centers (SOCs), employee fatigue and attrition
in cybersecurity initiatives, and other topics will all be covered in this papers research.
Throughout this paper, we will discuss in greater detail how human factor engineering relates to
security engineering and cybersecurity, and how much human error cause a need for human
factor engineering and security engineering. We will also discuss how much this affects the
Healthcare industry as an example to show how huge of an impact human error has on a
company.
HUMAN FACTOR ENGINEERING
3
Research Objectives
What is Human factor engineering?
What is Security Engineering and how does it work with Human Factor Engineering?
Describe how human error works with human factor engineering and security
engineering.
Describe how human error is a big threat to cybersecurity especially in healthcare.
Research Questions
1. Does human factors engineering really work with security engineering and cybersecurity?
2. Does human error really cause issues in cybersecurity especially in healthcare?
3. How does Security Engineering help with human error?
4. How does Human Factor Engineering help with human error?
Human Factor Engineering
I have always felt that humans/employees were one of the biggest weaknesses when it comes to
cybersecurity. One of the things that I feel helps control this is something called Human Factors
Engineering. “Human Factors Engineering, also known as ergonomics, is the discipline of
understanding physical and psychological components of humans and applying them to devices
for human use. The reason Human Factors Engineering is an important science, is because it
helps to improve the safety and efficiency of devices for users.” (Robinson, 2023) Human error
is something that happens everywhere and cybersecurity training for all employees is a must for
every company big or small, to help make the human error threat smaller. But Human Factor
Engineering is important too because it helps to reduce the chance of human error. There are
two types of insider threats and those are intentional and unintentional. When a threat is
unintentional that means that a particular person has breached security through accident or
HUMAN FACTOR ENGINEERING
4
carelessness. A few examples would be an employee opening an email and clicking on a link or
opening an attachment that makes them enter in their credentials, or downloads software of the
system that has a backdoor in it that allows someone who shouldn’t have access to have access to
the system. An employee putting a thumb drive into the computer that they just randomly picked
up that loads software or crashes a computer system. This can result in equal loss of data or
system failure as an intentional attack. If it is unintentional though, the employee will usually
learn from their mistakes and make sure not to repeat the actions that caused the problem.
(Richardson, 2012) Since the early 1930s, human factors engineering has been a well-known
field of study. This is a very useful branch of engineering that is being investigated in connection
with cybersecurity. There are several issues in the realm of cybersecurity that can be resolved
with an understanding of the psychological aspects of human dynamics. Human factors are an
increasing topic in cybersecurity, ranging from understanding burnout for SOC analysts to
recruiting and retaining employees. Cybersecurity experts can enhance security by design, lessen
cognitive overload using security tooling, and raise knowledge of behavioral analytic
methodologies by studying and comprehending the principles of human factors. The popularity
of human aspects security in academic publications has been rising, and this trend is expected to
continue as more scientists and technological experts recognize the advantages of fusing the two
domains. “Behavioral techniques may also be used to help understand social engineering
attacks, like phishing, vishing, or spear phishing. More specifically, that users can be persuaded
to give out sensitive or personal information to malicious attackers. Understanding attacker and
user behavior can help to inform users what to be aware of, creating focused security awareness
training and implementing technical security controls as appropriate” (Robinson, 2023) “God is
not man, that he should lie, or a son of man, that he should change his mind. Has he said, and
HUMAN FACTOR ENGINEERING
5
will he not do it? Or has he spoken, and will he not fulfill it?” -Numbers 23:29 God knows that
human error is always possible. Every human in the world makes mistakes. But with the right
teachings whether it be through the Bible, or making sure employees are properly trained in
cybersecurity, can make sure that humans are less prone to make mistakes and are always trying
to do the right thing. This is where Human Factor Engineering comes into play at least when it
comes to cybersecurity.
Security Engineering
Security Engineering focuses on defining customer needs, security protection requirements, and
required functionality early in the systems development lifecycle, documenting requirements,
and then proceeding with design, synthesis, and system validation while considering the
complete problem. Cross-disciplinary knowledge is needed for security engineering, from
computer security and cryptography to hardware tamper-resistance and formal techniques, as
well as knowledge of applied psychology, economics, organizations, and the law. System
engineering abilities, which cover everything from software engineering to business process
analysis to testing and assessment, are equally crucial, but they fall short since they primarily
address mistakes and mishaps rather than malicious intent. Critical assurance requirements are
present in many security systems. Their failure could jeopardize public health and safety,
threaten the environment (as with nuclear safety and control systems), seriously impair vital
economic infrastructure (as with cash machines and other bank systems), jeopardize individual
privacy (as with medical record systems), jeopardize the viability of entire industry sectors (as
with pay-TV), and encourage crime (as with car alarms and burglar alarms). Part of keeping
things secure involves security analysis. (Anderson, n.d.) “Security analysis tasks are constrained
by time, skills, knowledge, methods, and other factors. These constraints may lead a security
HUMAN FACTOR ENGINEERING
6
engineer to prioritize work based on statistical analysis or a qualitative measure of risk. These
constraints may also lead a security engineer to focus on familiar issues, well-known
countermeasures, and convenient security mechanisms, rather than a more difficult path of
defining and evaluating the complete attack surface for the system.” (Whitmore, 2023)) Another
factor that would come into play would be using protocols which helps with human error
because it can be set up to only give people the access they absolutely need. “For example, the
logon protocol that consists of a user entering a password into a machine assumes that she can
enter it into the right machine. In the old days of hard-wired terminals in the workplace, this was
reasonable; now that people log on to websites over the Internet, it is much less so.” (Anderson,
n.d) An example would be they have to have a username and password to even get on the
system. Authentication between humans and machines is often referred to as login or logon.
Two types of authentications exist: machine-to-machine and human-to-machine. Though
distinct, they frequently cooperate to establish a chain of authentication, much like the idea of a
chain of custody for documents. Verifying to a computer that a person is who they say they are,
or at least that they match the identification of the person who is registered with the system, is
the goal of human-to-machine authentication. Multifactor authentication is something that is
becoming more and more necessary as well, so that a username and password is no longer
enough. There is an unspoken belief that a process is stronger the more components it uses.
When creating an authentication system, a security engineer should present a well-organized
case, or assurance case, outlining how weaknesses and strengths could complement one another
or even work against one another. (Basta, 2023) Firewalls are in place to make getting on the
internet is secure, and then emails have a spam filter that tries to help make sure phishing
attempts aren’t successful. “No weapon that is fashioned against you shall succeed, and you
HUMAN FACTOR ENGINEERING
7
shall refute every tongue that rises against you in judgment. This is the heritage of the servants of
the Lord and their vindication from me, declares the Lord.”-Isiah 54:17. Using security
engineering and security analysis and protocols is like using the Lord to help protect you and
guide you. It helps protect and guide the company so that it won’t have a cybersecurity attack.
Using security engineering and security analysis and protocols are just cogs in human factor
engineering.
Human Error
Social engineering is nearly always successful. While designers may roll their eyes, wish things
were otherwise, and point the finger at "dumb users" for the security lapse, the true culprits are
the cybersecurity engineers who built the systems with insufficient awareness of this reality. It is
impossible to make it impossible, just like any other attack, but it is plausible to make it seem
unlikely. In the event that social engineering attacks result in users disclosing their passwords,
designers ought to think about replacing passwords with a less susceptible form of verification,
such as biometrics, token-based systems, or multifactor authentication. After all, they are just
human. They have shortcomings, issues, ideologies, and unfulfilled needs. Adversaries may use
these to recruit insiders, especially highly privileged and well-positioned insiders like CEOs,
system administrators, and investigators hired to locate them. Insiders who have access to the
system can launch assaults from within and cause significant harm. This is especially
problematic for firms that concentrate on perimeter defenses, such as firewalls. If insiders have
access to monitoring tools like audit logs, they can hide the evidence of their attacks. They can
make sure that attacks happen below intrusion detection thresholds if they are aware of them.
(Basta, 2023) This helps to show that human error is in fact one of the biggest threats and that it
can help make a cyber attack happen. All companies need to prioritize cybersecurity, especially
HUMAN FACTOR ENGINEERING
8
since a lot of work environments changed due to the Covid-19 epidemic. The abrupt shift from
working in offices to working from home, or the "new normal," has brought about information
security issues involving human aspects. For instance, although they use the same platform for
information exchange, criminals and employees have quite different goals. However, the security
of information is jeopardized by both of their actions. Employee carelessness exposes systems to
risk, whereas criminals purposefully exploit systems to gain illegal access for their own gain.
(Ncubukezi, 2022) However, using human factor engineering to make devices safer and more
secure for user, and then using security engineering can indeed make it less likely that a cyber-
attack will happen due to human error. “Be sober minded; be watchful. Your adversary the devil
prowls around like a roaring lion, seeking someone to devour.” -1 Peter 5:8 God knows we have
enemies, for example the devil. We need to be watchful and sober minded to not succumb to
those enemies though. The same rule can be applied when looking at making sure employees
know who their enemies are when it comes to attacks and knows the ways to prevent this from
happening. Phishing is one example of a cyber-attack, that if an employee is properly trained on
how to recognize the attempt, then it will make it more difficult for the attack to be successful.
HealthCare and Human Error
Another example that would support that human error is one of the biggest threats to
cyber security and shows why we need human factor engineering and security engineering,
would be to look at the Healthcare industry. “In 2019, a survey identified human errors, such as
sending personal information to unintended email recipients or releasing personal information by
accident, as the largest source of data breaches in the health sector. Similarly, several peers were
found to be inadvertently sharing their financial, email, and web cache data in a study on the
KaZaA P2P network. In addition, some P2P users share their personal information intentionally
HUMAN FACTOR ENGINEERING
9
to increase the number of files shared on the network to meet the participation requirements of
some P2P systems. Most breaches are the product of human error. When it comes to recovering
medical data from leaks, it is shown that it is more expensive than other sort of information to
recover. This results in high expenses. Therefore, prevention is crucial. More than 70% of data
breaches in the US that were recently analyzed involved medical institutions.
Nurses are continually exposed to and flooded with patient data. Despite overseeing making sure
patient health information is safeguarded, nurses have been complicit in information security
breaches. Nurses are responsible for the violations, yet they can and do still happen. Secret
information, for instance, may be accidentally disclosed in talks out in the hallways, or in an
elevator, or while on break or lunch. Secret information-containing files may be misplaced
during archiving or because of irresponsible disposal. Computers could be left unlocked, and
someone not authorized may see information that they should not. A rogue usb drive could be
placed into a computer that should not be used, that might contain malware of some kind.
(Kang, 2022) “Security issues are defined as any action that could be used to disrupt the
functionality of the peer-to-peer network or enable unauthorized users to access, modify, or
delete user data, specifically, due to threats or vulnerabilities, such as malware, bugs, access
control failures, or patients' inadvertent exposure of their data.” (Abdullahi, 2021) Cybersecurity
controls and assumptions mitigate threats. Combinations of these elements are represented by a
“Combined Mitigations” node type. In some cases, controls and assumptions may be similar due
to technical circumstances. Technical measures like channel encryption used by the SUD are
usually modeled as controls. By contrast, laws of nature, responsibilities, or controls of third
parties, attacker capabilities, and the analysis limits are documented as assumptions. Controls
and assumptions, like threats, provide attack feasibility factors and protected security properties.
HUMAN FACTOR ENGINEERING
10
The attack feasibility factors facilitate the estimation of the controls or assumption’s effect on the
attack feasibility of related threats.” (Angermeier, 2023) “If we say we have no sin, we deceive
ourselves, and the truth is not in us.” -1 John 1:8 Human error is a given, you can find it
throughout the Bible. God knows it and still loves us anyways. But by recognizing that it will
happen and trying to learn about ways to make it happen less and taking precautions to prevent
it, you can not only help yourself be better, but also help protect a company and other people.
Conclusion
In conclusion some things to take away from this would be what is Human factor engineering?
“Human Factors Engineering, also known as ergonomics, is the discipline of understanding
physical and psychological components of humans and applying them to devices for human use.
The reason Human Factors Engineering is an important science, is because it helps to improve
the safety and efficiency of devices for users.” (Robinson, 2023) What is Security Engineering
and how does it work with Human Factor Engineering? Security Engineering focuses on
defining customer needs, security protection requirements, and required functionality early in the
systems development lifecycle, documenting requirements, and then proceeding with design,
synthesis, and system validation while considering the complete problem. They work together
because they human factor engineering makes sure devices are safe for users, and security
engineering helps make sure that users are keeping information that are on devices safe from
cyber-attacks. How does human error work with human factor engineering and security
engineering. Social engineering is nearly always successful. Human error is what causes social
engineering to be successful. While designers may roll their eyes, wish things were otherwise,
and point the finger at "dumb users" for the security lapse, the true culprits are the cybersecurity
engineers who built the systems with insufficient awareness of this reality. Because of this
HUMAN FACTOR ENGINEERING
11
human factor engineering and security engineering has to work together to make sure human
error is likely to happen and cause cyber attacks to be successful. Is human error really a big
threat to cybersecurity especially in healthcare. Most breaches are the product of human error.
When it comes to recovering medical data from leaks, it is shown that it is more expensive than
other sort of information to recover. This results in high expenses. Therefore, prevention is
crucial. More than 70% of data breaches in the US that were recently analyzed involved medical
institution. (Kang, 2022) How does Security Engineering help with human error? Security
engineering helps with human error, because it makes sure that protocols and rules are in place
that helps reduce human error from occurring. If done correctly it will also make sure that all
employees are properly trained and continuously updated on new threats so that they know what
to look for to avoid letting a social engineering attack be successful. How does Human Factor
Engineering help with human error? Human Factor Engineering helps make sure that devices
that humans use are safe for users to use, which makes it harder for a cyber-attack to happen.
Making morally sound decisions is more likely for the Christian who strives for godly character.
A right purpose springs from a right heart and aims to accomplish a godly goal. In the end, we
are looking for God's reign and his glory. This goal is fulfilled in our daily activities by looking
out for others' interests while avoiding choices that can be harmful. From the first two
viewpoints, right behavior follows. By first cultivating a right heart and pursuing a proper goal,
the Christian will be more inclined to act in a righteous manner. The Christian who adopts this
strategy will be more likely to make decisions with a solid foundation that honor God and
advance his kingdom. (2022 Scholoemer)
References
HUMAN FACTOR ENGINEERING
12
Abdullahi Yari I, Dehling T, Kluge F, Geck J, Sunyaev A, Eskofier B. Security Engineering of
Patient-Centered Health Care Information Systems in Peer-to-Peer Environments:
Systematic Review. J Med Internet Res. 2021 Nov 15;23(11):e24460. doi:
10.2196/24460. PMID: 34779788; PMCID: PMC8663665.
Anderson. (n.d.). Protocols - University of Cambridge. Protocols.
https://www.cl.cam.ac.uk/~rja14/Papers/SEv2-c03.pdf
Anderson. (n.d.). What is security engineering? - university of Cambridge. What is Security
Engineering? https://www.cl.cam.ac.uk/~rja14/Papers/SEv2-c01.pdf
Angermeier, D., Wester, H., Beilke, Hansch, G., Eichler, J. 2023. Security Risk Assessments:
Modeling and Risk Level Propagation. ACM Trans. Cyber-Phys. Syst. 7, 1, Article 8 25
pages. https://doi.org/10.1145/3569458
Basta, Alfred 2023.NSecurity Engineering. McGraw Hill
https://bookshelf.vitalsource.com/books/9781307917031
J. Whitmore. (2023). Information-Driven Security Analysis: Tools and Techniques for the Study
and Practice of Security Engineering.Computer,56(6), 107-
120.Nhttps://doi.org/10.1109/MC.2023.3263575
Kang, P. , Kang, J. & Monsen, K.N(2022).NNurse Information Security Policy Compliance,
Information Competence, and Information Security Attitudes Predict Information
Security Behavior.NCIN: Computers, Informatics, Nursing,Publish Ahead of Print,Ndoi:
10.1097/CIN.0000000000000981.
Ncubukezi, T. (2022).NHuman Errors: A Cybersecurity Concern and the Weakest Link to Small
Businesses. Academic Conferences International Limited.
References Continued
HUMAN FACTOR ENGINEERING
13
Robinson, N. (2023). HUMAN FACTORS SECURITY ENGINEERING: THE FUTURE OF
CYBERSECURITY TEAMS.Edpacs,67(5), 1-
17.Nhttps://doi.org/10.1080/07366981.2023.2211429
Scholoemer, P. (2022). Business Ethics: A Christian Method for Making Moral Decisions. The
Journal of Biblical Integration in Business, 25(1), 109-110.
https://cbfa-jbib.org/index.php/jbib/article/view/630/629
Students also viewed