A longitudinal study of information system threat categories: the enduring problem of human error

  • Authors:
  • Ghi Paul Im;Richard L. Baskerville

  • Affiliations:
  • Georgia State University;Georgia State University

  • Venue:
  • ACM SIGMIS Database
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Taxonomies of information security threats usually distinguish between accidental and intentional sources of system risk. Security reports have paid a great deal of attention in recent years to the growing problem of hacking and intentional abuse. The prevalence of these reports suggests that hacking has become a more severe problem in relation to other security threats, such as human error. In this paper, we report on research that addresses this question: "How have changes over time in the frequency of hacking and other intentional forms of security threats affected the validity of information systems risk management taxonomies?" We replicate a simple study of the proportions of categories of security threats that was originally completed in 1993. Comparing the results from the replicated study with the results from the original study, we find that the proportions of threat categories have, in contradiction with the popular perception, remained relatively stable over the past decade. These results indicate that human error remains a significant and poorly recognized issue for information systems security. We propose and validate an elaborated taxonomy of information security threats that provides additional insight into human error as a significant source of security risk.