The information security industry has experienced remarkable growth over the past few decades, particularly in presenting various solutions from technical, managerial, and institutional perspectives. Despite these advancements, security incidents cont...
The information security industry has experienced remarkable growth over the past few decades, particularly in presenting various solutions from technical, managerial, and institutional perspectives. Despite these advancements, security incidents continue to occur annually, highlighting a critical issue: existing security measures are overly focused on technology and prevention, failing to address the diverse business changes of the digital age. This has led to a rising interest in People-Centric Security(PCS), which seeks to overcome the limitations of traditional security approaches.
This study aims to analyze fundamental causes of security incidents by categorizing human-induced vulnerabilities into five progressive expansion types based on the ethical perspective of value relation extension, further subdividing them into 20 detailed components. The research introduces the concept of information security violations, strategic principles of PCS, and employs Focus Group Interviews (FGI) with experts to evaluate the effectiveness of human vulnerability checklists.
Human vulnerabilities are classified into five major categories: ‘personal vulnerability,’ which focuses on individual traits; ‘interpersonal relationships,’ concerning interactions between people; ‘Organizational Threats,’ related to intra-organizational dynamics; ‘sociality,’ arising from broader social interactions; and ‘ethicality,’ addressing universal ethical considerations. By defining these categories and their components, a comprehensive human vulnerability classification model is developed.
The industry has continually evolved, offering diverse solutions and preventative measures, particularly on the technical front. However, the persistent occurrence of security incidents necessitates a reevaluation of overlooked areas beyond technological and managerial aspects. Despite the long-standing emphasis on human security, intensive research and investment have lagged. Consequently, the Zero Trust security model, which operates on the premise of trusting no one in cyberspace, has gained traction, naturally leading to a focus on people-centric security.
Gartner's 2024 major cybersecurity trends underscore the importance of communication with management and the significance of security behavior and culture programs, highlighting the shift towards human-centric security strategies. This consensus acknowledges that relying solely on security solutions or policies is insufficient to combat increasingly sophisticated threats driven by IT advancements. In light of this, there is a growing need for in-depth research on human security. Similar to systematic vulnerability classifications for databases, networks, servers, and endpoints, establishing a fundamental classification model for human-induced vulnerabilities is a crucial starting point. This study leverages the principles of PCS, ISMS-P human security control standards, and a cybercrime profiling approach to analyze psychological aspects, conducting iterative FGIs and both qualitative and quantitative research to propose an optimized human vulnerability classification model.
Furthermore, based on the proposed model, this study develops specific measurement indicators for each category, ultimately deriving 168 human security measurement items through phased research, expansion, and validation. The goal is to clarify and objectify abstract human security control standards. Given the novelty of developing classification models or measurement indicators for human-induced security vulnerabilities compared to technical perspectives, this research relied heavily on FGIs and Delphi surveys involving domain experts.
In conclusion, considering the current state of human security research and the limitations of information security, the human vulnerability classification model and the development of specific measurement indicators presented in this study are expected to establish a new normal in human security within the complex and diverse IT environment.