Grand Duchy of Luxembourg
Advice & Guidance
Human Error

Human Error

In Brief

Considering human errors as threats may seem a little insensitive, yet as statistics from various organisations show, they are still a very common cause of IT incidents.

Types of Error


‘Human error’ is defined as any human behaviour that does not fall under correct usage and may involuntarily result in various damages. Voluntary acts committed with malicious intent are not considered errors.

Drawing up an exhaustive list of human errors would be impossible. It might not be possible to list all possibilities for human error, but it is, however, possible to identify some distinctive criteria that we can use to categorise human error.

Errors Through Negligence

Actions carried out by people who understand the rules, but fail to apply them fall under this heading. Negligence can, therefore, be considered a voluntary act. However, negligence is rarely intended to be fraudulent.

Examples:

  • not following procedures set out for saving data,
  • deactivating the antivirus update when starting up the computer,
  • sharing a password with a colleague,
  • using the company’s IT architecture for personal use,
  • installing ‘non-standard’ software on a machine.

Errors Through Incompetence

This category includes all errors committed unknowingly. A number of errors may be committed ‘in good faith’, without the user having realised they were acting irresponsibly or breaking a rule, and without them realising the consequences of their actions.

Examples:

How Does It Work?


Human errors are unintentional threats that exploit different vulnerabilities, such as

Idleness and Lack of Conscientiousness

This category includes all acts committed through negligence and that is very difficult to combat, except by making employees accountable and using sanctions.

Lack of Training or Security Awareness

A person’s lack of awareness is a huge vulnerability, of which the result is a lack of awareness of the error committed and the inability for the error to be detected and corrected.

A person’s lack of training and security awareness is a vulnerability that can easily be exploited through the highly dangerous threat of social engineering.

How Can We Protect Ourselves?

The American mathematician Gilb’s Law of ‘unreliability’ states that ‘Any system which depends on human reliability is unreliable.’

There are multiple ways to combat human error. However, it is recommended that you focus on limiting the impact of human error and not get caught up in the idea that we will ever be able to avoid human error entirely. The primary countermeasures are as follows:

Awareness

Increased awareness is an easy way to noticeably reduce risk.

Most people mean well and if they are aware of the importance of their daily actions, as well as the value of the data processed, they will make sure they treat it with due diligence.

Training

The best way to avoid the incorrect handling of data and software is to train the users on how to use the software and devices.

Implementation and Control of Procedures

It is vital to introduce procedures covering all important security-related aspects (access, backups, etc.). These procedures must be cyclically controlled, and non-compliance should result in sanctions. These procedures are generally part of the security policy.

Double Validation

In order to avoid data entry errors in critical software (e.g. electronic payment), it is a good idea to set up a duplicate data entry or a double validation system.

Error Management and Follow-up

As errors cannot be avoided entirely, it is important to learn from the consequences so they do not happen again. Only a targeted analysis of the mistakes made and what caused them can prevent them from being repeated in the future.

Centralised Administration

To minimise human error, it is advisable to limit access to software and data only to those persons who really need to use them (see: access management and authentication).