Managing Human Factors Vulnerabilities in the Risk Assessment Process
摘要
Risk assessment, a crucial component of an organization's information security risk management program, is heavily influenced by human decision-making. Human factor elements can affect decision-making, introduce vulnerabilities in the risk assessment process, and impact the deliverables. We aim to create awareness for organizations to focus attention and resources on reducing and capturing human error at the early stages of risk management programs. This paper delves into these human factors, exploring their impact on decision-making and risk assessment. We provide recommendations to address these vulnerabilities at all levels of the risk assessment approach, aiming to enhance organizations’ overall information technology security.