错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Adaptation of STPA-sec: A Case Study in the Socio-Technical Control Inputs Taxonomies for Health Information Cyber Security

  • Joseph Kaberuka

摘要

In the aftermath of ransomware incidents in UK and US hospitals, healthcare cyber security strategies have faced criticism for lagging behind those of other industries, thereby making the healthcare sector more vulnerable to cyber-attacks. Security standards and regulations designed to support healthcare security generally recognize cyber security in healthcare as a complex socio-technical problem. Implementing technical countermeasures relies on the collaboration and commitment of various stakeholders. The Systems Thinking approach (STAMP) has found applications across diverse socio-technical domain and its extension, STPA-sec, is tailored for cyber security analysis. STPA-sec has proven effective in addressing the socio-technical challenges of cyber security. However, when applied in the area of limited resources, the efficacy of the methodology came at a cost (Kaberuka and Johnson in: 2020 International conference on cyber security and protection of digital services (cyber security). IEEE, 2020). In fact, in regions with a scarcity of trained analysts and reliance on traditional cyber security methods, there is a need for detailed information to facilitate appropriate interventions. Hence, this paper argues that in an environment characterized by a shortage of socio-technical trained analysts, coupled with a substantial public demand and sociotechnical threats, there is a pressing need to offer adequate support. We observed several limitations in relation to security extension of the method. We propose an improvement with extended control inputs taxonomies that are pertinent to this context. Future work is needed to evaluate whether the extended technique becomes effective in the area with advanced trained analysts.