Info Risk Vulnerabilities Blog

Friday, September 14, 2012

Human error and vulnerabilities

Human error is a strange threat as its activity often results in the creation of vulnerabilities.  Coding errors create application vulnerabilities and administration errors create configuration vulnerabilities.  Training is about  the only measure to act against the occurrence of errors.  Various scanners can help to detect vulnerabilities but someone has to go in and correct the error, a shortcoming in my opinion, as the correction can be erroneous and new vulnerabilities result.  It can all become quite a vicious cycle.  Human error is so common, particularly in long processes, such as configuring a system that finding ways to take the human out of the process has significant value, thus mirroring and similar approaches are important.  The incidence of an error created vulnerability needs timely identification and remediation as human threat agents have their own ways of quickly finding and exploiting them.  Interestingly this fact showed up on a "Top 10 " list recently, which got me rethinking the issues.  Like malware many of us considered config errors to be a solved, if endemic problem.  Annoying but little more.  Obviously we were too optimistic as sophisticated firms continue to be bitten for what can generously be referred to as flawed policies and aggressive threats ready to pounce on any opportunity. 

0 Comments:

Post a Comment

<< Home