China Safety Science Journal ›› 2023, Vol. 33 ›› Issue (2): 38-47.doi: 10.16265/j.cnki.issn1003-3033.2023.02.0412
• Safety social science and safety management • Previous Articles Next Articles
ZHANG Bingjian1,2,3(), SU Qin1,2,3, LIU Hailong1,2,3
Received:
2022-09-20
Revised:
2022-12-10
Online:
2023-02-28
Published:
2023-08-28
ZHANG Bingjian, SU Qin, LIU Hailong. Human error analysis for unsafe events of cloud ERP based on FTA-BN[J]. China Safety Science Journal, 2023, 33(2): 38-47.
Add to citation manager EndNote|Ris|BibTeX
URL: http://www.cssjj.com.cn/EN/10.16265/j.cnki.issn1003-3033.2023.02.0412
Tab.3
Name and description of human error factors
名称 | 中文描述 | 文献来源 | |
---|---|---|---|
缺乏责任心或对安全规程持有忽视、冷漠和抵抗的态度 | [ [ | ||
缺少对特定岗位角色、权限、责任的认识 | [ | ||
没有严格按照安全规程执行操作,如配置监督、防御措施等 | [ [ | ||
缺少员工安全实践的培训,导致“钓鱼攻击”等的发生 | [ | ||
名称 | 中文描述 | 文献来源 | |
管理层支持不够,在安全上投入的人力、物力、财力不足 | [ | ||
工作、组织与管理流程中的问题,包括授权流程、终止权限、资产返还、人员调配、沟通协调等 | [ | ||
工作难度高、责任重、任务多导致人员身心疲劳、压力爆棚,人员能力有限,无法及时保障云安全 | [ | ||
不具备岗位所需的技能和经验,无法应对系统故障或外部攻击 | [ | ||
缺少安全治理的措施、制度与政策;缺少对安全行为的奖励和对不安全行为的惩罚;没有安全氛围 | [ |
Tab.6
Probability of unsafe events when setting the states of human error factors%
不安全人因类型 | 不安全事件类型 | |||
---|---|---|---|---|
基础设施、设备与虚拟化管理 | 软件管理 | 数据资产管理 | 人员管理 | |
安全意识浅薄 | 8.57 | 47.26 | 26.21 | 11.46 |
职责不清 | 8.57 | 54.66 | 23.90 | 11.46 |
工作不到位 | 8.48 | 28.24 | 23.98 | 7.54 |
培训和教育不足 | 8.57 | 29.56 | 53.48 | 18.21 |
资源分配不足 | 75.02 | 28.52 | 22.51 | 11.46 |
管理流程的问题 | 8.57 | 28.52 | 22.51 | 41.04 |
任务复杂 | 8.57 | 28.52 | 22.51 | 68.66 |
技能、经验不足 | 11.14 | 36.30 | 25.84 | 21.85 |
安全文化环境匮乏 | 8.57 | 42.99 | 47.95 | 11.46 |
维护不当 | 100 | 29.57 | 22.89 | 11.88 |
应用程序和终端不安全 | 8.57 | 76.13 | 35.80 | 9.17 |
供应故障 | 8.61 | 86.73 | 24.24 | 12.91 |
病毒感染 | 8.82 | 81.81 | 26.23 | 11.62 |
系统崩溃 | 9.31 | 79.37 | 37.62 | 11.18 |
数据加密不当 | 8.48 | 29.72 | 88.75 | 14.81 |
数据存储不当 | 8.57 | 44.75 | 85.17 | 11.29 |
数据泄露篡改 | 9.29 | 50.09 | 80.25 | 10.62 |
没有尽责 | 8.57 | 28.94 | 35.01 | 95.54 |
资质能力 | 9.12 | 25.82 | 16.81 | 97.10 |
人员违规 | 8.50 | 51.35 | 35.48 | 8.47 |
人员差错 | 9.82 | 52.22 | 34.33 | 10.96 |
[1] |
国务院. “十四五”数字经济发展规划[EB/OL].(2022-01-12). http://www.gov.cn/zhengce/content/2022-01/12/content_ 5667817.htm
|
[2] |
工业和信息化部. 工业和信息化部关于印发《推动企业上云实施指南(2018—2020年)》的通知[EB/OL]. (2018-08-10). https://www.miit.gov.cn/jgsj/xxjsfzs/wjfb/art/2020/art_06a6a6a924ba46adb39735d90f61765d.html
|
[3] |
曾忠平. 信息安全人因风险研究进展综述[J]. 情报杂志, 2014, 33(4) : 6-11.
|
|
|
[4] |
Cloud Security Alliance. Top threats to cloud computing: egregious eleven[EB/OL].(2019-08-06). https://cloudsecurityalliance.org/artifacts/top-threats-to-cloud-computing-egregious-eleven/
|
[5] |
doi: 10.1016/j.cose.2009.05.008 |
[6] |
|
[7] |
高原, 吴长安. 云计算下的信息安全问题研究[J]. 情报科学, 2015, 33(11):48-52.
|
|
|
[8] |
doi: 10.1016/j.cose.2009.04.006 |
[9] |
|
[10] |
王军武, 王梦雨, 刘登辉, 等. 基于HFACS-BN的地铁车站施工高处坠落可能性评价[J]. 中国安全科学学报, 2021, 31(6):90-98.
doi: 10.16265/j.cnki.issn 1003-3033.2021.06.012 |
doi: 10.16265/j.cnki.issn 1003-3033.2021.06.012 |
|
[11] |
许保光, 王蓓蓓, 池宏, 等. 基于贝叶斯网络的航空安全中不安全信息分析[J]. 中国管理科学, 2020, 28(12):118-128.
|
|
|
[12] |
潘丹, 李永周, 罗帆, 等. 飞行区外来物入侵安全风险致因FTA-BN模型[J]. 中国安全科学学报, 2021, 31(6):7-13.
doi: 10.16265/j.cnki.issn 1003-3033.2021.06.002 |
doi: 10.16265/j.cnki.issn 1003-3033.2021.06.002 |
|
[13] |
doi: 10.1016/j.ress.2011.03.012 |
[14] |
周志华. 机器学习[M]. 北京: 清华大学出版社, 2016:156-157.
|
[15] |
Cloud Security Alliance. CCM v4.0 implementation guidelines[EB/OL]. [2021-12-03]. https://cloudsecurityalliance.org/artifacts/ccm-v4-0-implementation-guidelines/
|
[16] |
ENISA. Cloud computing benefits, risks and recommendations for information security: cloud computing security risk assessment[EB/OL]. (2022-05-24). https://www.enisa.europa.eu/publications/cloud-computing-risk-assessment
|
[17] |
doi: 10.1016/j.future.2010.12.006 |
[18] |
|
[19] |
姜茸, 马自飞, 李彤, 等. 云计算安全风险因素挖掘及应对策略[J]. 现代情报, 2015, 35(1):85-90.
doi: 10.3969/j.issn.1008-0821.2015.01.016 |
doi: 10.3969/j.issn.1008-0821.2015.01.016 |
|
[20] |
|
[21] |
周知, 吕美娇. 云服务中的数字学术信息资源安全风险防范[J]. 数字图书馆论坛, 2017(7):14-19.
|
|
|
[22] |
|
[23] |
|
[24] |
doi: 10.1016/j.cose.2006.02.008 |
[25] |
doi: 10.1016/j.cose.2006.11.004 |
[26] |
|
[27] |
doi: 10.1080/10658980701401959 |
[28] |
|
[29] |
|
[30] |
|
[1] | LI Yike, ZHANG Honghai, SHI Zongbei, ZHOU Jinlun. Coupling mechanism of air traffic operation safety risk based on N-K-FRAM [J]. China Safety Science Journal, 2024, 34(5): 175-185. |
[2] | LIU Fupeng, YANG Jiu, WU Shibo, XU Lixin. Quantitative risk analysis on failure of submarine pipeline leakage based on FDHHFLTS-BN [J]. China Safety Science Journal, 2024, 34(1): 166-170. |
[3] | SUN Yilin, ZHENG Xiaoqiang, LIU Xianfeng, HE Yanyan, WANG Ye. Analysis of gas pipeline leakage and explosion accident based on AcciMap model [J]. China Safety Science Journal, 2023, 33(7): 140-146. |
[4] | WU Haitao, LIU Yue, DU Huimin. Research on model of subway operation accident's cause under small sample condition [J]. China Safety Science Journal, 2023, 33(3): 134-140. |
[5] | MA Gang, XU Xiaonan, GUO Xiaofang, ZHANG Zhizhen, XU Zihao. Scenario deduction of fire accidents in electroplating enterprises based on Bayesian network [J]. China Safety Science Journal, 2023, 33(2): 202-208. |
[6] | WANG Jinjiang, GUAN Pengting, CHEN Zhuo, GE Weifeng, JU Qian. Intelligent warning of risk during maintenance operations based on deep learning [J]. China Safety Science Journal, 2023, 33(10): 16-22. |
[7] | HU Yu. Human error analysis and pre-control measures of power generation enterprises [J]. China Safety Science Journal, 2022, 32(S2): 19-25. |
[8] | ZHAO Jianwei, XIE Lei, YANG Yang, HU Xinyuan, OU Changkui, ZENG Rong. An ISM-BN based research on navigation risk factors of inland waterway vessels [J]. China Safety Science Journal, 2022, 32(8): 37-44. |
[9] | LI Xiang, LI Xiao, WANG Song, LEI Miaomiao, LAI Bentao. Study on factors leading to human errors in railway maintenance [J]. China Safety Science Journal, 2022, 32(6): 23-30. |
[10] | YANG Yue, MA Bokai, CAO Yuxuan. Human error risk analysis based on foreign unsafe events in air traffic management [J]. China Safety Science Journal, 2022, 32(12): 38-45. |
[11] | ZHANG Yan, CHEN Xingbang, LI Ming, WU Song, TONG Ruipeng. Intellectual structure and evolution trend of human error and human reliability in complex industrial systems [J]. China Safety Science Journal, 2022, 32(12): 46-52. |
[12] | HAN Peng, WANG Jun, WANG Qi, ZHAO Yifei. Study on air traffic control risks of aircraft flight test activities based on flight profile [J]. China Safety Science Journal, 2022, 32(1): 149-156. |
[13] | WEN Xinyu, ZHANG Jian. Fault-handling strategies and methods large-scale thermal power units [J]. China Safety Science Journal, 2021, 31(S1): 103-108. |
[14] | HU Yunpin, LI Chao, LI Zongliang, YANG Daohe. IHFACS-BN safety assessment model for large-span steel structure construction and its application [J]. China Safety Science Journal, 2021, 31(8): 147-154. |
[15] | YANG Yue, SONG Xiangbo, WANG Jianzhong. Quantitative analysis method of ATCO's error risks based on TRACEr [J]. China Safety Science Journal, 2020, 30(8): 109-115. |
Viewed | ||||||
Full text |
|
|||||
Abstract |
|
|||||