Human error analysis for unsafe events of cloud ERP based on FTA-BN

ZHANG Bingjian,SU Qin,LIU Hailong
DOI: https://doi.org/10.16265/j.cnki.issn1003-3033.2023.02.0412
2023-01-01
Abstract:In order to figure out the human error factors of unsafe events of cloud ERP, a human error analysis model based on FTA-BN was constructed, which could avoid the limitations of a single method. Firstly, the unsafe events which were disclosed by security audit records of cloud ERP were classified and the causes of these events were analyzed, then the fault tree of unsafe events of cloud ERP was constructed. Moreover, the quantitative analysis of the minimum cut and structure importance were carried on according to the fault tree. Then the fault tree was mapped to BN structure. Based on case data, the final BN was obtained by structure learning and parameter learning. Furthermore, the probability of unsafe events was predicted by predictive reasoning and the critical human error factors were identified by sensitivity analysis. The results show that the key human error factors include inadequate work, insufficient training, insufficient resource, unclear responsibility and problems in the management process, so major efforts should be made on them to ensure sustainable security.
What problem does this paper attempt to address?