@zackwhittaker
Human error describes the proximate cause of an incident, not the root cause.
Human error is a symptom, not the cause, of failure.ย
Human error is a social judgment, not an objective conclusion.
Human error is the start of the investigation, not the conclusion.
Human error can reveal systemic design flaws in the system that fail to account for human use.
Human error as a conclusion will lead to myopic and insufficient remedies like โuser educationโ.
Human error is a label that shifts responsibility from system designers to system users who will inevitably fail.
๐ฆ๐๐๐๐ฒ๐บ๐ ๐๐ต๐ฎ๐ ๐ณ๐ฎ๐ถ๐น ๐ฏ๐ฒ๐ฐ๐ฎ๐๐๐ฒ ๐ผ๐ณ ๐ฎ๐ป ๐ถ๐ป๐ป๐ผ๐ฐ๐ฒ๐ป๐ ๐บ๐ถ๐๐๐ฎ๐ธ๐ฒ ๐ฏ๐ ๐ฎ ๐ต๐๐บ๐ฎ๐ป ๐ฎ๐ฟ๐ฒ ๐ฑ๐ฒ๐๐ถ๐ด๐ป๐ฒ๐ฑ ๐๐ต๐ฎ๐ ๐๐ฎ๐. ๐ง๐ต๐ฒ๐ ๐ฎ๐ฟ๐ฒ ๐ฏ๐ฟ๐ถ๐๐๐น๐ฒ ๐ฏ๐ ๐ฑ๐ฒ๐๐ถ๐ด๐ป.
If you are curious as to why we should be intolerant of the label โhuman errorโ when talking about security incidents, please see Behind Human Error by David Woods and friends.