Technology rarely fails on its own. Behind most security incidents stands a person: a developer who missed a detail, an administrator who left a setting open, or a user who trusted the wrong message. This category examines the human side of security, which is often the weakest link and almost always the hardest to patch. It belongs in the Foundation pillar because no amount of tooling matters if the people around it are not accounted for.
The topics below describe the main ways people shape outcomes.
Human error in design and development looks at the mistakes introduced when systems are built, from flawed logic to overlooked edge cases.
Misconfiguration covers the gap between a secure design and a secure deployment, where defaults and oversights create openings.
User behavior and misuse examines how everyday choices, shortcuts, and habits expose systems to risk.
Lack of training and awareness addresses the knowledge gap that leaves people unable to recognize threats.
Humans as the root cause behind most incidents ties these threads together and explains why culture and education matter as much as technology.