Abstract
Many of information security measures are technical ones, and today even small and medium-sized enterprises adopt such measures. However, it is also true that human error is one of the most important fact for information security measures. In this paper, factors of incidents are classified based on investigation on statistics related to the information security incidents in Japan. By making use of this classification including human error factor we build cognitive map of information security and clarify factors of information security incidents.