{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T17:36:07Z","timestamp":1725471367311},"publisher-location":"Berlin, Heidelberg","reference-count":37,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540465355"},{"type":"electronic","value":"9783540465362"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2006]]},"DOI":"10.1007\/11892960_148","type":"book-chapter","created":{"date-parts":[[2006,10,9]],"date-time":"2006-10-09T17:29:42Z","timestamp":1160414982000},"page":"1234-1241","source":"Crossref","is-referenced-by-count":3,"title":["General Drawing of the Integrated Framework for Security Governance"],"prefix":"10.1007","author":[{"given":"Heejun","family":"Park","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sangkyun","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hong Joo","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"148_CR1","unstructured":"GDRC: The Global Development Research Center (2005)"},{"key":"148_CR2","unstructured":"Appel, W.: Redefining IT Governance Readiness. META Group (2005)"},{"key":"148_CR3","unstructured":"Dallas, S., Bell, M.: The Need for IT Governance: Now More than Ever. Gartner Inc., Stamford (2004)"},{"key":"148_CR4","doi-asserted-by":"crossref","unstructured":"Solms, B.V.: Corporate Governance and Information Security. Computers & Security\u00a020(3) (2001)","DOI":"10.1016\/S0167-4048(01)00305-4"},{"key":"148_CR5","unstructured":"Conner, F.W., Coviello, A.W.: Information Security Governance: A Call to Action. National Cyber Security Summit Task Force (2004)"},{"key":"148_CR6","doi-asserted-by":"crossref","unstructured":"Solms, B.V.: Information security governance: CobiT or ISO 17799 or both? Computers & Security\u00a024(2) (2005)","DOI":"10.1016\/j.cose.2005.02.002"},{"key":"148_CR7","unstructured":"Swindle, O., Conner, B.: The Link Between Information Security and Corporate Governance. Computerworld (2004)"},{"key":"148_CR8","unstructured":"IT Governance Institute: Information Security Governance. IT Governance Institute (2004)"},{"key":"148_CR9","unstructured":"IT Governance Institute: Board Briefing on IT Governance ITGI. IT Governance Institute (2001)"},{"key":"148_CR10","unstructured":"OECD: OECD Principles of Corporate Governance, Organization for Economic Co-operation and Development. Organisation for Economic Co-operation and Development (1999)"},{"key":"148_CR11","unstructured":"Neela, A.M., Mahoney, J.: Work With, Not Against, Your Culture to Refine IT Governance. Gartner Inc., Stamford, CT (2003)"},{"key":"148_CR12","volume-title":"An Introduction to Governing for Enterprise Security","author":"J. Allen","year":"2005","unstructured":"Allen, J.: An Introduction to Governing for Enterprise Security. Software Engineering Institute, Carnegie Mellon University in Pittsburgh (2005)"},{"key":"148_CR13","unstructured":"IT Governance Institute: Information Security Governance: Guidance for Boards of Directors and Executive Management. IT Governance Institute (2001)"},{"key":"148_CR14","doi-asserted-by":"crossref","unstructured":"Moulton, R., Coles, R.S.: Applying Information Security Governance. Computers & Security\u00a022(7) (2003)","DOI":"10.1016\/S0167-4048(03)00705-3"},{"key":"148_CR15","volume-title":"Six IT Governance Rules to Boost IT and User Credibility","author":"S. Dallas","year":"2002","unstructured":"Dallas, S.: Six IT Governance Rules to Boost IT and User Credibility. Gartner Inc., Stamford, CT (2002)"},{"key":"148_CR16","unstructured":"Gerrard, M.: Creating an Effective IT Governance Process. Gartner Inc., Stamford, CT (2003)"},{"key":"148_CR17","series-title":"Lecture Notes in Computer Science","volume-title":"Computational Science and Its Applications \u2013 ICCSA 2005","author":"S. Kim","year":"2005","unstructured":"Kim, S., Leem, C.S.: An Information Engineering Methodology for the Security Strategy Planning. In: Gervasi, O., Gavrilova, M.L., Kumar, V., Lagan\u00e1, A., Lee, H.P., Mun, Y., Taniar, D., Tan, C.J.K. (eds.) ICCSA 2005. LNCS, vol.\u00a03482, Springer, Heidelberg (2005)"},{"key":"148_CR18","unstructured":"Kim, S., Leem, C.S.: Decision Supporting Method with the Analytic Hierarchy Process Model for the Systematic Selection of COTS-based Security Control. Lecture Series on Computer Scienceand on Computational Science, vol.\u00a01 (2004)"},{"key":"148_CR19","doi-asserted-by":"crossref","unstructured":"Kim, S., Leem, C.S.: Information Strategy Planning Methodology for the Security of Information Systems. In: ICCIE 2004, Cheju (2004)","DOI":"10.1007\/978-3-540-24707-4_71"},{"key":"148_CR20","unstructured":"ISO, ISO13335-1: Information Technology - Guidelines for the Management of IT Security - Part 1: Concepts and Models for IT Security. International Organization for Standardization"},{"key":"148_CR21","unstructured":"NIST: An Introduction to Computer Security: The NIST Handbook. NIST, Gaithersburg, MD (1995)"},{"key":"148_CR22","unstructured":"Henze, D.: IT Baseline Protection Manual. UK (2000)"},{"key":"148_CR23","unstructured":"Kim, S., Choi, S.S., Leem, C.S.: An Integrated Framework for Secure E-business Models and Their Implementation. In: INFORMS 1999, Seoul(1999)"},{"key":"148_CR24","unstructured":"Geer, D.E.: Making Choices to Show ROI. Secure Business Quarterly\u00a01(2) (2001)"},{"key":"148_CR25","unstructured":"Scott, D.: Security Investment Justification and Success Factors. Gartner Inc., Stamford, CT (1998)"},{"key":"148_CR26","unstructured":"Blakley, B.: Returns on Security Investment: An Imprecise But Necessary Calculation. Secure Business Quarterly\u00a01(2) (2001)"},{"key":"148_CR27","volume-title":"A Security Funding Strategy","author":"W. Malik","year":"2001","unstructured":"Malik, W.: A Security Funding Strategy. Gartner Inc., Stamford (2001)"},{"key":"148_CR28","unstructured":"Power, R.: CSI\/FBI Computer Crime and Security Survey, Computer Security Issues & Trends (2002)"},{"key":"148_CR29","volume-title":"Disaster Recovery Planning","author":"R.J. Bates","year":"1991","unstructured":"Bates, R.J.: Disaster Recovery Planning. McGraw-Hill, New York (1991)"},{"key":"148_CR30","unstructured":"Witty, R.J., Girard, J., Graff, J.W., Hallawell, A., Hildreth, B., MacDonald, N., Malik, W.J., Pescatore, J., Reynolds, M., Russell, K., Wheatman, V., Dubiel, J.P., Weintraub, A.: The Price of Information Security, Gartner Inc., Stamford, CT (2001)"},{"key":"148_CR31","volume-title":"CISSP All-in-One Exam Guide","author":"S. Harris","year":"2003","unstructured":"Harris, S.: CISSP All-in-One Exam Guide, 2nd edn. McGraw-Hill, New York (2003)","edition":"2"},{"key":"148_CR32","volume-title":"Risk Management for Security Professionals","author":"C.A. Roper","year":"1999","unstructured":"Roper, C.A.: Risk Management for Security Professionals. Butterworth-Heinemann, Boston (1999)"},{"key":"148_CR33","unstructured":"SEI: A Systems Engineering Capability Maturity Model, Version 2.0. Software Engineering Institute, Carnegie Mellon University in Pittsburgh, PA (1999)"},{"key":"148_CR34","doi-asserted-by":"crossref","unstructured":"Rex, R.K., Charles, S.A., Houston, C.H.: Risk Analysis for Information Technology. Journal of Management Information Systems\u00a08(1) (1991)","DOI":"10.1080\/07421222.1991.11517914"},{"key":"148_CR35","series-title":"Lecture Notes in Computer Science","volume-title":"Computational and Information Science","author":"S. Kim","year":"2004","unstructured":"Kim, S., Leem, C.S.: Implementation of the Security System for Instant Messengers. In: Zhang, J., He, J.-H., Fu, Y. (eds.) CIS 2004. LNCS, vol.\u00a03314, Springer, Heidelberg (2004)"},{"key":"148_CR36","doi-asserted-by":"crossref","unstructured":"Kim, S., Leem, C.S.: Security of the Internet-based Instant Messenger: Risks and Safeguards. Internet Research: Electronic Networking Applications and Policy\u00a015(1) (2005)","DOI":"10.1108\/10662240510577086"},{"key":"148_CR37","volume-title":"EDP Auditing: Conceptual Foundations and Practice","author":"W. Ron","year":"1988","unstructured":"Ron, W.: EDP Auditing: Conceptual Foundations and Practice. McGraw-Hill, New York (1988)"}],"container-title":["Lecture Notes in Computer Science","Knowledge-Based Intelligent Information and Engineering Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11892960_148.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,17]],"date-time":"2020-11-17T19:52:59Z","timestamp":1605642779000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11892960_148"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006]]},"ISBN":["9783540465355","9783540465362"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/11892960_148","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2006]]}}}