{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T14:47:18Z","timestamp":1776782838556,"version":"3.51.2"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030127855","type":"print"},{"value":"9783030127862","type":"electronic"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-12786-2_10","type":"book-chapter","created":{"date-parts":[[2019,1,31]],"date-time":"2019-01-31T00:31:20Z","timestamp":1548894680000},"page":"153-172","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Understanding Challenges to Adoption of the Protection Poker Software Security\u00a0Game"],"prefix":"10.1007","author":[{"given":"Inger Anne","family":"T\u00f8ndel","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin Gilje","family":"Jaatun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniela","family":"Cruzes","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tosin Daniel","family":"Oyetoyan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,1,31]]},"reference":[{"key":"10_CR1","volume-title":"Understanding Attitudes and Predicting Social Behavior","author":"I Ajzen","year":"1980","unstructured":"Ajzen, I., Fishbein, M.: Understanding Attitudes and Predicting Social Behavior. Prentice-Hall, Upper Saddle River (1980)"},{"key":"10_CR2","doi-asserted-by":"crossref","unstructured":"Baca, D., Boldt, M., Carlsson, B., Jacobsson, A.: A novel security-enhanced agile software development process applied in an industrial setting. In: 10th International Conference on Availability, Reliability and Security (ARES), pp. 11\u201319. IEEE (2015)","DOI":"10.1109\/ARES.2015.45"},{"key":"10_CR3","volume-title":"Extreme Programming Explained: Embrace Change","author":"K Beck","year":"2000","unstructured":"Beck, K.: Extreme Programming Explained: Embrace Change. Addison-Wesley Professional, Boston (2000)"},{"key":"10_CR4","doi-asserted-by":"crossref","unstructured":"Bostr\u00f6m, G., W\u00e4yrynen, J., Bod\u00e9n, M., Beznosov, K., Kruchten, P.: Extending XP practices to support security requirements engineering. In: Proceedings of the 2006 International Workshop on Software Engineering for Secure Systems, pp. 11\u201318. ACM (2006)","DOI":"10.1145\/1137627.1137631"},{"key":"10_CR5","volume-title":"Fun Retrospectives - Activities and Ideas for Making Agile Retrospectives More Engaging","author":"P Caroli","year":"2015","unstructured":"Caroli, P., Caetano, T.: Fun Retrospectives - Activities and Ideas for Making Agile Retrospectives More Engaging. Leanpub, Layton (2015)"},{"issue":"11","key":"10_CR6","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1109\/2.963450","volume":"34","author":"A Cockburn","year":"2001","unstructured":"Cockburn, A., Highsmith, J.: Agile software development, the people factor. Computer 34(11), 131\u2013133 (2001)","journal-title":"Computer"},{"key":"10_CR7","unstructured":"Davis, F.D.: A technology acceptance model for empirically testing new end-user information systems: theory and results. Ph.D. thesis, Massachusetts Institute of Technology (1985)"},{"key":"10_CR8","doi-asserted-by":"publisher","first-page":"319","DOI":"10.2307\/249008","volume":"13","author":"FD Davis","year":"1989","unstructured":"Davis, F.D.: Perceived usefulness, perceived ease of use, and user acceptance of information technology. MIS Q. 13, 319\u2013340 (1989)","journal-title":"MIS Q."},{"key":"10_CR9","unstructured":"Dyb\u00e5, T., Moe, N.B., Mikkelsen, E.M.: An empirical investigation on factors affecting software developer acceptance and utilization of electronic process guides. In: 10th International Symposium on Software Metrics, pp. 220\u2013231. IEEE (2004)"},{"key":"10_CR10","first-page":"22","volume":"3","author":"J Grenning","year":"2002","unstructured":"Grenning, J.: Planning poker or how to avoid analysis paralysis while release planning. Hawthorn Woods: Renaissance Softw. Consult. 3, 22\u201323 (2002)","journal-title":"Hawthorn Woods: Renaissance Softw. Consult."},{"issue":"3","key":"10_CR11","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1023\/A:1026586415054","volume":"5","author":"M H\u00f6st","year":"2000","unstructured":"H\u00f6st, M., Regnell, B., Wohlin, C.: Using students as subjects - a comparative study of students and professionals in lead-time impact assessment. Empirical Softw. Eng. 5(3), 201\u2013214 (2000)","journal-title":"Empirical Softw. Eng."},{"key":"10_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1007\/978-3-319-23318-5_7","volume-title":"Information Security","author":"MG Jaatun","year":"2015","unstructured":"Jaatun, M.G., Cruzes, D.S., Bernsmed, K., T\u00f8ndel, I.A., R\u00f8stad, L.: Software security maturity in public organisations. In: Lopez, J., Mitchell, C.J. (eds.) ISC 2015. LNCS, vol. 9290, pp. 120\u2013138. Springer, Cham (2015). \n                      https:\/\/doi.org\/10.1007\/978-3-319-23318-5_7"},{"key":"10_CR13","doi-asserted-by":"crossref","unstructured":"Jaatun, M.G., T\u00f8ndel, I.A.: Covering your assets in software engineering. In: The Third International Conference on Availability, Reliability and Security (ARES), Barcelona, Spain, pp. 1172\u20131179 (2008)","DOI":"10.1109\/ARES.2008.8"},{"key":"10_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"679","DOI":"10.1007\/978-3-319-49094-6_55","volume-title":"Product-Focused Software Process Improvement","author":"MG Jaatun","year":"2016","unstructured":"Jaatun, M.G., T\u00f8ndel, I.A.: Playing protection poker for practical software security. In: Abrahamsson, P., Jedlitschka, A., Nguyen Duc, A., Felderer, M., Amasaki, S., Mikkonen, T. (eds.) PROFES 2016. LNCS, vol. 10027, pp. 679\u2013682. Springer, Cham (2016). \n                      https:\/\/doi.org\/10.1007\/978-3-319-49094-6_55"},{"issue":"3","key":"10_CR15","first-page":"49","volume":"7","author":"R Khaim","year":"2016","unstructured":"Khaim, R., Naz, S., Abbas, S., Iqbal, N., Hamayun, M.: A review of security integration technique in agile software development. Int. J. Softw. Eng. Appl. 7(3), 49\u201368 (2016)","journal-title":"Int. J. Softw. Eng. Appl."},{"key":"10_CR16","unstructured":"Li, L.: A critical review of technology acceptance literature. Department of Accounting, Economics and Information Systems, College of Business, Grambling State University (2008)"},{"issue":"3","key":"10_CR17","doi-asserted-by":"publisher","first-page":"71","DOI":"10.4018\/jsse.2010070105","volume":"1","author":"T Nicolaysen","year":"2010","unstructured":"Nicolaysen, T., Sassoon, R., Line, M.B., Jaatun, M.G.: Agile software development: the straight and narrow path to secure software? Int. J. Secure Softw. Eng. (IJSSE) 1(3), 71\u201385 (2010)","journal-title":"Int. J. Secure Softw. Eng. (IJSSE)"},{"key":"10_CR18","doi-asserted-by":"publisher","first-page":"823","DOI":"10.1007\/s12652-017-0488-2","volume":"9","author":"E Odzaly","year":"2017","unstructured":"Odzaly, E., Greer, D., Stewart, D.: Agile risk management using software agents. J. Ambient Intell. Hum. Comput. 9, 823\u2013841 (2017)","journal-title":"J. Ambient Intell. Hum. Comput."},{"key":"10_CR19","doi-asserted-by":"crossref","unstructured":"Oueslati, H., Rahman, M.M., ben Othmane, L.: Literature review of the challenges of developing secure software using the agile approach. In: 10th International Conference on Availability, Reliability and Security (ARES), pp. 540\u2013547. IEEE (2015)","DOI":"10.1109\/ARES.2015.69"},{"key":"10_CR20","unstructured":"Peeters, J.: Agile security requirements engineering. In: Symposium on Requirements Engineering for Information Security (2005)"},{"key":"10_CR21","unstructured":"Pohl, C., Hof, H.J.: Secure scrum: Development of secure software with scrum. arXiv preprint \n                      arXiv:1507.02992\n                      \n                     (2015)"},{"key":"10_CR22","doi-asserted-by":"crossref","unstructured":"Renatus, S., Teichmann, C., Eichler, J.: Method selection and tailoring for agile threat assessment and mitigation. In: 10th International Conference on Availability, Reliability and Security (ARES), pp. 548\u2013555. IEEE (2015)","DOI":"10.1109\/ARES.2015.96"},{"issue":"12","key":"10_CR23","first-page":"1679","volume":"18","author":"RM Savola","year":"2012","unstructured":"Savola, R.M., Fr\u00fchwirth, C., Pietik\u00e4inen, A.: Risk-driven security metrics in agile software development-an industrial pilot study. J. UCS 18(12), 1679\u20131702 (2012)","journal-title":"J. UCS"},{"key":"10_CR24","doi-asserted-by":"crossref","unstructured":"Svahnberg, M., Aurum, A., Wohlin, C.: Using students as subjects - an empirical evaluation. In: Proceedings of the Second ACM-IEEE International Symposium on Empirical Software Engineering and Measurement, pp. 288\u2013290. ACM (2008)","DOI":"10.1145\/1414004.1414055"},{"key":"10_CR25","doi-asserted-by":"crossref","unstructured":"Tavares, B., Silva, C., Diniz de Souza, A.: Risk management analysis in scrum software projects. Int. Trans. Oper. Res., 1\u201322 (2017)","DOI":"10.18293\/SEKE2016-083"},{"key":"10_CR26","doi-asserted-by":"crossref","unstructured":"Terpstra, E., Daneva, M., Wang, C.: Agile practitioners\u2019 understanding of security requirements: insights from a grounded theory analysis. In: 2017 IEEE 25th International Requirements Engineering Conference Workshops (REW), pp. 439\u2013442. IEEE (2017)","DOI":"10.1109\/REW.2017.54"},{"issue":"1","key":"10_CR27","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1109\/MS.2008.19","volume":"25","author":"IA T\u00f8ndel","year":"2008","unstructured":"T\u00f8ndel, I.A., Jaatun, M.G., Meland, P.H.: Security requirements for the rest of us: a survey. IEEE Softw. 25(1), 20\u201327 (2008)","journal-title":"IEEE Softw."},{"key":"10_CR28","doi-asserted-by":"crossref","unstructured":"T\u00f8ndel, I.A., Oyetoyan, T.D., Jaatun, M.G., Cruzes, D.: Understanding challenges to adoption of the microsoft elevation of privilege game. In: Proceedings of the 5th Annual Symposium and Bootcamp on Hot Topics in the Science of Security (HoTSoS 2018), pp. 2:1\u20132:10. ACM (2018)","DOI":"10.1145\/3190619.3190633"},{"key":"10_CR29","unstructured":"V\u00e4h\u00e4-Sipil\u00e4, A.: Product security risk management in agile product management. Stockholm, Sweden (2010)"},{"issue":"3","key":"10_CR30","doi-asserted-by":"publisher","first-page":"451","DOI":"10.1111\/j.1540-5915.1996.tb01822.x","volume":"27","author":"V Venkatesh","year":"1996","unstructured":"Venkatesh, V., Davis, F.D.: A model of the antecedents of perceived ease of use: development and test. Decis. Sci. 27(3), 451\u2013481 (1996)","journal-title":"Decis. Sci."},{"key":"10_CR31","unstructured":"Weir, C., Rashid, A., Noble, J.: Developer essentials: top five interventions to support secure software development (2017)"},{"key":"10_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"122","DOI":"10.1007\/978-3-642-00199-4_11","volume-title":"Engineering Secure Software and Systems","author":"L Williams","year":"2009","unstructured":"Williams, L., Gegick, M., Meneely, A.: Protection poker: structuring software security risk assessment and knowledge transfer. In: Massacci, F., Redwine, S.T., Zannone, N. (eds.) ESSoS 2009. LNCS, vol. 5429, pp. 122\u2013134. Springer, Heidelberg (2009). \n                      https:\/\/doi.org\/10.1007\/978-3-642-00199-4_11"},{"issue":"3","key":"10_CR33","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/MSP.2010.58","volume":"8","author":"L Williams","year":"2010","unstructured":"Williams, L., Meneely, A., Shipley, G.: Protection poker: the new software security game. IEEE Secur. Privacy 8(3), 14\u201320 (2010)","journal-title":"IEEE Secur. Privacy"}],"container-title":["Lecture Notes in Computer Science","Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-12786-2_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,20]],"date-time":"2019-05-20T06:56:24Z","timestamp":1558335384000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-12786-2_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030127855","9783030127862"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-12786-2_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"31 January 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CyberICPS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Workshop on the Security of Industrial Control Systems and Cyber-Physical Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Barcelona","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 September 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 September 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cyberics2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.ds.unipi.gr\/cybericps2018\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"15","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"8","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"53% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}}]}}