{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T05:15:16Z","timestamp":1781673316658,"version":"3.54.5"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030217518","type":"print"},{"value":"9783030217525","type":"electronic"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-21752-5_3","type":"book-chapter","created":{"date-parts":[[2019,6,7]],"date-time":"2019-06-07T05:02:41Z","timestamp":1559883761000},"page":"28-41","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Sharing Cyber Threat Intelligence Under the General Data Protection Regulation"],"prefix":"10.1007","author":[{"given":"Adham","family":"Albakri","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Eerke","family":"Boiten","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rog\u00e9rio","family":"De Lemos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,6,8]]},"reference":[{"key":"3_CR1","doi-asserted-by":"publisher","first-page":"154","DOI":"10.1016\/j.cose.2016.04.003","volume":"60","author":"F Skopik","year":"2016","unstructured":"Skopik, F., Settanni, G., Fiedler, R.: A problem shared is a problem halved: a survey on the dimensions of collective cyber defense through security information sharing. Comput. Secur. 60, 154\u2013176 (2016)","journal-title":"Comput. Secur."},{"key":"3_CR2","doi-asserted-by":"crossref","unstructured":"Albakri, A., Boiten, E., De Lemos, R.: Risks of sharing cyber incident information. In: Proceedings of International Conference on Availability, Reliability and Security, Hamburg, Germany, 10 p. (2018)","DOI":"10.1145\/3230833.3233284"},{"key":"3_CR3","unstructured":"Sweeney, L.: Operationalizing american jurisprudence for data sharing, Technical report (2013)"},{"key":"3_CR4","unstructured":"Personal Information Protection Commission: Amended Act on the Protection of Personal Information (2016). \n                      https:\/\/www.ppc.go.jp\/files\/pdf\/Act_on_the_Protection_of_Personal_Information.pdf\n                      \n                    . Accessed 03 Jan 2019"},{"key":"3_CR5","unstructured":"European Union: Regulation 2016\/679 of the European parliament and the Council of the European Union of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/. Official J. Eur. Communities 59, 1\u201388 (2016)"},{"key":"3_CR6","unstructured":"ENISA: Directive on security of network and information systems (2017). \n                      https:\/\/ec.europa.eu\/digital-single-market\/en\/network-and-information-security-nis-directive\n                      \n                    . Accessed: 13 Dec 2018"},{"key":"3_CR7","unstructured":"ENISA: Information Security Agency, \u2018A step-by-step approach on how to set up a CSIRT\u2019, WP2006\/5.1, 86 (2006)"},{"key":"3_CR8","doi-asserted-by":"crossref","unstructured":"Bar-Sinai, M., Sweeney, L., Crosas, M.: DataTags, data handling policy spaces and the tags language. In: Proceedings - 2016 IEEE Symposium on Security and Privacy Workshops, SPW 2016, pp. 1\u20138 (2016)","DOI":"10.1109\/SPW.2016.11"},{"key":"3_CR9","unstructured":"Sweeney, L., Crosas, M., Bar-Sinai, M.: Sharing sensitive data with confidence: the datatags system. Technol. Sci. 2015101601 (2015). \n                      https:\/\/techscience.org\/a\/2015101601"},{"key":"3_CR10","unstructured":"IFIRST.ORG: Traffic Light Protocol (TLP) (2001). \n                      https:\/\/www.first.org\/tlp\/\n                      \n                    . Accessed 14 Aug 2018"},{"key":"3_CR11","unstructured":"CIRCL: Traffic Light Protocol (TLP) - Classification and Sharing of Sensitive Information (2018). \n                      https:\/\/www.circl.lu\/pub\/traffic-light-protocol\/\n                      \n                    . Accessed 29 Sept 2018"},{"key":"3_CR12","doi-asserted-by":"crossref","unstructured":"Goyal, V., Pandey, O., Sahai, A., Waters, B.: Attribute-based encryption for fine-grained access control of encrypted data. In: Proceedings of the 13th ACM Conference on Computer and Communications Security - CCS 2006, pp. 89\u201398 (2006)","DOI":"10.1145\/1180405.1180418"},{"key":"3_CR13","doi-asserted-by":"crossref","unstructured":"Bethencourt, J., Sahai, A., Waters, B.: Ciphertext-policy attribute-based encryption. In: Proceedings - IEEE Symposium on Security and Privacy, pp. 321\u2013334 (2007)","DOI":"10.1109\/SP.2007.11"},{"issue":"2","key":"3_CR14","doi-asserted-by":"publisher","first-page":"97","DOI":"10.2753\/MIS0742-1222250205","volume":"25","author":"ME Johnson","year":"2008","unstructured":"Johnson, M.E.: Information risk of inadvertent disclosure: an analysis of file-sharing risk in the financial supply chain. J. Manag. Inf. Syst. 25(2), 97\u2013124 (2008)","journal-title":"J. Manag. Inf. Syst."},{"issue":"05","key":"3_CR15","doi-asserted-by":"publisher","first-page":"557","DOI":"10.1142\/S0218488502001648","volume":"10","author":"LATANYA SWEENEY","year":"2002","unstructured":"Sweeney, L.: k-Anonymity: a model for protecting privacy. Int. J. Uncertainty, Fuzziness Knowl.-Based Syst., 10(05), 557\u2013570 (2002)","journal-title":"International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems"},{"key":"3_CR16","doi-asserted-by":"crossref","unstructured":"Xiao, X., Tao, Y.: Personalized privacy preservation. In: Proceedings of the 2006 ACM SIGMOD International Conference on Management of Data - SIGMOD 2006, pp. 229\u2013240 (2006)","DOI":"10.1145\/1142473.1142500"},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Nergiz, M.E., Atzori, M., Clifton, C.: Hiding the presence of individuals from shared databases. In: Proceedings of the 2007 ACM SIGMOD International Conference on Management of Data - SIGMOD 2007, pp. 665\u2013676 (2007)","DOI":"10.1145\/1247480.1247554"},{"key":"3_CR18","unstructured":"Kifer, D.: L-diversity\u202f: privacy beyond k\u2013Anonymity. In: Proceedings of the 22nd International Conference on Data Engineering, pp. 24\u201336 (2006)"},{"key":"3_CR19","doi-asserted-by":"crossref","unstructured":"Machanavajjhala, A., Gehrke, J., Kifer, D., Venkitasubramaniam, M.L.: L-diversity: privacy beyond k-anonymity. In: Proceedings - International Conference on Data Engineering, p. 24 (2006)","DOI":"10.1109\/ICDE.2006.1"},{"key":"3_CR20","unstructured":"Ninghui, L., Tiancheng, L., Venkatasubramanian, S.: t-closeness: privacy beyond k-anonymity and l-diversity. In: Proceedings of the International Conference on Data Engineering, no. 2, pp. 106\u2013115 (2007)"},{"key":"3_CR21","unstructured":"CIRCL: Legal compliance and CSIRT activities (2018). \n                      https:\/\/github.com\/CIRCL\/compliance\n                      \n                    . Accessed 29 Sept 2018"},{"key":"3_CR22","unstructured":"CIRCL: AIL information leaks analysis and the GDPR in the context of collection, analysis and sharing information leaks (2018). \n                      https:\/\/www.circl.lu\/assets\/files\/information-leaks-analysis-and-gdpr.pdf\n                      \n                    . Accessed: 20 Dec 2018"},{"key":"3_CR23","unstructured":"Thielman, S.: Yahoo hack: 1 bn accounts compromised by biggest data breach in history, The Guardian (UK) (2016). \n                      https:\/\/www.theguardian.com\/technology\/2016\/dec\/14\/yahoo-hack-security-of-one-billion-accounts-breached\n                      \n                    . Accessed 24 Oct 2018"},{"key":"3_CR24","first-page":"59","volume-title":"IFIP Advances in Information and Communication Technology","author":"Kaniz Fatema","year":"2012","unstructured":"Fatema, K., Chadwick, D.W., Van Alsenoy, B.: Extracting access control and conflict resolution policies from European data protection law. In: IFIP Advances in Information and Communication Technology, vol. 375, pp. 59\u201372. AICT (2012)"},{"key":"3_CR25","unstructured":"Directive 95\/46\/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (1995)"},{"key":"3_CR26","unstructured":"Doorn, P., Thomas, E.: Tagging privacy-sensitive data according to the new European privacy legislation: GDPR DataTags - a prototype (2017). \n                      https:\/\/dans.knaw.nl\/en\/current\/first-gdpr-datatags-results-presented-in-workshop\n                      \n                    . Accessed 20 Dec 2018"},{"key":"3_CR27","unstructured":"Tjalsma, H.: Data Archiving and Networked Services (DANS) (2012). \n                      https:\/\/easy.dans.knaw.nl\/\n                      \n                    . Accessed 24 Oct 2018"},{"issue":"1","key":"3_CR28","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/TSE.2007.70746","volume":"34","author":"TD Breaux","year":"2008","unstructured":"Breaux, T.D., Ant\u00f3n, A.I.: Analyzing regulatory rules for privacy and security requirements. IEEE Trans. Softw. Eng. 34(1), 5\u201320 (2008)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"3_CR29","unstructured":"Breaux, T.D., Ant\u00f3n, A.I.: A systematic method for acquiring regulatory requirements: a frame-based approach. In: RHAS-6 (2007)"},{"key":"3_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/978-3-319-67280-9_6","volume-title":"Privacy Technologies and Policy","author":"E Schweighofer","year":"2017","unstructured":"Schweighofer, E., Heussler, V., Kieseberg, P.: Privacy by design data exchange between CSIRTs. In: Schweighofer, E., Leitold, H., Mitrakas, A., Rannenberg, K. (eds.) APF 2017. LNCS, vol. 10518, pp. 104\u2013119. Springer, Cham (2017). \n                      https:\/\/doi.org\/10.1007\/978-3-319-67280-9_6"}],"container-title":["Lecture Notes in Computer Science","Privacy Technologies and Policy"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-21752-5_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,7]],"date-time":"2019-06-07T05:03:17Z","timestamp":1559883797000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-21752-5_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030217518","9783030217525"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-21752-5_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"8 June 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"APF","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual Privacy Forum","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Rome","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 June 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 June 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"apf2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/privacyforum.eu\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"50","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"12","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"24% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"3.5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}}]}}