{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T06:00:20Z","timestamp":1726034420256},"publisher-location":"Cham","reference-count":14,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030225582"},{"type":"electronic","value":"9783030225599"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-22559-9_4","type":"book-chapter","created":{"date-parts":[[2019,6,29]],"date-time":"2019-06-29T02:33:19Z","timestamp":1561775599000},"page":"71-97","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Risk-Based Elicitation of Security Requirements According to the ISO 27005 Standard"],"prefix":"10.1007","author":[{"given":"Roman","family":"Wirtz","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maritta","family":"Heisel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angela","family":"Borchert","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rene","family":"Meis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aida","family":"Omerovic","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ketil","family":"St\u00f8len","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,6,29]]},"reference":[{"key":"4_CR1","series-title":"The CORAS Approach","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-12323-8","volume-title":"Model-Driven Risk Analysis","author":"MS Lund","year":"2010","unstructured":"Lund, M.S., Solhaug, B., St\u00f8len, K.: Model-Driven Risk Analysis. The CORAS Approach. Springer, Heidelberg (2010). \n                    https:\/\/doi.org\/10.1007\/978-3-642-12323-8"},{"key":"4_CR2","volume-title":"Problem Frames: Analyzing and Structuring Software Development Problems","author":"M Jackson","year":"2001","unstructured":"Jackson, M.: Problem Frames: Analyzing and Structuring Software Development Problems. Addison-Wesley Longman Publishing Co., Inc., Boston (2001)"},{"key":"4_CR3","unstructured":"International Organization for Standardization: ISO 27005:2011 Information technology - Security techniques - Information security risk management. Standard (2011)"},{"key":"4_CR4","unstructured":"International Organization for Standardization: ISO 31000:2018 Risk management - Principles and guidelines. Standard (2018)"},{"key":"4_CR5","unstructured":"Common Criteria: Common Criteria for Information Technology Security Evaluation v3.1. Release 5. Standard (2017)"},{"key":"4_CR6","doi-asserted-by":"crossref","unstructured":"Wirtz, R., Heisel, M., Meis, R., Omerovic, A., St\u00f8len, K.: Problem-based elicitation of security requirements - the ProCOR method. In: Proceedings of the 13th International Conference on Evaluation of Novel Approaches to Software Engineering. ENASE, INSTICC, vol. 1, pp. 26\u201338. SciTePress (2018)","DOI":"10.5220\/0006669400260038"},{"key":"4_CR7","first-page":"19","volume-title":"IFIP Advances in Information and Communication Technology","author":"M. Heisel","year":"1998","unstructured":"Heisel, M.: Agendas - a concept to guide software development activities. In: Proceedings of the IFIP TC2 WG2.4 Working Conference on Systems Implementation: Languages, Methods and Tools, pp. 19\u201332. Chapman and Hall London (1998)"},{"key":"4_CR8","doi-asserted-by":"crossref","unstructured":"Fa\u00dfbender, S., Heisel, M., Meis, R.: Functional requirements under security presSuRE. In: ICSOFT-PT 2014 - Proceedings of the 9th International Conference on Software Paradigm Trends, Vienna, Austria, 29\u201331 August 2014. SciTePress (2014)","DOI":"10.5220\/0005098600050016"},{"key":"4_CR9","unstructured":"OPEN meter Consortium: Report on the identification and specification of functional, technical, economical and general requirements of advanced multi-metering infrasturcture, including security requirements (2009)"},{"key":"4_CR10","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/s00766-013-0195-2","volume":"20","author":"R Scandariato","year":"2015","unstructured":"Scandariato, R., Wuyts, K., Joosen, W.: A descriptive study of Microsoft\u2019s threat modeling technique. Requir. Eng. 20, 163\u2013180 (2015)","journal-title":"Requir. Eng."},{"key":"4_CR11","unstructured":"Ministerio de Administraciones Publicas: MAGERIT - version 3.0. Methodology for Information Systems Risk Analysis and Management. Book I - The Method. Ministry of Finance and Public Administration (2014)"},{"key":"4_CR12","unstructured":"Mayer, N., Rifaut, A., Dubois, E.: Towards a risk-based security requirements engineering framework. In: Proceeding of REFSQ 2005 (2005)"},{"key":"4_CR13","series-title":"Lecture Notes in Business Information Processing","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-642-29231-6_6","volume-title":"Workshops on Business Informatics Research","author":"A Herrmann","year":"2012","unstructured":"Herrmann, A., Morali, A., Etalle, S., Wieringa, R.: Risk and business goal based security requirement and countermeasure prioritization. In: Niedrite, L., Strazdina, R., Wangler, B. (eds.) BIR 2011. LNBIP, vol. 106, pp. 64\u201376. Springer, Heidelberg (2012). \n                    https:\/\/doi.org\/10.1007\/978-3-642-29231-6_6"},{"key":"4_CR14","volume-title":"Threat Modeling: Designing for Security","author":"A Shostack","year":"2014","unstructured":"Shostack, A.: Threat Modeling: Designing for Security. Wiley, Hoboken (2014)"}],"container-title":["Communications in Computer and Information Science","Evaluation of Novel Approaches to Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-22559-9_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,29]],"date-time":"2019-06-29T02:35:26Z","timestamp":1561775726000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-22559-9_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030225582","9783030225599"],"references-count":14,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-22559-9_4","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"29 June 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ENASE","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Evaluation of Novel Approaches to Software Engineering","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Funchal","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 March 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 March 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"enase2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.enase.org\/?y=2018","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}