{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T07:11:37Z","timestamp":1760080297954,"version":"3.37.3"},"publisher-location":"Cham","reference-count":31,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030292379"},{"type":"electronic","value":"9783030292386"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-29238-6_1","type":"book-chapter","created":{"date-parts":[[2019,9,1]],"date-time":"2019-09-01T19:02:43Z","timestamp":1567364563000},"page":"3-17","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["GDPR-Based User Stories in the Access Control Perspective"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6538-3466","authenticated-orcid":false,"given":"Cesare","family":"Bartolini","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3073-6217","authenticated-orcid":false,"given":"Said","family":"Daoudagh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8229-3270","authenticated-orcid":false,"given":"Gabriele","family":"Lenzini","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4223-8036","authenticated-orcid":false,"given":"Eda","family":"Marchetti","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,8,8]]},"reference":[{"key":"1_CR1","unstructured":"Ahola, J., et al.: Handbook of the secure agile software development life cycle. University of Oulu (2014)"},{"issue":"1","key":"1_CR2","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1186\/s42400-018-0019-2","volume":"2","author":"M Alohaly","year":"2019","unstructured":"Alohaly, M., Takabi, H., Blanco, E.: Automated extraction of attributes from natural language attribute-based access control (ABAC) policies. Cybersecurity 2(1), 2 (2019)","journal-title":"Cybersecurity"},{"key":"1_CR3","unstructured":"Asthana, V., Tarandach, I., O\u2019Donoghue, N., Sullivan, B., Saario, M.: Practical security stories and security tasks for agile development environments, July 2012"},{"key":"1_CR4","doi-asserted-by":"crossref","unstructured":"Azham, Z., Ghani, I., Ithnin, N.: Security backlog in scrum security practices. In: 2011 Malaysian Conference in Software Engineering, pp. 414\u2013417. IEEE (2011)","DOI":"10.1109\/MySEC.2011.6140708"},{"key":"1_CR5","doi-asserted-by":"crossref","unstructured":"Bartolini, C., Daoudagh, S., Lenzini, G., Marchetti, E.: Towards a lawful authorized access: a preliminary GDPR-based authorized access. In: 14th International Conference on Software Technologies (ICSOFT 2019), Prague, Czech Republic, 26\u201328 July 2019, pp. 331\u2013338 (2019)","DOI":"10.5220\/0007978703310338"},{"key":"1_CR6","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/978-3-319-67468-1_4","volume-title":"BNAIC 2016: Artificial Intelligence","author":"C Bartolini","year":"2017","unstructured":"Bartolini, C., Giurgiu, A., Lenzini, G., Robaldo, L.: Towards legal compliance by correlating standards and laws with a semi-automated methodology. In: Bosse, T., Bredeweg, B. (eds.) BNAIC 2016. CCIS, vol. 765, pp. 47\u201362. Springer, Cham (2017). \n                    https:\/\/doi.org\/10.1007\/978-3-319-67468-1_4"},{"key":"1_CR7","unstructured":"Cerbo, F.D., Martinelli, F., Matteucci, I., Mori, P.: Towards a declarative approach to stateful and stateless usage control for data protection. In: WEBIST, pp. 308\u2013315. SciTePress (2018)"},{"key":"1_CR8","volume-title":"User Stories Applied: For Agile Software Development","author":"M Cohn","year":"2004","unstructured":"Cohn, M.: User Stories Applied: For Agile Software Development. Addison-Wesley Professional, Boston (2004)"},{"key":"1_CR9","doi-asserted-by":"crossref","unstructured":"Fatema, K., Debruyne, C., Lewis, D., O\u2019Sullivan, D., Morrison, J.P., Mazed, A.: A semi-automated methodology for extracting access control rules from the European data protection directive. In: 2016 IEEE SPW, pp. 25\u201332, May 2016","DOI":"10.1109\/SPW.2016.16"},{"issue":"8","key":"1_CR10","first-page":"28","volume":"9","author":"M Fowler","year":"2001","unstructured":"Fowler, M., Highsmith, J., et al.: The agile manifesto. Softw. Dev. 9(8), 28\u201335 (2001)","journal-title":"Softw. Dev."},{"key":"1_CR11","doi-asserted-by":"crossref","unstructured":"Gupta, M., Benson, J., Patwa, F., Sandhu, R.: Dynamic groups and attribute-based access control for next-generation smart cars. In: CODASPY 2019, Richardson, TX, USA, 25\u201327 March 2019 (2019)","DOI":"10.1145\/3292006.3300048"},{"key":"1_CR12","unstructured":"Hu, C.T., et al.: Guide to attribute based access control (ABAC) definition and considerations [includes updates as of 02-25-2019]. Technical report (2019)"},{"key":"1_CR13","doi-asserted-by":"crossref","unstructured":"Kassab, M.: The changing landscape of requirements engineering practices over the past decade. In: 2015 IEEE EmpiRE, pp. 1\u20138, August 2015","DOI":"10.1109\/EmpiRE.2015.7431299"},{"key":"1_CR14","unstructured":"Kniberg, H.: Scrum and XP from the Trenches (2015). \n                    Lulu.com"},{"issue":"3","key":"1_CR15","doi-asserted-by":"publisher","first-page":"383","DOI":"10.1007\/s00766-016-0250-x","volume":"21","author":"G Lucassen","year":"2016","unstructured":"Lucassen, G., Dalpiaz, F., van der Werf, J.M.E.M., Brinkkemper, S.: Improving agile requirements: the quality user story framework and tool. Requirements Eng. 21(3), 383\u2013403 (2016)","journal-title":"Requirements Eng."},{"key":"1_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1007\/978-3-319-30282-9_14","volume-title":"Requirements Engineering: Foundation for Software Quality","author":"G Lucassen","year":"2016","unstructured":"Lucassen, G., Dalpiaz, F., Werf, J.M.E.M., Brinkkemper, S.: The use and effectiveness of user stories in practice. In: Daneva, M., Pastor, O. (eds.) REFSQ 2016. LNCS, vol. 9619, pp. 205\u2013222. Springer, Cham (2016). \n                    https:\/\/doi.org\/10.1007\/978-3-319-30282-9_14"},{"key":"1_CR17","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1007\/978-3-319-97925-0_14","volume-title":"Systems, Software and Services Process Improvement","author":"F McCaffery","year":"2018","unstructured":"McCaffery, F., et al.: A process framework combining safety and security in practice. In: Larrucea, X., Santamaria, I., O\u2019Connor, R.V., Messnarz, R. (eds.) EuroSPI 2018. CCIS, vol. 896, pp. 173\u2013180. Springer, Cham (2018). \n                    https:\/\/doi.org\/10.1007\/978-3-319-97925-0_14"},{"key":"1_CR18","unstructured":"OASIS: eXtensible Access Control Markup Language (XACML) Version 3.0, January 2013. \n                    http:\/\/docs.oasis-open.org\/xacml\/3.0\/xacml-3.0-core-spec-os-en.html"},{"key":"1_CR19","unstructured":"Palmirani, M., Martoni, M., Rossi, A., Bartolini, C., Robaldo, L.: Legal ontology for modelling GDPR concepts and norms. In: Legal Knowledge and Information Systems: JURIX 2018, vol. 313, p. 91. IOS Press (2018)"},{"key":"1_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1007\/978-3-319-98349-3_11","volume-title":"Electronic Government and the Information Systems Perspective","author":"M Palmirani","year":"2018","unstructured":"Palmirani, M., Martoni, M., Rossi, A., Bartolini, C., Robaldo, L.: PrOnto: privacy ontology for legal reasoning. In: K\u0151, A., Francesconi, E. (eds.) EGOVIS 2018. LNCS, vol. 11032, pp. 139\u2013152. Springer, Cham (2018). \n                    https:\/\/doi.org\/10.1007\/978-3-319-98349-3_11"},{"key":"1_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1007\/978-3-319-93417-4_31","volume-title":"The Semantic Web","author":"HJ Pandit","year":"2018","unstructured":"Pandit, H.J., Fatema, K., O\u2019Sullivan, D., Lewis, D.: GDPRtEXT - GDPR as a linked data resource. In: Gangemi, A., et al. (eds.) ESWC 2018. LNCS, vol. 10843, pp. 481\u2013495. Springer, Cham (2018). \n                    https:\/\/doi.org\/10.1007\/978-3-319-93417-4_31"},{"key":"1_CR22","unstructured":"Pandit, H.J., Lewis, D.: Modelling provenance for GDPR compliance using linked open data vocabularies. In: PrivOn@ ISWC (2017)"},{"key":"1_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"468","DOI":"10.1007\/978-3-030-03638-6_29","volume-title":"Secure IT Systems","author":"H Rygge","year":"2018","unstructured":"Rygge, H., J\u00f8sang, A.: Threat poker: solving security and privacy threats in agile software development. In: Gruschka, N. (ed.) NordSec 2018. LNCS, vol. 11252, pp. 468\u2013483. Springer, Cham (2018). \n                    https:\/\/doi.org\/10.1007\/978-3-030-03638-6_29"},{"issue":"9","key":"1_CR24","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1109\/35.312842","volume":"32","author":"RS Sandhu","year":"1994","unstructured":"Sandhu, R.S., Samarati, P.: Access control: principle and practice. IEEE Commun. Mag. 32(9), 40\u201348 (1994)","journal-title":"IEEE Commun. Mag."},{"key":"1_CR25","unstructured":"Siiskonen, T., S\u00e4rs, C., V\u00e4h\u00e4-Sipil\u00e4, A., Pietik\u00e4\u00e4inen, A.: Generic security user stories. In: Pekka, P., Juha, R. (eds.) Handbook of the Secure Agile Software Development Life Cycle. University of Oulu, Oulu (2014)"},{"key":"1_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"311","DOI":"10.1007\/978-3-319-23781-7_25","volume-title":"Model and Data Engineering","author":"\u015a Sobieski","year":"2015","unstructured":"Sobieski, \u015a., Zieli\u0144ski, B.: User stories and parameterized role based access control. In: Bellatreche, L., Manolopoulos, Y. (eds.) MEDI 2015. LNCS, vol. 9344, pp. 311\u2013319. Springer, Cham (2015). \n                    https:\/\/doi.org\/10.1007\/978-3-319-23781-7_25"},{"key":"1_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-030-00305-0_23","volume-title":"Data Privacy Management, Cryptocurrencies and Blockchain Technology","author":"M-R Ulbricht","year":"2018","unstructured":"Ulbricht, M.-R., Pallas, F.: YaPPL - a lightweight privacy preference language for legally sufficient and automated consent provision in IoT scenarios. In: Garcia-Alfaro, J., Herrera-Joancomart\u00ed, J., Livraga, G., Rios, R. (eds.) DPM\/CBT -2018. LNCS, vol. 11025, pp. 329\u2013344. Springer, Cham (2018). \n                    https:\/\/doi.org\/10.1007\/978-3-030-00305-0_23"},{"issue":"3","key":"1_CR28","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1016\/j.clsr.2018.02.002","volume":"34","author":"S Wachter","year":"2018","unstructured":"Wachter, S.: Normative challenges of identification in the internet of things: privacy, profiling, discrimination, and the GDPR. Comput. Law Secur. Rev. 34(3), 436\u2013449 (2018)","journal-title":"Comput. Law Secur. Rev."},{"key":"1_CR29","doi-asserted-by":"crossref","unstructured":"Wang, W., Gupta, A., Niu, N.: Mining security requirements from common vulnerabilities and exposures for agile projects. In: 2018 IEEE 1st International Workshop on Quality Requirements in Agile Projects (QuaRAP), pp. 6\u20139, August 2018","DOI":"10.1109\/QuaRAP.2018.00007"},{"key":"1_CR30","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1007\/978-3-662-43610-3_15","volume-title":"Requirements Engineering","author":"X Wang","year":"2014","unstructured":"Wang, X., Zhao, L., Wang, Y., Sun, J.: The role of requirements engineering practices in agile development: an empirical study. In: Zowghi, D., Jin, Z. (eds.) Requirements Engineering. CCIS, vol. 432, pp. 195\u2013209. Springer, Heidelberg (2014). \n                    https:\/\/doi.org\/10.1007\/978-3-662-43610-3_15"},{"key":"1_CR31","doi-asserted-by":"crossref","unstructured":"Xiao, X., Paradkar, A., Thummalapenta, S., Xie, T.: Automated extraction of security policies from natural-language software documents. In: Proceedings of the ACM SIGSOFT FSE 2012, FSE 2012, pp. 12:1\u201312:11. ACM, New York (2012)","DOI":"10.1145\/2393596.2393608"}],"container-title":["Communications in Computer and Information Science","Quality of Information and Communications Technology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-29238-6_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,1]],"date-time":"2019-09-01T19:02:55Z","timestamp":1567364575000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-29238-6_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030292379","9783030292386"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-29238-6_1","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"8 August 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"QUATIC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on the Quality of Information and Communications Technology","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ciudad Real","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 September 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 September 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"quatic2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/2019.quatic.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"66","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"29% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1-2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}