{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T14:22:48Z","timestamp":1742912568045,"version":"3.40.3"},"publisher-location":"Cham","reference-count":36,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030494421"},{"type":"electronic","value":"9783030494438"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-49443-8_3","type":"book-chapter","created":{"date-parts":[[2020,6,27]],"date-time":"2020-06-27T12:02:48Z","timestamp":1593259368000},"page":"48-73","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Information Technology Consulting Firms\u2019 Readiness for Managing Information Security Incidents"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4869-5094","authenticated-orcid":false,"given":"Christine","family":"Gro\u00dfe","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maja","family":"Nyman","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1337-0479","authenticated-orcid":false,"given":"Leif","family":"Sundberg","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,6,28]]},"reference":[{"unstructured":"Blix, F.: 1177-leak in Sweden: 2.7 million recorded healthcare phone calls leaked online (complete write-up). \nhttps:\/\/www.linkedin.com\/pulse\/1177-leak-sweden-27-million-recorded-healthcare-phone-fredrik-blix","key":"3_CR1"},{"unstructured":"Sones, M.: Sweden accidentally leaks nearly all citizens\u2019 personal details. \nhttp:\/\/www.israelnationalnews.com\/News\/News.aspx\/233057","key":"3_CR2"},{"unstructured":"The Local Sweden: Swedish authority handed over \u2018keys to the Kingdom\u2019 in IT security slip-up. \nhttps:\/\/www.thelocal.se\/20170717\/swedish-authority-handed-over-keys-to-the-kingdom-in-it-security-slip-up","key":"3_CR3"},{"unstructured":"Olsson, J.: Svenska Kraftn\u00e4t medger s\u00e4kerhetsbrister. \nhttps:\/\/www.svt.se\/nyheter\/inrikes\/svenska-kraftnat-medger-sakerhetsbrister","key":"3_CR4"},{"key":"3_CR5","doi-asserted-by":"publisher","first-page":"643","DOI":"10.1016\/j.cose.2012.04.001","volume":"31","author":"A Ahmad","year":"2012","unstructured":"Ahmad, A., Hadgkiss, J., Ruighaver, A.B.: Incident response teams \u2013 challenges in supporting the organisational security function. Comput. Secur. 31, 643\u2013652 (2012)","journal-title":"Comput. Secur."},{"key":"3_CR6","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1016\/j.cose.2014.11.006","volume":"49","author":"NH Ab Rahman","year":"2015","unstructured":"Ab Rahman, N.H., Choo, K.-K.R.: A survey of information security incident handling in the cloud. Comput. Secur. 49, 45\u201369 (2015)","journal-title":"Comput. Secur."},{"doi-asserted-by":"crossref","unstructured":"Hove, C., T\u00e5rnes, M., Line, M.B., Bernsmed, K.: Information security incident management. Identified practice in large organizations. In: Freiling, F. (ed.) 8th International Conference on IT Security Incident Management and IT Forensics, pp. 27\u201346. IEEE, Piscataway (2014)","key":"3_CR7","DOI":"10.1109\/IMF.2014.9"},{"key":"3_CR8","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1016\/j.cose.2014.05.003","volume":"45","author":"IA T\u00f8ndel","year":"2014","unstructured":"T\u00f8ndel, I.A., Line, M.B., Jaatun, M.G.: Information security incident management Current practice as reported in the literature. Comput. Secur. 45, 42\u201357 (2014)","journal-title":"Comput. Secur."},{"doi-asserted-by":"crossref","unstructured":"Cusick, J.J., Ma, G.: Creating an ITIL inspired incident management approach. roots, response, and results. In: Gaspary, L.P. (ed.) 2010 IEEE\/IFIP Network Operations and Management Symposium workshops, pp. 142\u2013148. IEEE, Piscataway (2010)","key":"3_CR9","DOI":"10.1109\/NOMSW.2010.5486589"},{"key":"3_CR10","volume-title":"Symposium on Computer Human Interaction for the Management of Information Technology","author":"J Bailey","year":"2007","unstructured":"Bailey, J., Kandogan, E., Haber, E., Maglio, P.P.: Activity-based management of IT service delivery. In: Kandogan, E. (ed.) Symposium on Computer Human Interaction for the Management of Information Technology. ACM, New York (2007)"},{"unstructured":"European Union (EU): Regulation 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation) (2016)","key":"3_CR11"},{"doi-asserted-by":"crossref","unstructured":"Line, M.B.: A case study. Preparing for the smart grids - identifying current practice for information security incident management in the power industry. In: Morgenstern, H. (ed.) 7th International Conference on IT Security Incident Management and IT Forensics, pp. 26\u201332. IEEE, Piscataway (2013)","key":"3_CR12","DOI":"10.1109\/IMF.2013.15"},{"key":"3_CR13","first-page":"81","volume":"33","author":"R O\u2019Brien","year":"2016","unstructured":"O\u2019Brien, R.: Privacy and security. Bus. Inf. Rev. 33, 81\u201384 (2016)","journal-title":"Bus. Inf. Rev."},{"unstructured":"Swedish Civil Contingencies Agency (MSB): \u00c5rsrapport it-incidentrapportering 2018. En sammanst\u00e4llning och analys av de statliga myndigheternas it-incidentrapportering (2019)","key":"3_CR14"},{"unstructured":"Swedish Civil Contingencies Agency (MSB): \u00c5rsrapport it-incidetnrapportering 2016 (2017)","key":"3_CR15"},{"doi-asserted-by":"crossref","unstructured":"Nyman, M., Gro\u00dfe, C.: Are you ready when it counts? IT Consulting firm\u2019s information security incident management. In: Proceedings of the 5th International Conference on Information Systems Security and Privacy, pp. 26\u201337. SCITEPRESS - Science and Technology Publications (2019)","key":"3_CR16","DOI":"10.5220\/0007247500260037"},{"unstructured":"International Organization for Standardization (ISO): \ufeffISO\/IEC 27000:2018\ufeff","key":"3_CR17"},{"unstructured":"Gro\u00dfe, C.: Towards an Integrated Framework for Quality and Information Security Management in Small Companies. Lule\u00e5 (2016)","key":"3_CR18"},{"unstructured":"European Union Agency For Network and Information Security (ENISA): Guidance and gaps analysis for European standardisation. Privacy standards in the information security context (2018)","key":"3_CR19"},{"key":"3_CR20","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1353-4858(16)30056-3","volume":"2016","author":"C Tankard","year":"2016","unstructured":"Tankard, C.: What the GDPR means for businesses. Netw. Secur. 2016, 5\u20138 (2016)","journal-title":"Netw. Secur."},{"unstructured":"European Union (EU): Directive 2016\/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union (2016)","key":"3_CR21"},{"unstructured":"Swedish Civil Contingencies Agency (MSB): V\u00e4gledning om rapportering av incidenter f\u00f6r leverant\u00f6rer av digitala tj\u00e4nster enligt NISregleringen. MSB 2018-13472 (2018)","key":"3_CR22"},{"unstructured":"Swedish Civil Contingencies Agency (MSB): Nationellt system f\u00f6r it-incidentrapportering (2012)","key":"3_CR23"},{"unstructured":"International Organization for Standardization (ISO): ISO\/IEC 27035:2016\ufeff. Information technology \u2013 Security techniques \u2013 Information security incident management (2016)","key":"3_CR24"},{"key":"3_CR25","volume-title":"NIST 800-61, Revision 2: Computer Security Incident Handling Guide","author":"P Cichonski","year":"2012","unstructured":"Cichonski, P., Millar, T., Grance, T., Scarfone, K.: NIST 800-61, Revision 2: Computer Security Incident Handling Guide. National Institute of Standards and Technology, Gaithersburg (2012)"},{"unstructured":"European Union Agency For Network and Information Security (ENISA): Reference Incident Classification Taxonomy. Task Force Status and Way Forward (2018)","key":"3_CR26"},{"key":"3_CR27","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1016\/j.cose.2016.05.004","volume":"61","author":"M Bartnes","year":"2016","unstructured":"Bartnes, M., Moe, N.B., Heegaard, P.E.: The future of information security incident management training. A case study of electrical power companies. Comput. Secur. 61, 32\u201345 (2016)","journal-title":"Comput. Secur."},{"key":"3_CR28","doi-asserted-by":"publisher","first-page":"527","DOI":"10.1007\/978-3-540-69295-9_42","volume-title":"Autonomic and Trusted Computing, 5060","author":"MG Jaatun","year":"2008","unstructured":"Jaatun, M.G., et al.: A study of information security practice in a critical infrastructure application. In: Rong, C., Jaatun, M.G., Ma, J., Sandnes, F.E., Yang, L.T. (eds.) Autonomic and Trusted Computing, 5060, pp. 527\u2013539. Springer, Berlin (2008). \nhttps:\/\/doi.org\/10.1007\/978-3-540-69295-9_42"},{"key":"3_CR29","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1108\/09685221011035241","volume":"18","author":"R Werlinger","year":"2010","unstructured":"Werlinger, R., Muldner, K., Hawkey, K., Beznosov, K.: Preparation, detection, and analysis. The diagnostic work of IT security incident response. Info. Manage. Comp. Secur. 18, 26\u201342 (2010)","journal-title":"Info. Manage. Comp. Secur."},{"doi-asserted-by":"crossref","unstructured":"Werlinger, R., Hawkey, K., Muldner, K., Jaferian, P., Beznosov, K.: The challenges of using an intrusion detection system. In: Cranor, L.F. (ed.) Proceedings of the 4th Symposium on Usable Privacy and Security, p. 107. ACM, New York (2008)","key":"3_CR30","DOI":"10.1145\/1408664.1408679"},{"key":"3_CR31","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1108\/09685220910944722","volume":"17","author":"R Werlinger","year":"2009","unstructured":"Werlinger, R., Hawkey, K., Beznosov, K.: An integrated view of human, organizational, and technological challenges of IT security management. Info. Manage. Comp. Secur. 17, 4\u201319 (2009)","journal-title":"Info. Manage. Comp. Secur."},{"key":"3_CR32","volume-title":"Business Research Methods","author":"A Bryman","year":"2015","unstructured":"Bryman, A., Bell, E.: Business Research Methods. University Press, Oxford (2015)"},{"key":"3_CR33","volume-title":"The Good Research Guide. For Small-Scale Social Research Projects.","author":"M Denscombe","year":"2014","unstructured":"Denscombe, M.: The Good Research Guide. For Small-Scale Social Research Projects. McGraw-Hill Education, Maidenhead (2014)"},{"key":"3_CR34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10632-8","volume-title":"An Introduction to Design Science","author":"P Johannesson","year":"2014","unstructured":"Johannesson, P., Perjons, E.: An Introduction to Design Science. Springer, Cham (2014). \nhttps:\/\/doi.org\/10.1007\/978-3-319-10632-8"},{"key":"3_CR35","first-page":"19","volume":"40","author":"JT Croasmun","year":"2011","unstructured":"Croasmun, J.T., Ostrom, L.: Using likert-type scales in the social sciences. J. Adult Educ. 40, 19\u201322 (2011)","journal-title":"J. Adult Educ."},{"key":"3_CR36","volume-title":"Investigating the Social World. The Process and Practice of Research","author":"RK Schutt","year":"2015","unstructured":"Schutt, R.K.: Investigating the Social World. The Process and Practice of Research. Sage, Thousand Oaks (2015)"}],"container-title":["Communications in Computer and Information Science","Information Systems Security and Privacy"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-49443-8_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,6,27]],"date-time":"2020-06-27T12:27:59Z","timestamp":1593260879000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-49443-8_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030494421","9783030494438"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-49443-8_3","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"28 June 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICISSP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information Systems Security and Privacy","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Prague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Czech Republic","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 February 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 February 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"5","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icissp2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.icissp.org\/?y=2019","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"PRIMORIS","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"100","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}