{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,6]],"date-time":"2025-07-06T22:40:08Z","timestamp":1751841608694,"version":"3.41.0"},"publisher-location":"Cham","reference-count":24,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030811105"},{"type":"electronic","value":"9783030811112"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-81111-2_7","type":"book-chapter","created":{"date-parts":[[2021,7,7]],"date-time":"2021-07-07T06:02:42Z","timestamp":1625637762000},"page":"81-90","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["What Can We Learn from the Analysis of Information Security Policies? The Case of UK\u2019s Schools"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8586-6767","authenticated-orcid":false,"given":"Martin","family":"Sparrius","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2981-6516","authenticated-orcid":false,"given":"Moufida","family":"Sadok","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3631-2626","authenticated-orcid":false,"given":"Peter","family":"Bednar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,7,8]]},"reference":[{"key":"7_CR1","unstructured":"Standard, I.: ISO\/IEC 27002 - Code of practice for information security management (2005)"},{"key":"7_CR2","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1016\/j.jsis.2010.10.002","volume":"19","author":"S Goel","year":"2010","unstructured":"Goel, S., Chengalur-Smith, I.N.: Metrics for characterizing the form of security policies. J. Strateg. Inf. Syst. 19, 281\u2013295 (2010). https:\/\/doi.org\/10.1016\/j.jsis.2010.10.002","journal-title":"J. Strateg. Inf. Syst."},{"key":"7_CR3","unstructured":"Weidman, J., Grossklags, J.: What\u2019s in your policy? An analysis of the current state of information security policies in academic institutions. In: 26th European Conference on Information Systems: Beyond Digitization \u2013 Facets of Socio-Technical Change, ECIS 2018, pp. 1\u201316 (2018)"},{"key":"7_CR4","doi-asserted-by":"publisher","unstructured":"Laszka, A., Farhang, S., Grossklags, J., On the Economics of Ransomware. Lecture Notes in Computer Science (including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). 10575 LNCS, pp. 397\u2013417 (2017). https:\/\/doi.org\/10.1007\/978-3-319-68711-7_21","DOI":"10.1007\/978-3-319-68711-7_21"},{"key":"7_CR5","doi-asserted-by":"publisher","unstructured":"Verizon: 2021 data breach investigations report. Verizon Bus. J. (2021). https:\/\/doi.org\/10.1057\/s41280-018-0097-z","DOI":"10.1057\/s41280-018-0097-z"},{"key":"7_CR6","doi-asserted-by":"publisher","unstructured":"Department for Digitial, Culture, M & S.: Cyber security breaches survey 2021 - Education institutions findings annex (2021). https:\/\/doi.org\/10.1016\/s1361-3723(20)30037-3","DOI":"10.1016\/s1361-3723(20)30037-3"},{"key":"7_CR7","doi-asserted-by":"publisher","first-page":"101608","DOI":"10.1016\/j.cose.2019.101608","volume":"88","author":"H Paananen","year":"2020","unstructured":"Paananen, H., Lapke, M., Siponen, M.: State of the art in information security policy development. Comput. Secur. 88, 101608 (2020). https:\/\/doi.org\/10.1016\/j.cose.2019.101608","journal-title":"Comput. Secur."},{"key":"7_CR8","doi-asserted-by":"publisher","first-page":"506","DOI":"10.1016\/S0167-4048(02)01006-4","volume":"21","author":"J David","year":"2002","unstructured":"David, J.: Policy enforcement in the workplace. Comput. Secur. 21, 506\u2013513 (2002). https:\/\/doi.org\/10.1016\/S0167-4048(02)01006-4","journal-title":"Comput. Secur."},{"key":"7_CR9","unstructured":"Klai\u0107, A.: Overview of the state and trends in the contemporary information security policy and information security management methodologies. In: MIPRO 2010 - 33rd International Convention on Information, Communication and Technology Electron Microelectron Proceedings, pp. 1203\u20131208 (2010)"},{"key":"7_CR10","doi-asserted-by":"publisher","first-page":"264","DOI":"10.1108\/09685221211267648","volume":"20","author":"V Pathari","year":"2012","unstructured":"Pathari, V., Sonar, R.: Identifying linkages between statements in information security policy, procedures and controls. Inf. Manag. Comput. Secur. 20, 264\u2013280 (2012). https:\/\/doi.org\/10.1108\/09685221211267648","journal-title":"Inf. Manag. Comput. Secur."},{"key":"7_CR11","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1016\/j.ijinfomgt.2009.05.003","volume":"29","author":"NF Doherty","year":"2009","unstructured":"Doherty, N.F., Anastasakis, L., Fulford, H.: The information security policy unpacked: a critical study of the content of university policies. Int. J. Inf. Manage. 29, 449\u2013457 (2009). https:\/\/doi.org\/10.1016\/j.ijinfomgt.2009.05.003","journal-title":"Int. J. Inf. Manage."},{"key":"7_CR12","doi-asserted-by":"publisher","first-page":"605","DOI":"10.1057\/s41303-017-0059-9","volume":"26","author":"WA Cram","year":"2017","unstructured":"Cram, W.A., Proudfoot, J.G., D\u2019Arcy, J.: Organizational information security policies: a review and research framework. Eur. J. Inf. Syst. 26, 605\u2013641 (2017). https:\/\/doi.org\/10.1057\/s41303-017-0059-9","journal-title":"Eur. J. Inf. Syst."},{"key":"7_CR13","doi-asserted-by":"publisher","first-page":"337","DOI":"10.1108\/09576050210447019","volume":"15","author":"R Baskerville","year":"2002","unstructured":"Baskerville, R., Siponen, M.: An information security meta-policy for emergent organizations. Logist. Inf. Manag. 15, 337\u2013346 (2002). https:\/\/doi.org\/10.1108\/09576050210447019","journal-title":"Logist. Inf. Manag."},{"key":"7_CR14","doi-asserted-by":"publisher","first-page":"246","DOI":"10.1016\/j.cose.2004.08.011","volume":"24","author":"M Karyda","year":"2005","unstructured":"Karyda, M., Kiountouzis, E., Kokolakis, S.: Information systems security policies: a contextual perspective. Comput. Secur. 24, 246\u2013260 (2005). https:\/\/doi.org\/10.1016\/j.cose.2004.08.011","journal-title":"Comput. Secur."},{"key":"7_CR15","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1016\/j.cose.2016.12.012","volume":"67","author":"F Karlsson","year":"2017","unstructured":"Karlsson, F., Hedstr\u00f6m, K., Goldkuhl, G.: Practice-based discourse analysis of information security policies. Comput. Secur. 67, 267\u2013279 (2017). https:\/\/doi.org\/10.1016\/j.cose.2016.12.012","journal-title":"Comput. Secur."},{"key":"7_CR16","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1111\/j.1365-2575.2011.00378.x","volume":"22","author":"BC Stahl","year":"2012","unstructured":"Stahl, B.C., Doherty, N.F., Shaw, M.: Information security policies in the UK healthcare sector: a critical evaluation. Inf. Syst. J. 22, 77\u201394 (2012). https:\/\/doi.org\/10.1111\/j.1365-2575.2011.00378.x","journal-title":"Inf. Syst. J."},{"key":"7_CR17","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1111\/j.1365-2575.2006.00219.x","volume":"16","author":"G Dhillon","year":"2006","unstructured":"Dhillon, G., Torkzadeh, G.: Value-focused assessment of information system security in organizations. Inf. Syst. J. 16, 293\u2013314 (2006). https:\/\/doi.org\/10.1111\/j.1365-2575.2006.00219.x","journal-title":"Inf. Syst. J."},{"issue":"5","key":"7_CR18","doi-asserted-by":"publisher","first-page":"597","DOI":"10.1016\/j.im.2003.08.001","volume":"41","author":"AG Kotulic","year":"2004","unstructured":"Kotulic, A.G., Clark, J.G.: Why there aren\u2019t more information security research studies. Inf. Manage. 41(5), 597\u2013607 (2004)","journal-title":"Inf. Manage."},{"key":"7_CR19","unstructured":"Department for Education: Schools, pupils and their characteristics (2019). https:\/\/www.gov.uk\/government\/statistics\/schools-pupils-and-their-characteristics-january-2019"},{"key":"7_CR20","unstructured":"NHS: Use a readability tool to prioritise content - NHS digital service manual. https:\/\/service-manual.nhs.uk\/content\/health-literacy\/use-a-readability-tool-to-prioritise-content"},{"key":"7_CR21","unstructured":"Feng, L., Jansche, M., Huenerfauth, M., Elhadad, N.: A comparison of features for automatic readability assessment. Coling 2010 \u2013 Proceedings of the 23rd International Conference on Computational Linguistics, vol. 2, pp. 276\u2013284 (2010)"},{"key":"7_CR22","unstructured":"Department for Education: Statutory policies for schools and academy trusts - GOV.UK. https:\/\/www.gov.uk\/government\/publications\/statutory-policies-for-schools-and-academy-trusts\/statutory-policies-for-schools-and-academy-trusts"},{"key":"7_CR23","doi-asserted-by":"publisher","first-page":"543","DOI":"10.1136\/bmj.c2665","volume":"4","author":"A McDonald","year":"2008","unstructured":"McDonald, A., Cranor, L.: The cost of reading privacy policies. Isjlp. 4, 543\u2013568 (2008). https:\/\/doi.org\/10.1136\/bmj.c2665","journal-title":"Isjlp."},{"issue":"3","key":"7_CR24","doi-asserted-by":"publisher","first-page":"467","DOI":"10.1108\/ICS-01-2019-0010","volume":"28","author":"M Sadok","year":"2020","unstructured":"Sadok, M., Alter, S., Bednar, P.: It is not my job: exploring the disconnect between corporate security policies and actual security policies in SMEs. Inf. Comput. Secur. 28(3), 467\u2013483 (2020)","journal-title":"Inf. Comput. Secur."}],"container-title":["IFIP Advances in Information and Communication Technology","Human Aspects of Information Security and Assurance"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-81111-2_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,6]],"date-time":"2025-07-06T22:03:18Z","timestamp":1751839398000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-81111-2_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030811105","9783030811112"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-81111-2_7","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"8 July 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"HAISA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Human Aspects of Information Security and Assurance","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 July 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 July 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"haisa2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.haisa.org\/?page=home","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"30","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"18","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"60% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.43","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}