{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:43:41Z","timestamp":1785512621877,"version":"3.56.0"},"publisher-location":"Cham","reference-count":21,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783031254598","type":"print"},{"value":"9783031254604","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-25460-4_38","type":"book-chapter","created":{"date-parts":[[2023,2,17]],"date-time":"2023-02-17T09:12:22Z","timestamp":1676625142000},"page":"666-685","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Product Incremental Security Risk Assessment Using DevSecOps Practices"],"prefix":"10.1007","author":[{"given":"S\u00e9bastien","family":"Dupont","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Artsiom","family":"Yautsiukhin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guillaume","family":"Ginis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giacomo","family":"Iadarola","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Stefano","family":"Fagnano","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fabio","family":"Martinelli","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christophe","family":"Ponsard","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Axel","family":"Legay","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Philippe","family":"Massonet","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,2,18]]},"reference":[{"key":"38_CR1","doi-asserted-by":"crossref","unstructured":"Dupont, S., et al.: Incremental common criteria certification processes using devsecops practices. p. 12 (2021). https:\/\/ieeexplore.ieee.org\/abstract\/document\/9583720","DOI":"10.1109\/EuroSPW54576.2021.00009"},{"key":"38_CR2","unstructured":"ISO. ISO\/IEC 27000 Family - Information Security Management Systems. https:\/\/www.iso.org\/isoiec-27001-information-security.html (2013)"},{"issue":"1","key":"38_CR3","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/52.62930","volume":"8","author":"B Boehm","year":"1991","unstructured":"Boehm, B.: Software risk management: principles and practices. IEEE Softw. 8(1), 32\u201341 (1991)","journal-title":"IEEE Softw."},{"key":"38_CR4","doi-asserted-by":"crossref","unstructured":"Verdon, D., McGraw, G.: Risk analysis in software design. IEEE Secur. Priv. 2(4), 79\u201384 (2004)","DOI":"10.1109\/MSP.2004.55"},{"key":"38_CR5","doi-asserted-by":"crossref","unstructured":"Baca, D., Petersen, K.: Countermeasure graphs for software security risk assessment. J. Syst. Softw. 86(9), 2411\u20132428 (2013)","DOI":"10.1016\/j.jss.2013.04.023"},{"issue":"6","key":"38_CR6","doi-asserted-by":"publisher","first-page":"1251","DOI":"10.1109\/TIM.2007.915139","volume":"57","author":"M Sahinoglu","year":"2008","unstructured":"Sahinoglu, M.: An input-output measurable design for the security meter model to quantify and manage software security risk. IEEE Trans. Instrum. Meas. 57(6), 1251\u20131260 (2008)","journal-title":"IEEE Trans. Instrum. Meas."},{"key":"38_CR7","unstructured":"ISO\/IEC. Common Criteria for Information Technology Security Evaluation, version 3.1 revision 5 ed"},{"key":"38_CR8","first-page":"2014","volume":"3","author":"D Edwards","year":"2010","unstructured":"Edwards, D.: What is devops. Retrieved 3, 2014 (2010)","journal-title":"Retrieved"},{"key":"38_CR9","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/978-3-319-67383-7_2","volume-title":"Software Process Improvement and Capability Determination","author":"H Myrbakken","year":"2017","unstructured":"Myrbakken, H., Colomo-Palacios, R.: DevSecOps: a multivocal literature review. In: Mas, A., Mesquida, A., O\u2019Connor, R.V., Rout, T., Dorling, A. (eds.) SPICE 2017. CCIS, vol. 770, pp. 17\u201329. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-67383-7_2"},{"key":"38_CR10","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2021.106700","volume":"141","author":"RN Rajapakse","year":"2022","unstructured":"Rajapakse, R.N., Zahedi, M., Babar, M.A., Shen, H.: Challenges and solutions when adopting devsecops: a systematic review. Inf. Softw. Technol. 141, 106700 (2022)","journal-title":"Inf. Softw. Technol."},{"key":"38_CR11","doi-asserted-by":"crossref","unstructured":"D\u00edaz, J., P\u00e9rez, J.E., Lopez-Pe\u00f1a, M.A., Mena, G.A., Yag\u00fce, A.: Self-service cybersecurity monitoring as enabler for devsecops. IEEE Access 7, 100283\u2013100295 (2019)","DOI":"10.1109\/ACCESS.2019.2930000"},{"key":"38_CR12","unstructured":"Hsu, T.H.-C.: Hands-On Security in DevOps: Ensure Continuous Security, Deployment, and Delivery with DevSecOps. Packt Publishing Ltd, Birmingham (2018)"},{"key":"38_CR13","volume-title":"Secdevops: Is it a Marketing Buzzword","author":"V Mohan","year":"2016","unstructured":"Mohan, V., Othmane, L.: Secdevops: Is it a Marketing Buzzword. Department of Computer Science, Technische Universit\u00e4t Darmstadt, Darmstadt (2016)"},{"key":"38_CR14","unstructured":"ISO\/IEC. ISO\/IEC 27005:2008 Information technology - Security techniques - Information security risk management (2008)"},{"key":"38_CR15","unstructured":"NIST. Risk management framework for information systems and organizations. a system life cycle approach for security and privacy. NIST, Tech. Rep., (2018). https:\/\/csrc.nist.gov\/projects\/risk-management\/about-rmf on 09\/05\/2022"},{"key":"38_CR16","doi-asserted-by":"crossref","unstructured":"Sadiq, M., Rahmani, M.K.I., Ahmad, M.W., Jung, S.: Software risk assessment and evaluation process (sraep) using model based approach. In: International Conference on Networking and Information Technology 2010, 171\u2013177 (2010)","DOI":"10.1109\/ICNIT.2010.5508535"},{"key":"38_CR17","unstructured":"Khan, M.A., Khan, S., Sadiq, M.: Systematic review of software risk assessment and estimation models. Int. J. Eng. Adv. Technol. 1(4) (2012)"},{"key":"38_CR18","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Jiang, S., Cui, Y., Zhang, B., Xia, H.: A qualitative and quantitative risk assessment method in software security. In: 2010 3rd International Conference on Advanced Computer Theory and Engineering(ICACTE). vol. 1, pp. V1\u2013534-V1-539 (2010)","DOI":"10.1109\/ICACTE.2010.5578960"},{"key":"38_CR19","doi-asserted-by":"crossref","unstructured":"Das, R., Sarkani, S., Mazzuchi, T.A.: Software selection based on quantitative security risk assessment. In: 2012 IEEE 14th International Symposium on High-Assurance Systems Engineering, pp. 171\u2013172 (2012)","DOI":"10.1109\/HASE.2012.10"},{"key":"38_CR20","doi-asserted-by":"crossref","unstructured":"Mkpong-Ruffin, I., Umphress, D., Hamilton, J., Gilbert, J.: Quantitative software security risk assessment model. In: Proceedings of the 2007 ACM Workshop on Quality of Protection, ser. QoP 2007. New York, USA: Association for Computing Machinery, pp. 31\u201333 (2007)","DOI":"10.1145\/1314257.1314267"},{"key":"38_CR21","doi-asserted-by":"crossref","unstructured":"Kumar, R., Goyal, R.: Modeling continuous security: a conceptual model for automated DevSecOps using open-source software over cloud (ADOC). Comput. Secu. 97, 101967 (2020)","DOI":"10.1016\/j.cose.2020.101967"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2022 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-25460-4_38","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,14]],"date-time":"2024-10-14T13:31:25Z","timestamp":1728912685000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-25460-4_38"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031254598","9783031254604"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-25460-4_38","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"18 February 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Copenhagen","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 September 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2022.compute.dtu.dk\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"80","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"38","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"48% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1.7","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}