{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,7]],"date-time":"2025-08-07T21:06:03Z","timestamp":1754600763074,"version":"3.40.3"},"publisher-location":"Cham","reference-count":43,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031330797"},{"type":"electronic","value":"9783031330803"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,5,23]],"date-time":"2023-05-23T00:00:00Z","timestamp":1684800000000},"content-version":"vor","delay-in-days":142,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Forensic-ready software systems enhance the security posture by designing the systems prepared for potential investigation of incidents. Yet, the principal obstacle is defining their exact requirements, i.e., what they should implement. Such a requirement needs to be on-point and verifiable. However, what exactly comprises a forensic readiness requirement is not fully understood due to distinct fields of expertise in software engineering and digital forensics. This paper describes a forensic readiness qualitative factor reference model that enables the formulation of specific requirements for forensic-ready software systems. It organises the qualitative properties of forensic readiness into a taxonomy, which can then be used to formulate a verifiable requirement targeted at a specific quality. The model is then utilised in an automated valet parking service to define requirements addressing found inadequacies regarding a potential incident investigation.<\/jats:p>","DOI":"10.1007\/978-3-031-33080-3_19","type":"book-chapter","created":{"date-parts":[[2023,5,22]],"date-time":"2023-05-22T16:02:35Z","timestamp":1684771355000},"page":"308-324","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["A Model of\u00a0Qualitative Factors in\u00a0Forensic-Ready Software Systems"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0853-2776","authenticated-orcid":false,"given":"Lukas","family":"Daubner","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1829-4794","authenticated-orcid":false,"given":"Raimundas","family":"Matulevi\u010dius","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4205-101X","authenticated-orcid":false,"given":"Barbora","family":"Buhnova","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,5,23]]},"reference":[{"key":"19_CR1","doi-asserted-by":"crossref","unstructured":"Ab Rahman, N.H., Glisson, W.B., Yang, Y., Choo, K.K.R.: Forensic-by-design framework for cyber-physical cloud systems. IEEE Cloud Comput. 3(1), 50\u201359 (2016)","DOI":"10.1109\/MCC.2016.5"},{"key":"19_CR2","doi-asserted-by":"crossref","unstructured":"Alrajeh, D., Pasquale, L., Nuseibeh, B.: On evidence preservation requirements for forensic-ready systems. In: Proceedings of the 2017 11th Joint Meeting on Foundations of Software Engineering, ESEC\/FSE 2017, pp. 559\u2013569. ACM (2017)","DOI":"10.1145\/3106237.3106308"},{"key":"19_CR3","unstructured":"Alrimawi, F.: Software engineering for forensic-ready cyber-physical systems. Theses, University of Limerick (2020). https:\/\/hdl.handle.net\/10344\/9294"},{"key":"19_CR4","doi-asserted-by":"crossref","unstructured":"Alrimawi, F., Pasquale, L., Nuseibeh, B.: Software engineering challenges for investigating cyber-physical incidents. In: 2017 IEEE\/ACM 3rd International Workshop on Software Engineering for Smart Cyber-Physical Systems, pp. 34\u201340 (2017)","DOI":"10.1109\/SEsCPS.2017.9"},{"key":"19_CR5","doi-asserted-by":"crossref","unstructured":"Bajramovic, E., Waedt, K., Ciriello, A., Gupta, D.: Forensic readiness of smart buildings: preconditions for subsequent cybersecurity tests. In: 2016 IEEE International Smart Cities Conference, pp. 1\u20136 (2016)","DOI":"10.1109\/ISC2.2016.7580754"},{"key":"19_CR6","first-page":"133","volume":"31","author":"A Bierska","year":"2022","unstructured":"Bierska, A., Buhnova, B., Bangui, H.: Integrated checklist for architecture design of critical software systems. Ann. Comput. Sci. Inf. Syst. 31, 133\u2013140 (2022)","journal-title":"Ann. Comput. Sci. Inf. Syst."},{"key":"19_CR7","unstructured":"Casey, E.: Error, uncertainty and loss in digital evidence. Int. J. Digit. EVid. 1 (2002)"},{"key":"19_CR8","volume-title":"Digital Evidence and Computer Crime","author":"E Casey","year":"2011","unstructured":"Casey, E.: Digital Evidence and Computer Crime, 3rd edn. Academic Press, Waltham (2011)","edition":"3"},{"key":"19_CR9","unstructured":"CESG: Good Practice Guide No. 18: Forensic Readiness. Guideline, National Technical Authority for Information Assurance, United Kingdom (2015)"},{"key":"19_CR10","unstructured":"Cosic, J., Baca, M.: Do we have full control over integrity in digital evidence life cycle? In: Proceedings of the ITI 2010, 32nd International Conference on Information Technology Interfaces, pp. 429\u2013434. IEEE (2010)"},{"key":"19_CR11","doi-asserted-by":"crossref","unstructured":"Daubner, L., Buhnova, B., Pitner, T.: Forensic experts\u2019 view of forensic-ready software systems: a qualitative study. J. Softw. Evol. Process (2023, under review)","DOI":"10.1002\/smr.2598"},{"key":"19_CR12","doi-asserted-by":"crossref","unstructured":"Daubner, L., Macak, M., Buhnova, B., Pitner, T.: Towards verifiable evidence generation in forensic-ready systems, pp. 2264\u20132269. IEEE (2020)","DOI":"10.1109\/BigData50022.2020.9378035"},{"key":"19_CR13","doi-asserted-by":"crossref","unstructured":"Daubner, L., Macak, M., Buhnova, B., Pitner, T.: Verification of Forensic Readiness in Software Development: A Roadmap, pp. 1658\u20131661. ACM (2020)","DOI":"10.1145\/3341105.3374094"},{"key":"19_CR14","volume":"73","author":"L Daubner","year":"2023","unstructured":"Daubner, L., Macak, M., Matulevi\u010dius, R., Buhnova, B., Maksovi\u0107, S., Pitner, T.: Addressing insider attacks via forensic-ready risk management. J. Inf. Secur. Appl. 73, 103433 (2023)","journal-title":"J. Inf. Secur. Appl."},{"key":"19_CR15","doi-asserted-by":"crossref","unstructured":"Daubner, L., Matulevi\u010dius, R.: Risk-oriented design approach for forensic-ready software systems. In: The 16th International Conference on Availability, Reliability and Security. ACM (2021)","DOI":"10.1145\/3465481.3470052"},{"key":"19_CR16","doi-asserted-by":"crossref","unstructured":"Daubner, L., Matulevi\u010dius, R., Buhnova, B., Pitner, T.: Business process model and notation for forensic-ready software systems. In: Proceedings of the 17th International Conference on Evaluation of Novel Approaches to Software Engineering, pp. 95\u2013106. SciTePress (2022)","DOI":"10.5220\/0011041000003176"},{"key":"19_CR17","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1007\/978-3-642-12544-7_16","volume-title":"Intentional Perspectives on Information Systems Engineering","author":"\u00c9 Dubois","year":"2010","unstructured":"Dubois, \u00c9., Heymans, P., Mayer, N., Matulevi\u010dius, R.: A systematic approach to define the domain of information system security risk management. In: Nurcan, S., Salinesi, C., Souveyet, C., Ralyt\u00e9, J. (eds.) Intentional Perspectives on Information Systems Engineering, pp. 289\u2013306. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-12544-7_16"},{"key":"19_CR18","doi-asserted-by":"publisher","DOI":"10.7717\/peerj-cs.1165","volume":"8","author":"P Dzurenda","year":"2022","unstructured":"Dzurenda, P., et al.: Privacy-preserving solution for vehicle parking services complying with EU legislation. PeerJ Comput. Sci. 8, e1165 (2022)","journal-title":"PeerJ Comput. Sci."},{"issue":"1","key":"19_CR19","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1109\/MCOM.2013.6400441","volume":"51","author":"M Erol-Kantarci","year":"2013","unstructured":"Erol-Kantarci, M., Mouftah, H.T.: Smart grid forensic science: applications, challenges, and open issues. IEEE Commun. Mag. 51(1), 68\u201374 (2013)","journal-title":"IEEE Commun. Mag."},{"key":"19_CR20","doi-asserted-by":"crossref","unstructured":"Firesmith, D.: Common concepts underlying safety, security, and survivability engineering. Technical report, CMU\/SEI-2003-TN-033, Software Engineering Institute, Carnegie Mellon University, Pittsburgh, PA (2003)","DOI":"10.21236\/ADA421683"},{"issue":"3","key":"19_CR21","doi-asserted-by":"publisher","first-page":"27","DOI":"10.5381\/jot.2004.3.3.c3","volume":"3","author":"D Firesmith","year":"2004","unstructured":"Firesmith, D.: Engineering safety requirements, safety constraints, and safety-critical requirements. J. Object Technol. 3(3), 27\u201342 (2004)","journal-title":"J. Object Technol."},{"issue":"1","key":"19_CR22","doi-asserted-by":"publisher","first-page":"53","DOI":"10.5381\/jot.2003.2.1.c6","volume":"2","author":"D Firesmith","year":"2003","unstructured":"Firesmith, D., et al.: Engineering security requirements. J. Object Technol. 2(1), 53\u201368 (2003)","journal-title":"J. Object Technol."},{"key":"19_CR23","doi-asserted-by":"crossref","unstructured":"Grispos, G., Garc\u00eda-Gal\u00e1n, J., Pasquale, L., Nuseibeh, B.: Are you ready? Towards the engineering of forensic-ready systems. In: 2017 11th International Conference on Research Challenges in Information Science, pp. 328\u2013333 (2017)","DOI":"10.1109\/RCIS.2017.7956555"},{"key":"19_CR24","doi-asserted-by":"crossref","unstructured":"Grispos, G., Glisson, W.B., Choo, K.K.R.: Medical cyber-physical systems development: a forensics-driven approach. In: 2017 IEEE\/ACM International Conference on Connected Health: Applications, Systems and Engineering Technologies, pp. 108\u2013113 (2017)","DOI":"10.1109\/CHASE.2017.68"},{"key":"19_CR25","series-title":"IFIP International Federation for Information Processing","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1007\/978-0-387-72367-9_2","volume-title":"New Approaches for Security, Privacy and Trust in Complex Environments","author":"CP Grobler","year":"2007","unstructured":"Grobler, C.P., Louwrens, C.P.: Digital forensic readiness as a component of information security best practice. In: Venter, H., Eloff, M., Labuschagne, L., Eloff, J., von Solms, R. (eds.) SEC 2007. IIFIP, vol. 232, pp. 13\u201324. Springer, Boston, MA (2007). https:\/\/doi.org\/10.1007\/978-0-387-72367-9_2"},{"key":"19_CR26","doi-asserted-by":"crossref","unstructured":"Grobler, C., Louwrens, C., von Solms, S.: A framework to guide the implementation of proactive digital forensics in organisations. In: 2010 International Conference on Availability, Reliability and Security, pp. 677\u2013682 (2010)","DOI":"10.1109\/ARES.2010.62"},{"key":"19_CR27","doi-asserted-by":"crossref","unstructured":"Hitchcock, B., Le-Khac, N.A., Scanlon, M.: Tiered forensic methodology model for digital field triage by non-digital evidence specialists. Digit. Invest. 16, S75\u2013S85 (2016). dFRWS 2016 Europe","DOI":"10.1016\/j.diin.2016.01.010"},{"key":"19_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"412","DOI":"10.1007\/3-540-45800-X_32","volume-title":"UML 2002 \u2014 The Unified Modeling Language","author":"J J\u00fcrjens","year":"2002","unstructured":"J\u00fcrjens, J.: UMLsec: extending UML for secure systems development. In: J\u00e9z\u00e9quel, J.-M., Hussmann, H., Cook, S. (eds.) UML 2002. LNCS, vol. 2460, pp. 412\u2013425. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-45800-X_32"},{"key":"19_CR29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-61717-6","volume-title":"Fundamentals of Secure System Modelling","author":"R Matulevi\u010dius","year":"2017","unstructured":"Matulevi\u010dius, R.: Fundamentals of Secure System Modelling. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-61717-6"},{"key":"19_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"541","DOI":"10.1007\/978-3-540-69534-9_40","volume-title":"Advanced Information Systems Engineering","author":"R Matulevi\u010dius","year":"2008","unstructured":"Matulevi\u010dius, R., Mayer, N., Mouratidis, H., Dubois, E., Heymans, P., Genon, N.: Adapting secure tropos for security risk management in the early phases of information systems development. In: Bellahs\u00e8ne, Z., L\u00e9onard, M. (eds.) CAiSE 2008. LNCS, vol. 5074, pp. 541\u2013555. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-69534-9_40"},{"key":"19_CR31","unstructured":"Mayer, N.: Model-based Management of Information System Security Risk. Theses, University of Namur (2009). https:\/\/tel.archives-ouvertes.fr\/tel-00402996"},{"key":"19_CR32","series-title":"IFIP \u2014 The International Federation for Information Processing","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-0-387-84927-0_1","volume-title":"Advances in Digital Forensics IV","author":"R McKemmish","year":"2008","unstructured":"McKemmish, R.: When is digital evidence forensically sound? In: Ray, I., Shenoi, S. (eds.) DigitalForensics 2008. ITIFIP, vol. 285, pp. 3\u201315. Springer, Boston, MA (2008). https:\/\/doi.org\/10.1007\/978-0-387-84927-0_1"},{"key":"19_CR33","doi-asserted-by":"publisher","DOI":"10.1201\/9780429466335","volume-title":"Handbook of Applied Cryptography","author":"AJ Menezes","year":"2018","unstructured":"Menezes, A.J., Van Oorschot, P.C., Vanstone, S.A.: Handbook of Applied Cryptography. CRC Press, Boca Raton (2018)"},{"key":"19_CR34","doi-asserted-by":"crossref","unstructured":"Mohammadi, N.G., et al.: An analysis of software quality attributes and their contribution to trustworthiness. In: Proceedings of the 3rd International Conference on Cloud Computing and Services Science, pp. 542\u2013552. SciTePress (2013)","DOI":"10.5220\/0004502705420552"},{"key":"19_CR35","doi-asserted-by":"crossref","unstructured":"Pasquale, L., Alrajeh, D., Peersman, C., Tun, T., Nuseibeh, B., Rashid, A.: Towards forensic-ready software systems. In: Proceedings of the 40th International Conference on Software Engineering: New Ideas and Emerging Results, pp. 9\u201312. ACM (2018)","DOI":"10.1145\/3183399.3183426"},{"key":"19_CR36","doi-asserted-by":"crossref","unstructured":"Richter, J., Kuntze, N., Rudolph, C.: Security digital evidence. In: 2010 Fifth IEEE International Workshop on Systematic Approaches to Digital Forensic Engineering, pp. 119\u2013130 (2010)","DOI":"10.1109\/SADFE.2010.31"},{"key":"19_CR37","doi-asserted-by":"crossref","unstructured":"Rivera-Ortiz, F., Pasquale, L.: Automated modelling of security incidents to represent logging requirements in software systems. In: Proceedings of the 15th International Conference on Availability, Reliability and Security. ACM (2020)","DOI":"10.1145\/3407023.3407081"},{"key":"19_CR38","first-page":"1","volume":"2","author":"R Rowlingson","year":"2004","unstructured":"Rowlingson, R.: A ten step process for forensic readiness. Int. J. Digit. Evid. 2, 1\u201328 (2004)","journal-title":"Int. J. Digit. Evid."},{"issue":"3","key":"19_CR39","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1093\/ijlit\/eaw005","volume":"24","author":"A Sethia","year":"2016","unstructured":"Sethia, A.: Rethinking admissibility of electronic evidence. Int. J. Law Inf. Technol. 24(3), 229\u2013250 (2016)","journal-title":"Int. J. Law Inf. Technol."},{"key":"19_CR40","volume-title":"Threat Modeling: Designing for Security","author":"A Shostack","year":"2014","unstructured":"Shostack, A.: Threat Modeling: Designing for Security. Wiley, Hoboken (2014)"},{"key":"19_CR41","series-title":"Lecture Notes in Business Information Processing","doi-asserted-by":"publisher","first-page":"689","DOI":"10.1007\/978-3-642-36285-9_68","volume-title":"Business Process Management Workshops","author":"I Soomro","year":"2013","unstructured":"Soomro, I., Ahmed, N.: Towards security risk-oriented misuse cases. In: La Rosa, M., Soffer, P. (eds.) BPM 2012. LNBIP, vol. 132, pp. 689\u2013700. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-36285-9_68"},{"key":"19_CR42","unstructured":"Tan, J.: Forensic readiness. Technical report, @stake, Inc. (2001)"},{"key":"19_CR43","unstructured":"\u0106osi\u0107, J., Ba\u010da, M.: (Im)proving chain of custody and digital evidence integrity with time stamp. In: The 33rd International Convention MIPRO, pp. 1226\u20131230 (2010)"}],"container-title":["Lecture Notes in Business Information Processing","Research Challenges in Information Science: Information Science and the Connected World"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-33080-3_19","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,20]],"date-time":"2024-10-20T21:35:52Z","timestamp":1729460152000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-33080-3_19"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031330797","9783031330803"],"references-count":43,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-33080-3_19","relation":{},"ISSN":["1865-1348","1865-1356"],"issn-type":[{"type":"print","value":"1865-1348"},{"type":"electronic","value":"1865-1356"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"23 May 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"RCIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Research Challenges in Information Science","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Corfu","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Greece","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 May 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 May 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"rcis2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.rcis-conf.com\/rcis2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"87","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"21","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"32% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}