{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T21:10:24Z","timestamp":1761340224113,"version":"3.40.3"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031385292"},{"type":"electronic","value":"9783031385308"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-38530-8_15","type":"book-chapter","created":{"date-parts":[[2023,7,25]],"date-time":"2023-07-25T20:38:17Z","timestamp":1690317497000},"page":"181-191","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["\u201cCheck, Check, Check, We Got Those\u201d \u2013 Catalogue Use in Information Security Risk Management"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1436-2980","authenticated-orcid":false,"given":"Erik","family":"Bergstr\u00f6m","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1692-5721","authenticated-orcid":false,"given":"Martin","family":"Lundgren","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9109-5401","authenticated-orcid":false,"given":"Karin","family":"Bernsmed","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4456-6279","authenticated-orcid":false,"given":"Guillaume","family":"Bour","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,7,26]]},"reference":[{"key":"15_CR1","unstructured":"Fortune Media IP Limited. https:\/\/fortune.com\/education\/articles\/this-cybersecurity-job-is-one-of-the-fastest-growing-in-the-u-s-and-it-pays-six-figures\/"},{"key":"15_CR2","doi-asserted-by":"publisher","first-page":"472","DOI":"10.1093\/comjnl\/bxx093","volume":"61","author":"E Osborn","year":"2018","unstructured":"Osborn, E., Simpson, A.: Risk and the small-scale cyber security decision making dialogue\u2014a UK case study. Comput. J. 61, 472\u2013495 (2018)","journal-title":"Comput. J."},{"key":"15_CR3","unstructured":"Carvalho, R.M., Andrade, R.M., Lelli, V., Silva, E.G., de Oliveira, K.M.: What about catalogs of non-functional requirements? In: REFSQ Workshops (2020)"},{"key":"15_CR4","first-page":"23","volume":"2","author":"F S\u00e1-Soares","year":"2022","unstructured":"S\u00e1-Soares, F., Soares, D., Arnaud, J.: A catalog of information systems outsourcing risks. Int. J. Inf. Syst. Proj. Manage. 2, 23\u201343 (2022)","journal-title":"Int. J. Inf. Syst. Proj. Manage."},{"key":"15_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1007\/978-3-319-16101-3_7","volume-title":"Requirements Engineering: Foundation for Software Quality","author":"M de Gramatica","year":"2015","unstructured":"de Gramatica, M., Labunets, K., Massacci, F., Paci, F., Tedeschi, A.: The role of catalogues of threats and security controls in security risk assessment: an empirical study with ATM professionals. In: Fricker, S.A., Schneider, K. (eds.) REFSQ 2015. LNCS, vol. 9013, pp. 98\u2013114. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-16101-3_7"},{"key":"15_CR6","unstructured":"Rudolph, M.: Generation of usable policy administration points for security and privacy. Technische Universit\u00e4t Kaiserslautern, vol. Ph.D., p. 386, Fraunhofer Verlag (2020)"},{"key":"15_CR7","unstructured":"Labunets, K.: Security Risk Assessment Methods: An Evaluation Framework and Theoretical Model of the Criteria Behind Methods\u00e2 Success. University of Trento (2016)"},{"key":"15_CR8","first-page":"212","volume":"32","author":"R Leming","year":"2015","unstructured":"Leming, R.: Why is information the elephant asset? An answer to this question and a strategy for information asset management. Bus. Inf. Rev. 32, 212\u2013219 (2015)","journal-title":"Bus. Inf. Rev."},{"key":"15_CR9","doi-asserted-by":"crossref","unstructured":"Andersson, S.: Problems in information classification: insights from practice. Inf. Comput. Secur. (2023)","DOI":"10.1108\/ICS-10-2022-0163"},{"issue":"1","key":"15_CR10","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/s11416-019-00342-x","volume":"16","author":"R Luh","year":"2019","unstructured":"Luh, R., Temper, M., Tjoa, S., Schrittwieser, S., Janicke, H.: PenQuest: a gamified attacker\/defender meta model for cyber security assessment and education. J. Comput. Virol. Hacking Tech. 16(1), 19\u201361 (2019). https:\/\/doi.org\/10.1007\/s11416-019-00342-x","journal-title":"J. Comput. Virol. Hacking Tech."},{"issue":"2","key":"15_CR11","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1007\/s00766-015-0220-8","volume":"21","author":"A Souag","year":"2015","unstructured":"Souag, A., Mazo, R., Salinesi, C., Comyn-Wattiau, I.: Reusable knowledge in security requirements engineering: a systematic mapping study. Requirements Eng. 21(2), 251\u2013283 (2015). https:\/\/doi.org\/10.1007\/s00766-015-0220-8","journal-title":"Requirements Eng."},{"key":"15_CR12","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/MAES.2017.170037","volume":"32","author":"H Asgari","year":"2017","unstructured":"Asgari, H., et al.: Provisioning for a distributed ATM security management: the GAMMA approach. IEEE Aerosp. Electron. Syst. Mag. 32, 5\u201321 (2017)","journal-title":"IEEE Aerosp. Electron. Syst. Mag."},{"key":"15_CR13","doi-asserted-by":"crossref","unstructured":"Nie, R.T., Zhao, Y., Dai, J.H.: Evaluation on safety performance of air traffic management based on fuzzy theory. In: 2009 International Conference on Measuring Technology and Mechatronics Automation, pp. 554\u2013557 (2009)","DOI":"10.1109\/ICMTMA.2009.129"},{"key":"15_CR14","doi-asserted-by":"publisher","DOI":"10.1016\/j.jairtraman.2022.102223","volume":"102","author":"K Bernsmed","year":"2022","unstructured":"Bernsmed, K., Bour, G., Lundgren, M., Bergstr\u00f6m, E.: An evaluation of practitioners\u2019 perceptions of a security risk assessment methodology in air traffic management projects. J. Air Transp. Manag. 102, 102223 (2022)","journal-title":"J. Air Transp. Manag."},{"key":"15_CR15","volume-title":"Management of Information Security","author":"ME Whitman","year":"2013","unstructured":"Whitman, M.E., Mattord, H.J.: Management of Information Security. Cengage Learning, Stamford (2013)"},{"key":"15_CR16","doi-asserted-by":"publisher","first-page":"212","DOI":"10.1504\/IJRAM.2019.101287","volume":"22","author":"M Lundgren","year":"2019","unstructured":"Lundgren, M., Bergstr\u00f6m, E.: Dynamic interplay in the information security risk management process. Int. J. Risk Assess. Manage. 22, 212\u2013230 (2019)","journal-title":"Int. J. Risk Assess. Manage."},{"key":"15_CR17","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1080\/07421222.2001.11045671","volume":"18","author":"MM Lynne","year":"2001","unstructured":"Lynne, M.M.: Toward a theory of knowledge reuse: types of knowledge reuse situations and factors in reuse success. J. Manag. Inf. Syst. 18, 57\u201393 (2001)","journal-title":"J. Manag. Inf. Syst."},{"key":"15_CR18","unstructured":"Lambrinoudakis, C., et al.: Compendium of risk management frameworks with potential interoperability: supplement to the interoperable EU risk management framework report. European Union Agency for Cybersecurity (ENISA) (2022)"},{"key":"15_CR19","unstructured":"Papadatos, K., et al.: Interoperable EU Risk Management Toolbox. European Union Agency for Cybersecurity (ENISA) (2022)"},{"key":"15_CR20","doi-asserted-by":"crossref","unstructured":"Yskout, K., Scandariato, R., Joosen, W.: Do security patterns really help designers? In: 2015 IEEE\/ACM 37th IEEE International Conference on Software Engineering, pp. 292\u2013302 (2015)","DOI":"10.1109\/ICSE.2015.49"},{"key":"15_CR21","doi-asserted-by":"crossref","unstructured":"Labunets, K., Paci, F., Massacci, F.: Which security catalogue is better for novices? In: 2015 IEEE Fifth International Workshop on Empirical Requirements Engineering (EmpiRE), pp. 25\u201332 (2015)","DOI":"10.1109\/EmpiRE.2015.7431304"},{"issue":"4","key":"15_CR22","doi-asserted-by":"publisher","first-page":"2127","DOI":"10.1007\/s10664-016-9481-1","volume":"22","author":"M Riaz","year":"2016","unstructured":"Riaz, M., et al.: Identifying the implied: findings from three differentiated replications on the use of security requirements templates. Empir. Softw. Eng. 22(4), 2127\u20132178 (2016). https:\/\/doi.org\/10.1007\/s10664-016-9481-1","journal-title":"Empir. Softw. Eng."},{"key":"15_CR23","doi-asserted-by":"crossref","unstructured":"Hasan, B., Sch\u00e4fer, P., G\u00f3mez, J.M., Kurzh\u00f6fer, J.: Risk catalogue for mobile business applications. In: Proceedings of the 13th International Joint Conference on e-Business and Telecommunications, pp. 43\u201353. SCITEPRESS - Science and Technology Publications, Lda, Lisbon, Portugal (2016)","DOI":"10.5220\/0005968900430053"},{"key":"15_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102306","volume":"108","author":"C Schmitz","year":"2021","unstructured":"Schmitz, C., Schmid, M., Harborth, D., Pape, S.: Maturity level assessments of information security controls: an empirical analysis of practitioners assessment capabilities. Comput. Secur. 108, 102306 (2021)","journal-title":"Comput. Secur."},{"key":"15_CR25","doi-asserted-by":"crossref","unstructured":"Quinn, S., Ivy, N., Barrett, M., Witte, G., Gardner, R.: Identifying and estimating cybersecurity risk for enterprise risk management. Natl. Inst. Stand. Technol. NIST Spec. Publ., 1\u201352 (2021)","DOI":"10.6028\/NIST.IR.8286A"},{"key":"15_CR26","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101776","volume":"92","author":"M Brunner","year":"2020","unstructured":"Brunner, M., Sauerwein, C., Felderer, M., Breu, R.: Risk management practices in information security: exploring the status quo in the DACH region. Comput. Secur. 92, 101776 (2020)","journal-title":"Comput. Secur."},{"key":"15_CR27","unstructured":"Bergstr\u00f6m, E.: Supporting information security management: developing a method for information classification. In: School of Informatics, vol. Doctoral dissertation, p. 310. University of Sk\u00f6vde, Sk\u00f6vde, Sweden (2020)"},{"key":"15_CR28","doi-asserted-by":"crossref","unstructured":"Fibikova, L., M\u00fcller, R.: A simplified approach for classifying applications. In: Pohlmann, N.R., Helmut; Schneider, Wolfgang (ed.) ISSE 2010 Securing Electronic Business Processes, pp. 39\u201349. Vieweg+Teubner (2011)","DOI":"10.1007\/978-3-8348-9788-6_4"},{"key":"15_CR29","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1080\/10919390802421242","volume":"18","author":"J Rees","year":"2008","unstructured":"Rees, J., Allen, J.: The state of risk assessment practices in information security: an exploratory investigation. J. Organ. Comput. Electron. Commer. 18, 255\u2013277 (2008)","journal-title":"J. Organ. Comput. Electron. Commer."},{"key":"15_CR30","volume-title":"Researching Information Systems and Computing","author":"BJ Oates","year":"2006","unstructured":"Oates, B.J.: Researching Information Systems and Computing. Sage, London (2006)"},{"key":"15_CR31","unstructured":"ISO\/IEC 27005: Information technology \u2013 Security techniques \u2013 Information security risk management. ISO\/IEC (2018)"},{"key":"15_CR32","doi-asserted-by":"crossref","unstructured":"Marotta, A., Carrozza, G., Battaglia, L., Montefusco, P., Manetti, V.: Applying the SecRAM methodology in a CLOUD-based ATM environment. In: 2013 International Conference on Availability, Reliability and Security, pp. 807\u2013813 (2013)","DOI":"10.1109\/ARES.2013.108"},{"key":"15_CR33","unstructured":"SESAR 3 Joint Undertaking. https:\/\/www.sesarju.eu\/"},{"key":"15_CR34","first-page":"11","volume":"28","author":"TJ Reynolds","year":"1988","unstructured":"Reynolds, T.J., Gutman, J.: Laddering theory, method, analysis, and interpretation. J. Advert. Res. 28, 11\u201331 (1988)","journal-title":"J. Advert. Res."},{"key":"15_CR35","doi-asserted-by":"publisher","DOI":"10.1016\/j.chbr.2020.100034","volume":"2","author":"A Skalkos","year":"2020","unstructured":"Skalkos, A., Tsohou, A., Karyda, M., Kokolakis, S.: Identifying the values associated with users\u2019 behavior towards anonymity tools through means-end analysis. Comput. Hum. Behav. Rep. 2, 100034 (2020)","journal-title":"Comput. Hum. Behav. Rep."},{"key":"15_CR36","first-page":"297","volume":"9","author":"T Modesto Veludo-de-Oliveira","year":"2006","unstructured":"Modesto Veludo-de-Oliveira, T., Akemi Ikeda, A., Cortez Campomar, M.: Laddering in the practice of marketing research: barriers and solutions. J. Cetacean Res. Manag. 9, 297\u2013306 (2006)","journal-title":"J. Cetacean Res. Manag."},{"key":"15_CR37","unstructured":"Lumivero. https:\/\/lumivero.com\/products\/nvivo\/"},{"key":"15_CR38","doi-asserted-by":"crossref","unstructured":"Kaarst-Brown, M.L., Thompson, E.D.: Cracks in the security foundation: employee judgments about information sensitivity. In: Proceedings of the 2015 ACM SIGMIS Conference on Computers and People Research, pp. 145\u2013151. ACM (2015)","DOI":"10.1145\/2751957.2751977"},{"key":"15_CR39","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1108\/ICS-07-2020-0110","volume":"29","author":"E Bergstr\u00f6m","year":"2021","unstructured":"Bergstr\u00f6m, E., Karlsson, F., \u00c5hlfeldt, R.-M.: Developing an information classification method. Inf. Comput. Secur. 29, 209\u2013239 (2021)","journal-title":"Inf. Comput. Secur."}],"container-title":["IFIP Advances in Information and Communication Technology","Human Aspects of Information Security and Assurance"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-38530-8_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,25]],"date-time":"2023-07-25T20:39:54Z","timestamp":1690317594000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-38530-8_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031385292","9783031385308"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-38530-8_15","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"26 July 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"HAISA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Human Aspects of Information Security and Assurance","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Kent","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Kingdom","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 July 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 July 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"haisa2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.haisa.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"54","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"37","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"69% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.93","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}