{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T15:36:11Z","timestamp":1742916971856,"version":"3.40.3"},"publisher-location":"Cham","reference-count":36,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031423062"},{"type":"electronic","value":"9783031423079"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-42307-9_4","type":"book-chapter","created":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T04:03:15Z","timestamp":1693281795000},"page":"47-58","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Towards a DevSecOps-Enabled Framework for Risk Management of Critical Infrastructures"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8060-5672","authenticated-orcid":false,"given":"Xhesika","family":"Ramaj","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1555-9726","authenticated-orcid":false,"given":"Ricardo","family":"Colomo-Palacios","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5102-1122","authenticated-orcid":false,"given":"Mary","family":"S\u00e1nchez-Gord\u00f3n","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vasileios","family":"Gkioulos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,8,30]]},"reference":[{"key":"4_CR1","unstructured":"European Commission: Communication from the Commission to the Council and the European Parliament - Critical Infrastructure Protection in the fight against terrorism. https:\/\/eur-lex.europa.eu\/legal-content\/GA\/TXT\/?uri=CELEX:52004DC0702"},{"key":"4_CR2","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1016\/j.ijcip.2016.06.002","volume":"14","author":"D Rehak","year":"2016","unstructured":"Rehak, D., Markuci, J., Hromada, M., Barcova, K.: Quantitative evaluation of the synergistic effects of failures in a critical infrastructure system. Int. J. Crit. Infrastruct. Prot. 14, 3\u201317 (2016). https:\/\/doi.org\/10.1016\/j.ijcip.2016.06.002","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"4_CR3","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1145\/3573074.3573095","volume":"48","author":"C Esnoul","year":"2023","unstructured":"Esnoul, C., Colomo-Palacios, R., Jee, E., Chockalingam, S., Eidar Simensen, J., Bae, D.-H.: Report on the 3rd international workshop on engineering and cybersecurity of critical systems (EnCyCriS - 2022). SIGSOFT Softw. Eng. Notes. 48, 81\u201384 (2023). https:\/\/doi.org\/10.1145\/3573074.3573095","journal-title":"SIGSOFT Softw. Eng. Notes."},{"key":"4_CR4","unstructured":"The European Programme for Critical Infrastructure Protection (EPCIP). https:\/\/home-affairs.ec.europa.eu\/pages\/page\/critical-infrastructure_en"},{"key":"4_CR5","unstructured":"Critical Infrastructure Sectors | CISA. https:\/\/www.cisa.gov\/topics\/critical-infrastructure-security-and-resilience\/critical-infrastructure-sectors"},{"key":"4_CR6","doi-asserted-by":"publisher","DOI":"10.1201\/9781315310657","volume-title":"Critical Infrastructure Protection, Risk Management, and Resilience: A Policy Perspective","author":"K Presch-Cronin","year":"2016","unstructured":"Presch-Cronin, K., Marion, N.E.: Critical Infrastructure Protection, Risk Management, and Resilience: A Policy Perspective. CRC Press, Boca Raton (2016)"},{"key":"4_CR7","doi-asserted-by":"publisher","DOI":"10.1016\/j.techsoc.2021.101809","volume":"68","author":"AH Khan Babar","year":"2022","unstructured":"Khan Babar, A.H., Ali, Y.: Framework construction for augmentation of resilience in critical infrastructure: developing countries a case in point. Technol. Soc. 68, 101809 (2022). https:\/\/doi.org\/10.1016\/j.techsoc.2021.101809","journal-title":"Technol. Soc."},{"key":"4_CR8","unstructured":"A Guide to Critical Infrastructure Security and Resilience. https:\/\/www.cisa.gov\/search"},{"key":"4_CR9","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijdrr.2020.101575","volume":"48","author":"G Quitana","year":"2020","unstructured":"Quitana, G., Molinos-Senante, M., Chamorro, A.: Resilience of critical infrastructure to natural hazards: a review focused on drinking water systems. Int. J. Disaster Risk Reduction 48, 101575 (2020). https:\/\/doi.org\/10.1016\/j.ijdrr.2020.101575","journal-title":"Int. J. Disaster Risk Reduction"},{"key":"4_CR10","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1109\/MITP.2020.2966614","volume":"22","author":"MR Fox","year":"2020","unstructured":"Fox, M.R.: IT Governance in a DevOps World. IT Prof. 22, 54\u201361 (2020). https:\/\/doi.org\/10.1109\/MITP.2020.2966614","journal-title":"IT Prof."},{"key":"4_CR11","doi-asserted-by":"publisher","first-page":"3707","DOI":"10.3390\/electronics11223707","volume":"11","author":"X Ramaj","year":"2022","unstructured":"Ramaj, X., S\u00e1nchez-Gord\u00f3n, M., Gkioulos, V., Chockalingam, S., Colomo-Palacios, R.: Holding on to compliance while adopting DevSecOps: an SLR. Electronics 11, 3707 (2022). https:\/\/doi.org\/10.3390\/electronics11223707","journal-title":"Electronics"},{"key":"4_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"590","DOI":"10.1007\/978-3-319-49094-6_44","volume-title":"Product-Focused Software Process Improvement","author":"L Riungu-Kalliosaari","year":"2016","unstructured":"Riungu-Kalliosaari, L., M\u00e4kinen, S., Lwakatare, L.E., Tiihonen, J., M\u00e4nnist\u00f6, T.: DevOps adoption benefits and challenges in practice: a case study. In: Abrahamsson, P., Jedlitschka, A., Nguyen Duc, A., Felderer, M., Amasaki, S., Mikkonen, T. (eds.) PROFES 2016. LNCS, vol. 10027, pp. 590\u2013597. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-49094-6_44"},{"key":"4_CR13","doi-asserted-by":"crossref","unstructured":"Carturan, S.B.O.G., Goya, D.H.: A systems-of-systems security framework for requirements definition in cloud environment. In: Proceedings of the 13th European Conference on Software Architecture, vol. 2, pp. 235\u2013240. Association for Computing Machinery, New York, NY, USA (2019)","DOI":"10.1145\/3344948.3344977"},{"key":"4_CR14","unstructured":"ISO - ISO 31000 \u2014 Risk management. https:\/\/www.iso.org\/iso-31000-risk-management.html"},{"key":"4_CR15","unstructured":"Computer Security Division, I.T.L.: NIST Risk Management Framework. https:\/\/csrc.nist.gov\/Projects\/risk-management"},{"key":"4_CR16","unstructured":"NIST Cybersecurity Framework. NIST (2013)"},{"key":"4_CR17","unstructured":"Compliance Risk Management Applying the COSO ERM Framework. https:\/\/www.coso.org\/Shared%20Documents\/Compliance-Risk-Management-Applying-the-COSO-ERM-Framework.pdf"},{"key":"4_CR18","unstructured":"1nstitute, F.: The Importance and Effectiveness of Quantifying Cyber Risk. https:\/\/www.fairinstitute.org\/fair-risk-management"},{"key":"4_CR19","unstructured":"Project Management Institute ed: PMI Risk Management Framework. Project Management Institute, Newtown Square, Pa (2009)"},{"key":"4_CR20","unstructured":"The Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE). https:\/\/www.enisa.europa.eu\/topics\/risk-management\/current-risk\/risk-management-inventory\/rm-ra-methods\/m_octave.html"},{"key":"4_CR21","unstructured":"The CCTA Risk Analysis and Management Method (CRAMM). https:\/\/www.enisa.europa.eu\/topics\/risk-management\/current-risk\/risk-management-inventory\/rm-ra-methods\/m_cramm.html"},{"key":"4_CR22","doi-asserted-by":"publisher","unstructured":"Forsgren, N., Kersten, M.: DevOps metrics. Queue. 15 (2017). https:\/\/doi.org\/10.1145\/3159169","DOI":"10.1145\/3159169"},{"key":"4_CR23","doi-asserted-by":"publisher","DOI":"10.1016\/j.accinf.2022.100560","volume":"45","author":"OH Plant","year":"2022","unstructured":"Plant, O.H., van Hillegersberg, J., Aldea, A.: Rethinking IT governance: designing a framework for mitigating risk and fostering internal control in a DevOps environment. Int. J. Account. Inf. Syst. 45, 100560 (2022). https:\/\/doi.org\/10.1016\/j.accinf.2022.100560","journal-title":"Int. J. Account. Inf. Syst."},{"key":"4_CR24","doi-asserted-by":"crossref","unstructured":"Aljohani, M.A., Alqahtani, S.S.: A unified framework for automating software security analysis in DevSecOps. In: 2023 International Conference on Smart Computing and Application (ICSCA), pp. 1\u20136 (2023)","DOI":"10.1109\/ICSCA57840.2023.10087568"},{"key":"4_CR25","doi-asserted-by":"crossref","unstructured":"Yasar, H.: Implementing Secure DevOps assessment for highly regulated environments. In: Proceedings of the 12th International Conference on Availability, Reliability and Security, pp. 1\u20133. Association for Computing Machinery, New York, NY, USA (2017)","DOI":"10.1145\/3098954.3105819"},{"key":"4_CR26","doi-asserted-by":"publisher","first-page":"105426","DOI":"10.1109\/ACCESS.2020.2998819","volume":"8","author":"S Rafi","year":"2020","unstructured":"Rafi, S., Yu, W., Akbar, M.A., Alsanad, A., Gumaei, A.: Prioritization based taxonomy of DevOps security challenges using PROMETHEE. IEEE Access 8, 105426\u2013105446 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.2998819","journal-title":"IEEE Access"},{"key":"4_CR27","unstructured":"Woody, C.: DevSecOps pipeline for complex software-intensive systems: addressing cybersecurity challenges (2020)"},{"key":"4_CR28","unstructured":"State of DevOps Report 2021 | Puppet by Perforce. https:\/\/www.puppet.com\/resources\/state-of-devops-report"},{"key":"4_CR29","unstructured":"State of Devops Report 2017 (2017)"},{"key":"4_CR30","doi-asserted-by":"crossref","unstructured":"Senapathi, M., Buchan, J., Osman, H.: DevOps capabilities, practices, and challenges: insights from a case study. In: Proceedings of the 22nd International Conference on Evaluation and Assessment in Software Engineering 2018, pp. 57\u201367. ACM, Christchurch New Zealand (2018)","DOI":"10.1145\/3210459.3210465"},{"key":"4_CR31","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1016\/j.infsof.2019.06.010","volume":"114","author":"LE Lwakatare","year":"2019","unstructured":"Lwakatare, L.E., et al.: DevOps in practice: a multiple case study of five companies. Inf. Softw. Technol. 114, 217\u2013230 (2019). https:\/\/doi.org\/10.1016\/j.infsof.2019.06.010","journal-title":"Inf. Softw. Technol."},{"key":"4_CR32","doi-asserted-by":"publisher","first-page":"711","DOI":"10.1002\/smr.1560","volume":"25","author":"M Khurum","year":"2013","unstructured":"Khurum, M., Gorschek, T., Wilson, M.: The software value map \u2014 an exhaustive collection of value aspects for the development of software intensive products. J. Softw. Evol. Process 25, 711\u2013741 (2013). https:\/\/doi.org\/10.1002\/smr.1560","journal-title":"J. Softw. Evol. Process"},{"key":"4_CR33","doi-asserted-by":"crossref","unstructured":"Ramaj, X., S\u00e1nchez-Gord\u00f3n, M., Chockalingam, S., Colomo-Palacios, R.: Unveiling the safety aspects of DevSecOps: evolution, gaps and trends. Recent Adv. Comput. Sci. Commun. 16, 61\u201369 (2023)","DOI":"10.2174\/2666255816666220804143918"},{"key":"4_CR34","unstructured":"DevOpsSec: Creating the Agile Triangle. https:\/\/www.gartner.com\/en\/documents\/1896617"},{"key":"4_CR35","doi-asserted-by":"publisher","first-page":"10695","DOI":"10.1109\/JIOT.2020.3012763","volume":"7","author":"MA L\u00f3pez-Pe\u00f1a","year":"2020","unstructured":"L\u00f3pez-Pe\u00f1a, M.A., D\u00edaz, J., P\u00e9rez, J.E., Humanes, H.: DevOps for IoT systems: fast and continuous monitoring feedback of system availability. IEEE Internet Things J. 7, 10695\u201310707 (2020). https:\/\/doi.org\/10.1109\/JIOT.2020.3012763","journal-title":"IEEE Internet Things J."},{"key":"4_CR36","doi-asserted-by":"crossref","unstructured":"Fenton, N., Bieman, J.: Software Metrics: A Rigorous and Practical Approach, 3rd edn. CRC Press (2014)","DOI":"10.1201\/b17461"}],"container-title":["Communications in Computer and Information Science","Systems, Software and Services Process Improvement"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-42307-9_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T04:04:14Z","timestamp":1693281854000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-42307-9_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031423062","9783031423079"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-42307-9_4","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"30 August 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EuroSPI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Software Process Improvement","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Grenoble","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 August 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurospi2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/conference.eurospi.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Open","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"conference website","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"100","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"47","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"47% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}