{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T11:43:54Z","timestamp":1742989434773,"version":"3.40.3"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031431258"},{"type":"electronic","value":"9783031431265"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-43126-5_15","type":"book-chapter","created":{"date-parts":[[2023,9,9]],"date-time":"2023-09-09T02:01:44Z","timestamp":1694224904000},"page":"199-213","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Improving IT Governance, Security and Privacy Using Fractal Enterprise Modeling: A Case of a Highly Regulated Company"],"prefix":"10.1007","author":[{"given":"Steven","family":"Leego","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ilia","family":"Bider","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,9,10]]},"reference":[{"key":"15_CR1","unstructured":"AXELOS. ITIL foundation, ITIL 4 edition. TSO The Stationery Office (2019)"},{"key":"15_CR2","unstructured":"ISO. ISO\/IEC 27001:2013 Information technology - Information technology - Security techniques - Information security management systems - Requirements (2013)"},{"key":"15_CR3","unstructured":"European Union. General Data Protection Regulation, Regulation (EU) 2016\/679 (2016). https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj. Accessed 16 July 2023"},{"key":"15_CR4","unstructured":"IIBA, BABOK v3 A Guide to the Business Analysis Body of Knowledge (2015)"},{"key":"15_CR5","doi-asserted-by":"publisher","first-page":"663","DOI":"10.1007\/s10270-016-0554-9","volume":"16","author":"I Bider","year":"2017","unstructured":"Bider, I., Perjons, E., Elias, M., et al.: A fractal enterprise model and its application for business development. Softw. Syst. Model. 16, 663\u2013689 (2017)","journal-title":"Softw. Syst. Model."},{"key":"15_CR6","doi-asserted-by":"crossref","unstructured":"Leego, S., Bider, I.: Using fractal enterprise model in technology-driven organisational change projects: a case of a water utility company. In: 2021 IEEE 23rd Conference on Business Informatics (CBI), pp. 107\u2013116 (2021)","DOI":"10.1109\/CBI52690.2021.10061"},{"key":"15_CR7","doi-asserted-by":"crossref","unstructured":"Bider, I., Lodhi, A.: Moving from Manufacturing to Software Business: A Business Model Transformation Pattern (2020)","DOI":"10.1007\/978-3-030-40783-4_25"},{"key":"15_CR8","doi-asserted-by":"crossref","unstructured":"Henkel, M., Koutsopoulos, G., Bider, I., Perjons, E.: Using the Fractal Enterprise Model for Inter-organizational Business Processes (2019)","DOI":"10.1007\/978-3-030-30429-4_21"},{"key":"15_CR9","unstructured":"ISACA. COBIT 2019 Framework: Introduction and Methodology (2018)"},{"key":"15_CR10","unstructured":"ISACA. COBIT 2019 Framework: Governance and Management Objectives (2018)"},{"key":"15_CR11","unstructured":"ISO. ISO\/IEC 27000:2018 Information technology \u2013 Security techniques \u2013 Information security management systems \u2013 Overview and vocabulary (2018)"},{"key":"15_CR12","unstructured":"ISO. ISO\/IEC 27002:2013 Information technology \u2013 Security techniques \u2013 Code of practice for information security controls (2013)"},{"key":"15_CR13","unstructured":"Center for Internet Security. CIS Controls Version 8 (2021)"},{"key":"15_CR14","unstructured":"FEM toolkit. www.fractalmodel.org\/fem-toolkit\/. Accessed 16 July 2023"},{"key":"15_CR15","unstructured":"ADOxx.org, ADOxx. https:\/\/www.adoxx.org. Accessed 16 July 2023"},{"key":"15_CR16","unstructured":"The Open Group. ArchiMate\u00ae 3.1 Specification (2019). https:\/\/pubs.opengroup.org\/architecture\/archimate3-doc\/. Accessed 16 July 2023"},{"key":"15_CR17","unstructured":"FEM website. www.fractalmodel.org\/. Accessed 16 July 2023"},{"key":"15_CR18","doi-asserted-by":"publisher","unstructured":"Bider, I., Johannesson, P., Perjons, E.: Design science research as movement between individual and generic situation-problem-solution spaces. In: Baskerville, R., De Marco, M., Spagnoletti, P. (eds.) Designing Organizational Systems. An Interdisciplinary Discourse, pp. 35\u201361. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-33371-2_3","DOI":"10.1007\/978-3-642-33371-2_3"},{"issue":"1","key":"15_CR19","doi-asserted-by":"publisher","first-page":"75","DOI":"10.2307\/25148625","volume":"28","author":"AR Hevner","year":"2004","unstructured":"Hevner, A.R., March, S.T., Park, J., Ram, S.: Design science in information systems research. MIS Q. 28(1), 75\u2013105 (2004)","journal-title":"MIS Q."},{"issue":"1","key":"15_CR20","doi-asserted-by":"publisher","first-page":"37","DOI":"10.2307\/23043488","volume":"35","author":"M Sein","year":"2011","unstructured":"Sein, M., Henfridsson, O., Purao, S., Rossi, M., Lindgren, R.: Action design research. MIS Q. 35(1), 37\u201356 (2011). https:\/\/doi.org\/10.2307\/23043488","journal-title":"MIS Q."},{"key":"15_CR21","unstructured":"OMG, Unified Modeling Language (UML), Version 2.5.1. https:\/\/www.omg.org\/spec\/UML\/. Accessed 16 July 2023"},{"key":"15_CR22","unstructured":"Gregor, S., Hevner, A.: Positioning and Presenting Design Science Research for Maximum Impact, White Paper submitted for publication (2011)"},{"key":"15_CR23","unstructured":"Soldatos, J. (ed.): Security Risk Management for the Internet of Things (2020)"},{"key":"15_CR24","doi-asserted-by":"crossref","unstructured":"Tsohou, A., et al.: Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platform (2020)","DOI":"10.1007\/978-3-030-42048-2_14"},{"key":"15_CR25","doi-asserted-by":"crossref","unstructured":"Gehrmann, M.: Combining ITIL, COBIT and ISO\/IEC 27002 for structuring comprehensive information technology for management in organizations. Navus: Revista de Gest\u00e3o e Tecnologia 2, 66\u201377 (2012)","DOI":"10.22279\/navus.2012.v2n2.p66-77.77"},{"key":"15_CR26","doi-asserted-by":"crossref","unstructured":"Sheikhpour, R., Modiri, N.: A best practice approach for integration of ITIL and ISO\/IEC 27001 services for information security management. Indian J. Sci. Technol. 5, 2170\u20132176 (2012)","DOI":"10.17485\/ijst\/2012\/v5i3.1"},{"key":"15_CR27","doi-asserted-by":"crossref","unstructured":"Al Faruq, B., Herlianto, H., Simbolon, S., Utama, D., Wibowo, A.: Integration of ITIL V3, ISO 20000 & ISO 27001: 2013 for IT services and security management system. Int. J. Adv. Trends Comput. Sci. Eng. (2020)","DOI":"10.30534\/ijatcse\/2020\/157932020"},{"key":"15_CR28","unstructured":"Models at Work website. www.models-at-work.org. Accessed 16 July 2023"},{"key":"15_CR29","first-page":"57","volume-title":"Workplace Learning: Debating Five Critical Questions of Theory and Practice","author":"V Mott","year":"1996","unstructured":"Mott, V.: Knowledge comes from practice: reflective theory building in practice. In: Rowden, R.W. (ed.) Workplace Learning: Debating Five Critical Questions of Theory and Practice, pp. 57\u201363. Jossey-Bass, San Francisco (1996)"},{"key":"15_CR30","unstructured":"European Union. Proposal for a regulation of the European Parliament and of the Council on digital operational resilience for the financial sector. COM\/2020\/595 final (2020). https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:52020PC0595. Accessed 16 July 2023"},{"key":"15_CR31","unstructured":"European Banking Authority. Final report on guidelines on ICT and security risk management (2019). https:\/\/www.eba.europa.eu\/regulation-and-policy\/internal-governance\/guidelines-on-ict-and-security-risk-management. Accessed 16 July 2023"},{"key":"15_CR32","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-56509-4","volume-title":"Fundamentals of Business Process Management","author":"M Dumas","year":"2018","unstructured":"Dumas, M., La Rosa, M., Mendling, J., Reijers, H.A.: Fundamentals of Business Process Management. Springer, Heidelberg (2018). https:\/\/doi.org\/10.1007\/978-3-662-56509-4"}],"container-title":["Lecture Notes in Business Information Processing","Perspectives in Business Informatics Research"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-43126-5_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,10,29]],"date-time":"2023-10-29T12:05:50Z","timestamp":1698581150000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-43126-5_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031431258","9783031431265"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-43126-5_15","relation":{},"ISSN":["1865-1348","1865-1356"],"issn-type":[{"type":"print","value":"1865-1348"},{"type":"electronic","value":"1865-1356"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"10 September 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"BIR","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Business Informatics Research","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ascoli Piceno","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"bir2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/bir2023.unicam.it","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"57","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"20","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.77","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}