{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T02:03:14Z","timestamp":1742954594404,"version":"3.40.3"},"publisher-location":"Cham","reference-count":41,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031541285"},{"type":"electronic","value":"9783031541292"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_1","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:15Z","timestamp":1710194595000},"page":"7-25","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["An Opportunity-Based Approach to\u00a0Information Security Risk"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5691-7641","authenticated-orcid":false,"given":"Dinh Uy","family":"Tran","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-6051-794X","authenticated-orcid":false,"given":"Sigrid Haug","family":"Selnes","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6337-2264","authenticated-orcid":false,"given":"Audun","family":"J\u00f8sang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5900-7061","authenticated-orcid":false,"given":"Janne","family":"Hagen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"issue":"2004","key":"1_CR1","first-page":"1","volume":"33","author":"B Kitchenham","year":"2004","unstructured":"Kitchenham, B.: Procedures for performing systematic reviews. Keele, UK, Keele Univ. 33(2004), 1\u201326 (2004)","journal-title":"Keele, UK, Keele Univ."},{"key":"1_CR2","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1177\/160940690600500103","volume":"5","author":"J Mills","year":"2006","unstructured":"Mills, J., Bonner, A., Francis, K.: The development of constructivist grounded theory. Int J Qual Methods 5, 25\u201335 (2006)","journal-title":"Int J Qual Methods"},{"key":"1_CR3","first-page":"15","volume":"48","author":"D Whitten","year":"2008","unstructured":"Whitten, D.: The chief information security officer: An analysis of the skills required for success. Journal Of Computer Information Systems. 48, 15\u201319 (2008)","journal-title":"Journal Of Computer Information Systems."},{"unstructured":"Information Standardization: Information security, cybersecurity and privacy protection - Information security management systems - Requirements (2022)","key":"1_CR4"},{"unstructured":"Information Standardization: Risk management - Guidelines (2018)","key":"1_CR5"},{"unstructured":"Information Standardization: Information technology - Security techniques - Information security management systems - Overview and vocabulary (2018)","key":"1_CR6"},{"unstructured":"Information Standardization: Information security, cybersecurity and privacy protection - Guidance on managing information security risks (2022)","key":"1_CR7"},{"unstructured":"Information Standardization: Quality management systems - Requirements (2015)","key":"1_CR8"},{"unstructured":"International Organization for Standardization - 0. Explanatory note and overview on ISO Survey 2021 results. https:\/\/www.iso.org\/the-iso-survey.html. Accessed 13 Jan 2023","key":"1_CR9"},{"unstructured":"Information Standardization: ISO Guide 73:2009, Risk management - Vocabulary (2009)","key":"1_CR10"},{"doi-asserted-by":"publisher","unstructured":"Technology Standardization: Technology risk management framework for information systems and organizations (2018). https:\/\/doi.org\/10.6028\/NIST.SP.800-37r2. Accessed 13 Jan 2023","key":"1_CR11","DOI":"10.6028\/NIST.SP.800-37r2"},{"unstructured":"Information Standardization: Risk management - Risk assessment techniques (2019)","key":"1_CR12"},{"unstructured":"Harris, S., Maymi, F.: CISSP All-in-One Exam Guide, 7 th edn. McGraw Hill LLC (2016)","key":"1_CR13"},{"unstructured":"Gregory, P.: CISM Certified Information Security Manager All-in-One Exam Guide. McGraw Hill LLC (2018)","key":"1_CR14"},{"unstructured":"Information Standardization: Information security, cybersecurity and privacy protection - Guidance on managing information security risks (2018)","key":"1_CR15"},{"key":"1_CR16","doi-asserted-by":"publisher","first-page":"2285","DOI":"10.1007\/s10270-018-0661-x","volume":"18","author":"N Mayer","year":"2019","unstructured":"Mayer, N., Aubert, J., Grandry, E., Feltus, C., Goettelmann, E., Wieringa, R.: An integrated conceptual model for information system security risk management supported by enterprise architecture management. Softw. Syst. Model. 18, 2285\u20132312 (2019)","journal-title":"Softw. Syst. Model."},{"key":"1_CR17","doi-asserted-by":"publisher","first-page":"358","DOI":"10.1108\/ICS-09-2018-0106","volume":"27","author":"E Bergstr\u00f6m","year":"2019","unstructured":"Bergstr\u00f6m, E., Lundgren, M., Ericson, A.: Revisiting information security risk management challenges: a practice perspective. Inform. Comput. Secur. 27, 358\u2013372 (2019)","journal-title":"Inform. Comput. Secur."},{"doi-asserted-by":"crossref","unstructured":"Diefenbach, T., Lucke, C., Lechner, U.: Towards an integration of information security management, risk management and enterprise architecture management-a literature review. In: 2019 IEEE International Conference on Cloud Computing Technology and Science (CloudCom), pp. 326\u2013333 (2019)","key":"1_CR18","DOI":"10.1109\/CloudCom.2019.00057"},{"doi-asserted-by":"crossref","unstructured":"Abbass, W., Baina, A., Bellafkih, M.: Improvement of information system security risk management. In: 2016 4th IEEE International Colloquium on Information Science and Technology (CiSt), pp. 182\u2013187 (2016)","key":"1_CR19","DOI":"10.1109\/CIST.2016.7805039"},{"key":"1_CR20","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1108\/IMCS-07-2013-0053","volume":"22","author":"S Fenz","year":"2014","unstructured":"Fenz, S., Heurix, J., Neubauer, T., Pechstein, F.: Current challenges in information security risk management. Inform. Manage. Comput. Secur. 22, 410\u2013430 (2014)","journal-title":"Inform. Manage. Comput. Secur."},{"doi-asserted-by":"crossref","unstructured":"Tran, D., J\u00f8sang, A.: Information security posture to organize and communicate the information security governance program. In: Proceedings of the 18th European Conference on Management Leadership and Governance, ECMLG 2022, vol. 18, pp. 515\u2013522 (2022)","key":"1_CR21","DOI":"10.34190\/ecmlg.18.1.729"},{"doi-asserted-by":"crossref","unstructured":"Aleksandrov, M., Vasiliev, V., Aleksandrova, S.: Implementation of the risk-based approach methodology in information security management systems. In: 2021 International Conference on Quality Management, Transport and Information Security, Information Technologies (IT &QM &IS), pp. 137\u2013139 (2021)","key":"1_CR22","DOI":"10.1109\/ITQMIS53292.2021.9642767"},{"key":"1_CR23","first-page":"1","volume":"36","author":"P Shamala","year":"2017","unstructured":"Shamala, P., Ahmad, R., Zolait, A., Sedek, M.: Integrating information quality dimensions into information security risk management (ISRM). J. Inform. Secur. Appl. 36, 1\u201310 (2017)","journal-title":"J. Inform. Secur. Appl."},{"key":"1_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cose.2014.04.005","volume":"44","author":"J Webb","year":"2014","unstructured":"Webb, J., Ahmad, A., Maynard, S., Shanks, G.: A situation awareness model for information security risk management. Comput. Security. 44, 1\u201315 (2014)","journal-title":"Comput. Security."},{"key":"1_CR25","doi-asserted-by":"publisher","first-page":"715","DOI":"10.1007\/s10207-019-00433-2","volume":"18","author":"R Riesco","year":"2019","unstructured":"Riesco, R., Villagr\u00e1, V.: Leveraging cyber threat intelligence for a dynamic risk framework. Int. J. Inf. Secur. 18, 715\u2013739 (2019)","journal-title":"Int. J. Inf. Secur."},{"doi-asserted-by":"crossref","unstructured":"Putra, I., Mutijarsa, K.: Designing information security risk management on bali regional police command center based on ISO 27005. In: 2021 3rd East Indonesia Conference on Computer and Information Technology (EIConCIT), pp. 14\u201319 (2021)","key":"1_CR26","DOI":"10.1109\/EIConCIT50028.2021.9431865"},{"key":"1_CR27","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1080\/07366981.2013.775792","volume":"47","author":"C Le Grand","year":"2013","unstructured":"Le Grand, C.: Positive security, risk management, and compliance. EDPACS 47, 1\u201310 (2013)","journal-title":"EDPACS"},{"doi-asserted-by":"crossref","unstructured":"Rajbhandari, L.: Consideration of opportunity and human factor: required paradigm shift for information security risk management. In: 2013 European Intelligence and Security Informatics Conference, pp. 147\u2013150 (2013)","key":"1_CR28","DOI":"10.1109\/EISIC.2013.32"},{"key":"1_CR29","doi-asserted-by":"publisher","first-page":"745","DOI":"10.1016\/j.ijproman.2007.03.005","volume":"25","author":"R Olsson","year":"2007","unstructured":"Olsson, R.: In search of opportunity management: is the risk management process enough? Int. J. Project Manage. 25, 745\u2013752 (2007)","journal-title":"Int. J. Project Manage."},{"key":"1_CR30","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1016\/S0263-7863(01)00074-6","volume":"20","author":"D Hillson","year":"2002","unstructured":"Hillson, D.: Extending the risk process to manage opportunities. Int. J. Project Manage. 20, 235\u2013240 (2002)","journal-title":"Int. J. Project Manage."},{"key":"1_CR31","first-page":"77","volume":"49","author":"L Ivascu","year":"2014","unstructured":"Ivascu, L., Cioca, L.: Opportunity risk: integrated approach to risk management for creating enterprise opportunities. Adv. Educ. Res. 49, 77\u201380 (2014)","journal-title":"Adv. Educ. Res."},{"key":"1_CR32","doi-asserted-by":"publisher","first-page":"881","DOI":"10.1111\/j.1539-6924.2010.01442.x","volume":"30","author":"G Purdy","year":"2010","unstructured":"Purdy, G.: ISO 31000: 2009-setting a new standard for risk management. Risk Anal. An Int. J. 30, 881\u2013886 (2010)","journal-title":"Risk Anal. An Int. J."},{"key":"1_CR33","doi-asserted-by":"publisher","first-page":"719","DOI":"10.1016\/j.ress.2010.12.020","volume":"96","author":"T Aven","year":"2011","unstructured":"Aven, T.: On the new ISO guide on risk management terminology. Reliab. Eng. Syst. Saf. 96, 719\u2013726 (2011)","journal-title":"Reliab. Eng. Syst. Saf."},{"unstructured":"Wangen, G., Snekkenes, E.: A taxonomy of challenges in information security risk management. In: Proceeding of Norwegian Information Security Conference\/Norsk Informasjonssikkerhetskonferanse-NISK 2013-Stavanger, 18th-20th November 2013 (2013)","key":"1_CR34"},{"key":"1_CR35","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1080\/1366987042000192435","volume":"8","author":"R Lion","year":"2005","unstructured":"Lion, R., Meertens, R.: Security or opportunity: the influence of risk-taking tendency on risk information preference. J. Risk Res. 8, 283\u2013294 (2005)","journal-title":"J. Risk Res."},{"unstructured":"Axelos. ITIL Foundation, ITIL (ITIL 4 Foundation). The Stationery Office (2020)","key":"1_CR36"},{"unstructured":"Measuring and Managing Information Risk: A FAIR Approach. Butterworth-Heinemann (2014)","key":"1_CR37"},{"key":"1_CR38","doi-asserted-by":"publisher","first-page":"205031211882292","DOI":"10.1177\/2050312118822927","volume":"7","author":"Y Chun Tie","year":"2019","unstructured":"Chun Tie, Y., Birks, M., Francis, K.: Grounded theory research: a design framework for novice researchers. SAGE Open Med. 7, 2050312118822927 (2019)","journal-title":"SAGE Open Med."},{"doi-asserted-by":"crossref","unstructured":"Stol, K., Ralph, P., Fitzgerald, B.: Grounded theory in software engineering research: a critical review and guidelines. In: Proceedings of The 38th International Conference on Software Engineering, pp. 120\u2013131 (2016)","key":"1_CR39","DOI":"10.1145\/2884781.2884833"},{"key":"1_CR40","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1057\/ejis.2012.48","volume":"22","author":"D Birks","year":"2013","unstructured":"Birks, D., Fernandez, W., Levina, N., Nasirin, S.: Grounded theory method in information systems research: its nature, diversity and opportunities. Eur. J. Inf. Syst. 22, 1\u20138 (2013)","journal-title":"Eur. J. Inf. Syst."},{"doi-asserted-by":"crossref","unstructured":"Tran, D., J\u00f8sang, A.: Business language for information security. In: International Symposium on Human Aspects of Information Security and Assurance, pp. 169\u2013180 (2023)","key":"1_CR41","DOI":"10.1007\/978-3-031-38530-8_14"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:37Z","timestamp":1710194617000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}