{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T12:48:56Z","timestamp":1783428536472,"version":"3.54.6"},"publisher-location":"Cham","reference-count":20,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031541285","type":"print"},{"value":"9783031541292","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_2","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:15Z","timestamp":1710194595000},"page":"26-41","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["A Methodology for\u00a0Cybersecurity Risk Assessment in\u00a0Supply Chains"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-3632-9768","authenticated-orcid":false,"given":"Betul","family":"Gokkaya","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2886-8445","authenticated-orcid":false,"given":"Leonardo","family":"Aniello","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8250-4389","authenticated-orcid":false,"given":"Erisa","family":"Karafili","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3470-7226","authenticated-orcid":false,"given":"Basel","family":"Halak","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"key":"2_CR1","doi-asserted-by":"publisher","first-page":"767","DOI":"10.1109\/TIFS.2019.2928493","volume":"15","author":"Y Zhang","year":"2019","unstructured":"Zhang, Y., Guin, U.: End-to-end traceability of ICs in component supply chain for fighting against recycling. IEEE Trans. Inf. Forensics Secur. 15, 767\u2013775 (2019)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"2_CR2","doi-asserted-by":"crossref","unstructured":"Alkhadra, R., Abuzaid, J., AlShammari, M., Mohammad, N.: Solar winds hack: in-depth analysis and countermeasures. In: 2021 12th International Conference on Computing Communication and Networking Technologies (ICCCNT), pp. 1\u20137. IEEE (2021)","DOI":"10.1109\/ICCCNT51525.2021.9579611"},{"issue":"4","key":"2_CR3","doi-asserted-by":"publisher","first-page":"2081","DOI":"10.9770\/jesi.2019.6.4(37)","volume":"6","author":"A Klju\u010dnikov","year":"2019","unstructured":"Klju\u010dnikov, A., Mura, L., Sklen\u00e1r, D.: Information security management in SMEs: factors of success. Entrepreneurship Sustain. Issues 6(4), 2081 (2019)","journal-title":"Entrepreneurship Sustain. Issues"},{"issue":"3","key":"2_CR4","doi-asserted-by":"publisher","first-page":"186","DOI":"10.4067\/S0718-27242013000400017","volume":"8","author":"C Verbano","year":"2013","unstructured":"Verbano, C., Venturini, K.: Managing risks in SMEs: a literature review and research agenda. J. Technol. Manage. Innov. 8(3), 186\u2013197 (2013)","journal-title":"J. Technol. Manage. Innov."},{"key":"2_CR5","doi-asserted-by":"crossref","unstructured":"Bel\u00e1s, J., Mach\u00e1\u010dek, J., Barto\u0161, P., Hlawiczka, R., Hud\u00e1kov\u00e1, M.: Business risks and the level of entrepreneurial optimism among SME in the Czech and Slovak Republic. J. competitiveness. Tomas Bata University in Zl\u00edn (2014)","DOI":"10.7441\/joc.2014.02.03"},{"key":"2_CR6","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s12198-018-0195-z","volume":"12","author":"S Schauer","year":"2019","unstructured":"Schauer, S., Polemi, N., Mouratidis, H.: MITIGATE: a dynamic supply chain cyber risk assessment methodology. J. Transp. Secur. 12, 1\u201335 (2019)","journal-title":"J. Transp. Secur."},{"key":"2_CR7","doi-asserted-by":"crossref","unstructured":"Kieras, T., Farooq, M.J., Zhu, Q.: RIoTS: Risk analysis of IoT supply chain threats. In: 2020 IEEE 6th World Forum on Internet of Things (WF-IoT), pp. 1\u20136. IEEE (2020)","DOI":"10.1109\/WF-IoT48130.2020.9221323"},{"key":"2_CR8","doi-asserted-by":"publisher","first-page":"109","DOI":"10.1016\/j.eswa.2015.08.028","volume":"43","author":"F Aqlan","year":"2016","unstructured":"Aqlan, F.: A software application for rapid risk assessment in integrated supply chains. Expert Syst. Appl. 43, 109\u2013116 (2016)","journal-title":"Expert Syst. Appl."},{"issue":"6","key":"2_CR9","doi-asserted-by":"publisher","first-page":"677","DOI":"10.1108\/17410390710830727","volume":"20","author":"MN Faisal","year":"2007","unstructured":"Faisal, M.N., Kumar, D.K.B., Shankar, R.: Information risks management in supply chains: an assessment and mitigation framework. J. Enterp. Inf. Manag. 20(6), 677\u2013699 (2007)","journal-title":"J. Enterp. Inf. Manag."},{"issue":"2","key":"2_CR10","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1108\/JEIM-03-2014-0031","volume":"29","author":"S Sharma","year":"2016","unstructured":"Sharma, S., Routroy, S.: Modeling information risk in supply chain using Bayesian networks. J. Enterp. Inf. Manag. 29(2), 238\u2013254 (2016)","journal-title":"J. Enterp. Inf. Manag."},{"issue":"1","key":"2_CR11","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1108\/SCM-02-2020-0073","volume":"27","author":"A Creazza","year":"2022","unstructured":"Creazza, A., Colicchia, C., Spiezia, S., Dallari, F.: Who cares? Supply chain managers\u2019 perceptions regarding cyber supply chain risk management in the digital transformation era. Supply Chain Manage. An Int. J. 27(1), 30\u201353 (2022)","journal-title":"Supply Chain Manage. An Int. J."},{"issue":"1\u20132","key":"2_CR12","first-page":"1","volume":"28","author":"S Garg","year":"2019","unstructured":"Garg, S., Singh, R.K., Mohapatra, A.K.: Analysis of software vulnerability classification based on different technical parameters. Inform. Secur. J. Glob. Perspect. 28(1\u20132), 1\u201319 (2019)","journal-title":"Inform. Secur. J. Glob. Perspect."},{"issue":"1","key":"2_CR13","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1111\/risa.12891","volume":"40","author":"AA Ganin","year":"2020","unstructured":"Ganin, A.A., Quach, P., Panwar, M., Collier, Z.A., Keisler, J.M., Marchese, D., Linkov, I.: Multicriteria decision framework for cybersecurity risk assessment and management. Risk Anal. 40(1), 183\u2013199 (2020)","journal-title":"Risk Anal."},{"key":"2_CR14","doi-asserted-by":"publisher","first-page":"121858","DOI":"10.1109\/ACCESS.2020.3006361","volume":"8","author":"X Zhang","year":"2020","unstructured":"Zhang, X., Xie, H., Yang, H., Shao, H., Zhu, M.: A general framework to understand vulnerabilities in information systems. IEEE Access 8, 121858\u2013121873 (2020)","journal-title":"IEEE Access"},{"key":"2_CR15","unstructured":"Cruz, S.T.: Information security risk assessment. In: Information Security Management Handbook, pp. 243\u2013250 (2007)"},{"issue":"March","key":"2_CR16","first-page":"284","volume":"283","author":"A Rot","year":"2008","unstructured":"Rot, A.: IT risk assessment: quantitative and qualitative approach. Resource 283(March), 284 (2008)","journal-title":"Resource"},{"key":"2_CR17","unstructured":"Nemoto, T., Beglar, D.: Likert-scale questionnaires. In: JALT 2013 Conference Proceedings, pp. 1\u20138 (2014)"},{"key":"2_CR18","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101609","volume":"88","author":"PT Figueira","year":"2020","unstructured":"Figueira, P.T., Bravo, C.L., L\u00f3pez, J.L.R.: Improving information security risk analysis by including threat-occurrence predictive models. Comput. Secur. 88, 101609 (2020)","journal-title":"Comput. Secur."},{"key":"2_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/978-3-030-70881-8_4","volume-title":"Foundations and Practice of Security","author":"R Khoury","year":"2021","unstructured":"Khoury, R., Vignau, B., Hall\u00e9, S., Hamou-Lhadj, A., Razgallah, A.: An analysis of the use of CVEs by IoT malware. In: Nicolescu, G., Tria, A., Fernandez, J.M., Marion, J.-Y., Garcia-Alfaro, J. (eds.) FPS 2020. LNCS, vol. 12637, pp. 47\u201362. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-70881-8_4"},{"key":"2_CR20","doi-asserted-by":"crossref","unstructured":"Mehta, D., et al.: The big hack explained: detection and prevention of PCB supply chain implants. ACM J. Emerg. Technol. Comput. Syst. (JETC) 16(4), 1\u201325 (2020)","DOI":"10.1145\/3401980"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:04:20Z","timestamp":1710194660000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}