{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,15]],"date-time":"2026-03-15T04:23:56Z","timestamp":1773548636760,"version":"3.50.1"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031604324","type":"print"},{"value":"9783031604331","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-60433-1_18","type":"book-chapter","created":{"date-parts":[[2024,5,30]],"date-time":"2024-05-30T05:03:34Z","timestamp":1717045414000},"page":"321-336","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["COPYCAT: Applying Serious Games in\u00a0Industry for\u00a0Defending Supply Chain Attack"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1518-4730","authenticated-orcid":false,"given":"Tiange","family":"Zhao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1462-6701","authenticated-orcid":false,"given":"Tiago","family":"Gasiba","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4286-3184","authenticated-orcid":false,"given":"Ulrike","family":"Lechner","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2725-7629","authenticated-orcid":false,"given":"Maria","family":"Pinto-Albuquerque","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3389-8916","authenticated-orcid":false,"given":"Didem","family":"Ongu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,5,31]]},"reference":[{"key":"18_CR1","unstructured":"Administration, G.S.: Fedramp (federal risk and authorization management program). Program, General Services Administration, Washington, D.C. (2019). https:\/\/www.fedramp.gov"},{"key":"18_CR2","doi-asserted-by":"crossref","unstructured":"Al\u00a0Nafea, R., Almaiah, M.A.: Cyber security threats in cloud: literature review. In: 2021 International Conference on Information Technology (ICIT), pp. 779\u2013786. IEEE (2021)","DOI":"10.1109\/ICIT52682.2021.9491638"},{"key":"18_CR3","unstructured":"Alliance, C.S.: Cloud controls matrix v4 (2021). https:\/\/cloudsecurityalliance.org\/artifact-s\/cloud-controls-matrix-v4\/"},{"key":"18_CR4","unstructured":"ATT &CK, M.: Supply Chain Compromise. https:\/\/attack.mitre.org\/techniques\/T1-195\/"},{"key":"18_CR5","unstructured":"ATT &CK, M.: Techniques (2017). https:\/\/attack.mitre.org\/techniques\/"},{"key":"18_CR6","unstructured":"BSI: Cloud computing C5 criteria catalogue (2020). http:\/\/tinyurl.com\/5665jp8y"},{"key":"18_CR7","unstructured":"Corporation, N.A.E.R.: Cip (critical infrastructure protection) reliability standards. Standards, North American Electric Reliability Corporation, Atlanta, GA (2020). https:\/\/www.nerc.com\/pa\/Stand\/Pages\/CIPStandards.aspx"},{"key":"18_CR8","unstructured":"CSA: Top threats to cloud computing: The egregious 11. BLACKHAT2019 (2019)"},{"key":"18_CR9","unstructured":"Cybercrime & Digital\u00a0Threats, C.M.: Hacker Infects Node.js Package to Steal from Bitcoin Wallets). https:\/\/www.trendmicro.com\/vinfo\/dk\/security\/news\/cybercrime-and-digital-threats\/hacker-infects-node-js-package-to-steal-from-bitcoin-wallets"},{"key":"18_CR10","unstructured":"PCI DSS: PCI Security Standards Council (PCI SSC) (2022). https:\/\/www.pcisecuritystandards.org\/"},{"key":"18_CR11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40612-1","volume-title":"Serious Games: Foundations, Concepts and Practice","author":"R D\u00f6rner","year":"2016","unstructured":"D\u00f6rner, R., G\u00f6bel, S., Effelsberg, W., Wiemeyer, J.: Serious Games: Foundations, Concepts and Practice. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-40612-1"},{"key":"18_CR12","doi-asserted-by":"crossref","unstructured":"Fenz, S., Ekelhart, A.: Formalizing information security knowledge. In: Proceedings of the 4th international Symposium on Information, Computer, and Communications Security, pp. 183\u2013194 (2009)","DOI":"10.1145\/1533057.1533084"},{"key":"18_CR13","doi-asserted-by":"publisher","unstructured":"Ferro, L.S., Marrella, A., Catarci, T., Sapio, F., Parenti, A., De\u00a0Santis, M.: AWATO: a serious game to improve cybersecurity awareness. In: Fang, X. (ed.) HCI in Games, pp. 508\u2013529. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-05637-6_33. http:\/\/tinyurl.com\/ykfjph4x","DOI":"10.1007\/978-3-031-05637-6_33"},{"key":"18_CR14","unstructured":"Gasiba, T.: Raising Awareness on Secure Coding in the Industry through CyberSecurity Challenges. Ph.D. thesis, Universit\u00e4t der Bundeswehr M\u00fcnchen (2021)"},{"key":"18_CR15","doi-asserted-by":"publisher","unstructured":"Gleeson, N., Walden, I.: \u2018It\u2019s a jungle out there\u2019?: cloud computing, standards and the law. SSRN Electron. J. (2014). https:\/\/doi.org\/10.2139\/ssrn.2441182","DOI":"10.2139\/ssrn.2441182"},{"key":"18_CR16","unstructured":"GVR-4-68038-210-5: Market Analysis Report: Cloud Computing Market Size, Share & Trends Analysis Report By Service (SaaS, IaaS), By Deployment, By Enterprise Size, By End-use, By Region, And Segment Forecasts, 2023\u20132030. https:\/\/www.grandviewresearch.com\/industry-analysis\/cloud-computing-industry"},{"key":"18_CR17","doi-asserted-by":"publisher","unstructured":"H\u00e4nsch, N., Benenson, Z.: Specifying IT security awareness. In: 25th International Workshop on Database and Expert Systems Applications, pp. 326\u2013330. IEEE (2014). https:\/\/doi.org\/10.1109\/DEXA.2014.71","DOI":"10.1109\/DEXA.2014.71"},{"key":"18_CR18","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101827","volume":"95","author":"S Hart","year":"2020","unstructured":"Hart, S., Margheri, A., Paci, F., Sassone, V.: Riskio: a serious game for cyber security awareness and education. Comput. Secur. 95, 101827 (2020). https:\/\/doi.org\/10.1016\/j.cose.2020.101827","journal-title":"Comput. Secur."},{"key":"18_CR19","first-page":"1","volume":"19","author":"A Hevner","year":"2007","unstructured":"Hevner, A.: A three cycle view of design science research. Scandinavian J. Inf. Syst. 19, 1\u20136 (2007). http:\/\/aisel.aisnet.org\/sjis\/vol19\/iss2\/4","journal-title":"Scandinavian J. Inf. Syst."},{"key":"18_CR20","unstructured":"for Internet\u00a0Security, C.: Cis (center for internet security) controls. Standards, Center for Internet Security, East Greenbush, NY (2020). https:\/\/www.cisecurity.org\/controls"},{"key":"18_CR21","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1007\/978-981-19-0468-4_13","volume-title":"Ubiquitous Security (UbiSec 2021)","author":"AC Iosif","year":"2022","unstructured":"Iosif, A.C., Gasiba, T.E., Zhao, T., Lechner, U., Pinto-Albuquerque, M.: A large-scale study on the security vulnerabilities of cloud deployments. In: Wang, G., Choo, K.K.R., Ko, R.K.L., Xu, Y., Crispo, B. (eds.) Ubiquitous Security (UbiSec 2021), pp. 171\u2013188. Springer, Singapore (2022). https:\/\/doi.org\/10.1007\/978-981-19-0468-4_13"},{"key":"18_CR22","unstructured":"ISACA: Cobit (control objectives for information and related technologies). Framework, ISACA, Rolling Meadows, IL (2019). https:\/\/www.isaca.org\/resources\/cobit"},{"key":"18_CR23","unstructured":"ISO27001: ISO\/IEC 27001 Information Security Management (2017). https:\/\/www.iso.org\/isoiec-27001-information-security.html"},{"key":"18_CR24","unstructured":"ISO27002: ISO\/IEC 27002:2013Information technology - Security techniques - Code of practice for information security controls (2013). https:\/\/www.iso.org\/standard\/54533.html"},{"key":"18_CR25","unstructured":"ISO27017: ISO\/IEC 27017:2015 Information technology - Security techniques - Code of practice for information security controls based on ISO\/IEC 27002 for cloud services (2015). https:\/\/www.iso.org\/standard\/43757.html"},{"key":"18_CR26","unstructured":"ISO27018: ISO\/IEC 27018:2019Information technology - Security techniques - Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors (2019). https:\/\/www.iso.org\/standard\/76559.html"},{"issue":"7","key":"18_CR27","doi-asserted-by":"publisher","first-page":"2083","DOI":"10.1080\/00207543.2018.1530473","volume":"57","author":"J Manuel Maqueira","year":"2019","unstructured":"Manuel Maqueira, J., Moyano-Fuentes, J., Bruque, S.: Drivers and consequences of an innovative technology assimilation in the supply chain: cloud computing and supply chain integration. Int. J. Prod. Res. 57(7), 2083\u20132103 (2019). https:\/\/doi.org\/10.1080\/00207543.2018.1530473","journal-title":"Int. J. Prod. Res."},{"issue":"4","key":"18_CR28","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1016\/j.cose.2006.02.008","volume":"25","author":"H Kruger","year":"2006","unstructured":"Kruger, H., Kearney, W.: A prototype for assessing information security awareness. Comput. Secur. 25(4), 289\u2013296 (2006). https:\/\/doi.org\/10.1016\/j.cose.2006.02.008. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404806000563","journal-title":"Comput. Secur."},{"key":"18_CR29","unstructured":"NIST: NIST SP 800-53 Rev. 5 Security and Privacy Controls for Information Systems and Organizations (2020). https:\/\/csrc.nist.gov\/pubs\/sp\/800\/53\/r5\/upd1\/final"},{"key":"18_CR30","unstructured":"Raza, M.: The Shared Responsibility Model for Security in The Cloud (IaaS, PaaS & SaaS). http:\/\/tinyurl.com\/3aez4epc"},{"key":"18_CR31","unstructured":"Shostack, A.: Tabletop security games & cards (2021). https:\/\/shostack.org\/games.html"},{"key":"18_CR32","doi-asserted-by":"crossref","unstructured":"\u0160v\u00e1bensk\u1ef3, V., Vykopal, J., Cermak, M., La\u0161tovi\u010dka, M.: Enhancing cybersecurity skills by creating serious games. In: Proceedings of the 23rd Annual ACM Conference on Innovation and Technology in Computer Science Education, pp. 194\u2013199 (2018). https:\/\/doi.org\/10.48550\/arXiv.1804.03567","DOI":"10.1145\/3197091.3197123"},{"key":"18_CR33","doi-asserted-by":"crossref","unstructured":"Thompson, M., Irvine, C.: Active learning with the cyberciege video game. In: Proceedings of the 4th Conference on Cyber Security Experimentation and Test. p.\u00a010. CSET\u201911, USENIX Association, USA (2011)","DOI":"10.21236\/ADA547670"},{"key":"18_CR34","unstructured":"TSC, A.: 2017 Trust Services Criteria (With Revised Points of Focus - 2022) (2017). https:\/\/www.aicpa-cima.com\/resources\/download\/2017-trust-services-criteria-with-revised-points-of-focus-2022"},{"issue":"2","key":"18_CR35","first-page":"3","volume":"56","author":"ED Wolff","year":"2021","unstructured":"Wolff, E.D., Growley, K., Gruden, M., et al.: Navigating the solarwinds supply chain attack. Procurement Lawyer 56(2), 3\u201310 (2021)","journal-title":"Procurement Lawyer"},{"key":"18_CR36","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2023.111946","volume":"210","author":"T Zhao","year":"2024","unstructured":"Zhao, T., Gasiba, T., Lechner, U., Pinto-Albuquerque, M.: Thriving in the era of hybrid work: raising cybersecurity awareness using serious games in industry trainings. J. Syst. Software 210, 111946 (2024). https:\/\/doi.org\/10.1016\/j.jss.2023.111946. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0164121223003412","journal-title":"J. Syst. Software"},{"key":"18_CR37","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-981-99-0272-9_5","volume-title":"Ubiquitous Security","author":"T Zhao","year":"2023","unstructured":"Zhao, T., Lechner, U., Pinto-Albuquerque, M., Ata, E., Gasiba, T.: Cats: a serious game in industry towards stronger cloud security. In: Wang, G., Choo, K.K.R., Wu, J., Damiani, E. (eds.) Ubiquitous Security, pp. 64\u201382. Springer, Singapore (2023). https:\/\/doi.org\/10.1007\/978-981-99-0272-9_5"},{"key":"18_CR38","doi-asserted-by":"publisher","unstructured":"Zhao, T., Lechner, U., Pinto-Albuquerque, M., Ongu, D.: An ontology-based model for evaluating cloud attack scenarios in cats - a serious game in cloud security. In: 2023 IEEE International Conference on Engineering, Technology and Innovation (ICE\/ITMC), pp.\u00a01\u20139 (2023). https:\/\/doi.org\/10.1109\/ICE\/ITMC58018.2023.10332371","DOI":"10.1109\/ICE\/ITMC58018.2023.10332371"}],"container-title":["Communications in Computer and Information Science","Innovations for Community Services"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-60433-1_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,30]],"date-time":"2024-05-30T05:15:47Z","timestamp":1717046147000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-60433-1_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031604324","9783031604331"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-60433-1_18","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"31 May 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"I4CS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Innovations for Community Services","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Mastricht","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 June 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 June 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"i4cs2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.eah-jena.de\/i4cs-conference\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}