{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T22:37:22Z","timestamp":1781131042029,"version":"3.54.1"},"publisher-location":"Cham","reference-count":51,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031945687","type":"print"},{"value":"9783031945694","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-94569-4_4","type":"book-chapter","created":{"date-parts":[[2025,6,14]],"date-time":"2025-06-14T02:58:28Z","timestamp":1749869908000},"page":"57-74","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Evaluating Organization Security: User Stories of\u00a0European Union NIS2 Directive"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9066-2467","authenticated-orcid":false,"given":"Mari","family":"Seeba","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-2575-5301","authenticated-orcid":false,"given":"Magnus","family":"Valgre","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1829-4794","authenticated-orcid":false,"given":"Raimundas","family":"Matulevi\u010dius","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,6,15]]},"reference":[{"key":"4_CR1","doi-asserted-by":"publisher","unstructured":"Alsaadi, M., Lisitsa, A., Qasaimeh, M.: Minimizing the ambiguities in medical devices regulations based on software requirement engineering techniques (2019). https:\/\/doi.org\/10.1145\/3368691.3368709","DOI":"10.1145\/3368691.3368709"},{"key":"4_CR2","doi-asserted-by":"publisher","unstructured":"Bernik, I., Prislan, K.: Measuring information security performance with 10 by 10 model for holistic state evaluation (2016). https:\/\/doi.org\/10.1371\/journal.pone.0163050","DOI":"10.1371\/journal.pone.0163050"},{"key":"4_CR3","doi-asserted-by":"publisher","DOI":"10.1016\/j.clsr.2024.105961","author":"PG Chiara","year":"2024","unstructured":"Chiara, P.G.: Towards a right to cybersecurity in EU law? Challenges Ahead (2024). https:\/\/doi.org\/10.1016\/j.clsr.2024.105961","journal-title":"Challenges Ahead"},{"key":"4_CR4","unstructured":"Cohn, M.: User Stories Applied: For Agile Software Development (2004)"},{"key":"4_CR5","unstructured":"Cohn, M.: The Two Ways to Add Detail to User Stories (2017). https:\/\/www.mountaingoatsoftware.com\/blog\/preview\/1691. Accessed 20 April 2024"},{"key":"4_CR6","unstructured":"Dixon, P., Emerson, J.: Global Visualization of Countries with Data Privacy Laws, Treaties, or Conventions. https:\/\/www.worldprivacyforum.org\/2024\/06\/countries-with-data-privacy-laws\/. Accessed 25 Nov 2024"},{"key":"4_CR7","unstructured":"e-Governance Academy: National cyber security index. https:\/\/ncsi.ega.ee\/. Accessed 12 April 2024"},{"key":"4_CR8","unstructured":"European Parlament: Directive (EU) 2022\/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910\/2014 and Directive (EU) 2018\/1972, and repealing Directive (EU) 2016\/1148 (NIS 2 Directive) (2022). https:\/\/eur-lex.europa.eu\/legal-content\/en\/TXT\/?uri=CELEX%3A32022L2555"},{"key":"4_CR9","unstructured":"European Union Agency for Cybersecurity: Cybersecurity Maturity Assessment for Small and Medium Enterprises. https:\/\/www.enisa.europa.eu\/cybersecurity-maturity-assessment-for-small-and-medium-enterprises#\/. Accessed 13 June 2024"},{"key":"4_CR10","unstructured":"European Union Agency for Cybersecurity: EU Cybersecurity Index. https:\/\/www.enisa.europa.eu\/topics\/cybersecurity-policy\/nis-directive-new\/eu-cybersecurity-index. Accessed 20 May 2024"},{"key":"4_CR11","doi-asserted-by":"publisher","unstructured":"Fatema, K., Debruyne, C., Lewis, D., OSullivan, D., Morrison, J.P., Mazed, A.A.: A Semi-Automated Methodology for Extracting Access Control Rules from the European Data Protection Directive (2016). https:\/\/doi.org\/10.1109\/SPW.2016.16","DOI":"10.1109\/SPW.2016.16"},{"key":"4_CR12","unstructured":"Finnish Transport and Communication Agency National Cyber Security Centre: Cybermeter. https:\/\/www.kyberturvallisuuskeskus.fi\/fi\/palvelumme\/tilannekuva-ja-verkostojohtaminen\/kybermittari. Accessed 13 May 2024"},{"key":"4_CR13","doi-asserted-by":"publisher","unstructured":"Grigali\u016bnas, S., Schmidt, M., Br\u016bzgien\u0117, R., Smyrli, P., Andreou, S., Lopata, A.: Holistic Information Security Management and Compliance Framework (2024). https:\/\/doi.org\/10.3390\/electronics13193955","DOI":"10.3390\/electronics13193955"},{"key":"4_CR14","doi-asserted-by":"publisher","unstructured":"Hassani, S., Sabetzadeh, M., Amyot, D., Liao, J.: Rethinking Legal Compliance Automation: Opportunities with Large Language Models (2024). https:\/\/doi.org\/10.1109\/RE59067.2024.00051","DOI":"10.1109\/RE59067.2024.00051"},{"key":"4_CR15","unstructured":"Hellenic Ministry of Digital Governance Government department: Cybersecurity Self Assessment Tool (2021). https:\/\/mindigital.gr\/wp-content\/uploads\/2022\/03\/cybersecurity-self-assessment.xlsm. Accessed 27 April 2024"},{"key":"4_CR16","unstructured":"International Organization for Standardization: ISO\/IEC 27002:2022 Information security, cybersecurity and privacy protection - Information security controls (2022)"},{"key":"4_CR17","unstructured":"International Telecommunications Union: Global Cybersecurity Index. https:\/\/www.itu.int\/en\/ITU-D\/Cybersecurity\/Pages\/global-cybersecurity-index.aspx. Accessed 20 May 2024"},{"key":"4_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1007\/978-3-642-14192-8_23","volume-title":"Requirements Engineering: Foundation for Software Quality","author":"S Islam","year":"2010","unstructured":"Islam, S., Mouratidis, H., Wagner, S.: Towards a framework to elicit and manage security and privacy requirements from laws and regulations. In: Wieringa, R., Persson, A. (eds.) REFSQ 2010. LNCS, vol. 6182, pp. 255\u2013261. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-14192-8_23"},{"key":"4_CR19","unstructured":"ISO\/IEC 27001:2022(en) Information security, cybersecurity and privacy protection - Information security management systems - Requirements. Standard, International Organization for Standardization (2022)"},{"key":"4_CR20","unstructured":"Jazri, H., Zakaria, O., Chikohora, E.: Measuring cybersecurity wellness index of critical organisations (2018)"},{"key":"4_CR21","doi-asserted-by":"publisher","unstructured":"Jorshari, F.Z., Mouratidis, H., Islam, S.: Extracting security requirements from relevant laws and regulations (2012). https:\/\/doi.org\/10.1109\/RCIS.2012.6240443","DOI":"10.1109\/RCIS.2012.6240443"},{"key":"4_CR22","doi-asserted-by":"publisher","unstructured":"Khaleghi, M., Aref, M.R., Rasti, M.: Comprehensive Comparison of Security Measurement Models (2022). https:\/\/doi.org\/10.1080\/19361610.2021.1981089","DOI":"10.1080\/19361610.2021.1981089"},{"key":"4_CR23","doi-asserted-by":"publisher","unstructured":"Kiyavitskaya, N., Krausov\u00e1, A., Zannone, N.: Why eliciting and managing legal requirements is hard (2008). https:\/\/doi.org\/10.1109\/RELAW.2008.10","DOI":"10.1109\/RELAW.2008.10"},{"key":"4_CR24","doi-asserted-by":"publisher","unstructured":"Leszczyna, R.: Review of cybersecurity assessment methods: applicability perspective (2021). https:\/\/doi.org\/10.1016\/j.cose.2021.102376","DOI":"10.1016\/j.cose.2021.102376"},{"key":"4_CR25","doi-asserted-by":"publisher","unstructured":"Lucassen, G., Dalpiaz, F., Werf, J., Brinkkemper, S.: The Use and Effectiveness of User Stories in Practice. In: Daneva, M., Pastor, O. (eds.) REFSQ 2016. LNCS, vol. 9619, pp. 205\u2013222. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-30282-9_14","DOI":"10.1007\/978-3-319-30282-9_14"},{"key":"4_CR26","doi-asserted-by":"publisher","unstructured":"Malaivongs, S., Kiattisin, S., Chatjuthamard, P.: Cyber trust index: a framework for rating and improving cybersecurity performance (2022). https:\/\/doi.org\/10.3390\/app122111174","DOI":"10.3390\/app122111174"},{"key":"4_CR27","doi-asserted-by":"crossref","unstructured":"Maleh, Y., Ezzati, A., Sahid, A., Belaissaoui, M.: Towards A Capability Assessment Framework for Information Security Governance in Organization (2017)","DOI":"10.1007\/978-3-319-76354-5_20"},{"key":"4_CR28","unstructured":"MIT Technology Review Insights: Cyber Defense Index. https:\/\/www.technologyreview.com\/2022\/11\/15\/1063189\/the-cyber-defense-index-2022-23\/. Accessed 12 May 2024"},{"key":"4_CR29","unstructured":"National Audit Office of Estonia: Administration and reliability of X-road. https:\/\/www.riigikontroll.ee\/DesktopModules\/DigiDetail\/FileDownloader.aspx?FileId=14778&AuditId=2520. Accessed 17 Nov 2024"},{"key":"4_CR30","unstructured":"National Audit Office of Estonia: Implementation of system of IT security measures in local governments. https:\/\/www.riigikontroll.ee\/DesktopModules\/DigiDetail\/FileDownloader.aspx?FileId=14270&AuditId=2466. Accessed 17 Nov 2024"},{"key":"4_CR31","unstructured":"National Cyber and Information Security Agency of the Czech Republic: 2023 Report on the State of Cybersecurity in the Czech Republic. https:\/\/nukib.gov.cz\/download\/publications_en\/2023_Report_on_the_State_of_Cybersecurity_in_the_Czech_Republic.pdf. Accessed 8 Nov 2023"},{"key":"4_CR32","unstructured":"Pisa, M., Dixon, P., Ndulu, B., Nwankwo, U.: Governing data for development: trends, challenges, and opportunities (2020). https:\/\/www.cgdev.org\/sites\/default\/files\/governing-data-development-trends-challenges-and-opportunities.pdf"},{"key":"4_CR33","doi-asserted-by":"publisher","unstructured":"Prislan, K., Miheli\u010d, A., Bernik, I.: A real-world information security performance assessment using a multidimensional socio-technical approach (2020). https:\/\/doi.org\/10.1371\/journal.pone.0238739","DOI":"10.1371\/journal.pone.0238739"},{"key":"4_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1007\/978-3-030-34339-2_20","volume-title":"Information Security Practice and Experience","author":"A Rae","year":"2019","unstructured":"Rae, A., Patel, A.: Defining a new composite cybersecurity rating scheme for SMEs in the U.K. In: Heng, S.-H., Lopez, J. (eds.) ISPEC 2019. LNCS, vol. 11879, pp. 362\u2013380. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-34339-2_20"},{"key":"4_CR35","doi-asserted-by":"publisher","unstructured":"Rea-Guaman, A.M., S\u00e1nchez-Garc\u00eda, I.D., Feliu, T.S., Calvo-Manzano, J.A.: Maturity models in cybersecurity: a systematic review (2017). https:\/\/doi.org\/10.23919\/CISTI.2017.7975865","DOI":"10.23919\/CISTI.2017.7975865"},{"key":"4_CR36","unstructured":"RIA (Estonian Information System Authority): E-ITS. Portal of Estonian Information Security Standard (2022). https:\/\/eits.ria.ee\/"},{"key":"4_CR37","doi-asserted-by":"publisher","unstructured":"Seeba, M., M\u00e4ses, S., Matulevi\u010dius, R.: Method for Evaluating Information Security Level in Organisations (2022). https:\/\/doi.org\/10.1007\/978-3-031-05760-1_39","DOI":"10.1007\/978-3-031-05760-1_39"},{"key":"4_CR38","doi-asserted-by":"publisher","unstructured":"Seeba, M., amefon Obot\u00a0Affia, A., M\u00e4ses, S., Matulevi\u010dius, R.: Create your own MUSE: a method for updating security level evaluation instruments. Comput. Standards Interfaces 87, 103776 (2024). https:\/\/doi.org\/10.1016\/j.csi.2023.103776","DOI":"10.1016\/j.csi.2023.103776"},{"key":"4_CR39","doi-asserted-by":"publisher","unstructured":"Seeba, M., Oja, T., Murumaa, M.P., Stupka, V.: Security Level Evaluation with F4SLE. In: Proceedings of the 18th International Conference on Availability, Reliability and Security. ARES 2023, Association for Computing Machinery, New York, NY, USA (2023). https:\/\/doi.org\/10.1145\/3600160.3605045","DOI":"10.1145\/3600160.3605045"},{"key":"4_CR40","doi-asserted-by":"publisher","unstructured":"Szczepaniuk, E.K., Szczepaniuk, H., Rokicki, T., Klepacki, B.: Information security assessment in public administration (2020). https:\/\/doi.org\/10.1016\/j.cose.2019.101709","DOI":"10.1016\/j.cose.2019.101709"},{"key":"4_CR41","doi-asserted-by":"publisher","unstructured":"Tasheva, I., Kunkel, I.: In a hyperconnected world, is the EU cybersecurity framework connected? (2022). https:\/\/doi.org\/10.1177\/17816858221136106","DOI":"10.1177\/17816858221136106"},{"key":"4_CR42","unstructured":"The IASME Consortium: IASME Cyber Essentials. https:\/\/getreadyforcyberessentials.iasme.co.uk\/. Accessed 13 June 2024"},{"key":"4_CR43","unstructured":"The National Cyber Security Centre of Ireland: Cyber Security Baseline Standards Self-Assessment Form (2023). https:\/\/www.ncsc.gov.ie\/pdfs\/Cyber_Resilience_Self-Assessment_Framework_Version_1.4_Jan_23.xlsx. Accessed 27 May 2024"},{"key":"4_CR44","unstructured":"The Spanish National Cybersecurity Institute: Herramienta de Autodiagn\u00f3stico, https:\/\/adl.incibe.es\/#. Accessed 27 May 2024"},{"key":"4_CR45","unstructured":"The State Audit Office of the Republic of Latvia: Can we rely on the access to information systems and the receipt of e-services? (2022). https:\/\/www.lrvk.gov.lv\/en\/getrevisionfile\/29525-5Aio6j7MwYsuSG4nKlzFVmCMG0JZircA.pdf"},{"key":"4_CR46","unstructured":"United States Department of Energy: C2M2 C2M2 V2.1 HTML-Based Tool. https:\/\/c2m2.doe.gov\/c2m2-assessment. Accessed 13 June 2024"},{"key":"4_CR47","unstructured":"University of Harvard Belfer Center: National cyber power index 2020 (2022). https:\/\/www.belfercenter.org\/publication\/national-cyber-power-index-2022"},{"key":"4_CR48","doi-asserted-by":"publisher","unstructured":"Vandezande, N.: Cybersecurity in the EU: how the NIS2-directive stacks up against its predecessor (2024). https:\/\/doi.org\/10.1016\/j.clsr.2023.105890","DOI":"10.1016\/j.clsr.2023.105890"},{"key":"4_CR49","doi-asserted-by":"publisher","unstructured":"Wanecki, P., Jasek, R., Drofova, I.: The Contribution of the European NIS2 directive to the design of the cyber security model (2023). https:\/\/doi.org\/10.1109\/IDT59031.2023.10194454","DOI":"10.1109\/IDT59031.2023.10194454"},{"issue":"9","key":"4_CR50","doi-asserted-by":"publisher","first-page":"3443","DOI":"10.1007\/s11227-015-1585-7","volume":"72","author":"Y You","year":"2015","unstructured":"You, Y., Cho, I., Lee, K.: An advanced approach to security measurement system. J. Supercomput. 72(9), 3443\u20133454 (2015). https:\/\/doi.org\/10.1007\/s11227-015-1585-7","journal-title":"J. Supercomput."},{"key":"4_CR51","doi-asserted-by":"publisher","unstructured":"Yu, E., Giorgini, P., Maiden, N., Mylopoulos, J.: Social Modeling for Requirements Engineering: An Introduction (2010). https:\/\/doi.org\/10.7551\/mitpress\/7549.001.0001","DOI":"10.7551\/mitpress\/7549.001.0001"}],"container-title":["Lecture Notes in Computer Science","Advanced Information Systems Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-94569-4_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,14]],"date-time":"2025-06-14T02:58:39Z","timestamp":1749869919000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-94569-4_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031945687","9783031945694"],"references-count":51,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-94569-4_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"15 June 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare relevant to this article\u2019s content.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"CAiSE","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Advanced Information Systems Engineering","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Vienna","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Austria","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 June 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 June 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"37","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"caise2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/conferences.big.tuwien.ac.at\/caise2025\/index.php","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}