{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T23:50:36Z","timestamp":1776901836690,"version":"3.51.2"},"publisher-location":"Cham","reference-count":49,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032195395","type":"print"},{"value":"9783032195401","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-19540-1_1","type":"book-chapter","created":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T23:30:46Z","timestamp":1776900646000},"page":"3-19","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["What Makes Information Critical? Information Classification in\u00a0Organizational Practice"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4057-9454","authenticated-orcid":false,"given":"Simon","family":"Andersson","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5706-4588","authenticated-orcid":false,"given":"\u00c5sa","family":"Ericson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0280-3160","authenticated-orcid":false,"given":"Johan","family":"Lugnet","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4869-5094","authenticated-orcid":false,"given":"Christine","family":"Gro\u00dfe","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,4,1]]},"reference":[{"key":"1_CR1","doi-asserted-by":"crossref","unstructured":"Adams, W.C.: Conducting semi-structured interviews. In: Handbook of Practical Program Evaluation, pp. 492\u2013505 (2015)","DOI":"10.1002\/9781119171386.ch19"},{"key":"1_CR2","doi-asserted-by":"crossref","unstructured":"Agrawal, V.: A framework for the information classification in ISO 27005 standard. In: 2017 IEEE 4th International Conference on Cyber Security and Cloud Computing (CSCloud), pp. 264\u2013269. IEEE (2017)","DOI":"10.1109\/CSCloud.2017.13"},{"key":"1_CR3","doi-asserted-by":"crossref","unstructured":"Ahlin, K.: Measuring the immeasurable? The intangible benefits of digital information. In: Hawaii International Conference on System Sciences, pp. 6176\u20136185. Hawaii International Conference on System Sciences (2019)","DOI":"10.24251\/HICSS.2019.743"},{"issue":"4","key":"1_CR4","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1108\/ICS-10-2022-0163","volume":"31","author":"S Andersson","year":"2023","unstructured":"Andersson, S.: Problems in information classification: insights from practice. Inf. Comput. Secur. 31(4), 449\u2013462 (2023)","journal-title":"Inf. Comput. Secur."},{"key":"1_CR5","doi-asserted-by":"crossref","unstructured":"Andersson, S., Bergstr\u00f6m, E., Lundgren, M., Bernsmed, K., Bour, G.: Information security risk management tools in the air traffic management domain: what are practitioners\u2019 needs? Inf. Secur. J. A Global Perspect., 1\u201318 (2025)","DOI":"10.1080\/19393555.2025.2498472"},{"issue":"2","key":"1_CR6","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1108\/ICS-03-2021-0032","volume":"30","author":"JH Bergquist","year":"2021","unstructured":"Bergquist, J.H., Tinet, S., Gao, S.: An information classification model for public sector organizations in Sweden: a case study of a Swedish municipality. Inf. Comput. Secur. 30(2), 153\u2013172 (2021)","journal-title":"Inf. Comput. Secur."},{"issue":"2","key":"1_CR7","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1108\/ICS-07-2020-0110","volume":"29","author":"E Bergstr\u00f6m","year":"2021","unstructured":"Bergstr\u00f6m, E., Karlsson, F., \u00c5hlfeldt, R.M.: Developing an information classification method. Inf. Comput. Secur. 29(2), 209\u2013239 (2021)","journal-title":"Inf. Comput. Secur."},{"key":"1_CR8","doi-asserted-by":"publisher","unstructured":"Bergstr\u00f6m, E., Lundgren, M.: Stress amongst novice information security risk management practitioners. Intl. J. Cyber Situational Awareness 4(1), 128\u2013154 (2019). https:\/\/doi.org\/10.22619\/IJCSA.2019.100128, https:\/\/c-mric.com\/100128","DOI":"10.22619\/IJCSA.2019.100128"},{"issue":"3","key":"1_CR9","doi-asserted-by":"publisher","first-page":"358","DOI":"10.1108\/ICS-09-2018-0106","volume":"27","author":"E Bergstr\u00f6m","year":"2019","unstructured":"Bergstr\u00f6m, E., Lundgren, M., Ericson, A.: Revisiting information security risk management challenges: a practice perspective. Inf. Comput. Secur. 27(3), 358\u2013372 (2019). https:\/\/doi.org\/10.1108\/ICS-09-2018-0106","journal-title":"Inf. Comput. Secur."},{"key":"1_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1007\/978-3-319-11599-3_2","volume-title":"Secure IT Systems","author":"E Bergstr\u00f6m","year":"2014","unstructured":"Bergstr\u00f6m, E., \u00c5hlfeldt, R.-M.: Information classification issues. In: Bernsmed, K., Fischer-H\u00fcbner, S. (eds.) NordSec 2014. LNCS, vol. 8788, pp. 27\u201341. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-11599-3_2"},{"issue":"2","key":"1_CR11","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1191\/1478088706qp063oa","volume":"3","author":"V Braun","year":"2006","unstructured":"Braun, V., Clarke, V.: Using thematic analysis in psychology. Qual. Res. Psychol. 3(2), 77\u2013101 (2006)","journal-title":"Qual. Res. Psychol."},{"issue":"5","key":"1_CR12","doi-asserted-by":"publisher","first-page":"351","DOI":"10.1002\/(SICI)1097-4571(199106)42:5<351::AID-ASI5>3.0.CO;2-3","volume":"42","author":"MK Buckland","year":"1991","unstructured":"Buckland, M.K.: Information as thing. J. Am. Soc. Inf. Sci. 42(5), 351\u2013360 (1991)","journal-title":"J. Am. Soc. Inf. Sci."},{"key":"1_CR13","unstructured":"Denscombe, M.: EBOOK: The Good Research Guide: For Small-Scale Social Research Projects. McGraw-Hill Education (UK) (2017)"},{"key":"1_CR14","doi-asserted-by":"publisher","unstructured":"European Union Agency for Cybersecurity (ENISA): ENISA Threat Landscape 2024 (2024). https:\/\/doi.org\/10.2824\/0710888, https:\/\/www.enisa.europa.eu\/sites\/default\/files\/2024-11\/ENISA%20Threat%20Landscape%202024_0.pdf","DOI":"10.2824\/0710888"},{"key":"1_CR15","first-page":"102193","volume":"54","author":"N Evans","year":"2020","unstructured":"Evans, N., Price, J.: Development of a holistic model for the management of an enterprise\u2019s information assets. Int. J. Inf. Manage. 54, 102193 (2020)","journal-title":"Int. J. Inf. Manage."},{"key":"1_CR16","doi-asserted-by":"crossref","unstructured":"Everett, C.: Building solid foundations: the case for data classification. Comput. Fraud Secur. 2011(6), 5\u20138 (2011). http:\/\/www.sciencedirect.com\/science\/article\/pii\/S1361372311700604","DOI":"10.1016\/S1361-3723(11)70060-4"},{"issue":"3","key":"1_CR17","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1353\/lib.2015.0014","volume":"63","author":"D Fallis","year":"2015","unstructured":"Fallis, D.: What is disinformation? Libr. Trends 63(3), 401\u2013426 (2015)","journal-title":"Libr. Trends"},{"key":"1_CR18","doi-asserted-by":"publisher","unstructured":"Fenz, S., Heurix, J., Neubauer, T., Pechstein, F.: Current challenges in information security risk management. Inf. Manage. Comput. Secur. 22(5), 410\u2013430 (2014), https:\/\/doi.org\/10.1108\/IMCS-07-2013-0053","DOI":"10.1108\/IMCS-07-2013-0053"},{"key":"1_CR19","doi-asserted-by":"crossref","unstructured":"Fibikova, L., M\u00fcller, R.: A Simplified Approach for Classifying Applications, pp. 39\u201349. Vieweg+Teubner, Wiesbaden (2011)","DOI":"10.1007\/978-3-8348-9788-6_4"},{"key":"1_CR20","doi-asserted-by":"publisher","unstructured":"Ghernaouti-Helie, S., Simms, D., Tashi, I.: Protecting information in a connected world: a question of security and of confidence in security. In: 2011 14th International Conference on Network-Based Information Systems, pp. 208\u2013212 (2011). https:\/\/doi.org\/10.1109\/NBiS.2011.38","DOI":"10.1109\/NBiS.2011.38"},{"issue":"1","key":"1_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3145905","volume":"51","author":"D Gritzalis","year":"2018","unstructured":"Gritzalis, D., Iseppi, G., Mylonas, A., Stavrou, V.: Exiting the risk assessment maze: a meta-survey. ACM Comput. Surv. 51(1), 1\u201330 (2018)","journal-title":"ACM Comput. Surv."},{"key":"1_CR22","unstructured":"Gro\u00dfe, C.: Towards an integrated framework for quality and information security management in small companies (2016)"},{"issue":"6","key":"1_CR23","doi-asserted-by":"publisher","first-page":"758","DOI":"10.1080\/13669877.2018.1459796","volume":"22","author":"C Gro\u00dfe","year":"2019","unstructured":"Gro\u00dfe, C.: Sources of uncertainty in Swedish emergency response planning. J. Risk Res. 22(6), 758\u2013772 (2019)","journal-title":"J. Risk Res."},{"key":"1_CR24","doi-asserted-by":"crossref","unstructured":"Gro\u00dfe, C.: Enhanced information management in inter-organisational planning for critical infrastructure protection: case and framework. In: ICISSP, pp. 319\u2013330 (2021)","DOI":"10.5220\/0010186803190330"},{"issue":"1","key":"1_CR25","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1504\/IJCIS.2023.129066","volume":"19","author":"C Gro\u00dfe","year":"2023","unstructured":"Gro\u00dfe, C., Larsson, A., Bj\u00f6rkqvist, O.: Information-flawing filters in critical infrastructure protection: the deficient information basis in a Swedish approach. Int. J. Crit. Infrastruct. 19(1), 40\u201357 (2023)","journal-title":"Int. J. Crit. Infrastruct."},{"issue":"2","key":"1_CR26","doi-asserted-by":"publisher","first-page":"58","DOI":"10.34190\/ejbrm.19.2.2509","volume":"19","author":"C Gro\u00dfe","year":"2021","unstructured":"Gro\u00dfe, C., Olausson, P.M., Wallman-Lund\u00e5sen, S.: Left in the dark: obstacles to studying and performing critical infrastructure protection. Electron. J. Bus. Res. Meth. 19(2), 58\u201370 (2021)","journal-title":"Electron. J. Bus. Res. Meth."},{"issue":"1","key":"1_CR27","first-page":"40","volume":"62","author":"M Hepfer","year":"2020","unstructured":"Hepfer, M., Powell, T.C.: Make cybersecurity a strategic asset. MIT Sloan Manag. Rev. 62(1), 40\u201345 (2020)","journal-title":"MIT Sloan Manag. Rev."},{"key":"1_CR28","doi-asserted-by":"crossref","unstructured":"Hove, C., T\u00e5rnes, M., Line, M.B., Bernsmed, K.: Information security incident management: identified practice in large organizations. In: 2014 Eighth International Conference on IT Security Incident Management & IT Forensics, pp. 27\u201346. IEEE (2014)","DOI":"10.1109\/IMF.2014.9"},{"key":"1_CR29","unstructured":"ISO\/IEC 27002: Information security, cybersecurity and privacy protection \u2013 information security controls. Standard ISO\/IEC 27002:2022, International Organization for Standardization, Geneva, CH (2022). https:\/\/www.iso.org\/standard\/75652.html"},{"issue":"12","key":"1_CR30","doi-asserted-by":"publisher","first-page":"2954","DOI":"10.1111\/jan.13031","volume":"72","author":"H Kallio","year":"2016","unstructured":"Kallio, H., Pietil\u00e4, A.M., Johnson, M., Kangasniemi, M.: Systematic methodological review: developing a framework for a qualitative semi-structured interview guide. J. Adv. Nurs. 72(12), 2954\u20132965 (2016)","journal-title":"J. Adv. Nurs."},{"issue":"3","key":"1_CR31","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1177\/107780049600200302","volume":"2","author":"S Kvale","year":"1996","unstructured":"Kvale, S.: The 1,000-page question. Q. Inq. 2(3), 275\u2013284 (1996)","journal-title":"Q. Inq."},{"issue":"5","key":"1_CR32","doi-asserted-by":"publisher","first-page":"524","DOI":"10.1080\/13669877.2023.2181858","volume":"26","author":"A Larsson","year":"2023","unstructured":"Larsson, A., Gro\u00dfe, C.: Data use and data needs in critical infrastructure risk analysis. J. Risk Res. 26(5), 524\u2013546 (2023)","journal-title":"J. Risk Res."},{"issue":"4","key":"1_CR33","first-page":"212","volume":"32","author":"R Leming","year":"2015","unstructured":"Leming, R.: Why is information the elephant asset? An answer to this question and a strategy for information asset management. Bus. Inf. Rev. 32(4), 212\u2013219 (2015)","journal-title":"Bus. Inf. Rev."},{"issue":"2","key":"1_CR34","first-page":"9","volume":"10","author":"JG March","year":"1997","unstructured":"March, J.G.: Understanding how decisions happen in organizations. Organ. Decis. Making 10(2), 9\u201332 (1997)","journal-title":"Organ. Decis. Making"},{"issue":"12","key":"1_CR35","first-page":"1","volume":"3","author":"DE Marcial","year":"2019","unstructured":"Marcial, D.E., Launer, M.A.: Towards the measurement of digital trust in the workplace: a proposed framework. Int. J. Sci. Eng. Sci. 3(12), 1\u20137 (2019)","journal-title":"Int. J. Sci. Eng. Sci."},{"key":"1_CR36","first-page":"225","volume":"3","author":"MK McBeth","year":"2014","unstructured":"McBeth, M.K., Jones, M.D., Shanahan, E.A.: The narrative policy framework. Theor. Policy Process 3, 225\u2013266 (2014)","journal-title":"Theor. Policy Process"},{"key":"1_CR37","doi-asserted-by":"crossref","unstructured":"Nyman, M., Gro\u00dfe, C.: Are you ready when it counts? It consulting firm\u2019s information security incident management. In: ICISSP, pp. 26\u201337 (2019)","DOI":"10.5220\/0007247500260037"},{"key":"1_CR38","unstructured":"General Data Protection Regulation: Regulation (EU) 2016\/679 of the European Parliament and of the council. Regulation (EU) 679, 2016 (2016)"},{"key":"1_CR39","doi-asserted-by":"publisher","unstructured":"Renn, O., Levine, D.: Credibility and trust in risk communication. In: Kasperson, R.E., Stallen, P.J.M. (eds.) Communicating Risks to the Public. Technology, Risk, and Society, vol. 4. Springer, Dordrecht (1991). https:\/\/doi.org\/10.1007\/978-94-009-1952-5_10","DOI":"10.1007\/978-94-009-1952-5_10"},{"key":"1_CR40","doi-asserted-by":"crossref","unstructured":"Robinson, S.L.: Trust and breach of the psychological contract. Adm. Sci. Q., 574\u2013599 (1996)","DOI":"10.2307\/2393868"},{"issue":"2","key":"1_CR41","doi-asserted-by":"publisher","first-page":"215","DOI":"10.1002\/acp.1812","volume":"26","author":"P Rodway","year":"2012","unstructured":"Rodway, P., Schepman, A., Lambert, J.: Preferring the one in the middle: further evidence for the centre-stage effect. Appl. Cogn. Psychol. 26(2), 215\u2013222 (2012)","journal-title":"Appl. Cogn. Psychol."},{"key":"1_CR42","volume-title":"The Coding Manual for Qualitative Researchers","author":"J Salda\u00f1a","year":"2021","unstructured":"Salda\u00f1a, J.: The Coding Manual for Qualitative Researchers, 4th edn. SAGE Publications Inc., Thousand Oaks, CA, USA (2021)","edition":"4"},{"issue":"16","key":"1_CR43","first-page":"1","volume":"15","author":"E S\u00f6derstr\u00f6m","year":"2009","unstructured":"S\u00f6derstr\u00f6m, E.: Trust types: an overview. Discourses Secur. Assur. Priv. 15(16), 1\u201312 (2009)","journal-title":"Discourses Secur. Assur. Priv."},{"key":"1_CR44","first-page":"279","volume":"2","author":"G Stasser","year":"1989","unstructured":"Stasser, G., Kerr, N.L., Davis, J.H.: Influence processes and consensus models in decision-making groups. Psychol. Group Influence 2, 279\u2013326 (1989)","journal-title":"Psychol. Group Influence"},{"key":"1_CR45","doi-asserted-by":"crossref","unstructured":"Svensson, \u00c5., Lundberg, J., Forsell, C., R\u00f6nnberg, N.: Automation, teamwork, and the feared loss of safety: air traffic controllers\u2019 experiences and expectations on current and future atm systems. In: Proceedings of the 32nd European Conference on Cognitive Ergonomics, pp. 1\u20138 (2021)","DOI":"10.1145\/3452853.3452855"},{"issue":"3","key":"1_CR46","doi-asserted-by":"publisher","first-page":"398","DOI":"10.1111\/nhs.12048","volume":"15","author":"M Vaismoradi","year":"2013","unstructured":"Vaismoradi, M., Turunen, H., Bondas, T.: Content analysis and thematic analysis: implications for conducting a qualitative descriptive study. Nurs. Health Sci. 15(3), 398\u2013405 (2013)","journal-title":"Nurs. Health Sci."},{"key":"1_CR47","doi-asserted-by":"crossref","unstructured":"Webb, J., Maynard, S., Ahmad, A., Shanks, G., et al.: Information security risk management: an intelligence-driven approach. Australas. J. Inf. Syst. 18(3) (2014)","DOI":"10.3127\/ajis.v18i3.1096"},{"key":"1_CR48","unstructured":"Whitman, M.E., Mattord, H.J.: Principles of Information Security, 7th edn. Cengage Learning (2022)"},{"key":"1_CR49","doi-asserted-by":"crossref","unstructured":"Yadav Ph D, S.B., Dong, T.: A comprehensive method to assess work system security risk. Commun. Assoc. Inf. Syst. 34(1), 8 (2014)","DOI":"10.17705\/1CAIS.03408"}],"container-title":["Lecture Notes in Computer Science","Critical Information Infrastructures Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-19540-1_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T23:30:50Z","timestamp":1776900650000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-19540-1_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032195395","9783032195401"],"references-count":49,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-19540-1_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 April 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare relevant to this article\u2019s content.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"CRITIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Critical Information Infrastructures Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"J\u00f6nk\u00f6ping","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Sweden","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"critis2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/jth-critis.hj.se\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}