{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T17:47:31Z","timestamp":1772041651232,"version":"3.50.1"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319074511","type":"print"},{"value":"9783319074528","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-07452-8_2","type":"book-chapter","created":{"date-parts":[[2014,5,22]],"date-time":"2014-05-22T01:53:43Z","timestamp":1400723623000},"page":"35-64","source":"Crossref","is-referenced-by-count":2,"title":["Empirical Assessment of Security Requirements and Architecture: Lessons Learned"],"prefix":"10.1007","author":[{"given":"Riccardo","family":"Scandariato","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Federica","family":"Paci","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Le Minh","family":"Sang Tran","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Katsiaryna","family":"Labunets","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Koen","family":"Yskout","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabio","family":"Massacci","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"2_CR1","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1109\/2.910904","volume":"34","author":"B. Nuseibeh","year":"2001","unstructured":"Nuseibeh, B.: Weaving together requirements and architectures. IEEE Computer\u00a034, 115\u2013119 (2001)","journal-title":"IEEE Computer"},{"key":"2_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1007\/978-3-642-19125-1_13","volume-title":"Engineering Secure Software and Systems","author":"T. Heyman","year":"2011","unstructured":"Heyman, T., Yskout, K., Scandariato, R., Schmidt, H., Yu, Y.: The security twin peaks. In: Erlingsson, \u00da., Wieringa, R., Zannone, N. (eds.) ESSoS 2011. LNCS, vol.\u00a06542, pp. 167\u2013180. Springer, Heidelberg (2011)"},{"key":"2_CR3","unstructured":"Howard, M., Lipner, S.: The Security Development Lifecycle. Microsoft Press (2006)"},{"key":"2_CR4","doi-asserted-by":"crossref","unstructured":"McGraw, G.: Software Security: Building Security. Addison-Wesley (2006)","DOI":"10.1109\/ISSRE.2006.43"},{"key":"2_CR5","doi-asserted-by":"crossref","unstructured":"Lund, M.S., Solhaug, B., St\u00f8len, K.: Model-Driven Risk Analysis: The CORAS Approach. Springer (2011)","DOI":"10.1007\/978-3-642-12323-8"},{"key":"2_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"192","DOI":"10.1007\/11863908_13","volume-title":"Computer Security \u2013 ESORICS 2006","author":"D. Mellado","year":"2006","unstructured":"Mellado, D., Fern\u00e1ndez-Medina, E., Piattini, M.: Applying a security requirements engineering process. In: Gollmann, D., Meier, J., Sabelfeld, A. (eds.) ESORICS 2006. LNCS, vol.\u00a04189, pp. 192\u2013206. Springer, Heidelberg (2006)"},{"key":"2_CR7","doi-asserted-by":"crossref","unstructured":"Scandariato, R., Wuyts, K., Joosen, W.: A descriptive study of Microsoft\u2019s threat modeling technique. Requirements Engineering (2014)","DOI":"10.1007\/s00766-013-0195-2"},{"key":"2_CR8","doi-asserted-by":"crossref","unstructured":"Labunets, K., Massacci, F., Paci, F., Tran, L.M.: An experimental comparison of two risk-based security methods. In: Proceedings of the 7th International Symposium on Empirical Software Engineering and Measurement (ESEM), pp. 163\u2013172 (2013)","DOI":"10.1109\/ESEM.2013.29"},{"key":"2_CR9","doi-asserted-by":"crossref","unstructured":"Massacci, F., Paci, F., Tran, L.M.S., Tedeschi, A.: Assessing a requirements evolution approach: Empirical studies in the air traffic management domain. Journal of Systems and Software (2013)","DOI":"10.1109\/EmpiRE.2012.6347682"},{"key":"2_CR10","doi-asserted-by":"crossref","unstructured":"Yskout, K., Scandariato, R., Joosen, W.: Change patterns: Co-evolving requirements and architecture. Software and Systems Modeling (2012)","DOI":"10.1007\/s10270-012-0276-6"},{"key":"2_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1007\/978-3-642-34210-3_7","volume-title":"Secure IT Systems","author":"F. Massacci","year":"2012","unstructured":"Massacci, F., Paci, F.: How to select a security requirements method? a comparative study with students and practitioners. In: J\u00f8sang, A., Carlsson, B. (eds.) NordSec 2012. LNCS, vol.\u00a07617, pp. 89\u2013104. Springer, Heidelberg (2012)"},{"key":"2_CR12","doi-asserted-by":"publisher","first-page":"916","DOI":"10.1016\/j.infsof.2008.05.013","volume":"51","author":"A.L. Opdahl","year":"2009","unstructured":"Opdahl, A.L., Sindre, G.: Experimental comparison of attack trees and misuse cases for security threat identification. Information and Software Technology\u00a051, 916\u2013932 (2009)","journal-title":"Information and Software Technology"},{"key":"2_CR13","unstructured":"Diallo, M.H., Romero-Mariona, J., Sim, S.E., Alspaugh, T., Richardson, D.J.: A comparative evaluation of three approaches to specifying security requirements. In: Proceeding of the 12th International Working Conference on Requirements Engineering: Foundation for Software Quality, REFSQ (2006)"},{"key":"2_CR14","doi-asserted-by":"crossref","unstructured":"Hogganvik, I., St\u00f8len, K.: On the comprehension of security risk scenarios. In: Proceedings of the 13th International Workshop on Program Comprehension (IWPC), pp. 115\u2013124. IEEE (2005)","DOI":"10.1109\/WPC.2005.27"},{"key":"2_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"574","DOI":"10.1007\/11880240_40","volume-title":"Model Driven Engineering Languages and Systems","author":"I. Hogganvik","year":"2006","unstructured":"Hogganvik, I., St\u00f8len, K.: A graphical approach to risk identification motivated by empirical investigations. In: Wang, J., Whittle, J., Harel, D., Reggio, G. (eds.) MoDELS 2006. LNCS, vol.\u00a04199, pp. 574\u2013588. Springer, Heidelberg (2006)"},{"key":"2_CR16","first-page":"916","volume":"51","author":"I. Hogganvik","year":"2009","unstructured":"Hogganvik, I., Lund, M., St\u00f8len, K.: Reducing the effort to comprehend risk models: Textlabels are often preferred over graphical means. Risk Analysis\u00a051, 916\u2013932 (2009)","journal-title":"Risk Analysis"},{"key":"2_CR17","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/MSP.2011.47","volume":"9","author":"D. Dhillon","year":"2011","unstructured":"Dhillon, D.: Developer-driven threat modeling: Lessons learned in the trenches. IEEE Security & Privacy\u00a09, 41\u201347 (2011)","journal-title":"IEEE Security & Privacy"},{"key":"2_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1007\/978-3-642-14192-8_13","volume-title":"Requirements Engineering: Foundation for Software Quality","author":"K. Villela","year":"2010","unstructured":"Villela, K., D\u00f6rr, J., John, I.: Evaluation of a method for proactively managing the evolving scope of a software product line. In: Wieringa, R., Persson, A. (eds.) REFSQ 2010. LNCS, vol.\u00a06182, pp. 113\u2013127. Springer, Heidelberg (2010)"},{"key":"2_CR19","doi-asserted-by":"crossref","unstructured":"Villela, K., D\u00f6rr, J., Gross, A.: Proactively managing the evolution of embedded system requirements. In: Proceeding of the 16th IEEE International Requirements Engineering Conference (RE), pp. 13\u201322. IEEE Computer Society (2008)","DOI":"10.1109\/RE.2008.57"},{"key":"2_CR20","doi-asserted-by":"publisher","first-page":"758","DOI":"10.1109\/32.6156","volume":"14","author":"V. Basili","year":"1988","unstructured":"Basili, V., Rombach, H.: The TAME project: Towards improvement-oriented software environments. IEEE Transactions on Software Engineering\u00a014, 758\u2013773 (1988)","journal-title":"IEEE Transactions on Software Engineering"},{"key":"2_CR21","doi-asserted-by":"crossref","unstructured":"McGee, S., Greer, D.: Software requirements change taxonomy: Evaluation by case study. In: Proceeding of the 19th IEEE International Requirements Engineering Conference (RE), pp. 25\u201334 (2011)","DOI":"10.1109\/RE.2011.6051641"},{"key":"2_CR22","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/s10664-008-9102-8","volume":"14","author":"P. Runeson","year":"2009","unstructured":"Runeson, P., Host, M.: Guidelines for conducting and reporting case study research in software engineering. Empirical Software Engineering\u00a014, 131\u2013164 (2009)","journal-title":"Empirical Software Engineering"},{"key":"2_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1007\/978-3-642-02050-6_5","volume-title":"Requirements Engineering: Foundation for Software Quality","author":"A. Herrmann","year":"2009","unstructured":"Herrmann, A., Walln\u00f6fer, A., Paech, B.: Specifying changes only \u2014 a case study on delta requirements. In: Glinz, M., Heymans, P. (eds.) REFSQ 2009 Amsterdam. LNCS, vol.\u00a05512, pp. 45\u201358. Springer, Heidelberg (2009)"},{"key":"2_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-540-73031-6_3","volume-title":"Requirements Engineering: Foundation for Software Quality","author":"C. Ncube","year":"2007","unstructured":"Ncube, C., Lockerbie, J., Maiden, N.: Automatically generating requirements from i* models: Experiences with a complex airport operations system. In: Sawyer, P., Paech, B., Heymans, P. (eds.) REFSQ 2007. LNCS, vol.\u00a04542, pp. 33\u201347. Springer, Heidelberg (2007)"},{"key":"2_CR25","doi-asserted-by":"crossref","unstructured":"Maiden, N., Robertson, S.: Integrating creativity into requirements processes: Experiences with an air traffic management system. In: Proceeding of the 13th IEEE International Requirements Engineering Conference (RE), pp. 105\u2013116 (2005)","DOI":"10.1109\/RE.2005.34"},{"key":"2_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"368","DOI":"10.1007\/978-3-540-25975-6_27","volume-title":"Advanced Information Systems Engineering","author":"N..A.M. Maiden","year":"2004","unstructured":"Maiden, N.A.M., Jones, S.V., Manning, S., Greenwood, J., Renou, L.: Model-driven requirements engineering: Synchronising models in an air traffic management case study. In: Persson, A., Stirna, J. (eds.) CAiSE 2004. LNCS, vol.\u00a03084, pp. 368\u2013383. Springer, Heidelberg (2004)"},{"key":"2_CR27","doi-asserted-by":"publisher","first-page":"145","DOI":"10.1016\/S0140-6736(02)07373-7","volume":"359","author":"D. Grimes","year":"2002","unstructured":"Grimes, D., Schulz, K.: Descriptive studies: what they can and cannot do. The Lancet\u00a0359, 145\u2013149 (2002)","journal-title":"The Lancet"},{"key":"2_CR28","doi-asserted-by":"crossref","unstructured":"Davis, F.D.: Perceived usefulness, perceived ease of use, and user acceptance of information technology. MIS Quarterly, 319\u2013340 (1989)","DOI":"10.2307\/249008"},{"key":"2_CR29","doi-asserted-by":"publisher","first-page":"985","DOI":"10.1080\/01621459.1973.10481460","volume":"68","author":"W.J. Conover","year":"1973","unstructured":"Conover, W.J.: On methods of handling ties in the wilcoxon signed-rank test. Journal of the American Statistical Association\u00a068, 985\u2013988 (1973)","journal-title":"Journal of the American Statistical Association"},{"key":"2_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1007\/978-3-642-21640-4_7","volume-title":"Advanced Information Systems Engineering","author":"L.M.S. Tran","year":"2011","unstructured":"Tran, L.M.S., Massacci, F.: Dealing with known unknowns: Towards a game-theoretic foundation for software requirement evolution. In: Mouratidis, H., Rolland, C. (eds.) CAiSE 2011. LNCS, vol.\u00a06741, pp. 62\u201376. Springer, Heidelberg (2011)"},{"key":"2_CR31","unstructured":"Tran, L.M.S.: Managing the Uncertainty of the Evolution of Requirements Model. PhD thesis, University of Trento (2014)"},{"key":"2_CR32","unstructured":"Moody, D.L.: The method evaluation model: A theoretical model for validating information systems design methods. In: Proceeding of the European Conference on Information Systems (ECIS), pp. 1327\u20131336 (2003)"},{"key":"2_CR33","doi-asserted-by":"crossref","unstructured":"Mens, T., Wermelinger, M., Ducasse, S., Demeyer, S., Hirschfeld, R., Jazayeri, M.: Challenges in software evolution. In: Proceeding of the 8th International Workshop on Principles of Software Evolution, pp. 13\u201322 (2005)","DOI":"10.1109\/IWPSE.2005.7"},{"key":"2_CR34","unstructured":"Si* Tool website: http:\/\/sesa.dit.unitn.it\/sistar_tool"},{"key":"2_CR35","unstructured":"Topcased UML editor: http:\/\/www.topcased.org\/"},{"key":"2_CR36","doi-asserted-by":"publisher","first-page":"309","DOI":"10.1023\/A:1009844119158","volume":"5","author":"W. Tichy","year":"2000","unstructured":"Tichy, W.: Hints for reviewing empirical work in software engineering. Empirical Software Engineering\u00a05, 309\u2013312 (2000)","journal-title":"Empirical Software Engineering"},{"key":"2_CR37","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1007\/s10664-009-9109-9","volume":"15","author":"J. Carver","year":"2010","unstructured":"Carver, J., Jaccheri, L., Morasca, S.: A checklist for integrating student empirical studies with research and teaching goals. Empirical Software Engineering\u00a015, 35\u201359 (2010)","journal-title":"Empirical Software Engineering"},{"key":"2_CR38","unstructured":"Runeson, P.: Using students as experiment subjects - an analysis on graduate and freshmen student data. In: Proceeding of the International Conference on Empirical Assessment in Software Engineering (EASE), pp. 95\u2013102 (2003)"},{"key":"2_CR39","unstructured":"van den Berghe, A., Scandariato, R., Joosen, W.: Towards a systematic literature review on secure software design. In: Doctoral Symposium of the International Symposium on Engineering Secure Software and Systems, ESSoS-DS (2013)"}],"container-title":["Lecture Notes in Computer Science","Engineering Secure Future Internet Services and Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-07452-8_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,3]],"date-time":"2025-05-03T00:32:35Z","timestamp":1746232355000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-07452-8_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319074511","9783319074528"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-07452-8_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014]]}}}