{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,30]],"date-time":"2025-12-30T23:40:15Z","timestamp":1767138015438,"version":"build-2238731810"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319117096","type":"print"},{"value":"9783319117102","type":"electronic"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-11710-2_3","type":"book-chapter","created":{"date-parts":[[2014,10,6]],"date-time":"2014-10-06T02:16:50Z","timestamp":1412561810000},"page":"24-35","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Security Risk Assessment Challenges in Port Information Technology Systems"],"prefix":"10.1007","author":[{"given":"Georgios","family":"Makrodimitris","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nineta","family":"Polemi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christos","family":"Douligeris","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,10,7]]},"reference":[{"key":"3_CR1","doi-asserted-by":"crossref","unstructured":"Adler, R., Fuller, J.: An integrated framework for assessing and mitigating risks to maritime critical infrastructure. In: Proceedings of IEEE Conference on Technologies for Home-land Security, pp. 252\u2013257 (2007)","DOI":"10.1109\/THS.2007.370054"},{"key":"3_CR2","unstructured":"Alberts, C., Dorofee, A.: Operationally critical threat, asset, and vulnerability evaluation (OCTAVE) method implementation guide, v2.0. Software Engineering Institute, Carnegie Mellon University (2001). http:\/\/www.cert.org\/octave\/"},{"issue":"15\u201316","key":"3_CR3","doi-asserted-by":"publisher","first-page":"1278","DOI":"10.1016\/j.oceaneng.2009.07.003","volume":"36","author":"J Balmat","year":"2009","unstructured":"Balmat, J., Lafont, F., Maifret, R., Pessel, N.: MAritime RISk Assessment (MARISA), a fuzzy approach to define an individual ship risk factor. Ocean Eng. 36(15\u201316), 1278\u20131286 (2009)","journal-title":"Ocean Eng."},{"key":"3_CR4","unstructured":"BSI Standard 100-1: Information Security Management Systems (ISMS) (2005). www.bsi.bund.de"},{"key":"3_CR5","unstructured":"BSI Standard 100-2.: IT - Grundszchutz methodology (2005). www.bsi.bund.de"},{"key":"3_CR6","unstructured":"BSI Standard 100-3: Risk analysis based on IT\u2013Grundszchutz (2005). www.bsi.bund.de"},{"key":"3_CR7","unstructured":"Club de la Securite de L\u2019 information Francais Methods Commision: Mehari 2010: Risk analysis and treatment Guide, France, August 2010 (2010). http:\/\/www.clusif.asso.fr\/fr\/production\/ouvrages\/pdf\/MEHARI-2010-Risk-Analysis-and-Treatment-Guide.pdf"},{"key":"3_CR8","volume-title":"MAGERIT \u2013 Version 2, Methodology for Information Systems Risk Analysis and Management, Books I \u2013 The Method","author":"F Crespo","year":"2006","unstructured":"Crespo, F., Gomez, M., Candau, J., Manas, J.A.: MAGERIT \u2013 Version 2, Methodology for Information Systems Risk Analysis and Management, Books I \u2013 The Method. Ministerio de Administraciones Publicas, Madrid (2006)"},{"key":"3_CR9","volume-title":"MAGERIT \u2013 Version 2, Methodology for Information Systems Risk Analysis and Management, Book III \u2013 Techniques","author":"F Crespo","year":"2006","unstructured":"Crespo, F., Gomez, M., Candau, J., Manas, J.A.: MAGERIT \u2013 Version 2, Methodology for Information Systems Risk Analysis and Management, Book III \u2013 Techniques. Ministerio de Administraciones Publicas, Madrid (2006)"},{"key":"3_CR10","volume-title":"MAGERIT \u2013 Version 2, Methodology for Information Systems Risk Analysis and Management, Book II \u2013 Catalogue of Elements","author":"F Crespo","year":"2006","unstructured":"Crespo, F., Gomez, M., Candau, J., Manas, J.A.: MAGERIT \u2013 Version 2, Methodology for Information Systems Risk Analysis and Management, Book II \u2013 Catalogue of Elements. Ministerio de Administraciones Publicas, Madrid (2006)"},{"key":"3_CR11","unstructured":"Downs, \u0392.: The maritime security risk analysis model. In: USCG Proceedings of the Marine Safety and Security Council (2007). http:\/\/www.uscg.mil\/proceedings\/"},{"key":"3_CR12","unstructured":"Ebios: Expression of Needs and Identification of Security Objectives Premier Ministre Secr\u00e9tariat g\u00e9n\u00e9ral de la d\u00e9fense nationale Direction centrale de la s\u00e9curit\u00e9 des syst\u00e8mes d\u2019information Sous-direction des op\u00e9rations Bureau conseil (2010). www.ssi.gouv.fr"},{"key":"3_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"428","DOI":"10.1007\/978-3-642-33260-9_37","volume-title":"Computer Information Systems and Industrial Management","author":"I El Fray","year":"2012","unstructured":"El Fray, I.: A comparative study of risk assessment methods, MEHARI & CRAMM with a new formal model of risk assessment (FoMRA) in information systems. In: Cortesi, A., Chaki, N., Saeed, K., Wierzcho\u0144, S. (eds.) CISIM 2012. LNCS, vol. 7564, pp. 428\u2013442. Springer, Heidelberg (2012)"},{"key":"3_CR14","doi-asserted-by":"crossref","unstructured":"Elachgar, H., Regragui, B.: Information Security, new approach. In: Conference on Innovative Computing Technology (INTECH). IEEE (2012)","DOI":"10.1109\/INTECH.2012.6457815"},{"key":"3_CR15","unstructured":"Analysis of cyber security aspects in the maritime sector. ENISA report (2011). http:\/\/www.enisa.europa.eu\/act\/res\/other-areas\/cyber-security-aspects-in-the-maritime-sector\/cyber-security-aspects-in-the-maritime-sector-1. Accessed 4 Mar 2014"},{"key":"3_CR16","unstructured":"Insight Consulting: CRAMM User Guide. Issue 5.1, United Kingdom (2005)"},{"key":"3_CR17","unstructured":"ISAMM - Information Security Assessment & Monitoring Method (2002). http:\/\/www.telindus.com"},{"key":"3_CR18","unstructured":"ISO\/IEC:17799: Information technology - security techniques - code of practice for information security management (2005). http:\/\/www.iso.org"},{"key":"3_CR19","unstructured":"ISO\/IEC:27002: Information technology - security techniques - code of practice for information security management (2005). http:\/\/www.iso.org"},{"key":"3_CR20","unstructured":"ISO\/IEC:27005: Information technology - Security techniques - Information Security Risk Management (2008). http:\/\/www.iso.org"},{"key":"3_CR21","unstructured":"ISO\/IEC:27001: Information technology - Security techniques - Specification for an Information Security Management System (2005). http:\/\/www.iso.org"},{"key":"3_CR22","unstructured":"L\u00f3pez, D., Pastor, O., Garc\u00eda Villalba, L.J.: Dynamic risk assessment in information systems: state-of-the-art. In: ICIT 2013, South Africa (2013)"},{"key":"3_CR23","unstructured":"Maritime Domain Awareness Data Sharing Community of Interest (MDA DS COI). Data Management Working Group, Spiral 2, Vocabulary Handbook Version 2.0.2 (2007). http:\/\/www.uscg.mil\/acquisition\/nais\/RFP\/SectionJ\/MDA-COI-vocab.pdf"},{"key":"3_CR24","unstructured":"National Institute for Standards and Technology: Risk management guide for information technology systems. NIST Special Publication 800-30, USA (2002)"},{"key":"3_CR25","doi-asserted-by":"crossref","unstructured":"Ntouskas, T., Polemi, N.: A secure, collaborative environment for the security management of port information systems. In: Proceedings of the 5th International Conference on the Internet and Web Applications and Services, pp. 374\u2013379. IEEE Press, Spain (2010a)","DOI":"10.1109\/ICIW.2010.62"},{"key":"3_CR26","unstructured":"Ntouskas, T., Polemi, N.: Collaborative security management services for Port Information Systems. In: Proceedings of International Conference on e-Business, pp. 305\u2013308. SciTePress, Italy (2012a)"},{"issue":"2","key":"3_CR27","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1504\/IJMCDM.2012.046941","volume":"2","author":"T Ntouskas","year":"2012","unstructured":"Ntouskas, T., Polemi, N.: STORM-RM: a collaborative and multicriteria risk management methodology. Int. J. Multicriteria Decis. Making 2(2), 159\u2013177 (2012)","journal-title":"Int. J. Multicriteria Decis. Making"},{"key":"3_CR28","unstructured":"Ntouskas, T., Polemi, N.: STORM-RA: an implemented, collaborative, multicriteria decision making risk assessment methodology. In: 7th Meeting Multicriteria Decision Analysis, Greece (2010b)"},{"key":"3_CR29","unstructured":"OCTAVE Method Implementation Guide Version 2.0. Carnegie Mellon University, June 2001 (2010). http:\/\/www.cert.org\/octave\/"},{"key":"3_CR30","unstructured":"Polemi, N.: Security management of the ports\u2019 information systems. ENISA project (2013). http:\/\/www.enisa.europa.eu. Accessed 4 Mar 2014"},{"key":"3_CR31","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"567","DOI":"10.1007\/978-3-642-30436-1_50","volume-title":"Information Security and Privacy Research","author":"N Polemi","year":"2012","unstructured":"Polemi, N., Ntouskas, T.: Open issues and proposals in the IT security management of commercial ports: the S-PORT national case. In: Gritzalis, D., Furnell, S., Theoharidou, M. (eds.) SEC 2012. IFIP AICT, vol. 376, pp. 567\u2013572. Springer, Heidelberg (2012)"},{"key":"3_CR32","doi-asserted-by":"crossref","unstructured":"Syalim, A., Hori, Y., Sakurai, K.: Comparison of risk analysis methods: Mehari, Magerit, NIST800-30 and Microsoft\u2019s Security Management Guide. In: International Conference on Availability, Reliability and Security (2009)","DOI":"10.1109\/ARES.2009.75"}],"container-title":["Communications in Computer and Information Science","E-Democracy, Security, Privacy and Trust in a Digital World"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-11710-2_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,4,2]],"date-time":"2024-04-02T12:27:39Z","timestamp":1712060859000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-11710-2_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319117096","9783319117102"],"references-count":32,"aliases":["10.1007\/978-3-319-14229-6_3"],"URL":"https:\/\/doi.org\/10.1007\/978-3-319-11710-2_3","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014]]},"assertion":[{"value":"7 October 2014","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}