{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,13]],"date-time":"2025-05-13T20:40:06Z","timestamp":1747168806068,"version":"3.40.5"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319125732"},{"type":"electronic","value":"9783319125749"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-12574-9_5","type":"book-chapter","created":{"date-parts":[[2014,11,21]],"date-time":"2014-11-21T13:38:31Z","timestamp":1416577111000},"page":"49-61","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Preserving Compliance with Security Requirements in Socio-Technical Systems"],"prefix":"10.1007","author":[{"given":"Mattia","family":"Salnitri","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elda","family":"Paja","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paolo","family":"Giorgini","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,11,18]]},"reference":[{"key":"5_CR1","unstructured":"Final report on aniketos on industrial case studies. Technical report (2014). http:\/\/aniketos.eu\/sites\/default\/files\/downloads\/Aniketos%20D6.4%20-%20Final%20report%20on%20Aniketos%20%20applied%20to%20industrial%20case%20studies.pdf"},{"key":"5_CR2","unstructured":"Federal Aviation Administration. SWIM ATM case study, Last visited, March 2014. http:\/\/www.faa.gov\/about\/office_org\/headquarters_offices\/ato\/service_units\/techops\/atc_comms_services\/swim\/"},{"key":"5_CR3","volume-title":"Security Engineering: A Guide to Building Dependable Distributed Systems","author":"R Anderson","year":"2008","unstructured":"Anderson, R.: Security Engineering: A Guide to Building Dependable Distributed Systems. Wiley, New York (2008)"},{"issue":"6","key":"5_CR4","doi-asserted-by":"publisher","first-page":"477","DOI":"10.1016\/j.is.2008.02.005","volume":"33","author":"C Beeri","year":"2008","unstructured":"Beeri, C., Eyal, A., Kamenkovich, S., Milo, T.: Querying business processes with BP-QL. Inf. Syst. 33(6), 477\u2013507 (2008)","journal-title":"Inf. Syst."},{"key":"5_CR5","doi-asserted-by":"crossref","unstructured":"Brucker, A.D., Hang, I., L\u00fcckemeyer, G., Ruparel, R.: SecureBPMN: modeling and enforcing access control requirements in business processes. In: Proceedings of SACMAT\u201912, pp. 123\u2013126 (2012)","DOI":"10.1145\/2295136.2295160"},{"key":"5_CR6","doi-asserted-by":"crossref","unstructured":"Cherdantseva, Y., Hilton, J.: A reference model of information assurance and security. In: Proceedings of ARES \u201913, pp. 546\u2013555 (2013)","DOI":"10.1109\/ARES.2013.72"},{"key":"5_CR7","doi-asserted-by":"crossref","unstructured":"Crook, R., Ince, D., Lin, L., Nuseibeh, B.: Security requirements engineering: when anti-requirements hit the fan. In: Proceedings of RE\u201902, pp. 203\u2013205. IEEE (2002)","DOI":"10.1109\/ICRE.2002.1048527"},{"key":"5_CR8","doi-asserted-by":"crossref","unstructured":"Dalpiaz, F., Paja, E., Giorgini, P.: Security requirements engineering via commitments. In: Proceedings of STAST\u201911, pp. 1\u20138 (2011)","DOI":"10.1109\/STAST.2011.6059249"},{"key":"5_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/978-3-540-75987-4_12","volume-title":"Database Programming Languages","author":"D Deutch","year":"2007","unstructured":"Deutch, D., Milo, T.: Querying structural and behavioral properties of business processes. In: Arenas, M. (ed.) DBPL 2007. LNCS, vol. 4797, pp. 169\u2013185. Springer, Heidelberg (2007)"},{"key":"5_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/978-3-540-74974-5_14","volume-title":"Service-Oriented Computing \u2013 ICSOC 2007","author":"AK Ghose","year":"2007","unstructured":"Ghose, A.K., Koliadis, G.: Auditing business process compliance. In: Kr\u00e4mer, B.J., Lin, K.-J., Narasimhan, P. (eds.) ICSOC 2007. LNCS, vol. 4749, pp. 169\u2013180. Springer, Heidelberg (2007)"},{"key":"5_CR11","doi-asserted-by":"crossref","unstructured":"Giorgini, P., Massacci, F., Mylopoulos, J., Zannone, N.: Modeling security requirements through ownership, permission and delegation. In: Proceedings of RE\u201905, pp. 167\u2013176 (2005)","DOI":"10.1109\/RE.2005.43"},{"key":"5_CR12","volume-title":"Business Process Reengineering: Breakpoint Strategies for Market Dominance","author":"HJ Johansson","year":"1993","unstructured":"Johansson, H.J., McHugh, P., Pendlebury, A.J., Wheeler, W.A.: Business Process Reengineering: Breakpoint Strategies for Market Dominance. Wiley and Sons, Chichester (1993)"},{"key":"5_CR13","unstructured":"Johnstone, M.N.: Security requirements engineering-the reluctant oxymoron. In: Proceedings of Australian Information Security Management Conference, p. 5 (2009)"},{"issue":"2","key":"5_CR14","doi-asserted-by":"publisher","first-page":"335","DOI":"10.1147\/sj.462.0335","volume":"46","author":"Y Liu","year":"2007","unstructured":"Liu, Y., M\u00fcller, S., Xu, K.: A static compliance-checking framework for business process models. IBM Syst. J. 46(2), 335\u2013361 (2007)","journal-title":"IBM Syst. J."},{"key":"5_CR15","doi-asserted-by":"crossref","unstructured":"Menzel, M., Thomas, I., Meinel, C.: Security requirements specification in service-oriented business process management. In: Proceedings of ARES \u201909, pp. 41\u201348 (2009)","DOI":"10.1109\/ARES.2009.90"},{"issue":"2","key":"5_CR16","first-page":"285","volume":"17","author":"H Mouratidis","year":"2007","unstructured":"Mouratidis, H., Giorgini, P.: Secure tropos: a security-oriented extension of the tropos methodology. IJSEKE 17(2), 285\u2013309 (2007)","journal-title":"IJSEKE"},{"key":"5_CR17","unstructured":"OMG. BPMN 2.0., Jan 2011. http:\/\/www.omg.org\/spec\/BPMN\/2.0"},{"key":"5_CR18","doi-asserted-by":"crossref","unstructured":"Paja, E., Dalpiaz, F., Giorgini, P.: Managing security requirements conflicts in socio-technical systems. In: Proceedings of ER\u201913, pp. 270\u2013283 (2013)","DOI":"10.1007\/978-3-642-41924-9_23"},{"key":"5_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"504","DOI":"10.1007\/978-3-642-41924-9_45","volume-title":"Conceptual Modeling","author":"E Paja","year":"2013","unstructured":"Paja, E., Dalpiaz, F., Poggianella, M., Roberti, P., Giorgini, P.: Specifying and reasoning over socio-technical security requirements with STS-tool. In: Ng, W., Storey, V.C., Trujillo, J.C. (eds.) ER 2013. LNCS, vol. 8217, pp. 504\u2013507. Springer, Heidelberg (2013)"},{"issue":"4","key":"5_CR20","doi-asserted-by":"publisher","first-page":"745","DOI":"10.1093\/ietisy\/e90-d.4.745","volume":"90","author":"A Rodr\u00edguez","year":"2007","unstructured":"Rodr\u00edguez, A., Fern\u00e1ndez-Medina, E., Piattini, M.: A BPMN extension for the modeling of security requirements in business processes. IEICE Trans. Inf. Syst. 90(4), 745\u2013752 (2007)","journal-title":"IEICE Trans. Inf. Syst."},{"key":"5_CR21","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1016\/S0951-8320(01)00092-8","volume":"75","author":"J Rushby","year":"2002","unstructured":"Rushby, J.: Using model checking to help discover mode confusions and other automation surprises. Reliab. Eng. Syst. Saf. 75, 167\u2013177 (2002)","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"5_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1007\/978-3-540-75183-0_12","volume-title":"Business Process Management","author":"W Sadiq","year":"2007","unstructured":"Sadiq, W., Governatori, G., Namiri, K.: Modeling control objectives for business process compliance. In: Alonso, G., Dadam, P., Rosemann, M. (eds.) BPM 2007. LNCS, vol. 4714, pp. 149\u2013164. Springer, Heidelberg (2007)"},{"issue":"1","key":"5_CR23","doi-asserted-by":"publisher","first-page":"353","DOI":"10.4156\/aiss.vol4.issue1.45","volume":"4","author":"M Saleem","year":"2012","unstructured":"Saleem, M., Jaafar, J., Hassan, M.: A domain- specific language for modelling security objectives in a business process models of SOA applications. AISS 4(1), 353\u2013362 (2012)","journal-title":"AISS"},{"key":"5_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"232","DOI":"10.1007\/978-3-642-33606-5_15","volume-title":"On the Move to Meaningful Internet Systems: OTM 2012","author":"M Salnitri","year":"2012","unstructured":"Salnitri, M., Dalpiaz, F., Giorgini, P.: Aligning service-oriented architectures with security requirements. In: Meersman, R., Panetto, H., Dillon, T., Rinderle-Ma, S., Dadam, P., Zhou, X., Pearson, S., Ferscha, A., Bergamaschi, S., Cruz, I.F. (eds.) OTM 2012, Part I. LNCS, vol. 7565, pp. 232\u2013249. Springer, Heidelberg (2012)"},{"key":"5_CR25","series-title":"Lecture Notes in Business Information Processing","doi-asserted-by":"publisher","first-page":"200","DOI":"10.1007\/978-3-662-43745-2_14","volume-title":"Enterprise, Business-Process and Information Systems Modeling","author":"M Salnitri","year":"2014","unstructured":"Salnitri, M., Dalpiaz, F., Giorgini, P.: Modeling and verifying security policies in business processes. In: Bider, I., Gaaloul, K., Krogstie, J., Nurcan, S., Proper, H.A., Schmidt, R., Soffer, P. (eds.) BPMDS 2014 and EMMSAD 2014. LNBIP, vol. 175, pp. 200\u2013214. Springer, Heidelberg (2014)"},{"key":"5_CR26","doi-asserted-by":"crossref","unstructured":"Salnitri, M., Giorgini, P.: Modeling and verification of ATM security policies with SecBPMN. In: Proceedings of SHPCS\u201914 (2014)","DOI":"10.1109\/HPCSim.2014.6903740"},{"key":"5_CR27","unstructured":"Salnitri, M., Giorgini, P.: Transforming socio-technical security requirements in SecBPMN security policies. In: Proceedings of IStar\u201914 (2014)"},{"issue":"4","key":"5_CR28","first-page":"211","volume":"55","author":"C Wolter","year":"2009","unstructured":"Wolter, C., Menzel, M., Schaad, A., Miseldine, P., Meinel, C.: Model-driven business process security requirement specification. JSA 55(4), 211\u2013223 (2009)","journal-title":"JSA"}],"container-title":["Communications in Computer and Information Science","Cyber Security and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-12574-9_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,13]],"date-time":"2025-05-13T20:12:41Z","timestamp":1747167161000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-12574-9_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319125732","9783319125749"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-12574-9_5","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2014]]},"assertion":[{"value":"18 November 2014","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}