{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T07:35:43Z","timestamp":1761896143651},"publisher-location":"Cham","reference-count":20,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319246468"},{"type":"electronic","value":"9783319246475"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-24647-5_8","type":"book-chapter","created":{"date-parts":[[2015,9,21]],"date-time":"2015-09-21T16:12:14Z","timestamp":1442851934000},"page":"87-99","source":"Crossref","is-referenced-by-count":7,"title":["An ISO Compliant and Integrated Model for IT GRC (Governance, Risk Management and Compliance)"],"prefix":"10.1007","author":[{"given":"Nicolas","family":"Mayer","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"B\u00e9atrix","family":"Barafort","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michel","family":"Picard","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"St\u00e9phane","family":"Cortina","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,9,22]]},"reference":[{"key":"8_CR1","doi-asserted-by":"crossref","unstructured":"Peterson, R.R.: Integration strategies and tactics for information technology governance. In: Strategies for Information Technology Governance, pp. 37\u201380. Idea Group Publishing, Hershey (2004)","DOI":"10.4018\/978-1-59140-140-7.ch002"},{"key":"8_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1007\/978-3-642-13241-4_11","volume-title":"Communications and Multimedia Security","author":"N Racz","year":"2010","unstructured":"Racz, N., Weippl, E., Seufert, A.: A frame of reference for research of integrated governance, risk and compliance (GRC). In: De Decker, B., Schaum\u00fcller-Bichl, I. (eds.) CMS 2010. LNCS, vol. 6109, pp. 106\u2013117. Springer, Heidelberg (2010)"},{"key":"8_CR3","volume-title":"Governance, Risk and Compliance for Information Systems: Towards an Integrated Approach","author":"N Racz","year":"2011","unstructured":"Racz, N.: Governance, Risk and Compliance for Information Systems: Towards an Integrated Approach. Sudwestdeutscher Verlag Fur Hochschulschriften AG, Saarbr\u00fccken (2011)"},{"key":"8_CR4","doi-asserted-by":"crossref","unstructured":"Vicente, P., da Silva, M.M.: A business viewpoint for integrated IT governance, risk and compliance. In: 2011 IEEE World Congress on Services (SERVICES), pp. 422\u2013428 (2011)","DOI":"10.1109\/SERVICES.2011.62"},{"key":"8_CR5","unstructured":"ISO\/IEC 38500:2015: Information technology - Governance of IT for the organization. International Organization for Standardization, Geneva (2015)"},{"key":"8_CR6","unstructured":"ISO 31000:2009: Risk management \u2013 Principles and guidelines. International Organization for Standardization, Geneva (2009)"},{"key":"8_CR7","unstructured":"ISO 19600:2014: Compliance management systems \u2014 Guidelines. International Organization for Standardization, Geneva (2014)"},{"key":"8_CR8","unstructured":"Committee of Sponsoring Organizations of the Treadway Commission: Enterprise Risk Management \u2013 Integrated Framework (Executive Summary and Framework). Committee of Sponsoring Organizations of the Treadway Commission (2004)"},{"key":"8_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1007\/978-3-642-21640-4_16","volume-title":"Advanced Information Systems Engineering","author":"P Vicente","year":"2011","unstructured":"Vicente, P., Mira da Silva, M.: A conceptual model for integrated governance, risk and compliance. In: Mouratidis, H., Rolland, C. (eds.) CAiSE 2011. LNCS, vol. 6741, pp. 199\u2013213. Springer, Heidelberg (2011)"},{"key":"8_CR10","unstructured":"The Open Group: ArchiMate 2.0 Specification. Van Haren Publishing, The Netherlands (2012)"},{"key":"8_CR11","unstructured":"OCEG: GRC Capability Model (Red Book 2.1) (2012). \n                    http:\/\/goo.gl\/7nrKku"},{"key":"8_CR12","unstructured":"ISACA: COBIT 5: A Business Framework for the Governance and Management of Enterprise IT (2012)"},{"key":"8_CR13","doi-asserted-by":"crossref","unstructured":"Gericke, A., Fill, H.-G., Karagiannis, D., Winter, R.: Situational method engineering for governance, risk and compliance information systems. In: Proceedings of the 4th International Conference on Design Science Research in Information Systems and Technology, pp. 24:1\u201324:12. ACM, New York (2009)","DOI":"10.1145\/1555619.1555651"},{"key":"8_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"152","DOI":"10.1007\/978-3-642-23082-0_6","volume-title":"Foundations of Security Analysis and Design VI","author":"Y Asnar","year":"2011","unstructured":"Asnar, Y., Massacci, F.: A method for security governance, risk, and compliance (GRC): a goal-process approach. In: Aldini, A., Gorrieri, R. (eds.) FOSAD 2011. LNCS, vol. 6858, pp. 152\u2013184. Springer, Heidelberg (2011)"},{"key":"8_CR15","unstructured":"RSA: The RSA GRC Reference Architecture (2013)"},{"key":"8_CR16","first-page":"20","volume":"90","author":"ML Frigo","year":"2009","unstructured":"Frigo, M.L., Anderson, R.J.: A strategic framework for governance, risk, and compliance. Strateg. Finance 90, 20\u201361 (2009)","journal-title":"Strateg. Finance"},{"key":"8_CR17","unstructured":"Paulus, S.: Overview Report: A GRC Reference Architecture (2009)"},{"key":"8_CR18","doi-asserted-by":"crossref","unstructured":"Krey, M., Furnell, S., Harriehausen, B., Knoll, M.: Approach to the Evaluation of a Method for the Adoption of Information Technology Governance, Risk Management and Compliance in the Swiss Hospital Environment. In: 2012 45th Hawaii International Conference on System Science (HICSS), pp. 2810\u20132819 (2012)","DOI":"10.1109\/HICSS.2012.118"},{"key":"8_CR19","unstructured":"ISO\/IEC TR 38502:2014: Information technology - Governance of IT - Framework and model. International Organization for Standardization, Geneva (2014)"},{"key":"8_CR20","unstructured":"ISO\/IEC 27005:2011: Information technology \u2013 Security techniques \u2013 Information security risk management. International Organization for Standardization, Geneva (2011)"}],"container-title":["Communications in Computer and Information Science","Systems, Software and Services Process Improvement"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-24647-5_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,30]],"date-time":"2019-05-30T21:00:26Z","timestamp":1559250026000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-24647-5_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319246468","9783319246475"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-24647-5_8","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2015]]}}}