{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T00:21:13Z","timestamp":1740097273231,"version":"3.37.3"},"publisher-location":"Cham","reference-count":24,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319453200"},{"type":"electronic","value":"9783319453217"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-45321-7_15","type":"book-chapter","created":{"date-parts":[[2016,9,7]],"date-time":"2016-09-07T05:13:41Z","timestamp":1473225221000},"page":"204-219","source":"Crossref","is-referenced-by-count":1,"title":["Auditing Security of Information Flows"],"prefix":"10.1007","author":[{"given":"Dmitrijs","family":"Kozlovs","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marite","family":"Kirikova","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,9,8]]},"reference":[{"key":"15_CR1","doi-asserted-by":"crossref","unstructured":"Schmitt, C., Liggesmeyer, P.: Getting grip on security requirements elicitation by structuring and reusing security requirements sources. In: Complex Systems Informatics and Modeling Quarterly, CSIMQ, 2015, No. 3, pp. 15\u201334 (2015). http:\/\/dx.doi.org\/10.7250\/csimq.2015-3.02","DOI":"10.7250\/csimq.2015-3.02"},{"key":"15_CR2","unstructured":"Information Systems Audit and Control Association, Glossary of Terms (2015). [cited Nov 2015]. http:\/\/www.isaca.org\/Pages\/Glossary.aspx"},{"key":"15_CR3","doi-asserted-by":"crossref","unstructured":"Ahmed, N., Matulievi\u010dius, R.: A taxonomy for assessing security in business process modelling. In: Research Challenges in Information Science (RCIS), IEEE Seventh International Conference, pp. 1\u201310 (2013)","DOI":"10.1109\/RCIS.2013.6577700"},{"issue":"4","key":"15_CR4","doi-asserted-by":"crossref","first-page":"723","DOI":"10.1016\/j.csi.2013.12.007","volume":"36","author":"N Ahmed","year":"2013","unstructured":"Ahmed, N., Matulievi\u010dius, R.: Securing business processes using security risk-oriented patterns. Comput. Stand. Interfaces 36(4), 723\u2013733 (2013). Elsevier B.V.","journal-title":"Comput. Stand. Interfaces"},{"key":"15_CR5","unstructured":"Wonnemann, C.: Towards information flow auditing in workflows. In: Software Engineering Workshops (2010)"},{"key":"15_CR6","unstructured":"Office of the Chief Information Officer, Washington State Standard No. 141.10: Securing Information Technology, Washington D.C., USA, August 2013, p. 29 (2013)"},{"key":"15_CR7","unstructured":"U.S. Department of Commerce & National Institute of Standards and Technology. Managing Information Security Risk: Organization, Mission, and Information System View- Information Security, Gaithersburg, p. 88 (2011)"},{"key":"15_CR8","unstructured":"Jarockin, V.: Information Security, 5th edn. (2015) (in Russian)"},{"key":"15_CR9","unstructured":"Gartner Inc., IT Glossary. (2015) http:\/\/www.gartner.com\/it-glossary\/"},{"key":"15_CR10","unstructured":"National Archives, Identifying Information Assets and Business Requirements. http:\/\/www.nationalarchives.gov.uk\/documents\/information-management\/identify-information-assets.pdf"},{"key":"15_CR11","unstructured":"IT Governance Institute, Control Objectives for Information and related Technology 4.1, p. 213 (2007)"},{"key":"15_CR12","unstructured":"Sandkuhl, K., Matulevi\u010dius, R., Kirikova, M., Ahmed, N.: Integration of it-security aspects into information demand analysis and patterns. In: Proceedings of the BIR 2015 Workshops and Doctoral Consortium Co-located with 14th International Conference on Perspectives in Business Informatics Research (BIR 2015), Tartu, Estonia, 26\u201328 August 2015, vol. 1420, pp. 36\u201347 (2015). Ceur-ws.org"},{"key":"15_CR13","unstructured":"ISO\/IEC, Common Criteria for Information Technology Security Evaluation. Part 2: Security functional requirements, p. 325 (2005)"},{"key":"15_CR14","unstructured":"ISO\/IEC, Common Criteria for Information Technology Security Evaluation. Part 3: Security assurance components, p. 233 (2012)"},{"key":"15_CR15","unstructured":"Rihtikova, N.: Organizational risk analysis and management, FORUM (2009) (in Russian)"},{"key":"15_CR16","unstructured":"Verdina, G.: Possibilities to improve internal control system in educational context, p. 252. Ph.D. Thesis, University of Latvia, Riga, Latvia (2012)"},{"key":"15_CR17","unstructured":"Caralli, R.A., Stevens, J.F., Young, L.R., Wilson, W.R.: Introducing OCTAVE Allegro: Improving the Information Security Risk Assessment Process, p. 154. Software Engineering Institute, Hanscom (2007). CMU\/SEI-2007-TR-012 ESC-TR-2007-012"},{"key":"15_CR18","unstructured":"N\u00f8rgaard, H., K\u00fchn, T.: EY Danmark, Presentation: Risikobaseret tilgang til revision (Use of Risk Based Concepts for Financial Statement Assurance), Copenhagen, p. 55 (2013)"},{"key":"15_CR19","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-642-33143-5","volume-title":"Fundamentals of Business Process Management","author":"M Dumas","year":"2013","unstructured":"Dumas, M., La Rosa, M., Mendling, J., Reijers, H.: Fundamentals of Business Process Management. Springer, Heidelberg (2013)"},{"key":"15_CR20","doi-asserted-by":"crossref","unstructured":"Accorsi, R., Stocker, T., Muller, G.: On the exploitation of process mining for security audits: the process discovery case. In: SAC 2013, 18\u201322 March 2013, Coimbra, Portugal (2013)","DOI":"10.1145\/2480362.2480634"},{"key":"15_CR21","unstructured":"Information Systems Audit and Control Association. In: IT Standards, Guidelines, and Tools and Techniques for Audit and Assurance and Control (2010). http:\/\/www.isaca.org\/Knowledge-Center\/Standards\/Documents\/IT-Audit-Assurance-Guidance-1March2010.pdf"},{"key":"15_CR22","unstructured":"Kozlovs, D., Cjaputa, K., Kirikova, M.: Towards continuous information security audit. In: Joint Proceedings of REFSQ-2016 Workshops, Doctoral Symposium, Research Method Track, and Poster Track Co-located with the 22nd International Conference on Requirements Engineering: Foundation for Software Quality (REFSQ) (2016)"},{"key":"15_CR23","unstructured":"German Federal Office for Information Security, Information Security Audit (IS Audit): A guideline for IS audits based on IT-Grundshutz, Bonn, p. 38 (2008)"},{"key":"15_CR24","unstructured":"Information Systems Audit and Control Association. Auditing Global Compliance of Data. Protection Mechanisms. In: ISACA Journal Volume 6 \u201cEmerging and Evolving IT Risk\u201d, pp. 46\u201349 (2011)"}],"container-title":["Lecture Notes in Business Information Processing","Perspectives in Business Informatics Research"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-45321-7_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,24]],"date-time":"2017-06-24T18:07:46Z","timestamp":1498327666000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-45321-7_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319453200","9783319453217"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-45321-7_15","relation":{},"ISSN":["1865-1348","1865-1356"],"issn-type":[{"type":"print","value":"1865-1348"},{"type":"electronic","value":"1865-1356"}],"subject":[],"published":{"date-parts":[[2016]]}}}