{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T14:54:06Z","timestamp":1774536846412,"version":"3.50.1"},"publisher-location":"Cham","reference-count":27,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319462622","type":"print"},{"value":"9783319462639","type":"electronic"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-46263-9_5","type":"book-chapter","created":{"date-parts":[[2016,9,7]],"date-time":"2016-09-07T09:21:47Z","timestamp":1473240107000},"page":"80-93","source":"Crossref","is-referenced-by-count":10,"title":["Bridging Two Worlds: Reconciling Practical Risk Assessment Methodologies with Theory of Attack Trees"],"prefix":"10.1007","author":[{"given":"Olga","family":"Gadyatskaya","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Carlo","family":"Harpes","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sjouke","family":"Mauw","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"C\u00e9dric","family":"Muller","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Steve","family":"Muller","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,9,8]]},"reference":[{"key":"5_CR1","doi-asserted-by":"crossref","unstructured":"Albanese, M., Jajodia, S., Noel, S.: Time-efficient and cost-effective network hardening using attack graphs. In: 2012 42nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 1\u201312. IEEE (2012)","DOI":"10.1109\/DSN.2012.6263942"},{"key":"5_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"95","DOI":"10.1007\/978-3-662-46666-7_6","volume-title":"Principles of Security and Trust","author":"Z Aslanyan","year":"2015","unstructured":"Aslanyan, Z., Nielson, F.: Pareto efficient solutions of attack-defence trees. In: Focardi, R., Myers, A. (eds.) POST 2015. LNCS, vol. 9036, pp. 95\u2013114. Springer, Heidelberg (2015)"},{"key":"5_CR3","doi-asserted-by":"crossref","unstructured":"Bistarelli, S., Fioravanti, F., Peretti, P.: Defense trees for economic evaluation of security investments. In: The First International Conference on Availability, Reliability and Security, 2006 ARES 2006, pp. 8-pp. IEEE (2006)","DOI":"10.1109\/ARES.2006.46"},{"key":"5_CR4","unstructured":"Bundesamt fur Sicherheit in der Informationstechnik: IT-Grundschutz-Catalogues, 13th version (2013)"},{"key":"5_CR5","doi-asserted-by":"crossref","unstructured":"Edge, K.S., Dalton, G.C., Raines, R.A., Mills, R.F., et al.: Using attack and protection trees to analyze threats and defenses to homeland security. In: Military Communications Conference 2006. MILCOM 2006, pp. 1\u20137. IEEE (2006)","DOI":"10.1109\/MILCOM.2006.302512"},{"key":"5_CR6","unstructured":"European Organization for Safety of Air Navigation: Threats, Pre-controls and post-controls catalogues (2009)"},{"key":"5_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1007\/978-3-319-29968-6_4","volume-title":"Graphical Models for Security","author":"O Gadyatskaya","year":"2016","unstructured":"Gadyatskaya, O.: How to generate security cameras: towards defence generation for socio-technical systems. In: Mauw, S., et al. (eds.) GraMSec 2015. LNCS, vol. 9390, pp. 50\u201365. Springer, Heidelberg (2016). doi: 10.1007\/978-3-319-29968-6_4"},{"key":"5_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/978-3-319-43425-4_10","volume-title":"Quantitative Evaluation of Systems","author":"O Gadyatskaya","year":"2016","unstructured":"Gadyatskaya, O., Jhawar, R., Kordy, P., Lounis, K., Mauw, S., Trujillo-Rasua, R.: Attack trees for practical security assessment: ranking of attack scenarios with ADTool 2.0. In: Agha, G., Van Houdt, B. (eds.) QEST 2016. LNCS, vol. 9826, pp. 159\u2013162. Springer, Heidelberg (2016). doi: 10.1007\/978-3-319-43425-4_10"},{"key":"5_CR9","unstructured":"Harpes, C., Adelsbach, A., Zatti, S., Peccia, N.: Quantitative risk assessment with ISAMM on ESA\u2019s operations data system. In: Proceedings of TTC (2007)"},{"key":"5_CR10","unstructured":"ISO: 27799:2008 Health Informatics - Information security management in health using ISO\/IEC 27002 (2008)"},{"key":"5_CR11","unstructured":"ISO, IEC: 27005:2011 Information technology Security techniques Information security risk management (2011)"},{"key":"5_CR12","unstructured":"ISO, IEC: 27001:2013 Information technology - Security techniques - Information security management systems - Requirements (2013)"},{"key":"5_CR13","unstructured":"ISO, IEC: 27002:2013 Information technology Security techniques Code of practice for information security controls (2013)"},{"key":"5_CR14","unstructured":"ISO, IEC: TR 27019:2013 Information technology Security techniques Information security management guidelines based on ISO\/IEC 27002 for process control systems specific to the energy utility industry (2013)"},{"key":"5_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"173","DOI":"10.1007\/978-3-642-40196-1_15","volume-title":"Quantitative Evaluation of Systems","author":"B Kordy","year":"2013","unstructured":"Kordy, B., Kordy, P., Mauw, S., Schweitzer, P.: ADTool: security analysis with attack\u2013defense trees. In: Joshi, K., Siegle, M., Stoelinga, M., D\u2019Argenio, P.R. (eds.) QEST 2013. LNCS, vol. 8054, pp. 173\u2013176. Springer, Heidelberg (2013)"},{"issue":"1","key":"5_CR16","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1093\/logcom\/exs029","volume":"24","author":"B Kordy","year":"2014","unstructured":"Kordy, B., Mauw, S., Radomirovi\u0107, S., Schweitzer, P.: Attack-defense trees. J. Logic Comput. 24(1), 55\u201387 (2014)","journal-title":"J. Logic Comput."},{"key":"5_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"186","DOI":"10.1007\/11734727_17","volume-title":"Information Security and Cryptology - ICISC 2005","author":"S Mauw","year":"2006","unstructured":"Mauw, S., Oostdijk, M.: Foundations of attack trees. In: Won, D.H., Kim, S. (eds.) ICISC 2005. LNCS, vol. 3935, pp. 186\u2013198. Springer, Heidelberg (2006)"},{"key":"5_CR18","unstructured":"NATO Research and Technology Organisation (RTO): Improving common security risk analysis (2008)"},{"key":"5_CR19","unstructured":"NIST: Special Publication 800\u201353 Revision 4. Security and privacy controls for federal information systems and organizations (2013). http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-53r4.pdf"},{"key":"5_CR20","unstructured":"NIST: Framework for Improving Critical Infrastructure Cybersecurity (2014)"},{"key":"5_CR21","unstructured":"OWASP: CISO AppSec Guide: Criteria for managing application security risks (2013)"},{"key":"5_CR22","unstructured":"PCI Security Standards Council: Payment Card Industry Data Security Standards (PCI DSS) (2016). https:\/\/www.pcisecuritystandards.org\/"},{"key":"5_CR23","unstructured":"PWC: The global state of information security survey (2016). http:\/\/www.pwc.com\/gx\/en\/issues\/cyber-security\/information-security-survey.html"},{"key":"5_CR24","series-title":"Springer Briefs in Computer Science","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-319-23570-7","volume-title":"Cyber-Risk Management","author":"A Refsdal","year":"2015","unstructured":"Refsdal, A., Solhaug, B., St\u00f8len, K.: Cyber-Risk Management. Springer Briefs in Computer Science. Springer International Publishing, Heidelberg (2015)"},{"key":"5_CR25","doi-asserted-by":"crossref","unstructured":"Roy, A., Kim, D.S., Trivedi, K.S.: Scalable optimal countermeasure selection using implicit enumeration on attack countermeasure trees. In: Proceedings of the 42nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, pp. 299\u2013310. IEEE (2012)","DOI":"10.1109\/DSN.2012.6263940"},{"key":"5_CR26","first-page":"21","volume":"24","author":"B Schneier","year":"1999","unstructured":"Schneier, B.: Attack trees. Dr. Dobb\u2019s J. Softw. Tools 24, 21\u201329 (1999)","journal-title":"Dr. Dobb\u2019s J. Softw. Tools"},{"key":"5_CR27","unstructured":"TREsPASS: Technology-supported Risk Estimation by Predictive Assessment of Socio-technical Security (2016). http:\/\/www.trespass-project.eu\/"}],"container-title":["Lecture Notes in Computer Science","Graphical Models for Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-46263-9_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,24]],"date-time":"2017-06-24T22:07:46Z","timestamp":1498342066000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-46263-9_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319462622","9783319462639"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-46263-9_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]}}}