{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T13:30:29Z","timestamp":1780493429942,"version":"3.54.1"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319699035","type":"print"},{"value":"9783319699042","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-69904-2_16","type":"book-chapter","created":{"date-parts":[[2017,10,20]],"date-time":"2017-10-20T05:18:33Z","timestamp":1508476713000},"page":"193-208","source":"Crossref","is-referenced-by-count":29,"title":["Towards an Ontology for Privacy Requirements via a Systematic Literature Review"],"prefix":"10.1007","author":[{"given":"Mohamad","family":"Gharib","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paolo","family":"Giorgini","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"John","family":"Mylopoulos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,10,21]]},"reference":[{"key":"16_CR1","doi-asserted-by":"crossref","unstructured":"Gharib, M., Salnitri, M., Paja, E., Giorgini, P., Mouratidis, H., Pavlidis, M., Ruiz, J.F., Fernandez, S., Della Siria, A.: Privacy requirements: findings and lessons learned in developing a privacy platform. In: The 24th International Requirements Engineering Conference (RE), pp. 256\u2013265. IEEE (2016)","DOI":"10.1109\/RE.2016.13"},{"key":"16_CR2","doi-asserted-by":"crossref","unstructured":"Hong, J.I., Ng, J.D., Lederer, S., Landay, J.A.: Privacy risk models for designing privacy-sensitive ubiquitous computing systems. In: Proceedings of the 5th Conference on Designing Interactive Systems: Processes, Practices, Methods, and Techniques, pp. 91\u2013100. ACM (2004)","DOI":"10.1145\/1013115.1013129"},{"key":"16_CR3","doi-asserted-by":"crossref","unstructured":"Labda, W., Mehandjiev, N., Sampaio, P.: Modeling of privacy-aware business processes in BPMN to protect personal data. In: Proceedings of the 29th Annual ACM Symposium on Applied Computing, pp. 1399\u20131405. ACM (2014)","DOI":"10.1145\/2554850.2555014"},{"issue":"3","key":"16_CR4","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1007\/s00766-008-0067-3","volume":"13","author":"C Kalloniatis","year":"2008","unstructured":"Kalloniatis, C., Kavakli, E., Gritzalis, S.: Addressing privacy requirements in system design: the PriS method. Requirements Eng. 13(3), 241\u2013255 (2008)","journal-title":"Requirements Eng."},{"issue":"2","key":"16_CR5","doi-asserted-by":"publisher","first-page":"285","DOI":"10.1142\/S0218194007003240","volume":"17","author":"H Mouratidis","year":"2007","unstructured":"Mouratidis, H., Giorgini, P.: Secure tropos: a security-oriented extension of the tropos methodology. J. Softw. Eng. Knowl. Eng. 17(2), 285\u2013309 (2007)","journal-title":"J. Softw. Eng. Knowl. Eng."},{"key":"16_CR6","unstructured":"Zannone, N.: A requirements engineering methodology for trust, security, and privacy. Ph.D. thesis, University of Trento (2006)"},{"key":"16_CR7","doi-asserted-by":"publisher","first-page":"477","DOI":"10.2307\/40041279","volume":"154","author":"DJ Solove","year":"2006","unstructured":"Solove, D.J.: A taxonomy of privacy. Univ. Pa. Law Rev. 154, 477\u2013564 (2006)","journal-title":"Univ. Pa. Law Rev."},{"key":"16_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1007\/978-3-319-15618-7_13","volume-title":"Engineering Secure Software and Systems","author":"A Souag","year":"2015","unstructured":"Souag, A., Salinesi, C., Mazo, R., Comyn-Wattiau, I.: A security ontology for security requirements elicitation. In: Piessens, F., Caballero, J., Bielova, N. (eds.) ESSoS 2015. LNCS, vol. 8978, pp. 157\u2013177. Springer, Cham (2015). doi: 10.1007\/978-3-319-15618-7_13"},{"key":"16_CR9","doi-asserted-by":"crossref","unstructured":"Liu, L., Yu, E., Mylopoulos, J.: Security and privacy requirements analysis within a social setting. In: 11th International RE Conference, pp. 151\u2013161. IEEE (2003)","DOI":"10.1109\/ICRE.2003.1232746"},{"key":"16_CR10","first-page":"1","volume":"33","author":"B Kitchenham","year":"2004","unstructured":"Kitchenham, B.: Procedures for performing systematic reviews. UK Keele Univ. 33, 1\u201326 (2004)","journal-title":"UK Keele Univ."},{"key":"16_CR11","unstructured":"Kitchenham, B., Charters, S.: Guidelines for performing systematic literature reviews in software engineering. Technical report, Keele University (2007)"},{"key":"16_CR12","doi-asserted-by":"crossref","unstructured":"Gharib, M., Giorgini, P., Mylopoulos, J.: Ontologies for privacy requirements engineering: a systematic literature review. arXiv preprint arXiv:1611.10097 (2016)","DOI":"10.1007\/978-3-319-69904-2_16"},{"key":"16_CR13","doi-asserted-by":"crossref","unstructured":"Van Lamsweerde, A.: Elaborating security requirements by construction of intentional anti-models. In: Proceedings of the 26th International Conference on Software Engineering, pp. 148\u2013157. IEEE Computer Society (2004)","DOI":"10.1109\/ICSE.2004.1317437"},{"key":"16_CR14","doi-asserted-by":"crossref","unstructured":"Braghin, S., Coen-Porisini, A., Colombo, P., Sicari, S., Trombetta, A.: Introducing privacy in a hospital information system. In: Proceedings of the Fourth International Workshop on Software Engineering for Secure Systems, pp. 9\u201316. ACM (2008)","DOI":"10.1145\/1370905.1370907"},{"key":"16_CR15","doi-asserted-by":"crossref","unstructured":"Singhal, A., Wijesekera, D.: Ontologies for modeling enterprise level security metrics. In: Proceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research, p. 58. ACM (2010)","DOI":"10.1145\/1852666.1852731"},{"key":"16_CR16","doi-asserted-by":"crossref","unstructured":"Wang, J.A., Guo, M.: OVM: an ontology for vulnerability management. In: Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research, p. 34. ACM (2009)","DOI":"10.1145\/1558607.1558646"},{"issue":"2","key":"16_CR17","first-page":"119","volume":"41","author":"JL Velasco","year":"2009","unstructured":"Velasco, J.L., Valencia-Garc\u00eda, R., Fern\u00e1ndez-Breis, J.T., Toval, A., et al.: Modelling reusable security requirements based on an ontology framework. J. Res. Pract. Inf. Technol. 41(2), 119 (2009)","journal-title":"J. Res. Pract. Inf. Technol."},{"key":"16_CR18","doi-asserted-by":"crossref","unstructured":"Souag, A., Salinesi, C., Wattiau, I., Mouratidis, H.: Using security and domain ontologies for security requirements analysis. In: Computer Software and Applications Conference Workshops (COMPSACW), pp. 101\u2013107. IEEE (2013)","DOI":"10.1109\/COMPSACW.2013.124"},{"key":"16_CR19","doi-asserted-by":"crossref","unstructured":"Tsoumas, B., Gritzalis, D.: Towards an ontology-based security management. In: 20th International Conference on Advanced Information Networking and Applications (AINA), vol. 1, pp. 985\u2013992. IEEE (2006)","DOI":"10.1109\/AINA.2006.329"},{"key":"16_CR20","doi-asserted-by":"crossref","unstructured":"Giorgini, P., Massacci, F., Mylopoulos, J., Zannone, N.: Modeling security requirements through ownership, permission and delegation. In: 13th International Conference on Requirements Engineering, pp. 167\u2013176. IEEE (2005)","DOI":"10.1109\/RE.2005.43"},{"key":"16_CR21","doi-asserted-by":"crossref","unstructured":"Kang, W., Liang, Y.: A security ontology with MDA for software development. In: 2013 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC), pp. 67\u201374. IEEE (2013)","DOI":"10.1109\/CyberC.2013.20"},{"key":"16_CR22","series-title":"Lecture Notes in Business Information Processing","doi-asserted-by":"publisher","first-page":"622","DOI":"10.1007\/978-3-642-22056-2_64","volume-title":"Advanced Information Systems Engineering Workshops","author":"F Massacci","year":"2011","unstructured":"Massacci, F., Mylopoulos, J., Paci, F., Tun, T.T., Yu, Y.: An extended ontology for security requirements. In: Salinesi, C., Pastor, O. (eds.) CAiSE 2011. LNBIP, vol. 83, pp. 622\u2013636. Springer, Heidelberg (2011). doi: 10.1007\/978-3-642-22056-2_64"},{"key":"16_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/978-3-642-04840-1_10","volume-title":"Conceptual Modeling - ER 2009","author":"G Elahi","year":"2009","unstructured":"Elahi, G., Yu, E., Zannone, N.: A modeling ontology for integrating vulnerabilities into security requirements conceptual foundations. In: Laender, A.H.F., Castano, S., Dayal, U., Casati, F., de Oliveira, J.P.M. (eds.) ER 2009. LNCS, vol. 5829, pp. 99\u2013114. Springer, Heidelberg (2009). doi: 10.1007\/978-3-642-04840-1_10"},{"issue":"1","key":"16_CR24","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/s00766-004-0194-4","volume":"10","author":"G Sindre","year":"2005","unstructured":"Sindre, G., Opdahl, A.L.: Eliciting security requirements with misuse cases. Requirements Eng. 10(1), 34\u201344 (2005)","journal-title":"Requirements Eng."},{"key":"16_CR25","doi-asserted-by":"crossref","unstructured":"Fenz, S., Ekelhart, A.: Formalizing information security knowledge. In: Proceedings of the 4th International Symposium on Information, Computer, and Communications Security, pp. 183\u2013194. ACM (2009)","DOI":"10.1145\/1533057.1533084"},{"key":"16_CR26","doi-asserted-by":"crossref","unstructured":"Asnar, Y., Moretti, R., Sebastianis, M., Zannone, N.: Risk as dependability metrics for the evaluation of business solutions: a model-driven approach. In: Third Conference on Availability, Reliability and Security, ARES 2008, pp. 1240\u20131247. IEEE (2008)","DOI":"10.1109\/ARES.2008.17"},{"key":"16_CR27","doi-asserted-by":"crossref","unstructured":"den Braber, F., Dimitrakos, T., Gran, B.A., Lund, M.S., St\u00f8len, K., Aagedal, J.: The CORAS methodology: model-based risk assessment using UML and up. UML Unified Process 332\u2013357 (2003)","DOI":"10.4018\/978-1-93177-744-5.ch017"},{"issue":"1","key":"16_CR28","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/s00766-009-0090-z","volume":"15","author":"G Elahi","year":"2010","unstructured":"Elahi, G., Yu, E., Zannone, N.: A vulnerability-centric requirements engineering framework: analyzing security attacks, countermeasures, and requirements based on vulnerabilities. Requirements Eng. 15(1), 41\u201362 (2010)","journal-title":"Requirements Eng."},{"key":"16_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"412","DOI":"10.1007\/3-540-45800-X_32","volume-title":"UML 2002 \u2014 The Unified Modeling Language","author":"J J\u00fcrjens","year":"2002","unstructured":"J\u00fcrjens, J.: UMLsec: extending UML for secure systems development. In: J\u00e9z\u00e9quel, J.-M., Hussmann, H., Cook, S. (eds.) UML 2002. LNCS, vol. 2460, pp. 412\u2013425. Springer, Heidelberg (2002). doi: 10.1007\/3-540-45800-X_32"},{"key":"16_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"541","DOI":"10.1007\/978-3-540-69534-9_40","volume-title":"Advanced Information Systems Engineering","author":"R Matulevi\u010dius","year":"2008","unstructured":"Matulevi\u010dius, R., Mayer, N., Mouratidis, H., Dubois, E., Heymans, P., Genon, N.: Adapting secure tropos for security risk management in the early phases of information systems development. In: Bellahs\u00e8ne, Z., L\u00e9onard, M. (eds.) CAiSE 2008. LNCS, vol. 5074, pp. 541\u2013555. Springer, Heidelberg (2008). doi: 10.1007\/978-3-540-69534-9_40"},{"key":"16_CR31","unstructured":"R\u00f8stad, L.: An extended misuse case notation: including vulnerabilities and the insider threat. In: International Working Conference on Requirements Engineering: Foundation for Software Quality, pp. 33\u201334. Springer (2006). doi:10.1.1.106.8353"},{"key":"16_CR32","unstructured":"Mayer, N.: Model-based management of information system security risk. Ph.D. thesis, University of Namur (2009)"},{"key":"16_CR33","first-page":"1","volume":"2","author":"S Dritsas","year":"2006","unstructured":"Dritsas, S., Gymnopoulos, L., Karyda, M., Balopoulos, T., Kokolakis, S., Lambrinoudakis, C., Katsikas, S.: A knowledge-based approach to security requirements for e-health applications. J. E-Commer. Tools Appl. 2, 1\u201324 (2006)","journal-title":"J. E-Commer. Tools Appl."},{"key":"16_CR34","doi-asserted-by":"crossref","unstructured":"Lin, L., Nuseibeh, B., Ince, D., Jackson, M., Moffett, J.: Introducing abuse frames for analysing security requirements. In: 11th Requirements Engineering International Conference, pp. 371\u2013372. IEEE (2003)","DOI":"10.1109\/ICRE.2003.1232791"},{"issue":"1","key":"16_CR35","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1109\/TDSC.2004.2","volume":"1","author":"A Avizienis","year":"2004","unstructured":"Avizienis, A., Laprie, J.C., Randell, B., Landwehr, C.: Basic concepts and taxonomy of dependable and secure computing. IEEE Trans. Dependable Secure Comput. 1(1), 11\u201333 (2004)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"16_CR36","doi-asserted-by":"crossref","unstructured":"Asnar, Y., Giorgini, P., Massacci, F., Zannone, N.: From trust to dependability through risk analysis. In: The Second International Conference on Availability, Reliability and Security, ARES 2007, pp. 19\u201326. IEEE (2007)","DOI":"10.1109\/ARES.2007.93"},{"key":"16_CR37","unstructured":"Asnar, Y., Giorgini, P., Mylopoulos, J.: Risk modelling and reasoning in goal models, DIT-06-008. Technical report, Universit\u00e1 degli studi di Trento (2006)"},{"key":"16_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/978-3-319-07452-8_3","volume-title":"Engineering Secure Future Internet Services and Systems","author":"E Paja","year":"2014","unstructured":"Paja, E., Dalpiaz, F., Giorgini, P.: STS-tool: security requirements engineering for socio-technical systems. In: Heisel, M., Joosen, W., Lopez, J., Martinelli, F. (eds.) Engineering Secure Future Internet Services and Systems. LNCS, vol. 8431, pp. 65\u201396. Springer, Cham (2014). doi: 10.1007\/978-3-319-07452-8_3"},{"key":"16_CR39","unstructured":"Van Blarkom, G., Borking, J., Olk, J.: Handbook of privacy and privacy-enhancing technologies. Privacy Incorporated Software Agent Consortium, The Hague (2003)"},{"key":"16_CR40","series-title":"Lecture Notes in Business Information Processing","doi-asserted-by":"publisher","first-page":"254","DOI":"10.1007\/978-3-319-25897-3_17","volume-title":"The Practice of Enterprise Modeling","author":"M Gharib","year":"2015","unstructured":"Gharib, M., Giorgini, P.: Analyzing trust requirements in socio-technical systems: a belief-based approach. In: Ralyt\u00e9, J., Espa\u00f1a, S., Pastor, \u00d3. (eds.) PoEM 2015. LNBIP, vol. 235, pp. 254\u2013270. Springer, Cham (2015). doi: 10.1007\/978-3-319-25897-3_17"},{"issue":"2","key":"16_CR41","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/s10664-008-9102-8","volume":"14","author":"P Runeson","year":"2009","unstructured":"Runeson, P., H\u00f6st, M.: Guidelines for conducting and reporting case study research in software engineering. Empir. Softw. Eng. 14(2), 131\u2013164 (2009)","journal-title":"Empir. Softw. Eng."},{"key":"16_CR42","series-title":"Lecture Notes in Business Information Processing","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/978-3-642-31069-0_5","volume-title":"Advanced Information Systems Engineering Workshops","author":"A Souag","year":"2012","unstructured":"Souag, A., Salinesi, C., Comyn-Wattiau, I.: Ontologies for security requirements: a literature survey and classification. In: Bajec, M., Eder, J. (eds.) CAiSE 2012. LNBIP, vol. 112, pp. 61\u201369. Springer, Heidelberg (2012). doi: 10.1007\/978-3-642-31069-0_5"},{"key":"16_CR43","doi-asserted-by":"crossref","unstructured":"Blanco, C., Lasheras, J., Valencia-Garc\u00eda, R., Fern\u00e1ndez-Medina, E., Toval, A., Piattini, M.: A systematic review and comparison of security ontologies. In: 3rd Conference on Availability, Reliability and Security, pp. 813\u2013820. IEEE (2008)","DOI":"10.1109\/ARES.2008.33"},{"issue":"1","key":"16_CR44","doi-asserted-by":"publisher","first-page":"7","DOI":"10.1007\/s00766-009-0092-x","volume":"15","author":"B Fabian","year":"2010","unstructured":"Fabian, B., G\u00fcrses, S., Heisel, M., Santen, T., Schmidt, H.: A comparison of security requirements engineering methods. Requirements Eng. 15(1), 7\u201340 (2010)","journal-title":"Requirements Eng."}],"container-title":["Lecture Notes in Computer Science","Conceptual Modeling"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-69904-2_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,4]],"date-time":"2019-10-04T19:08:56Z","timestamp":1570216136000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-69904-2_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319699035","9783319699042"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-69904-2_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]}}}