{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T11:33:27Z","timestamp":1725536007806},"publisher-location":"Berlin, Heidelberg","reference-count":20,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642033537"},{"type":"electronic","value":"9783642033544"}],"license":[{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009]]},"DOI":"10.1007\/978-3-642-03354-4_35","type":"book-chapter","created":{"date-parts":[[2009,7,23]],"date-time":"2009-07-23T02:46:56Z","timestamp":1248317216000},"page":"461-471","source":"Crossref","is-referenced-by-count":6,"title":["Supporting Agile Development of Authorization Rules for SME Applications"],"prefix":"10.1007","author":[{"given":"Steffen","family":"Bartsch","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Karsten","family":"Sohr","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Carsten","family":"Bormann","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"35_CR1","unstructured":"ISO\/IEC 27001:2005. Information technology \u2013 Security techniques \u2013 Information security management systems \u2013 Requirements. ISO, Geneva, Switzerland"},{"key":"35_CR2","unstructured":"ANSI\u00a0INCITS 359-2004. Role-Based Access Control. American Nat\u2019l Standard for Information Technology (2004)"},{"key":"35_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"154","DOI":"10.1007\/11774129_16","volume-title":"Extreme Programming and Agile Processes in Software Engineering","author":"E.G. Aydal","year":"2006","unstructured":"Aydal, E.G., Paige, R.F., Chivers, H., Brooke, P.J.: Security planning and refactoring in extreme programming. In: Abrahamsson, P., Marchesi, M., Succi, G. (eds.) XP 2006. LNCS, vol.\u00a04044, pp. 154\u2013163. Springer, Heidelberg (2006)"},{"issue":"1","key":"35_CR4","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1145\/300830.300837","volume":"2","author":"E. Bertino","year":"1999","unstructured":"Bertino, E., Ferrari, E., Atluri, V.: The specification and enforcement of authorization constraints in workflow management systems. ACM Trans. Inf. Syst. Secur.\u00a02(1), 65\u2013104 (1999)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"35_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1007\/11499053_7","volume-title":"Extreme Programming and Agile Processes in Software Engineering","author":"H. Chivers","year":"2005","unstructured":"Chivers, H., Paige, R.F., Ge, X.: Agile security using an incremental security architecture. In: Baumeister, H., Marchesi, M., Holcombe, M. (eds.) XP 2005. LNCS, vol.\u00a03556, pp. 57\u201365. Springer, Heidelberg (2005)"},{"key":"35_CR6","unstructured":"Church, L.: End user security: The democratisation of security usability. In: Security and Human Behaviour (2008)"},{"key":"35_CR7","volume-title":"Agile Software Development","author":"A. Cockburn","year":"2001","unstructured":"Cockburn, A.: Agile Software Development. Addison-Wesley Professional, Reading (2001)"},{"key":"35_CR8","unstructured":"Dai, J., Alves-Foss, J.: Logic based authorization policy engineering. In: The 6th World Multiconference on Systemics, Cybernetics and Informatics (2002)"},{"key":"35_CR9","unstructured":"Ferraiolo, D., Kuhn, R.: Role-based access controls. In: 15th NIST-NCSC National Computer Security Conference, pp. 554\u2013563 (1992)"},{"key":"35_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1007\/978-3-540-73101-6_42","volume-title":"Agile Processes in Software Engineering and Extreme Programming","author":"X. Ge","year":"2007","unstructured":"Ge, X., Paige, R.F., Polack, F., Brooke, P.J.: Extreme programming security practices. In: Concas, G., Damiani, E., Scotto, M., Succi, G. (eds.) XP 2007. LNCS, vol.\u00a04536, pp. 226\u2013230. Springer, Heidelberg (2007)"},{"key":"35_CR11","doi-asserted-by":"publisher","first-page":"805","DOI":"10.1145\/1176617.1176727","volume-title":"OOPSLA 2006: Companion to the 21st ACM SIGPLAN symposium on Object-oriented programming systems, languages, and applications","author":"V. Kongsli","year":"2006","unstructured":"Kongsli, V.: Towards agile security in web applications. In: OOPSLA 2006: Companion to the 21st ACM SIGPLAN symposium on Object-oriented programming systems, languages, and applications, pp. 805\u2013808. ACM, New York (2006)"},{"key":"35_CR12","doi-asserted-by":"publisher","DOI":"10.1007\/1-4020-5386-X","volume-title":"End user development","author":"H. Lieberman","year":"2006","unstructured":"Lieberman, H.: End user development. Springer, Heidelberg (2006)"},{"key":"35_CR13","first-page":"55","volume-title":"ACSAC 1999: Proceedings of the 15th Annual Computer Security Applications Conference","author":"J. McDermott","year":"1999","unstructured":"McDermott, J., Fox, C.: Using abuse case models for security requirements analysis. In: ACSAC 1999: Proceedings of the 15th Annual Computer Security Applications Conference, Washington, DC, USA, p. 55. IEEE Computer Society, Los Alamitos (1999)"},{"issue":"6","key":"35_CR14","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1016\/S0306-4379(02)00029-7","volume":"28","author":"S. Oh","year":"2003","unstructured":"Oh, S., Park, S.: Task-role-based access control model. Inf. Syst.\u00a028(6), 533\u2013562 (2003)","journal-title":"Inf. Syst."},{"issue":"2","key":"35_CR15","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/2.485845","volume":"29","author":"R.S. Sandhu","year":"1996","unstructured":"Sandhu, R.S., Coyne, E.J., Feinstein, H.L., Youman, C.E.: Role-based access control models. IEEE Computer\u00a029(2), 38\u201347 (1996)","journal-title":"IEEE Computer"},{"key":"35_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"525","DOI":"10.1007\/11686699_53","volume-title":"Computer Supported Cooperative Work in Design II","author":"Y. Sun","year":"2006","unstructured":"Sun, Y., Meng, X., Liu, S., Pan, P.: Flexible workflow incorporated with RBAC. In: Shen, W.-m., Chao, K.-M., Lin, Z., Barth\u00e8s, J.-P.A., James, A. (eds.) CSCWD 2005. LNCS, vol.\u00a03865, pp. 525\u2013534. Springer, Heidelberg (2006)"},{"key":"35_CR17","first-page":"29","volume-title":"AGILE","author":"A. Tappenden","year":"2005","unstructured":"Tappenden, A., Beatty, P., Miller, J.: Agile security testing of web-based systems via httpunit. In: AGILE, pp. 29\u201338. IEEE Computer Society Press, Los Alamitos (2005)"},{"key":"35_CR18","first-page":"166","volume-title":"Proceedings of the IFIP TC11 WG11.3 Eleventh International Conference on Database Securty XI","author":"R.K. Thomas","year":"1998","unstructured":"Thomas, R.K., Sandhu, R.S.: Thomas and Ravi\u00a0S. Sandhu. Task-based authorization controls (TBAC): A family of models for active and enterprise-oriented autorization management. In: Proceedings of the IFIP TC11 WG11.3 Eleventh International Conference on Database Securty XI, London, UK, pp. 166\u2013181. Chapman & Hall, Ltd., Boca Raton (1998)"},{"issue":"4","key":"35_CR19","doi-asserted-by":"publisher","first-page":"455","DOI":"10.1142\/S0218843003000814","volume":"12","author":"J. Wainer","year":"2003","unstructured":"Wainer, J., Barthelmess, P., Kumar, A.: W-RBAC - a workflow security model incorporating controlled overriding of constraints. Int. J. Cooperative Inf. Syst.\u00a012(4), 455\u2013485 (2003)","journal-title":"Int. J. Cooperative Inf. Syst."},{"key":"35_CR20","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1145\/304851.304859","volume-title":"NSPW 1996: Proceedings of the 1996 workshop on New security paradigms","author":"M.E. Zurko","year":"1996","unstructured":"Zurko, M.E., Simon, R.T.: User-centered security. In: NSPW 1996: Proceedings of the 1996 workshop on New security paradigms, pp. 27\u201333. ACM, New York (1996)"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Collaborative Computing: Networking, Applications and Worksharing"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-03354-4_35","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,3,9]],"date-time":"2019-03-09T01:27:26Z","timestamp":1552094846000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-03354-4_35"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009]]},"ISBN":["9783642033537","9783642033544"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-03354-4_35","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2009]]}}}