{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,31]],"date-time":"2026-03-31T08:39:13Z","timestamp":1774946353823,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":47,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642342653","type":"print"},{"value":"9783642342660","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-34266-0_3","type":"book-chapter","created":{"date-parts":[[2012,11,4]],"date-time":"2012-11-04T18:49:04Z","timestamp":1352054944000},"page":"38-59","source":"Crossref","is-referenced-by-count":5,"title":["Audit Mechanisms for Provable Risk Management and Accountable Data Governance"],"prefix":"10.1007","author":[{"given":"Jeremiah","family":"Blocki","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicolas","family":"Christin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anupam","family":"Datta","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Arunesh","family":"Sinha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"3_CR1","unstructured":"Center for Information Policy Leadership: Accountability-Based Privacy Governance Project (accessed May 1, 2012)"},{"key":"3_CR2","unstructured":"The White House: Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy (accessed May 1, 2012)"},{"key":"3_CR3","unstructured":"Fairwarning: Industry Best Practices for Patient Privacy in Electronic Health Records (April 2011)"},{"key":"3_CR4","unstructured":"Hulme, G.: Steady Bleed: State of HealthCare Data Breaches. InformationWeek (September 2010)"},{"key":"3_CR5","unstructured":"U.S. Department of Health & Human Services: HIPAA enforcement (accessed May 1,2012)"},{"key":"3_CR6","unstructured":"Ornstein, C.: Breaches in privacy cost Kaiser, \n                    \n                      http:\/\/articles.latimes.com\/2009\/may\/15\/local\/me-privacy15\n                    \n                    \n                   (May 2009)"},{"key":"3_CR7","unstructured":"Picard, K.: Are Drug-Stealing Nurses Punished More Than Doctors? (2012)"},{"key":"3_CR8","doi-asserted-by":"crossref","unstructured":"Blocki, J., Christin, N., Datta, A., Sinha, A.: Regret minimizing audits: A learning-theoretic basis for privacy protection. In: Computer Security Foundations Symposium, pp. 312\u2013327 (2011)","DOI":"10.1109\/CSF.2011.28"},{"key":"3_CR9","unstructured":"Fudenberg, D., Tirole, J.: Game Theory. The MIT Press (1991)"},{"key":"3_CR10","unstructured":"PricewaterhouseCoopers: A practical guide to risk assessment (December 2008)"},{"key":"3_CR11","doi-asserted-by":"crossref","unstructured":"Vellani, K.H.: Strategic Healthcare Security, Risk Assessments in the Environment of Care, Report for Wisconsin Healthcare Engineering Association (2008)","DOI":"10.1016\/B978-012370897-7\/50009-8"},{"key":"3_CR12","unstructured":"NIST: Guide for Conducting Risk Assessments (September 2011)"},{"key":"3_CR13","unstructured":"Cheng, P.-C., Rohatgi, P.: IT Security as Risk Management: A Reserach Perspective. IBM Research Report (April 2008)"},{"key":"3_CR14","unstructured":"Petrochko, C.: DHC: EHR Data Target for Identity Thieves (December 2011)"},{"key":"3_CR15","unstructured":"American National Standards Institute(ANSI)\/The Santa Fe Group\/Internet Security Alliance: The financial impact of breached protected health information (accessed May 1,2012)"},{"key":"3_CR16","unstructured":"Verizon: 2012 Data Breach Investigations Report (2012)"},{"key":"3_CR17","unstructured":"Ponemon Institute, LLC: Benchmark Study on Patient Privacy and Data Security (November 2010)"},{"key":"3_CR18","unstructured":"Ponemon Institute, LLC: 2011 Cost of Data Breach Study: United States (March 2012)"},{"key":"3_CR19","unstructured":"Ponemon Institute, LLC: 2010 Annual Study: U.S. Cost of a Data Breach (March 2011)"},{"key":"3_CR20","doi-asserted-by":"crossref","unstructured":"Ichniowski, C., Shaw, K., Prennushi, G.: The Effects of Human Resource Management Practices on Productivity. Technical Report 5333, National Bureau of Economic Research (November 1995)","DOI":"10.3386\/w5333"},{"key":"3_CR21","volume-title":"Statistical Methods for Social Scientists","author":"E.A. Hanushek","year":"1977","unstructured":"Hanushek, E.A.: Statistical Methods for Social Scientists. Academic Press, New York (1977)"},{"key":"3_CR22","doi-asserted-by":"publisher","DOI":"10.1093\/acprof:oso\/9780195300796.001.0001","volume-title":"Repeated Games and Reputations: Long-Run Relationships","author":"G.J. Mailath","year":"2006","unstructured":"Mailath, G.J., Samuelson, L.: Repeated Games and Reputations: Long-Run Relationships. Oxford University Press, USA (2006)"},{"key":"3_CR23","doi-asserted-by":"crossref","unstructured":"Varian, H.: System reliability and free riding. In: Economics of Information Security (Advances in Information Security), vol.\u00a012, pp. 1\u201315 (2004)","DOI":"10.1007\/1-4020-8090-5_1"},{"key":"3_CR24","doi-asserted-by":"crossref","unstructured":"Grossklags, J., Christin, N., Chuang, J.: Secure or insure? A game-theoretic analysis of information security games. In: World Wide Web Conference (WWW 2008), pp. 209\u2013218 (2008)","DOI":"10.1145\/1367497.1367526"},{"issue":"9","key":"3_CR25","doi-asserted-by":"publisher","first-page":"1278","DOI":"10.1109\/PROC.1975.9939","volume":"63","author":"J.H. Saltzer","year":"1975","unstructured":"Saltzer, J.H., Schroeder, M.D.: The protection of information in computer systems. Proceedings of the IEEE\u00a063(9), 1278\u20131308 (1975)","journal-title":"Proceedings of the IEEE"},{"key":"3_CR26","unstructured":"U.S. Department of Health & Human Services: HIPAA Privacy and Security Audit Program"},{"key":"3_CR27","unstructured":"Ponemon Institute, LLC: Second Annual Benchmark Study on Patient Privacy and Data Security (December 2011)"},{"key":"3_CR28","doi-asserted-by":"crossref","unstructured":"Romanosky, S., Hoffman, D., Acquisti, A.: Empirical analysis of data breach litigation. In: International Conference on Information Systems (2011)","DOI":"10.2139\/ssrn.1884499"},{"key":"3_CR29","unstructured":"MedAssets: MedAssets Case Sudy: Stanford hospital takes charge of its charge capture process, increasing net revenue by 4 million (2011)"},{"key":"3_CR30","doi-asserted-by":"crossref","unstructured":"Barth, A., Datta, A., Mitchell, J.C., Nissenbaum, H.: Privacy and contextual integrity: Framework and applications. In: IEEE Symposium on Security and Privacy, pp. 184\u2013198 (2006)","DOI":"10.1109\/SP.2006.32"},{"key":"3_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-14295-6_1","volume-title":"Computer Aided Verification","author":"D. Basin","year":"2010","unstructured":"Basin, D., Klaedtke, F., M\u00fcller, S.: Policy Monitoring in First-Order Temporal Logic. In: Touili, T., Cook, B., Jackson, P. (eds.) CAV 2010. LNCS, vol.\u00a06174, pp. 1\u201318. Springer, Heidelberg (2010)"},{"key":"3_CR32","doi-asserted-by":"crossref","unstructured":"Garg, D., Jia, L., Datta, A.: Policy auditing over incomplete logs: theory, implementation and applications. In: ACM Computer and Communications Security (CCS), pp. 151\u2013162 (2011)","DOI":"10.1145\/2046707.2046726"},{"key":"3_CR33","doi-asserted-by":"crossref","unstructured":"Tschantz, M.C., Datta, A., Wing, J.M.: Formalizing and enforcing purpose requirements in privacy policies. In: IEEE Symposium on Security and Privacy (2012)","DOI":"10.1109\/SP.2012.21"},{"issue":"1-2","key":"3_CR34","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1016\/j.tcs.2006.08.039","volume":"367","author":"M. Backes","year":"2006","unstructured":"Backes, M., Datta, A., Derek, A., Mitchell, J.C., Turuani, M.: Compositional analysis of contract-signing protocols. Theor. Comput. Sci.\u00a0367(1-2), 33\u201356 (2006)","journal-title":"Theor. Comput. Sci."},{"key":"3_CR35","doi-asserted-by":"crossref","unstructured":"Barth, A., Datta, A., Mitchell, J.C., Sundaram, S.: Privacy and utility in business processes. In: Computer Security Foundations Symposium (CSF), pp. 279\u2013294 (2007)","DOI":"10.1109\/CSF.2007.26"},{"key":"3_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"152","DOI":"10.1007\/978-3-642-04444-1_10","volume-title":"Computer Security \u2013 ESORICS 2009","author":"R. Jagadeesan","year":"2009","unstructured":"Jagadeesan, R., Jeffrey, A., Pitcher, C., Riely, J.: Towards a Theory of Accountability and Audit. In: Backes, M., Ning, P. (eds.) ESORICS 2009. LNCS, vol.\u00a05789, pp. 152\u2013167. Springer, Heidelberg (2009)"},{"key":"3_CR37","doi-asserted-by":"crossref","unstructured":"K\u00fcsters, R., Truderung, T., Vogt, A.: Accountability: definition and relationship to verifiability. In: ACM Conference on Computer and Communications Security, pp. 526\u2013535 (2010)","DOI":"10.1145\/1866307.1866366"},{"key":"3_CR38","doi-asserted-by":"crossref","unstructured":"Feigenbaum, J., Jaggard, A.D., Wright, R.N.: Towards a formal model of accountability. In: Proceedings of the 2011 Workshop on New Security Paradigms Workshop (2011)","DOI":"10.1145\/2073276.2073282"},{"key":"3_CR39","doi-asserted-by":"crossref","unstructured":"Bauer, L., Garriss, S., Reiter, M.K.: Detecting and resolving policy misconfigurations in access-control systems. In: Symposium on Access Control Models and Technologies (SACMAT), pp. 185\u2013194 (2008)","DOI":"10.1145\/1377836.1377866"},{"key":"3_CR40","doi-asserted-by":"crossref","unstructured":"Vaughan, J.A., Jia, L., Mazurak, K., Zdancewic, S.: Evidence-based audit. In: Computer Security Foundations Symposium (CSF), pp. 177\u2013191 (2008)","DOI":"10.1109\/CSF.2008.24"},{"issue":"6","key":"3_CR41","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1109\/MC.2004.17","volume":"37","author":"B.W. Lampson","year":"2004","unstructured":"Lampson, B.W.: Computer security in the real world. IEEE Computer\u00a037(6), 37\u201346 (2004)","journal-title":"IEEE Computer"},{"issue":"2-3","key":"3_CR42","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1007\/s10207-007-0017-y","volume":"6","author":"J.G. Cederquist","year":"2007","unstructured":"Cederquist, J.G., Corin, R., Dekker, M.A.C., Etalle, S., den Hartog, J.I., Lenzini, G.: Audit-based compliance control. Int. J. Inf. Sec.\u00a06(2-3), 133\u2013151 (2007)","journal-title":"Int. J. Inf. Sec."},{"key":"3_CR43","doi-asserted-by":"crossref","unstructured":"Cheng, P.C., Rohatgi, P., Keser, C., Karger, P.A., Wagner, G.M., Reninger, A.S.: Fuzzy Multi-Level Security: An Experiment on Quantified Risk-Adaptive Access Control. In: Proceedings of the IEEE Symposium on Security and Privacy (2007)","DOI":"10.1109\/SP.2007.21"},{"key":"3_CR44","unstructured":"Cheng, P.C., Rohatgi, P.: IT Security as Risk Management: A Research Perspective. IBM Research Report\u00a0RC24529 (April 2008)"},{"key":"3_CR45","doi-asserted-by":"crossref","unstructured":"Zhao, X., Johnson, M.E.: Access governance: Flexibility with escalation and audit. In: Hawaii International International Conference on Systems Science (HICSS), pp. 1\u201313 (2010)","DOI":"10.1109\/HICSS.2010.42"},{"key":"3_CR46","doi-asserted-by":"crossref","unstructured":"Zhang, N., Yu, W., Fu, X., Das, S.K.: Towards effective defense against insider attacks: The establishment of defender\u2019s reputation. In: IEEE International Conference on Parallel and Distributed Systems, pp. 501\u2013508 (2008)","DOI":"10.1109\/ICPADS.2008.85"},{"key":"3_CR47","unstructured":"Band, S.R., Cappelli, D.M., Fischer, L.F., Moore, A.P., Shaw, E.D., Trzeciak, R.F.: Comparing Insider IT Sabotage and Espionage: A Model-Based Analysis. Technical Report CMU\/SEI-2006-TR-026, Carnegie Mellon University (December 2006)"}],"container-title":["Lecture Notes in Computer Science","Decision and Game Theory for Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-34266-0_3.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,4]],"date-time":"2021-05-04T08:49:47Z","timestamp":1620118187000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-34266-0_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642342653","9783642342660"],"references-count":47,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-34266-0_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012]]}}}