{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T08:12:25Z","timestamp":1775808745255,"version":"3.50.1"},"publisher-location":"Singapore","reference-count":37,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819996131","type":"print"},{"value":"9789819996148","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-981-99-9614-8_4","type":"book-chapter","created":{"date-parts":[[2024,1,3]],"date-time":"2024-01-03T15:02:31Z","timestamp":1704294151000},"page":"58-76","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A Systematic Method for Constructing ICT Supply Chain Security Requirements"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7850-7288","authenticated-orcid":false,"given":"Yinxing","family":"Wei","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Zheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hong","family":"Zhong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,1,4]]},"reference":[{"key":"4_CR1","doi-asserted-by":"publisher","unstructured":"Boyens, J., Paulsen, C., Bartol, N., Shankles, S.A., Moorthy, R.: Notional supply chain risk management practices for federal information systems. National Institute of Standards and Technology, Gaithersburg, MD (2012). https:\/\/doi.org\/10.6028\/NIST.IR.7622","DOI":"10.6028\/NIST.IR.7622"},{"key":"4_CR2","unstructured":"Supply Chain Compromise, Technique T1195 - Enterprise | MITRE ATT&CK\u00ae. https:\/\/attack.mitre.org\/techniques\/T1195\/. Accessed 10 June 2023"},{"key":"4_CR3","unstructured":"TC260: GB\/T 36637-2018 Information security technology-Guidelines for the information and communication technology supply chain risk management (in Chinese) (2018)"},{"key":"4_CR4","unstructured":"ENISA Threat Landscape 2022. https:\/\/www.enisa.europa.eu\/publications\/enisa-threat-landscape-2022. Accessed 11 May 2023"},{"key":"4_CR5","unstructured":"Supply Chain Integrity: An overview of the ICT supply chain risks and challenges, and vision for the way forward (2015). https:\/\/www.enisa.europa.eu\/publications\/sci-2015. Accessed 25 May 2023"},{"key":"4_CR6","unstructured":"Authoritative UK Organization Recognizes Code and Build Engineering of Huawei OLT Product MA5800. https:\/\/www.huawei.com\/en\/news\/2019\/12\/huawei-ma5800-code-evaluation-build-engineering-assessment. Accessed 17 Oct 2023"},{"key":"4_CR7","unstructured":"Assessment of the Critical Supply Chains Supporting the U.S. ICT Industry | Homeland Security. https:\/\/www.dhs.gov\/publication\/assessment-critical-supply-chains-supporting-us-ict-industry. Accessed 18 May 2023"},{"key":"4_CR8","unstructured":"The Open Group: Open Trusted Technology Provider Framework (O-TTPF) (2021)"},{"key":"4_CR9","unstructured":"CVE security vulnerability database. Security vulnerabilities, exploits, references and more. https:\/\/www.cvedetails.com\/index.php. Accessed 18 Oct 2023"},{"key":"4_CR10","doi-asserted-by":"publisher","first-page":"223","DOI":"10.1108\/SCM-10-2018-0357","volume":"25","author":"A Ghadge","year":"2020","unstructured":"Ghadge, A., Wei\u00df, M., Caldwell, N.D., Wilding, R.: Managing cyber risk in supply chains: a review and research agenda. Supply Chain Manage.: Int. J. 25, 223\u2013240 (2020). https:\/\/doi.org\/10.1108\/SCM-10-2018-0357","journal-title":"Supply Chain Manage.: Int. J."},{"key":"4_CR11","unstructured":"Cybersecurity Workforce Study. https:\/\/www.isc2.org\/research. Accessed 18 Oct 2023"},{"key":"4_CR12","unstructured":"Executive Order on Improving the Nation\u2019s Cybersecurity. https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/. Accessed 19 Apr 2023"},{"key":"4_CR13","unstructured":"Directive (EU) 2022\/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910\/2014 and Directive (EU) 2018\/1972, and repealing Directive (EU) 2016\/1148 (NIS 2 Directive). OJ L333, pp. 80\u2013152 (2022). https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2555. Accessed 18 Apr 2023"},{"key":"4_CR14","unstructured":"ETSI: ETSI TS 102 165-1 V5.2.5 CYBER; Methods and protocols; Part 1: Method and pro forma for Threat, Vulnerability, Risk Analysis (TVRA) (2022)"},{"key":"4_CR15","unstructured":"GSMA: FS.16 - Network Equipment Security Assurance Scheme \u2013 Development and Lifecycle Security Requirements Version 2.2 (2022)"},{"key":"4_CR16","unstructured":"Threat Landscape for Supply Chain Attacks. https:\/\/www.enisa.europa.eu\/publications\/threat-landscape-for-supply-chain-attacks. Accessed 18 Apr 2023"},{"key":"4_CR17","unstructured":"Miller, J.F.: Supply Chain Attack Framework and Attack Patterns. https:\/\/www.mitre.org\/news-insights\/publication\/supply-chain-attack-framework-and-attack-patterns. Accessed 06 May 2023"},{"key":"4_CR18","doi-asserted-by":"crossref","unstructured":"Ladisa, P., Plate, H., Martinez, M., Barais, O.: Taxonomy of attacks on open-source software supply chains. arXiv preprint arXiv:2204.04008 (2022)","DOI":"10.1145\/3560835.3564546"},{"key":"4_CR19","doi-asserted-by":"publisher","unstructured":"Okafor, C., Schorlemmer, T.R., Torres-Arias, S., Davis, J.C.: SoK: analysis of software supply chain security by establishing secure design properties. In: Proceedings of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses, pp. 15\u201324 (2022). https:\/\/doi.org\/10.1145\/3560835.3564556","DOI":"10.1145\/3560835.3564556"},{"key":"4_CR20","unstructured":"Stacy, S.: Framework for Software Supply Chain Integrity. https:\/\/safecode.org\/resource-secure-development-practices\/framework-for-software-supply-chain-integrity\/. Accessed 18 Apr 2023"},{"key":"4_CR21","unstructured":"Stacy, S.: Overview of Software Integrity Controls. https:\/\/safecode.org\/resource-secure-development-practices\/overview-of-software-integrity-controls\/. Accessed 18 Apr 2023"},{"key":"4_CR22","unstructured":"ISO\/IEC: ISO\/IEC 27036-3:2013 Information technology - Security techniques - Information security for supplier relationships - Part 3: Guidelines for information and communication technology supply chain security (2013)"},{"key":"4_CR23","unstructured":"ISO\/IEC: ISO\/IEC 20243-1:2018 Information technology - Open Trusted Technology Provider Standard (O-TTPS) - Mitigating maliciously tainted and counterfeit products - Part 1: Requirements and recommendations (2018)"},{"key":"4_CR24","unstructured":"Enduring Security Framework ESF. https:\/\/www.nsa.gov\/About\/Cybersecurity-Collaboration-Center\/Cybersecurity-Partnerships\/ESF\/. Accessed 19 Apr 2023"},{"key":"4_CR25","doi-asserted-by":"publisher","unstructured":"Boyens, J., Smith, A., Bartol, N., Winkler, K., Holbrook, A., Fallon, M.: Cybersecurity supply chain risk management for systems and organizations. National Institute of Standards and Technology, Gaithersburg, MD (2022). https:\/\/doi.org\/10.6028\/NIST.SP.800-161r1","DOI":"10.6028\/NIST.SP.800-161r1"},{"key":"4_CR26","unstructured":"ISO\/IEC: ISO\/IEC 20243-2:2018 Information technology - Open Trusted Technology Provider Standard (O-TTPS) - Mitigating maliciously tainted and counterfeit products - Part 2: Assessment procedures for the O-TTPS and ISO\/IEC 20243-1:2018 (2018)"},{"key":"4_CR27","unstructured":"ISO\/IEC: ISO\/IEC 27036-1:2021 Cybersecurity - Supplier relationships - Part 1: Overview and concepts (2021)"},{"key":"4_CR28","unstructured":"ITU-T: X.805: Security architecture for systems providing end-to-end communications (2003)"},{"key":"4_CR29","unstructured":"Heinbockel, W.J., Laderman, E.R., Serrao, G.J.: Supply chain attacks and resiliency mitigations. https:\/\/www.mitre.org\/news-insights\/publication\/supply-chain-attacks-and-resiliency-mitigations. Accessed 06 May 2023"},{"key":"4_CR30","unstructured":"The Minimum Elements for a Software Bill of Materials (SBOM). https:\/\/www.ntia.gov\/report\/2021\/minimum-elements-software-bill-materials-sbom. Accessed 22 Apr 2023"},{"key":"4_CR31","unstructured":"ISO\/IEC: ISO\/IEC 15408-1:2022 Evaluation criteria for IT security - Part 1: Introduction and general model (2022)"},{"key":"4_CR32","unstructured":"Cyber Resilience Act | Shaping Europe\u2019s digital future. https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act. Accessed 18 Apr 2023"},{"key":"4_CR33","doi-asserted-by":"publisher","unstructured":"Souppaya, M., Scarfone, K., Dodson, D.: Secure software development framework (SSDF) version 1.1: recommendations for mitigating the risk of software vulnerabilities. National Institute of Standards and Technology, Gaithersburg (2022). https:\/\/doi.org\/10.6028\/NIST.SP.800-218","DOI":"10.6028\/NIST.SP.800-218"},{"key":"4_CR34","unstructured":"BSIMM13 Foundations. https:\/\/www.synopsys.com\/software-integrity\/engage\/bsimm-web\/bsimm13-foundations. Accessed 14 June 2023"},{"key":"4_CR35","doi-asserted-by":"publisher","unstructured":"NIST: Minimum security requirements for federal information and information systems. National Institute of Standards and Technology, Gaithersburg (2006). https:\/\/doi.org\/10.6028\/NIST.FIPS.200","DOI":"10.6028\/NIST.FIPS.200"},{"key":"4_CR36","doi-asserted-by":"publisher","unstructured":"Ross, R., Pillitteri, V., Graubart, R., Bodeau, D., McQuaid, R.: Developing cyber-resilient systems: a systems security engineering approach. National Institute of Standards and Technology, Gaithersburg (2021). https:\/\/doi.org\/10.6028\/NIST.SP.800-160v2r1","DOI":"10.6028\/NIST.SP.800-160v2r1"},{"key":"4_CR37","unstructured":"EU-wide coordinated risk assessment of 5G networks security | Shaping Europe\u2019s digital future. https:\/\/digital-strategy.ec.europa.eu\/en\/news\/eu-wide-coordinated-risk-assessment-5g-networks-security. Accessed 20 Oct 2023"}],"container-title":["Communications in Computer and Information Science","Emerging Information Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-99-9614-8_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,3]],"date-time":"2024-01-03T15:03:24Z","timestamp":1704294204000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-99-9614-8_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9789819996131","9789819996148"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-981-99-9614-8_4","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"4 January 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EISA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Emerging Information Security and Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hangzhou","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 December 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 December 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eisa2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eisa.compute.dtu.dk\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"11","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"31% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}