{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,19]],"date-time":"2025-03-19T14:17:09Z","timestamp":1742393829793},"reference-count":60,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2005,12,13]],"date-time":"2005-12-13T00:00:00Z","timestamp":1134432000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Requirements Eng"],"published-print":{"date-parts":[[2006,4]]},"DOI":"10.1007\/s00766-005-0023-4","type":"journal-article","created":{"date-parts":[[2005,12,12]],"date-time":"2005-12-12T14:25:51Z","timestamp":1134397551000},"page":"138-151","source":"Crossref","is-referenced-by-count":33,"title":["Using trust assumptions with security requirements"],"prefix":"10.1007","volume":"11","author":[{"given":"Charles B.","family":"Haley","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robin C.","family":"Laney","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jonathan D.","family":"Moffett","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bashar","family":"Nuseibeh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2005,12,13]]},"reference":[{"key":"23_CR1","unstructured":"ISO\/IEC: Information Technology\u2014Security Techniques\u2014Evaluation Criteria for IT Security. Part 1: Introduction and general model. International Standard 15408\u20131, ISO\/IEC, Geneva Switzerland, 1 Dec 1999"},{"issue":"4","key":"23_CR2","doi-asserted-by":"crossref","first-page":"315","DOI":"10.1145\/267580.267581","volume":"29","author":"P Zave","year":"1997","unstructured":"Zave P (1997) Classification of research efforts in requirements engineering. Comput Survey 29(4):315\u2013321","journal-title":"Comput Survey"},{"key":"23_CR3","doi-asserted-by":"crossref","unstructured":"van Lamsweerde A (2000) Requirements engineering in the year 00: a research perspective. In: Proceedings of the 22nd international conference on software engineering (ICSE\u201900), 4\u201311 June 2000. IEEE Computer Society Press","DOI":"10.1145\/337180.337184"},{"key":"23_CR4","unstructured":"Greenspan SJ, Mylopoulos J, Borgida A (1982) Capturing more world knowledge in the requirements specification. In: Proceedings of the 6th international conference on software engineering (ICSE\u201982), Tokyo, 13\u201316 September 1982, pp 225\u2013234"},{"key":"23_CR5","doi-asserted-by":"crossref","unstructured":"Devanbu P, Stubblebine S (2000) Software engineering for security: a roadmap. In: Finkelstein A (ed) The future of software engineering. ACM Press, New York","DOI":"10.1145\/336512.336559"},{"key":"23_CR6","doi-asserted-by":"crossref","unstructured":"Firesmith DG (2003) Common concepts underlying safety, security, and survivability engineering. Technical Report CMU\/SEI-2003-TN-033, Software Engineering Institute, Carnegie Mellon University, Pittsburgh","DOI":"10.21236\/ADA421683"},{"key":"23_CR7","unstructured":"Moffett JD, Haley CB, Nuseibeh B (2004) Core security requirements artefacts. Technical Report 2004\/23, Department of Computing, The Open University, Milton Keynes"},{"key":"23_CR8","volume-title":"Software requirements and specifications","author":"M Jackson","year":"1995","unstructured":"Jackson M (1995) Software requirements and specifications. Addison Wesley, Reading"},{"key":"23_CR9","volume-title":"Problem frames","author":"M Jackson","year":"2001","unstructured":"Jackson M (2001) Problem frames. Addison Wesley, Reading"},{"issue":"2","key":"23_CR10","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1145\/359205.359223","volume":"44","author":"J Viega","year":"2001","unstructured":"Viega J, Kohno T, Potter B (2001) Trust (and mistrust) in secure applications. Commun ACM 44(2):31\u201336","journal-title":"Commun ACM"},{"issue":"8","key":"23_CR11","doi-asserted-by":"crossref","first-page":"761","DOI":"10.1145\/358198.358210","volume":"27","author":"K Thompson","year":"1984","unstructured":"Thompson K (1984) Reflections on trusting trust. Commun ACM 27(8):761\u2013763","journal-title":"Commun ACM"},{"key":"23_CR12","doi-asserted-by":"crossref","unstructured":"Haley CB, Laney RC, Nuseibeh B (2004) Deriving security requirements from crosscutting threat descriptions. In: Proceedings of the 3rd international conference on aspect-oriented software development (AOSD\u201904), Lancaster, 22\u201326 March 2004. ACM Press, New York, pp 112\u2013121","DOI":"10.1145\/976270.976285"},{"key":"23_CR13","unstructured":"van Lamsweerde A (2001) Goal-oriented requirements engineering: a guided tour. In: Proceedings of the 5th IEEE international symposium on requirements engineering (RE\u201901), Toronto, 27\u201331 August 2001. IEEE Computer Society Press, pp 249\u2013263"},{"issue":"1","key":"23_CR14","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/237432.237434","volume":"6","author":"Zave","year":"1997","unstructured":"Zave P, Jackson M (1997) Four dark corners of requirements engineering. Trans Softw Eng Method 6(1):1\u201330","journal-title":"Trans Softw Eng Method"},{"key":"23_CR15","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4615-5269-7","volume-title":"Non-functional requirements in software engineering","author":"L Chung","year":"2000","unstructured":"Chung L, Nixon B, Yu E, Mylopoulos J (2000) Non-functional requirements in software engineering. Kluwer, Dordrecht"},{"key":"23_CR16","unstructured":"Gani A, Manson G, Giorgini P, Mouratidis H (2003) Analysing security requirements of information systems using Tropos. In: Proceedings of the 5th international conference on enterprise information systems (ICEIS\u201903), Angers, 23\u201326 April 2003"},{"key":"23_CR17","volume-title":"Requirements engineering: processes and techniques","author":"G Kotonya","year":"1998","unstructured":"Kotonya G, Sommerville I (1998) Requirements engineering: processes and techniques. Wiley, United Kingdom"},{"key":"23_CR18","volume-title":"Security in computing","author":"CP Pfleeger","year":"2002","unstructured":"Pfleeger CP, Pfleeger SL (2002) Security in computing. Prentice Hall, Englewood Cliffs"},{"key":"23_CR19","doi-asserted-by":"crossref","unstructured":"Grandison T, Sloman M (2003) Trust management tools for internet applications. In: Proceedings of the 1st international conference on trust management, vol 2692, Heraklion, Crete, 28\u201330 May 2003. Springer, Berlin Heidelberg New York","DOI":"10.1007\/3-540-44875-6_7"},{"key":"23_CR20","unstructured":"Secure Electronic Transaction LLC: SET Secure Electronic Transaction Specification Book 1: Business description, version 1.0. Purchase NY, 31 May 1997"},{"key":"23_CR21","unstructured":"Secure Electronic Transaction LLC: SET Secure Electronic Transaction Specification Book 2: Programmer\u2019s guide, version 1.0. Purchase NY, 31 May 1997"},{"key":"23_CR22","unstructured":"Secure Electronic Transaction LLC: SET Secure Electronic Transaction Specification Book 3: Formal protocol definition, version 1.0. Purchase NY, 31 May 1997"},{"key":"23_CR23","doi-asserted-by":"crossref","unstructured":"Yu E (1997) Towards modelling and reasoning support for early-phase requirements engineering. In: Proceedings of the 3rd IEEE international symposium on requirements engineering (RE\u201997), Annapolis, 6\u201310 January 1997, pp 226\u2013235","DOI":"10.1109\/ISRE.1997.566873"},{"key":"23_CR24","doi-asserted-by":"crossref","unstructured":"Yu E, Liu L (2001) Modelling trust for system design using the i* strategic actors framework. In: Falcone R, Singh MP, Tan YH (eds) Trust in cyber-societies, integrating the human and artificial perspectives Springer, Berlin Heidelberg New York, 15\u201316 October 2002, pp 175\u2013194","DOI":"10.1007\/3-540-45547-7_11"},{"key":"23_CR25","doi-asserted-by":"crossref","unstructured":"Liu L, Yu E, Mylopoulos J (2003) Security and privacy requirements analysis within a social setting. In: Proceedings of the 11th IEEE international requirements engineering conference (RE\u201903), Monteray Bay, 8\u201312 September 2003","DOI":"10.1109\/ICRE.2003.1232746"},{"key":"23_CR26","doi-asserted-by":"crossref","unstructured":"Castro J, Kolp M, Mylopoulos J (2001) A requirements-driven development methodology. In: Proceedings of the 13th conference on advanced information systems engineering (CAiSE\u201901), Interlaken, Switzerland, 4\u20138 June 2001, pp 108\u2013123","DOI":"10.1007\/3-540-45341-5_8"},{"key":"23_CR27","unstructured":"Fuxman A, Pistore M, Mylopoulos J, Traverso P (2001) Model checking early requirements specifications in Tropos. In: Proceedings of the 5th IEEE international symposium on requirements engineering, Toronto, pp 174\u2013181"},{"key":"23_CR28","doi-asserted-by":"crossref","unstructured":"Giorgini P, Massacci F, Mylopoulos J (2003) Requirement engineering meets security: a case study on modelling secure electronic transactions by VISA and Mastercard. In: Proceedings of the 22nd international conference on conceptual modeling, Chicago, 13\u201316 October 2003. Springer, Berlin Heidelberg New York, pp 263\u2013276","DOI":"10.1007\/978-3-540-39648-2_22"},{"key":"23_CR29","doi-asserted-by":"crossref","unstructured":"Giorgini P, Massacci F, Mylopoulos J, Zannone N (2004) Requirements engineering meets trust management: model, method, and reasoning. In: Proceedings of the 2nd international conference on trust management, Oxford, 28 March\u20131 April 2004. Lecture notes in computer science. Springer, Berlin Heidelberg New York","DOI":"10.1007\/978-3-540-24747-0_14"},{"key":"23_CR30","doi-asserted-by":"crossref","unstructured":"Mouratidis H, Giorgini P, Manson G (2003) Integrating security and systems engineering: toward the modelling of secure information systems. In: Proceedings of the 15th conference on advanced information systems engineering (CAiSE\u201903), Klagenfurt\/Velden, 6\u201310 June 2003. Springer, Berlin Heidelberg New York","DOI":"10.1007\/3-540-45017-3_7"},{"key":"23_CR31","unstructured":"Gans G, Jarke M, Kethers S, Lakemeyer G, Ellrich L, Funken C, Meister M (2001) Requirements modeling for organization networks: a (dis)trust-based approach. In: Proceedings of the 5th IEEE international symposium on requirements engineering (RE\u201901), 27\u201331 August 2001. IEEE Computer Society Press, Toronto, pp 154\u2013165"},{"key":"23_CR32","unstructured":"Yu E, Cysneiros LM (2002) Designing for privacy and other competing requirements. In: Proceedings of the 2nd symposium on requirements engineering for information security (SREIS\u201902), Raleigh"},{"issue":"1\u20132","key":"23_CR33","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1016\/0167-6423(93)90021-G","volume":"20","author":"A Dardenne","year":"1993","unstructured":"Dardenne A, van Lamsweerde A, Fickas S (1993) Goal-directed requirements acquisition. Sci Comput Program 20(1\u20132):3\u201350","journal-title":"Sci Comput Program"},{"issue":"10","key":"23_CR34","doi-asserted-by":"crossref","first-page":"978","DOI":"10.1109\/32.879820","volume":"26","author":"A Lamsweerde van","year":"2000","unstructured":"van Lamsweerde A, Letier E (2000) Handling obstacles in goal-oriented requirements engineering. Transact Softw Eng (IEEE) 26(10):978\u20131005","journal-title":"Transact Softw Eng (IEEE)"},{"key":"23_CR35","doi-asserted-by":"crossref","unstructured":"van Lamsweerde A (2004) Elaborating security requirements by construction of intentional anti-models. In: Proceedings of the 26th international conference on software engineering (ICSE\u201904), Edinburgh, 26\u201328 May 2004, pp 148\u2013157","DOI":"10.1109\/ICSE.2004.1317437"},{"key":"23_CR36","unstructured":"van Lamsweerde A, Brohez S, De Landtsheer R, Janssens D (2003) From system goals to intruder anti-goals: attack generation and resolution for security requirements engineering. In: Requirements for high assurance systems workshop (RHAS\u201903), 11th international requirements engineering conference (RE\u201903), Monterey, 8 September 2003"},{"key":"23_CR37","unstructured":"He Q, Ant\u00f3n AI (2003) A framework for modeling privacy requirements in role engineering. In: Proceedings of the 9th international workshop on requirements engineering: foundation for software quality, the 15th conference on advanced information systems engineering (CAiSE\u201903), Klagenfurt\/Velden, 16 June 2003"},{"key":"23_CR38","doi-asserted-by":"crossref","unstructured":"Heitmeyer CL (2001) Applying \u2018practical\u2019 formal methods to the specification and analysis of security properties. In: Proceedings of the international workshop on information assurance in computer networks: methods, models, and architectures for network computer security (MMM ACNS 2001), vol 2052, St. Petersburg, 21\u201323 May 2001. Springer, Berlin Heidelberg New York, pp 84\u201389","DOI":"10.21236\/ADA464842"},{"issue":"1","key":"23_CR39","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1023\/A:1012547320602","volume":"11","author":"H In","year":"2001","unstructured":"In H, Boehm BW (2001) Using WinWin quality requirements management tools: a case study. Ann Softw Eng 11(1):141\u2013174","journal-title":"Ann Softw Eng"},{"key":"23_CR40","doi-asserted-by":"crossref","unstructured":"Alexander I (2002) Initial industrial experience of misuse cases in trade-off analysis. In: Proceedings of the IEEE joint international conference on requirements engineering (RE\u201902), Essen, pp 61\u201368","DOI":"10.1109\/ICRE.2002.1048506"},{"key":"23_CR41","unstructured":"Alexander I (2002) Modelling the interplay of conflicting goals with use and misuse cases. In: Proceedings of 8th international workshop on requirements engineering: foundation for software quality (REFSQ\u201902), Essen, 9\u201310 September 2002, pp 145\u2013152"},{"key":"23_CR42","doi-asserted-by":"crossref","unstructured":"Sindre G, Opdahl AL (2000) Eliciting security requirements by misuse cases. In: Proceedings of the 37th international conference on technology of object-oriented languages and systems (TOOLS-Pacific\u201900), Sydney, 20\u201323 November 2000, pp 120\u2013131","DOI":"10.1109\/TOOLS.2000.891363"},{"key":"23_CR43","doi-asserted-by":"crossref","unstructured":"McDermott J (2001) Abuse-case-based assurance arguments. In: Proceedings of the 17th computer security applications conference (ACSAC\u201901), New Orleans, 10\u201314 December 2001. IEEE Computer Society Press, pp 366\u2013374","DOI":"10.1109\/ACSAC.2001.991553"},{"key":"23_CR44","doi-asserted-by":"crossref","unstructured":"McDermott J, Fox C (1999) Using abuse case models for security requirements analysis. In: Proceedings of the 15th computer security applications conference (ACSAC\u201999), Phoenix, 6\u201310 December 1999. IEEE Computer Society Press, pp 55\u201364","DOI":"10.1109\/CSAC.1999.816013"},{"key":"23_CR45","unstructured":"Srivatanakul T, Clark JA, Polack F (2004) Writing effective security abuse cases. Technical Report YCS-2004\u2013375, Department of Computer Science, University of York, York, 11 May 2004"},{"key":"23_CR46","doi-asserted-by":"crossref","unstructured":"Lin L, Nuseibeh B, Ince D, Jackson M, Moffett J (2003) Introducing abuse frames for analyzing security requirements. In: Proceedings of the 11th IEEE international requirements engineering conference (RE\u201903), Monterey, 8\u201312 September 2003, pp 371\u2013372","DOI":"10.1109\/ICRE.2003.1232791"},{"key":"23_CR47","doi-asserted-by":"crossref","unstructured":"Rashid A, Moreira AMD, Ara\u00fajo J (2003) Modularisation and composition of aspectual requirements. In: Proceedings of the 2nd international conference on aspect-oriented software development (AOSD\u201903), Boston, 17\u201321 March 2003. ACM Press, New York, pp 11\u201320","DOI":"10.1145\/643603.643605"},{"key":"23_CR48","doi-asserted-by":"crossref","unstructured":"Rashid A, Sawyer P, Moreira AMD, Ara\u00fajo J (2002) Early aspects: a model for aspect-oriented requirements engineering. In: Proceedings of the IEEE joint international conference on requirements engineering (RE\u201902), Essen, 9\u201313 September 2002, pp 199\u2013202","DOI":"10.1109\/ICRE.2002.1048526"},{"key":"23_CR49","unstructured":"Brito I, Moreira A (2004) Integrating the NFR framework in a RE model. Presented at Early aspects 2004: aspect-oriented requirements engineering and architecture design (AORE\u201904), with the 3rd international conference on aspect-oriented software development (AOSD\u201904), Lancaster University, UK"},{"issue":"3\u20134","key":"23_CR50","doi-asserted-by":"crossref","first-page":"251","DOI":"10.1207\/s15327051hci0603&4_3","volume":"6","author":"J Lee","year":"1991","unstructured":"Lee J, Lai KY (1991) What\u2019s in design rationale? Hum Comput Interact Spec Issue Design Rationale 6(3\u20134):251\u2013280","journal-title":"Hum Comput Interact Spec Issue Design Rationale"},{"key":"23_CR51","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/978-1-4471-0037-9_1","volume-title":"Visualizing argumentation: software tools for collaborative, educational sense-making","author":"SJ Backingham Shum","year":"2003","unstructured":"Backingham Shum SJ (2003) The roots of computer supported argument visualization. In: Kirschner PA, Buckingham Shum SJ, Carr CS (eds) Visualizing argumentation: software tools for collaborative, educational sense-making. Springer, London, pp 3\u201324"},{"key":"23_CR52","doi-asserted-by":"crossref","unstructured":"Potts C, Bruns G (1988) Recording the reasons for design decisions. In: Proceedings of the 10th international conference on software engineering (ICSE\u201988), Singapore. IEEE Computer Society, pp 418\u2013427","DOI":"10.1109\/ICSE.1988.93722"},{"key":"23_CR53","doi-asserted-by":"crossref","unstructured":"Burge JE, Brown DC (2004) An integrated approach for software design checking using design rationale. In: Gero JS (ed) Proceedings of the 1st international conference on design computing and cognition. Kluwer, Cambridge, pp 557\u2013576","DOI":"10.1007\/978-1-4020-2393-4_29"},{"issue":"4","key":"23_CR54","doi-asserted-by":"crossref","first-page":"325","DOI":"10.1145\/102675.102676","volume":"8","author":"J Mylopoulos","year":"1990","unstructured":"Mylopoulos J, Borgida A, Jarke M, Koubarakis M (1990) Telos: representing knowledge about information systems. ACM Trans Inf Syst (TOIS) 8(4):325\u2013362","journal-title":"ACM Trans Inf Syst (TOIS)"},{"issue":"6","key":"23_CR55","doi-asserted-by":"crossref","first-page":"498","DOI":"10.1109\/32.142872","volume":"18","author":"B Ramesh","year":"1992","unstructured":"Ramesh B, Dhar V (1992) Supporting systems development by capturing deliberations during requirements engineering. IEEE Trans Softw Eng 18(6):498\u2013510","journal-title":"IEEE Trans Softw Eng"},{"key":"23_CR56","unstructured":"Fischer G, Lemke AC, McCall R, Morch A (1996) Making argumentation serve design. In: Moran T, Carrol J (Eds) Design rationale concepts, techniques, and use. Lawrence Erlbaum and Associates, Mahwah, pp 267\u2013293"},{"key":"23_CR57","doi-asserted-by":"crossref","unstructured":"Finkelstein A, Fuks H (1989) Multiparty specification. In: Proceedings of the 5th international workshop on software specification and design, Pittsburgh, pp 185\u2013195","DOI":"10.1145\/75199.75228"},{"key":"23_CR58","unstructured":"Haley CB, Laney RC, Nuseibeh B (2005) Arguing security: validating security requirements using structured argumentation. Technical Report 2005\/04, Department of Computing, The Open University, Milton Keynes, 21 March 2005"},{"key":"23_CR59","doi-asserted-by":"crossref","unstructured":"Haley CB, Laney RC, Moffett JD, Nuseibeh B (2004) The effect of trust assumptions on the elaboration of security requirements. In: Proceedings of the 12th international requirements engineering conference (RE\u201904), Kyoto, 6\u201310 September 2004. IEEE Computer Society Press, pp 102\u2013111","DOI":"10.1109\/ICRE.2004.1335668"},{"key":"23_CR60","doi-asserted-by":"crossref","unstructured":"Haley CB, Laney RC, Moffett JD, Nuseibeh B (2004) Picking battles: the impact of trust assumptions on the elaboration of security requirements. In: Proceedings of the 2nd international conference on trust management (iTrust\u201904), vol 2995, St Anne\u2019s College, Oxford, 29 March\u20131April 2004. Lecture notes in computer science. Springer, Berlin Heidelberg New York, pp 347\u2013354","DOI":"10.1007\/978-3-540-24747-0_27"}],"container-title":["Requirements Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-005-0023-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00766-005-0023-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-005-0023-4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,11]],"date-time":"2020-04-11T14:16:41Z","timestamp":1586614601000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00766-005-0023-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,12,13]]},"references-count":60,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2006,4]]}},"alternative-id":["23"],"URL":"https:\/\/doi.org\/10.1007\/s00766-005-0023-4","relation":{},"ISSN":["0947-3602","1432-010X"],"issn-type":[{"value":"0947-3602","type":"print"},{"value":"1432-010X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2005,12,13]]}}}