{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T22:25:54Z","timestamp":1776205554166,"version":"3.50.1"},"reference-count":64,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2013,6,4]],"date-time":"2013-06-04T00:00:00Z","timestamp":1370304000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Requirements Eng"],"published-print":{"date-parts":[[2013,11]]},"DOI":"10.1007\/s00766-013-0174-7","type":"journal-article","created":{"date-parts":[[2013,6,3]],"date-time":"2013-06-03T11:35:11Z","timestamp":1370259311000},"page":"343-395","source":"Crossref","is-referenced-by-count":36,"title":["A pattern-based method for establishing a cloud-specific information security management system"],"prefix":"10.1007","volume":"18","author":[{"given":"Kristian","family":"Beckers","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Isabelle","family":"C\u00f4t\u00e9","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stephan","family":"Fa\u00dfbender","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maritta","family":"Heisel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefan","family":"Hofbauer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2013,6,4]]},"reference":[{"key":"174_CR1","unstructured":"ISO\/IEC (2009) Common criteria for information technology security evaluation. ISO\/IEC 15408, International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)"},{"key":"174_CR2","unstructured":"Cloud Security Alliance (CSA) (2010) Top threats to cloud computing v1.0. http:\/\/cloudsecurityalliance.org\/topthreats\/csathreats.v1.0.pdf"},{"key":"174_CR3","unstructured":"Gartner (2008) Assessing the security risks of cloud computing. http:\/\/www.gartner.com\/id=685308"},{"key":"174_CR4","unstructured":"ISO\/IEC (2005) Information technology\u2014Security techniques\u2014Information security management systems\u2014Requirements. ISO\/IEC 27001, International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)"},{"key":"174_CR5","doi-asserted-by":"crossref","unstructured":"Armbrust M, Fox A, Griffith R, Joseph AD, Katz RH, Konwinski A, Lee G, Patterson DA, Rabkin A, Stoica I, Zaharia M (2009) Above the clouds: A berkeley view of cloud computing. Technical report, EECS Department, University of California, Berkeley","DOI":"10.1145\/1721654.1721672"},{"key":"174_CR6","unstructured":"Mell P, Grance T (2009) The NIST definition of cloud computing. Working Paper of the National Institute of Standards and Technology (NIST)"},{"issue":"1","key":"174_CR7","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1145\/1496091.1496100","volume":"39","author":"LM Vaquero","year":"2008","unstructured":"Vaquero LM, Rodero-Merino L, Caceres J, Lindner M (2008) A break in the clouds: Towards a cloud definition. Special Interest Group Data Commun (SIGCOMM) Comput Commun Rev 39(1):50\u201355","journal-title":"Special Interest Group Data Commun (SIGCOMM) Comput Commun Rev"},{"key":"174_CR8","doi-asserted-by":"crossref","unstructured":"Buyya R, Ranjan R, Calheiros RN (2009) Modeling and simulation of scalable cloud computing environments and the cloudsim toolkit: Challenges and opportunities. In: Proceedings of the international conference von high performance computing and simulation (HPCS). IEEE Computer Society","DOI":"10.1109\/HPCSIM.2009.5192685"},{"key":"174_CR9","doi-asserted-by":"crossref","unstructured":"Beckers K, K\u00fcster JC, Fa\u00dfbender S, Schmidt H (2011) Pattern-based support for context establishment and asset identification of the ISO 27000 in the field of cloud computing. In: Proceedings of the international conference on availability, reliability and security (ARES). IEEE Computer Society, pp 327\u2013333","DOI":"10.1109\/ARES.2011.55"},{"key":"174_CR10","volume-title":"Problem frames: analyzing and structuring software development problems","author":"M Jackson","year":"2001","unstructured":"Jackson M (2001) Problem frames: analyzing and structuring software development problems. Addison-Wesley, Reading, MA"},{"key":"174_CR11","volume-title":"Analysis patterns: reusable object models","author":"M Fowler","year":"1996","unstructured":"Fowler M (1996) Analysis patterns: reusable object models. Addison-Wesley, Reading, MA"},{"key":"174_CR12","volume-title":"Design patterns: elements of reusable object-oriented software","author":"E Gamma","year":"1994","unstructured":"Gamma E, Helm R, Johnson R, Vlissides J (1994) Design patterns: elements of reusable object-oriented software. Addison-Wesley, Reading, MA"},{"key":"174_CR13","volume-title":"Security patterns: integrating security and systems engineering","author":"M Schumacher","year":"2006","unstructured":"Schumacher M, Fernandez-Buglioni E, Hybertson D, Buschmann F, Sommerlad P (2006) Security patterns: integrating security and systems engineering. Wiley, New York"},{"key":"174_CR14","unstructured":"Calder A (2009) Implementing Information Security based on ISO 27001\/ISO 27002: A Management Guide. Haren Van Publishing"},{"key":"174_CR15","unstructured":"ISO\/IEC (2009) Information technology\u2014Security techniques\u2014Information security management systems\u2014Overview and Vocabulary. ISO\/IEC 27000, International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)"},{"key":"174_CR16","doi-asserted-by":"crossref","unstructured":"Klipper S (2010) Information security risk management mit ISO\/IEC 27005: Risikomanagement mit ISO\/IEC 27001, 27005 und 31010. Vieweg+ Teubner","DOI":"10.1007\/978-3-8348-9870-8_3"},{"key":"174_CR17","unstructured":"UML Revision Task Force. OMG Unified Modeling Language (UML), Superstructure. http:\/\/www.omg.org\/spec\/UML\/2.3\/Superstructure\/PDF"},{"key":"174_CR18","unstructured":"IETF (1997) Hmac: keyed-hashing for message authentication. IETF rfc 2104, Internet Engineering Task Force (IETF)"},{"key":"174_CR19","doi-asserted-by":"crossref","unstructured":"Jansen WA (2011) Cloud hooks: Security and privacy issues in cloud computing. In: HICSS. IEEE Computer Society, pp 1\u201310","DOI":"10.1109\/HICSS.2011.103"},{"key":"174_CR20","unstructured":"Chang F, Dean J, Ghemawat S (2006) Bigtable: A distributed storage system for structured data. Technical report, Google"},{"key":"174_CR21","doi-asserted-by":"crossref","unstructured":"Chow R, Golle P, Jakobsson M, Shi E, Staddon J, Masuoka R, Molina J (2009) Controlling data in the cloud: outsourcing computation without outsourcing control. In: CCSW. ACM, pp 85\u201390","DOI":"10.1145\/1655008.1655020"},{"key":"174_CR22","doi-asserted-by":"crossref","unstructured":"Scarfone KA, Souppaya MP, Hoffman P (2011) Sp 800-125. guide to security for full virtualization technologies. Technical report, NIST, Gaithersburg, MD, USA","DOI":"10.6028\/NIST.SP.800-125"},{"key":"174_CR23","unstructured":"Government H (2012) It infrastructure library (ITIL). http:\/\/www.itil-officialsite.com\/home\/home.aspx"},{"issue":"1","key":"174_CR24","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1007\/s00766-009-0092-x","volume":"15","author":"B Fabian","year":"2010","unstructured":"Fabian B, G\u00fcrses S, Heisel M, Santen T, Schmidt H (2010) A comparison of security requirements engineering methods. Requir Eng 15(1):7\u201340","journal-title":"Requir Eng"},{"key":"174_CR25","doi-asserted-by":"crossref","first-page":"916","DOI":"10.1016\/j.infsof.2008.05.013","volume":"51","author":"AL Opdahl","year":"2009","unstructured":"Opdahl AL, Sindre G (2009) Experimental comparison of attack trees and misuse cases for security threat identification. Inf Softw Technol 51:916\u2013932","journal-title":"Inf Softw Technol"},{"key":"174_CR26","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","volume":"16","author":"M Deng","year":"2011","unstructured":"Deng M, Wuyts K, Scandariato R, Preneel B, Joosen W (2011) A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements. Requir Eng 16:3\u201332","journal-title":"Requir Eng"},{"key":"174_CR27","doi-asserted-by":"crossref","unstructured":"Lund MS, Solhaug B, St\u00f8len K (2010) Model-driven risk analysis: the CORAS approach, 1st edn. Springer, Berlin","DOI":"10.1007\/978-3-642-12323-8"},{"key":"174_CR28","unstructured":"American National Standards Institute (ANSI) (2004) American national standard for information technology\u2014role based access control. Ansi incits, pp 359\u20132004, ANSI"},{"key":"174_CR29","unstructured":"OASIS (2005) extensible Access Control Markup Language TC v2.0 (XACML). OASIS. http:\/\/docs.oasis-open.org\/xacml\/2.0\/access_control-xacml-2.0-core-spec-os.pdf"},{"key":"174_CR30","doi-asserted-by":"crossref","DOI":"10.1109\/ISSRE.2006.43","volume-title":"Software security: building security in","author":"G McGraw","year":"2006","unstructured":"McGraw G (2006) Software security: building security in. Addison-Wesley, Reading, MA"},{"key":"174_CR31","unstructured":"VMWARE. Vmware ha. http:\/\/www.vmware.com\/de\/products\/datacenter-virtualization\/vsphere\/high-availability.html"},{"key":"174_CR32","unstructured":"VMWARE. Vmware vmotion. http:\/\/www.vmware.com\/files\/pdf\/VMware-VMotion-DS-EN.pdf"},{"key":"174_CR33","doi-asserted-by":"crossref","unstructured":"Beckers K, Fa\u00dfbender S, K\u00fcster JC, Schmidt H (2012) A pattern-based method for identifying and analyzing laws. In: Proceedings of the international working conference on requirements engineering: foundation for software quality (REFSQ). In: LNCS. Springer, pp 256\u2013262","DOI":"10.1007\/978-3-642-28714-5_23"},{"key":"174_CR34","doi-asserted-by":"crossref","unstructured":"Beckers K, Fa\u00dfbender S, Schmidt H (2012) An integrated method for pattern-based elicitation of legal requirements applied to a cloud computing example. In: Proceedings of the international conference on availability, reliability and security (ARES)\u20142nd international workshop on resilience and it-risk in social infrastructures (RISI 2012). IEEE Computer Society, pp 463\u2013472","DOI":"10.1109\/ARES.2012.25"},{"key":"174_CR35","doi-asserted-by":"crossref","unstructured":"Biagioli C, Mariani P, Tiscornia D (1987) Esplex: a rule and conceptual model for representing statutes. In: ICAIL. ACM, pp 240\u2013251","DOI":"10.1145\/41735.41762"},{"key":"174_CR36","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1007\/978-3-642-18110-8_5","volume-title":"Trust in IT","author":"A Duisberg","year":"2011","unstructured":"Duisberg A (2011) Gel\u00f6ste und ungel\u00f6ste Rechtsfragen im IT-Outsourcing und Cloud Computing. In: Picot A, G\u00f6tz T, Hertz U (eds) Trust in IT, Springer, Berlin, pp 49\u201370"},{"key":"174_CR37","unstructured":"G\u00fcrses SF, Santen T (2006) Contextualizing security goals: a method for multilateral security requirements elicitation. In: Dittmann J (ed.), Sicherheit 2006: Sicherheit\u2014Schutz und Zuverl\u00e4ssigkeit, Beitr\u00e4ge der 3. Jahrestagung des Fachbereichs Sicherheit der Gesellschaft f\u00fcr Informatik e.v. (GI), pp 20\u201322. Februar 2006 in Magdeburg, vol 77 of LNI., pp 42\u201353. GI"},{"key":"174_CR38","unstructured":"OECD (1980) OECD guidelines on the protection of privacy and transborder flows of personal data. Technical report, Organisation for Economic Co-operation and Development (OECD)"},{"key":"174_CR39","doi-asserted-by":"crossref","unstructured":"Beckers K, Heisel M (2012) A foundation for requirements analysis of privacy preserving software. In: Proceedings of the International Cross Domain Conference and Workshop (CD-ARES 2012). Lecture Notes in Computer Science, Springer, pp 93\u2013107","DOI":"10.1007\/978-3-642-32498-7_8"},{"key":"174_CR40","unstructured":"Beckers K, Fa\u00dfbender S, Heisel M, Meis R (2012) A problem-based approach for computer aided privacy threat identification. In: Privacy Forum 2012. Lecture Notes in Computer Science, Springer. Accepted for Publication"},{"key":"174_CR41","unstructured":"C\u00f4t\u00e9 I, Hatebur D, Heisel M, Schmidt H (2011) UML4PF\u2014a tool for problem-oriented requirements analysis. In: Proceedings of the international conference on requirements engineering (RE), IEEE Computer Society, pp 349\u2013350"},{"key":"174_CR42","unstructured":"Pfitzmann A, Hansen M (2011) A terminology for talking about privacy by data minimization: Anonymity, unlinkability, unobservability, pseudonymity, and identity management\u2014version v0.34. Technical report, TU Dresden and ULD Kiel"},{"key":"174_CR43","unstructured":"Clau\u00df S, Kesdogan D, K\u00f6lsch T (2005) Privacy enhancing identity management: protection against re-identification and profiling. In: Proceedings of the 2005 workshop on Digital identity management. DIM \u201905, ACM, pp 84\u201393"},{"key":"174_CR44","doi-asserted-by":"crossref","unstructured":"Kersten H, Reuter J, Schr\u00f6der KW (2011) IT-Sicherheits management nach ISO 27001 und Grundschutz. Vieweg+Teubner","DOI":"10.1007\/978-3-8348-8165-6"},{"key":"174_CR45","unstructured":"Cheremushkin DV, Lyubimov AV (2010) An application of integral engineering technique to information security standards analysis and refinement. In: Proceedings of the international conference on Security of information and networks. SIN \u201910, ACM, pp 12\u201318"},{"key":"174_CR46","doi-asserted-by":"crossref","unstructured":"Lyubimov A, Cheremushkin D, Andreeva N, Shustikov S (2011) Information security integral engineering technique and its application in isms design. In: Proceedings of the international conference on availability, reliability and security (ARES), IEEE Computer Society, pp 585\u2013590","DOI":"10.1109\/ARES.2011.121"},{"key":"174_CR47","doi-asserted-by":"crossref","unstructured":"Montesino R, Fenz S (2011) Information security automation: how far can we go? In: Proceedings of the international conference on availability, reliability and security (ARES), IEEE Computer Society, pp 280\u2013285","DOI":"10.1109\/ARES.2011.48"},{"key":"174_CR48","doi-asserted-by":"crossref","unstructured":"Fenz S, Goluch G, Ekelhart A, Riedl B, Weippl E (2007) Information security fortification by ontological mapping of the ISO\/IEC 27001 standard. In: Proceedings of the international symposium on dependable computing, IEEE Computer Society, pp 381\u2013388","DOI":"10.1109\/PRDC.2007.29"},{"key":"174_CR49","doi-asserted-by":"crossref","unstructured":"Auty M, Creese S, Goldsmith M, Hopkins P (2010) Inadequacies of current risk controls for the cloud. In: Proceedings of the 2010 IEEE second international conference on cloud computing technology and science. CLOUDCOM \u201910, IEEE Computer Society, pp 659\u2013666","DOI":"10.1109\/CloudCom.2010.49"},{"key":"174_CR50","unstructured":"ISO\/IEC (2005) Information technology - Security techniques\u2014code of practice for information security management. ISO\/IEC 27002, International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)"},{"key":"174_CR51","unstructured":"Shaikh F, Haider S (2011) Security threats in cloud computing. In: Internet technology and secured transactions (ICITST), 2011 international conference for, pp 214 \u2013219"},{"key":"174_CR52","doi-asserted-by":"crossref","unstructured":"Greenwood D, Sommerville I (2011) Responsibility modeling for identifying sociotechnical threats to the dependability of coalitions of systems. In: System of systems engineering (SoSE), 2011 6th international conference on, pp 173 \u2013178","DOI":"10.1109\/SYSOSE.2011.5966593"},{"issue":"2","key":"174_CR53","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1109\/MSP.2010.115","volume":"9","author":"B Grobauer","year":"2011","unstructured":"Grobauer B, Walloschek T, Stocker E (2011) Understanding cloud computing vulnerabilities. Secur Priv, IEEE 9(2):50\u201357","journal-title":"Secur Priv, IEEE"},{"key":"174_CR54","unstructured":"ISO\/IEC (2008) Information technology\u2014security techniques\u2014information security risk management. ISO\/IEC 27005, International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)"},{"key":"174_CR55","doi-asserted-by":"crossref","unstructured":"Breaux TD, Vail MW, Ant\u00f3n AI (2006) Towards regulatory compliance: Extracting rights and obligations to align requirements with regulations. In: RE, IEEE Computer Society, pp 46\u201355","DOI":"10.1109\/RE.2006.68"},{"issue":"1","key":"174_CR56","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1109\/TSE.2007.70746","volume":"34","author":"TD Breaux","year":"2008","unstructured":"Breaux TD, Ant\u00f3n AI (2008) Analyzing regulatory rules for privacy and security requirements. IEEE Trans Softw Eng 34(1):5\u201320","journal-title":"IEEE Trans Softw Eng"},{"key":"174_CR57","doi-asserted-by":"crossref","unstructured":"Bench-Capon T, Robinson G, Routen T, Sergot M (1987) Logic programming for large scale applications in law: a formalization of supplementary benefit legislation. In: ICAIL, ACM, pp 190\u2013198","DOI":"10.1145\/41735.41757"},{"key":"174_CR58","doi-asserted-by":"crossref","unstructured":"Siena A, Perini A, Susi A (2008) From laws to requirements. In: RELAW, IEEE Computer Society, pp 6\u201310","DOI":"10.1109\/RELAW.2008.6"},{"issue":"8","key":"174_CR59","doi-asserted-by":"crossref","first-page":"710","DOI":"10.2307\/786270","volume":"26","author":"WN Hohfeld","year":"1917","unstructured":"Hohfeld WN (1917) Fundamental legal conceptions as applied in judicial reasoning. Yale Law J 26(8):710\u2013770","journal-title":"Yale Law J"},{"key":"174_CR60","doi-asserted-by":"crossref","unstructured":"Siena A, Perini A, Susi A, Mylopoulos J (2009) A meta-model for modelling law-compliant requirements. In: Proceedings of the international workshop on requirements engineering and law (RELAW), IEEE Computer Society, pp 45\u201351","DOI":"10.1109\/RELAW.2009.1"},{"key":"174_CR61","unstructured":"\u00c1lvarez JAT, Olmos A, Piattini M (2002) Legal requirements reuse: a critical success factor for requirements quality and personal data protection. In: Proceedings of the international conference on requirements engineering (RE), IEEE Computer Society, pp 95\u2013103"},{"key":"174_CR62","doi-asserted-by":"crossref","first-page":"241","DOI":"10.1007\/s00766-008-0067-3","volume":"13","author":"C Kalloniatis","year":"2008","unstructured":"Kalloniatis C, Kavakli E, Gritzalis S (2008) Addressing privacy requirements in system design: the PriS method. Requir Eng 13:241\u2013255","journal-title":"Requir Eng"},{"key":"174_CR63","doi-asserted-by":"crossref","unstructured":"Hafiz M (2006) A collection of privacy design patterns. In: Proceedings of the 2006 conference on pattern languages of programs. PLoP \u201906, ACM, pp 7:1\u20137:13","DOI":"10.1145\/1415472.1415481"},{"key":"174_CR64","unstructured":"UML Revision Task Force (2010) OMG object constraint language: reference"}],"container-title":["Requirements Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-013-0174-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00766-013-0174-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-013-0174-7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,14]],"date-time":"2019-07-14T08:41:08Z","timestamp":1563093668000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00766-013-0174-7"}},"subtitle":["Establishing information security management systems for clouds considering security, privacy, and legal compliance"],"short-title":[],"issued":{"date-parts":[[2013,6,4]]},"references-count":64,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2013,11]]}},"alternative-id":["174"],"URL":"https:\/\/doi.org\/10.1007\/s00766-013-0174-7","relation":{},"ISSN":["0947-3602","1432-010X"],"issn-type":[{"value":"0947-3602","type":"print"},{"value":"1432-010X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,6,4]]}}}