{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,22]],"date-time":"2026-02-22T05:36:40Z","timestamp":1771738600510,"version":"3.50.1"},"reference-count":33,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2024,5,24]],"date-time":"2024-05-24T00:00:00Z","timestamp":1716508800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,5,24]],"date-time":"2024-05-24T00:00:00Z","timestamp":1716508800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Requirements Eng"],"published-print":{"date-parts":[[2024,6]]},"DOI":"10.1007\/s00766-024-00420-7","type":"journal-article","created":{"date-parts":[[2024,5,24]],"date-time":"2024-05-24T15:02:49Z","timestamp":1716562969000},"page":"261-278","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["BPMN extension evaluation for security requirements engineering framework"],"prefix":"10.1007","volume":"29","author":[{"given":"Saima","family":"Zareen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8179-3959","authenticated-orcid":false,"given":"Syed Muhammad","family":"Anwar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,5,24]]},"reference":[{"key":"420_CR1","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1016\/j.scico.2014.02.019","volume":"88","author":"AI Molina","year":"2014","unstructured":"Molina AI, Redondo MA, Ortega M, Lacave C (2014) Evaluating a graphical notation for modeling collaborative learning activities: a family of experiments. Sci Comput Program 88:54\u201381. https:\/\/doi.org\/10.1016\/j.scico.2014.02.019","journal-title":"Sci Comput Program"},{"key":"420_CR2","doi-asserted-by":"publisher","unstructured":"Zarour K, Benmerzoug D, Guermouche N, Drira K (Jan. 2020) A systematic literature review on BPMN extensions. Bus Process Manag J 26(6):1473\u20131503. https:\/\/doi.org\/10.1108\/BPMJ-01-2019-0040","DOI":"10.1108\/BPMJ-01-2019-0040"},{"key":"420_CR3","unstructured":"Strimbel N, Dospinescu C, Strainu O (2016) R. M., the Bpmn Approach of the University Information Systems, Ecoforum, vol. 5, no. 2"},{"issue":"3","key":"420_CR4","doi-asserted-by":"publisher","first-page":"737","DOI":"10.1007\/s10270-015-0499-4","volume":"16","author":"M Salnitri","year":"2017","unstructured":"Salnitri M, Dalpiaz F, Giorgini P (2017) Designing secure business processes with SecBPMN. Softw Syst Model 16(3):737\u2013757. https:\/\/doi.org\/10.1007\/s10270-015-0499-4","journal-title":"Softw Syst Model"},{"issue":"10","key":"420_CR5","first-page":"1472","volume":"24","author":"MZ Barra","year":"2018","unstructured":"Barra MZ, Rodr\u00edguez A, Caro A, Fern\u00e1ndez EB (2018) Towards obtaining UML class diagrams from secure business processes using security patterns. J Univers Comput Sci 24(10):1472\u20131492","journal-title":"J Univers Comput Sci"},{"key":"420_CR6","doi-asserted-by":"publisher","unstructured":"Sang KS (2015) B. Zhou BPMN security extensions for healthcare process. Proc - 15th IEEE Int Conf Comput Inf Technol CIT 2015 14th IEEE Int Conf Ubiquitous Comput Commun IUCC 2015 13th IEEE Int Conf Dependable Auton Se 2340\u20132345 https:\/\/doi.org\/10.1109\/CIT\/IUCC\/DASC\/PICOM.2015.346","DOI":"10.1109\/CIT\/IUCC\/DASC\/PICOM.2015.346"},{"key":"420_CR7","doi-asserted-by":"publisher","first-page":"pp133","DOI":"10.1109\/CBI.2015.41","volume":"1","author":"Braun","year":"2015","unstructured":"Braun R. (2015) BPMN Extension profiles - adapting the Profile mechanism for Integrated BPMN Extensibility. Proc \u2013 17th IEEE Conf Bus Inf CBI 2015 1:pp133\u2013142. https:\/\/doi.org\/10.1109\/CBI.2015.41","journal-title":"Proc \u2013 17th IEEE Conf Bus Inf CBI 2015"},{"key":"420_CR8","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/978-3-642-25160-3_5","volume":"95 LNBIP","author":"LJR Stroppi","year":"2011","unstructured":"Stroppi LJR, Chiotti O, Villarreal PD (2011) Extending BPMN 2.0: method and tool support. Lect Notes Bus Inf Process 95 LNBIP:59\u201373. https:\/\/doi.org\/10.1007\/978-3-642-25160-3_5","journal-title":"Lect Notes Bus Inf Process"},{"key":"420_CR9","volume-title":"0 based on a Reference Model of Information Assurance & Security Yulia Cherdantseva Cardi Ff University","author":"Y Cherdantseva","year":"2014","unstructured":"Cherdantseva Y (2014) Secure * BPMN - a graphical extension for BPMN 2. 0 based on a Reference Model of Information Assurance & Security Yulia Cherdantseva Cardi Ff University. Cardiff University, Wales, UK"},{"key":"420_CR10","unstructured":"S. M. B. Mohamed El Amine Chergui, a valid BPMN extension for supporting security requirements, vol. 1. Springer Nature Switzerland, (2018)"},{"key":"420_CR11","doi-asserted-by":"publisher","unstructured":"Zareen S, Akram A, Khan SA (2020) Security requirements engineering framework with BPMN 2.0.2 extension model for development of information systems. Appl Sci 10(14). https:\/\/doi.org\/10.3390\/app10144981","DOI":"10.3390\/app10144981"},{"key":"420_CR12","doi-asserted-by":"crossref","unstructured":"Mead NR, Stehney T (2005) Security Quality Requirements Engineering (SQUARE) Methodology, in Software Engineering for Secure Systems -- Building Trustworthy Applications (SESS\u201905), pp. 1\u20137","DOI":"10.1145\/1083200.1083214"},{"key":"420_CR13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-29044-2","volume-title":"Ohlsson4, B. Regnell5, and A. Wessl\u00e9n, Experimentation in Software Engineering","author":"C Wohlin","year":"2012","unstructured":"Wohlin C, Runeson2 P, H\u00f6st3 M (2012) M. C. Ohlsson4, B. Regnell5, and A. Wessl\u00e9n, Experimentation in Software Engineering. Springer, Berlin, Heidelberg"},{"issue":"1","key":"420_CR14","doi-asserted-by":"publisher","first-page":"43","DOI":"10.3102\/00346543059001043","volume":"59","author":"RE Mayer","year":"1989","unstructured":"Mayer RE (1989) Models for understanding. Rev Educ Res 59(1):43\u201364","journal-title":"Rev Educ Res"},{"key":"420_CR15","unstructured":"Bieman JM (1997) Software Metrics: A Rigorous & Practical Approach, Second Edition, IBM Syst. J., vol. 36, no. 4, pp. 594\u2013595, [Online]. Available: https:\/\/www.proquest.com\/scholarly-journals\/software-metrics-rigorous-amp-practical-approach\/docview\/222413718\/se-2?accountid=135034"},{"key":"420_CR16","unstructured":"Rafa P, Al-Qutaish E (2010) Quality Models in Software Engineering Literature: An Analytical and Comparative Study, J. Am. Sci., vol. 6, no. 3, pp. 166\u2013175, [Online]. Available: http:\/\/www.jofamericanscience.org\/journals\/am-sci\/am0603\/22_2208_Qutaish_am0603_166_175.pdf"},{"key":"420_CR17","unstructured":"Kolovos DS, Paige RF, Kelly T, Polack FAC (2006) Requirements for domain-specific languages, in Proc. of ECOOP Workshop on Domain-Specific Program Development (DSPD), vol. 2006"},{"issue":"3","key":"420_CR18","doi-asserted-by":"publisher","first-page":"701","DOI":"10.1016\/j.datak.2007.04.008","volume":"63","author":"A Maes","year":"2007","unstructured":"Maes A, Poels G (2007) Evaluating quality of conceptual modelling scripts based on user perceptions. Data Knowl Eng 63(3):701\u2013724. https:\/\/doi.org\/10.1016\/j.datak.2007.04.008","journal-title":"Data Knowl Eng"},{"issue":"1","key":"420_CR19","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s13173-010-0003-5","volume":"16","author":"S Espa\u00f1a","year":"2010","unstructured":"Espa\u00f1a S, Condori-Fernandez N, Gonz\u00e1lez A, Pastor \u00d3 (2010) An empirical comparative evaluation of requirements engineering methods. J Brazilian Comput Soc 16(1):3\u201319. https:\/\/doi.org\/10.1007\/s13173-010-0003-5","journal-title":"J Brazilian Comput Soc"},{"key":"420_CR20","doi-asserted-by":"publisher","unstructured":"Abrah\u00e3o S, Insfran E, Cars\u00ed JA, Genero M, Ny (2011) 181, 16, 3356\u20133378 doi: https:\/\/doi.org\/10.1016\/j.ins.2011.04.005","DOI":"10.1016\/j.ins.2011.04.005"},{"key":"420_CR21","doi-asserted-by":"publisher","unstructured":"Kujala S, Kauppinen M, Lehtola L, Kojo T (2005) The role of user involvement in requirements quality and project success. Proc IEEE Int Conf Requir Eng 75\u201384. https:\/\/doi.org\/10.1109\/re.2005.72","DOI":"10.1109\/re.2005.72"},{"key":"420_CR22","doi-asserted-by":"publisher","unstructured":"Caivano D, Fern\u00e1ndez-Ropero M, P\u00e9rez-Castillo R, Piattini M, Scalera M (2017) Artifact-based vs. human-perceived understandability and modifiability of refactored business processes: An experiment, J. Syst. Softw., vol. 144, no. October pp. 143\u2013164, 2018, https:\/\/doi.org\/10.1016\/j.jss.2018.06.026","DOI":"10.1016\/j.jss.2018.06.026"},{"key":"420_CR23","first-page":"1684","volume":"2004","author":"J Parsons","year":"2004","unstructured":"Parsons J, Cole L (2004) Understanding representation Fidelity: guidelines for experimental evaluation of conceptual modeling techniques. Am Conf Inf Syst 2004:1684\u20131693","journal-title":"Am Conf Inf Syst"},{"key":"420_CR24","doi-asserted-by":"publisher","first-page":"V","DOI":"10.1007\/978-3-319-16101-3","volume":"9013","author":"SA Fricker","year":"2015","unstructured":"Fricker SA, Schneider K (2015) The role of catalogues of threats and security controls in Security Risk Assessment: an empirical study with ATM professionals. Lect Notes Comput Sci (Including Subser Lect Notes Artif Intell Lect Notes Bioinformatics) 9013:V\u2013VI. https:\/\/doi.org\/10.1007\/978-3-319-16101-3","journal-title":"Lect Notes Comput Sci (Including Subser Lect Notes Artif Intell Lect Notes Bioinformatics)"},{"key":"420_CR25","unstructured":"ISO, International Standard (2013) ISO\/IEC 27002 Information technology \u2014 Security techniques \u2014 Code of practice for information security controls, ISO\/IEC 27002:2013(E), vol. pp. 1\u201380, 2013, [Online]. Available: www.iso.org"},{"key":"420_CR26","volume-title":"COBIT 2019 Framework introduction and methodology","author":"D Lanter","year":"2019","unstructured":"Lanter D (2019) COBIT 2019 Framework introduction and methodology. ISACA Schaumberg, IL"},{"key":"420_CR27","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1007\/978-3-030-25918-1_5","volume-title":"COBIT as a Framework for Enterprise Governance of IT BT - Enterprise Governance of Information Technology: achieving alignment and value in Digital Organizations","author":"S De Haes","year":"2020","unstructured":"De Haes S, Van Grembergen W, Joshi A, Huygh T (2020) In: De Haes S, Van Grembergen W, Joshi A, Huygh T (eds) COBIT as a Framework for Enterprise Governance of IT BT - Enterprise Governance of Information Technology: achieving alignment and value in Digital Organizations. Springer International Publishing, Cham, pp 125\u2013162"},{"key":"420_CR28","unstructured":"OWASP T, Application Security Risks-2017. Open Web Appl Secur Proj, 10AD"},{"key":"420_CR29","doi-asserted-by":"publisher","unstructured":"Labunets K, Massacci F, Paci F, Tran LMS (2013) An experimental comparison of two risk-based security methods, Int. Symp. Empir. Softw. Eng. Meas., pp. 163\u2013172, https:\/\/doi.org\/10.1109\/ESEM.2013.29","DOI":"10.1109\/ESEM.2013.29"},{"key":"420_CR30","unstructured":"Moody DL (2003) The method evaluation model : a theoretical model for validating Information Systems Design methods the method evaluation model : a theoretical model for validating Information Systems Design methods, pp. 9\u201312"},{"issue":"1","key":"420_CR31","first-page":"66","volume":"2","author":"R Garland","year":"1991","unstructured":"Garland R (1991) The mid-point on a rating scale: is it desirable. Mark Bull 2(1):66\u201370","journal-title":"Mark Bull"},{"key":"420_CR32","unstructured":"State of New Hampshire Employee Assistance Program (1983) Perceived Stress Scale Score Cut Off, State New Hampsh. Empl. Assist. Progr., p. 2"},{"key":"420_CR33","unstructured":"Nunnally JC (1994) Psychometric theory 3E. Tata McGraw-hill education"}],"container-title":["Requirements Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-024-00420-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00766-024-00420-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-024-00420-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,31]],"date-time":"2024-05-31T18:34:11Z","timestamp":1717180451000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00766-024-00420-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,24]]},"references-count":33,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2024,6]]}},"alternative-id":["420"],"URL":"https:\/\/doi.org\/10.1007\/s00766-024-00420-7","relation":{},"ISSN":["0947-3602","1432-010X"],"issn-type":[{"value":"0947-3602","type":"print"},{"value":"1432-010X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,5,24]]},"assertion":[{"value":"23 June 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 May 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 May 2024","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}