{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T15:11:50Z","timestamp":1780413110580,"version":"3.54.1"},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"the Science Committee of the Ministry of Education and Science of the Republic of Kazakhstan","award":["AP19680345"],"award-info":[{"award-number":["AP19680345"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cluster Comput"],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1007\/s10586-026-05992-3","type":"journal-article","created":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T14:28:33Z","timestamp":1780410513000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A cloud-based SCIUMA framework for standardisation of cyber incident response"],"prefix":"10.1007","volume":"29","author":[{"given":"Tamara","family":"Zhukabayeva","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Oluwaseguan","family":"Adedugbe","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Elhadj","family":"Benkhelifa","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,2]]},"reference":[{"key":"5992_CR1","doi-asserted-by":"publisher","first-page":"102122","DOI":"10.1016\/j.cose.2020.102122","volume":"101","author":"A Ahmad","year":"2021","unstructured":"Ahmad, A., Maynard, S.B., Desouza, K.C., Kotsias, J., Whitty, M.T., Baskerville, R.L.: How can organizations develop situation awareness for incident response: a case study of management practice. Comput. Secur. 101, 102122 (2021)","journal-title":"Comput. Secur."},{"key":"5992_CR2","doi-asserted-by":"crossref","unstructured":"Almoabady, T.A., Alblawi, Y.M., Albalawi, A.E., Aborokbah, M.M., Manimurugan, S., Aljuhani, A., Aldawood, H. & Karthikeyan, P. (2025). Protecting digital assets using an ontology based cyber situational awareness system.\u00a0Frontiers in Artificial Intelligence.","DOI":"10.3389\/frai.2024.1394363"},{"key":"5992_CR3","doi-asserted-by":"publisher","DOI":"10.1007\/s10586-022-03576-5","author":"M Ammi","year":"2022","unstructured":"Ammi, M., Adedugbe, O., Alharby, F.M., Benkhelifa, E.: Leveraging a cloud-native architecture to enable semantic interconnectedness of data for cyber threat intelligence. Cluster Computing (2022). https:\/\/doi.org\/10.1007\/s10586-022-03576-5","journal-title":"Cluster Computing"},{"key":"5992_CR4","doi-asserted-by":"crossref","unstructured":"Ben-Shimol, L., Grolman, E., Elyashar, A., Maimon, I., Mimran, D., Brodt, O., Strassmann, M., Lehmann, H., Elovici, Y. & Shabtai, A. (2024). Observability and incident response in managed serverless environments using ontology-based log monitoring. CoRR, abs\/2405.07172.","DOI":"10.1109\/TCC.2025.3598060"},{"key":"5992_CR5","doi-asserted-by":"publisher","first-page":"710","DOI":"10.1016\/j.future.2019.06.026","volume":"102","author":"DW Chadwick","year":"2020","unstructured":"Chadwick, D.W., Fan, W., Costantino, G., De Lemos, R., Di Cerbo, F., Herwono, I., Manea, M., Mori, P., Sajjad, A., Wang, X.S.: A cloud-edge based data security architecture for sharing and analysing cyber threat information. Future Generation Computer Systems 102, 710\u2013722 (2020)","journal-title":"Future Generation Computer Systems"},{"key":"5992_CR6","unstructured":"Drata (2025) \u2018Understanding the NIST incident response guide (updated for 2025)\u2019, Drata Blog, https:\/\/drata.com\/blog\/nist-incident-response-guide [Accessed 3 May 2025]."},{"key":"5992_CR7","doi-asserted-by":"crossref","unstructured":"Freas, R.L., Adair, H.F. & Hammad, E. (2022). An engineering process framework for cybersecurity incident response assessment. In 2022 IEEE Conference on Dependable and Secure Computing (DSC), (pp.1\u20138) IEEE","DOI":"10.1109\/DSC54232.2022.9888795"},{"key":"5992_CR8","doi-asserted-by":"crossref","unstructured":"Garg, M., Dahiya, S. & Kaushik, K. (2023). International cyberspace laws: A review.\u00a0Unleashing the Art of Digital Forensics.\u00a015\u201328.","DOI":"10.1201\/9781003204862-2"},{"key":"5992_CR9","doi-asserted-by":"crossref","unstructured":"Ghelani, D., Hua, T.K. & Koduru, S.K.R. (2022). Cyber security threats, vulnerabilities, and security solutions models in banking. Authorea Preprints.","DOI":"10.22541\/au.166385206.63311335\/v1"},{"issue":"3","key":"5992_CR10","doi-asserted-by":"publisher","DOI":"10.3390\/electronics10030239","volume":"10","author":"S Gong","year":"2021","unstructured":"Gong, S., Lee, C.: Cyber threat intelligence framework for incident response in an energy cloud platform. Electronics 10(3), 239 (2021)","journal-title":"Electronics"},{"issue":"2","key":"5992_CR11","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1111\/1468-5973.12341","volume":"29","author":"P Hayes","year":"2021","unstructured":"Hayes, P., Bearman, C., Butler, P., Owen, C.: Non\u2010technical skills for emergency incident management teams: A literature review. Journal of Contingencies and Crisis Management 29(2), 185\u2013203 (2021)","journal-title":"Journal of Contingencies and Crisis Management"},{"key":"5992_CR12","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102609","volume":"115","author":"M Hus\u00e1k","year":"2022","unstructured":"Hus\u00e1k, M., Sadlek, L., \u0160pa\u010dek, S., La\u0161tovi\u010dka, M., Javorn\u00edk, M., Kom\u00e1rkov\u00e1, J.: CRUSOE: A toolset for cyber situational awareness and decision support in incident handling. Computers & Security 115, 102609 (2022)","journal-title":"Computers & Security"},{"key":"5992_CR13","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-031-12285-9_2","volume-title":"Data Analytics and Management in Data Intensive Domains: 23rd International Conference, DAMDID\/RCDL 2021, Revised Selected Papers","author":"N Kalinin","year":"2022","unstructured":"Kalinin, N., Skvortsov, N.: Response to cybersecurity threats of informational infrastructure based on conceptual models. In: Data Analytics and Management in Data Intensive Domains: 23rd International Conference, DAMDID\/RCDL 2021, Revised Selected Papers, pp. 19\u201335. Springer International Publishing (2022)"},{"key":"5992_CR14","doi-asserted-by":"publisher","first-page":"102036","DOI":"10.1016\/j.cose.2020.102036","volume":"99","author":"R Knight","year":"2020","unstructured":"Knight, R., Nurse, J.R.: A framework for effective corporate communication after cyber security incidents. Computers & Security 99, 102036 (2020)","journal-title":"Computers & Security"},{"key":"5992_CR15","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1016\/j.comcom.2020.12.003","volume":"166","author":"P Kumar","year":"2021","unstructured":"Kumar, P., Gupta, G.P., Tripathi, R.: An ensemble learning and fog-cloud architecture-driven cyber-attack detection framework for IoMT networks. Computer Communications 166, 110\u2013124 (2021)","journal-title":"Computer Communications"},{"issue":"1","key":"5992_CR16","first-page":"1","volume":"3","author":"S Kumar","year":"2020","unstructured":"Kumar, S.: An emerging threat fileless malware: a survey and research challenges. Cybersecurity 3(1), 1\u201312 (2020)","journal-title":"Cybersecurity"},{"key":"5992_CR17","volume":"59","author":"A Naseer","year":"2021","unstructured":"Naseer, A., Naseer, H., Ahmad, A., Maynard, S.B., Siddiqui, A.M.: Real-time analytics, incident response process agility and enterprise cybersecurity performance: a contingent resource-based analysis. Int. J. Inf. Manage. 59, 102334 (2021)","journal-title":"Int. J. Inf. Manage."},{"key":"5992_CR18","doi-asserted-by":"publisher","first-page":"113476","DOI":"10.1016\/j.dss.2020.113476","volume":"143","author":"H Naseer","year":"2021","unstructured":"Naseer, H., Maynard, S.B., Desouza, K.C.: Demystifying analytical information processing capability: The case of cybersecurity incident response. Decision Support Systems 143, 113476 (2021)","journal-title":"Decision Support Systems"},{"key":"5992_CR19","doi-asserted-by":"crossref","unstructured":"Nil\u0103, C., Apostol, I. & Patriciu, V. (2020). Machine learning approach to quick incident response. In 2020 13th International Conference on Communications (COMM). (pp.291\u2013296). IEEE.\u00a0","DOI":"10.1109\/COMM48946.2020.9141989"},{"key":"5992_CR20","doi-asserted-by":"crossref","unstructured":"Nyre-Yu, M., Gutzwiller, R.S. & Caldwell, B.S. (2019). Observing cyber security incident response: Qualitative themes from field research. In Proceedings of the Human Factors and Ergonomics Society Annual Meeting.\u00a0(pp.437\u2013441). Sage Publications.","DOI":"10.1177\/1071181319631016"},{"key":"5992_CR21","doi-asserted-by":"crossref","unstructured":"Park, Y.S., Choi, C.S., Jang, C., Shin, D.G., Cho, G.C. & Kim, H.S. (2019). Development of incident response tool for cyber security training based on virtualization and cloud. In 2019 International Workshop on Big Data and Information Security (IWBIS). (pp.115\u2013118).\u00a0IEEE.\u00a0","DOI":"10.1109\/IWBIS.2019.8935723"},{"key":"5992_CR22","doi-asserted-by":"publisher","unstructured":"Pollini, A., Callari, T.C., Tedeschi, A., Ruscio, D., Save, L., Chiarugi, F., Guerri, D.: Leveraging human factors in cybersecurity: an integrated methodological approach. Cogn. Technol. Work 24(2), 371\u2013390 (2022). https:\/\/doi.org\/10.1007\/s10111-021-00683-y","DOI":"10.1007\/s10111-021-00683-y"},{"key":"5992_CR23","doi-asserted-by":"crossref","unstructured":"Prajapati, S. & Singh, A. (2022). Cyber-attacks on internet of things (IoT) devices, attack vectors, and remedies: A position paper. IoT and Cloud Computing for Societal Good. (pp.277\u2013295).","DOI":"10.1007\/978-3-030-73885-3_17"},{"key":"5992_CR24","doi-asserted-by":"crossref","unstructured":"Roy, P.P. (2020). A high-level comparison between the NIST cyber security framework and the ISO 27001 information security standard. In 2020 National Conference on Emerging Trends on Sustainable Technology and Engineering Applications (NCETSTEA). (pp.1\u20133). IEEE.","DOI":"10.1109\/NCETSTEA48365.2020.9119914"},{"issue":"4","key":"5992_CR25","doi-asserted-by":"publisher","first-page":"2525","DOI":"10.1109\/COMST.2021.3117338","volume":"23","author":"D Schlette","year":"2021","unstructured":"Schlette, D., Caselli, M., Pernul, G.: A comparative study on cyber threat intelligence: The security incident response perspective. IEEE Communications Surveys & Tutorials 23(4), 2525\u20132556 (2021)","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"5992_CR26","doi-asserted-by":"publisher","first-page":"100821","DOI":"10.1016\/j.segan.2022.100821","volume":"32","author":"\u00d6 Sen","year":"2022","unstructured":"Sen, \u00d6., van der Velde, D., Wehrmeister, K.A., Hacker, I., Henze, M., Andres, M.: On using contextual correlation to detect multi-stage cyber-attacks in smart grids. Sustainable Energy, Grids and Networks 32, 100821 (2022)","journal-title":"Sustainable Energy, Grids and Networks"},{"key":"5992_CR27","volume-title":"Advanced Cyber Security Techniques for Data, Blockchain, IoT, and Network Protection","author":"VH Shah","year":"2025","unstructured":"Shah, V.H., Maniar, R.: \u2018A comprehensive review of ontologies in cybersecurity.\u2019 In: Advanced Cyber Security Techniques for Data, Blockchain, IoT, and Network Protection. IGI Global (2025)"},{"issue":"1","key":"5992_CR28","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1016\/S1361-3723(21)00009-9","volume":"2021","author":"N Shinde","year":"2021","unstructured":"Shinde, N., Kulkarni, P.: Cyber incident response and planning: A flexible approach. Computer Fraud & Security 2021(1), 14\u201319 (2021)","journal-title":"Computer Fraud & Security"},{"key":"5992_CR29","doi-asserted-by":"publisher","first-page":"102398","DOI":"10.1016\/j.cose.2021.102398","volume":"109","author":"R Smith","year":"2021","unstructured":"Smith, R., Janicke, H., He, Y., Ferra, F., Albakri, A.: The agile incident response for industrial control systems (AIR4ICS) framework. Computers & Security 109, 102398 (2021)","journal-title":"Computers & Security"},{"key":"5992_CR30","doi-asserted-by":"publisher","first-page":"100505","DOI":"10.1016\/j.ijcip.2021.100505","volume":"37","author":"A Staves","year":"2022","unstructured":"Staves, A., Anderson, T., Balderstone, H., Green, B., Gouglidis, A., Hutchison, D.: A cyber incident response and recovery framework to support operators of industrial control systems. Int. J. Crit. Infrastruct. Prot. 37, 100505 (2022)","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"5992_CR31","first-page":"301883","volume":"52","author":"YC Tok","year":"2025","unstructured":"Tok, Y.C., Zheng, D.Y., Chattopadhyay, S.: A smart city infrastructure ontology for threats, cybercrime, and digital forensics. Forensic Science International: Digital Investigation 52, 301883 (2025)","journal-title":"Forensic Science International: Digital Investigation"},{"key":"5992_CR32","doi-asserted-by":"crossref","unstructured":"Torkura, K.A., Sukmana, M.I., Cheng, F. & Meinel, C. (2019). Slingshot-automated threat detection and incident response in multi cloud storage systems. In 2019 IEEE 18th International Symposium on Network Computing and Applications (NCA). (pp.1\u20135). IEEE.","DOI":"10.1109\/NCA.2019.8935040"}],"container-title":["Cluster Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-026-05992-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10586-026-05992-3","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-026-05992-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T14:28:42Z","timestamp":1780410522000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10586-026-05992-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":32,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2026,6]]}},"alternative-id":["5992"],"URL":"https:\/\/doi.org\/10.1007\/s10586-026-05992-3","relation":{},"ISSN":["1386-7857","1573-7543"],"issn-type":[{"value":"1386-7857","type":"print"},{"value":"1573-7543","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"6 September 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 January 2026","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 January 2026","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 June 2026","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"293"}}