{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T17:15:23Z","timestamp":1770225323462,"version":"3.49.0"},"reference-count":24,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2021,12,22]],"date-time":"2021-12-22T00:00:00Z","timestamp":1640131200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,12,22]],"date-time":"2021-12-22T00:00:00Z","timestamp":1640131200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100011039","name":"Intelligence Advanced Research Projects Activity","doi-asserted-by":"publisher","award":["2016-16031400006"],"award-info":[{"award-number":["2016-16031400006"]}],"id":[{"id":"10.13039\/100011039","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["SN COMPUT. SCI."],"published-print":{"date-parts":[[2022,3]]},"DOI":"10.1007\/s42979-021-00990-1","type":"journal-article","created":{"date-parts":[[2021,12,22]],"date-time":"2021-12-22T10:02:34Z","timestamp":1640167354000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["The Dynamic Nature of Insider Threat Indicators"],"prefix":"10.1007","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0687-1774","authenticated-orcid":false,"given":"Frank L.","family":"Greitzer","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Justin","family":"Purl","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,12,22]]},"reference":[{"key":"990_CR1","unstructured":"CERT Insider Threat Center. Common sense guide to mitigating insider threats, 5th ed., Carnegie Mellon University Software Engineering Institute, technical note CMU\/SEI-2015-TR-010. 2016. https:\/\/resources.sei.cmu.edu\/asset_files\/TechnicalReport\/2016_005_001_484758.pdf. Accessed 30 Sept 2021"},{"issue":"6","key":"990_CR2","doi-asserted-by":"publisher","first-page":"526","DOI":"10.1016\/S0167-4048(02)01009-X","volume":"21","author":"EE Schultz","year":"2002","unstructured":"Schultz EE. A framework for understanding and predicting insider attacks. Comput Secur. 2002;21(6):526\u201331.","journal-title":"Comput Secur"},{"key":"990_CR3","doi-asserted-by":"publisher","unstructured":"Magklaras GB, Furnell SM (2005) A preliminary model of end user sophistication for insider threat prediction in IT systems. Comput Secur 24(5): 371\u2013380. Doi: https:\/\/doi.org\/10.1016\/j.cose.2004.10.003. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404804002603. Accessed 30 Sept 2021","DOI":"10.1016\/j.cose.2004.10.003"},{"issue":"4","key":"990_CR4","doi-asserted-by":"publisher","first-page":"20","DOI":"10.22667\/JOWUA.2013.12.31.020","volume":"4","author":"P Legg","year":"2013","unstructured":"Legg P, Moffat N, Nurse JRC, Happa J, Agrafiotis I, Goldsmith M, Creese S. Towards a conceptual model and reasoning structure for insider threat detection. J Wirel Mob Netw Ubiquitous Comput Dependable Appl. 2013;4(4):20\u201337. https:\/\/doi.org\/10.22667\/JOWUA.2013.12.31.020.","journal-title":"J Wirel Mob Netw Ubiquitous Comput Dependable Appl"},{"key":"990_CR5","doi-asserted-by":"crossref","unstructured":"Nurse JRC, Buckley O, Legg P, Goldsmith M, Creese S, Wright GRT, Whitty M. Understanding insider threat: a framework for characterising attacks. IEEE security and privacy workshops (SPW), San Jose, CA, IEEE. 2014, pp. 214\u2013228. http:\/\/ieeexplore.ieee.org\/document\/6957307\/?arnumber=6957307. Accessed 30 Sept 2021","DOI":"10.1109\/SPW.2014.38"},{"key":"990_CR6","doi-asserted-by":"publisher","unstructured":"Greitzer FL, Kangas LJ, Noonan CF, Brown CR, Ferryman T. Psychosocial modeling of insider threat risk based on behavioral and word use analysis. e-Service J 2014; 9(1): 106\u2013138. http:\/\/www.jstor.org\/stable\/. Doi: https:\/\/doi.org\/10.2979\/eservicej.9.1.106. Accessed 30 Sept 2021","DOI":"10.2979\/eservicej.9.1.106"},{"key":"990_CR7","doi-asserted-by":"crossref","unstructured":"Greitzer FL, Purl J, Leong YM, Becker DE. SOFIT: sociotechnical and organizational factors for insider threat. In: 2018 IEEE security and privacy workshops, San Francisco, CA, 2018","DOI":"10.1109\/SPW.2018.00035"},{"key":"990_CR8","doi-asserted-by":"crossref","unstructured":"Greitzer FL, Purl J, Becker DE, Sticha P, Leong YM. Modeling expert judgments of insider threat using ontology structure: effects of individual indicator threat value and class membership. 52nd Hawaii international conference on systems sciences (HICSS-52), Maui, Hawaii, 2019; pp. 3202\u20133211","DOI":"10.24251\/HICSS.2019.387"},{"key":"990_CR9","doi-asserted-by":"crossref","unstructured":"Senator TE et al. Detecting insider threats in a real corporate database of computer usage activity. Proceedings of the 19th ACM SIGKDD conference on knowledge discovery and data mining, Aug 11\u201314, Chicago, IL, 2013; 1393\u20131401","DOI":"10.1145\/2487575.2488213"},{"key":"990_CR10","doi-asserted-by":"publisher","unstructured":"Buede DM, Axelrad ET, Brown DP, Hudson DW, Laskey KB, Sticha PJ, Thomas JL. Inference enterprise models: an approach to organizational performance improvement. Wiley Interdiscip Rev Data Min Knowl Discov. 2018; 8(6), e1277. Doi: https:\/\/doi.org\/10.1002\/widm.1277. Accessed 30 Sept 2021","DOI":"10.1002\/widm.1277"},{"issue":"2","key":"990_CR11","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/EMR.2019.2914612","volume":"47","author":"FL Greitzer","year":"2019","unstructured":"Greitzer FL, Purl J, Leong YM, Sticha P. Positioning your organization to respond to insider threats. IEEE Eng Manag Rev. 2019;47(2):1\u201311.","journal-title":"IEEE Eng Manag Rev"},{"key":"990_CR12","doi-asserted-by":"publisher","unstructured":"Greitzer FL, Purl J, Sticha PJ, Yu MC, Lee J. Use of expert judgments to inform bayesian models of insider threat risk. J Wirel Mob Netw Ubiquitous Comput Dependable Appl (JoWUA) 12(2): 3\u201347. 2021. https:\/\/doi.org\/10.22667\/JOWUA.2021.06.30.003. Accessed 30 Oct 2021","DOI":"10.22667\/JOWUA.2021.06.30.003"},{"issue":"1","key":"990_CR13","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1016\/j.econlet.2011.11.015","volume":"115","author":"DA Cobb-Clark","year":"2012","unstructured":"Cobb-Clark DA, Schurer S. The stability of big-five personality traits. Econ Lett. 2012;115(1):11\u20135.","journal-title":"Econ Lett"},{"issue":"2","key":"990_CR14","first-page":"41","volume":"59","author":"E Shaw","year":"2015","unstructured":"Shaw E, Sellers L. Application of the critical-path method to evaluate insider risks. Stud Intell. 2015;59(2):41\u20138.","journal-title":"Stud Intell"},{"key":"990_CR15","doi-asserted-by":"crossref","unstructured":"Shaw ED, Fischer L. Ten tales of betrayal: an analysis of attacks on corporate infrastructure by information technology insiders, Vol. 1. Monterrey, CA: Defense Personnel Security Research and Education Center. 2005","DOI":"10.21236\/ADA441293"},{"key":"990_CR16","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1016\/S1361-3723(15)30066-X","volume":"7","author":"I Agrafiotis","year":"2015","unstructured":"Agrafiotis I, Nurse JRC, Buckley O, Legg P, Creese S, Goldsmith M. Identifying attack patterns for insider threat detection. Comput Fraud Secur. 2015;7:9\u201317.","journal-title":"Comput Fraud Secur"},{"issue":"2","key":"990_CR17","doi-asserted-by":"publisher","first-page":"503","DOI":"10.1109\/JSYST.2015.2438442[online:accessedonSeptember30,2021]","volume":"11","author":"PA Legg","year":"2017","unstructured":"Legg PA, Buckley O, Goldsmith M, Creese S. Automated insider threat detection system using user and role-based profile assessment. IEEE Syst J. 2017;11(2):503\u201312. https:\/\/doi.org\/10.1109\/JSYST.2015.2438442[online:accessedonSeptember30,2021].","journal-title":"IEEE Syst J"},{"key":"990_CR18","unstructured":"INFOSEC Research Council (IRC). Hard Problems List. 2005. https:\/\/www.infosec-research.org\/docs_public\/20051130-IRC-HPL-FINAL.pdf. Accessed 13 June 2021"},{"key":"990_CR19","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1016\/0030-5073(78)90037-5","volume":"21","author":"R Hogarth","year":"1978","unstructured":"Hogarth R. A note on aggregating opinions. Organ Behav Hum Perform. 1978;21:40\u20136.","journal-title":"Organ Behav Hum Perform"},{"key":"990_CR20","doi-asserted-by":"publisher","unstructured":"Yusoff, MSB (2019) ABC of content validation and content validity index calculation. Educ Med J 11(2): 9\u201354, 2019. https:\/\/doi.org\/10.21315\/eimj2019.11.2.6. Accessed 30 Sept 2021","DOI":"10.21315\/eimj2019.11.2.6"},{"key":"990_CR21","unstructured":"Forrester Y. The quality of expert judgment: an interdisciplinary investigation, Ph.D. Thesis, University of Maryland, College Park, MD. 2005"},{"key":"990_CR22","doi-asserted-by":"publisher","unstructured":"Herath T, Rao HR. Encouraging information security behaviors in organizations: role of penalties, pressures and perceived effectiveness. Decis Support Syst. 2009. Doi: https:\/\/doi.org\/10.1016\/j.dss.2009.02.005. https:\/\/www.sciencedirect.com\/science\/article\/abs\/pii\/S0167923609000530. Accessed 30 Sept 2021","DOI":"10.1016\/j.dss.2009.02.005"},{"issue":"3","key":"990_CR23","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1145\/3130515.3130518","volume":"48","author":"P Balozian","year":"2017","unstructured":"Balozian P, Leidner D. Review of IS security policy compliance: toward the building blocks of an IS security theory. Data Base Adv Inf Syst. 2017;48(3):11\u201343.","journal-title":"Data Base Adv Inf Syst"},{"key":"990_CR24","unstructured":"Henderson J, Cavalanca N. Insider threat program maturity model report. 2019. https:\/\/cdn2.hubspot.net\/hubfs\/5260286\/PDFs%20-%20%20Whitepapers,%20Case%20Studies,%20%20Datasheets\/Whitepapers\/insider-threat-maturity-report-2019.pdf. Accessed 30 Sept 2021"}],"container-title":["SN Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-021-00990-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s42979-021-00990-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-021-00990-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,3,18]],"date-time":"2022-03-18T11:12:24Z","timestamp":1647601944000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s42979-021-00990-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,22]]},"references-count":24,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2022,3]]}},"alternative-id":["990"],"URL":"https:\/\/doi.org\/10.1007\/s42979-021-00990-1","relation":{},"ISSN":["2662-995X","2661-8907"],"issn-type":[{"value":"2662-995X","type":"print"},{"value":"2661-8907","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,12,22]]},"assertion":[{"value":"3 September 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 December 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 December 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"On behalf of all the authors, the corresponding author states that there is no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of Interest"}}],"article-number":"102"}}