{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T15:36:25Z","timestamp":1773243385973,"version":"3.50.1"},"reference-count":75,"publisher":"Elsevier BV","issue":"4","license":[{"start":{"date-parts":[[2003,5,1]],"date-time":"2003-05-01T00:00:00Z","timestamp":1051747200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2003,5]]},"DOI":"10.1016\/s0167-4048(03)00413-9","type":"journal-article","created":{"date-parts":[[2003,6,30]],"date-time":"2003-06-30T12:45:30Z","timestamp":1056977130000},"page":"337-360","source":"Crossref","is-referenced-by-count":39,"title":["An integral framework for information systems security management"],"prefix":"10.1016","volume":"22","author":[{"given":"Denis","family":"Tr\u00e8ek","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/S0167-4048(03)00413-9_BIB1","unstructured":"Aberdeen Group, 1998. Evaluating the Cost of Ownership for Digital Certificate Projects. Boston: Aberdeen Group."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB2","unstructured":"Alhir, S. 1998. UML in a Nutshell. Cambridge: O' Reilly."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB3","unstructured":"Anderson, R. J. 1994. Whither Cryptography. Inf. Management & Com. Security, Vol. 2, No. 5, pp. 13\u201320."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB4","unstructured":"Anderson, R. J., Kuhn, M. 1996. Tamper Resistance \u2014 a Cautionary Note. The 2nd USENIX Workshop on E-commerce Proceedings, pp. 1\u201311. Berkley: USENIX."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB6","unstructured":"ANSI, 1998. The Elliptic Curve Digital Signature Algorithm (ECDSA). X9.62 standard. Washington, DC: ANSI."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB7","doi-asserted-by":"crossref","unstructured":"Arce, I., 2002. Bug Hunting: The Seven Ways of the Security Samurai. Security & Privacy Supplement to IEEE Computer, pp. 11\u201315.","DOI":"10.1109\/MC.2002.1012424"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB8","unstructured":"Aresenault, A. et al., 2002. Internet X.509 Public Key Infrastructure Roadmap. PKIX Draft Standard. Reston: IETF."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB9","unstructured":"ASC X12, 2001. X12 Standard Release 4050. Washington, DC: ANSI."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB10","unstructured":"Baker & Mc Kenzie, 2002. Global E-Commerce Law. http:\/\/www.bmck.com\/ecommerce\/intlegis-t.htm. Chicago: Baker & Mc Kenize."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB11","article-title":"Secure Computer Systems","author":"Bell","year":"1973","journal-title":"ESD-TR-73-278. Washington, DC: MITRE Corp."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB12","unstructured":"Broder, J.F. 2000. Risk Analysis \u2014 The Security Survey. Woburn: Butterworth- Heinemann."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB13","unstructured":"BSI 1999, Code of practice for information security management. British Standard 7799. London: British Standards Institute."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB14","unstructured":"Burrows, M., Abadi, M., Needham, R. 1990. Logic of Authentication. ACM Transactions on Comp. Systems, Vol. 8, No. 1, pp. 18\u201336."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB15","unstructured":"Cheswick, W., Bellovin, S. 1994. Firewalls and Internet Security. Reading: Addison-Wesley."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB16","unstructured":"COBIT Steering Committee 1998. Executive Overview (2nd ed.). Rolling Meadows: Information Systems Audit and Control Foundation."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB17","doi-asserted-by":"crossref","unstructured":"Crocker, D.H. 1982. Standard For The Format Of Arpa Internet Text Messages. RFC 822. Reston: IETF.","DOI":"10.17487\/rfc0822"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB18","doi-asserted-by":"crossref","unstructured":"DeMaio, H. 2002. Global Trust, Certification and (ISC)2. Computers & Security Vol. 21, No. 8, pp. 701\u2013704.","DOI":"10.1016\/S0167-4048(02)00806-4"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB19","doi-asserted-by":"crossref","unstructured":"Devargas M.,1999. Survival is Not Compulsory. Elsevier, Computers & Security, Vol. 18, No. 1, pp. 35\u201346.","DOI":"10.1016\/S0167-4048(99)80007-8"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB20","unstructured":"Devetak, G. 1995. Organization of marketing and marketing information system. Organization and information systems. Aedermannsdorf: Scitec Publications."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB21","unstructured":"Dichter, M.S., Burkhardt, M.S. 2001. Electronic Interaction in the Workplace: Monitoring, Retrieving and Storing Employee Communications. Age. Publications and Seminars. New York: Morgan & Lewis Counselors.http:\/\/www.morganlewis.com\/art61499.htm."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB22","unstructured":"Dierks, T., Allen, C. 1999. Transport Layer Security. Standard RFC 2246. Reston: IETF."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB23","unstructured":"Dreben, R.N., Werbach, J.L. 1999. Top 10 Things to Consider in Developing an Electronic Commerce Web Site. Publications and Seminars. New York: Morgan & Lewis Counselors. http:\/\/www.morganlewis.com\/art8999.htm."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB24","doi-asserted-by":"crossref","unstructured":"Eastlake, D., Jones, P. 2001. Secure Hash Algorithm \u2014 1. RFC 3174 Standard. Reston: IETF.","DOI":"10.17487\/rfc3174"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB25","unstructured":"EU, 1998. Data Protection Directive. Directive 1998\/46\/EC, Official Journal of the European Communities. Brussels: November: 1995."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB26","unstructured":"EU, 1999. Electronic Signature Directive. Directive 1999\/93\/EC, Official Journal of the European Communities. Brussels: December: 1999."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB27","unstructured":"EU, 2000. Directive on Electronic Commerce. Directive 2000\/31\/EC, Official Journal of the European Communities. Brussels: June 2000."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB28","unstructured":"EU, 2001. Directive on Privacy and Electronic Communications. Directive 2002\/58\/EC, Official Journal of the European Communities. Brussels: July 2002."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB29","unstructured":"Foti, J. (Ed.) 2001. Advanced Encryption Standard. FIPS Draft. Washington, DC: DoC."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB30","unstructured":"Foundation for Intelligent Physical Agents (2001). FIPA Security SIG Request For Information. F-OUT-00065 Deliverable. Concord: FIPA."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB31","unstructured":"Freed, N. 1996. Multipurpose Internet Mail Extensions. RFC 2045 Standard. Reston: IETF."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB32","unstructured":"Freier, A.O., et al. 1996. Secure Sockets Layer Protocol (version 3). Mountain View: Netscape Corp. http:\/\/wp.netscape.com\/eng\/ssl3\/index.html."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB33","unstructured":"Fumy, W., 2000. From Common Criteria to Elliptic Curves \u2014 ISO \/ IEC JTC 1\/SC 27, IT Security Techniques. ISO Bulletin, No. 6, pp. 20\u201325."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB34","doi-asserted-by":"crossref","unstructured":"Gong, L., Needham, R., Yahalom, R., 1990. Reasoning about Belief in Cryptographic Protocols. Proc. of the IEEE Computer Society Symposium on Research in Security and Privacy, pp. 234\u2013248. Los Alamitos: IEEE Press.","DOI":"10.1109\/RISP.1990.63854"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB35","unstructured":"Group on the Next Generation Internet Policy, 2000. e-Japan Initiative. Tokyo: GNGIP."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB36","doi-asserted-by":"crossref","unstructured":"Gutmann P., 2002. PKI: It\u2019s Not Dead, Just Resting. IEEE Computer, Vol. 35, No. 8, pp. 41\u201349.","DOI":"10.1109\/MC.2002.1023787"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB37","unstructured":"Harmon, P., 2001. Developing E-Business Systems and Architectures. San Francisco: Morgan Kaufman."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB38","unstructured":"Hendry, M., 1997. Smart Card Security and Application. London: Artech House."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB39","unstructured":"Holzmann, J.G., 1991. Design and validation of computer protocols. London: Prentice Hall."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB40","doi-asserted-by":"crossref","unstructured":"Hunker, J., 2002. Policy challenges in building dependability in global infrastructures. Elsevier Science, Computers & Security, Vol. 21, No. 8, pp. 705\u2013710.","DOI":"10.1016\/S0167-4048(02)00807-6"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB41","unstructured":"ISO, 1994. IT \u2014 Identification Cards. IS 7816 \/ 1thru 10. Geneva: ISO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB42","unstructured":"ISO, 1995a. IT, OSI: Security Frameworks in Open Systems. IS 10181 \/ 1 thru 7. Geneva: ISO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB43","unstructured":"ISO, 1995b. Quality Systems. Standards IS0 9001 thru 9003. Geneva: ISO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB44","unstructured":"ISO, 1997. Quality Management and Quality System Elements. Standards IS0 9004 \/ 1 thru 2. Geneva: ISO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB45","unstructured":"ISO, 1999. Common Criteria, Security techniques \u2014 Evaluation criteria for IT security. IS 15408, parts 1 thru 3. Geneva: ISO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB46","unstructured":"ISO, 2000. Code of practice for inf. sec. management. ISO 17799 Standard. Geneva: ISO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB47","unstructured":"ISO, 2002. Z formal specification notation. FDIS 13568. Geneva: ISO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB48","unstructured":"ITU-T, 1997c. IT \u2014 Open Systems Interconnection \u2014 The Directory: Overview of concepts, models and services. Recommendation X.500. Geneva: ISO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB49","unstructured":"ITU-T, 2000. Public-key and attribute certificate frameworks. X.509 Standard. Geneva: ISO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB50","unstructured":"Katzenbeisser S., Petitcolas F.A.P., 1999. Information hiding techniques for steganography and digital watermarking. London: Artech House."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB51","doi-asserted-by":"crossref","unstructured":"Kemmerer, R.A., Vigna, G., 2002. Intrusion Detection: A Brief History and Overview. IEEE Computer, Security & Privacy, Vol. 35, No. 5, pp. 27\u201330.","DOI":"10.1109\/MC.2002.1012428"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB52","unstructured":"Kocher, P., Jaffe, J., Jun, B., 2000. Differential Power Analysis, White paper. San Francisco: Cryptography Research Inc."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB53","unstructured":"Koops, B.J., 2001. Crypto Law Survey. http:\/\/rechten.kub.nl\/koops\/cryptolaw."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB54","unstructured":"Mactaggart M., 2001. Enabling XML security. http:\/\/www-106.ibm.com\/developerworks\/xm. New York: IBM."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB55","unstructured":"Likar, B., 2001. Inoviranje. Koper: College of Management."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB56","doi-asserted-by":"crossref","unstructured":"Miller, S.K., 2001. Facing the Challenge of Wireless Security. IEEE Computer, Vol. 35, No. 7, pp. 16\u201318.","DOI":"10.1109\/2.933495"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB57","doi-asserted-by":"crossref","unstructured":"OECD, 1997. Guidelines for Cryptography Policy. Paris: OECD.","DOI":"10.1016\/S0960-2593(97)85653-4"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB58","unstructured":"OECD, 1998. Implementing The OECD \u201dPrivacy Guidelines\u201d In The Electronic Environment: Focus On The Internet. Paris: OECD."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB59","unstructured":"OMG, 2001. Unified Modeling Language, v 1.4. Needham: OMG."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB60","unstructured":"Powers, D.M., 2001. The Internet Legal Guide: Everything you need to know when doing business online. New York: John Wiley & Sons."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB61","unstructured":"Raepple, M., 2001. Sicherheitskonzepte fuer das Internet. Heidelberg: dpunkt-Verlag."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB62","doi-asserted-by":"crossref","unstructured":"Ramsdell, B., 1999. S\/MIME Message Specification. Standard RFC 2633. Reston: IETF.","DOI":"10.17487\/rfc2633"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB63","unstructured":"Roe, M., 1993. CA Requirements. PASSWORD Project R. 2.5 document. Cambridge: Cambridge University."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB64","unstructured":"RSA Labs, 2002. PKCS \u2014 RSA Cryptography Standard, v 2.1. Bedford: RSA Security."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB65","doi-asserted-by":"crossref","unstructured":"Sander, T., Tschudin, C.F., 1998. Protecting Mobile Agents Against Malicious Hosts. Mobile Agent Security, LNCS 1419. Heidelberg: Springer Verlag.","DOI":"10.1007\/3-540-68671-1_4"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB66","unstructured":"Schneier, B., 1996. Applied Cryptography. New York: John Willey & Sons."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB67","unstructured":"Stallings, W., 1999. Cryptography and Network Security. London: Prentice Hall."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB68","doi-asserted-by":"crossref","unstructured":"Syverson, P., van Oorschot, P., 1994. On Unifying Some Cryptographic Protocol Logic. Proc. of the Symposium on Security & Privacy, pp. 14\u201328. Oakland: IEEE.","DOI":"10.21236\/ADA465512"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB69","doi-asserted-by":"crossref","unstructured":"Thayer R., et al., 1998. IP Security Document Roadmap. RFC 2411. Reston: IETF.","DOI":"10.17487\/rfc2411"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB70","doi-asserted-by":"crossref","unstructured":"Tr\u00e8ek, D. et al., 2001. Slovene smart card and IP based health-care information system infrastructure. International journal of medical informatics. Vol. 61, pp.33\u201343. Amsterdam: Elsevier.","DOI":"10.1016\/S1386-5056(00)00132-5"},{"key":"10.1016\/S0167-4048(03)00413-9_BIB71","unstructured":"UN Economic Commission for Europe, 1993. Electronic Data Interchange for Administration, Commerce and Transport \u2014 Syntax Rules. ISO 9735. Geneva: ISO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB72","unstructured":"UNCITRAL, 1996. Model Law on Electronic Commerce. http:\/\/www.uncitral.org\/english\/texts\/elect-com\/ecommerceindex.htm. Vienna: UNCITRAL."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB73","unstructured":"UNCITRAL, 2001. Model Law on Digital Signatures. http:\/\/www.uncitral.org\/english\/texts\/elect-com\/ecommerceindex.htm. Vienna: UNCITRAL."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB74","unstructured":"US Congress, 1998. Digital Millennium Copyright Act. H. R. 2281, Public Law 105-304. Washington D.C.: January 1998."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB75","unstructured":"WIPO, 2000. Primer On E-commerce And Intellectual Property Issues. Geneva: WIPO."},{"key":"10.1016\/S0167-4048(03)00413-9_BIB76","unstructured":"Wysocki, R.K., DeMichiell, R.L., 1997. Managing Information Across the Enterprise. New York: John Willey & Sons."}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404803004139?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404803004139?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2020,3,24]],"date-time":"2020-03-24T05:20:08Z","timestamp":1585027208000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404803004139"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2003,5]]},"references-count":75,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2003,5]]}},"alternative-id":["S0167404803004139"],"URL":"https:\/\/doi.org\/10.1016\/s0167-4048(03)00413-9","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2003,5]]}}}