{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T20:51:36Z","timestamp":1759092696294,"version":"3.41.2"},"reference-count":60,"publisher":"Emerald","issue":"1","license":[{"start":{"date-parts":[[2016,3,14]],"date-time":"2016-03-14T00:00:00Z","timestamp":1457913600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016,3,14]]},"abstract":"<jats:sec>\n               <jats:title content-type=\"abstract-heading\">Purpose<\/jats:title>\n               <jats:p> \u2013 This paper aims to discuss whether recent theoretical and practical approaches within industrial safety management might be applicable to, and solve challenges experienced in, the field of information security, specifically related to incident management. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title>\n               <jats:p> \u2013 A literature review was carried out. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Findings<\/jats:title>\n               <jats:p> \u2013 Principles, research and experiences on the issues of plans, training and learning in the context of industrial safety management would be suitable for adoption into the field of information security incident management and aid in addressing current challenges. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Research limitations\/implications<\/jats:title>\n               <jats:p> \u2013 There are a number of reasons why approaches from industrial safety management have something to offer to information security incident management: the former field is more mature and has longer traditions, there is more organizational research on industrial safety issues than on information security issues so far, individual awareness is higher for industrial safety risks and worker participation in systematic industrial safety work is ensured by law. More organizational research on information security issues and continuous strengthening of individual security awareness would push information security to further maturity levels where current challenges are solved. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title>\n               <jats:p> \u2013 This paper shows that the field of information security incident management would gain from closer collaborations with industrial safety management, both in research and in practical loss prevention in organizations. The ideas discussed in this paper form a basis for further research on practical implementations and case studies. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title>\n               <jats:p> \u2013 The main audience of this paper includes information security researchers and practitioners, as they will find inspirational theories and experiences to bring into their daily work and future projects.<\/jats:p>\n            <\/jats:sec>","DOI":"10.1108\/ics-01-2015-0003","type":"journal-article","created":{"date-parts":[[2016,2,25]],"date-time":"2016-02-25T10:03:20Z","timestamp":1456394600000},"page":"20-37","source":"Crossref","is-referenced-by-count":6,"title":["Examining the suitability of industrial safety management approaches for information security incident management"],"prefix":"10.1108","volume":"24","author":[{"given":"Maria Bartnes","family":"Line","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eirik","family":"Albrechtsen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2020121801265969100_b1","doi-asserted-by":"crossref","unstructured":"Ahmad, A.\n               , \n                  Hadgkiss, J.\n                and \n                  Ruighaver, A.B.\n                (2012), \u201cIncident response teams \u2013 challenges in supporting the organisational security function\u201d, \n                  Computers & Security\n               , Vol. 31 No. 5, pp. 643-652.","DOI":"10.1016\/j.cose.2012.04.001"},{"key":"key2020121801265969100_b2","unstructured":"Albrechtsen, E.\n                (2008), \u201cFriend or foe? Information security management of employees\u201d, Doctoral dissertation, Norwegian University of Science and Technology."},{"key":"key2020121801265969100_b3","unstructured":"Albrechtsen, E.\n                and \n                  Hovden, J.\n                (2007), \u201cIndustrial safety management and information security management: risk characteristic and management approaches\u201d, in \n                  Aven, T.\n                and \n                  Vinnem, J.E.\n                (Eds), Risk, Reliability and Social Safety: Proceedings of the European Safety and Reliability Conference (ESREL), Taylor \n\t\t\t\t\t&\n\t\t\t\t Francis, London, pp. 2333-2340."},{"key":"key2020121801265969100_b4","unstructured":"Alexander, D.\n                (2002), \n                  Principles of Emergency Planning and Management\n               , Oxford University Press, Oxford."},{"key":"key2020121801265969100_b5","unstructured":"Andresen, G.\n               , \n                  Rosness, R.\n                and \n                  S\u00e6tre, P.O.\n                (2008), \u201cImprovisasjon \u2013 tabu og n\u00f8dvendighet\u201d, in Norwegian [Improvisastion \u2013 taboo and necessity] and \n                  Tinmanssvik, R.K.\n                (Ed.), \n                  Robust Arbeidpraksis\n               , Tapir, Trondheim."},{"key":"key2020121801265969100_b6","unstructured":"Argyris, C.\n                and \n                  Sch\u00f6n, D.A.\n                (1996), \n                  Organizational Learning II; Theory, Method and Practice\n               , Addison Wesley, Reading, MA."},{"key":"key2020121801265969100_b7","unstructured":"Bergstr\u00f6m, J.\n               , \n                  Dahlstr\u00f6m, N.\n               , \n                  Dekker, S.\n                and \n                  Petersen, K.\n                (2010), \u201cTraining organizational resilience in escalating situations\u201d, in \n                  Hollnagel, E.\n               , \n                  Pari\u00e9s, J, Woods, D.D.\n                and \n                  Wreathall, J.\n                (Eds), \n                  Resilience Engineering in Practice: A Guidebook\n               , Ashgate, Aldershot, pp. 45-56."},{"key":"key2020121801265969100_b8","unstructured":"Brewster, E.\n               , \n                  Griffiths, R.\n               , \n                  Lawes, A.\n                and \n                  Sansbury, J.\n                (2012), \u201cIT service management: a guide for ITIL foundation exam candidates\u201d, 2nd ed. BCS, The Chartered Institute for IT."},{"key":"key2020121801265969100_b9","unstructured":"Cichonski, P.\n               , \n                  Millar, T.\n               , \n                  Grance, T.\n                and \n                  Scarfone, K.\n                (2011), \u201cNIST Special Publication 800 \u2013 61: Computer Security Incident Handling Guide\u201d, revision 2 (draft)."},{"key":"key2020121801265969100_b10","unstructured":"Cusick, J.\n                and \n                  Ma, G.\n                (2010), \u201cCreating an ITIL \u2013 inspired incident management approach: roots, response, and results\u201d, \n                  Network Operations and Management Symposium Workshops (NOMS\n               ), IEEE\/IFIP, pp. 142-148. doi: 10.1109\/NOMSW 2010.5486589."},{"key":"key2020121801265969100_b11","doi-asserted-by":"crossref","unstructured":"da Veiga, A.\n                and \n                  Martins, N.\n                (2015), \u201cImproving the information security culture through monitoring and implementation actions illustrated through a case study\u201d, \n                  Computers & Security\n               , Vol. 49, pp. 162-176.","DOI":"10.1016\/j.cose.2014.12.006"},{"key":"key2020121801265969100_b12","unstructured":"Dekker, S.W.A.\n               , \n                  Dahlstr\u00f6m, N.\n               , \n                  van Winsen, R.\n                and \n                  Nyce, J.\n                (2008), \u201cCreating resilience and simulator training in aviation\u201d, in \n                  Hollnagel, E.\n               , \n                  Nemeth, C.\n                and \n                  Dekker, S.W.A.\n                (Eds), \n                  Resilience Engineering Perspectives, Remaining Sensitive to the Possibility of Failure\n               , Ashgate, Aldershot."},{"key":"key2020121801265969100_b13","doi-asserted-by":"crossref","unstructured":"Dhillon, G.\n                and \n                  Backhouse, J.\n                (2001), \u201cCurrent directions in IS security research: towards socio \u2013 organizational perspectives\u201d, \n                  Information Systems Journal\n               , Vol. 11 No. 2, pp. 127-153.","DOI":"10.1046\/j.1365-2575.2001.00099.x"},{"key":"key2020121801265969100_b14","doi-asserted-by":"crossref","unstructured":"Drupsteen, L.\n                and \n                  Guldenmund, F.W.\n                (2014), \u201cWhat is learning? A review of the safety literature to define learning from incidents, accidents and disasters\u201d, \n                  Journal of Contingencies and Crisis Management\n               , Vol. 22 No. 2, pp. 81-96.","DOI":"10.1111\/1468-5973.12039"},{"key":"key2020121801265969100_b15","unstructured":"European Network and Information Security Agency (ENISA)\n                (2008), \n                  A Basic Collection of Good Practices for Running a CSIRT\n               , European Network and Information Security Agency, Heraklion, Crete, Greece."},{"key":"key2020121801265969100_b16","unstructured":"European Network and Information Security Agency (ENISA)\n                (2010), \n                  Good Practice Guide for Incident Management\n               , European Network and Information Security Agency, Heraklion, Crete, Greece."},{"key":"key2020121801265969100_b17","doi-asserted-by":"crossref","unstructured":"Hale, A.\n                and \n                  Borys, D.\n                (2013), \u201cWorking to rule, or working safely? Part 1: a state of the art review\u201d, \n                  Safety Science\n               , Vol. 55, pp. 207-221.","DOI":"10.1016\/j.ssci.2012.05.011"},{"key":"key2020121801265969100_b18","doi-asserted-by":"crossref","unstructured":"Hale, A.R.\n                and \n                  Hovden, J.\n                (1998), \u201cManagement and culture: the third age of safety\u201d, in \n                  Feyer, A.M.\n                and \n                  Wlliamson, A.\n                (Eds), \n                  Occupational Injury: Risk Prevention and Intervention\n               , Taylor \n\t\t\t\t\t&\n\t\t\t\t Francis, London.","DOI":"10.1201\/9780203212493.ch11"},{"key":"key2020121801265969100_b19","unstructured":"Hollnagel, E.\n                (2011), \u201cTo learn or not to learn, that is the question\u201d, in \n                  Hollnagel, E.\n               , \n                  Paries, J.\n               , \n                  Woods, D.D.\n                and \n                  Wreathall, J.\n                (Eds), \n                  Resilience Engineering in Practice\n               , Ashgate, Farnham."},{"key":"key2020121801265969100_b20","unstructured":"Hollnagel, E.\n                (2011), \u201cProlouge: the scope of resilience engineering\u201d, in \n                  Hollnagel, E.\n               , \n                  Pari\u00e9s, J, Woods, D.D.\n                and \n                  Wreathall, J.\n                (Eds), \n                  Resilience Engineering in Practice: A Guidebook\n               , Ashgate, Aldershot."},{"key":"key2020121801265969100_b21","unstructured":"Hollnagel, E.\n                (2014), \n                  Safety \u2013 I and Safety \u2013 II: The Past and Future of Safety Management\n               , Ashgate, Farnham."},{"key":"key2020121801265969100_b22","unstructured":"Hollnagel, E.\n               , \n                  Woods, D.D.\n                and \n                  Leveson, N.\n                (2006), \n                  Resilience Engineering: Concepts and Precepts\n               , Ashgate, Aldershot."},{"key":"key2020121801265969100_b23","doi-asserted-by":"crossref","unstructured":"Hovden, J.\n               , \n                  St\u00f8rseth, F.\n                and \n                  Tinmannsvik, R.K.\n                (2011), \u201cMultilevel learning from accidents \u2013 case studies in transport\u201d, \n                  Safety Science\n               , Vol. 49 No. 1, pp. 98-105.","DOI":"10.1016\/j.ssci.2010.02.023"},{"key":"key2020121801265969100_b24","doi-asserted-by":"crossref","unstructured":"Hove, C.\n               , \n                  T\u00e5rnes, M.\n               , \n                  Line, M.B.\n                and \n                  Bernsmed, K.\n                (2014), \u201cInformation security incident management: identified practice in large organizations\u201d, 8th International Conference on IT Security Incident Management and IT Forensics (IMF), M\u00fcnster, pp. 27-46.","DOI":"10.1109\/IMF.2014.9"},{"key":"key2020121801265969100_b25","unstructured":"ISACA\n                (2012), \n                  Incident Management and Response\n               , ISACA, Rolling Meadow, Illinois."},{"key":"key2020121801265969100_b26","unstructured":"ISO\/IEC 27001\n                (2013), \n                  Information Technology \u2013 Security Techniques \u2013 Information Security Management Systems \u2013 Requirements\n               , ISO\/IEC 27001, Geneva, Switzerland."},{"key":"key2020121801265969100_b27","unstructured":"ISO\/IEC 27035\n                (2011), \n                  Information Technology \u2013 Security Techniques \u2013 Information Security Incident Management\n               , ISO\/IEC 27001, Geneva, Switzerland."},{"key":"key2020121801265969100_b28","doi-asserted-by":"crossref","unstructured":"Jaatun, M.G.\n               , \n                  Albrechtsen, E.\n               , \n                  Line, M.B.\n               , \n                  T\u00f8ndel, I.A.\n                and \n                  Longva, O.H.\n                (2009), \u201cA framework for incident response management in the petroleum industry\u201d, \n                  International Journal of Critical Infrastructure Protection\n               , Vol. 2 Nos 1\/2, pp. 26-37.","DOI":"10.1016\/j.ijcip.2009.02.004"},{"key":"key2020121801265969100_b30","doi-asserted-by":"crossref","unstructured":"Johnsen, S.\n               , \n                  Skramstad, T.\n                and \n                  Hagen, J.\n                (2009), \u201cEnhancing the safety, security and resilience of ICT and SCADA systems using action research\u201d, \n                  Critical Infrastructure Protection III\n               , Springer, Berlin\/Heidelberg, pp. 113-123.","DOI":"10.1007\/978-3-642-04798-5_8"},{"key":"key2020121801265969100_b29","doi-asserted-by":"crossref","unstructured":"Johnsen, S.O.\n                (2012), \u201cResilience at interfaces: improvement of safety and security in distributed control systems by web of influence\u201d, \n                  Information Management and Computer Security\n               , Vol. 20 No. 2, pp. 71-87.","DOI":"10.1108\/09685221211235607"},{"key":"key2020121801265969100_b31","doi-asserted-by":"crossref","unstructured":"Kjell\u00e9n, U.\n                (2000), \n                  Prevention of Accident through Experience Feedback\n               , Taylor \n\t\t\t\t\t&\n\t\t\t\t Francis, London.","DOI":"10.1201\/b17206"},{"key":"key2020121801265969100_b32","unstructured":"Koivunen, E.\n                (2010), \u201cWhy wasn\u2019t i notified: information security incident reporting demystified\u201d, 15th Nordic Conference in Secure IT Systems (Nordsec)."},{"key":"key2020121801265969100_b33","unstructured":"Kral, P.\n                (2011), \n                  Incident Handler\u2019s Handbook\n               , SANS Institute Information Security Reading Room, Swansea, UK."},{"key":"key2020121801265969100_b34","unstructured":"Kurowski, S.\n                and \n                  Frings, S.\n                (2011), \u201cComputational documentation of IT incidents as support for forensic operations\u201d, 6th International Conference on IT Security Incident Management and IT Forensics (IMF), Stuttgart, pp. 37-47. doi: 10.1109\/IMF 2011.18."},{"key":"key2020121801265969100_b35","unstructured":"LaPorte, T.R.\n                and \n                  Consolini, P.M.\n                (1991), \u201cWorking in practice but not in theory: theoretical challenges of\u2018 high \u2013 reliability organizations\u201d, \n                  Journal of Public Administration Research and Theory: J \u2013 PART\n               , Vol. 1 No. 1, pp. 19-48."},{"key":"key2020121801265969100_b36","unstructured":"Levin, M.\n                and \n                  Klev, R.\n                (2002), \u201cForandring som praksis: l\u00e6ring og utvikling i organisasjoner\u201d, \n                  Norwegian [Changes in practice: learning and development in organizations]\n               , Fagbokforlaget, Bergen."},{"key":"key2020121801265969100_b37","doi-asserted-by":"crossref","unstructured":"Line, M.B.\n               , \n                  T\u00f8ndel, I.A.\n                and \n                  Jaatun, M.G.\n                (2014), \u201cInformation security incident management: planning for failure\u201d, 8th International Conference on IT Security Incident Management and IT Forensics (IMF), M\u00fcnster, pp. 47-62.","DOI":"10.1109\/IMF.2014.10"},{"key":"key2020121801265969100_b38","doi-asserted-by":"crossref","unstructured":"MacKenzie, D.\n                and \n                  Pottinger, G.\n                (1997), \u201cMathematics, technology, and trust: formal verification, computer security and the US military\u201d, \n                  IEEE Annals of the History of Computing\n               , Vol. 19 No. 3, pp. 41-59.","DOI":"10.1109\/85.601735"},{"key":"key2020121801265969100_b39","doi-asserted-by":"crossref","unstructured":"Metzger, S.\n               , \n                  Hommel, W.\n                and \n                  Reiser, H.\n                (2011), \u201cIntegrated security incident management \u2013 concepts and real \u2013 world experiences\u201d, 6th International Conference on IT Security Incident Management and IT Forensics (IMF), Washington, DC, pp. 107-121.","DOI":"10.1109\/IMF.2011.15"},{"key":"key2020121801265969100_b40","doi-asserted-by":"crossref","unstructured":"M\u00f6ller, S.\n               , \n                  Ben \u2013 Asher, N.\n               , \n                  Engelbrecht, K.-P.\n               , \n                  Engler, R.\n                and \n                  Meyer, J.\n                (2011), \u201cModelling the behavior of users who are confronted with security mechanisms\u201d, \n                  Computers & Security\n               , Vol. 30 No. 4, pp. 242-256.","DOI":"10.1016\/j.cose.2011.01.001"},{"key":"key2020121801265969100_b41","unstructured":"Pari\u00e9s, J.\n                (2011), \u201cLessons from the Hudson\u201d, in \n                  Hollnagel, E.\n               , \n                  Pari\u00e9s, J, Woods, D.D.\n                and \n                  Wreathall, J.\n                (Eds), \n                  Resilience Engineering in Practice: A Guidebook\n               , Ashgate, Farnham, pp. 9-27."},{"key":"key2020121801265969100_b42","doi-asserted-by":"crossref","unstructured":"Perry, R.W.\n                and \n                  Lindell, M.K.\n                (2003), \u201cPreparedness for emergency response: guidelines for the emergency planning process\u201d, \n                  Disasters\n               , Vol. 27 No. 4, pp. 336-350.","DOI":"10.1111\/j.0361-3666.2003.00237.x"},{"key":"key2020121801265969100_b43","unstructured":"Rhee, H.-S.\n               , \n                  Ryu, Y.U.\n                and \n                  Kim, C.-T.\n                (2012), \u201cUnrealistic optimism on information security management\u201d, \n                  Computers & Security\n               , Vol. 31 No. 2, pp. 221-232, available at: www.sciencedirect.com\/science\/article\/pii\/S0167404811001441"},{"key":"key2020121801265969100_b44","doi-asserted-by":"crossref","unstructured":"Ruighaver, A.B.\n               , \n                  Maynard, S.B.\n                and \n                  Chang, S.\n                (2007), \u201cOrganisational security culture: extending the end \u2013 user perspective\u201d, \n                  Computers & Security\n               , Vol. 26 No. 1, pp. 56-62.","DOI":"10.1016\/j.cose.2006.10.008"},{"key":"key2020121801265969100_b45","unstructured":"Scholl, F.\n                and \n                  Mangold, M.\n                (2011), \u201cProactive incident response\u201d, \n                  The Information Systems Security Association Journal\n               , The Information Systems Security Association, Vol. 9 No. 2."},{"key":"key2020121801265969100_b46","unstructured":"Shedden, P.\n               , \n                  Ahmad, A.\n                and \n                  Ruighaver, A.B.\n                (2011), \u201cInformal learning in security incident response teams\u201d, 22nd Australasian Conference on Information Systems, Sydney."},{"key":"key2020121801265969100_b47","doi-asserted-by":"crossref","unstructured":"Shropshire, J.\n               , \n                  Warkentin, M.\n                and \n                  Sharma, S.\n                (2015), \u201cPersonality, attitudes, and intentions: predicting initial adoption of information security behavior\u201d, \n                  Computers & Security\n               , Vol. 49, pp. 177-191.","DOI":"10.1016\/j.cose.2015.01.002"},{"key":"key2020121801265969100_b48","doi-asserted-by":"crossref","unstructured":"Stanton, J.M.\n               , \n                  Stam, K.R.\n               , \n                  Mastrangelo, P.\n                and \n                  Jolton, J.\n                (2005), \u201cAnalysis of end user security behaviors\u201d, \n                  Computers & Security\n               , Vol. 24 No. 2, pp. 124-133.","DOI":"10.1016\/j.cose.2004.07.001"},{"key":"key2020121801265969100_b49","doi-asserted-by":"crossref","unstructured":"St\u00f8rseth, F.\n                and \n                  Tinmannsvik, R.K.\n                (2012), \u201cThe critical re-action: learning from accidents\u201d, \n                  Safety Science\n               , Vol. 50 No. 10, pp. 1977-1982.","DOI":"10.1016\/j.ssci.2011.11.003"},{"key":"key2020121801265969100_b50","doi-asserted-by":"crossref","unstructured":"T\u00f8ndel, I.A.\n               , \n                  Line, M.B.\n                and \n                  Jaatun, M.G.\n                (2014), \u201cInformation security incident management: current practice as reported in the literature\u201d, \n                  Computers & Security\n               , Vol. 45, pp. 42-57.","DOI":"10.1016\/j.cose.2014.05.003"},{"key":"key2020121801265969100_b51","unstructured":"Trist, E.\n                (1981), \n                  The Evolution of Socio \u2013 Technical Systems: A Conceptual Framework and An Action Research Program\n               , Quality of Working Life Centre, Toronto, ON."},{"key":"key2020121801265969100_b52","doi-asserted-by":"crossref","unstructured":"Trist, E.\n                and \n                  Bamforth, K.W.\n                (1951), \u201cSome social and psychological consequences of the Longwall method of coal getting\u201d, \n                  Human Relations\n               , Vol. 4 No. 1, pp. 3-38.","DOI":"10.1177\/001872675100400101"},{"key":"key2020121801265969100_b53","unstructured":"Turner, B.A.\n                (1978), \n                  Man \u2013 Made Disasters\n               , Wykeham Science Press, London."},{"key":"key2020121801265969100_b54","doi-asserted-by":"crossref","unstructured":"van Niekerk, J.F.\n                and \n                  von Solms, R.\n                (2010), \u201cInformation security culture: a management perspective\u201d, \n                  Computers & Security\n               , Vol. 29 No. 4, pp. 476-486.","DOI":"10.1016\/j.cose.2009.10.005"},{"key":"key2020121801265969100_b55","unstructured":"Weick, K.\n                and \n                  Sutcliffe, K.\n                (2007), \n                  Managing the Unexpected: Resilient Performance in an Age of Uncertainty\n               , John Wiley \n\t\t\t\t\t&\n\t\t\t\t Sons, Hoboken."},{"key":"key2020121801265969100_b56","unstructured":"Werlinger, R.\n               , \n                  Hawkey, K.\n               , \n                  Muldner, K.\n               , \n                  Jaferian, P.\n                and \n                  Beznosov, K.\n                (2008), \u201cThe challenges of using an intrusion detection system: is it worth the effort?\u201d, Proceedings of the 4th Symposium on Usable Privacy and Security (SOUPS), ACM, New York, NY, pp. 107-118, available at: http:\/\/doi.acm.org\/101145\/1408664.1408679"},{"key":"key2020121801265969100_b57","doi-asserted-by":"crossref","unstructured":"Werlinger, R.\n               , \n                  Muldner, K.\n               , \n                  Hawkey, K.\n                and \n                  Beznosov, K.\n                (2010), \u201cPreparation, detection, and analysis: the diagnostic work of IT security incident response\u201d, \n                  Information Management & Computer Security\n               , Vol. 18 No. 1.","DOI":"10.1108\/09685221011035241"},{"key":"key2020121801265969100_b58","unstructured":"Wilson, M.\n               , \n                  de Zafra, D.E.\n               , \n                  Pitcher, S.I.\n               , \n                  Tressler, J.D.\n                and \n                  Ippolito, J.B.\n                (2008), \n                  NIST SP 800 \u2013 16: Information Technology Security Training Requirements: A Role \u2013 and Performance \u2013 Based Model\n               , National Institute of Standards and Technology, Gaithersburg, Maryland."},{"key":"key2020121801265969100_b59","unstructured":"Woods, D.D.\n                (2005), \u201cCreating foresight: lessons for enhancing resilience from Columbia\u201d, in \n                  Starbuck, W.H.\n                and \n                  Farjoun, M.\n                (Eds), \n                  Organization at the Limit: Lessons from the Columbia Disaster\n               , Blackwell Publishing, Oxford."},{"key":"key2020121801265969100_b60","unstructured":"Woods, D.D.\n                and \n                  Hollnagel, E.\n                (2006), \u201cPrologue: resilience engineering concepts\u201d, in \n                  Hollnagel, E.\n               , \n                  Woods, D.D.\n                and \n                  Leveson, N.\n                (Eds), \n                  Resilience Engineering. Concepts and Precepts\n               , Ashgate, Aldershot."}],"container-title":["Information &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/ICS-01-2015-0003","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-01-2015-0003\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-01-2015-0003\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T01:22:33Z","timestamp":1753406553000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/24\/1\/20-37\/108717"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,3,14]]},"references-count":60,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2016,3,14]]}},"alternative-id":["10.1108\/ICS-01-2015-0003"],"URL":"https:\/\/doi.org\/10.1108\/ics-01-2015-0003","relation":{},"ISSN":["2056-4961"],"issn-type":[{"type":"print","value":"2056-4961"}],"subject":[],"published":{"date-parts":[[2016,3,14]]}}}