{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,27]],"date-time":"2026-01-27T15:49:36Z","timestamp":1769528976042,"version":"3.49.0"},"reference-count":48,"publisher":"Emerald","issue":"5","license":[{"start":{"date-parts":[[2021,8,16]],"date-time":"2021-08-16T00:00:00Z","timestamp":1629072000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ICS"],"published-print":{"date-parts":[[2021,11,12]]},"abstract":"<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title>\n<jats:p>This paper aims to present a tool-supported approach for visualising personas as social goal models, which can subsequently be used to identify security tensions.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title>\n<jats:p>The authors devised an approach to partially automate the construction of social goal models from personas. The authors provide two examples of how this approach can identify previously hidden implicit vulnerabilities and validate ethical hazards faced by penetration testers and their safeguards.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Findings<\/jats:title>\n<jats:p>Visualising personas as goal models makes it easier for stakeholders to see implications of their goals being satisfied or denied and designers to incorporate the creation and analysis of such models into the broader requirements engineering (RE) tool-chain.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title>\n<jats:p>The approach can be used with minimal changes to existing user experience and goal modelling approaches and security RE tools.<\/jats:p>\n<\/jats:sec>","DOI":"10.1108\/ics-03-2021-0035","type":"journal-article","created":{"date-parts":[[2021,8,17]],"date-time":"2021-08-17T02:44:36Z","timestamp":1629168276000},"page":"787-815","source":"Crossref","is-referenced-by-count":6,"title":["Visualising personas as goal models to find security tensions"],"prefix":"10.1108","volume":"29","author":[{"given":"Shamal","family":"Faily","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Claudia","family":"Iacob","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Raian","family":"Ali","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Duncan","family":"Ki-Aries","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","published-online":{"date-parts":[[2021,8,16]]},"reference":[{"issue":"1","key":"key2021111012415464400_ref001","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1016\/j.infsof.2012.06.013","article-title":"Reasoning with contextual requirements: detecting inconsistency and conflicts","volume":"55","year":"2013","journal-title":"Information and Software Technology"},{"issue":"8","key":"key2021111012415464400_ref002","doi-asserted-by":"crossref","first-page":"841","DOI":"10.1002\/int.20433","article-title":"Evaluating goal models within the goal-oriented requirement language","volume":"25","year":"2010","journal-title":"International Journal of Intelligent Systems"},{"key":"key2021111012415464400_ref003","article-title":"ACM code of ethics and professional conduct","author":"Association for Computer Machinery","year":"2018"},{"key":"key2021111012415464400_ref004","unstructured":"AT&T (2020), \u201cGraphviz web site\u201d, available at: www.graphviz.org"},{"key":"key2021111012415464400_ref005","volume-title":"Rationale-Based Software Engineering","year":"2008"},{"key":"key2021111012415464400_ref006","first-page":"634","article-title":"The persona\u2019s new clothes: methodological and practical arguments against a popular method","year":"2006"},{"issue":"4","key":"key2021111012415464400_ref007","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1109\/MS.2013.80","article-title":"Meet Elaine: a persona-driven approach to exploring architecturally significant requirements","volume":"30","year":"2013","journal-title":"IEEE Software"},{"key":"key2021111012415464400_ref008","volume-title":"About Face: The Essentials of Interaction Design","year":"2014"},{"key":"key2021111012415464400_ref009","volume-title":"Basics of Qualitative Research: techniques and Procedures for Developing Grounded Theory","year":"2008","edition":"3rd ed."},{"key":"key2021111012415464400_ref010","unstructured":"CREST (2014), \u201cCode of conduct for CREST qualified individuals\u201d, available at: www.crest-approved.org\/wp-content\/uploads\/1401-Code-of-Conduct-Individual-v4.0.pdf"},{"key":"key2021111012415464400_ref011","unstructured":"CREST (2021), \u201cCREST: Accredited companies providing penetration testing\u201d, available at: https:\/\/service-selection-platform.crest-approved.org\/accredited_companies\/penetration_testing\/"},{"issue":"1","key":"key2021111012415464400_ref012","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1007\/s00766-009-0090-z","article-title":"A vulnerability-centric requirements engineering framework: analyzing security attacks, countermeasures, and requirements based on vulnerabilities","volume":"15","year":"2010","journal-title":"Requirements Engineering"},{"key":"key2021111012415464400_ref013","first-page":"114","article-title":"Bridging User-Centered design and requirements engineering with GRL and persona cases","year":"2011"},{"key":"key2021111012415464400_ref014","volume-title":"Designing Usable and Secure Software with IRIS and CAIRIS","year":"2018"},{"key":"key2021111012415464400_ref015","first-page":"124","article-title":"Barry is not the weakest link: eliciting secure system requirements with personas","year":"2010"},{"key":"key2021111012415464400_ref016","first-page":"2267","article-title":"Persona cases: a technique for grounding personas","year":"2011"},{"key":"key2021111012415464400_ref017","first-page":"17","article-title":"Eliciting and visualising trust expectations using persona trust characteristics and goal models","year":"2014"},{"key":"key2021111012415464400_ref018","first-page":"185","article-title":"Identifying implicit vulnerabilities through personas as goal models","volume-title":"Computer Security","year":"2020"},{"key":"key2021111012415464400_ref019","first-page":"186","article-title":"Contextualisation of data flow diagrams for security analysis","volume-title":"Graphical Models for Security","year":"2020"},{"key":"key2021111012415464400_ref020","article-title":"Secure system? Challenge accepted: finding and resolving security failures using security premortems","volume":"2012","year":"2012","journal-title":"Designing Interactive Secure Systems: Workshop at British HCI"},{"key":"key2021111012415464400_ref021","first-page":"233","article-title":"Ethical dilemmas and dimensions in penetration testing","year":"2015"},{"key":"key2021111012415464400_ref022","volume-title":"Value-Sensitive Design: Shaping Technology with Moral Imagination","year":"2019"},{"key":"key2021111012415464400_ref023","first-page":"1209","article-title":"Personas and decision making in the design process: an ethnographic case study","year":"2012"},{"key":"key2021111012415464400_ref024","first-page":"167","article-title":"Modeling security requirements through ownership, permission and delegation","year":"2005"},{"key":"key2021111012415464400_ref025","first-page":"167","article-title":"Reasoning with goal models","year":"2003"},{"issue":"2","key":"key2021111012415464400_ref026","doi-asserted-by":"crossref","first-page":"285","DOI":"10.1007\/s00766-015-0221-7","article-title":"A questionnaire-based survey methodology for systematically validating goal-oriented models","volume":"21","year":"2016","journal-title":"Requirements Engineering"},{"issue":"2","key":"key2021111012415464400_ref027","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1007\/s00766-007-0056-y","article-title":"Clear justification of modeling decisions for goal-oriented requirements engineering","volume":"13","year":"2008","journal-title":"Requirements Engineering"},{"issue":"9","key":"key2021111012415464400_ref028","first-page":"18","article-title":"Performing a project Premortem","volume":"85","year":"2007","journal-title":"Harvard Business Review"},{"key":"key2021111012415464400_ref029","first-page":"151","article-title":"Security and privacy requirements analysis within a social setting","year":"2003"},{"key":"key2021111012415464400_ref030","first-page":"337","article-title":"Detecting conflicts between functional and security requirements with secure tropos: John Rusnak and the allied Irish bank","volume-title":"Social Modeling for Requirements Engineering","year":"2011"},{"key":"key2021111012415464400_ref031","first-page":"2247","article-title":"Collaboration personas: a new approach to designing workplace collaboration tools","year":"2011"},{"key":"key2021111012415464400_ref032","first-page":"412","article-title":"Crowd sourcing the creation of personae non gratae for requirements-phase threat modeling","year":"2017"},{"key":"key2021111012415464400_ref033","first-page":"171","article-title":"Improving the effectiveness of visual representations in requirements engineering: an evaluation of i* visual syntax","year":"2009"},{"issue":"2","key":"key2021111012415464400_ref034","doi-asserted-by":"crossref","first-page":"285","DOI":"10.1142\/S0218194007003240","article-title":"Secure tropos: a security-oriented extension of the tropos methodology","volume":"17","year":"2007","journal-title":"International Journal of Software Engineering and Knowledge Engineering"},{"key":"key2021111012415464400_ref035","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1016\/j.cose.2015.09.001","article-title":"Necessity for ethics in social engineering research","volume":"55","year":"2015","journal-title":"Computers and Security"},{"key":"key2021111012415464400_ref036","first-page":"352","article-title":"A persona-based modelling for contextual requirements","volume-title":"Requirements Engineering: Foundation for Software Quality","year":"2018"},{"key":"key2021111012415464400_ref037","first-page":"79","article-title":"Designing secure socio-technical systems with STS-ml","year":"2013"},{"key":"key2021111012415464400_ref038","first-page":"607","article-title":"Strengths and weaknesses of the i* framework: an empirical evaluation","volume-title":"Social Modeling for Requirements Engineering","year":"2011"},{"issue":"3","key":"key2021111012415464400_ref039","first-page":"265","article-title":"Ethical hazards: a motive, means, and opportunity approach for curbing corporate unethical behavior","volume":"107","year":"2011","journal-title":"Journal of Business Ethics"},{"key":"key2021111012415464400_ref040","first-page":"353","article-title":"Where do goals come from: the underlying principles of goal-oriented requirements engineering","year":"2005"},{"issue":"4","key":"key2021111012415464400_ref041","first-page":"493","article-title":"Rational decision making in business organizations","volume":"69","year":"1979","journal-title":"The American Economic Review"},{"key":"key2021111012415464400_ref042","volume-title":"Capturing Dependability Threats in Conceptual Modelling","year":"2007"},{"key":"key2021111012415464400_ref043","volume-title":"The Uses of Argument","year":"2003","edition":"updated ed."},{"key":"key2021111012415464400_ref044","volume-title":"Requirements Engineering: From System Goals to UML Models to Software Specifications","year":"2009"},{"key":"key2021111012415464400_ref045","first-page":"226","article-title":"Towards modeling and reasoning support for early-phase requirements engineering","year":"1997"},{"key":"key2021111012415464400_ref046","first-page":"99","article-title":"Social modeling and i*","volume-title":"Conceptual Modeling: Foundations and Applications: Essays in Honor of John Mylopoulos","year":"2009"},{"key":"key2021111012415464400_ref047","article-title":"Social modeling for requirements engineering: an introduction","volume-title":"Social Modeling for Requirements Engineering","year":"2011"},{"key":"key2021111012415464400_ref048","unstructured":"Yu, E. (1995), \u201cModeling strategic relationships for process reengineering\u201d, PhD thesis, University of Toronto."}],"container-title":["Information &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-03-2021-0035\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-03-2021-0035\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T01:22:47Z","timestamp":1753406567000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/29\/5\/787-815\/105846"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,16]]},"references-count":48,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2021,8,16]]},"published-print":{"date-parts":[[2021,11,12]]}},"alternative-id":["10.1108\/ICS-03-2021-0035"],"URL":"https:\/\/doi.org\/10.1108\/ics-03-2021-0035","relation":{},"ISSN":["2056-4961","2056-4961"],"issn-type":[{"value":"2056-4961","type":"print"},{"value":"2056-4961","type":"print"}],"subject":[],"published":{"date-parts":[[2021,8,16]]}}}