{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T03:48:29Z","timestamp":1784346509699,"version":"3.55.0"},"reference-count":45,"publisher":"Emerald","issue":"2","license":[{"start":{"date-parts":[[2023,10,3]],"date-time":"2023-10-03T00:00:00Z","timestamp":1696291200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ICS"],"published-print":{"date-parts":[[2024,4,17]]},"abstract":"<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title>\n<jats:p>Security assurance evaluation (SAE) is a well-established approach for assessing the effectiveness of security measures in systems. However, one aspect that is often overlooked in these evaluations is the assurance context in which they are conducted. This paper aims to explore the role of assurance context in system SAEs and proposes a conceptual model to integrate the assurance context into the evaluation process.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title>\n<jats:p>The conceptual model highlights the interrelationships between the various elements of the assurance context, including system boundaries, stakeholders, security concerns, regulatory compliance and assurance assumptions and regulatory compliance.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Findings<\/jats:title>\n<jats:p>By introducing the proposed conceptual model, this research provides a framework for incorporating the assurance context into SAEs and offers insights into how it can influence the evaluation outcomes.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title>\n<jats:p>By delving into the concept of assurance context, this research seeks to shed light on how it influences the scope, methodologies and outcomes of assurance evaluations, ultimately enabling organizations to strengthen their system security postures and mitigate risks effectively.<\/jats:p>\n<\/jats:sec>","DOI":"10.1108\/ics-06-2023-0101","type":"journal-article","created":{"date-parts":[[2023,10,3]],"date-time":"2023-10-03T07:11:28Z","timestamp":1696317088000},"page":"159-178","source":"Crossref","is-referenced-by-count":14,"title":["Exploring the role of assurance context in system security assurance evaluation: a conceptual model"],"prefix":"10.1108","volume":"32","author":[{"given":"Shao-Fang","family":"Wen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Basel","family":"Katt","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","published-online":{"date-parts":[[2023,10,3]]},"reference":[{"key":"key2024041515463991700_ref001","first-page":"304","article-title":"Towards a better understanding of context and context-awareness","year":"1999"},{"key":"key2024041515463991700_ref002","doi-asserted-by":"crossref","first-page":"644","DOI":"10.1109\/GCCE46687.2019.9015599","article-title":"Ontology-based dynamic and context-aware security assessment automation for critical applications","volume-title":"2019 IEEE 8th Global Conference on Consumer Electronics (GCCE)","year":"2019"},{"key":"key2024041515463991700_ref003","volume-title":"Security Engineering: A Guide to Building Dependable Distributed Systems","year":"2020"},{"issue":"5","key":"key2024041515463991700_ref004","first-page":"28","article-title":"The semantic web","volume":"284","year":"2001","journal-title":"Scientific American"},{"key":"key2024041515463991700_ref005","first-page":"45","article-title":"Groupware system design and the context concept","volume-title":"Computer Supported Cooperative Work in Design I: 8th International Conference, CSCWD 2004","year":"2005"},{"key":"key2024041515463991700_ref006","volume-title":"Information Assurance: Managing Organizational IT Security Risks","year":"2002"},{"key":"key2024041515463991700_ref007","unstructured":"Br\u00e9zillon, P. (2002), \u201cModeling and using context: past, present and future\u201d, Rapport de recherche interne LIP6, Paris."},{"issue":"3","key":"key2024041515463991700_ref008","doi-asserted-by":"crossref","first-page":"537","DOI":"10.3166\/ria.19.537-556","article-title":"Reinforcing shared context to improve collaboration","volume":"19","year":"2005","journal-title":"Revue D'intelligence Artificielle"},{"key":"key2024041515463991700_ref009","unstructured":"Cambridge Dictionary (2023), \u201cContext\u201d, available at: https:\/\/dictionary.cambridge.org\/dictionary\/english\/context (accessed 3 May 2023)."},{"issue":"16","key":"key2024041515463991700_ref010","doi-asserted-by":"crossref","first-page":"2768","DOI":"10.1002\/sec.1200","article-title":"Model driven security framework for software design and verification","volume":"8","year":"2015","journal-title":"Security and Communication Networks"},{"issue":"1","key":"key2024041515463991700_ref011","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1007\/s007790170019","article-title":"Understanding and using context","volume":"5","year":"2001","journal-title":"Personal and Ubiquitous Computing"},{"key":"key2024041515463991700_ref012","article-title":"A semantic model for security evaluation of information systems","year":"2020","journal-title":"Journal of Cyber Security and Mobility: 301\u201330-01\u201330"},{"issue":"2","key":"key2024041515463991700_ref013","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1201\/1078\/45099.22.2.20050301\/87274.3","article-title":"A model of information assurance benefits","volume":"22","year":"2005","journal-title":"Information Systems Management"},{"key":"key2024041515463991700_ref014","first-page":"1","article-title":"Towards an ontology for IoT context-based security evaluation","volume-title":"2019 Global IoT Summit (GIoTS)","year":"2019"},{"issue":"3","key":"key2024041515463991700_ref015","doi-asserted-by":"crossref","first-page":"365","DOI":"10.1007\/s00766-017-0287-5","article-title":"Semantic hierarchies for extracting, modeling, and connecting compliance requirements in information security control standards","volume":"24","year":"2019","journal-title":"Requirements Engineering"},{"key":"key2024041515463991700_ref016","first-page":"266","volume-title":"Smart Spaces and Next Generation Wired\/Wireless Networking: 9th International Conference, NEW2AN 2009 and Second Conference on Smart Spaces","year":"2009"},{"key":"key2024041515463991700_ref017","volume-title":"Using the Common Criteria for IT Security Evaluation","year":"2002"},{"key":"key2024041515463991700_ref018","unstructured":"ISO (2022), \u201cISO\/IEC 15408-1:2022 information security, cybersecurity and privacy protection \u2013 evaluation criteria for IT security\u201d, available at: www.iso.org\/standard\/72891.html (accessed 3 May 2023)."},{"issue":"1","key":"key2024041515463991700_ref019","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1108\/03055720810870897","article-title":"Exploring the contextual dimensions of organization from knowledge management perspective","volume":"38","year":"2008","journal-title":"VINE"},{"issue":"5","key":"key2024041515463991700_ref020","doi-asserted-by":"crossref","first-page":"602","DOI":"10.1016\/j.envsoft.2006.01.004","article-title":"Ten iterative steps in development and evaluation of environmental models","volume":"21","year":"2006","journal-title":"Environmental Modelling and Software"},{"key":"key2024041515463991700_ref021","first-page":"511","article-title":"Recommendations for effective security assurance of software-dependent systems","volume-title":"Intelligent Computing: Proceedings of the 2020 Computing Conference","year":"2020"},{"issue":"2","key":"key2024041515463991700_ref022","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1016\/S1353-4858(06)70337-3","article-title":"Security awareness: switch to a better programme","volume":"2006","year":"2006","journal-title":"Network Security"},{"key":"key2024041515463991700_ref023","article-title":"'Quantitative security assurance","volume-title":"Exploring Security in Software Architecture and Design","year":"2019"},{"key":"key2024041515463991700_ref024","doi-asserted-by":"crossref","unstructured":"Kirlappos, I., Parkin, S. and Sasse, M.A. (2014), \u201cLearning from \u2018shadow security\u2019: why understanding non-compliance provides the basis for effective security\u201d.","DOI":"10.14722\/usec.2014.23007"},{"issue":"1","key":"key2024041515463991700_ref025","doi-asserted-by":"crossref","first-page":"67","DOI":"10.2307\/249410","article-title":"A set of principles for conducting and evaluating interpretive field studies in information systems","volume":"23","year":"1999","journal-title":"MIS Quarterly"},{"key":"key2024041515463991700_ref026","article-title":"Context framework \u2013 an open approach to enhance organisational memory systems with context modelling techniques","year":"2000"},{"issue":"4","key":"key2024041515463991700_ref027","doi-asserted-by":"crossref","first-page":"467","DOI":"10.1016\/S0167-9236(02)00126-4","article-title":"KnowledgeScope: managing knowledge in context","volume":"35","year":"2003","journal-title":"Decision Support Systems"},{"key":"key2024041515463991700_ref028","doi-asserted-by":"crossref","first-page":"1012","DOI":"10.1109\/IAEAC47372.2019.8997783","article-title":"Context-aware security evaluation ontology for cloud services","volume-title":"2019 IEEE 4th Advanced Information Technology, Electronic and Automation Control Conference (IAEAC)","year":"2019"},{"issue":"1","key":"key2024041515463991700_ref029","doi-asserted-by":"crossref","first-page":"193","DOI":"10.1016\/j.jss.2011.08.013","article-title":"Appraisal and reporting of security assurance at operational systems level","volume":"85","year":"2012","journal-title":"Journal of Systems and Software"},{"key":"key2024041515463991700_ref030","unstructured":"OWASP (2021), \u201cApplication security verification standard (ASVS)\u201d, available at: https:\/\/owasp.org\/www-project-application-security-verification-standard\/ (accessed 3 June 2022.)."},{"key":"key2024041515463991700_ref031","volume-title":"Information Security Risk Analysis","year":"2005"},{"key":"key2024041515463991700_ref032","first-page":"37","article-title":"An evaluation ontology applied to connected vehicle security assurance","volume-title":"INCOSE International Symposium","year":"2019"},{"key":"key2024041515463991700_ref033","article-title":"Towards an ontology of security assessment: a core model proposal","volume-title":"Information Technology-New Generations","year":"2018"},{"key":"key2024041515463991700_ref034","article-title":"Managing information security risk: Organization, mission, and information system view","year":"2011"},{"key":"key2024041515463991700_ref035","first-page":"232","article-title":"Developing shared context within group stories","volume-title":"Groupware: Design, Implementation, and Use: 11th International Workshop, CRIWG 2005","year":"2005"},{"key":"key2024041515463991700_ref036","first-page":"17","article-title":"IT security review: privacy, protection, access control, assurance and system security","volume":"2","year":"2007","journal-title":"International Journal of Multimedia and Ubiquitous Engineering"},{"key":"key2024041515463991700_ref037","first-page":"73","article-title":"Ontology-based model for automotive security verification and validation","volume-title":"Proceedings of the 21st International Conference on Information Integration and Web-based Applications and Services","year":"2019"},{"key":"key2024041515463991700_ref038","article-title":"System security assurance: a systematic literature review","year":"2021"},{"key":"key2024041515463991700_ref039","doi-asserted-by":"crossref","first-page":"100496","DOI":"10.1016\/j.cosrev.2022.100496","article-title":"System security assurance: a systematic literature review","volume":"45","year":"2022","journal-title":"Computer Science Review"},{"key":"key2024041515463991700_ref040","doi-asserted-by":"crossref","first-page":"861","DOI":"10.1109\/CSCWD.2012.6221922","article-title":"Defining context in a business process collaborative elicitation approach","volume-title":"Proceedings of the 2012 IEEE 16th International Conference on Computer Supported Cooperative Work in Design (CSCWD)","year":"2012"},{"issue":"7","key":"key2024041515463991700_ref041","doi-asserted-by":"crossref","first-page":"598","DOI":"10.1016\/j.im.2013.08.004","article-title":"Theorizing the concept and role of assurance in information systems security","volume":"50","year":"2013","journal-title":"Information and Management"},{"key":"key2024041515463991700_ref042","volume-title":"Plans and Situated Actions: The Problem of Human-Machine Communication","year":"1987"},{"issue":"6","key":"key2024041515463991700_ref043","doi-asserted-by":"crossref","first-page":"473","DOI":"10.1016\/S0959-4752(98)00031-0","article-title":"From context to contextualizing","volume":"8","year":"1998","journal-title":"Learning and Instruction"},{"key":"key2024041515463991700_ref044","first-page":"1","article-title":"Refining the evaluation of the degree of security of a system built using security patterns","volume-title":"Proceedings of the 15th International Conference on Availability, Reliability and Security","year":"2020"},{"issue":"3","key":"key2024041515463991700_ref045","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1016\/S1363-4127(01)00309-0","article-title":"Information security governance","volume":"6","year":"2001","journal-title":"Information Security Technical Report"}],"container-title":["Information &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-06-2023-0101\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-06-2023-0101\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T01:23:00Z","timestamp":1753406580000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/32\/2\/159-178\/1229171"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,3]]},"references-count":45,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2023,10,3]]},"published-print":{"date-parts":[[2024,4,17]]}},"alternative-id":["10.1108\/ICS-06-2023-0101"],"URL":"https:\/\/doi.org\/10.1108\/ics-06-2023-0101","relation":{},"ISSN":["2056-4961","2056-4961"],"issn-type":[{"value":"2056-4961","type":"print"},{"value":"2056-4961","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,10,3]]}}}