{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T17:46:08Z","timestamp":1778175968826,"version":"3.51.4"},"reference-count":64,"publisher":"Emerald","issue":"4","license":[{"start":{"date-parts":[[2019,6,20]],"date-time":"2019-06-20T00:00:00Z","timestamp":1560988800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ICS"],"published-print":{"date-parts":[[2019,9,23]]},"abstract":"<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title>\n<jats:p>Within critical-infrastructure industries, bow-tie analysis is an established way of eliciting requirements for safety and reliability concerns. Because of the ever-increasing digitalisation and coupling between the cyber and physical world, security has become an additional concern in these industries. The purpose of this paper is to evaluate how well bow-tie analysis performs in the context of security, and the study\u2019s hypothesis is that the bow-tie notation has a suitable expressiveness for security and safety.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title>\n<jats:p>This study uses a formal, controlled quasi-experiment on two sample populations \u2013 security experts and security graduate students \u2013 working on the same case. As a basis for comparison, the authors used a similar experiment with misuse case analysis, a well-known technique for graphical security modelling.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Findings<\/jats:title>\n<jats:p>The results show that the collective group of graduate students, inexperienced in security modelling, perform similarly as security experts in a well-defined scope and familiar target system\/situation. The students showed great creativity, covering most of the same threats and consequences as the experts identified and discovering additional ones. One notable difference was that these na\u00efve professionals tend to focus on preventive barriers, leading to requirements for risk mitigation or avoidance, while experienced professionals seem to balance this more with reactive barriers and requirements for incident management.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title>\n<jats:p>Our results are useful in areas where we need to evaluate safety and security concerns together, especially for domains that have experience in health, safety and environmental hazards, but now need to expand this with cybersecurity as well.<\/jats:p>\n<\/jats:sec>","DOI":"10.1108\/ics-11-2018-0132","type":"journal-article","created":{"date-parts":[[2019,6,20]],"date-time":"2019-06-20T08:40:47Z","timestamp":1561020047000},"page":"536-561","source":"Crossref","is-referenced-by-count":8,"title":["An experimental evaluation of bow-tie analysis for security"],"prefix":"10.1108","volume":"27","author":[{"given":"Per H\u00e5kon","family":"Meland","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Karin","family":"Bernsmed","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Fr\u00f8ystad","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jingyue","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guttorm","family":"Sindre","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","published-online":{"date-parts":[[2019,6,20]]},"reference":[{"key":"key2021102014190997500_ref001","doi-asserted-by":"crossref","first-page":"175","DOI":"10.1016\/j.cose.2017.09.004","article-title":"A safety\/security risk analysis approach of industrial control systems: a cyber bowtie \u2013 combining new version of attack tree with bowtie analysis","volume":"72","year":"2018","journal-title":"Computers and Security"},{"issue":"1","key":"key2021102014190997500_ref002","doi-asserted-by":"crossref","first-page":"283","DOI":"10.1109\/JPROC.2011.2165689","article-title":"Ensuring safety, security, and sustainability of mission-critical cyber-physical systems","volume":"100","year":"2012","journal-title":"Proceedings of the Ieee"},{"issue":"3","key":"key2021102014190997500_ref003","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1109\/MSP.2011.2","article-title":"Security modeling and analysis","volume":"9","year":"2011","journal-title":"IEEE Security and Privacy Magazine"},{"key":"key2021102014190997500_ref004","unstructured":"BBC (2016), \u201cAlmost 6,000 online shops hit by hackers\u201d, [Online], available at: www.bbc.com\/news\/technology-37643754 (accessed 8 November 2018)."},{"key":"key2021102014190997500_ref005","first-page":"38","article-title":"Visualizing cyber security risks with bow-tie diagrams","volume-title":"International Workshop on Graphical Models for Security","year":"2017"},{"key":"key2021102014190997500_ref006","volume-title":"Internet Shut down in Algeria to Stop Exam Cheats","year":"2018"},{"key":"key2021102014190997500_ref007","first-page":"239","article-title":"Issues in using students in empirical studies in software engineering education","volume-title":"Software Metrics Symposium, 2003 Proceedings. Ninth International","year":"2004"},{"key":"key2021102014190997500_ref008","article-title":"Security risks and protection in online learning: a survey","volume":"14","year":"2013","journal-title":"The International Review of Research in Open and Distributed Learning"},{"key":"key2021102014190997500_ref009","first-page":"50","article-title":"Integrated safety and security risk assessment methods: a survey of key characteristics and applications","volume-title":"International Conference on Critical Information Infrastructures Security","year":"2016"},{"issue":"1","key":"key2021102014190997500_ref010","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1007\/s00766-009-0090-z","article-title":"A vulnerability-centric requirements engineering framework: analyzing security attacks, countermeasures, and requirements based on vulnerabilities","volume":"15","year":"2010","journal-title":"Requirements Engineering"},{"issue":"7","key":"key2021102014190997500_ref011","doi-asserted-by":"crossref","first-page":"661","DOI":"10.1109\/TSE.2015.2396526","article-title":"Extending the UML statecharts notation to model security aspects","volume":"41","year":"2015","journal-title":"IEEE Transactions on Software Engineering"},{"issue":"1","key":"key2021102014190997500_ref012","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1007\/s00766-009-0092-x","article-title":"A comparison of security requirements engineering methods","volume":"15","year":"2010","journal-title":"Requirements Engineering"},{"issue":"1","key":"key2021102014190997500_ref013","doi-asserted-by":"crossref","first-page":"452","DOI":"10.1007\/s10664-017-9523-3","article-title":"Empirical software engineering experts on the use of students and professionals in experiments","volume":"23","year":"2018","journal-title":"Empirical Software Engineering"},{"issue":"3","key":"key2021102014190997500_ref014","article-title":"Security use cases","volume":"2","year":"2003","journal-title":"Journal of Object Technology"},{"key":"key2021102014190997500_ref015","unstructured":"Green, D. (2018), \u201cIf you shopped at these 7 stores in the last year, your data might have been stolen\u201d, [Online]. Business Insider Nordic, available at: https:\/\/nordic.businessinsider.com\/data-breaches-2018-4 (accessed 8 November 2018)."},{"key":"key2021102014190997500_ref016","first-page":"470","article-title":"Experimental context classification: incentives and experience of subjects","volume-title":"Proceedings of the 27th international conference on Software engineering","year":"2005"},{"issue":"1","key":"key2021102014190997500_ref017","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1007\/s00766-009-0093-9","article-title":"Eliciting security requirements and tracing them to design: an integration of common criteria, heuristics, and UMLsec","volume":"15","year":"2010","journal-title":"Requirements Engineering"},{"key":"key2021102014190997500_ref018","volume-title":"ISO\/IEC 27005: 2011 Information Technology \u2013 Security Techniques\u2013Information Security Risk Management","author":"ISO\/IEC","year":"2011"},{"key":"key2021102014190997500_ref019","volume-title":"Object-Oriented Software Engineering: A Use Case Driven Approach","year":"1993"},{"key":"key2021102014190997500_ref020","article-title":"Using assurance cases and Boolean logic driven Markov processes to formalise cyber security concerns for safety-critical interaction with global navigation satellite systems","volume":"45","year":"2011","journal-title":"Electronic Communications of the EASST"},{"key":"key2021102014190997500_ref021","first-page":"412","article-title":"UMLsec: extending UML for secure systems development","year":"2002"},{"key":"key2021102014190997500_ref022","doi-asserted-by":"crossref","first-page":"108","DOI":"10.1016\/j.ssci.2013.01.022","article-title":"Quantitative risk analysis of offshore drilling operations: a Bayesian approach","volume":"57","year":"2013","journal-title":"Safety Science"},{"key":"key2021102014190997500_ref023","unstructured":"Kimminich, B. (2018), \u201cOWASP juice shop tool project\u201d, [Online]. OWASP, available: www.owasp.org\/index.php\/OWASP_Juice_Shop_Project (accessed 8 November 2018)."},{"issue":"8","key":"key2021102014190997500_ref024","doi-asserted-by":"crossref","first-page":"721","DOI":"10.1109\/TSE.2002.1027796","article-title":"Preliminary guidelines for empirical research in software engineering","volume":"28","year":"2002","journal-title":"IEEE Transactions on Software Engineering"},{"issue":"1","key":"key2021102014190997500_ref025","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1093\/logcom\/exs029","article-title":"Attack\u2013defense trees","volume":"24","year":"2014","journal-title":"Journal of Logic and Computation"},{"key":"key2021102014190997500_ref026","doi-asserted-by":"crossref","first-page":"156","DOI":"10.1016\/j.ress.2015.02.008","article-title":"A survey of approaches combining safety and security for industrial control systems","volume":"139","year":"2015","journal-title":"Reliability Engineering and System Safety"},{"key":"key2021102014190997500_ref027","first-page":"25","article-title":"Quantitative security and safety analysis with attack-fault trees. High assurance systems engineering (HASE)","volume-title":"IEEE 18th International Symposium on, 2017","year":"2017"},{"key":"key2021102014190997500_ref028","first-page":"22","article-title":"Lessons learned from real world application of the bow-tie method","volume-title":"6th Global Congress on Process Safety","year":"2010"},{"key":"key2021102014190997500_ref029","first-page":"426","article-title":"SecureUML: a UML-based modeling language for model-driven security","volume-title":"International Conference on the Unified Modeling Language","year":"2002"},{"key":"key2021102014190997500_ref030","unstructured":"London, M. (2017), \u201c5 Ways to cheat on online exams\u201d, [Online]. Inside Higher ED, available at: www.insidehighered.com\/digital-learning\/views\/2017\/09\/20\/creative-ways-students-try-cheat-online-exams (accessed 27 September 2018)."},{"key":"key2021102014190997500_ref031","doi-asserted-by":"crossref","unstructured":"Lu, L., Liang, W., Zhang, L., Zhang, H., Lu, Z. and Shan, J. (2015), \u201cA comprehensive risk evaluation method for natural gas pipelines by combining a risk matrix with a bow-tie model\u201d, Journal of Natural Gas Science and Engineering, Vol. 25, pp. 124-133.","DOI":"10.1016\/j.jngse.2015.04.029"},{"key":"key2021102014190997500_ref032","unstructured":"Maggi, F., Quarta, D., Pogliani, M., Polino, M., Zanchettin, A.M. and Zanero, S. (2017), \u201cRogue robots: testing the limits of an industrial robot\u2019s security. Technical report\u201d, Trend Micro, Politecnico di Milano."},{"key":"key2021102014190997500_ref033","unstructured":"Marsh, S. (2017), \u201cMore university students are using tech to cheat in exams\u201d, [Online]. The Guardian, available at: www.theguardian.com\/education\/2017\/apr\/10\/more-university-students-are-using-tech-to-in-exams (accessed 27 September 2018)."},{"key":"key2021102014190997500_ref034","first-page":"1397","article-title":"Alignment of misuse cases with security risk management","volume-title":"Availability, reliability and security, ARES 08. Third international conference on, 2008","year":"2008"},{"key":"key2021102014190997500_ref035","first-page":"121","volume-title":"Design of a Modelling Language for Information System Security Risk Management","year":"2007"},{"key":"key2021102014190997500_ref036","unstructured":"Meland, P.H. (2018a), \u201cBowtie experiment NTNU SINTEF 2018\u201d, [Online]. NTNU, available at: https:\/\/doi.org\/10.21400\/f685ryu2 (accessed 20 November 2018)."},{"key":"key2021102014190997500_ref037","unstructured":"Meland, P.H. (2018b), \u201cMisusecaseexperiments_SINTEF\u201d, [Online]. Zenodo, available at: https:\/\/doi.org\/10.5281\/zenodo.1492322 (accessed 20 November 2018)."},{"key":"key2021102014190997500_ref038","article-title":"An experimental evaluation of bow-tie analysis for cybersecurity requirements","volume-title":"ESORICS 2018 International Workshops, CyberICPS 2018 and SECPRE 2018, September 06-07 2018","year":"2018"},{"issue":"4","key":"key2021102014190997500_ref039","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1016\/j.csi.2010.01.006","article-title":"A systematic review of security requirements engineering","volume":"32","year":"2010","journal-title":"Computer Standards Interfaces"},{"issue":"2","key":"key2021102014190997500_ref040","doi-asserted-by":"crossref","first-page":"465","DOI":"10.1016\/j.jhazmat.2011.05.035","article-title":"Application of a generic bow-tie based risk analysis framework on risk management of sea ports and offshore terminals","volume":"192","year":"2011","journal-title":"Journal of Hazardous Materials"},{"key":"key2021102014190997500_ref041","article-title":"The method evaluation model: a theoretical model for validating information systems design methods","volume":"79","year":"2003","journal-title":"ECIS 2003 Proceedings"},{"key":"key2021102014190997500_ref042","doi-asserted-by":"crossref","first-page":"285","DOI":"10.1142\/S0218194007003240","article-title":"Secure tropos: a security-oriented extension of the tropos methodology","volume":"17","year":"2007","journal-title":"International Journal of Software Engineering and Knowledge Engineering"},{"key":"key2021102014190997500_ref043","article-title":"Safety and security review for the process industries: application of HAZOP","volume-title":"PHA, What-If and SVA Reviews","year":"2014"},{"issue":"4","key":"key2021102014190997500_ref044","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1145\/190679.190680","article-title":"Design and analysis in software engineering: the language of case studies and formal experiments","volume":"19","year":"1994","journal-title":"ACM SIGSOFT Software Engineering Notes"},{"key":"key2021102014190997500_ref045","doi-asserted-by":"crossref","first-page":"110","DOI":"10.1016\/j.ress.2012.09.011","article-title":"Cross-fertilization between safety and security engineering","volume":"110","year":"2013","journal-title":"Reliability Engineering and System Safety"},{"key":"key2021102014190997500_ref046","article-title":"A combined process for elicitation and analysis of safety and security requirements","volume-title":"Enterprise, Business-Process and Information Systems Modeling","year":"2012"},{"key":"key2021102014190997500_ref047","article-title":"An extended misuse case notation: including vulnerabilities and the insider threat","volume":"67","year":"2008","journal-title":"Access Control in Healthcare Information Systems"},{"key":"key2021102014190997500_ref048","first-page":"95","article-title":"Using students as experiment subjects \u2013 an analysis on graduate and freshmen student data","volume-title":"Proceedings of the 7th International Conference on Empirical Assessment in Software Engineering","year":"2003"},{"key":"key2021102014190997500_ref049","first-page":"666","article-title":"Are students representatives of professionals in software engineering experiments? Software engineering (ICSE)","volume-title":"IEEE\/ACM 37th IEEE International Conference on, 2015","year":"2015"},{"key":"key2021102014190997500_ref050","first-page":"282","article-title":"Fmvea for safety and security analysis of intelligent and cooperative vehicles","volume-title":"International Conference on Computer Safety, Reliability, and Security","year":"2014"},{"key":"key2021102014190997500_ref051","first-page":"21","article-title":"Attack trees","volume":"24","year":"1999","journal-title":"Dr Dobb\u2019s Journal"},{"key":"key2021102014190997500_ref052","article-title":"Experiences threat modeling at Microsoft","volume-title":"Modeling security workshop. Department of Computing","year":"2008"},{"key":"key2021102014190997500_ref053","volume-title":"Capturing Security Requirments through Misuse Cases","year":"2001"},{"key":"key2021102014190997500_ref054","doi-asserted-by":"crossref","first-page":"733","DOI":"10.1109\/TSE.2005.97","article-title":"A survey of controlled experiments in software engineering","volume":"31","year":"2005","journal-title":"IEEE Transactions on Software Engineering"},{"issue":"2","key":"key2021102014190997500_ref055","doi-asserted-by":"crossref","first-page":"251","DOI":"10.1007\/s00766-015-0220-8","article-title":"Reusable knowledge in security requirements engineering: a systematic mapping study","volume":"21","year":"2016","journal-title":"Requirements Engineering"},{"key":"key2021102014190997500_ref056","first-page":"721","article-title":"Safety hazard identification by misuse cases: experimental comparison of text and diagrams","volume-title":"International Conference on Model Driven Engineering Languages and Systems","year":"2008"},{"key":"key2021102014190997500_ref057","doi-asserted-by":"crossref","first-page":"288","DOI":"10.1145\/1414004.1414055","article-title":"Using students as subjects-an empirical evaluation","volume-title":"Proceedings of the Second ACM-IEEE international symposium on Empirical Software Engineering and Measurement","year":"2008"},{"issue":"5","key":"key2021102014190997500_ref058","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/2.675631","article-title":"Should computer scientists experiment more?","volume":"31","year":"1998","journal-title":"Computer"},{"issue":"1-3","key":"key2021102014190997500_ref059","doi-asserted-by":"crossref","first-page":"467","DOI":"10.1016\/S0304-3894(99)00094-1","article-title":"Risk based methodology for safety improvements in ports","volume":"71","year":"2000","journal-title":"Journal of Hazardous Materials"},{"key":"key2021102014190997500_ref060","first-page":"148","article-title":"Elaborating security requirements by construction of intentional anti-models","volume-title":"Proceedings of the 26th International Conference on Software Engineering","year":"2004"},{"key":"key2021102014190997500_ref061","first-page":"254","article-title":"Extending HARM to make test cases for penetration testing","volume-title":"6th International Workshop on Information Systems Security Engineering","year":"2016"},{"key":"key2021102014190997500_ref062","first-page":"14","article-title":"Security assessments of safety critical systems using HAZOPs","volume-title":"International Conference on Computer Safety, Reliability, and Security","year":"2001"},{"key":"key2021102014190997500_ref063","unstructured":"WMN (2014), \u201cIMB: Shipping next playground for hackers\u201d, [Online], available at: https:\/\/worldmaritimenews.com\/archives\/134727\/imb-shipping-next-playground-for-hackers\/ (accessed 20 November 2018)."},{"key":"key2021102014190997500_ref064","first-page":"207","volume-title":"Towards Experimental Assessment of Security Threats in Protecting the Critical Infrastructure","year":"2012"}],"container-title":["Information &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-11-2018-0132\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-11-2018-0132\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T01:23:19Z","timestamp":1753406599000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/27\/4\/536-561\/190444"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,6,20]]},"references-count":64,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2019,6,20]]},"published-print":{"date-parts":[[2019,9,23]]}},"alternative-id":["10.1108\/ICS-11-2018-0132"],"URL":"https:\/\/doi.org\/10.1108\/ics-11-2018-0132","relation":{},"ISSN":["2056-4961","2056-4961"],"issn-type":[{"value":"2056-4961","type":"print"},{"value":"2056-4961","type":"print"}],"subject":[],"published":{"date-parts":[[2019,6,20]]}}}