{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,19]],"date-time":"2025-03-19T16:27:01Z","timestamp":1742401621987,"version":"3.37.3"},"reference-count":72,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100002347","name":"German Federal Ministry of Education and Research","doi-asserted-by":"publisher","award":["16KIS1269K"],"award-info":[{"award-number":["16KIS1269K"]}],"id":[{"id":"10.13039\/501100002347","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/access.2023.3238326","type":"journal-article","created":{"date-parts":[[2023,1,19]],"date-time":"2023-01-19T18:53:41Z","timestamp":1674154421000},"page":"9967-9994","source":"Crossref","is-referenced-by-count":8,"title":["Evaluation of Visual Notations as a Basis for ICS Security Design Decisions"],"prefix":"10.1109","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4730-0126","authenticated-orcid":false,"given":"Sarah","family":"Fluchs","sequence":"first","affiliation":[{"name":"Admeritia GmbH, Langenfeld, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1238-2571","authenticated-orcid":false,"given":"Rainer","family":"Drath","sequence":"additional","affiliation":[{"name":"School of Engineering, Pforzheim University, Pforzheim, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1922-654X","authenticated-orcid":false,"given":"Alexander","family":"Fay","sequence":"additional","affiliation":[{"name":"Department of Automation, Helmut Schmidt University, Hamburg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-71440-0_1"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/IECON.2019.8927590"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxu152"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.5220\/0005614502910300"},{"volume-title":"Engineering and Execution of PCT Projects in Process Industry","year":"2019","key":"ref5"},{"volume-title":"Collaborative Process Automation Systems","year":"2010","author":"Hollender","key":"ref6"},{"key":"ref7","first-page":"1","article-title":"A SysML extension for security analysis of industrial control systems","volume-title":"Proc. Electron. Workshops Comput.","author":"Lemaire"},{"key":"ref8","first-page":"191","article-title":"Model-based security metrics using ADversary VIew security evaluation (ADVISE)","volume-title":"Proc. 8th Int. Conf. Quant. Eval. Syst.","author":"LeMay"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/jsyst.2012.2221853"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10696-0_29"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2020.3033150"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.5220\/0010544000002998"},{"volume-title":"Department of Homeland Security, USA, Cyber Security Evaluation Tool (CSET)","year":"2022","key":"ref13"},{"key":"ref14","first-page":"1","article-title":"A security decision base: How to prepare security by design decisions for industrial control systems","volume-title":"Proc. 17th EKA (Fachtagung Entwurf Komplexer Automatisierungssysteme)","author":"Fluchs"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/IECON49645.2022.9968406"},{"journal-title":"Semiology of Graphics","year":"1983","author":"Bertin","key":"ref16"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1985.10478147"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1111\/j.1551-6708.1987.tb00863.x"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1080\/00221300009598596"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2009.67"},{"volume-title":"Thinking, Fast and Slow","year":"2011","author":"Kahneman","key":"ref21"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-70802-7_40"},{"volume-title":"INCOSE Systems Engineering Handbook: A Guide for System Life Cycle Processes and Activities","year":"2015","author":"Walden","key":"ref23"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36654-3_6"},{"journal-title":"Don\u2019t Make Me Think, Revisited: A Common Sense Ap-Proach to Web Usability","year":"2013","author":"Krug","key":"ref25"},{"volume-title":"PERA control and information systems lead engineer\u2019s guide industry sector: Oil & gas","year":"2018","author":"Rathwell","key":"ref26"},{"volume-title":"Diagrams for the Chemical and Petrochemical Industry\u2014Part 1: Specification of Diagrams","year":"2014","key":"ref27"},{"volume-title":"Diagrams for the Chemical and Petrochemical Industry\u2014Part 2: Graphical Symbols","year":"2012","key":"ref28"},{"volume-title":"Representation of Process Control Engineering Requests in P&I Diagrams and Data Exchange Between P&ID Tools and PCE-CAE Tools","year":"2016","key":"ref29"},{"volume-title":"Programmable Controllers\u2014Part 3: Pro-Gramming Languages","year":"2013","key":"ref30"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1049\/cp.2013.1077"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2007.70754"},{"key":"ref33","first-page":"356","article-title":"A pattern system for security requirements engineering","volume-title":"Proc. 2nd Int. Conf. Availability, Rel. Secur. (ARES)","author":"Hatebur"},{"volume-title":"Unified Modeling Language (UML) Specification v2.5.1","year":"2022","key":"ref34"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45800-x_32"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/b137706"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45800-x_33"},{"key":"ref38","first-page":"55","article-title":"Using abuse case models for security requirements analysis","volume-title":"Proc. 15th Annu. Comput. Secur. Appl. Conf. (ACSAC)","author":"McDermott"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-004-0194-4"},{"key":"ref40","first-page":"478","article-title":"Security-critical system development with extended use cases","volume-title":"Proc. 10th Asia\u2013Pacific Softw. Eng. Conf.","author":"Popp"},{"key":"ref41","doi-asserted-by":"crossref","DOI":"10.3384\/lic.diva-98213","author":"Vasilevskaya","year":"2013","journal-title":"Designing Security-Enhanced Embedded Systems: Bridging Two Islands of Expertise: Link\u00f6ping"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/11863908_13"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/10958513_29"},{"volume-title":"Object Management Group (OMG), System Modeling Language (SysML) Specification v1.6","year":"2022","key":"ref44"},{"volume-title":"System Architecture: Strategy and Product Development for Complex Systems","year":"2016","author":"Crawley","key":"ref45"},{"key":"ref46","first-page":"8","article-title":"SysML-Sec: A SysML environment for the design and de-velopment of secure embedded systems","volume-title":"Proc. AP-COSEC, Asia\u2013Pacific Council Syst. Eng.","author":"Apvrille"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.3390\/app10072574"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02463-4_7"},{"key":"ref49","first-page":"261","article-title":"Tropos: A framework for requirements-driven software development","volume-title":"Information Systems Engineering: State of the Art and Research Themes","author":"Mylopoulos","year":"2000"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1142\/s0218194007003240"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2007.93"},{"key":"ref52","first-page":"1","article-title":"Towards a risk-based security requirements engineering framework","volume-title":"Proc. REFSQ","author":"Mayer"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-39417-6_16"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/7549.003.0014"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-75563-0_26"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-12323-8"},{"key":"ref57","first-page":"152","article-title":"SecDSVL: A domain-specific isual language to sup-port enterprise security modelling","volume-title":"Proc. 23rd Austral. Softw. Eng. Conf.","author":"Almorsy"},{"volume-title":"Virtual Expo: CISA\u2019s Cybersecurity Evaluation Tool (CSET)","year":"2020","author":"Geraldo","key":"ref58"},{"volume-title":"Security for Industrial Automation and Control Systems\u2014Part 3\u20132: Security Risk Assessment for System Design","year":"2020","key":"ref59"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1007\/s11623-010-0021-7"},{"volume-title":"The Technique of Data Flow Diagramming","year":"2022","author":"Kozar","key":"ref61"},{"volume-title":"Data Flow Diagrams","author":"Drewry","key":"ref62"},{"issue":"12","key":"ref63","first-page":"21","article-title":"Attack trees","volume":"24","author":"Schneier","year":"1999","journal-title":"Dr. Dobb\u2019s J."},{"key":"ref64","first-page":"9","article-title":"The use of attack trees in assessing vulnerabilities in SCADA systems","volume-title":"Proc. Int. Infrastruct. Survivability Workshop","author":"Byres"},{"volume-title":"Creating attack graphs for adversary emulation, simulation and purple teaming in industrial control system (ICS) environments","year":"2021","author":"Hoff","key":"ref65"},{"volume-title":"MITRE, ATT&CK for ICS","year":"2022","key":"ref66"},{"key":"ref67","first-page":"148","article-title":"Elaborating security requirements by construction of intentional anti-models","volume-title":"Proc. 26th Int. Conf. Softw. Eng.","author":"van Lamsweerde"},{"key":"ref68","first-page":"80","article-title":"Foundations of attack-defense trees","volume-title":"Formal Aspects of Security and Trust","author":"Kordy"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-00434-6_3"},{"volume-title":"Making OT security engineering deserve its name: A guide to security engineering for OT engineers","year":"2019","author":"Fluchs","key":"ref70"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.4324\/9780367491161"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/ares.2013.102"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/10005208\/10021609.pdf?arnumber=10021609","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,13]],"date-time":"2024-02-13T06:03:48Z","timestamp":1707804228000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10021609\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":72,"URL":"https:\/\/doi.org\/10.1109\/access.2023.3238326","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2023]]}}}