{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T02:23:33Z","timestamp":1773195813419,"version":"3.50.1"},"reference-count":13,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,12,8]],"date-time":"2025-12-08T00:00:00Z","timestamp":1765152000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,12,8]],"date-time":"2025-12-08T00:00:00Z","timestamp":1765152000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,12,8]]},"DOI":"10.1109\/acsacw69556.2025.00051","type":"proceedings-article","created":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T19:56:13Z","timestamp":1773086173000},"page":"414-419","source":"Crossref","is-referenced-by-count":0,"title":["Cybersecurity Threat Intelligence for Audit: LLM Scoping, Evidence Guardrails, and Materiality"],"prefix":"10.1109","author":[{"given":"Gurkan","family":"Akalin","sequence":"first","affiliation":[{"name":"University of Virginia&#x2019;s College at Wise,Business and Economics Department,Wise,Virginia,USA"}]},{"given":"Ning","family":"Zhou","sequence":"additional","affiliation":[{"name":"University of Virginia&#x2019;s College at Wise,Business and Economics Department,Wise,Virginia,USA"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1111\/1911-3846.12212"},{"key":"ref2","article-title":"AS 2201: An audit of internal control over financial reporting that is integrated with an audit of financial statements"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1111\/ijau.12365"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.2308\/ISYS-2020-065"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.2308\/horizons-18-123"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1108\/ICS-02-2019-0033"},{"key":"ref7","volume-title":"Framework for improving critical infrastructure cybersecurity, version 1.1 (NIST Cybersecurity Framework)","author":"Barrett","year":"2018"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2018\/13853"},{"key":"ref9","article-title":"Unauthorized access to Okta\u2019s support case management system: Root cause","volume-title":"Okta Security","year":"2023"},{"key":"ref10","volume-title":"#StopRansomware: CL0P ransomware gang exploits MOVEit vulnerability (AA23-158A)","year":"2023"},{"key":"ref11","volume-title":"Supply chain compromise","year":"2021"},{"key":"ref12","article-title":"Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email","volume-title":"Microsoft Security Response Center (MSRC)","year":"2023"},{"key":"ref13","volume-title":"3CX software supply chain compromise initiated by a prior software supply chain compromise","year":"2023"}],"event":{"name":"2025 Annual Computer Security Applications Conference Workshops (ACSAC Workshops)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,12,8]]},"end":{"date-parts":[[2025,12,9]]}},"container-title":["2025 Annual Computer Security Applications Conference Workshops (ACSAC Workshops)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11417955\/11417996\/11418054.pdf?arnumber=11418054","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T05:36:27Z","timestamp":1773120987000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11418054\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,8]]},"references-count":13,"URL":"https:\/\/doi.org\/10.1109\/acsacw69556.2025.00051","relation":{},"subject":[],"published":{"date-parts":[[2025,12,8]]}}}