{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T02:20:29Z","timestamp":1776824429909,"version":"3.51.2"},"reference-count":22,"publisher":"IEEE","license":[{"start":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T00:00:00Z","timestamp":1559347200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T00:00:00Z","timestamp":1559347200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T00:00:00Z","timestamp":1559347200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,6]]},"DOI":"10.1109\/cybersecpods.2019.8885144","type":"proceedings-article","created":{"date-parts":[[2019,10,31]],"date-time":"2019-10-31T20:28:15Z","timestamp":1572553695000},"page":"1-8","source":"Crossref","is-referenced-by-count":17,"title":["Threat modelling and agile software development: Identified practice in four Norwegian organisations"],"prefix":"10.1109","author":[{"given":"Karin","family":"Bernsmed","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin Gilje","family":"Jaatun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW.2018.00018"},{"key":"ref11","author":"oates","year":"2005","journal-title":"Researching Information Systems and Computing"},{"key":"ref12","author":"yin","year":"2009","journal-title":"Case Study Research Design and Methods"},{"key":"ref13","author":"robson","year":"2011","journal-title":"Real World Research"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1016\/j.infoandorg.2006.11.001"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.4135\/9781446280119"},{"key":"ref16","year":"2019","journal-title":"Software security takes a champion"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1177\/1098214005283748"},{"key":"ref18","year":"2013","journal-title":"OWASP Top 10 2013"},{"key":"ref19","article-title":"ISO\/IEC 27001:2013 Information technology - Security techniques - Information security management systems - Requirements","year":"2013","journal-title":"Tech Rep"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ASWEC.2018.00023"},{"key":"ref3","first-page":"21","article-title":"Attack trees","volume":"24","author":"schneier","year":"1999","journal-title":"Dr Dobbs Journal"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2006.43"},{"key":"ref5","author":"howard","year":"2006","journal-title":"The Security Development Lifecycle"},{"key":"ref8","article-title":"Elevation of privilege: Drawing developers into threat modeling","author":"shostack","year":"2014","journal-title":"2014 USE-NIX Summit on Gaming Games and Gamification in Security Education (3GSE 14)"},{"key":"ref7","article-title":"Experiences threat modeling at Microsoft","author":"shostack","year":"2008","journal-title":"MODSEC MoDELS"},{"key":"ref2","author":"shostack","year":"2014","journal-title":"Threat Modeling Designing for Security"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.4018\/978-1-5225-6313-6.ch001"},{"key":"ref9","first-page":"281","article-title":"Security in the software development lifecycle","author":"assal","year":"2018","journal-title":"Fourteenth Symposium on Usable Privacy and Security (SOUPS 2018)"},{"key":"ref20","article-title":"REGULATION (EU) 2016\/679 OF THE EUROPEAN PARLIA-MENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation)","year":"2016","journal-title":"Official Journal of the European Union"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2018.06.073"},{"key":"ref21","author":"m?ller","year":"2014","journal-title":"This POODLE Bites Exploiting The SSL 3 0 Fallback"}],"event":{"name":"2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security)","location":"Oxford, United Kingdom","start":{"date-parts":[[2019,6,3]]},"end":{"date-parts":[[2019,6,4]]}},"container-title":["2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8871248\/8884876\/08885144.pdf?arnumber=8885144","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,18]],"date-time":"2022-07-18T10:50:10Z","timestamp":1658141410000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8885144\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,6]]},"references-count":22,"URL":"https:\/\/doi.org\/10.1109\/cybersecpods.2019.8885144","relation":{},"subject":[],"published":{"date-parts":[[2019,6]]}}}