{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,10,22]],"date-time":"2024-10-22T21:02:44Z","timestamp":1729630964153,"version":"3.28.0"},"reference-count":45,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,9]]},"DOI":"10.1109\/icnss.2011.6060003","type":"proceedings-article","created":{"date-parts":[[2011,11,1]],"date-time":"2011-11-01T16:59:24Z","timestamp":1320166764000},"page":"216-223","source":"Crossref","is-referenced-by-count":3,"title":["Exploring twisted paths: Analyzing authorization processes in organizations"],"prefix":"10.1109","author":[{"given":"Steffen","family":"Bartsch","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"crossref","first-page":"137","DOI":"10.1007\/3-540-45608-2_3","article-title":"Access control: Policies, models, and mechanisms","author":"samarati","year":"2001","journal-title":"Foundations of Security Analysis and Design"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"year":"2007","key":"ref33"},{"year":"2007","key":"ref32"},{"year":"2007","key":"ref31"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/507711.507717"},{"article-title":"Security Education, Awareness and Training: from Theory to Practice","year":"2005","author":"roper","key":"ref37"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/792704.792706"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/0268-4012(95)00010-5"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.2139\/ssrn.1471801"},{"key":"ref10","article-title":"On the importance of the separation-of-concerns principle in secure software engineering","author":"de win","year":"2003","journal-title":"ACSA Workshop on the Application of Engineering Principles to System Security Design"},{"key":"ref40","article-title":"Schneier-Ranum face-off: Is perfect access control possible?","author":"schneier","year":"2009","journal-title":"Information Security"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1046\/j.1365-2575.2001.00099.x"},{"key":"ref12","first-page":"554","article-title":"Role-based access controls","author":"ferraiolo","year":"1992","journal-title":"15th NIST-NCSC National Computer Security Conference"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2007.10.002"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.34"},{"article-title":"Inside Java(TM) 2 Platform Security: Architecture, API Design, and Implementation","year":"2003","author":"gong","key":"ref15"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1201\/9781420013283"},{"article-title":"Agile software development ecosystems","year":"2002","author":"highsmith","key":"ref17"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1002\/0470048204.ch14"},{"year":"2005","key":"ref19"},{"key":"ref28","article-title":"Organizational structures and configurations","author":"mcphee","year":"2000","journal-title":"The New Handbook of Organizational Communication SAGE"},{"key":"ref4","article-title":"Some usability considerations in access control systems","author":"bertino","year":"2008","journal-title":"USM &#x2018;08 Workshop on Usable IT Security Management"},{"article-title":"The future of work: how the new order of business will shape your organization, your management style, and your life","year":"2004","author":"malone","key":"ref27"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/1595676.1595684"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/2.59"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/344287.344306"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.1999.816041"},{"key":"ref8","first-page":"979","article-title":"Modelling access policies using roles in requirements engineering. Information and Software Technology","volume":"45","author":"crook","year":"2003","journal-title":"Eighth International Workshop on Requirements Engineering Foundation for Software Quality"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1002\/spe.691"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/1518701.1518838"},{"key":"ref9","article-title":"Logic based authorization policy engineering","author":"dai","year":"2002","journal-title":"Proceedings of the World Multiconference on Systemics Cybernetics and Informatics"},{"key":"ref1","article-title":"Computer security technology planning study","author":"anderson","year":"1972","journal-title":"Technical Report ESD-TR-73&#x2013;51 Deputy for Command and Management Systems L G Hanscom Field Bedford MA"},{"year":"2010","key":"ref20"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/304851.304859"},{"year":"2007","key":"ref22"},{"year":"0","key":"ref21"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/1572532.1572552"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/507711.507718"},{"key":"ref41","article-title":"Information risk in the professional services &#x2013; field study results from financial institutions and a roadmap for research","author":"sinclair","year":"2007","journal-title":"Proceedings for the 3rd International Workshop on Enterprise Applications and Services in the Finance Industry"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/996943.996944"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/1125451.1125729"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.im.2003.08.001"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/1330311.1330320"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/BFb0053381"}],"event":{"name":"2011 5th International Conference on Network and System Security (NSS)","start":{"date-parts":[[2011,9,6]]},"location":"Milan, Italy","end":{"date-parts":[[2011,9,8]]}},"container-title":["2011 5th International Conference on Network and System Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/6044613\/6059944\/06060003.pdf?arnumber=6060003","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,20]],"date-time":"2017-06-20T04:56:08Z","timestamp":1497934568000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6060003\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,9]]},"references-count":45,"URL":"https:\/\/doi.org\/10.1109\/icnss.2011.6060003","relation":{},"subject":[],"published":{"date-parts":[[2011,9]]}}}