{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,18]],"date-time":"2025-10-18T10:56:28Z","timestamp":1760784988426,"version":"3.28.0"},"reference-count":37,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,7,20]],"date-time":"2020-07-20T00:00:00Z","timestamp":1595203200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,7,20]],"date-time":"2020-07-20T00:00:00Z","timestamp":1595203200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,7,20]],"date-time":"2020-07-20T00:00:00Z","timestamp":1595203200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,7,20]]},"DOI":"10.1109\/indin45582.2020.9442219","type":"proceedings-article","created":{"date-parts":[[2021,6,8]],"date-time":"2021-06-08T21:43:32Z","timestamp":1623188612000},"page":"153-158","source":"Crossref","is-referenced-by-count":4,"title":["How to Quantify the Security Level of Embedded Systems? A Taxonomy of Security Metrics"],"prefix":"10.1109","author":[{"given":"Angel","family":"Longueira-Romero","sequence":"first","affiliation":[]},{"given":"Rosa","family":"Iglesias","sequence":"additional","affiliation":[]},{"given":"David","family":"Gonzalez","sequence":"additional","affiliation":[]},{"given":"Inaki","family":"Garitano","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"journal-title":"Security Metrics Replacing Fear Uncertainty and Doubt","year":"2007","author":"jaquith","key":"ref33"},{"key":"ref32","first-page":"230","article-title":"On the feasibility of utilizing security metrics in software-intensive systems","volume":"10","author":"savola","year":"2010","journal-title":"International Journal of Computer Science and Network Security"},{"key":"ref31","article-title":"SSE-CMM Security Metrics","author":"jelen","year":"0","journal-title":"National Institute of Standards and Techonology (NIST) and Computer System Security and Privacy Advisory Board (CSSPAB) Workshop"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.05.002"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2006.51"},{"journal-title":"Mapping the field of software security metrics","year":"2014","author":"morrison","key":"ref36"},{"key":"ref35","first-page":"137","volume":"2017","author":"yusuf enoch","year":"2017","journal-title":"Composite Metrics for Network Security Analysis[J]"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2017.2745505"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2019.2904475"},{"key":"ref11","article-title":"Security for industrial automation and control systems - Network and system security: System security compliance metrics","author":"commission","year":"0","journal-title":"IEC Standard"},{"journal-title":"The Common Criteria for Information Technology Security Evaluation - Introduction and General Model","year":"0","key":"ref12"},{"journal-title":"Common Methodology for Information Technology Security Evaluation","year":"0","key":"ref13"},{"key":"ref14","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.SP.800-55r1","author":"chew","year":"2008","journal-title":"Performance Measurement Guide for Information Security"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-26"},{"journal-title":"Security Metrics Guide for Information Technology Systems","year":"2003","author":"marianne","key":"ref16"},{"journal-title":"Industrial Internet of Things Volume G4 Security Framework","year":"2016","key":"ref17"},{"journal-title":"ISECOM","article-title":"The Open Source Security Testing Methodology Manual (OSSTMM)","year":"2010","key":"ref18"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2012.10"},{"key":"ref28","first-page":"35","article-title":"There's a s.m.a.r.t. way to write managements's goals and objectives","volume":"70","author":"doran","year":"1981","journal-title":"Management Review"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2011.115"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.60"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2015.7232966"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CC.2018.8438279"},{"journal-title":"PRAGMATIC Security Metrics Applying Metametrics to Information Security","year":"2013","author":"krag brotby","key":"ref29"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/s11277-015-2478-z"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3005714"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-36584-8_1"},{"journal-title":"Embedded Systems Security Practical Methods for Safe and Secure Software and Systems Development","year":"2012","author":"kleidermacher","key":"ref2"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2017.2745505"},{"journal-title":"Embedded System Design Embedded Systems Foundations of Cyber-physical Systems","year":"2010","author":"marwedel","key":"ref1"},{"key":"ref20","article-title":"What do we know about software security evaluation? a preliminary study","author":"sentilles","year":"2018","journal-title":"QuA-SoQ APSEC"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICSEA.2007.79"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.3745\/JIPS.2009.5.4.197"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.56"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.31"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/1719030.1719036"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2006.101"}],"event":{"name":"2020 IEEE 18th International Conference on Industrial Informatics (INDIN)","start":{"date-parts":[[2020,7,20]]},"location":"Warwick, United Kingdom","end":{"date-parts":[[2020,7,23]]}},"container-title":["2020 IEEE 18th International Conference on Industrial Informatics (INDIN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9441666\/9442071\/09442219.pdf?arnumber=9442219","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,30]],"date-time":"2022-12-30T10:29:42Z","timestamp":1672396182000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9442219\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7,20]]},"references-count":37,"URL":"https:\/\/doi.org\/10.1109\/indin45582.2020.9442219","relation":{},"subject":[],"published":{"date-parts":[[2020,7,20]]}}}