{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,21]],"date-time":"2026-01-21T14:02:21Z","timestamp":1769004141084,"version":"3.49.0"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"German Federal Ministry of Education and Research","award":["16KIS1269K"],"award-info":[{"award-number":["16KIS1269K"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,1]]},"DOI":"10.1109\/tdsc.2025.3613828","type":"journal-article","created":{"date-parts":[[2025,9,30]],"date-time":"2025-09-30T17:40:54Z","timestamp":1759254054000},"page":"1326-1342","source":"Crossref","is-referenced-by-count":0,"title":["Communicating Cybersecurity Decisions and Their Rationales Explicitly During and After CPS Design"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4730-0126","authenticated-orcid":false,"given":"Sarah","family":"Fluchs","sequence":"first","affiliation":[{"name":"admeritia GmbH, Langenfeld, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emre","family":"Ta\u015ftan","sequence":"additional","affiliation":[{"name":"admeritia GmbH, Langenfeld, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Mertens","sequence":"additional","affiliation":[{"name":"INEOS, K&#x00F6;ln, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexander","family":"Horch","sequence":"additional","affiliation":[{"name":"HIMA, Br&#x00FC;hl, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francesco","family":"Matraxia","sequence":"additional","affiliation":[{"name":"HIMA, Br&#x00FC;hl, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1238-2571","authenticated-orcid":false,"given":"Rainer","family":"Drath","sequence":"additional","affiliation":[{"name":"Pforzheim University, Pforzheim, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1922-654X","authenticated-orcid":false,"given":"Alexander","family":"Fay","sequence":"additional","affiliation":[{"name":"Ruhr University, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Cyber-physical Systems: Solutions to Pandemic Challenges","author":"Semwal","year":"2022"},{"key":"ref2","article-title":"The \u2018Vulkan files\u2019: A look inside Putin\u2019s secret plans for cyber-warfare","volume-title":"SPIEGEL Int.","author":"Antoniadis","year":"2023"},{"key":"ref3","article-title":"Proposal for a regulation on horizontal cybersecurity requirements for products with digital elements (COM\/2022\/454): In Cyber Resilience Act (CRA)","year":"2022"},{"key":"ref4","article-title":"Shifting balance cybersecurity risk: principles approaches for secure by design software","year":"2023"},{"key":"ref5","article-title":"Engineering and Execution of PCT Projects in Process Industry, 35, NAMUR e. V.","year":"2019"},{"key":"ref6","volume-title":"Collaborative Process Automation Systems","author":"Hollender","year":"2009"},{"key":"ref7","article-title":"Position proposal for a cyber resilience act: Call for a realistic implementation approach","year":"2023"},{"key":"ref8","article-title":"Position: Cyber resilience act","year":"2023"},{"key":"ref9","article-title":"Industrial Communication Networks - Network and System Security - Part 3-3: System security Requirements and Security Levels, 62443\u201362443-3, ISA\/IEC","year":"2013"},{"key":"ref10","article-title":"Security For Industrial Automation and Control Systems - Part 4-2: Technical security Requirements For IACS Components, 62443\u201362444-2, ISA\/IEC","year":"2018"},{"key":"ref11","article-title":"Industrial Communication Networks - Network and System Security - Part 1-1: Terminology, Concepts and Models, 62443\u201362441-1, ISA\/IEC","year":"2009"},{"key":"ref12","article-title":"Common criteria for information technology security evaluation. Version 3.1, revision 5","year":"2024"},{"key":"ref13","article-title":"Security For Industrial Automation and Control Systems - Part 1-5: Scheme for IEC 62443 Security Profiles, 62443\u201362441-5, ISA\/IEC","year":"2023"},{"key":"ref14","article-title":"Security For Industrial Automation and Control Systems, Part 3-2: Security risk assessment for system design, 62443\u201362443-2, ISA\/IEC","year":"2020"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/IECON.2019.8927590"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.compind.2022.103715"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.09.009"},{"key":"ref18","first-page":"1","article-title":"A security decision base: How to prepare security by design decisions for industrial control systems","volume-title":"Proc. 17th EKA Conf.","author":"Fluchs"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.3390\/s23125547"},{"key":"ref20","volume-title":"Security PHA Review for Consequence-Based Cybersecurity","author":"Marszal","year":"2019"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.4324\/9780367491161"},{"key":"ref22","article-title":"Cyber-informed engineering implementation guide: Version 1,0","author":"Wright","year":"2023"},{"key":"ref23","article-title":"Engineering-grade OT security","volume-title":"A Manager\u2019s Guide","author":"Ginter","year":"2023"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/access.2023.3238326"},{"key":"ref25","article-title":"Cybersecurity decision diagrams: A visual, model-based concept for making, documenting, and communicating cybersecurity decisions during and after the (re-)design of industrial cyber-physical systems","author":"Fluchs","year":"2024"},{"key":"ref26","article-title":"Making OT security engineering deserve its name - A guide to security engineering for OT engineers","volume-title":"CONTROL Global","author":"Fluchs","year":"2019"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1016\/j.cirp.2017.04.037"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2009.67"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/access.2020.2965257"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3341161.3344379"},{"key":"ref31","article-title":"Top 20 secure PLC coding practices","author":"Security Project","year":"2022"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-W58399.2023.00031"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/IOLTS60994.2024.10616052"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/mcomstd.0001.2100080"},{"key":"ref35","article-title":"An adaptive, context-sensitive, workflow support system for process Automation engineering production plant","author":"Ghobadi-Bigvand","year":"2024"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-43839-8"},{"key":"ref37","doi-asserted-by":"crossref","first-page":"413","DOI":"10.51202\/9783181024195-413","article-title":"Security engineering with AutomationML \u2013 A methodology for modeling security decisions, goals, risks, and requirements [in German]","volume-title":"Automation 2023","author":"Ta\u015ftan","year":"2023"},{"key":"ref38","article-title":"An information model for automation security engineering","year":"2024"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11354469\/11184747.pdf?arnumber=11184747","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T23:23:34Z","timestamp":1768951414000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11184747\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1]]},"references-count":38,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3613828","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1]]}}}