{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T13:16:31Z","timestamp":1784553391852,"version":"3.55.0"},"reference-count":198,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2007,2,28]],"date-time":"2007-02-28T00:00:00Z","timestamp":1172620800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGMIS Database"],"published-print":{"date-parts":[[2007,2,28]]},"abstract":"<jats:p>This paper identifies four security issues (access to Information Systems, secure communication, security management, development of secure Information Systems), and examines the extent to which these security issues have been addressed by existing research efforts. Research contributions in relation to these four security issues are analyzed from three viewpoints: a meta-model for information systems, the research approaches used, and the reference disciplines used. Our survey reveals that most information security research has focused on the technical context, and on issues of access to IS and secure communication. The corresponding security issues have been resolved by using mathematical approaches as a research approach. The reference disciplines most commonly reflected have been mathematics, including philosophical logic. Based on this analysis, we suggest new directions for studying information security from an information systems viewpoint, with respect to research methodology and research questions. Empirical studies in relation to the issues of security management and the development of secure IS, based on suitable reference theories (e.g., psychology, sociology, semiotics, and philosophy), are particularly necessary.<\/jats:p>","DOI":"10.1145\/1216218.1216224","type":"journal-article","created":{"date-parts":[[2007,4,5]],"date-time":"2007-04-05T19:52:18Z","timestamp":1175802738000},"page":"60-80","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":136,"title":["A review of information security issues and respective research contributions"],"prefix":"10.1145","volume":"38","author":[{"given":"Mikko T.","family":"Siponen","sequence":"first","affiliation":[{"name":"University of Oulu"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Harri","family":"Oinas-Kukkonen","sequence":"additional","affiliation":[{"name":"University of Oulu"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2007,2,28]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(95)97048-F"},{"key":"e_1_2_1_2_1","volume-title":"Evaluation Issues,\" in Abrams","author":"Abrams M. D.","year":"1995","unstructured":"Abrams , M. D. and Podell , H. J . ( 1995 ). \" Evaluation Issues,\" in Abrams , M.D., Jajodia, S. and Podell, H.J. (Eds.), Information Security - An Integrated Collection of Essays, Los Alamitos, CA : IEEE Computer Society Press . Abrams, M. D. and Podell, H. J. (1995). \"Evaluation Issues,\" in Abrams, M.D., Jajodia, S. and Podell, H.J. (Eds.), Information Security - An Integrated Collection of Essays, Los Alamitos, CA: IEEE Computer Society Press."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/0749-5978(91)90020-T"},{"key":"e_1_2_1_4_1","volume-title":"A Security Policy Model for Clinical Information Systems,\" Proceedings of the 1996 IEEE Symposium on Security and Privacy","author":"Anderson R.","year":"1996","unstructured":"Anderson , R. ( 1996 ). \" A Security Policy Model for Clinical Information Systems,\" Proceedings of the 1996 IEEE Symposium on Security and Privacy . Anderson, R. (1996). \"A Security Policy Model for Clinical Information Systems,\" Proceedings of the 1996 IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_5_1","first-page":"18","volume-title":"Oakland","author":"Anderson R.","year":"1996","unstructured":"Anderson , R. , and Kuhn , M . ( 1996 ). \" Tamper Resistance - a Cautionary Note,\" Proceedings of The Second USENIX Workshop on Electronic Commerce , Oakland , California , pp. 18 -- 21 . Anderson, R., and Kuhn, M. (1996). \"Tamper Resistance - a Cautionary Note,\" Proceedings of The Second USENIX Workshop on Electronic Commerce, Oakland, California, pp. 18--21."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.668971"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.1996.7"},{"key":"e_1_2_1_8_1","volume-title":"Naming and Grouping Privileges to Simplify Security Management in Large Databases,\" Proceedings of the IEEE Computer Society Symposium on Research in Security and Privacy","author":"Baldwin R. W.","year":"1990","unstructured":"Baldwin , R. W. ( 1990 ). \" Naming and Grouping Privileges to Simplify Security Management in Large Databases,\" Proceedings of the IEEE Computer Society Symposium on Research in Security and Privacy . Baldwin, R. W. (1990). \"Naming and Grouping Privileges to Simplify Security Management in Large Databases,\" Proceedings of the IEEE Computer Society Symposium on Research in Security and Privacy."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/63238.63241"},{"key":"e_1_2_1_10_1","volume-title":"Information Systems Series: John Wiley.","author":"Baskerville R.","year":"1988","unstructured":"Baskerville , R. ( 1988 ). Designing Information Systems Security , Information Systems Series: John Wiley. Baskerville, R. (1988). Designing Information Systems Security, Information Systems Series: John Wiley."},{"key":"e_1_2_1_11_1","volume-title":"Systems Development for Human Progress","author":"Baskerville R.","year":"1989","unstructured":"Baskerville , R. ( 1989 ). \" Logical Controls Specification: An Approach to Information System Security,\" in Klein , H., and Kumar, K. (Eds.), Systems Development for Human Progress , Amsterdam : North-Holland . Baskerville, R. (1989). \"Logical Controls Specification: An Approach to Information System Security,\" in Klein, H., and Kumar, K. (Eds.), Systems Development for Human Progress, Amsterdam: North-Holland."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.1991.20"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/162124.162127"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1038\/sj.ejis.3000298"},{"key":"e_1_2_1_15_1","volume-title":"Security and Auditing of VPN,\" Proceedings of Third International Workshop on Services in Distributed and Networked Environments","author":"Baukari N.","year":"1996","unstructured":"Baukari , N. and Aljane , A . ( 1996 ). \" Security and Auditing of VPN,\" Proceedings of Third International Workshop on Services in Distributed and Networked Environments . Baukari, N. and Aljane, A. (1996). \"Security and Auditing of VPN,\" Proceedings of Third International Workshop on Services in Distributed and Networked Environments."},{"key":"e_1_2_1_16_1","volume-title":"Virtual Private Networks - The Major Issues, Problems and Opportunities,\" IEE Colloquium on Virtual Networking","author":"Bell R.","year":"1993","unstructured":"Bell , R. ( 1993 ). \" Virtual Private Networks - The Major Issues, Problems and Opportunities,\" IEE Colloquium on Virtual Networking . Bell, R. (1993). \"Virtual Private Networks - The Major Issues, Problems and Opportunities,\" IEE Colloquium on Virtual Networking."},{"key":"e_1_2_1_17_1","volume-title":"Probable Plaintext Cryptanalysis of the IP Security Protocols,\" Proceedings of the 1997 Symposium on Network and Distributed Systems Security","author":"Bellovin S. M.","year":"1997","unstructured":"Bellovin , S. M. ( 1997 ). \" Probable Plaintext Cryptanalysis of the IP Security Protocols,\" Proceedings of the 1997 Symposium on Network and Distributed Systems Security . Bellovin, S. M. (1997). \"Probable Plaintext Cryptanalysis of the IP Security Protocols,\" Proceedings of the 1997 Symposium on Network and Distributed Systems Security."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/35.312843"},{"key":"e_1_2_1_19_1","volume-title":"Specification and Analysis of A Security Management System,\" Proceedings of the IEEE Network Operations and Management Symposium","author":"Bemardi A.","year":"1994","unstructured":"Bemardi , A. , Rico , N. , Cherkaoui , O. , and Banfield , J . ( 1994 ). \" Specification and Analysis of A Security Management System,\" Proceedings of the IEEE Network Operations and Management Symposium . Bemardi, A., Rico, N., Cherkaoui, O., and Banfield, J. (1994). \"Specification and Analysis of A Security Management System,\" Proceedings of the IEEE Network Operations and Management Symposium."},{"key":"e_1_2_1_20_1","volume-title":"An Application of Qualitative Risk Analysis to Computer Security for the Commercial Sector,\" Proceedings of the Eight Annual Computer Security Applications Conference","author":"Bennett S.P.","year":"1992","unstructured":"Bennett , S.P. and Kailay , M.P . ( 1992 ). \" An Application of Qualitative Risk Analysis to Computer Security for the Commercial Sector,\" Proceedings of the Eight Annual Computer Security Applications Conference . Bennett, S.P. and Kailay, M.P. (1992). \"An Application of Qualitative Risk Analysis to Computer Security for the Commercial Sector,\" Proceedings of the Eight Annual Computer Security Applications Conference."},{"key":"e_1_2_1_21_1","volume-title":"An Overview of Computer Viruses in a Research Environment,\" 4th DPMA","author":"Bishop M.","year":"1991","unstructured":"Bishop , M. ( 1991 ). \" An Overview of Computer Viruses in a Research Environment,\" 4th DPMA , IEEE, ACM Computer virus and Security Conference . Bishop, M. (1991). \"An Overview of Computer Viruses in a Research Environment,\" 4th DPMA, IEEE, ACM Computer virus and Security Conference."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(97)88131-X"},{"key":"e_1_2_1_23_1","volume-title":"GSM Security: A Description of the Reasons for Security and the Techniques,\" IEE Colloquium on Security and Cryptography","author":"Bookson C.","year":"1994","unstructured":"Bookson , C. ( 1994 ). \" GSM Security: A Description of the Reasons for Security and the Techniques,\" IEE Colloquium on Security and Cryptography . Bookson, C. (1994). \"GSM Security: A Description of the Reasons for Security and the Techniques,\" IEE Colloquium on Security and Cryptography."},{"key":"e_1_2_1_24_1","volume-title":"A Methodology for the Development of Secure Application Systems,\" Proceeding of the 11th IFIP TC11 International Conference on Information Security","author":"Booysen H. A. S.","year":"1995","unstructured":"Booysen , H. A. S. and Eloff , J. H. P . ( 1995 ). \" A Methodology for the Development of Secure Application Systems,\" Proceeding of the 11th IFIP TC11 International Conference on Information Security . Booysen, H. A. S. and Eloff, J. H. P. (1995). \"A Methodology for the Development of Secure Application Systems,\" Proceeding of the 11th IFIP TC11 International Conference on Information Security."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.345822"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/35.312848"},{"key":"e_1_2_1_27_1","volume-title":"British Standard Institution","year":"1993","unstructured":"BS7799 ( 1993 ). British Standard Institution , London, UK . BS7799 (1993). British Standard Institution, London, UK."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/38.736466"},{"key":"e_1_2_1_29_1","volume-title":"Database Security","author":"Castano S.","year":"1995","unstructured":"Castano , S. , Fugini , M. , Martell , G. , and Samarati , P . ( 1995 ). Database Security , Boston, MA : Addison-Wesley . Castano, S., Fugini, M., Martell, G., and Samarati, P. (1995). Database Security, Boston, MA: Addison-Wesley."},{"key":"e_1_2_1_30_1","volume-title":"Penetration Testing Through Social Engineering,\" Information Systems Security","author":"Ceraolo J. P.","year":"1996","unstructured":"Ceraolo , J. P. ( 1996 ). \" Penetration Testing Through Social Engineering,\" Information Systems Security , Vol. 4 , No. 4. Ceraolo, J. P. (1996). \"Penetration Testing Through Social Engineering,\" Information Systems Security, Vol. 4, No. 4."},{"key":"e_1_2_1_31_1","volume-title":"Communication, Control and Power Engineering.","author":"Chan K. L.","year":"1993","unstructured":"Chan , K. L. , Kwong , S. , and Longginnou , L . ( 1993 ). \" Security Management on Mobile-Phone Communication,\" Proceedings of the Computer , Communication, Control and Power Engineering. Chan, K. L., Kwong, S., and Longginnou, L. (1993). \"Security Management on Mobile-Phone Communication,\" Proceedings of the Computer, Communication, Control and Power Engineering."},{"key":"e_1_2_1_32_1","volume-title":"Cryptographic Authentication of Passwords,\" Proceedings of 25th Annual 1991 IEEE International Carnahan Conference on Security Technology","author":"Chang C. C.","year":"1991","unstructured":"Chang , C. C. and Hwang , S. J . ( 1991 ). \" Cryptographic Authentication of Passwords,\" Proceedings of 25th Annual 1991 IEEE International Carnahan Conference on Security Technology . Chang, C. C. and Hwang, S. J. (1991). \"Cryptographic Authentication of Passwords,\" Proceedings of 25th Annual 1991 IEEE International Carnahan Conference on Security Technology."},{"key":"e_1_2_1_33_1","volume-title":"Institute of Electrical and Electronics Engineers 1993 International Carnahan Conference on Security Technology.","author":"Chang C. C.","year":"1993","unstructured":"Chang , C. C. , Hwang , R. J. , and Buehrer , D . ( 1993 ). \" Using Smart Cards to Authenticate Passwords,\" Proceedings , Institute of Electrical and Electronics Engineers 1993 International Carnahan Conference on Security Technology. Chang, C. C., Hwang, R. J., and Buehrer, D. (1993). \"Using Smart Cards to Authenticate Passwords,\" Proceedings, Institute of Electrical and Electronics Engineers 1993 International Carnahan Conference on Security Technology."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/358549.358563"},{"key":"e_1_2_1_35_1","volume-title":"Analysing Consistency of Security Policies,\" Proceedings of 1997 IEEE Symposium on Security and Privacy","author":"Cholvy L.","year":"1997","unstructured":"Cholvy , L. and Cuppens , F . ( 1997 ). \" Analysing Consistency of Security Policies,\" Proceedings of 1997 IEEE Symposium on Security and Privacy . Cholvy, L. and Cuppens, F. (1997). \"Analysing Consistency of Security Policies,\" Proceedings of 1997 IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_36_1","volume-title":"A Comparison of Commercial and Military Security Policies,\" Proceedings of the 1987 IEEE Symposium on Security and Privacy","author":"Clark D. D.","year":"1987","unstructured":"Clark , D. D. and Wilson , D. R . ( 1987 ). \" A Comparison of Commercial and Military Security Policies,\" Proceedings of the 1987 IEEE Symposium on Security and Privacy . Clark, D. D. and Wilson, D. R. (1987). \"A Comparison of Commercial and Military Security Policies,\" Proceedings of the 1987 IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_37_1","volume-title":"Computer Viruses - Theory and Experiments,\" Proceedings of IFIP\/SEC'84","author":"Cohen F.","year":"1984","unstructured":"Cohen , F. ( 1984 ). \" Computer Viruses - Theory and Experiments,\" Proceedings of IFIP\/SEC'84 . Cohen, F. (1984). \"Computer Viruses - Theory and Experiments,\" Proceedings of IFIP\/SEC'84."},{"key":"e_1_2_1_38_1","volume-title":"Current Best Practice Against Computer Viruses,\" Proceedings of 25th Annual 1991 IEEE International Carnahan Conference on Security Technology","author":"Cohen F.","year":"1991","unstructured":"Cohen , F. ( 1991 ). \" Current Best Practice Against Computer Viruses,\" Proceedings of 25th Annual 1991 IEEE International Carnahan Conference on Security Technology . Cohen, F. (1991). \"Current Best Practice Against Computer Viruses,\" Proceedings of 25th Annual 1991 IEEE International Carnahan Conference on Security Technology."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1049\/cce:19980407"},{"key":"e_1_2_1_40_1","volume-title":"Elsevier Advanced Technology","author":"Computer Fraud","year":"2000","unstructured":"Computer Fraud & Security Bulletin ( 2000 ). Elsevier Advanced Technology . Computer Fraud & Security Bulletin (2000). Elsevier Advanced Technology."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/278476.278486"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1004254420302"},{"key":"e_1_2_1_43_1","volume-title":"The Use of Baseline Measures in Risk Assessment,\" Proceedings of the 30th Annual International Carnahan Conference on Security Technology","author":"Custance N. D. E.","year":"1996","unstructured":"Custance , N. D. E. ( 1996 ). \" The Use of Baseline Measures in Risk Assessment,\" Proceedings of the 30th Annual International Carnahan Conference on Security Technology . IEEE Computer Society Press . Custance, N. D. E. (1996). \"The Use of Baseline Measures in Risk Assessment,\" Proceedings of the 30th Annual International Carnahan Conference on Security Technology. IEEE Computer Society Press."},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.796110"},{"key":"e_1_2_1_45_1","volume-title":"Privilege Graph: An Extension to the Typed Access Matrix Model,\" Proceedings of the Third European Symposium on Research in Computer Security (ESORICS)","author":"Dacier M.","year":"1994","unstructured":"Dacier , M. and Deswarte , Y . ( 1994 ). \" Privilege Graph: An Extension to the Typed Access Matrix Model,\" Proceedings of the Third European Symposium on Research in Computer Security (ESORICS) , Sringer-Verlag . Dacier, M. and Deswarte, Y. (1994). \"Privilege Graph: An Extension to the Typed Access Matrix Model,\" Proceedings of the Third European Symposium on Research in Computer Security (ESORICS), Sringer-Verlag."},{"key":"e_1_2_1_46_1","volume-title":"Working Group Report on Internet\/Intranet Security,\" Proceedings of the Sixth IEEE Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises","author":"Davis B. C.","year":"1997","unstructured":"Davis , B. C. and Yl\u00f6nen , T . ( 1997 ). \" Working Group Report on Internet\/Intranet Security,\" Proceedings of the Sixth IEEE Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises , IEEE Computer Society Press , Los Alamitos, CA . Davis, B. C. and Yl\u00f6nen, T. (1997). \"Working Group Report on Internet\/Intranet Security,\" Proceedings of the Sixth IEEE Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises, IEEE Computer Society Press, Los Alamitos, CA."},{"key":"e_1_2_1_47_1","first-page":"241","volume-title":"Reprinted in Denning, D.E., and Denning, P.J. (1998) (Eds)","author":"Dean D.","year":"1996","unstructured":"Dean , D. , Felten , E.W. , Wallach , D.S. , and Balfanz , D . ( 1996 ). \" Java Security: Web Browsers and Beyond,\" Proceedings of 1996 IEEE Symposium on Security and Privacy , Reprinted in Denning, D.E., and Denning, P.J. (1998) (Eds) , Internet Besieged : Countering Cyberspace Scofflaws , New York : ACM Press , pp. 241 -- 269 . Dean, D., Felten, E.W., Wallach, D.S., and Balfanz, D. (1996). \"Java Security: Web Browsers and Beyond,\" Proceedings of 1996 IEEE Symposium on Security and Privacy, Reprinted in Denning, D.E., and Denning, P.J. (1998) (Eds), Internet Besieged: Countering Cyberspace Scofflaws, New York: ACM Press, pp. 241--269."},{"key":"e_1_2_1_48_1","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4899-2271-7","volume-title":"Intrinsic Motivation and Self-Determination in Human Behavior","author":"Deci E. L.","year":"1985","unstructured":"Deci , E. L. and Ryan , R. M . ( 1985 ). Intrinsic Motivation and Self-Determination in Human Behavior , New York : Plenum Press . Deci, E. L. and Ryan, R. M. (1985). Intrinsic Motivation and Self-Determination in Human Behavior, New York: Plenum Press."},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/360051.360056"},{"key":"e_1_2_1_50_1","first-page":"117","article-title":"Passwords","volume":"80","author":"Denning P.J.","year":"1992","unstructured":"Denning , P.J. ( 1992 ). \" Passwords ,\" American Scientist , Vol. 80 , pp. 117 -- 120 . Denning, P.J. (1992). \"Passwords,\" American Scientist, Vol. 80, pp. 117--120.","journal-title":"American Scientist"},{"issue":"2","key":"e_1_2_1_51_1","first-page":"34","article-title":"Key Escrow Encryption Policies and Technologies","volume":"5","author":"Denning D.E","year":"1996","unstructured":"Denning , D.E and Baugh , W.E., Jr. ( 1996 ). \" Key Escrow Encryption Policies and Technologies ,\" Information Systems Security , Vol. 5 , No. 2 , pp. 34 -- 44 . Denning, D.E and Baugh, W.E., Jr. (1996). \"Key Escrow Encryption Policies and Technologies,\" Information Systems Security, Vol. 5, No. 2, pp. 34--44.","journal-title":"Information Systems Security"},{"key":"e_1_2_1_52_1","first-page":"357","volume-title":"Internet Besieged: Countering Cyberspace Scofflaws, Denning","author":"Denning D. E.","year":"1998","unstructured":"Denning , D. E. and Branstad , D. K . ( 1998 ). A Taxonomy for Key Recovery Encryption Systems . in Internet Besieged: Countering Cyberspace Scofflaws, Denning , D.E. and Denning, P.J. (Ed.), New York : ACM Press , pp. 357 -- 375 . Denning, D. E. and Branstad, D. K. (1998). A Taxonomy for Key Recovery Encryption Systems. in Internet Besieged: Countering Cyberspace Scofflaws, Denning, D.E. and Denning, P.J. (Ed.), New York: ACM Press, pp. 357--375."},{"key":"e_1_2_1_53_1","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-349-14454-9","volume-title":"Managing Information Systems Security","author":"Dhillon G.","year":"1997","unstructured":"Dhillon , G. ( 1997 ). Managing Information Systems Security , United Kingdom : MacMillan Press LTD. Dhillon, G. (1997). Managing Information Systems Security, United Kingdom: MacMillan Press LTD."},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1046\/j.1365-2575.2001.00099.x"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/MMCS.1997.609792"},{"key":"e_1_2_1_56_1","volume-title":"A Security Model for the Design of Hypermedia Systems,\" Proceedings of the TC11 14th International Conference on Information Security (SEC'98)","author":"Diaz P","year":"1998","unstructured":"Diaz , P , Aedo , A. , and Ribagorda , A . ( 1998 ). \" A Security Model for the Design of Hypermedia Systems,\" Proceedings of the TC11 14th International Conference on Information Security (SEC'98) . Diaz, P, Aedo, A., and Ribagorda, A. (1998). \"A Security Model for the Design of Hypermedia Systems,\" Proceedings of the TC11 14th International Conference on Information Security (SEC'98)."},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/6294.774950"},{"key":"e_1_2_1_58_1","volume-title":"Computer Security and Information Integrity","author":"Dobson J.","year":"1991","unstructured":"Dobson , J. ( 1991 ). \" A Methodology for Analysing Human and Computer-Related Issues in Secure Systems,\" in Dittrich , K., Rautakivi, S., and Saari, J. (Eds.), Computer Security and Information Integrity , Elsevier Science Publishers . Dobson, J. (1991). \"A Methodology for Analysing Human and Computer-Related Issues in Secure Systems,\" in Dittrich, K., Rautakivi, S., and Saari, J. (Eds.), Computer Security and Information Integrity, Elsevier Science Publishers."},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1989.36297"},{"key":"e_1_2_1_60_1","volume-title":"A Framework for Dealing With and Specifying Security Requirements in Information Systems,\" Proceedings of IFP SEC'96","author":"Dubois E.","year":"1996","unstructured":"Dubois , E. and Wu , S . ( 1996 ). \" A Framework for Dealing With and Specifying Security Requirements in Information Systems,\" Proceedings of IFP SEC'96 . Dubois, E. and Wu, S. (1996). \"A Framework for Dealing With and Specifying Security Requirements in Information Systems,\" Proceedings of IFP SEC'96."},{"key":"e_1_2_1_61_1","volume-title":"WWW Distribution of Private Information with Watermarking,\" Proceedings of the 32nd Annual Hawaii International Conference on Systems Sciences (HICSS-32)","author":"Dymond P.","year":"1999","unstructured":"Dymond , P. and Jenkin , M . ( 1999 ). \" WWW Distribution of Private Information with Watermarking,\" Proceedings of the 32nd Annual Hawaii International Conference on Systems Sciences (HICSS-32) . Dymond, P. and Jenkin, M. (1999). \"WWW Distribution of Private Information with Watermarking,\" Proceedings of the 32nd Annual Hawaii International Conference on Systems Sciences (HICSS-32)."},{"key":"e_1_2_1_62_1","volume-title":"IFIP\/SEC'95.","author":"Eckert C.","year":"1995","unstructured":"Eckert , C. ( 1995 ). \" Matching Security Policies to Application Needs,\" Proceedings of the IFIP TC11 Eleventh International Conference on Information Security , IFIP\/SEC'95. Eckert, C. (1995). \"Matching Security Policies to Application Needs,\" Proceedings of the IFIP TC11 Eleventh International Conference on Information Security, IFIP\/SEC'95."},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(95)00021-6"},{"key":"e_1_2_1_64_1","volume-title":"Object-Oriented Modeling of Security Semantics,\" Proceedings of the 11th Annual Computer Society Applications Conference (ACSAC'95)","author":"Ellmer E.","year":"1995","unstructured":"Ellmer , E. , Pernul , G. , and Kappel , G . ( 1995 ). \" Object-Oriented Modeling of Security Semantics,\" Proceedings of the 11th Annual Computer Society Applications Conference (ACSAC'95) . Ellmer, E., Pernul, G., and Kappel, G. (1995). \"Object-Oriented Modeling of Security Semantics,\" Proceedings of the 11th Annual Computer Society Applications Conference (ACSAC'95)."},{"key":"e_1_2_1_65_1","volume-title":"A Methodology for Network Security,\" Proceedings of the International Workshop on Advanced Communications and Applications for High Speed Networks","author":"Eloff J. H. P.","year":"1992","unstructured":"Eloff , J. H. P. and Nel , A. J . ( 1992 ). \" A Methodology for Network Security,\" Proceedings of the International Workshop on Advanced Communications and Applications for High Speed Networks , IEEE Computer Society Press . Eloff, J. H. P. and Nel, A. J. (1992). \"A Methodology for Network Security,\" Proceedings of the International Workshop on Advanced Communications and Applications for High Speed Networks, IEEE Computer Society Press."},{"key":"e_1_2_1_66_1","volume-title":"Measuring the Information Security Level in an Organization,\" Proceedings of the Sixth Working Conference of Workgroup 11.1 and Workgroup 11.2 of Technical Committee 11","author":"Eloff J. H. P","year":"1998","unstructured":"Eloff , J. H. P and von Solms , R. ( 1998 ). \" Measuring the Information Security Level in an Organization,\" Proceedings of the Sixth Working Conference of Workgroup 11.1 and Workgroup 11.2 of Technical Committee 11 . Eloff, J. H. P and von Solms, R. (1998). \"Measuring the Information Security Level in an Organization,\" Proceedings of the Sixth Working Conference of Workgroup 11.1 and Workgroup 11.2 of Technical Committee 11."},{"key":"e_1_2_1_67_1","volume-title":"Managing Network Security - a Pragmatic Approach,\" Proceedings of the Seventeenth IEEE Symposium on Reliable Distributed Systems","author":"Falk R.","year":"1998","unstructured":"Falk , R. and Trommer , M . ( 1998 ). \" Managing Network Security - a Pragmatic Approach,\" Proceedings of the Seventeenth IEEE Symposium on Reliable Distributed Systems . Falk, R. and Trommer, M. (1998). \"Managing Network Security - a Pragmatic Approach,\" Proceedings of the Seventeenth IEEE Symposium on Reliable Distributed Systems."},{"key":"e_1_2_1_68_1","volume-title":"An Abstract Authorization System for the Internet,\" Proceedings of the Ninth International Workshop on Database and Expert Systems Applications","author":"Fernandez E.B.","year":"1998","unstructured":"Fernandez , E.B. and Nair , K.R . ( 1998 ). \" An Abstract Authorization System for the Internet,\" Proceedings of the Ninth International Workshop on Database and Expert Systems Applications . Fernandez, E.B. and Nair, K.R. (1998). \"An Abstract Authorization System for the Internet,\" Proceedings of the Ninth International Workshop on Database and Expert Systems Applications."},{"key":"e_1_2_1_69_1","volume-title":"A Taxonomy for Information Flow Policies and Models,\" Proceedings of the 1991 IEEE Computer Security Symposium on Research in Security and Privacy","author":"Foley S.N.","year":"1991","unstructured":"Foley , S.N. ( 1991 ). \" A Taxonomy for Information Flow Policies and Models,\" Proceedings of the 1991 IEEE Computer Security Symposium on Research in Security and Privacy . Foley, S.N. (1991). \"A Taxonomy for Information Flow Policies and Models,\" Proceedings of the 1991 IEEE Computer Security Symposium on Research in Security and Privacy."},{"key":"e_1_2_1_70_1","volume-title":"Secure Electronic Commerce: Building the Infrastructure for Digital Signatures & Encryption","author":"Ford W.","year":"1997","unstructured":"Ford , W. and Baum , M. S . ( 1997 ). Secure Electronic Commerce: Building the Infrastructure for Digital Signatures & Encryption , Upper Saddle River, NJ : Prentice Hall . Ford, W. and Baum, M. S. (1997). Secure Electronic Commerce: Building the Infrastructure for Digital Signatures & Encryption, Upper Saddle River, NJ: Prentice Hall."},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.223881"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/32206.315753"},{"key":"e_1_2_1_73_1","volume-title":"Web Security & Commerce","author":"Garfinkel S.","year":"1997","unstructured":"Garfinkel , S. and Spafford , G . ( 1997 ). Web Security & Commerce , Sebastopol, CA : O'Reilly & Associates , Inc. Garfinkel, S. and Spafford, G. (1997). Web Security & Commerce, Sebastopol, CA: O'Reilly & Associates, Inc."},{"key":"e_1_2_1_74_1","volume-title":"The Inference Problem for Computer Security,\" Proceedings of Computer Security Foundations Workshop V","author":"Garvey T.D.","year":"1992","unstructured":"Garvey , T.D. ( 1992 ). \" The Inference Problem for Computer Security,\" Proceedings of Computer Security Foundations Workshop V . Garvey, T.D. (1992). \"The Inference Problem for Computer Security,\" Proceedings of Computer Security Foundations Workshop V."},{"key":"e_1_2_1_75_1","volume-title":"Washington D.C.","author":"Garvey T. D.","year":"1991","unstructured":"Garvey , T. D. and Lunt , T . ( 1991 ). \" Model-Based Intrusion Detection,\" Proceedings of the 14th National Computer Security Conference , Washington D.C. Garvey, T. D. and Lunt, T. (1991). \"Model-Based Intrusion Detection,\" Proceedings of the 14th National Computer Security Conference, Washington D.C."},{"key":"e_1_2_1_76_1","volume-title":"Best Defenses","author":"Ghosh A. K.","year":"1998","unstructured":"Ghosh , A. K. ( 1998 ). E-Commerce Security: Weak Links , Best Defenses , Hoboken, NJ : Wiley Computer Publishing . Ghosh, A. K. (1998). E-Commerce Security: Weak Links, Best Defenses, Hoboken, NJ: Wiley Computer Publishing."},{"key":"e_1_2_1_77_1","first-page":"13335","article-title":"Guidelines for the Management of IT Security","author":"GMITS","year":"1996","unstructured":"GMITS ( 1996 ), Guidelines for the Management of IT Security , Part 1: Concepts and Models for IT Security. ISO\/IEC TR 13335 - 13331 . GMITS (1996), Guidelines for the Management of IT Security, Part 1: Concepts and Models for IT Security. ISO\/IEC TR 13335-1.","journal-title":"Part 1: Concepts and Models for IT Security. ISO\/IEC TR"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.223866"},{"key":"e_1_2_1_79_1","volume-title":"Optimal Authentication Protocols Resistant to Password Guessing Attacks,\" Proceedings of the Eighth IEEE Computer Security Foundations Workshop","author":"Gong L.","year":"1995","unstructured":"Gong , L. ( 1995 ). \" Optimal Authentication Protocols Resistant to Password Guessing Attacks,\" Proceedings of the Eighth IEEE Computer Security Foundations Workshop , IEEE Computer Society Press . Gong, L. (1995). \"Optimal Authentication Protocols Resistant to Password Guessing Attacks,\" Proceedings of the Eighth IEEE Computer Security Foundations Workshop, IEEE Computer Society Press."},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/40.591650"},{"key":"e_1_2_1_81_1","volume-title":"Fundamentals of Cryptography and Encryption. Handbook of Information Security Management","author":"Gove R. A.","year":"1999","unstructured":"Gove , R. A. ( 1999 ). Fundamentals of Cryptography and Encryption. Handbook of Information Security Management 1999, Krause, M. , and Tipton, H.F. (Eds .), Boca Raton, FL : CRC Press . Gove, R. A. (1999). Fundamentals of Cryptography and Encryption. Handbook of Information Security Management 1999, Krause, M., and Tipton, H.F. (Eds.), Boca Raton, FL: CRC Press."},{"key":"e_1_2_1_82_1","volume-title":"Addressing Security Issues in Programming Languages for Mobile Code,\" Proceedings of the Ninth International Workshop on Database and Expert System Applications","author":"Gritzalis S.","year":"1998","unstructured":"Gritzalis , S. and Iliadis , J . ( 1998 ). \" Addressing Security Issues in Programming Languages for Mobile Code,\" Proceedings of the Ninth International Workshop on Database and Expert System Applications . IEEE Computer Society Press . Gritzalis, S. and Iliadis, J. (1998). \"Addressing Security Issues in Programming Languages for Mobile Code,\" Proceedings of the Ninth International Workshop on Database and Expert System Applications. IEEE Computer Society Press."},{"key":"e_1_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.2307\/249656"},{"key":"e_1_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/360303.360333"},{"key":"e_1_2_1_85_1","volume-title":"Smart Card Security and Applications","author":"Hendry M.","year":"1997","unstructured":"Hendry , M. ( 1997 ). Smart Card Security and Applications , Norwood, MA : Artech House . Hendry, M. (1997). Smart Card Security and Applications, Norwood, MA: Artech House."},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1080\/10864415.1999.11518343"},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1016\/0959-8022(96)00004-5"},{"key":"e_1_2_1_88_1","volume-title":"IFIP\/SEC'96.","author":"Hitchings J.","year":"1996","unstructured":"Hitchings , J. ( 1996 ). \" A Practical Solution to the Complex Human Issues of Information Security Design,\" Proceedings of the 12th IFIP TC11 International Conference on Information Security , IFIP\/SEC'96. Hitchings, J. (1996). \"A Practical Solution to the Complex Human Issues of Information Security Design,\" Proceedings of the 12th IFIP TC11 International Conference on Information Security, IFIP\/SEC'96."},{"key":"e_1_2_1_89_1","volume-title":"Virus Detection,\" European Conference on Security and Detection (ECOS'97)","author":"Hruska J.","year":"1997","unstructured":"Hruska , J. ( 1997 ). \" Virus Detection,\" European Conference on Security and Detection (ECOS'97) . Hruska, J. (1997). \"Virus Detection,\" European Conference on Security and Detection (ECOS'97)."},{"key":"e_1_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.372146"},{"key":"e_1_2_1_91_1","volume-title":"E.D., and Lindgreen, P., (Eds), Information System Concepts: An In-depth Analysis., North-Holland","author":"Iivari J.","year":"1989","unstructured":"Iivari , J. ( 1989 ). \" Levels of Abstraction as a Conceptual Framework for an Information System,\" In Falkenberg , E.D., and Lindgreen, P., (Eds), Information System Concepts: An In-depth Analysis., North-Holland , Amsterdam . Iivari, J. (1989). \"Levels of Abstraction as a Conceptual Framework for an Information System,\" In Falkenberg, E.D., and Lindgreen, P., (Eds), Information System Concepts: An In-depth Analysis., North-Holland, Amsterdam."},{"key":"e_1_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.1991.47"},{"key":"e_1_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0306-4379(96)00028-2"},{"key":"e_1_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.9.2.164"},{"key":"e_1_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1080\/07421222.2000.11045656"},{"key":"e_1_2_1_96_1","volume-title":"Secure Mobile IP Using Security Primitives,\" Proceedings of the Sixth IEEE Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises","author":"Inoue A.","year":"1997","unstructured":"Inoue , A. , Ishiyama , M. , Fukumoto , A. , and Okamoto , T . ( 1997 ). \" Secure Mobile IP Using Security Primitives,\" Proceedings of the Sixth IEEE Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises . Inoue, A., Ishiyama, M., Fukumoto, A., and Okamoto, T. (1997). \"Secure Mobile IP Using Security Primitives,\" Proceedings of the Sixth IEEE Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises."},{"key":"e_1_2_1_97_1","volume-title":"Information Technology Security Evaluation Criteria, Provisional Harmonised Criteria: Version 1.2","author":"ITSEC","year":"1991","unstructured":"ITSEC ( 1991 ). Commission of the European Communities , Information Technology Security Evaluation Criteria, Provisional Harmonised Criteria: Version 1.2 , Office for Official Publications of the European Communities, Luxembourg . ITSEC (1991). Commission of the European Communities, Information Technology Security Evaluation Criteria, Provisional Harmonised Criteria: Version 1.2, Office for Official Publications of the European Communities, Luxembourg."},{"key":"e_1_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.106973"},{"key":"e_1_2_1_99_1","volume-title":"Solutions to the Polyinstantiation Problem,\" in Abrams","author":"Jajodia S.","year":"1995","unstructured":"Jajodia S. , Sandhu , R. S. , and Blaustein B. T . ( 1995 ). \" Solutions to the Polyinstantiation Problem,\" in Abrams , M.D., Jajodia, S., and Podell, H.J. (Eds.), Information Security, An Integrated Collection of Essays , Los Alamitos, CA : IEEE Computer Society Press . Jajodia S., Sandhu, R. S., and Blaustein B. T. (1995). \"Solutions to the Polyinstantiation Problem,\" in Abrams, M.D., Jajodia, S., and Podell, H.J. (Eds.), Information Security, An Integrated Collection of Essays, Los Alamitos, CA: IEEE Computer Society Press."},{"key":"e_1_2_1_100_1","volume-title":"Managing Information Systems Security: A Soft Approach,\" Proceedings of the Information Systems Conference of New Zealand","author":"James H. L.","year":"1996","unstructured":"James , H. L. ( 1996 ). \" Managing Information Systems Security: A Soft Approach,\" Proceedings of the Information Systems Conference of New Zealand , IEEE Society Press . James, H. L. (1996). \"Managing Information Systems Security: A Soft Approach,\" Proceedings of the Information Systems Conference of New Zealand, IEEE Society Press."},{"key":"e_1_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1109\/45.747237"},{"key":"e_1_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(89)90051-5"},{"key":"e_1_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.1998.10029"},{"key":"e_1_2_1_104_1","volume-title":"Research Questions Guiding Selection of an Appropriate Research Method,\" Proceedings of the 8th European Conference on Information Systems (ECIS","author":"J\u00e4rvinen P.","year":"2000","unstructured":"J\u00e4rvinen , P. ( 2000 ). \" Research Questions Guiding Selection of an Appropriate Research Method,\" Proceedings of the 8th European Conference on Information Systems (ECIS 2000), Vienna . J\u00e4rvinen, P. (2000). \"Research Questions Guiding Selection of an Appropriate Research Method,\" Proceedings of the 8th European Conference on Information Systems (ECIS 2000), Vienna."},{"key":"e_1_2_1_105_1","doi-asserted-by":"publisher","DOI":"10.1109\/4236.612220"},{"key":"e_1_2_1_106_1","doi-asserted-by":"publisher","DOI":"10.1145\/357369.357374"},{"key":"e_1_2_1_107_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.106972"},{"key":"e_1_2_1_108_1","volume-title":"Security Requirements and Models in Open Systems,\" Proceedings of the Twenty-Third Southeastern Conference on Systems Theory","author":"Kolstad","year":"1991","unstructured":"Kolstad and Bowles ( 1991 ). \" Security Requirements and Models in Open Systems,\" Proceedings of the Twenty-Third Southeastern Conference on Systems Theory . Kolstad and Bowles (1991). \"Security Requirements and Models in Open Systems,\" Proceedings of the Twenty-Third Southeastern Conference on Systems Theory."},{"key":"e_1_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(95)00020-8"},{"key":"e_1_2_1_110_1","volume-title":"Computer Ethics and Computer Abuse: A Longitudinal Study of Swedish University Students,\" IFIP TC11 6th International Conference on Information Systems Security","author":"Kowalski S.","year":"1990","unstructured":"Kowalski , S. ( 1990 ). \" Computer Ethics and Computer Abuse: A Longitudinal Study of Swedish University Students,\" IFIP TC11 6th International Conference on Information Systems Security . Kowalski, S. (1990). \"Computer Ethics and Computer Abuse: A Longitudinal Study of Swedish University Students,\" IFIP TC11 6th International Conference on Information Systems Security."},{"key":"e_1_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1049\/ip-com:19982282"},{"key":"e_1_2_1_112_1","volume-title":"A Software Platform for Secure Applications Based on CORBA,\" Proceedings of the Sixth IEEE Computer Society Workshop on Future Trends of Distributed Computing Systems","author":"Kyeongbeom K.","year":"1997","unstructured":"Kyeongbeom , K. , Youngkyun K. , Youngkee S. , and Soran , I . ( 1997 ). \" A Software Platform for Secure Applications Based on CORBA,\" Proceedings of the Sixth IEEE Computer Society Workshop on Future Trends of Distributed Computing Systems . Kyeongbeom, K., Youngkyun K., Youngkee S., and Soran, I. (1997). \"A Software Platform for Secure Applications Based on CORBA,\" Proceedings of the Sixth IEEE Computer Society Workshop on Future Trends of Distributed Computing Systems."},{"key":"e_1_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.1145\/775265.775268"},{"key":"e_1_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.1998.707612"},{"key":"e_1_2_1_115_1","volume-title":"A Generic Virus Detection Agent on the Internet,\" Proceedings of the Thirtieth Hwaii International Conference on System Sciences (HICSS'97)","author":"Lee J. S.","year":"1997","unstructured":"Lee , J. S. , Hsiang , J. , and Tsang , P. H . ( 1997 ). \" A Generic Virus Detection Agent on the Internet,\" Proceedings of the Thirtieth Hwaii International Conference on System Sciences (HICSS'97) . Lee, J. S., Hsiang, J., and Tsang, P. H. (1997). \"A Generic Virus Detection Agent on the Internet,\" Proceedings of the Thirtieth Hwaii International Conference on System Sciences (HICSS'97)."},{"key":"e_1_2_1_116_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.1998.654776"},{"key":"e_1_2_1_117_1","volume-title":"Harmonization of Information Security Requirements,\" Informatica","author":"Leiwo J.","year":"1999","unstructured":"Leiwo , J. , Gamage , C. , and Zheng , Y . ( 1999 ). \" Harmonization of Information Security Requirements,\" Informatica , Vol. 17 . Leiwo, J., Gamage, C., and Zheng, Y. (1999). \"Harmonization of Information Security Requirements,\" Informatica, Vol. 17."},{"key":"e_1_2_1_118_1","volume-title":"Developing Internet Security Policy for Organizations,\" Proceedings of the Thirtieth Hwaii International Conference on System Sciences","author":"Lichtenstein S.","year":"1997","unstructured":"Lichtenstein , S. ( 1997 ). \" Developing Internet Security Policy for Organizations,\" Proceedings of the Thirtieth Hwaii International Conference on System Sciences . Lichtenstein, S. (1997). \"Developing Internet Security Policy for Organizations,\" Proceedings of the Thirtieth Hwaii International Conference on System Sciences."},{"key":"e_1_2_1_119_1","volume-title":"Constructs, Compliance,\" Proceedings of the IFIP TC11 13th International Conference on Information Security (SEC'97).","author":"Lindgreen E. R.","year":"1997","unstructured":"Lindgreen , E. R. , Janus , H. R. D. , Shahim , A. , Hulst , G. , and Herscberg , I. S . ( 1997 ). \" Security When Outsourcing: Concepts , Constructs, Compliance,\" Proceedings of the IFIP TC11 13th International Conference on Information Security (SEC'97). Lindgreen, E. R., Janus, H. R. D., Shahim, A., Hulst, G., and Herscberg, I. S. (1997). \"Security When Outsourcing: Concepts, Constructs, Compliance,\" Proceedings of the IFIP TC11 13th International Conference on Information Security (SEC'97)."},{"key":"e_1_2_1_120_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(96)81709-3"},{"key":"e_1_2_1_121_1","doi-asserted-by":"publisher","DOI":"10.1109\/6.648669"},{"key":"e_1_2_1_122_1","volume-title":"A Policy Based Role Object Model,\" Proceedings of the First International Enterprise Distributed Object Computing Workshop","author":"Lupu E.","year":"1997","unstructured":"Lupu , E. and Sloman , M . ( 1997 ). \" A Policy Based Role Object Model,\" Proceedings of the First International Enterprise Distributed Object Computing Workshop , IEEE Computer Society Press . Lupu, E. and Sloman, M. (1997). \"A Policy Based Role Object Model,\" Proceedings of the First International Enterprise Distributed Object Computing Workshop, IEEE Computer Society Press."},{"key":"e_1_2_1_123_1","volume-title":"A Taxonomic Perspective of Information Systems Development: Theoretical Constructs and Recommendations,\" in Boland","author":"Lyytinen K.","year":"1987","unstructured":"Lyytinen , K. ( 1987 ). \" A Taxonomic Perspective of Information Systems Development: Theoretical Constructs and Recommendations,\" in Boland , R.J., and Hirscheim, R.A. (Eds.), Critical Issues in Information Systems Research , Hoboken, NJ : John Wiley & Sons Ltd . Lyytinen, K. (1987). \"A Taxonomic Perspective of Information Systems Development: Theoretical Constructs and Recommendations,\" in Boland, R.J., and Hirscheim, R.A. (Eds.), Critical Issues in Information Systems Research, Hoboken, NJ: John Wiley & Sons Ltd."},{"key":"e_1_2_1_124_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-9236(94)00041-2"},{"key":"e_1_2_1_125_1","volume-title":"Blocking Java Applets at the Firewall,\" Proceedings of the 1997 Symposium on Network and Distributed System Security","author":"Martin D. M.","year":"1997","unstructured":"Martin , D. M. , Rajagopalan , S. , and Rubun , A. D . ( 1997 ). \" Blocking Java Applets at the Firewall,\" Proceedings of the 1997 Symposium on Network and Distributed System Security , IEEE Computer Society Press . Martin, D. M., Rajagopalan, S., and Rubun, A. D. (1997). \"Blocking Java Applets at the Firewall,\" Proceedings of the 1997 Symposium on Network and Distributed System Security, IEEE Computer Society Press."},{"key":"e_1_2_1_126_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2.3.173"},{"key":"e_1_2_1_127_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.48795"},{"key":"e_1_2_1_128_1","first-page":"27","volume-title":"Proceedings of the IFIP TC11 \/SEC'92","author":"McLean K.","year":"1992","unstructured":"McLean , K. ( 1992 ). \" Information Security Awareness - Selling the Cause,\" in Gable, G., et al. (Eds.), Security and Control: From Small Systems to Large , Proceedings of the IFIP TC11 \/SEC'92 , Singapore , pp. 27 -- 29 . McLean, K. (1992). \"Information Security Awareness - Selling the Cause,\" in Gable, G., et al. (Eds.), Security and Control: From Small Systems to Large, Proceedings of the IFIP TC11 \/SEC'92, Singapore, pp. 27--29."},{"key":"e_1_2_1_129_1","volume-title":"Handbook of Applied Cryptography","author":"Menezes A. J.","year":"1999","unstructured":"Menezes , A. J. , van Oorschot , P. C. and Vanstone , S. C . ( 1999 ). Handbook of Applied Cryptography , Boca Raton, FL : CRC Press . Menezes, A. J., van Oorschot, P. C. and Vanstone, S. C. (1999). Handbook of Applied Cryptography, Boca Raton, FL: CRC Press."},{"key":"e_1_2_1_130_1","volume-title":"20 Years of Covert Channel Modeling and Analysis,\" Proceedings of the 1999 IEEE Symposium on Security and Privacy","author":"Millen J.","year":"1999","unstructured":"Millen , J. ( 1999 ). \" 20 Years of Covert Channel Modeling and Analysis,\" Proceedings of the 1999 IEEE Symposium on Security and Privacy . Millen, J. (1999). \"20 Years of Covert Channel Modeling and Analysis,\" Proceedings of the 1999 IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_131_1","doi-asserted-by":"publisher","DOI":"10.1109\/6.259484"},{"key":"e_1_2_1_132_1","doi-asserted-by":"publisher","DOI":"10.1109\/65.272938"},{"key":"e_1_2_1_133_1","volume-title":"Electronic Communications Risk Management: A Checklist for Business Managers,\" Computer & Security","author":"Moulton R. T.","year":"1996","unstructured":"Moulton , R. T. and Moulton , M. E . ( 1996 ). \" Electronic Communications Risk Management: A Checklist for Business Managers,\" Computer & Security , Vol. 15 , No. 5. Moulton, R. T. and Moulton, M. E. (1996). \"Electronic Communications Risk Management: A Checklist for Business Managers,\" Computer & Security, Vol. 15, No. 5."},{"key":"e_1_2_1_134_1","volume-title":"Reliability, Fault Tolerance, Concurrency and Real Time, Security.","author":"Moskowitz I. S.","year":"1994","unstructured":"Moskowitz , I. S. and Kang , M. H . ( 1994 ). \" Covert Channels - Here to Stay?\" Proceedings of the Ninth Annual Conference on Computer Assurance (COMPASS '94) Safety , Reliability, Fault Tolerance, Concurrency and Real Time, Security. Moskowitz, I. S. and Kang, M. H. (1994). \"Covert Channels - Here to Stay?\" Proceedings of the Ninth Annual Conference on Computer Assurance (COMPASS '94) Safety, Reliability, Fault Tolerance, Concurrency and Real Time, Security."},{"key":"e_1_2_1_135_1","first-page":"189","volume-title":"Safe & Secure Computing Systems","author":"Needham R. M.","year":"1989","unstructured":"Needham , R. M. ( 1989 ). \" Authentication,\" in Anderson , T. (Ed.), Safe & Secure Computing Systems , Blackwell Scientific Publications , pp. 189 -- 196 . Needham, R. M. (1989). \"Authentication,\" in Anderson, T. (Ed.), Safe & Secure Computing Systems, Blackwell Scientific Publications, pp. 189--196."},{"issue":"1","key":"e_1_2_1_136_1","first-page":"21","article-title":"Science and Epistemic Values","volume":"3","author":"Niiniluoto I.","year":"1990","unstructured":"Niiniluoto , I. ( 1990 ). \" Science and Epistemic Values ,\" Science Studies , Vol. 3 , No. 1 , pp. 21 -- 26 . Niiniluoto, I. (1990). \"Science and Epistemic Values,\" Science Studies, Vol. 3, No. 1, pp. 21--26.","journal-title":"Science Studies"},{"key":"e_1_2_1_137_1","volume-title":"Architectures for MLS Database Management Systems,\" in Abrams","author":"Notargiacomo L.","year":"1995","unstructured":"Notargiacomo , L. ( 1995 ). \" Architectures for MLS Database Management Systems,\" in Abrams , M.D., Jajodia, S., and Podell, H.J. (Eds.), Information Security, An Integrated Collection of Essays , Los Alamitos, CA : IEEE Computer Society Press . Notargiacomo, L. (1995). \"Architectures for MLS Database Management Systems,\" in Abrams, M.D., Jajodia, S., and Podell, H.J. (Eds.), Information Security, An Integrated Collection of Essays, Los Alamitos, CA: IEEE Computer Society Press."},{"key":"e_1_2_1_138_1","doi-asserted-by":"publisher","DOI":"10.1080\/07421222.1990.11517898"},{"key":"e_1_2_1_139_1","volume-title":"Information Theoretic Analysis of Steganography,\" Proceedings of 1998 IEEE International Symposium on Information Theory","author":"O'Sullivan J. A.","year":"1998","unstructured":"O'Sullivan , J. A. , Moulin , P. , and Ettinger , J. M . ( 1998 ). \" Information Theoretic Analysis of Steganography,\" Proceedings of 1998 IEEE International Symposium on Information Theory . O'Sullivan, J. A., Moulin, P., and Ettinger, J. M. (1998). \"Information Theoretic Analysis of Steganography,\" Proceedings of 1998 IEEE International Symposium on Information Theory."},{"key":"e_1_2_1_140_1","volume-title":"Fighting Computer Crime - A New Framework for Protecting Information","author":"Parker D. B.","year":"1998","unstructured":"Parker , D. B. ( 1998 ). Fighting Computer Crime - A New Framework for Protecting Information , Hoboken, NJ : Wiley Computer Publishing . Parker, D. B. (1998). Fighting Computer Crime - A New Framework for Protecting Information, Hoboken, NJ: Wiley Computer Publishing."},{"key":"e_1_2_1_141_1","volume-title":"Cost-effective Computer Security: Cognitive and Associative Passwords,\" Proceedings of the Sixth Australian Conference on Computer-Human Interaction","author":"Podd J.","year":"1996","unstructured":"Podd , J. , Bunnell , J. , and Henderson , R . ( 1996 ). \" Cost-effective Computer Security: Cognitive and Associative Passwords,\" Proceedings of the Sixth Australian Conference on Computer-Human Interaction . Podd, J., Bunnell, J., and Henderson, R. (1996). \"Cost-effective Computer Security: Cognitive and Associative Passwords,\" Proceedings of the Sixth Australian Conference on Computer-Human Interaction."},{"key":"e_1_2_1_142_1","volume-title":"Security Constraint Processing During Multilevel Secure Database Design,\" Proceedings of the 8th Annual Computer Security Applications Conference","author":"Pernul G.","year":"1992","unstructured":"Pernul , G. ( 1992 ). \" Security Constraint Processing During Multilevel Secure Database Design,\" Proceedings of the 8th Annual Computer Security Applications Conference , IEEE Society Press . Pernul, G. (1992). \"Security Constraint Processing During Multilevel Secure Database Design,\" Proceedings of the 8th Annual Computer Security Applications Conference, IEEE Society Press."},{"key":"e_1_2_1_143_1","volume-title":"Database Security,\" Advances in Computers","author":"Pernul G.","year":"1994","unstructured":"Pernul , G. ( 1994 ). \" Database Security,\" Advances in Computers , Vol. 38 , Yovits, M.C. (Ed.), Academic Press . Pernul, G. (1994). \"Database Security,\" Advances in Computers, Vol. 38, Yovits, M.C. (Ed.), Academic Press."},{"key":"e_1_2_1_144_1","volume-title":"Organizing MLS Databases from a Data Modelling Point of View,\" Proceedings of the 10th Annual Computer Security Applications Conference","author":"Pernul G.","year":"1994","unstructured":"Pernul , G. and Quirchmayr , G . ( 1994 ). \" Organizing MLS Databases from a Data Modelling Point of View,\" Proceedings of the 10th Annual Computer Security Applications Conference , IEEE Society Press . Pernul, G. and Quirchmayr, G. (1994). \"Organizing MLS Databases from a Data Modelling Point of View,\" Proceedings of the 10th Annual Computer Security Applications Conference, IEEE Society Press."},{"key":"e_1_2_1_145_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0169-023X(97)00045-1"},{"key":"e_1_2_1_146_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(97)80795-X"},{"key":"e_1_2_1_147_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.544350"},{"key":"e_1_2_1_148_1","doi-asserted-by":"publisher","DOI":"10.1109\/35.210402"},{"key":"e_1_2_1_149_1","doi-asserted-by":"publisher","DOI":"10.1145\/290163.290168"},{"key":"e_1_2_1_150_1","volume-title":"Computer Security and Information Integrity","author":"Rie\u00df H. P.","year":"1991","unstructured":"Rie\u00df , H. P. ( 1991 ). \" Modeling Security in Distributed Systems,\" in Dittrich , K., Rautakivi, S., and Saari, J. (Eds.), Computer Security and Information Integrity , Elsevier Science Publishers . Rie\u00df, H. P. (1991). \"Modeling Security in Distributed Systems,\" in Dittrich, K., Rautakivi, S., and Saari, J. (Eds.), Computer Security and Information Integrity, Elsevier Science Publishers."},{"key":"e_1_2_1_151_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.708448"},{"key":"e_1_2_1_152_1","volume-title":"Process Algebra and Non-interference,\" Proceedings of the 12th IEEE Computer Security Foundations Workshop","author":"Ryan P. Y. A.","year":"1999","unstructured":"Ryan , P. Y. A. and Schneider , S. A . ( 1999 ). \" Process Algebra and Non-interference,\" Proceedings of the 12th IEEE Computer Security Foundations Workshop . Ryan, P. Y. A. and Schneider, S. A. (1999). \"Process Algebra and Non-interference,\" Proceedings of the 12th IEEE Computer Security Foundations Workshop."},{"key":"e_1_2_1_153_1","volume-title":"Modelling Secure and Fair Electronic Commerce,\" Proceedings of the 14th Annual Computer Security Applications Conference","author":"R\u00f6hm A. W.","year":"1998","unstructured":"R\u00f6hm , A. W. , Pernul , G. , and Herrmann , G . ( 1998 ). \" Modelling Secure and Fair Electronic Commerce,\" Proceedings of the 14th Annual Computer Security Applications Conference . R\u00f6hm, A. W., Pernul, G., and Herrmann, G. (1998). \"Modelling Secure and Fair Electronic Commerce,\" Proceedings of the 14th Annual Computer Security Applications Conference."},{"key":"e_1_2_1_154_1","volume-title":"A Language for Modeling Secure Business Transactions,\" Proceedings of the IEEE Annual Computer Security Applications Conference (ACSAC'99)","author":"R\u00f6hm A. W.","year":"1999","unstructured":"R\u00f6hm , A. W. , Herrmann , G. , and Pernul , G . ( 1999 ). \" A Language for Modeling Secure Business Transactions,\" Proceedings of the IEEE Annual Computer Security Applications Conference (ACSAC'99) . R\u00f6hm, A. W., Herrmann, G., and Pernul, G. (1999). \"A Language for Modeling Secure Business Transactions,\" Proceedings of the IEEE Annual Computer Security Applications Conference (ACSAC'99)."},{"key":"e_1_2_1_155_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(96)88964-4"},{"key":"e_1_2_1_156_1","doi-asserted-by":"publisher","DOI":"10.1145\/266741.266752"},{"key":"e_1_2_1_157_1","doi-asserted-by":"publisher","DOI":"10.1145\/42282.42286"},{"key":"e_1_2_1_158_1","volume-title":"The Typed Access Matrix Model,\" Proceedings of the 1992 IEEE Symposium on Research in Security and Privacy","author":"Sandhu R. S.","year":"1992","unstructured":"Sandhu , R. S. ( 1992 ). \" The Typed Access Matrix Model,\" Proceedings of the 1992 IEEE Symposium on Research in Security and Privacy . Sandhu, R. S. (1992). \"The Typed Access Matrix Model,\" Proceedings of the 1992 IEEE Symposium on Research in Security and Privacy."},{"key":"e_1_2_1_159_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.241422"},{"key":"e_1_2_1_160_1","doi-asserted-by":"publisher","DOI":"10.1145\/234313.234412"},{"key":"e_1_2_1_161_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.485845"},{"key":"e_1_2_1_162_1","volume-title":"Role-Based Access Control,\" Advances in Computers","author":"Sandhu R.","year":"1998","unstructured":"Sandhu , R. ( 1998 ). \" Role-Based Access Control,\" Advances in Computers , Vol. 46 , Academic Press . Sandhu, R. (1998). \"Role-Based Access Control,\" Advances in Computers, Vol. 46, Academic Press."},{"key":"e_1_2_1_163_1","doi-asserted-by":"publisher","DOI":"10.1145\/356789.356793"},{"key":"e_1_2_1_164_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.4445"},{"key":"e_1_2_1_165_1","doi-asserted-by":"publisher","DOI":"10.1108\/09685220010371394"},{"key":"e_1_2_1_166_1","volume-title":"On the Role of Human Morality in Information System Security: The Problems of Descriptivism and Non-descriptive Foundations,\" 15th International Information Security Conference (IFIP TC11\/SEC2000)","author":"Siponen M. T.","year":"2000","unstructured":"Siponen , M. T. ( 2000 b). \" On the Role of Human Morality in Information System Security: The Problems of Descriptivism and Non-descriptive Foundations,\" 15th International Information Security Conference (IFIP TC11\/SEC2000) , Beijing, China . Siponen, M. T. (2000b). \"On the Role of Human Morality in Information System Security: The Problems of Descriptivism and Non-descriptive Foundations,\" 15th International Information Security Conference (IFIP TC11\/SEC2000), Beijing, China."},{"key":"e_1_2_1_167_1","volume-title":"Policies for Construction of Information Systems' Security Guidelines: Five Approaches,\" 15th International Information Security Conference (IFIP TC11\/SEC2000)","author":"Siponen M. T.","year":"2000","unstructured":"Siponen , M. T. ( 2000 c). \" Policies for Construction of Information Systems' Security Guidelines: Five Approaches,\" 15th International Information Security Conference (IFIP TC11\/SEC2000) , Beijing, China . Siponen, M. T. (2000c). \"Policies for Construction of Information Systems' Security Guidelines: Five Approaches,\" 15th International Information Security Conference (IFIP TC11\/SEC2000), Beijing, China."},{"key":"e_1_2_1_168_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(95)96991-B"},{"key":"e_1_2_1_169_1","first-page":"73","volume-title":"Computer Viruses,\" in Denning","author":"Spafford E. G.","year":"1998","unstructured":"Spafford , E. G. ( 1998 ). \" Computer Viruses,\" in Denning , D. E., and Denning, P. J. (Eds.), Internet Besieged : Countering Cyberspace Scofflaws , New York : ACM Press , pp. 73 -- 95 . Spafford, E. G. (1998). \"Computer Viruses,\" in Denning, D. E., and Denning, P. J. (Eds.), Internet Besieged: Countering Cyberspace Scofflaws, New York: ACM Press, pp. 73--95."},{"key":"e_1_2_1_170_1","volume-title":"Competing Against Human Failing,\" 15th IFIP World Computer Congress. 'The Global Information Society on the Way to the Next Millennium'. SEC","author":"Spruit M.E.M.","year":"1998","unstructured":"Spruit , M.E.M. ( 1998 ). \" Competing Against Human Failing,\" 15th IFIP World Computer Congress. 'The Global Information Society on the Way to the Next Millennium'. SEC , TC11 , Vienna . Spruit, M.E.M. (1998). \"Competing Against Human Failing,\" 15th IFIP World Computer Congress. 'The Global Information Society on the Way to the Next Millennium'. SEC, TC11, Vienna."},{"key":"e_1_2_1_171_1","volume-title":"Promoting Security Awareness and Commitment,\" Information Management and Computer Security","author":"Spurling P.","year":"1995","unstructured":"Spurling , P. ( 1995 ). \" Promoting Security Awareness and Commitment,\" Information Management and Computer Security , Vol. 3 No. 2. Spurling, P. (1995). \"Promoting Security Awareness and Commitment,\" Information Management and Computer Security, Vol. 3 No. 2."},{"key":"e_1_2_1_172_1","volume-title":"The Model,\" v2.0","year":"1999","unstructured":"SSE-CMM ( 1999 a). \" The Model,\" v2.0 . http:\/\/www.sse-cmm.org. SSE-CMM (1999a). \"The Model,\" v2.0. http:\/\/www.sse-cmm.org."},{"key":"e_1_2_1_173_1","volume-title":"The Appraisal Method,\" v2.0","year":"1999","unstructured":"SSE-CMM ( 1999 b). \" The Appraisal Method,\" v2.0 . http:\/\/www.sse-cmm.org. SSE-CMM (1999b). \"The Appraisal Method,\" v2.0. http:\/\/www.sse-cmm.org."},{"issue":"3","key":"e_1_2_1_174_1","first-page":"50","article-title":"Identifying Information Security Threats","volume":"5","author":"Stacey T. R.","year":"1996","unstructured":"Stacey , T. R. , Helsley , R. E. , and Baston , J. V. ( 1996 ). \" Identifying Information Security Threats ,\" Information Systems Security , Vol. 5 , No. 3 , pp. 50 -- 59 . Stacey, T. R., Helsley, R. E., and Baston, J. V. (1996). \"Identifying Information Security Threats,\" Information Systems Security, Vol. 5, No. 3, pp. 50--59.","journal-title":"Information Systems Security"},{"key":"e_1_2_1_175_1","first-page":"387","volume-title":"Handbook of Information Security Management","author":"Stackpole B.","year":"1999","unstructured":"Stackpole , B. ( 1999 ). \" An Introduction to IPSEC,\" in Krause, M., and Tipton, H.F. (Eds.) , Handbook of Information Security Management , Auerbach , pp. 387 -- 399 . Stackpole, B. (1999). \"An Introduction to IPSEC,\" in Krause, M., and Tipton, H.F. (Eds.), Handbook of Information Security Management, Auerbach, pp. 387--399."},{"key":"e_1_2_1_176_1","volume-title":"An Evaluation of the Java Security Model,\" 12th Annual Computer Security Applications Conference","author":"Sterbenz A.","year":"1996","unstructured":"Sterbenz , A. ( 1996 ). \" An Evaluation of the Java Security Model,\" 12th Annual Computer Security Applications Conference . Sterbenz, A. (1996). \"An Evaluation of the Java Security Model,\" 12th Annual Computer Security Applications Conference."},{"key":"e_1_2_1_177_1","first-page":"219","volume-title":"On the Buzzword 'Security Policy',\" Proceedings of the IEEE Computer Society Symposium on Research in Security and Privacy","author":"Sterne D. F.","year":"1991","unstructured":"Sterne , D. F. ( 1991 ). \" On the Buzzword 'Security Policy',\" Proceedings of the IEEE Computer Society Symposium on Research in Security and Privacy , Los Alamitos, CA : IEEE Society Press , pp. 219 -- 230 . Sterne, D. F. (1991). \"On the Buzzword 'Security Policy',\" Proceedings of the IEEE Computer Society Symposium on Research in Security and Privacy, Los Alamitos, CA: IEEE Society Press, pp. 219--230."},{"key":"e_1_2_1_178_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1.3.255"},{"key":"e_1_2_1_179_1","doi-asserted-by":"publisher","DOI":"10.2307\/249551"},{"key":"e_1_2_1_180_1","volume-title":"The Validity of Security Risk Assessment,\" Proceedings of 30th Annual International Carnahan Conference on Security Technology","author":"Tarr C. J.","year":"1996","unstructured":"Tarr , C. J. and Kinsman , P . ( 1996 ). \" The Validity of Security Risk Assessment,\" Proceedings of 30th Annual International Carnahan Conference on Security Technology . Tarr, C. J. and Kinsman, P. (1996). \"The Validity of Security Risk Assessment,\" Proceedings of 30th Annual International Carnahan Conference on Security Technology."},{"key":"e_1_2_1_181_1","volume-title":"Conceptual Foundations for a Model of Task-based Authorizations,\" Proceedings of the 7th IEEE Computer Security Foundations Workshop","author":"Thomas R. K.","year":"1994","unstructured":"Thomas , R. K. and Sandhu . R. S. ( 1994 ). \" Conceptual Foundations for a Model of Task-based Authorizations,\" Proceedings of the 7th IEEE Computer Security Foundations Workshop , Franconia, NH . Thomas, R. K. and Sandhu. R. S. (1994). \"Conceptual Foundations for a Model of Task-based Authorizations,\" Proceedings of the 7th IEEE Computer Security Foundations Workshop, Franconia, NH."},{"key":"e_1_2_1_182_1","doi-asserted-by":"publisher","DOI":"10.1108\/09685229810227649"},{"key":"e_1_2_1_183_1","volume-title":"Proceedings of the Sixth IEEE Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises.","author":"Valia R.","year":"1997","unstructured":"Valia , R. and Al-Salqan , Y . ( 1997 ). Proceedings of the Sixth IEEE Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises. Valia, R. and Al-Salqan, Y. (1997). Proceedings of the Sixth IEEE Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises."},{"key":"e_1_2_1_184_1","volume-title":"An Approach for Mobile Agent Security and Fault Tolerance Using Distributed Transactions,\" Proceedings of the 1997 International Conference on Parallel and Distributed Systems","author":"Vogler H.","year":"1997","unstructured":"Vogler , H. , Kunkelmann , T. , and Moschgath , M.L . ( 1997 ). \" An Approach for Mobile Agent Security and Fault Tolerance Using Distributed Transactions,\" Proceedings of the 1997 International Conference on Parallel and Distributed Systems , IEEE Computer Society Press . Vogler, H., Kunkelmann, T., and Moschgath, M.L. (1997). \"An Approach for Mobile Agent Security and Fault Tolerance Using Distributed Transactions,\" Proceedings of the 1997 International Conference on Parallel and Distributed Systems, IEEE Computer Society Press."},{"key":"e_1_2_1_185_1","doi-asserted-by":"publisher","DOI":"10.1109\/38.736465"},{"key":"e_1_2_1_186_1","first-page":"800","article-title":"Keeping Your Site Comfortably Secure: An Introduction to Internet Firewalls","author":"Wack J. P.","year":"1995","unstructured":"Wack , J. P. and Carnahan , L. J. ( 1995 ). \" Keeping Your Site Comfortably Secure: An Introduction to Internet Firewalls ,\" NIST Special Publication 800 - 810 . Wack, J. P. and Carnahan, L. J. (1995). \"Keeping Your Site Comfortably Secure: An Introduction to Internet Firewalls,\" NIST Special Publication 800-10.","journal-title":"NIST Special Publication"},{"key":"e_1_2_1_187_1","doi-asserted-by":"publisher","DOI":"10.1145\/263814.263897"},{"key":"e_1_2_1_188_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.108052"},{"key":"e_1_2_1_189_1","doi-asserted-by":"publisher","DOI":"10.1016\/0306-4379(79)90017-6"},{"key":"e_1_2_1_190_1","volume-title":"Computer Security: A Comprehensive Controls Checklist","author":"Wood C. C.","year":"1987","unstructured":"Wood , C. C. , Banks , W. W. , Guarro , S. B. , Garcia , A. A. , Hampel , V. E. , and Sartorio , H. P . ( 1987 ). Computer Security: A Comprehensive Controls Checklist , Hoboken, NJ : John Wiley & Sons . Wood, C. C., Banks, W. W., Guarro, S. B., Garcia, A. A., Hampel, V. E., and Sartorio, H. P. (1987). Computer Security: A Comprehensive Controls Checklist, Hoboken, NJ: John Wiley & Sons."},{"key":"e_1_2_1_191_1","volume-title":"A Policy for Sending Secret Information Over Communications Networks,\" Information Management & Computer Security","author":"Wood C. C.","year":"1996","unstructured":"Wood , C. C. ( 1996 ). \" A Policy for Sending Secret Information Over Communications Networks,\" Information Management & Computer Security , Vol. 4 , No. 3. Wood, C. C. (1996). \"A Policy for Sending Secret Information Over Communications Networks,\" Information Management & Computer Security, Vol. 4, No. 3."},{"key":"e_1_2_1_192_1","doi-asserted-by":"publisher","DOI":"10.1109\/38.736467"},{"key":"e_1_2_1_193_1","volume-title":"Role-Based Security for Distributed Object Systems,\" Proceedings of the 5th Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE'96)","author":"Yialelis N.","year":"1996","unstructured":"Yialelis , N. , Lupu , E. , and Sloman , M . ( 1996 ). \" Role-Based Security for Distributed Object Systems,\" Proceedings of the 5th Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE'96) . Yialelis, N., Lupu, E., and Sloman, M. (1996). \"Role-Based Security for Distributed Object Systems,\" Proceedings of the 5th Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE'96)."},{"key":"e_1_2_1_194_1","volume-title":"Current Solutions, and a Proposed Approach,\" Proceedings of the 1997 IEEE International Conference on Intelligent Processing Systems (ICIPS'97).","author":"Zeng L.","year":"1997","unstructured":"Zeng , L. , Wamg , H. , Lee , M.K.O. ( 1997 ). \" Multiple Intelligent Agent Supported Internet Security System: Issues , Current Solutions, and a Proposed Approach,\" Proceedings of the 1997 IEEE International Conference on Intelligent Processing Systems (ICIPS'97). Zeng, L., Wamg, H., Lee, M.K.O. (1997). \"Multiple Intelligent Agent Supported Internet Security System: Issues, Current Solutions, and a Proposed Approach,\" Proceedings of the 1997 IEEE International Conference on Intelligent Processing Systems (ICIPS'97)."},{"key":"e_1_2_1_195_1","volume-title":"Security in the Large: Is Java's Sandbox Scalable?\" Proceedings of the Seventeenth IEEE Symposium on Reliable Distributed Systems","author":"Zhong Q.","year":"1998","unstructured":"Zhong , Q. and Edwards , N . ( 1998 ). \" Security in the Large: Is Java's Sandbox Scalable?\" Proceedings of the Seventeenth IEEE Symposium on Reliable Distributed Systems . Zhong, Q. and Edwards, N. (1998). \"Security in the Large: Is Java's Sandbox Scalable?\" Proceedings of the Seventeenth IEEE Symposium on Reliable Distributed Systems."},{"key":"e_1_2_1_196_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.587552"},{"key":"e_1_2_1_197_1","volume-title":"User Authentication by Cognitive Passwords: An Empirical Assessment,\" Proceedings of the 5th Jerusalem Conference on Information Tech-nology","author":"Zviran M.","year":"1990","unstructured":"Zviran , M. and Haga , W. J . ( 1990 ). \" User Authentication by Cognitive Passwords: An Empirical Assessment,\" Proceedings of the 5th Jerusalem Conference on Information Tech-nology , 1990. 'Next Decade in Information Technology', IEEE Society Press . Zviran, M. and Haga, W. J. (1990). \"User Authentication by Cognitive Passwords: An Empirical Assessment,\" Proceedings of the 5th Jerusalem Conference on Information Tech-nology, 1990. 'Next Decade in Information Technology', IEEE Society Press."},{"key":"e_1_2_1_198_1","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/36.3.227"}],"container-title":["ACM SIGMIS Database: the DATABASE for Advances in Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1216218.1216224","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1216218.1216224","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T20:22:16Z","timestamp":1750278136000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1216218.1216224"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2007,2,28]]},"references-count":198,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2007,2,28]]}},"alternative-id":["10.1145\/1216218.1216224"],"URL":"https:\/\/doi.org\/10.1145\/1216218.1216224","relation":{},"ISSN":["0095-0033","1532-0936"],"issn-type":[{"value":"0095-0033","type":"print"},{"value":"1532-0936","type":"electronic"}],"subject":[],"published":{"date-parts":[[2007,2,28]]},"assertion":[{"value":"2007-02-28","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}