{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,30]],"date-time":"2025-08-30T16:53:16Z","timestamp":1756572796598,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":54,"publisher":"ACM","license":[{"start":{"date-parts":[[2014,9,9]],"date-time":"2014-09-09T00:00:00Z","timestamp":1410220800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2014,9,9]]},"DOI":"10.1145\/2659651.2659711","type":"proceedings-article","created":{"date-parts":[[2014,12,16]],"date-time":"2014-12-16T13:41:52Z","timestamp":1418737312000},"page":"77-84","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":17,"title":["Compliance with standards, assurance and audit"],"prefix":"10.1145","author":[{"given":"Bob","family":"Duncan","sequence":"first","affiliation":[{"name":"Computing Science, University of Aberdeen"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mark","family":"Whittington","sequence":"additional","affiliation":[{"name":"Accountancy and Finance, University of Aberdeen"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2014,9,9]]},"reference":[{"volume-title":"House of Lords Select Committee","year":"2013","author":"Affairs H. o. L. S. C. o. E.","key":"e_1_3_2_1_1_1"},{"key":"e_1_3_2_1_2_1","unstructured":"R. Alexander R. Hawkins and T. Kelly. Security Assurance Cases: Motivation and the State of the Art. www-users.cs.york.ac.uk pages 1--19 2011.  R. Alexander R. Hawkins and T. Kelly. Security Assurance Cases: Motivation and the State of the Art. www-users.cs.york.ac.uk pages 1--19 2011."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.2308\/aud.2002.21.1.125"},{"key":"e_1_3_2_1_4_1","unstructured":"O. Alliance. Open Data Center Alliance Usage: Carbon Footprint Values. Tech reprt 2011.  O. Alliance. Open Data Center Alliance Usage: Carbon Footprint Values. Tech reprt 2011."},{"key":"e_1_3_2_1_5_1","unstructured":"O. D. C. Alliance. Open Data Center Alliance Usage: Input\/Output (IO) Controls. Tech reprt 2011.  O. D. C. Alliance. Open Data Center Alliance Usage: Input\/Output (IO) Controls. Tech reprt 2011."},{"key":"e_1_3_2_1_6_1","unstructured":"O. D. C. Alliance. Open Data Center Alliance Usage: Security Monitoring. pages 1--9 2011.  O. D. C. Alliance. Open Data Center Alliance Usage: Security Monitoring. pages 1--9 2011."},{"key":"e_1_3_2_1_7_1","unstructured":"O. D. C. Alliance. Open Data Center Alliance Usage: Service Catalog. pages 1--16 2011.  O. D. C. Alliance. Open Data Center Alliance Usage: Service Catalog. pages 1--16 2011."},{"key":"e_1_3_2_1_8_1","unstructured":"O. D. C. Alliance. Open Data Center Alliance Usage: Virtual Machine (VM) Interoperability. (Vm):1--10 2011.  O. D. C. Alliance. Open Data Center Alliance Usage: Virtual Machine (VM) Interoperability. (Vm):1--10 2011."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.2308\/acch.2008.22.4.375"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10550-007-0015-7"},{"key":"e_1_3_2_1_11_1","first-page":"1","volume-title":"WEIS","author":"Beautement A.","year":"2010"},{"key":"e_1_3_2_1_12_1","first-page":"1","volume-title":"Framework","author":"Beres Y.","year":"2008"},{"key":"e_1_3_2_1_13_1","unstructured":"BIAC and ICO. An International Business Commentary on the 2002 OECD Guidelines for the Security of Networks and Information Systems: Towards a Culture of Security. pages 1--24 2003.  BIAC and ICO. An International Business Commentary on the 2002 OECD Guidelines for the Security of Networks and Information Systems: Towards a Culture of Security. pages 1--24 2003."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.2308\/ciia-50741"},{"key":"e_1_3_2_1_15_1","unstructured":"BSI. The BS5750 Quality Management Standard 2014.  BSI. The BS5750 Quality Management Standard 2014."},{"volume-title":"HMG","year":"1992","author":"Cadbury A.","key":"e_1_3_2_1_16_1"},{"volume-title":"Cisco","year":"2010","key":"e_1_3_2_1_17_1"},{"volume-title":"Cisco","year":"2013","key":"e_1_3_2_1_18_1"},{"key":"e_1_3_2_1_19_1","unstructured":"COBIT. Executive Summary Framework. 2007.  COBIT. Executive Summary Framework. 2007."},{"issue":"4","key":"e_1_3_2_1_20_1","first-page":"573","volume":"19","author":"Cohen J.","year":"2002","journal-title":"Corporate Governance and the Audit Process. Contemp. Account. Res."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.4108\/ICST.SIMUTOOLS2010.8631"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1017\/S0960129509990077"},{"volume-title":"PCI Security Standards Council","year":"2013","author":"P. S. S. Council","key":"e_1_3_2_1_23_1"},{"key":"e_1_3_2_1_24_1","unstructured":"CSA. Security Guidance for Critical Areas of Focus in Cloud. Tech reprt Cloud Security Alliance 2012.  CSA. Security Guidance for Critical Areas of Focus in Cloud. Tech reprt Cloud Security Alliance 2012."},{"key":"e_1_3_2_1_25_1","unstructured":"CSO. Cloud Standards 2013.  CSO. Cloud Standards 2013."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CloudCom.2013.144"},{"key":"e_1_3_2_1_27_1","unstructured":"ENISA. A Security Analysis of Next Generation Web Standards 2013.  ENISA. A Security Analysis of Next Generation Web Standards 2013."},{"key":"e_1_3_2_1_28_1","unstructured":"FedRamp. FedRamp 2014.  FedRamp. FedRamp 2014."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"crossref","unstructured":"K. Goertzel T. Winograd H. McKinley L. Oh M. Colon T. McGibbon E. Fedchak and R. Vienneau. Software Security Assurance: A State-of-Art Report (SAR). pages 1--396 2007.  K. Goertzel T. Winograd H. McKinley L. Oh M. Colon T. McGibbon E. Fedchak and R. Vienneau. Software Security Assurance: A State-of-Art Report (SAR). pages 1--396 2007.","DOI":"10.21236\/ADA472363"},{"volume-title":"Washington DC","year":"2013","author":"House W.","key":"e_1_3_2_1_30_1"},{"key":"e_1_3_2_1_31_1","unstructured":"I. G. Institute. Framework Control Objectives Management Guidelines Maturity Models. 2007.  I. G. Institute. Framework Control Objectives Management Guidelines Maturity Models. 2007."},{"key":"e_1_3_2_1_32_1","unstructured":"ISACA. An Introduction to the Business Model for Information Security. Technical report 2009.  ISACA. An Introduction to the Business Model for Information Security. Technical report 2009."},{"key":"e_1_3_2_1_33_1","first-page":"4","article-title":"Planning for and Implementing ISO 27001","author":"ISACA","year":"2011","journal-title":"ISACA J."},{"key":"e_1_3_2_1_34_1","unstructured":"IsecT. Information security compliance. (March):1--10 2011.  IsecT. Information security compliance. (March):1--10 2011."},{"key":"e_1_3_2_1_35_1","unstructured":"ISO.org. ISO\/IEC 27000:2009 - Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary. Tech reprt ISO.org Geneva Switzerland 2009.  ISO.org. ISO\/IEC 27000:2009 - Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary. Tech reprt ISO.org Geneva Switzerland 2009."},{"key":"e_1_3_2_1_36_1","unstructured":"Kaspersky. Threat Evolution Reprt for 2010 2010.  Kaspersky. Threat Evolution Reprt for 2010 2010."},{"key":"e_1_3_2_1_37_1","unstructured":"J. Mcgovern J. Payne and C. Watson. Software Assurance Maturity Model - Version1.0. pages 1--96 2009.  J. Mcgovern J. Payne and C. Watson. Software Assurance Maturity Model - Version1.0. pages 1--96 2009."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jbusres.2007.02.004"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1002\/jcaf.20021"},{"volume-title":"Addison-Wesley","year":"1995","author":"Neumann P. G.","key":"e_1_3_2_1_40_1"},{"volume-title":"NIST","year":"2012","author":"NIST.","key":"e_1_3_2_1_41_1"},{"key":"e_1_3_2_1_42_1","unstructured":"OED. Oxford English Dictionary 2014.  OED. Oxford English Dictionary 2014."},{"volume-title":"Wiley","year":"1998","author":"Parker D. B.","key":"e_1_3_2_1_43_1"},{"key":"e_1_3_2_1_44_1","first-page":"1","volume-title":"Proc. SPIE","author":"Pham N.","year":"2007"},{"volume-title":"PWC","year":"2010","author":"Information Security Breaches Survey PWC.","key":"e_1_3_2_1_45_1"},{"key":"e_1_3_2_1_47_1","first-page":"1","volume-title":"Res. Opp. Intern. Audit.","author":"Ramamoorti S.","year":"2003"},{"key":"e_1_3_2_1_48_1","first-page":"2002","author":"SOX","year":"2002","journal-title":"Sarbanes-Oxley Act of"},{"volume-title":"Tech Reprt Dec","year":"2010","key":"e_1_3_2_1_49_1"},{"key":"e_1_3_2_1_50_1","unstructured":"Trend. A Look Back at 2011. Tech reprt 2011.  Trend. A Look Back at 2011. Tech reprt 2011."},{"volume-title":"Trend Micro","year":"2012","key":"e_1_3_2_1_51_1"},{"key":"e_1_3_2_1_52_1","unstructured":"Trend and K. Wilhoit. Who's Really Attacking Your ICS Equipment? Tech reprt 2013.  Trend and K. Wilhoit. Who's Really Attacking Your ICS Equipment? Tech reprt 2013."},{"key":"e_1_3_2_1_53_1","unstructured":"Verizon. 2012 Data Breach Investigation Report: A study conducted by the Verizon RISK Team in cooperation with the United States Secret Service and Others. Tech reprt 2012.  Verizon. 2012 Data Breach Investigation Report: A study conducted by the Verizon RISK Team in cooperation with the United States Secret Service and Others. Tech reprt 2012."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/274348.274359"},{"volume-title":"Acct. Bus. Res.","year":"2007","author":"Zeff S. A.","key":"e_1_3_2_1_55_1"}],"event":{"name":"SIN '14: The 7th International Conference on Security of Information and Networks","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","MNIT Malaviya National Institute of Technology","Aksaray Univ. Aksaray University","SICSA The Scottish Informatics and Computer Science Alliance","University of Glasgow University of Glasgow"],"location":"Glasgow Scotland UK","acronym":"SIN '14"},"container-title":["Proceedings of the 7th International Conference on Security of Information and Networks"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2659651.2659711","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2659651.2659711","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T07:19:22Z","timestamp":1750231162000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2659651.2659711"}},"subtitle":["does this equal security?"],"short-title":[],"issued":{"date-parts":[[2014,9,9]]},"references-count":54,"alternative-id":["10.1145\/2659651.2659711","10.1145\/2659651"],"URL":"https:\/\/doi.org\/10.1145\/2659651.2659711","relation":{},"subject":[],"published":{"date-parts":[[2014,9,9]]},"assertion":[{"value":"2014-09-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}