{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T01:46:46Z","timestamp":1784771206314,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":54,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,8,25]],"date-time":"2020-08-25T00:00:00Z","timestamp":1598313600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,8,25]]},"DOI":"10.1145\/3407023.3407059","type":"proceedings-article","created":{"date-parts":[[2020,7,30]],"date-time":"2020-07-30T16:32:52Z","timestamp":1596126772000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["SoK"],"prefix":"10.1145","author":[{"given":"Rainer","family":"Diesch","sequence":"first","affiliation":[{"name":"fortiss GmbH, Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Helmut","family":"Krcmar","sequence":"additional","affiliation":[{"name":"Technical University of Munich, Garching, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,8,25]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22351-9{_}15"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2013.03.011"},{"key":"e_1_3_2_1_3_1","volume-title":"Building a Practical Information Security Program","author":"Andress Jason"},{"key":"e_1_3_2_1_4_1","first-page":"280","article-title":"Technical Security Metrics Model in Compliance with ISO\/IEC 27001 Standard","volume":"1","author":"Azuwa M. P.","year":"2017","journal-title":"International Journal of Cyber-Security and Digital Forensics (IJCSDF)"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1984.5010301"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1002\/sys.21211"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.03.006"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1002\/9780470087923.hhs440"},{"key":"e_1_3_2_1_9_1","unstructured":"Jim Boehm Peter Merrath Thomas Poppensieker Rolf Riemenschnitter and Tobias St\u00e4hle. 2017. Cyber risk measurement and the holistic cybersecurity approach. https:\/\/www.mckinsey.com\/business-functions\/risk\/our-insights\/cyber-risk-measurement-and-the-holistic-cybersecurity-approach last checked: 30.09.2019.  Jim Boehm Peter Merrath Thomas Poppensieker Rolf Riemenschnitter and Tobias St\u00e4hle. 2017. Cyber risk measurement and the holistic cybersecurity approach. https:\/\/www.mckinsey.com\/business-functions\/risk\/our-insights\/cyber-risk-measurement-and-the-holistic-cybersecurity-approach last checked: 30.09.2019."},{"key":"e_1_3_2_1_10_1","volume-title":"Advances in Information and Computer Security","author":"B\u00f6hme Rainer"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89173-4{_}21"},{"key":"e_1_3_2_1_13_1","volume-title":"Information security management metrics: A definitive guide to effective security monitoring and measurement","author":"Brotby W. Krag"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2010.08.017"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/EAIT.2012.6408003"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/IAW.2005.1495978"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-32125-7_9"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF00988593"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5220\/0006545602070215"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101747"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3341496"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1080\/10658980601051482"},{"key":"e_1_3_2_1_23_1","volume-title":"Measuring and managing information risk: A FAIR approach. Butterworth-Heinemann","author":"Freund Jack"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1219053"},{"key":"e_1_3_2_1_25_1","volume-title":"36th International Convention on Information & Communication Technology, Electronics & Microelectronics. 1121--1126","author":"Hajdarevic Kemal","year":"2013"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jsis.2011.06.001"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCST.2005.1594818"},{"key":"e_1_3_2_1_28_1","unstructured":"ISO\/IEC. 2018. ISO\/IEC 27000:2018(E): Information technology - Security techniques - Information security management systems - Overview and vocabulary. Standard. ISO\/IEC Switzerland.  ISO\/IEC. 2018. ISO\/IEC 27000:2018(E): Information technology - Security techniques - Information security management systems - Overview and vocabulary. Standard. ISO\/IEC Switzerland."},{"key":"e_1_3_2_1_29_1","unstructured":"ISO\/IEC. 2018. ISO\/IEC 27004:2009(E) - Information technology - Security techniques - Information security management - Measurement. Standard. ISO\/IEC Switzerland.  ISO\/IEC. 2018. ISO\/IEC 27004:2009(E) - Information technology - Security techniques - Information security management - Measurement. Standard. ISO\/IEC Switzerland."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/Metrisec.2011.19"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/IDAACS.2013.6663004"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(97)80798-5"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2015.0607"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5220\/0006170901280139"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxu100"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1201\/1079.07366981\/46248.34.3.20060901\/94537.2"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3005714"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICICI-BME.2011.6108598"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.4018\/IJISCRAM.2017070103"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1201\/1086.1065898X\/46183.15.3.20060701\/94183.3"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2012.10"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2008.125"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.05.002"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSA.2011.6027518"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1108\/IMCS-05-2013-0041"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2015.11.009"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2011.6127465"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.11648\/j.ajomis.20190403.15"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1007\/11836810{_}38"},{"key":"e_1_3_2_1_51_1","volume-title":"Critical Success Factors Analysis on Effective Information Security Management: A Literature Review. In 20th Americas Conference on Information Systems. 1874--1886","author":"Tu Zhiling","year":"2014"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2003.1174904"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/1719030.1719036"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017160.2017162"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2016.04.001"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.15439\/2014F490"}],"event":{"name":"ARES 2020: The 15th International Conference on Availability, Reliability and Security","location":"Virtual Event Ireland","acronym":"ARES 2020"},"container-title":["Proceedings of the 15th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3407023.3407059","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3407023.3407059","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:24:42Z","timestamp":1750195482000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3407023.3407059"}},"subtitle":["linking information security metrics to management success factors"],"short-title":[],"issued":{"date-parts":[[2020,8,25]]},"references-count":54,"alternative-id":["10.1145\/3407023.3407059","10.1145\/3407023"],"URL":"https:\/\/doi.org\/10.1145\/3407023.3407059","relation":{},"subject":[],"published":{"date-parts":[[2020,8,25]]},"assertion":[{"value":"2020-08-25","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}