{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T16:18:25Z","timestamp":1775837905712,"version":"3.50.1"},"reference-count":115,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2021,5,8]],"date-time":"2021-05-08T00:00:00Z","timestamp":1620432000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Higher Education Commission"},{"name":"National Center for Cyber Security for the affiliated lab National Cyber Security Auditing and Evaluation Lab","award":["2(1078)\/HEC\/ME\/2018\/707"],"award-info":[{"award-number":["2(1078)\/HEC\/ME\/2018\/707"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2022,4,30]]},"abstract":"<jats:p>Cyber threats have been growing tremendously in recent years. There are significant advancements in the threat space that have led towards an essential need for the strengthening of digital infrastructure security. Better security can be achieved by fine-tuning system parameters to the best and optimized security levels. For the protection of infrastructure and information systems, several guidelines have been provided by well-known organizations in the form of cybersecurity standards. Since security vulnerabilities incur a very high degree of financial, reputational, informational, and organizational security compromise, it is imperative that a baseline for standard compliance be established. The selection of security standards and extracting requirements from those standards in an organizational context is a tedious task. This article presents a detailed literature review, a comprehensive analysis of various cybersecurity standards, and statistics of cyber-attacks related to operating systems (OS). In addition to that, an explicit comparison between the frameworks, tools, and software available for OS compliance testing is provided. An in-depth analysis of the most common software solutions ensuring compliance with certain cybersecurity standards is also presented. Finally, based on the cybersecurity standards under consideration, a comprehensive set of minimum requirements is proposed for OS hardening and a few open research challenges are discussed.<\/jats:p>","DOI":"10.1145\/3442480","type":"journal-article","created":{"date-parts":[[2021,5,8]],"date-time":"2021-05-08T11:03:22Z","timestamp":1620471802000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":24,"title":["Cybersecurity Standards in the Context of Operating System"],"prefix":"10.1145","volume":"54","author":[{"given":"Syed Wasif Abbas","family":"Hamdani","sequence":"first","affiliation":[{"name":"National University of Sciences and Technology, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haider","family":"Abbas","sequence":"additional","affiliation":[{"name":"SENIOR MEMBER IEEE, National University of Sciences and Technology, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Abdul Rehman","family":"Janjua","sequence":"additional","affiliation":[{"name":"National University of Sciences and Technology, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Waleed Bin","family":"Shahid","sequence":"additional","affiliation":[{"name":"National University of Sciences and Technology, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muhammad Faisal","family":"Amjad","sequence":"additional","affiliation":[{"name":"SENIOR MEMBER IEEE, National University of Sciences and Technology, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jahanzaib","family":"Malik","sequence":"additional","affiliation":[{"name":"National University of Sciences and Technology, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Malik Hamza","family":"Murtaza","sequence":"additional","affiliation":[{"name":"National University of Sciences and Technology, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammed","family":"Atiquzzaman","sequence":"additional","affiliation":[{"name":"SENIOR MEMBER IEEE, The University of Oklahoma, Norman, OK, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Abdul Waheed","family":"Khan","sequence":"additional","affiliation":[{"name":"National University of Computer and Emerging Sciences, Haripur-KPK, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,5,8]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Cards.","author":"Jr Tom Huddleston","year":"2014","unstructured":"Tom Huddleston Jr . Staples: Breach May Have Affected 1.16 Million Customers \u2019 Cards. 2014 . Retrieved from https:\/\/fortune.com\/2014\/12\/19\/staples-cards-affected-breach\/. Tom Huddleston Jr. Staples: Breach May Have Affected 1.16 Million Customers\u2019 Cards. 2014. Retrieved from https:\/\/fortune.com\/2014\/12\/19\/staples-cards-affected-breach\/."},{"key":"e_1_2_1_2_1","article-title":"Importance of cyber security","volume":"111","author":"Goutam Rajesh Kumar","year":"2015","unstructured":"Rajesh Kumar Goutam . 2015 . Importance of cyber security . Int. J. Comput. Applic. 111 , 7 (2015). Rajesh Kumar Goutam. 2015. Importance of cyber security. Int. J. Comput. Applic. 111, 7 (2015).","journal-title":"Int. J. Comput. Applic."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3057729"},{"key":"e_1_2_1_4_1","unstructured":"Jason Andress. 2014. The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice. Syngress.  Jason Andress. 2014. The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice. Syngress."},{"key":"e_1_2_1_5_1","volume-title":"The Parkerian hexad: The CIA expanded. \u017di\u016br\u0117ta 5","author":"Pender-Bey Georgie","year":"2016","unstructured":"Georgie Pender-Bey . 2016. The Parkerian hexad: The CIA expanded. \u017di\u016br\u0117ta 5 ( 2016 ), 15. Georgie Pender-Bey. 2016. The Parkerian hexad: The CIA expanded. \u017di\u016br\u0117ta 5 (2016), 15."},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the 2nd IEEE PES International Conference and Exhibition on Innovative Smart Grid Technologies. IEEE, 1--7.","author":"Yang Y.","unstructured":"Y. Yang , Tim Littler , Sakir Sezer , Kieran McLaughlin , and H. F. Wang . 2011. Impact of cyber-security issues on smart grid . In Proceedings of the 2nd IEEE PES International Conference and Exhibition on Innovative Smart Grid Technologies. IEEE, 1--7. Y. Yang, Tim Littler, Sakir Sezer, Kieran McLaughlin, and H. F. Wang. 2011. Impact of cyber-security issues on smart grid. In Proceedings of the 2nd IEEE PES International Conference and Exhibition on Innovative Smart Grid Technologies. IEEE, 1--7."},{"key":"e_1_2_1_7_1","volume-title":"Optimising Australia\u2019s Response to the Cyber Challenge","author":"Blackburn John","unstructured":"John Blackburn and Gary Waters . 2011. Optimising Australia\u2019s Response to the Cyber Challenge . Kokoda Foundation . John Blackburn and Gary Waters. 2011. Optimising Australia\u2019s Response to the Cyber Challenge. Kokoda Foundation."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1093\/itnow\/bws003"},{"key":"e_1_2_1_9_1","volume-title":"Microsoft Security Compliance Manager (SCM)","year":"2013","unstructured":"Microsoft. Microsoft Security Compliance Manager (SCM) . 2013 . Microsoft. Microsoft Security Compliance Manager (SCM). 2013."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom.2015.402"},{"key":"e_1_2_1_11_1","volume-title":"Murphy and JoAnne Yates","author":"Craig","year":"2009","unstructured":"Craig N. Murphy and JoAnne Yates . 2009 . The International Organization for Standardization (ISO): Global Governance through Voluntary Consensus. Routledge . Craig N. Murphy and JoAnne Yates. 2009. The International Organization for Standardization (ISO): Global Governance through Voluntary Consensus. Routledge."},{"key":"e_1_2_1_12_1","volume-title":"Definition of Cloud Computing--US Department of Commerce. Special Publication 800, 145","author":"Mell Peter","year":"2011","unstructured":"Peter Mell and Tim Grance . 2011. Definition of Cloud Computing--US Department of Commerce. Special Publication 800, 145 ( 2011 ). NIST, National Institute of Standards and Technology . Peter Mell and Tim Grance. 2011. Definition of Cloud Computing--US Department of Commerce. Special Publication 800, 145 (2011). NIST, National Institute of Standards and Technology."},{"key":"e_1_2_1_13_1","unstructured":"CIS. Center for Internet Security(CIS). 2000. Retrieved from https:\/\/www.cisecurity.org\/.  CIS. Center for Internet Security(CIS). 2000. Retrieved from https:\/\/www.cisecurity.org\/."},{"key":"e_1_2_1_14_1","volume-title":"Information Technology-Information Security\u2014Information Assurance (ISACA)","author":"ISACA.","year":"1994","unstructured":"ISACA. Information Technology-Information Security\u2014Information Assurance (ISACA) . 1994 . Retrieved from https:\/\/www.isaca.org\/pages\/default.aspx. ISACA. Information Technology-Information Security\u2014Information Assurance (ISACA). 1994. Retrieved from https:\/\/www.isaca.org\/pages\/default.aspx."},{"key":"e_1_2_1_15_1","volume-title":"Information Systems Audit, and Control Association","author":"ISACA","year":"2011","unstructured":"ISACA , Information Systems Audit, and Control Association . 2011 . IT Control Objectives for Cloud Computing: Controls and Assurance in the Cloud. ISACA. ISACA, Information Systems Audit, and Control Association. 2011. IT Control Objectives for Cloud Computing: Controls and Assurance in the Cloud. ISACA."},{"key":"e_1_2_1_16_1","unstructured":"ISF. Information Security Forum (ISF). 1989. Retrieved from https:\/\/www.securityforum.org\/.  ISF. Information Security Forum (ISF). 1989. Retrieved from https:\/\/www.securityforum.org\/."},{"key":"e_1_2_1_17_1","unstructured":"ITU. International Telecommunication Union (ITU). 1865. Retrieved from https:\/\/www.itu.int\/en\/Pages\/default.aspx.  ITU. International Telecommunication Union (ITU). 1865. Retrieved from https:\/\/www.itu.int\/en\/Pages\/default.aspx."},{"key":"e_1_2_1_18_1","unstructured":"M.-O. Beau. 2010. lnternational Telecommunication Union.  M.-O. Beau. 2010. lnternational Telecommunication Union."},{"key":"e_1_2_1_19_1","unstructured":"ETSI. The European Telecommunications Standards Institute (ETSI). 1988. Retrieved from https:\/\/www.etsi.org\/.  ETSI. The European Telecommunications Standards Institute (ETSI). 1988. Retrieved from https:\/\/www.etsi.org\/."},{"key":"e_1_2_1_20_1","volume-title":"Charted by the American National Standards Institute","year":"1979","unstructured":"X12. X12 , Charted by the American National Standards Institute . 1979 . Retrieved from http:\/\/www.x12.org\/. X12. X12, Charted by the American National Standards Institute. 1979. Retrieved from http:\/\/www.x12.org\/."},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1080\/00987913.1992.10764102"},{"key":"e_1_2_1_22_1","unstructured":"ITIL. Information Technology Infrastructure Library (ITIL) Guide. 2003. Retrieved from https:\/\/www.ibm.com\/cloud\/learn\/it-infrastructure-library.  ITIL. Information Technology Infrastructure Library (ITIL) Guide. 2003. Retrieved from https:\/\/www.ibm.com\/cloud\/learn\/it-infrastructure-library."},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the 4th National Conference. 25--26","author":"Dabade T. D.","year":"2012","unstructured":"T. D. Dabade . 2012 . Information technology infrastructure library (ITIL) . In Proceedings of the 4th National Conference. 25--26 . T. D. Dabade. 2012. Information technology infrastructure library (ITIL). In Proceedings of the 4th National Conference. 25--26."},{"key":"e_1_2_1_24_1","unstructured":"IEEE. Institute of Electrical and Electronics Engineers (IEEE). 1963. Retrieved from https:\/\/www.ieee.org\/.  IEEE. Institute of Electrical and Electronics Engineers (IEEE). 1963. Retrieved from https:\/\/www.ieee.org\/."},{"key":"e_1_2_1_25_1","volume-title":"Institute of Electrical and Electronics Engineers","author":"PROPOSED AMENDMENTS TO.","year":"2007","unstructured":"PROPOSED AMENDMENTS TO. 2007. Institute of Electrical and Electronics Engineers ( IEEE) . ( 2007 ). PROPOSED AMENDMENTS TO. 2007. Institute of Electrical and Electronics Engineers (IEEE). (2007)."},{"key":"e_1_2_1_26_1","volume-title":"Download Data Security and Credit Card Security Standards.","author":"PCI Security Standards Council","year":"2006","unstructured":"PCI Security Standards Council . Official PCI Security Standards Council Site - Verify PCI Compliance , Download Data Security and Credit Card Security Standards. 2006 . Retrieved from https:\/\/www.pcisecuritystandards.org\/. PCI Security Standards Council. Official PCI Security Standards Council Site - Verify PCI Compliance, Download Data Security and Credit Card Security Standards. 2006. Retrieved from https:\/\/www.pcisecuritystandards.org\/."},{"key":"e_1_2_1_27_1","unstructured":"IETF. Internet Engineering Task Force (IETF). 1986. Retrieved from https:\/\/www.ietf.org\/.  IETF. Internet Engineering Task Force (IETF). 1986. Retrieved from https:\/\/www.ietf.org\/."},{"key":"e_1_2_1_29_1","volume-title":"Open Web Application Security Project (OWASP)","author":"Foundation OWASP","year":"2004","unstructured":"OWASP Foundation . Open Web Application Security Project (OWASP) . 2004 . Retrieved from https:\/\/www.owasp.org\/index.php\/Main_Page. OWASP Foundation. Open Web Application Security Project (OWASP). 2004. Retrieved from https:\/\/www.owasp.org\/index.php\/Main_Page."},{"key":"e_1_2_1_30_1","unstructured":"ILTA. International Legal Technology Association (ILTA). 1980. Retrieved from https:\/\/www.iltanet.org\/home?ssopc&equals;1.  ILTA. International Legal Technology Association (ILTA). 1980. Retrieved from https:\/\/www.iltanet.org\/home?ssopc&equals;1."},{"key":"e_1_2_1_31_1","volume-title":"New CC Portal","author":"Common Criteria CC.","year":"1994","unstructured":"CC. Common Criteria : New CC Portal . 1994 . Retrieved from https:\/\/www.commoncriteriaportal.org\/. CC. Common Criteria: New CC Portal. 1994. Retrieved from https:\/\/www.commoncriteriaportal.org\/."},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13753-011-0002-y"},{"key":"e_1_2_1_33_1","volume-title":"Advancing Open Standards for the Information Socitey (OASIS)","author":"OASIS-Group","year":"1993","unstructured":"OASIS-Group . Advancing Open Standards for the Information Socitey (OASIS) . 1993 . Retrieved from https:\/\/www.oasis-open.org\/. OASIS-Group. Advancing Open Standards for the Information Socitey (OASIS). 1993. Retrieved from https:\/\/www.oasis-open.org\/."},{"key":"e_1_2_1_34_1","unstructured":"Abbie Barbir and OASIS Diplomat. 2015. Organization for the Advancement of Structured Information Standards (OASIS). https:\/\/www.itu.int\/dms_pub\/itu-t\/oth\/15\/07\/T15070000060001PDFE.pdf.  Abbie Barbir and OASIS Diplomat. 2015. Organization for the Advancement of Structured Information Standards (OASIS). https:\/\/www.itu.int\/dms_pub\/itu-t\/oth\/15\/07\/T15070000060001PDFE.pdf."},{"key":"e_1_2_1_35_1","volume-title":"Proceedings of the 9th IEEE-GCC Conference and Exhibition (GCCCE\u201917)","author":"Aysha","unstructured":"Aysha K. Alharam and Wael El-Madany. 2017. The effects of cyber-security on healthcare industry . In Proceedings of the 9th IEEE-GCC Conference and Exhibition (GCCCE\u201917) . IEEE, 1--9. Aysha K. Alharam and Wael El-Madany. 2017. The effects of cyber-security on healthcare industry. In Proceedings of the 9th IEEE-GCC Conference and Exhibition (GCCCE\u201917). IEEE, 1--9."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2020.03.004"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/TITB.2011.2154363"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1177\/1932296816676281"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2018.1700364"},{"key":"e_1_2_1_40_1","unstructured":"FFIEC-IT Handbook. 2016. Retrieved from https:\/\/www.ffiec.gov\/.  FFIEC-IT Handbook. 2016. Retrieved from https:\/\/www.ffiec.gov\/."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSCloud.2016.46"},{"key":"e_1_2_1_42_1","first-page":"935","article-title":"Cybersecurity, data breaches, and the economic loss doctrine in the payment card industry","volume":"75","author":"Opderbeck David W.","year":"2015","unstructured":"David W. Opderbeck . 2015 . Cybersecurity, data breaches, and the economic loss doctrine in the payment card industry . Md. L. Rev. 75 (2015), 935 . David W. Opderbeck. 2015. Cybersecurity, data breaches, and the economic loss doctrine in the payment card industry. Md. L. Rev. 75 (2015), 935.","journal-title":"Md. L. Rev."},{"key":"e_1_2_1_43_1","unstructured":"The Cybersecurity Regulations Healthcare Financial Services and Retail Industries Must Know About. ([n. d.]). Retrieved from https:\/\/www.csoonline.com\/article\/3298962\/the-cybersecurity-regulations-healthcare-financial-services-and-retail-industries-must-know-about.html.  The Cybersecurity Regulations Healthcare Financial Services and Retail Industries Must Know About. ([n. d.]). Retrieved from https:\/\/www.csoonline.com\/article\/3298962\/the-cybersecurity-regulations-healthcare-financial-services-and-retail-industries-must-know-about.html."},{"key":"e_1_2_1_44_1","volume-title":"Payment Card Industry Data Security Standards (PCI DSS)","author":"Chorney Rhonda","unstructured":"Rhonda Chorney . 2016. Payment Card Industry Data Security Standards (PCI DSS) . University of Manitoba . https:\/\/www.umanitoba.ca\/admin\/financial_services\/media\/PCI_DSS_Compliance_FinalNov_01_-_PDF.pdf. Rhonda Chorney. 2016. Payment Card Industry Data Security Standards (PCI DSS). University of Manitoba. https:\/\/www.umanitoba.ca\/admin\/financial_services\/media\/PCI_DSS_Compliance_FinalNov_01_-_PDF.pdf."},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/TENCONSpring.2016.7519379"},{"key":"e_1_2_1_46_1","volume-title":"Cybersecurity in the energy sector: A comparative analysis between Europe and the United States. \u00c9tudes de l'Ifri","author":"Barichella A.","year":"2018","unstructured":"A. Barichella . 2018. Cybersecurity in the energy sector: A comparative analysis between Europe and the United States. \u00c9tudes de l'Ifri . 2018 . A. Barichella. 2018. Cybersecurity in the energy sector: A comparative analysis between Europe and the United States. \u00c9tudes de l'Ifri. 2018."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/TEM.2018.2798408"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2016.2627399"},{"key":"e_1_2_1_49_1","article-title":"Cyber security for the defence industry. Cyber","author":"Sharma Sanjana","year":"2017","unstructured":"Sanjana Sharma . 2017 . Cyber security for the defence industry. Cyber Sec. Rev.. Retrieved from http:\/\/www.cybersecurity-review.com\/industry-perspective\/cybersecurity-for-the-defence-industry. Sanjana Sharma. 2017. Cyber security for the defence industry. Cyber Sec. Rev.. Retrieved from http:\/\/www.cybersecurity-review.com\/industry-perspective\/cybersecurity-for-the-defence-industry.","journal-title":"Sec. Rev.. Retrieved from http:\/\/www.cybersecurity-review.com\/industry-perspective\/cybersecurity-for-the-defence-industry."},{"key":"e_1_2_1_50_1","unstructured":"B. J. Murrill E. C. Liu and R. M. Thompson. 2012. Smart meter data: Privacy and cybersecurity. Congressional Research Service. CRS Report for Congress. https:\/\/ipmall.law.unh.edu\/sites\/default\/files\/hosted_resources\/crs\/R42338_120203.pdf.  B. J. Murrill E. C. Liu and R. M. Thompson. 2012. Smart meter data: Privacy and cybersecurity. Congressional Research Service. CRS Report for Congress. https:\/\/ipmall.law.unh.edu\/sites\/default\/files\/hosted_resources\/crs\/R42338_120203.pdf."},{"key":"e_1_2_1_51_1","volume-title":"Risks Report","author":"Forum World Economic","year":"2018","unstructured":"World Economic Forum . 2018. The Global Risks Report 2018 . Technical Report. Retrieved from http:\/\/www3.weforum.org\/docs\/WEF. World Economic Forum. 2018. The Global Risks Report 2018. Technical Report. Retrieved from http:\/\/www3.weforum.org\/docs\/WEF."},{"key":"e_1_2_1_52_1","volume-title":"Latest information | Data theft | British Airways","author":"Airways British","year":"2018","unstructured":"British Airways , Latest information | Data theft | British Airways . 2018 . Retrieved from https:\/\/www.britishairways.com\/en-gb\/information\/incident\/data-theft\/latest-information. British Airways, Latest information | Data theft | British Airways. 2018. Retrieved from https:\/\/www.britishairways.com\/en-gb\/information\/incident\/data-theft\/latest-information."},{"key":"e_1_2_1_53_1","volume-title":"MyFitnessPal Security Information FAQ","year":"2018","unstructured":"MyFitnessPal , MyFitnessPal Security Information FAQ . 2018 . Retrieved from https:\/\/content.myfitnesspal.com\/security-information\/FAQ.html. MyFitnessPal, MyFitnessPal Security Information FAQ. 2018. Retrieved from https:\/\/content.myfitnesspal.com\/security-information\/FAQ.html."},{"key":"e_1_2_1_54_1","volume-title":"Ticketfly cyber incident information","author":"Ticketfly","year":"2018","unstructured":"Ticketfly , Ticketfly cyber incident information . 2018 . Retrieved from https:\/\/support.ticketfly.com\/s\/article\/41507. Ticketfly, Ticketfly cyber incident information. 2018. Retrieved from https:\/\/support.ticketfly.com\/s\/article\/41507."},{"key":"e_1_2_1_55_1","volume-title":"MyHeritage Statement About a Cybersecurity Incident - MyHeritage Blog","year":"2018","unstructured":"MyHeritage , MyHeritage Statement About a Cybersecurity Incident - MyHeritage Blog . 2018 . Retrieved from https:\/\/blog.myheritage.com\/2018\/06\/myheritage-statement-about-a-cybersecurity-incident\/. MyHeritage, MyHeritage Statement About a Cybersecurity Incident - MyHeritage Blog. 2018. Retrieved from https:\/\/blog.myheritage.com\/2018\/06\/myheritage-statement-about-a-cybersecurity-incident\/."},{"key":"e_1_2_1_56_1","volume-title":"Cybercrime Report","author":"Morgan Steve","year":"2015","unstructured":"Steve Morgan . 2017. Cyber security Ventures , Cybercrime Report , Herjavec Group . Retrieved from https:\/\/cybersecurityventures.com\/ 2015 -wp\/wp-content\/uploads\/2017\/10\/2017-Cybercrime-Report.pdf. Steve Morgan. 2017. Cyber security Ventures, Cybercrime Report, Herjavec Group. Retrieved from https:\/\/cybersecurityventures.com\/2015-wp\/wp-content\/uploads\/2017\/10\/2017-Cybercrime-Report.pdf."},{"key":"e_1_2_1_57_1","volume-title":"The state of industrial Cybersecurity","author":"Levine B. Kaspersky","year":"2017","unstructured":"B. Kaspersky Levine . 2017. The state of industrial Cybersecurity 2017 . ScientistJune (2017), 38--42. Retrieved from https:\/\/go.kaspersky.com\/rs\/802-IJN-240\/images\/ICSWHITEPAPER.pdf. B. Kaspersky Levine. 2017. The state of industrial Cybersecurity 2017. ScientistJune (2017), 38--42. Retrieved from https:\/\/go.kaspersky.com\/rs\/802-IJN-240\/images\/ICSWHITEPAPER.pdf."},{"key":"e_1_2_1_58_1","unstructured":"O. H. Alhazmi Y. K. Malaiya and I. Ray. 2004. Vulnerabilities in Major Operating Systems. Colorado State University. Technical Report.  O. H. Alhazmi Y. K. Malaiya and I. Ray. 2004. Vulnerabilities in Major Operating Systems. Colorado State University. Technical Report."},{"key":"e_1_2_1_59_1","volume-title":"1--13","author":"Test AV","year":"2018","unstructured":"AV Test . 2018. AV- Test 2017-18. ( 2018 ), 1--13 . AV Test. 2018. AV-Test 2017-18. (2018), 1--13."},{"key":"e_1_2_1_61_1","unstructured":"CVE MITRE Corporation. 2008. Microsoft Windows 95: CVE Security Vulnerabilities Versions and Detailed Reports. Retrieved from https:\/\/www.cvedetails.com\/product\/112\/Microsoft-Windows-95.html?vendor.  CVE MITRE Corporation. 2008. Microsoft Windows 95: CVE Security Vulnerabilities Versions and Detailed Reports. Retrieved from https:\/\/www.cvedetails.com\/product\/112\/Microsoft-Windows-95.html?vendor."},{"key":"e_1_2_1_62_1","volume-title":"Cybersecurity is Broken: Here\u2019s How We Start to Fix it | ZDNet","author":"Interactive Net CBS","year":"2019","unstructured":"ZD Net CBS Interactive . Cybersecurity is Broken: Here\u2019s How We Start to Fix it | ZDNet . 2019 . Retrieved from https:\/\/www.zdnet.com\/article\/cybersecurity-is-broken-heres-how-we-start-to-fix-it\/. ZDNet CBS Interactive. Cybersecurity is Broken: Here\u2019s How We Start to Fix it | ZDNet. 2019. Retrieved from https:\/\/www.zdnet.com\/article\/cybersecurity-is-broken-heres-how-we-start-to-fix-it\/."},{"key":"e_1_2_1_63_1","unstructured":"The SSL Store. 70% of US Employees Don\u2019t Know Privacy and Security Best Practices. 2017. Retrieved from https:\/\/www.thesslstore.com\/blog\/report-70-us-employees-lack-strong-knowledge-privacy-security-best-practices\/.  The SSL Store. 70% of US Employees Don\u2019t Know Privacy and Security Best Practices. 2017. Retrieved from https:\/\/www.thesslstore.com\/blog\/report-70-us-employees-lack-strong-knowledge-privacy-security-best-practices\/."},{"key":"e_1_2_1_64_1","volume-title":"Heel of FT 500 Companies | ImmuniWeb Security Blog.","year":"2018","unstructured":"ImmuniWeb. Abandoned Web Applications: Achilles \u2019 Heel of FT 500 Companies | ImmuniWeb Security Blog. 2018 . Retrieved from https:\/\/www.immuniweb.com\/blog\/FT500-application-security.html. ImmuniWeb. Abandoned Web Applications: Achilles\u2019 Heel of FT 500 Companies | ImmuniWeb Security Blog. 2018. Retrieved from https:\/\/www.immuniweb.com\/blog\/FT500-application-security.html."},{"key":"e_1_2_1_65_1","unstructured":"Verizon.2018. Payment security compliance drops for the first time in six years. https:\/\/www.bloomberg.com\/press-releases\/2018-09-25\/payment-security-compliance-drops-for-the-first-time-in-six-years-states-verizons-2018-payment-security-report.  Verizon.2018. Payment security compliance drops for the first time in six years. https:\/\/www.bloomberg.com\/press-releases\/2018-09-25\/payment-security-compliance-drops-for-the-first-time-in-six-years-states-verizons-2018-payment-security-report."},{"key":"e_1_2_1_66_1","volume-title":"Why No HTTPS? The World\u2019s Most Popular Websites Loaded Insecurely","author":"Hunt Troy","year":"2020","unstructured":"Troy Hunt . Why No HTTPS? The World\u2019s Most Popular Websites Loaded Insecurely . 2020 . Retrieved from https:\/\/whynohttps.com\/. Troy Hunt. Why No HTTPS? The World\u2019s Most Popular Websites Loaded Insecurely. 2020. Retrieved from https:\/\/whynohttps.com\/."},{"key":"e_1_2_1_67_1","volume-title":"But It May Not Protect Them from Data Breaches - TechRepublic","author":"Password Rules Companies Have","year":"2017","unstructured":"TechRepublic. 93% of Companies Have Password Rules , But It May Not Protect Them from Data Breaches - TechRepublic . 2017 . Retrieved from https:\/\/www.techrepublic.com\/article\/93-of-companies-have-password-rules-but-it-may-not-protect-them-from-data-breaches\/. TechRepublic. 93% of Companies Have Password Rules, But It May Not Protect Them from Data Breaches - TechRepublic. 2017. Retrieved from https:\/\/www.techrepublic.com\/article\/93-of-companies-have-password-rules-but-it-may-not-protect-them-from-data-breaches\/."},{"key":"e_1_2_1_68_1","unstructured":"BulletProof. 2019. Bulletproof annual cyber security report. https:\/\/www.bulletproof.co.uk\/industryreports\/2019.pdf.  BulletProof. 2019. Bulletproof annual cyber security report. https:\/\/www.bulletproof.co.uk\/industryreports\/2019.pdf."},{"key":"e_1_2_1_69_1","unstructured":"Cisco. 2018. Cyber security and insurance.. Retrieved from https:\/\/www.cisco.com\/c\/en\/us\/solutions\/security\/cyber-insurance\/index.html.  Cisco. 2018. Cyber security and insurance.. Retrieved from https:\/\/www.cisco.com\/c\/en\/us\/solutions\/security\/cyber-insurance\/index.html."},{"key":"e_1_2_1_70_1","volume-title":"Small Business Disaster Recovery Survey Results","year":"2017","unstructured":"NationWide. Small Business Disaster Recovery Survey Results . 2017 . Retrieved from https:\/\/blog.nationwide.com\/news\/disaster-recovery-plan-study-results\/. NationWide. Small Business Disaster Recovery Survey Results. 2017. Retrieved from https:\/\/blog.nationwide.com\/news\/disaster-recovery-plan-study-results\/."},{"key":"e_1_2_1_71_1","unstructured":"Ncipher and P. Institute. 2018. Global encryption trends study. https:\/\/go.ncipher.com\/rs\/104-QOX-775\/images\/2018-nCipher-Ponemon-Global-Encryption-Trends-Study-es.pdf.  Ncipher and P. Institute. 2018. Global encryption trends study. https:\/\/go.ncipher.com\/rs\/104-QOX-775\/images\/2018-nCipher-Ponemon-Global-Encryption-Trends-Study-es.pdf."},{"key":"e_1_2_1_72_1","unstructured":"B. U. States. 2018. Bdo cyber governance survey. Retrieved from https:\/\/www.bdo.com\/insights\/assurance\/corporate-governance\/2018-bdo-cyber-governance-survey-board-perspecti.  B. U. States. 2018. Bdo cyber governance survey. Retrieved from https:\/\/www.bdo.com\/insights\/assurance\/corporate-governance\/2018-bdo-cyber-governance-survey-board-perspecti."},{"key":"e_1_2_1_73_1","volume-title":"Cybersecurity Market Worth Over $300bn by 2024: Global Market Insights","author":"Newswire PR","year":"2019","unstructured":"PR Newswire . Cybersecurity Market Worth Over $300bn by 2024: Global Market Insights , Inc. 2019 . Retrieved from https:\/\/www.prnewswire.com\/news-releases\/cybersecurity-market-worth-over-300bn-by-2024-global-market-insights-inc--863930577.html. PR Newswire. Cybersecurity Market Worth Over $300bn by 2024: Global Market Insights, Inc. 2019. Retrieved from https:\/\/www.prnewswire.com\/news-releases\/cybersecurity-market-worth-over-300bn-by-2024-global-market-insights-inc--863930577.html."},{"key":"e_1_2_1_74_1","volume-title":"\u201cWeb of Profit","author":"Store The SSL","year":"2018","unstructured":"The SSL Store . 2018 Cybercrime Statistics: A Closer Look at the \u201cWeb of Profit .\u201d 2018 . Retrieved from https:\/\/www.thesslstore.com\/blog\/2018-cybercrime-statistics\/. The SSL Store. 2018 Cybercrime Statistics: A Closer Look at the \u201cWeb of Profit.\u201d 2018. Retrieved from https:\/\/www.thesslstore.com\/blog\/2018-cybercrime-statistics\/."},{"key":"e_1_2_1_75_1","unstructured":"HIMSS North America. 2016. 2016 HIMSS cybersecurity survey. Retrieved from http:\/\/www.himss.org\/library\/2016-himss-cybersecurity-survey.  HIMSS North America. 2016. 2016 HIMSS cybersecurity survey. Retrieved from http:\/\/www.himss.org\/library\/2016-himss-cybersecurity-survey."},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom.2015.402"},{"key":"e_1_2_1_77_1","volume-title":"Proceedings of the 17th IEEE\/ACM International Symposium on Cluster, Cloud and Grid Computing (CCGRID\u201917)","author":"Giulio Carlo Di","unstructured":"Carlo Di Giulio , Read Sprabery , Charles Kamhoua , Kevin Kwiat , Roy Campbell , and Masooda N. Bashir . 2017. IT security and privacy standards in comparison: Improving FedRAMP authorization for cloud service providers . In Proceedings of the 17th IEEE\/ACM International Symposium on Cluster, Cloud and Grid Computing (CCGRID\u201917) . IEEE, 1090--1099. Carlo Di Giulio, Read Sprabery, Charles Kamhoua, Kevin Kwiat, Roy Campbell, and Masooda N. Bashir. 2017. IT security and privacy standards in comparison: Improving FedRAMP authorization for cloud service providers. In Proceedings of the 17th IEEE\/ACM International Symposium on Cluster, Cloud and Grid Computing (CCGRID\u201917). IEEE, 1090--1099."},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1145\/2659651.2659711"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCSI.2017.41"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2011.05.005"},{"key":"e_1_2_1_81_1","volume-title":"Control Objectives for Information and Related Technology","author":"COBIT.","year":"2019","unstructured":"COBIT. Control Objectives for Information and Related Technology . 2019 . Retrieved from http:\/\/www.isaca.org. COBIT. Control Objectives for Information and Related Technology. 2019. Retrieved from http:\/\/www.isaca.org."},{"key":"e_1_2_1_82_1","volume-title":"Proceedings of the International Conference on Evaluation of Novel Approaches to Software Engineering. Springer, 61--73","author":"Pardo C\u00e9sar","year":"2010","unstructured":"C\u00e9sar Pardo , Francisco J. Pino , F\u00e9lix Garc\u00eda , Mario Piattini Velthius , and Maria Teresa Baldassarre . 2010 . Trends in harmonization of multiple reference models . In Proceedings of the International Conference on Evaluation of Novel Approaches to Software Engineering. Springer, 61--73 . C\u00e9sar Pardo, Francisco J. Pino, F\u00e9lix Garc\u00eda, Mario Piattini Velthius, and Maria Teresa Baldassarre. 2010. Trends in harmonization of multiple reference models. In Proceedings of the International Conference on Evaluation of Novel Approaches to Software Engineering. Springer, 61--73."},{"key":"e_1_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2006.04.002"},{"key":"e_1_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2015.03.001"},{"key":"e_1_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.5555\/3375069.3375097"},{"key":"e_1_2_1_86_1","first-page":"305","article-title":"Toward a global cybersecurity standard of care: Exploring the implications of the 2014 NIST cybersecurity framework on shaping reasonable national and international cybersecurity practices","volume":"50","author":"Shackelford Scott J.","year":"2015","unstructured":"Scott J. Shackelford , Andrew A. Proia , Brenton Martell , and Amanda N. Craig . 2015 . Toward a global cybersecurity standard of care: Exploring the implications of the 2014 NIST cybersecurity framework on shaping reasonable national and international cybersecurity practices . Texas Int. Law J. 50 (2015), 305 . Scott J. Shackelford, Andrew A. Proia, Brenton Martell, and Amanda N. Craig. 2015. Toward a global cybersecurity standard of care: Exploring the implications of the 2014 NIST cybersecurity framework on shaping reasonable national and international cybersecurity practices. Texas Int. Law J. 50 (2015), 305.","journal-title":"Texas Int. Law J."},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1109\/PES.2010.5590215"},{"key":"e_1_2_1_88_1","first-page":"280","article-title":"Technical security metrics model in compliance with ISO\/IEC 27001 standard","volume":"1","author":"Azuwa M.","year":"2012","unstructured":"M. Azuwa , Rabiah Ahmad , Shahrin Sahib , and Solahuddin Shamsuddin . 2012 . Technical security metrics model in compliance with ISO\/IEC 27001 standard . Int. J. Cyber-Sec. Dig. Forens. 1 , 4 (2012), 280 -- 288 . M. Azuwa, Rabiah Ahmad, Shahrin Sahib, and Solahuddin Shamsuddin. 2012. Technical security metrics model in compliance with ISO\/IEC 27001 standard. Int. J. Cyber-Sec. Dig. Forens. 1, 4 (2012), 280--288.","journal-title":"Int. J. Cyber-Sec. Dig. Forens."},{"key":"e_1_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1108\/09685220710817806"},{"key":"e_1_2_1_90_1","volume-title":"Information security maturity model for nist cyber security framework. Comput. Sci. Inf. Technol. 51","author":"Almuhammadi Sultan","year":"2017","unstructured":"Sultan Almuhammadi and Majeed Alsaleh . 2017. Information security maturity model for nist cyber security framework. Comput. Sci. Inf. Technol. 51 ( 2017 ). Sultan Almuhammadi and Majeed Alsaleh. 2017. Information security maturity model for nist cyber security framework. Comput. Sci. Inf. Technol. 51 (2017)."},{"key":"e_1_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2010.03.007"},{"key":"e_1_2_1_92_1","first-page":"280","article-title":"Technical security metrics model in compliance with ISO\/IEC 27001 standard","volume":"1","author":"Azuwa M","year":"2012","unstructured":"M Azuwa , Rabiah Ahmad , Shahrin Sahib , and Solahuddin Shamsuddin . 2012 . Technical security metrics model in compliance with ISO\/IEC 27001 standard . Int. J. Cyber-Sec. Dig. Forens. 1 , 4 (2012), 280 -- 288 . M Azuwa, Rabiah Ahmad, Shahrin Sahib, and Solahuddin Shamsuddin. 2012. Technical security metrics model in compliance with ISO\/IEC 27001 standard. Int. J. Cyber-Sec. Dig. Forens. 1, 4 (2012), 280--288.","journal-title":"Int. J. Cyber-Sec. Dig. Forens."},{"key":"e_1_2_1_93_1","volume-title":"National Institute of Standards and Technology | NIST","author":"National Institute of Standards and Technology.","year":"2019","unstructured":"National Institute of Standards and Technology. National Institute of Standards and Technology | NIST . 2019 . Retrieved from https:\/\/www.nist.gov\/. National Institute of Standards and Technology. National Institute of Standards and Technology | NIST. 2019. Retrieved from https:\/\/www.nist.gov\/."},{"key":"e_1_2_1_94_1","unstructured":"NIST. Federal Information Processing Standards Publications (FIPS PUBS) | NIST. 2015. Retrieved from https:\/\/www.nist.gov\/topics\/federal-information-standards-fips.  NIST. Federal Information Processing Standards Publications (FIPS PUBS) | NIST. 2015. Retrieved from https:\/\/www.nist.gov\/topics\/federal-information-standards-fips."},{"key":"e_1_2_1_95_1","volume-title":"ISO\u2014International Organization for Standardization","author":"International Organization for Standardization.","year":"1947","unstructured":"International Organization for Standardization. ISO\u2014International Organization for Standardization . 1947 . Retrieved from https:\/\/www.iso.org\/home.html. International Organization for Standardization. ISO\u2014International Organization for Standardization. 1947. Retrieved from https:\/\/www.iso.org\/home.html."},{"key":"e_1_2_1_96_1","volume-title":"Welcome to the IEC - International Electrotechnical Commission","author":"and Commission","year":"1904","unstructured":"International, Electrotechnical, and Commission . Welcome to the IEC - International Electrotechnical Commission . 1904 . Retrieved from https:\/\/www.iec.ch\/. International, Electrotechnical, and Commission. Welcome to the IEC - International Electrotechnical Commission. 1904. Retrieved from https:\/\/www.iec.ch\/."},{"key":"e_1_2_1_97_1","volume-title":"Implementing the ISO\/IEC 27001: 2013 ISMS Standard","author":"Humphreys Edward","unstructured":"Edward Humphreys . 2016. Implementing the ISO\/IEC 27001: 2013 ISMS Standard . Artech House . Edward Humphreys. 2016. Implementing the ISO\/IEC 27001: 2013 ISMS Standard. Artech House."},{"key":"e_1_2_1_98_1","volume-title":"New CC Portal","author":"Criteria Common","year":"2017","unstructured":"Common Criteria . Common Criteria : New CC Portal . 2017 . Retrieved from https:\/\/www.commoncriteriaportal.org\/. Common Criteria. Common Criteria : New CC Portal. 2017. Retrieved from https:\/\/www.commoncriteriaportal.org\/."},{"key":"e_1_2_1_99_1","unstructured":"Acuity. Store | Acuity Risk Management. 2018. Retrieved from https:\/\/acuityrm.com\/store\/Personal-Editions.  Acuity. Store | Acuity Risk Management. 2018. Retrieved from https:\/\/acuityrm.com\/store\/Personal-Editions."},{"key":"e_1_2_1_100_1","unstructured":"Vigilant Software. VsRisk. 2019. Retrieved from https:\/\/www.vigilantsoftware.co.uk\/topic\/free-trial.  Vigilant Software. VsRisk. 2019. Retrieved from https:\/\/www.vigilantsoftware.co.uk\/topic\/free-trial."},{"key":"e_1_2_1_101_1","volume-title":"Download Microsoft Baseline Security Analyzer 2.1.1 (for IT Professionals) from Official Microsoft Download Center","year":"2015","unstructured":"Microsoft. Download Microsoft Baseline Security Analyzer 2.1.1 (for IT Professionals) from Official Microsoft Download Center . 2015 . Retrieved from https:\/\/www.microsoft.com\/en-pk\/download\/details.aspx?id&equals;19892. Microsoft. Download Microsoft Baseline Security Analyzer 2.1.1 (for IT Professionals) from Official Microsoft Download Center. 2015. Retrieved from https:\/\/www.microsoft.com\/en-pk\/download\/details.aspx?id&equals;19892."},{"key":"e_1_2_1_102_1","volume-title":"Download Microsoft Security Assessment Tool 4.0 from Official Microsoft Download Center","author":"Microsoft","year":"2009","unstructured":"Microsoft (MS). Download Microsoft Security Assessment Tool 4.0 from Official Microsoft Download Center . 2009 . Retrieved from https:\/\/systemscenter.ru\/scm.en\/. Microsoft (MS). Download Microsoft Security Assessment Tool 4.0 from Official Microsoft Download Center. 2009. Retrieved from https:\/\/systemscenter.ru\/scm.en\/."},{"key":"e_1_2_1_103_1","volume-title":"Products: Belarc Advisor","year":"2010","unstructured":"Belarc. Products: Belarc Advisor . 2010 . Retrieved from https:\/\/www.belarc.com\/products. Belarc. Products: Belarc Advisor. 2010. Retrieved from https:\/\/www.belarc.com\/products."},{"key":"e_1_2_1_104_1","volume-title":"Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with Compliance Testing (HIPAA\/ISO27001\/PCI DSS) and System Hardening. Agentless, and Installation Optional","author":"Boelen Michael","year":"2013","unstructured":"Michael Boelen . GitHub - CISOfy\/lynis : Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with Compliance Testing (HIPAA\/ISO27001\/PCI DSS) and System Hardening. Agentless, and Installation Optional . 2013 . Retrieved from https:\/\/github.com\/CISOfy\/lynis. Michael Boelen. GitHub - CISOfy\/lynis: Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with Compliance Testing (HIPAA\/ISO27001\/PCI DSS) and System Hardening. Agentless, and Installation Optional. 2013. Retrieved from https:\/\/github.com\/CISOfy\/lynis."},{"key":"e_1_2_1_105_1","unstructured":"OpenSCAP Download | OpenSCAP portal. 2014. Retrieved from http:\/\/www.open-scap.org\/download\/.  OpenSCAP Download | OpenSCAP portal. 2014. Retrieved from http:\/\/www.open-scap.org\/download\/."},{"key":"e_1_2_1_106_1","volume-title":"Tiger - the unix security audit and intrusion detection tool","author":"Fern\u00e1ndez-Sanguino J.","year":"2010","unstructured":"J. Fern\u00e1ndez-Sanguino , Tiger - the unix security audit and intrusion detection tool . 2010 . Retrieved from https:\/\/www.nongnu.org\/tiger\/index.html{#}download. J. Fern\u00e1ndez-Sanguino, Tiger - the unix security audit and intrusion detection tool. 2010. Retrieved from https:\/\/www.nongnu.org\/tiger\/index.html{#}download."},{"key":"e_1_2_1_107_1","volume-title":"CIS Configuration Assessment Tool CIS-CAT","author":"Center for Internet Security.","year":"2015","unstructured":"Center for Internet Security. CIS Configuration Assessment Tool CIS-CAT . 2015 . Retrieved from https:\/\/learn.cisecurity.org\/cis-cat-lite. Center for Internet Security. CIS Configuration Assessment Tool CIS-CAT. 2015. Retrieved from https:\/\/learn.cisecurity.org\/cis-cat-lite."},{"key":"e_1_2_1_108_1","first-page":"1","article-title":"NIST cloud computing reference architecture","volume":"500","author":"Liu Fang","year":"2011","unstructured":"Fang Liu , Jin Tong , Jian Mao , Robert Bohn , John Messina , Lee Badger , and Dawn Leaf . 2011 . NIST cloud computing reference architecture . NIST Special Publication 500 , 2011 (2011), 1 -- 28 . Fang Liu, Jin Tong, Jian Mao, Robert Bohn, John Messina, Lee Badger, and Dawn Leaf. 2011. NIST cloud computing reference architecture. NIST Special Publication 500, 2011 (2011), 1--28.","journal-title":"NIST Special Publication"},{"key":"e_1_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1109\/CPRE.2011.6035634"},{"key":"e_1_2_1_110_1","first-page":"16","article-title":"The NIST cybersecurity framework: Overview and potential impacts","volume":"10","author":"Shen Lei","year":"2014","unstructured":"Lei Shen . 2014 . The NIST cybersecurity framework: Overview and potential impacts . Scitech Lawyer 10 , 4 (2014), 16 . Lei Shen. 2014. The NIST cybersecurity framework: Overview and potential impacts. Scitech Lawyer 10, 4 (2014), 16.","journal-title":"Scitech Lawyer"},{"key":"e_1_2_1_111_1","volume-title":"Using the Common Criteria for IT Security Evaluation","author":"Herrmann Debra S.","unstructured":"Debra S. Herrmann . 2002. Using the Common Criteria for IT Security Evaluation . Auerbach Publications . Debra S. Herrmann. 2002. Using the Common Criteria for IT Security Evaluation. Auerbach Publications."},{"key":"e_1_2_1_112_1","volume-title":"Eloff","author":"Kruger R.","year":"1997","unstructured":"R. Kruger and Jan H. P . Eloff . 1997 . A common criteria framework for the evaluation of information technology systems security. In Information Security in Research and Business. Springer , 197--209. R. Kruger and Jan H. P. Eloff. 1997. A common criteria framework for the evaluation of information technology systems security. In Information Security in Research and Business. Springer, 197--209."},{"key":"e_1_2_1_113_1","volume-title":"Proceedings of the 8th IADIS International Conference on Information Systems. IADIS Press, 161--168","author":"Brodin Martin","year":"2015","unstructured":"Martin Brodin . 2015 . Combining ISMS with strategic management: The case of BYOD . In Proceedings of the 8th IADIS International Conference on Information Systems. IADIS Press, 161--168 . Martin Brodin. 2015. Combining ISMS with strategic management: The case of BYOD. In Proceedings of the 8th IADIS International Conference on Information Systems. IADIS Press, 161--168."},{"key":"e_1_2_1_114_1","volume-title":"Proceedings of the International Conference on Challenges in Information Science 65","author":"Disson E.","year":"2017","unstructured":"E. Disson , G. Collard , S. Ducroquet , and G. Talens . 2017. A definition of information security classification in cybersecurity context . Proceedings of the International Conference on Challenges in Information Science 65 , 3 ( 2017 ), 77--82. E. Disson, G. Collard, S. Ducroquet, and G. Talens. 2017. A definition of information security classification in cybersecurity context. Proceedings of the International Conference on Challenges in Information Science 65, 3 (2017), 77--82."},{"key":"e_1_2_1_115_1","volume-title":"Encyclopedia of Cryptography and Security","author":"Caddy T.","unstructured":"T. Caddy . 2011. FIPS 140-2 . In Encyclopedia of Cryptography and Security ( 2 nd Ed.) Springer , 468--471. https:\/\/doi.org\/10.1007\/978-1-4419-5906-5_205 T. Caddy. 2011. FIPS 140-2. In Encyclopedia of Cryptography and Security (2nd Ed.) Springer, 468--471. https:\/\/doi.org\/10.1007\/978-1-4419-5906-5_205","edition":"2"},{"key":"e_1_2_1_116_1","first-page":"44","article-title":"Analisis aktivitas dan pola jaringan terhadap eternal blue dan wannacry ransomware","volume":"2","author":"Ferdiansyah Ferdiansyah","year":"2018","unstructured":"Ferdiansyah Ferdiansyah . 2018 . Analisis aktivitas dan pola jaringan terhadap eternal blue dan wannacry ransomware . JUSIFO (Jurnal Sistem Informasi) 2 , 1 (2018), 44 -- 59 . Ferdiansyah Ferdiansyah. 2018. Analisis aktivitas dan pola jaringan terhadap eternal blue dan wannacry ransomware. JUSIFO (Jurnal Sistem Informasi) 2, 1 (2018), 44--59.","journal-title":"JUSIFO (Jurnal Sistem Informasi)"},{"key":"e_1_2_1_117_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.67"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3442480","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3442480","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:24:36Z","timestamp":1750195476000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3442480"}},"subtitle":["Practical Aspects, Analysis, and Comparisons"],"short-title":[],"issued":{"date-parts":[[2021,5,8]]},"references-count":115,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2022,4,30]]}},"alternative-id":["10.1145\/3442480"],"URL":"https:\/\/doi.org\/10.1145\/3442480","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,5,8]]},"assertion":[{"value":"2020-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-05-08","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}