{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T02:34:40Z","timestamp":1784342080296,"version":"3.55.0"},"reference-count":57,"publisher":"Association for Computing Machinery (ACM)","issue":"CSCW2","license":[{"start":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T00:00:00Z","timestamp":1667779200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Hum.-Comput. Interact."],"published-print":{"date-parts":[[2022,11,7]]},"abstract":"<jats:p>Numerous security attacks that resulted in devastating consequences can be traced back to a delay in applying a security patch. Despite the criticality of timely patch application, not much is known about why and how delays occur when applying security patches in practice, and how the delays can be mitigated. Based on longitudinal data collected from 132 delayed patching tasks over a period of four years and observations of patch meetings involving eight teams from two organisations in the healthcare domain, and using quantitative and qualitative data analysis approaches, we identify a set of reasons relating to technology, people and organisation as key explanations that cause delays in patching. Our findings also reveal that the most prominent cause of delays is attributable to coordination delays in the patch management process and a majority of delays occur during the patch deployment phase. Towards mitigating the delays, we describe a set of strategies employed by the studied practitioners. This research serves as the first step toward understanding the practical reasons for delays and possible mitigation strategies in vulnerability patch management. Our findings provide useful insights for practitioners to understand what and where improvement is needed in the patch management process and guide them towards taking timely actions against potential attacks. Also, our findings help researchers to invest effort into designing and developing computer-supported tools to better support a timely security patch management process.<\/jats:p>","DOI":"10.1145\/3555087","type":"journal-article","created":{"date-parts":[[2022,11,11]],"date-time":"2022-11-11T22:58:54Z","timestamp":1668207534000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":19,"title":["Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare Sector"],"prefix":"10.1145","volume":"6","author":[{"given":"Nesara","family":"Dissanayake","sequence":"first","affiliation":[{"name":"The University of Adelaide, Adelaide, SA, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mansooreh","family":"Zahedi","sequence":"additional","affiliation":[{"name":"The University of Melbourne, Melbourne, VIC, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Asangi","family":"Jayatilaka","sequence":"additional","affiliation":[{"name":"The University of Adelaide, Adelaide, SA, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Muhammad Ali","family":"Babar","sequence":"additional","affiliation":[{"name":"The University of Adelaide, Adelaide, SA, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,11,11]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3417056"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1177\/1049732316654870"},{"key":"e_1_2_1_3_1","volume-title":"The Mythical Man-Month: Essays on Software Engineering. Adisson-Wesley","author":"Brooks Frederick P.","unstructured":"Frederick P. Brooks . 1975. The Mythical Man-Month: Essays on Software Engineering. Adisson-Wesley , London . Frederick P. Brooks. 1975. The Mythical Man-Month: Essays on Software Engineering. Adisson-Wesley, London."},{"key":"e_1_2_1_4_1","unstructured":"Huseyin Cavusoglu Hasan Cavusoglu and Jun Zhang. 2006. Economics of Security Patch Management. In WEIS. Citeseer 1--10.  Huseyin Cavusoglu Hasan Cavusoglu and Jun Zhang. 2006. Economics of Security Patch Management. In WEIS. Citeseer 1--10."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1070.0794"},{"key":"e_1_2_1_6_1","volume-title":"Constructing Grounded Theory: A Practical Guide through Qualitative Analysis","author":"Charmaz Kathy","unstructured":"Kathy Charmaz . 2006. Constructing Grounded Theory: A Practical Guide through Qualitative Analysis . Sage . Kathy Charmaz. 2006. Constructing Grounded Theory: A Practical Guide through Qualitative Analysis. Sage."},{"key":"e_1_2_1_7_1","volume-title":"Identifying Information Disclosure in Web Applications with Retroactive Auditing. In 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI 14)","author":"Chen Haogang","unstructured":"Haogang Chen , Taesoo Kim , Xi Wang , Nickolai Zeldovich , and M. Frans Kaashoek . 2014 . Identifying Information Disclosure in Web Applications with Retroactive Auditing. In 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI 14) . USENIX Association, 555--569. https:\/\/www.usenix.org\/conference\/osdi14\/technical-sessions\/presentation\/chen_haogang Haogang Chen, Taesoo Kim, Xi Wang, Nickolai Zeldovich, and M. Frans Kaashoek. 2014. Identifying Information Disclosure in Web Applications with Retroactive Auditing. In 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI 14). USENIX Association, 555--569. https:\/\/www.usenix.org\/conference\/osdi14\/technical-sessions\/presentation\/chen_haogang"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1323293.1294283"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.5555\/3214931.3214934"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243794"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2021.106771"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468595"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10445-9_18"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICAC.2004.1301353"},{"key":"e_1_2_1_15_1","volume-title":"Retrieved","author":"Eddy Melissa","year":"2020","unstructured":"Melissa Eddy and Nicole Perlroth . 2020 . Cyber Attack Suspected in German Woman's Death . Retrieved June 23, 2021 from https:\/\/www.nytimes.com\/2020\/09\/18\/world\/europe\/cyber-attack-germany-ransomeware-death.html'smid=tw-share Melissa Eddy and Nicole Perlroth. 2020. Cyber Attack Suspected in German Woman's Death. Retrieved June 23, 2021 from https:\/\/www.nytimes.com\/2020\/09\/18\/world\/europe\/cyber-attack-germany-ransomeware-death.html'smid=tw-share"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.87283"},{"key":"e_1_2_1_17_1","volume-title":"Theoretical Sensitivity: Advances in the Methodology of Grounded Theory","author":"Glaser Barney G.","year":"1978","unstructured":"Barney G. Glaser . 1978 . Theoretical Sensitivity: Advances in the Methodology of Grounded Theory . Sociology Press , Mill Valley, CA . Barney G. Glaser. 1978. Theoretical Sensitivity: Advances in the Methodology of Grounded Theory. Sociology Press, Mill Valley, CA."},{"key":"e_1_2_1_18_1","volume-title":"Strauss","author":"Glaser Barney G.","year":"1967","unstructured":"Barney G. Glaser and Anselmo L . Strauss . 1967 . The Discovery of Grounded Theory: Strategies for Qualitative Research. Aldine Transaction, Chicago . Barney G. Glaser and Anselmo L. Strauss. 1967. The Discovery of Grounded Theory: Strategies for Qualitative Research. Aldine Transaction, Chicago."},{"key":"e_1_2_1_19_1","volume-title":"Retrieved","author":"Goodin Dan","year":"2017","unstructured":"Dan Goodin . 2017 . Failure to patch two-month-old bug led to massive Equifax breach . Retrieved June 23, 2021 from https:\/\/arstechnica.com\/information-technology\/2017\/09\/massive-equifax-breach-caused-by-failure-to-patch-two-month-old-bug\/ Dan Goodin. 2017. Failure to patch two-month-old bug led to massive Equifax breach. Retrieved June 23, 2021 from https:\/\/arstechnica.com\/information-technology\/2017\/09\/massive-equifax-breach-caused-by-failure-to-patch-two-month-old-bug\/"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2003.1205177"},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the 2000 ACM Conference on Computer Supported Cooperative Work (CSCW). Association for Computing Machinery, 319--328","author":"Herbsleb James D.","unstructured":"James D. Herbsleb , Audris Mockus , Thomas A. Finholt , and Rebecca E. Grinter . 2000. Distance, dependencies, and delay in a global collaboration . In Proceedings of the 2000 ACM Conference on Computer Supported Cooperative Work (CSCW). Association for Computing Machinery, 319--328 . https:\/\/doi.org\/10.1145\/358916.359003 10.1145\/358916.359003 James D. Herbsleb, Audris Mockus, Thomas A. Finholt, and Rebecca E. Grinter. 2000. Distance, dependencies, and delay in a global collaboration. In Proceedings of the 2000 ACM Conference on Computer Supported Cooperative Work (CSCW). Association for Computing Machinery, 319--328. https:\/\/doi.org\/10.1145\/358916.359003"},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the 23rd International Conference on Software Engineering, ICSE 2001. IEEE, 81--90","author":"Herbsleb James D.","year":"2001","unstructured":"James D. Herbsleb , Audris Mockus , Thomas A. Finholt , and Rebecca E. Grinter . 2001. An Empirical Study of Global Software Development: Distance and Speed . In Proceedings of the 23rd International Conference on Software Engineering, ICSE 2001. IEEE, 81--90 . https:\/\/doi.org\/10.1109\/ICSE. 2001 .919083 10.1109\/ICSE.2001.919083 James D. Herbsleb, Audris Mockus, Thomas A. Finholt, and Rebecca E. Grinter. 2001. An Empirical Study of Global Software Development: Distance and Speed. In Proceedings of the 23rd International Conference on Software Engineering, ICSE 2001. IEEE, 81--90. https:\/\/doi.org\/10.1109\/ICSE.2001.919083"},{"key":"e_1_2_1_23_1","volume-title":"Patch Management Automation for Enterprise Cloud. In IEEE Network Operations and Management Symposium. IEEE, 691--705","author":"Huang Hai","year":"2012","unstructured":"Hai Huang , Salman Baset , Chunqiang Tang , Ashu Gupta , KN Madhu Sudhan , Fazal Feroze , Rajesh Garg , and Sumithra Ravichandran . 2012 . Patch Management Automation for Enterprise Cloud. In IEEE Network Operations and Management Symposium. IEEE, 691--705 . https:\/\/doi.org\/10.1109\/NOMS.2012.6211988 10.1109\/NOMS.2012.6211988 Hai Huang, Salman Baset, Chunqiang Tang, Ashu Gupta, KN Madhu Sudhan, Fazal Feroze, Rajesh Garg, and Sumithra Ravichandran. 2012. Patch Management Automation for Enterprise Cloud. In IEEE Network Operations and Management Symposium. IEEE, 691--705. https:\/\/doi.org\/10.1109\/NOMS.2012.6211988"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00015"},{"key":"e_1_2_1_25_1","volume-title":"Directions in Hybrid Intelligence: Complementing AI Systems with Human Intelligence","author":"Kamar Ece","unstructured":"Ece Kamar . 2016. Directions in Hybrid Intelligence: Complementing AI Systems with Human Intelligence . In IJCAI. IEEE , 4070--4073. Ece Kamar. 2016. Directions in Hybrid Intelligence: Complementing AI Systems with Human Intelligence. In IJCAI. IEEE, 4070--4073."},{"key":"e_1_2_1_26_1","volume-title":"Spectre Attacks: Exploiting Speculative Execution. In 2019 IEEE Symposium on Security and Privacy (S&P'19)","author":"Kocher Paul","year":"2019","unstructured":"Paul Kocher , Jann Horn , Anders Fogh , Daniel Genkin , Daniel Gruss , Werner Haas , Mike Hamburg , Moritz Lipp , Stefan Mangard , Thomas Prescher , Michael Schwarz , and Yuval Yarom . 2019 . Spectre Attacks: Exploiting Speculative Execution. In 2019 IEEE Symposium on Security and Privacy (S&P'19) . IEEE, 1--19. https:\/\/doi.org\/10.1109\/SP.2019.00002 10.1109\/SP.2019.00002 Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2019. Spectre Attacks: Exploiting Speculative Execution. In 2019 IEEE Symposium on Security and Privacy (S&P'19). IEEE, 1--19. https:\/\/doi.org\/10.1109\/SP.2019.00002"},{"key":"e_1_2_1_27_1","volume-title":"Keepers of the Machines: Examining How System Administrators Manage Software Updates. In Fifteenth Symposium on Usable Privacy and Security (SOUPS","author":"Li Frank","year":"2019","unstructured":"Frank Li , Lisa Rogers , Arunesh Mathur , Nathan Malkin , and Marshini Chetty . 2019 . Keepers of the Machines: Examining How System Administrators Manage Software Updates. In Fifteenth Symposium on Usable Privacy and Security (SOUPS 2019). USENIX Association, 273--288. Frank Li, Lisa Rogers, Arunesh Mathur, Nathan Malkin, and Marshini Chetty. 2019. Keepers of the Machines: Examining How System Administrators Manage Software Updates. In Fifteenth Symposium on Usable Privacy and Security (SOUPS 2019). USENIX Association, 273--288."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818052.2869117"},{"key":"e_1_2_1_29_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp , Michael Schwarz , Daniel Gruss , Thomas Prescher , Werner Haas , Anders Fogh , Jann Horn , Stefan Mangard , Paul Kocher , Daniel Genkin , Yuval Yarom , and Mike Hamburg . 2018 . Meltdown: Reading Kernel Memory from User Space . In 27th USENIX Security Symposium (USENIX Security 18) . USENIX Association, 973--990. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/lipp Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading Kernel Memory from User Space. In 27th USENIX Security Symposium (USENIX Security 18). USENIX Association, 973--990. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/lipp"},{"key":"e_1_2_1_30_1","volume-title":"Sampling for qualitative research. Family practice 13, 6","author":"Marshall Martin N.","year":"1996","unstructured":"Martin N. Marshall . 1996. Sampling for qualitative research. Family practice 13, 6 ( 1996 ), 522--526. https:\/\/doi.org\/10.1093\/fampra\/13.6.522 10.1093\/fampra Martin N. Marshall. 1996. Sampling for qualitative research. Family practice 13, 6 (1996), 522--526. https:\/\/doi.org\/10.1093\/fampra\/13.6.522"},{"key":"e_1_2_1_31_1","first-page":"289","article-title":"Multiteam systems","volume":"2","author":"Mathieu John E.","year":"2001","unstructured":"John E. Mathieu , Michelle A. Marks , and Stephen J. Zaccaro . 2001 . Multiteam systems . Handbook of Industrial, Work and Organizational Psychology 2 (2001), 289 -- 313 . John E. Mathieu, Michelle A. Marks, and Stephen J. Zaccaro. 2001. Multiteam systems. Handbook of Industrial, Work and Organizational Psychology 2 (2001), 289--313.","journal-title":"Handbook of Industrial, Work and Organizational Psychology"},{"key":"e_1_2_1_32_1","volume-title":"TACHYON: Tandem execution for efficient live patch testing. In 21st {USENIX} Security Symposium ({USENIX} Security 12. {USENIX}","author":"Maurer Matthew","year":"2012","unstructured":"Matthew Maurer and David Brumley . 2012 . TACHYON: Tandem execution for efficient live patch testing. In 21st {USENIX} Security Symposium ({USENIX} Security 12. {USENIX} Association , Bellevue, WA , 617--630. https:\/\/www.usenix.org\/conference\/usenixsecurity12\/technical-sessions\/presentation\/maurer Matthew Maurer and David Brumley. 2012. TACHYON: Tandem execution for efficient live patch testing. In 21st {USENIX} Security Symposium ({USENIX} Security 12. {USENIX} Association, Bellevue, WA, 617--630. https:\/\/www.usenix.org\/conference\/usenixsecurity12\/technical-sessions\/presentation\/maurer"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.17763\/haer.62.3.8323320856251826"},{"key":"e_1_2_1_34_1","first-page":"40","article-title":"Creating a patch and vulnerability management program","volume":"800","author":"Mell Peter","year":"2005","unstructured":"Peter Mell , Tiffany Bergeron , and David Henning . 2005 . Creating a patch and vulnerability management program . NIST Special Publication 800 (2005), 40 . Peter Mell, Tiffany Bergeron, and David Henning. 2005. Creating a patch and vulnerability management program. NIST Special Publication 800 (2005), 40.","journal-title":"NIST Special Publication"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.5555\/2206254"},{"key":"e_1_2_1_36_1","unstructured":"Sharan B. Merriam. 1998. Qualitative Research and Case Study Applications in Education. Revised and Expanded from. ERIC.  Sharan B. Merriam. 1998. Qualitative Research and Case Study Applications in Education. Revised and Expanded from. ERIC."},{"key":"e_1_2_1_37_1","volume-title":"The Attack of the Clones: A Study of the Impact of Shared Code on Vulnerability Patching. In IEEE Symposium on Security and Privacy (S&P). IEEE, 692--708","author":"Nappa Antonio","year":"2015","unstructured":"Antonio Nappa , Richard Johnson , Leyla Bilge , Juan Caballero , and Tudor Dumitras . 2015 . The Attack of the Clones: A Study of the Impact of Shared Code on Vulnerability Patching. In IEEE Symposium on Security and Privacy (S&P). IEEE, 692--708 . https:\/\/doi.org\/10.1109\/SP.2015.48 10.1109\/SP.2015.48 Antonio Nappa, Richard Johnson, Leyla Bilge, Juan Caballero, and Tudor Dumitras. 2015. The Attack of the Clones: A Study of the Impact of Shared Code on Vulnerability Patching. In IEEE Symposium on Security and Privacy (S&P). IEEE, 692--708. https:\/\/doi.org\/10.1109\/SP.2015.48"},{"key":"e_1_2_1_38_1","volume-title":"Retrieved","author":"Newman Lily Hay","year":"2017","unstructured":"Lily Hay Newman . 2017 . Equifax Officially Has No Excuse . Retrieved June 23, 2021 from https:\/\/www.wired.com\/story\/equifax-breach-no-excuse\/ Lily Hay Newman. 2017. Equifax Officially Has No Excuse. Retrieved June 23, 2021 from https:\/\/www.wired.com\/story\/equifax-breach-no-excuse\/"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICGSE.2008.39"},{"key":"e_1_2_1_40_1","first-page":"5","article-title":"Security Patch","volume":"12","author":"Nicastro Felicia M.","year":"2003","unstructured":"Felicia M. Nicastro . 2003 . Security Patch Management. Inf. Secur. J. A Glob. Perspect. 12 , 5 (2003), 5 -- 18 . https:\/\/doi.org\/10.1201\/1086\/43808.12.5.20031101\/78486.2 10.1201\/1086 Felicia M. Nicastro. 2003. Security Patch Management. Inf. Secur. J. A Glob. Perspect. 12, 5 (2003), 5--18. https:\/\/doi.org\/10.1201\/1086\/43808.12.5.20031101\/78486.2","journal-title":"Management. Inf. Secur. J. A Glob. Perspect."},{"key":"e_1_2_1_41_1","volume-title":"Procedures for Handling Security Patches. Special Publication (SP) 800--40","author":"NIST.","year":"2002","unstructured":"NIST. 2002. Procedures for Handling Security Patches. Special Publication (SP) 800--40 ( 2002 ). NIST. 2002. Procedures for Handling Security Patches. Special Publication (SP) 800--40 (2002)."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0950-5849(03)00016-8"},{"key":"e_1_2_1_43_1","volume-title":"Proceedings of the 19th USENIX Systems Administration Conference. IEEE, 6--6.","author":"Potter Shaya","year":"2005","unstructured":"Shaya Potter and Jason Nieh . 2005 . Reducing Downtime Due to System Maintenance and Upgrades . In Proceedings of the 19th USENIX Systems Administration Conference. IEEE, 6--6. Shaya Potter and Jason Nieh. 2005. Reducing Downtime Due to System Maintenance and Upgrades. In Proceedings of the 19th USENIX Systems Administration Conference. IEEE, 6--6."},{"key":"e_1_2_1_44_1","volume-title":"A Theory of Value for Value-based Feature Selection in Software Engineering","author":"Rodriguez Pilar","year":"2020","unstructured":"Pilar Rodriguez , Cathy Urquhart , and Emilia Mendes . 2020. A Theory of Value for Value-based Feature Selection in Software Engineering . IEEE Transactions on Software Engineering ( 2020 ). https:\/\/doi.org\/10.1109\/TSE.2020.2989666 10.1109\/TSE.2020.2989666 Pilar Rodriguez, Cathy Urquhart, and Emilia Mendes. 2020. A Theory of Value for Value-based Feature Selection in Software Engineering. IEEE Transactions on Software Engineering (2020). https:\/\/doi.org\/10.1109\/TSE.2020.2989666"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-008-9102-8"},{"key":"e_1_2_1_46_1","unstructured":"Thomas A. Schwandt. 1997. Qualitative Inquiry. Sage London.  Thomas A. Schwandt. 1997. Qualitative Inquiry. Sage London."},{"key":"e_1_2_1_47_1","volume-title":"Retrieved","author":"Security Accenture","year":"2020","unstructured":"Accenture Security . 2020 . 2020 Cyber Threatscape Report . Retrieved June 23, 2021 from https:\/\/www.accenture.com\/_acnmedia\/PDF-136\/Accenture-2020-Cyber-Threatscape-Full-Report.pdf Accenture Security. 2020. 2020 Cyber Threatscape Report. Retrieved June 23, 2021 from https:\/\/www.accenture.com\/_acnmedia\/PDF-136\/Accenture-2020-Cyber-Threatscape-Full-Report.pdf"},{"key":"e_1_2_1_48_1","volume-title":"Guide to Enterprise Patch Management Technologies. NIST Special Publication 800--40 Revision 3","author":"Souppaya Murugiah","year":"2013","unstructured":"Murugiah Souppaya and Karen Scarfone . 2013. Guide to Enterprise Patch Management Technologies. NIST Special Publication 800--40 Revision 3 ( 2013 ), 40. http:\/\/dx.doi.org\/10.6028\/NIST.SP.800--40r3 10.6028\/NIST.SP.800--40r3 Murugiah Souppaya and Karen Scarfone. 2013. Guide to Enterprise Patch Management Technologies. NIST Special Publication 800--40 Revision 3 (2013), 40. http:\/\/dx.doi.org\/10.6028\/NIST.SP.800--40r3"},{"key":"e_1_2_1_49_1","volume-title":"Corbin","author":"Strauss Anselm L.","year":"1998","unstructured":"Anselm L. Strauss and Juliet M . Corbin . 1998 . Basics of Qualitative Research : Techniques and Procedures for Developing Grounded Theory (2nd ed.). Sage . Anselm L. Strauss and Juliet M. Corbin. 1998. Basics of Qualitative Research : Techniques and Procedures for Developing Grounded Theory (2nd ed.). Sage."},{"key":"e_1_2_1_50_1","volume-title":"Corbin","author":"Strauss Anselm L.","year":"2007","unstructured":"Anselm L. Strauss and Juliet M . Corbin . 2007 . Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory (3rd ed.). Sage . Anselm L. Strauss and Juliet M. Corbin. 2007. Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory (3rd ed.). Sage."},{"key":"e_1_2_1_51_1","volume-title":"Sixteenth Symposium on Usable Privacy and Security (SOUPS","author":"Tiefenau Christian","year":"2020","unstructured":"Christian Tiefenau , Maximilian H\u00e4ring , Katharina Krombholz , and Emanuel von Zezschwitz . 2020 . Security, Availability, and Multiple Information Sources: Exploring Update Behavior of System Administrators . In Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020). USENIX Association, 239--258. Christian Tiefenau, Maximilian H\u00e4ring, Katharina Krombholz, and Emanuel von Zezschwitz. 2020. Security, Availability, and Multiple Information Sources: Exploring Update Behavior of System Administrators. In Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020). USENIX Association, 239--258."},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/1508244.1508267"},{"key":"e_1_2_1_53_1","volume-title":"Grounded Theory for Qualitative Research: A Practical Guide","author":"Urquhart Cathy","unstructured":"Cathy Urquhart . 2013. Grounded Theory for Qualitative Research: A Practical Guide . Sage . Cathy Urquhart. 2013. Grounded Theory for Qualitative Research: A Practical Guide. Sage."},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359313"},{"key":"e_1_2_1_55_1","volume-title":"Proceedings of the ACM Conference on Computer Supported Cooperative Work Social Computing 2, CSCW","author":"Wessel Mairieli","year":"2018","unstructured":"Mairieli Wessel , Bruno Mendes de Souza , Igor Steinmacher , Igor S. Wiese , Ivanilton Polato , Ana Paula Chaves , and Marco A. Gerosa . 2018. The Power of Bots: Characterizing and Understanding Bots in OSS Projects . Proceedings of the ACM Conference on Computer Supported Cooperative Work Social Computing 2, CSCW ( 2018 ). https:\/\/doi.org\/10.1145\/3274451 10.1145\/3274451 Mairieli Wessel, Bruno Mendes de Souza, Igor Steinmacher, Igor S. Wiese, Ivanilton Polato, Ana Paula Chaves, and Marco A. Gerosa. 2018. The Power of Bots: Characterizing and Understanding Bots in OSS Projects. Proceedings of the ACM Conference on Computer Supported Cooperative Work Social Computing 2, CSCW (2018). https:\/\/doi.org\/10.1145\/3274451"},{"key":"e_1_2_1_56_1","unstructured":"Robert K. Yin. 1994. Case Study Research: Design and Methods.  Robert K. Yin. 1994. Case Study Research: Design and Methods."},{"key":"e_1_2_1_57_1","volume-title":"Case Study Research: Design and Methods (4 ed.)","author":"Yin Robert K.","unstructured":"Robert K. Yin . 2009. Case Study Research: Design and Methods (4 ed.) . Sage, Thousand Oaks, CA , USA. Robert K. Yin. 2009. Case Study Research: Design and Methods (4 ed.). Sage, Thousand Oaks, CA, USA."}],"container-title":["Proceedings of the ACM on Human-Computer Interaction"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3555087","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3555087","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:51Z","timestamp":1750178811000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3555087"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,7]]},"references-count":57,"journal-issue":{"issue":"CSCW2","published-print":{"date-parts":[[2022,11,7]]}},"alternative-id":["10.1145\/3555087"],"URL":"https:\/\/doi.org\/10.1145\/3555087","relation":{},"ISSN":["2573-0142"],"issn-type":[{"value":"2573-0142","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,7]]},"assertion":[{"value":"2022-11-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}