{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T11:08:15Z","timestamp":1768475295333,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":54,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,7,30]],"date-time":"2024-07-30T00:00:00Z","timestamp":1722297600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,7,30]]},"DOI":"10.1145\/3664476.3670883","type":"proceedings-article","created":{"date-parts":[[2024,7,25]],"date-time":"2024-07-25T12:35:50Z","timestamp":1721910950000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["A Trust and Reputation System for Examining Compliance with Access Control"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0157-3057","authenticated-orcid":false,"given":"Thomas","family":"Baumer","sequence":"first","affiliation":[{"name":"Nexis GmbH, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-9578-8821","authenticated-orcid":false,"given":"Johannes","family":"Grill","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Regensburg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-0877-8326","authenticated-orcid":false,"given":"Jacob","family":"Adan","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Regensburg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1338-9003","authenticated-orcid":false,"given":"G\u00fcnther","family":"Pernul","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Regensburg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,7,30]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1186\/s13677-023-00416-8"},{"key":"e_1_3_2_1_2_1","unstructured":"American Institute of Certified Public Accountants. 2022. SOC 2\u00ae Reporting on an Examination of Controls at a Service Organization Relevant to Security Availability Processing Integrity Confidentiality or Privacy. https:\/\/www.aicpa-cima.com\/cpe-learning\/publication\/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy"},{"key":"e_1_3_2_1_3_1","unstructured":"Basel Committee on Banking Supervision. 2011. Basel III: A global regulatory framework for more resilient banks and banking systems."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3304270"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3471140"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2969820"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236008"},{"key":"e_1_3_2_1_8_1","unstructured":"California State Legislature. 2018. California Consumer Privacy Act. https:\/\/oag.ca.gov\/privacy\/ccpa"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICITIS.2010.5689468"},{"key":"e_1_3_2_1_10_1","unstructured":"C\u00e2mara dos Deputados. 2018. Lei Geral de Prote\u00e7\u00e3o de Dados Pessoais. https:\/\/www.planalto.gov.br\/ccivil_03\/_Ato2015-2018\/2018\/Lei\/L13709.htm"},{"key":"e_1_3_2_1_11_1","volume-title":"OTM 2018 Conferences, Herv\u00e9 Panetto, Christophe Debruyne, Henderik\u00a0A. Proper, Claudio\u00a0Agostino Ardagna, Dumitru Roman, and Robert Meersman (Eds.). Springer International Publishing, Cham, 277\u2013288","author":"El\u00a0Ioini Nabil","year":"2018","unstructured":"Nabil El\u00a0Ioini and Claus Pahl. 2018. A Review of Distributed Ledger Technologies. In On the Move to Meaningful Internet Systems. OTM 2018 Conferences, Herv\u00e9 Panetto, Christophe Debruyne, Henderik\u00a0A. Proper, Claudio\u00a0Agostino Ardagna, Dumitru Roman, and Robert Meersman (Eds.). Springer International Publishing, Cham, 277\u2013288."},{"key":"e_1_3_2_1_12_1","unstructured":"European Commission. 2016. General Data Protection Regulation."},{"key":"e_1_3_2_1_13_1","volume-title":"Council of the European Union","author":"Parliament European","year":"2014","unstructured":"European Parliament, Council of the European Union. 2014. Regulation (EU) No 910\/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999\/93\/EC."},{"key":"e_1_3_2_1_14_1","unstructured":"Hyperledger Foundation. 2024. Hyperledger Fabric Documentation. https:\/\/hyperledger-fabric.readthedocs.io\/en\/release-2.5\/index.html"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom.2012.58"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2007.145"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.08.002"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623144"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2816826"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"crossref","unstructured":"Paul\u00a0A. Grassi James\u00a0L. Fenton Elaine\u00a0M. Newton Ray\u00a0A. Perlner Andrew\u00a0R. Regenscheid William\u00a0E. Burr Justin\u00a0P. Richer Naomi\u00a0B. Lefkovitz Jamie\u00a0M. Danker Yee-Yin Choong Kristen\u00a0K. Greene and Mary\u00a0F. Theofanos. 2017. Digital identity guidelines: authentication and lifecycle management. Technical Report. National Institute of Standards and Technology. https:\/\/doi.org\/10.6028\/nist.sp.800-63b","DOI":"10.6028\/NIST.SP.800-63b"},{"key":"e_1_3_2_1_21_1","unstructured":"Health Information Trust Alliance. 2023. Health Information Trust Alliance Common Security Framework. https:\/\/hitrustalliance.net\/hitrust-framework"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1257\/089533003765888403"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1592451.1592452"},{"key":"e_1_3_2_1_24_1","volume-title":"Information technology \u2014 Security techniques \u2014 Information security management systems \u2014 Requirements. Standard","author":"ISO","unstructured":"ISO 27001. 2013. Information technology \u2014 Security techniques \u2014 Information security management systems \u2014 Requirements. Standard. International Organization for Standardization."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560609"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2005.05.019"},{"key":"e_1_3_2_1_27_1","unstructured":"Michael Kapoor. 2023. Deloitte Canada Fined $1.1 Million for Backdating Audit Papers. https:\/\/news.bloombergtax.com\/financial-accounting\/deloitte-canada-fined-1-1-million-for-backdating-audit-papers"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","unstructured":"Sascha Kern Thomas Baumer Ludwig Fuchs and G\u00fcnther Pernul. 2023. Maintain High-Quality Access Control Policies: An Academic and\u00a0Practice-Driven Approach. In Data and Applications Security and Privacy XXXVII Vijayalakshmi Atluri and Anna\u00a0Lisa Ferrara (Eds.). Springer Nature Switzerland Cham 223\u2013242. https:\/\/doi.org\/10.1007\/978-3-031-37586-6_14","DOI":"10.1007\/978-3-031-37586-6_14"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2022.103301"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/J.COSREV.2012.01.002"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","unstructured":"Yong Kuang Hongyun Xu Rui Jiang and Zhikang Liu. 2022. GTMS: A Gated Linear Unit Based Trust Management System for Internet of Vehicles Using Blockchain Technology. In 2022 IEEE International Conference on Trust Security and Privacy in Computing and Communications (TrustCom). IEEE Wuhan China 28\u201335. https:\/\/doi.org\/10.1109\/TrustCom56396.2022.00015","DOI":"10.1109\/TrustCom56396.2022.00015"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3603705"},{"key":"e_1_3_2_1_33_1","unstructured":"Mark Maurer. 2024. KPMG Fined Record $25 Million in Exam-Cheating Scandal. https:\/\/www.wsj.com\/articles\/kpmg-fined-25-million-over-alleged-netherlands-exam-cheating-a4dcba2a"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2871148"},{"key":"e_1_3_2_1_35_1","unstructured":"National Cyber Security Centre. 2018. Cloud security guidance. https:\/\/www.ncsc.gov.uk\/collection\/cloud"},{"key":"e_1_3_2_1_36_1","unstructured":"North American Electric Reliability Corporation. 2024. Critical Infrastructure Protection. https:\/\/www.nerc.com\/pa\/Stand\/Pages\/ReliabilityStandards.aspx Series of standards."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-98385-1_12"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.3390\/cryptography2010001"},{"key":"e_1_3_2_1_39_1","unstructured":"OWASP Top 10 team. 2021. OWASP Top10. https:\/\/owasp.org\/Top10\/"},{"key":"e_1_3_2_1_40_1","unstructured":"PCI Security Standards Council. 2022. PCI DSS: v4.0. https:\/\/docs-prv.pcisecuritystandards.org\/PCI%20DSS\/Standard\/PCI-DSS-v4_0.pdf"},{"key":"e_1_3_2_1_41_1","unstructured":"J Ratnatunga. 2023. PwC Tax Scandal\u2019s Aftermath: It\u2019s Time to Seriously Regulate the Big 4. https:\/\/cmaaustralia.edu.au\/ontarget\/pwc-tax-scandals-aftermath-its-time-to-seriously-regulate-the-big-4\/"},{"key":"e_1_3_2_1_42_1","volume-title":"TAP: Transparent and Privacy-Preserving Data Services. In 32nd USENIX Security Symposium (USENIX Security 23)","author":"Reijsbergen Dani\u00ebl","year":"2023","unstructured":"Dani\u00ebl Reijsbergen, Aung Maw, Zheng Yang, Tien Tuan\u00a0Anh Dinh, and Jianying Zhou. 2023. TAP: Transparent and Privacy-Preserving Data Services. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 6489\u20136506. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/reijsbergen"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0065-2458(08)60206-5"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3600160.3604997"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623080"},{"key":"e_1_3_2_1_46_1","unstructured":"Stavros Simou Aikaterini-Georgia Mavroeidi and Christos Kalloniatis. 2024. Review on Privacy and Trust Methodologies in Cloud Computing. In Computer Security. ESORICS 2023 International Workshops Sokratis Katsikas Fr\u00e9d\u00e9ric Cuppens Nora Cuppens-Boulahia Costas Lambrinoudakis Joaquin Garcia-Alfaro Guillermo Navarro-Arribas Pantaleone Nespoli Christos Kalloniatis John Mylopoulos Annie Ant\u00f3n and Stefanos Gritzalis (Eds.). Springer Nature Switzerland Cham 494\u2013505."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.942344"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-34957-8"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179481"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1108\/JFC-12-2022-0301"},{"key":"e_1_3_2_1_51_1","volume-title":"States Congress. 1996","author":"United","year":"1996","unstructured":"United States Congress. 1996. Health Insurance Portability and Accountability Act of 1996."},{"key":"e_1_3_2_1_52_1","volume-title":"States Congress. 2002","author":"United","year":"2002","unstructured":"United States Congress. 2002. Sarbanes-Oxley Act of 2002. Corporate responsibility."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVCBT.2018.00011"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2010.2059690"}],"event":{"name":"ARES 2024: The 19th International Conference on Availability, Reliability and Security","location":"Vienna Austria","acronym":"ARES 2024"},"container-title":["Proceedings of the 19th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664476.3670883","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3664476.3670883","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T16:55:35Z","timestamp":1755881735000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664476.3670883"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,30]]},"references-count":54,"alternative-id":["10.1145\/3664476.3670883","10.1145\/3664476"],"URL":"https:\/\/doi.org\/10.1145\/3664476.3670883","relation":{},"subject":[],"published":{"date-parts":[[2024,7,30]]},"assertion":[{"value":"2024-07-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}