{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T16:14:53Z","timestamp":1784736893254,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,11,26]],"date-time":"2024-11-26T00:00:00Z","timestamp":1732579200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,11,26]]},"DOI":"10.1145\/3697090.3697098","type":"proceedings-article","created":{"date-parts":[[2024,12,11]],"date-time":"2024-12-11T07:06:08Z","timestamp":1733900768000},"page":"101-110","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Supporting continuous vulnerability compliance through automated identity provisioning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-7705-4170","authenticated-orcid":false,"given":"Diego","family":"Gama","sequence":"first","affiliation":[{"name":"Federal University of Campina Grande, Campina Grande, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7350-8599","authenticated-orcid":false,"given":"Andrey","family":"Brito","sequence":"additional","affiliation":[{"name":"Federal University of Campina Grande, Campina Grande, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7135-6288","authenticated-orcid":false,"given":"Andr\u00e9","family":"Martin","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Dresden, Dresden, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8240-5420","authenticated-orcid":false,"given":"Christof","family":"Fetzer","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Dresden, Dresden, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,10]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"2021. Compliance in a DevOps Culture \u2014 martinfowler.com. https:\/\/martinfowler.com\/articles\/devops-compliance.html. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_3_2","unstructured":"2024. Documents & Templates | FedRAMP.gov \u2014 fedramp.gov. https:\/\/www.fedramp.gov\/documents-templates\/. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_4_2","unstructured":"2024. Exploit Prediction Scoring System (EPSS) \u2014 first.org. https:\/\/www.first.org\/epss\/. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_5_2","unstructured":"2024. GitHub - spiffe\/spiffe-helper: The SPIFFE Helper is a tool that can be used to retrieve and manage SVIDs on behalf of a workload \u2014 github.com. https:\/\/github.com\/spiffe\/spiffe-helper. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_6_2","unstructured":"2024. Graduated and Incubating Projects \u2014 cncf.io. https:\/\/www.cncf.io\/projects\/. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_7_2","unstructured":"2024. Home \u2014 scorecard.dev. https:\/\/scorecard.dev\/. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_8_2","unstructured":"2024. Home Page | CISA \u2014 cisa.gov. https:\/\/www.cisa.gov\/. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_9_2","unstructured":"2024. Official PCI Security Standards Council Site. https:\/\/east.pcisecuritystandards.org\/. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_10_2","unstructured":"2024. Security levels \u2014 slsa.dev. https:\/\/slsa.dev\/spec\/v1.0\/levels. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_11_2","unstructured":"2024. Signing \u2014 docs.sigstore.dev. https:\/\/docs.sigstore.dev\/signing\/overview. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_12_2","unstructured":"2024. spire\/ADOPTERS.md at main \u00b7 spiffe\/spire \u2014 github.com. https:\/\/github.com\/spiffe\/spire\/blob\/main\/ADOPTERS.md. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_13_2","unstructured":"2024. The Kerberos ticket \u2014 ibm.com. https:\/\/www.ibm.com\/docs\/en\/sc-and-ds\/8.4.0?topic=concepts-kerberos-ticket. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_14_2","unstructured":"2024. The Leading Open-Source IAM Solution \u2014 wso2.com. https:\/\/wso2.com\/identity-server\/. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD55607.2022.00066"},{"key":"e_1_3_3_2_16_2","doi-asserted-by":"publisher","unstructured":"Andrew Babakian Pere Monclus Robin Braun and Justin Lipman. 2022. A Retrospective on Workload Identifiers: From Data Center to Cloud-Native Networks. IEEE Access 10 (2022) 105518\u2013105527. 10.1109\/ACCESS.2022.3211293","DOI":"10.1109\/ACCESS.2022.3211293"},{"key":"e_1_3_3_2_17_2","doi-asserted-by":"publisher","unstructured":"Christoph Buck Christian Olenberger Andr\u00e9 Schweizer Fabiane V\u00f6lter and Torsten Eymann. 2021. Never trust always verify: A multivocal literature review on current knowledge and research gaps of zero-trust. Computers & Security 110 (2021) 102436. 10.1016\/j.cose.2021.102436 https:\/\/dl.acm.org\/doi\/10.1016\/j.cose.2021.102436","DOI":"10.1016\/j.cose.2021.102436"},{"key":"e_1_3_3_2_18_2","doi-asserted-by":"publisher","unstructured":"Baozhan Chen Siyuan Qiao Jie Zhao Dongqing Liu Xiaobing Shi Minzhao Lyu Haotian Chen Huimin Lu and Yunkai Zhai. 2021. A Security Awareness and Protection System for 5G Smart Healthcare Based on Zero-Trust Architecture. IEEE Internet of Things Journal 8 13 (2021) 10248\u201310263. 10.1109\/JIOT.2020.3041042","DOI":"10.1109\/JIOT.2020.3041042"},{"key":"e_1_3_3_2_19_2","volume-title":"When to Issue VEX Information","year":"2023","unstructured":"CISA. 2023. When to Issue VEX Information. https:\/\/www.cisa.gov\/resources-tools\/resources\/when-issue-vex-information\/."},{"key":"e_1_3_3_2_20_2","unstructured":"CISA. 2023. Zero Trust Maturity Model v2.0. https:\/\/www.cisa.gov\/sites\/default\/files\/2023-04\/zero_trust_maturity_model_v2_508.pdf. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_21_2","volume-title":"Prioritization to Prediction Volume 8: Measuring and Minimizing Exploitability","author":"CYENTIA\u00a0INSTITUTE KENNA\u00a0SECURITY","year":"2022","unstructured":"KENNA\u00a0SECURITY CYENTIA\u00a0INSTITUTE. 2022. Prioritization to Prediction Volume 8: Measuring and Minimizing Exploitability."},{"key":"e_1_3_3_2_22_2","unstructured":"Catherine de Weever and Marios Andreou. 2020. Zero trust network security model in containerized environments. University of Amsterdam: Amsterdam The Netherlands (2020)."},{"key":"e_1_3_3_2_23_2","unstructured":"Richard Fang Rohan Bindu Akul Gupta and Daniel Kang. 2024. LLM Agents can Autonomously Exploit One-day Vulnerabilities. arxiv:https:\/\/arXiv.org\/abs\/2404.08144\u00a0[cs.CR]"},{"key":"e_1_3_3_2_24_2","unstructured":"Jerry Gamblin. 2024. 2023 CVE Data Review \u2014 jerrygamblin.com. https:\/\/jerrygamblin.com\/2024\/01\/03\/2023-cve-data-review\/. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_25_2","doi-asserted-by":"publisher","unstructured":"Yuanhang He Daochao Huang Lei Chen Yi Ni Xiangjie Ma and Yan Huo. 2022. A Survey on Zero Trust Architecture: Challenges and Future Trends. Wirel. Commun. Mob. Comput. 2022 (jan 2022) 13\u00a0pages. 10.1155\/2022\/6476274 https:\/\/dl.acm.org\/doi\/10.1155\/2022\/6476274","DOI":"10.1155\/2022\/6476274"},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"publisher","unstructured":"Jay Jacobs Sasha Romanosky Benjamin Edwards Idris Adjerid and Michael Roytman. 2021. Exploit Prediction Scoring System (EPSS). Digital Threats 2 3 Article 20 (jul 2021) 17\u00a0pages. 10.1145\/3436242https:\/\/dl.acm.org\/doi\/10.1145\/3436242","DOI":"10.1145\/3436242"},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","unstructured":"Pontus Johnson Robert Lagerstr\u00f6m Mathias Ekstedt and Ulrik Franke. 2018. Can the Common Vulnerability Scoring System be Trusted? A Bayesian Analysis. IEEE Transactions on Dependable and Secure Computing 15 6 (2018) 1002\u20131015. 10.1109\/TDSC.2016.2644614","DOI":"10.1109\/TDSC.2016.2644614"},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416593"},{"key":"e_1_3_3_2_29_2","unstructured":"Aditya\u00a0Sirish (NYU) and Tom Hennen\u00a0(Google) representing the in-toto Community. 2024. in-toto and SLSA \u2014 slsa.dev. https:\/\/slsa.dev\/blog\/2023\/05\/in-toto-and-slsa. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"publisher","unstructured":"Xhesika Ramaj Mary S\u00e1nchez-Gord\u00f3n Vasileios Gkioulos Sabarathinam Chockalingam and Ricardo Colomo-Palacios. 2022. Holding on to Compliance While Adopting DevSecOps: An SLR. Electronics 11 22 (2022). 10.3390\/electronics11223707","DOI":"10.3390\/electronics11223707"},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"publisher","unstructured":"Scott Rose Oliver Borchert Stuart Mitchell and Sean Connelly. 2020. Zero Trust Architecture. 10.6028\/NIST.SP.800-207","DOI":"10.6028\/NIST.SP.800-207"},{"key":"e_1_3_3_2_32_2","volume-title":"8th State of the Software Supply Chain","year":"2022","unstructured":"Sonatype. 2022. 8th State of the Software Supply Chain. https:\/\/www.sonatype.com\/resources\/state-of-the-software-supply-chain-2022\/introduction - Access in May 8th, 2024."},{"key":"e_1_3_3_2_33_2","volume-title":"9th State of the Software Supply Chain","year":"2023","unstructured":"Sonatype. 2023. 9th State of the Software Supply Chain. https:\/\/www.sonatype.com\/state-of-the-software-supply-chain\/open-source-supply-and-demand - Access in May 8th, 2024."},{"key":"e_1_3_3_2_34_2","unstructured":"Steve Springett. 2024. Deploying Docker Container \u2014 docs.dependencytrack.org. https:\/\/docs.dependencytrack.org\/getting-started\/deploy-docker\/. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_35_2","volume-title":"Software Engineering","author":"Steffens Andreas","year":"2018","unstructured":"Andreas Steffens, Horst Lichter, and Marco Moscher. 2018. Towards Data-driven Continuous Compliance Testing. In Software Engineering. https:\/\/api.semanticscholar.org\/CorpusID:3818261"},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"publisher","unstructured":"Naeem\u00a0Firdous Syed Syed\u00a0W. Shah Arash Shaghaghi Adnan Anwar Zubair Baig and Robin Doss. 2022. Zero Trust Architecture (ZTA): A Comprehensive Survey. IEEE Access 10 (2022) 57143\u201357179. 10.1109\/ACCESS.2022.3174679","DOI":"10.1109\/ACCESS.2022.3174679"},{"key":"e_1_3_3_2_37_2","unstructured":"Synopsys. 2024. Open Source Security & Risk Analysis Report (OSSRA) | Synopsys \u2014 synopsys.com. https:\/\/www.synopsys.com\/software-integrity\/resources\/analyst-reports\/open-source-security-risk-analysis.html. [Accessed 19-07-2024]."},{"key":"e_1_3_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2016.022"}],"event":{"name":"LADC 2024: 13th Latin-American Symposium on Dependable and Secure Computing","location":"Recife Brazil","acronym":"LADC 2024"},"container-title":["Proceedings of the 13th Latin-American Symposium on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3697090.3697098","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3697090.3697098","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:17:33Z","timestamp":1750295853000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3697090.3697098"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,26]]},"references-count":37,"alternative-id":["10.1145\/3697090.3697098","10.1145\/3697090"],"URL":"https:\/\/doi.org\/10.1145\/3697090.3697098","relation":{},"subject":[],"published":{"date-parts":[[2024,11,26]]},"assertion":[{"value":"2024-12-10","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}