{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,12]],"date-time":"2026-02-12T11:19:35Z","timestamp":1770895175928,"version":"3.50.1"},"reference-count":170,"publisher":"Association for Computing Machinery (ACM)","issue":"8","funder":[{"name":"German Federal Ministry of Education and Research"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Identity and Access Management (IAM) challenges organizations, requiring carefully orchestrated processes, technologies, and authorizations. Despite its strategic relevance, we lack a consolidated scientific understanding of IAM metrics and their alignment with IAM goals, like security, compliance, and operational efficiency. This systematic review aims to identify and classify IAM metrics from the literature to support evidence-based IAM. It links collected metrics to IAM goals and audiences. The literature review followed the guidelines of Levy and Ellis. It includes publications from databases SpringerLink, AIS eLibrary, IEEE Explore, ScienceDirect, ACM Digital Library, and relevant cross-referenced publications. The search strategy used keyword combinations, like \u201cIdentity and Access Management\u201d and \u201cMetrics,\u201d since 2000. We screened and included publications based on eligibility criteria for relevance, quality, and the explicit presentation of IAM metrics, resulting in sixty publications. The review identified 43 IAM metrics, categorized by seven perspectives derived from IAM goals and processes. Each metric was analyzed by its target, impact on IAM goals, and relevant audiences. The synthesis shows that the literature lacks unified terminology and frameworks for IAM metrics. Future research includes standardizing terminology, linking metrics and targets to maturity levels, and establishing IAM process metrics. The DEVISE project funded this work. It was not registered in PROSPERO.<\/jats:p>\n                  <jats:p\/>","DOI":"10.1145\/3788858","type":"journal-article","created":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T20:15:28Z","timestamp":1768421728000},"page":"1-37","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Identity and Access Management Metrics: A Systematic Review"],"prefix":"10.1145","volume":"58","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0157-3057","authenticated-orcid":false,"given":"Thomas","family":"Baumer","sequence":"first","affiliation":[{"name":"University of Regensburg","place":["Regensburg, Germany"]},{"name":"Nexis GmbH","place":["Regensburg, Germany"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7082-000X","authenticated-orcid":false,"given":"Sascha","family":"Kern","sequence":"additional","affiliation":[{"name":"Nexis GmbH","place":["Regensburg, Germany"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8432-6755","authenticated-orcid":false,"given":"Ludwig","family":"Fuchs","sequence":"additional","affiliation":[{"name":"Nexis GmbH","place":["Regensburg, Germany"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1338-9003","authenticated-orcid":false,"given":"G\u00fcnther","family":"Pernul","sequence":"additional","affiliation":[{"name":"University of Regensburg","place":["Regensburg, Germany"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,2,11]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11227-020-03594-3"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3468379"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623156"},{"key":"e_1_3_2_5_2","volume-title":"OWASP Top 10:2025 (Release Candidate)","author":"Gigler Andrew van der Stock, Brian Glas, Neil Smithline, Tanya Janca, Torsten","year":"2025","unstructured":"Andrew van der Stock, Brian Glas, Neil Smithline, Tanya Janca, Torsten Gigler. 2025. OWASP Top 10:2025 (Release Candidate). Technical Report. Open Web Application Security Project (OWASP). Retrieved from https:\/\/owasp.org\/Top10\/"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-012-9244-2"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3336117"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1177\/0971097320130206"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2024.3519861"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1080\/10447310802205776"},{"issue":"1","key":"e_1_3_2_11_2","first-page":"528","article-title":"The goal question metric approach","volume":"1","author":"Basili Victor","year":"1994","unstructured":"Victor Basili, Gianluigi Caliera, and H. Dieter Rombach. 1994. The goal question metric approach. Encyclopedia of Software Engineering 1, 1 (1994), 528\u2013532.","journal-title":"Encyclopedia of Software Engineering"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2007.66"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/3664476.3670883"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3304270"},{"key":"e_1_3_2_15_2","volume-title":"Proceedings of the 20th USENIX Conference on Usable Privacy and Security (SOUPS\u201924)","author":"Baumer Thomas","year":"2024","unstructured":"Thomas Baumer, Tobias Reittinger, Sascha Kern, and G\u00fcnther Pernul. 2024. Digital nudges for access reviews: Guiding deciders to revoke excessive authorizations. In Proceedings of the 20th USENIX Conference on Usable Privacy and Security (SOUPS\u201924). USENIX Association, USA, Article 13, 20 pages."},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/52.765786"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/2501604.2501606"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2015.07.002"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38844-6_9"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2009.5314213"},{"key":"e_1_3_2_21_2","unstructured":"Beyond Identity. 2022. Former employees admit to using continued account access to harm previous employers. Retrieved January 20 2025 from https:\/\/www.beyondidentity.com\/blog\/great-resignation-impact-on-company-security"},{"issue":"3","key":"e_1_3_2_22_2","first-page":"13","article-title":"Biometric authentication: A review","volume":"2","author":"Bhattacharyya Debnath","year":"2009","unstructured":"Debnath Bhattacharyya, Rahul Ranjan, Farkhod Alisherov, Minkyu Choi, et\u00a0al. 2009. Biometric authentication: A review. International Journal of u-and e-Service, Science, and Technology 2, 3 (2009), 13\u201328.","journal-title":"International Journal of u-and e-Service, Science, and Technology"},{"key":"e_1_3_2_23_2","volume-title":"Cyber Security Metrics and Measures","author":"Black Paul","year":"2009","unstructured":"Paul Black, Karen Scarfone, and Murugiah Souppaya. 2009. Cyber Security Metrics and Measures. John Wiley and Sons, Inc., Hoboken, NJ, Nebraska. Retrieved from https:\/\/tsapps.nist.gov\/publication\/get_pdf.cfm?pub_id=51292"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.5555\/800253.807736"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74800-7_9"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1201\/9781498710411-35"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.5555\/2817912.2817913"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.5555\/2206269"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2899751"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/11766155_14"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/1179529.1179539"},{"key":"e_1_3_2_32_2","volume-title":"OASIS Service Provisioning Markup Language (SPML) Version 2","author":"Cole Gary","year":"2005","unstructured":"Gary Cole. 2005. OASIS Service Provisioning Markup Language (SPML) Version 2. Committee Draft 1.0 pstc-spml2-cd-01. OASIS. Retrieved from https:\/\/docs.oasis-open.org\/provision\/spml-2.0-cd-01\/pstc-spml2-cd-01.pdf"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3381991.3395597"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23268"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.5555\/3767870.3767875"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1504\/ijict.2014.063220"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/3407023.3407059"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/52.476284"},{"key":"e_1_3_2_39_2","unstructured":"Elimity. 2020. KPI-driven approach to Identity and Access Management\u2014A guide to maximize the value of IAM. Retrieved January 20 2025 from https:\/\/elimity.com\/kpi-driven-approach-to-iam-guide"},{"key":"e_1_3_2_40_2","first-page":"349","volume-title":"Proceedings of the Software Engineering Research and Practice","author":"Elliott Aaron","year":"2010","unstructured":"Aaron Elliott and Scott Knight. 2010. Role explosion: Acknowledging the problem. In Proceedings of the Software Engineering Research and Practice. CSREA Press, Las Vegas, Nevada, 349\u2013355."},{"key":"e_1_3_2_41_2","unstructured":"European Commission. 2016. General Data Protection Regulation. Retrieved from https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/501978.501980"},{"key":"e_1_3_2_43_2","unstructured":"FIRST. 2019. CVSS v3.1 Specification Document. Retrieved January 20 2025 from https:\/\/www.first.org\/cvss\/specification-document"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2021.102916"},{"key":"e_1_3_2_45_2","first-page":"1","volume-title":"Proceedings of the European Conference on Information Systems (ECIS)","author":"Fuchs Ludwig","year":"2014","unstructured":"Ludwig Fuchs, Michael Kunz, and G\u00fcnther Pernul. 2014. Role model optimization for secure role-based identity management. In Proceedings of the European Conference on Information Systems (ECIS). AIS, Tel Aviv, Israel, 1\u201315. Retrieved from https:\/\/epub.uni-regensburg.de\/30394\/"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2007.145"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89862-7_24"},{"key":"e_1_3_2_48_2","first-page":"1322","volume-title":"Proceedings of the 16th European Conference on Information Systems (ECIS 2008), Galway, Ireland, June 9-11, 2008","author":"Fuchs Ludwig","year":"2008","unstructured":"Ludwig Fuchs and G\u00fcnther Pernul. 2008. proROLE: A process-oriented lifecycle model for role systems. In Proceedings of the 16th European Conference on Information Systems (ECIS 2008), Galway, Ireland, June 9-11, 2008. Springer, Berlin, 1322\u20131333. Retrieved from https:\/\/aisel.aisnet.org\/ecis2008\/111"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.22667\/JOWUA.2010.06.31.014"},{"key":"e_1_3_2_50_2","unstructured":"Inc. Gartner. 17.05.2021. Gartner Forecasts Worldwide Security and Risk Management Spending to Exceed $150 Billion in 2021. Retrieved January 20 2025 from https:\/\/www.gartner.com\/en\/newsroom\/press-releases\/2021-05-17-gartner-forecasts-worldwide-security-and-risk-managem"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","unstructured":"Martin D. Gibbs. 2010. Biometrics: Body odor authentication perception and acceptance. ACMSIGCAS Computers and Society 40 4 (2010) 16\u201324. DOI:10.1145\/1929609.1929612","DOI":"10.1145\/1929609.1929612"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12599-023-00830-x"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22444-7_8"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.5555\/140207"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.6028\/nist.sp.800-63b"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-86586-3_1"},{"key":"e_1_3_2_57_2","first-page":"13","volume-title":"Proceedings of the Fourteenth Symposium on Usable Privacy and Security (SOUPS 2018)","author":"Habib Hana","year":"2018","unstructured":"Hana Habib, Pardis Emami Naeini, Summer Devlin, Maggie Oates, Chelse Swoopes, Lujo Bauer, Nicolas Christin, and Lorrie Faith Cranor. 2018. User behaviors and attitudes under password expiration policies. In Proceedings of the Fourteenth Symposium on Usable Privacy and Security (SOUPS 2018). USENIX Association, Baltimore, MD, 13\u201330. Retrieved from https:\/\/www.usenix.org\/conference\/soups2018\/presentation\/habib-password"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/PRDC.2013.39"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1186\/s40294-014-0005-9"},{"key":"e_1_3_2_60_2","first-page":"1121","volume-title":"Proceedings of the 2013 36th International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO)","author":"Hajdarevic Kemal","year":"2013","unstructured":"Kemal Hajdarevic and Pat Allen. 2013. A new method for the identification of proactive information security management system metrics. In Proceedings of the 2013 36th International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO). IEEE, Opatija, Croatia, 1121\u20131126."},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1197\/jamia.M2143"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1016\/S1363-4127(04)00014-7"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","unstructured":"Dick Hardt. 2012. The OAuth 2.0 Authorization Framework. DOI:10.17487\/RFC6749","DOI":"10.17487\/RFC6749"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.accinf.2013.09.002"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/3148238"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1147\/sj.382.0472"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3433174.3433585"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.6028\/nist.sp.800-162"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.6028\/nist.ir.7316"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.IR.7874"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.5220\/0006557702330240"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1186\/s13635-016-0043-2"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/SERVICES-2.2008.24"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3347495"},{"key":"e_1_3_2_75_2","unstructured":"ISACA. 2018. Introducing COBIT 2019 Overview. Retrieved January 20 2025 from https:\/\/www.isaca.org\/resources\/cobit"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/CIS.2011.6169137"},{"key":"e_1_3_2_77_2","volume-title":"Radiofrequency Identification of Animals","author":"14223 ISO","year":"2018","unstructured":"ISO 14223. 2018. Radiofrequency Identification of Animals. International Organization for Standardization."},{"key":"e_1_3_2_78_2","volume-title":"IT Security and Privacy\u2014A Framework for Identity Management","author":"24760 ISO","year":"2019","unstructured":"ISO 24760. 2019. IT Security and Privacy\u2014A Framework for Identity Management. International Organization for Standardization."},{"key":"e_1_3_2_79_2","volume-title":"Systems and Software Engineering\u2014Systems and software Quality Requirements and Evaluation (SQuaRE)\u2014System and Software Quality Models","author":"25010 ISO","year":"2011","unstructured":"ISO 25010. 2011. Systems and Software Engineering\u2014Systems and software Quality Requirements and Evaluation (SQuaRE)\u2014System and Software Quality Models. International Organization for Standardization."},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.5555\/3235838.3235865"},{"key":"e_1_3_2_81_2","first-page":"1","volume-title":"Proceedings of the 16th Symposium on Usable Privacy and Security (SOUPS 2020)","author":"Jayakrishnan Gokul Chettoor","year":"2020","unstructured":"Gokul Chettoor Jayakrishnan, Gangadhara Reddy Sirigireddy, Sukanya Vaddepalli, Vijayanand Banahatti, Sachin Premsukh Lodha, and Sankalp Suneel Pandit. 2020. Passworld: A serious game to promote password awareness and diversity in an enterprise. In Proceedings of the 16th Symposium on Usable Privacy and Security (SOUPS 2020). USENIX Association, online, 1\u201318. Retrieved from https:\/\/www.usenix.org\/conference\/soups2020\/presentation\/jayakrishnan"},{"issue":"1","key":"e_1_3_2_82_2","first-page":"71","article-title":"The balanced scorecard\u2013measures that drive performance","volume":"1","author":"Kaplan Robert S.","year":"1992","unstructured":"Robert S. Kaplan and David P. Norton. 1992. The balanced scorecard\u2013measures that drive performance. Havard Business Review 1, 1 (1992), 71\u201379. Retrieved from https:\/\/hbr.org\/1992\/01\/the-balanced-scorecard-measures-that-drive-performance-2","journal-title":"Havard Business Review"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1145\/3003733.3003764"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-37586-6_14"},{"key":"e_1_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2022.103301"},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-27668-7_4"},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2018.11.004"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom.2012.153"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.28945\/479"},{"key":"e_1_3_2_90_2","doi-asserted-by":"publisher","DOI":"10.1080\/10447318.2018.1455307"},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7642"},{"key":"e_1_3_2_92_2","volume-title":"A Role Based Framework for Distributed Systems Management","author":"Lupu Emil Constantin","year":"1998","unstructured":"Emil Constantin Lupu. 1998. A Role Based Framework for Distributed Systems Management. Ph. D. Dissertation. University of London London, England."},{"key":"e_1_3_2_93_2","doi-asserted-by":"publisher","DOI":"10.1109\/CISIM.2010.5643698"},{"key":"e_1_3_2_94_2","first-page":"13","volume-title":"Proceedings of the 13th Symposium on Usable Privacy and Security (SOUPS 2017)","author":"Mayer Peter","year":"2017","unstructured":"Peter Mayer, Jan Kirchner, and Melanie Volkamer. 2017. A second look at password composition policies in the wild: Comparing samples from 2010 and 2016. In Proceedings of the 13th Symposium on Usable Privacy and Security (SOUPS 2017). USENIX Association, Santa Clara, CA, 13\u201328. Retrieved from https:\/\/www.usenix.org\/conference\/soups2017\/technical-sessions\/presentation\/mayer"},{"key":"e_1_3_2_95_2","first-page":"66","volume-title":"Proceedings of the 11th Internationale Tagung Wirtschaftsinformatik, Leipzig, Germany, February 27 \u2013 March 1, 2013","author":"Meier Stefan","year":"2013","unstructured":"Stefan Meier, Ludwig Fuchs, and G\u00fcnther Pernul. 2013. Managing the access grid\u2014A process view to minimize insider misuse risks. In Proceedings of the 11th Internationale Tagung Wirtschaftsinformatik, Leipzig, Germany, February 27 \u2013 March 1, 2013. AIS, Leipzig, Germany, 66. Retrieved from http:\/\/aisel.aisnet.org\/wi2013\/66"},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2011.87"},{"key":"e_1_3_2_97_2","doi-asserted-by":"publisher","DOI":"10.1037\/h0043158"},{"key":"e_1_3_2_98_2","doi-asserted-by":"publisher","DOI":"10.1109\/FiCloud.2016.26"},{"key":"e_1_3_2_99_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICAI50593.2020.9311361"},{"key":"e_1_3_2_100_2","doi-asserted-by":"publisher","DOI":"10.1145\/1377836.1377840"},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.forsciint.2019.01.046"},{"key":"e_1_3_2_102_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-S65789.2025.00052"},{"key":"e_1_3_2_103_2","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359172"},{"key":"e_1_3_2_104_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSA.2014.6950490"},{"key":"e_1_3_2_105_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSA.2017.8251778"},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1109\/MobileCloud.2016.22"},{"key":"e_1_3_2_107_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC4120"},{"key":"e_1_3_2_108_2","doi-asserted-by":"publisher","DOI":"10.1145\/2470654.2470701"},{"key":"e_1_3_2_109_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-98385-1_12"},{"key":"e_1_3_2_110_2","doi-asserted-by":"publisher","DOI":"10.1109\/52.582974"},{"key":"e_1_3_2_111_2","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2003.819611"},{"key":"e_1_3_2_112_2","doi-asserted-by":"publisher","DOI":"10.2307\/25148790"},{"key":"e_1_3_2_113_2","doi-asserted-by":"publisher","DOI":"10.3390\/cryptography2010001"},{"key":"e_1_3_2_114_2","volume-title":"Identity and Access Management: Business Performance Through Connected Intelligence","author":"Osmanoglu Ertem","year":"2013","unstructured":"Ertem Osmanoglu. 2013. Identity and Access Management: Business Performance Through Connected Intelligence. Elsevier, Waltham, MA, USA."},{"key":"e_1_3_2_115_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12599-012-0230-8"},{"key":"e_1_3_2_116_2","doi-asserted-by":"publisher","DOI":"10.1145\/3533703"},{"key":"e_1_3_2_117_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2006.94"},{"key":"e_1_3_2_118_2","unstructured":"Andreas Pfitzmann and Marit Hansen. 2010. A terminology for talking about privacy by data minimization: Anonymity unlinkability undetectability unobservability pseudonymity and identity management. Retrieved from https:\/\/dud.inf.tu-dresden.de\/literatur\/Anon_Terminology_v0.34.pdf"},{"key":"e_1_3_2_119_2","doi-asserted-by":"publisher","DOI":"10.1145\/505248.506010"},{"key":"e_1_3_2_120_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCC.2015.2404816"},{"key":"e_1_3_2_121_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-29272-4_7"},{"key":"e_1_3_2_122_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22479-0_12"},{"key":"e_1_3_2_123_2","doi-asserted-by":"publisher","DOI":"10.5220\/0010315706110618"},{"key":"e_1_3_2_124_2","volume-title":"Security Assertion Markup Language (SAML) V2.0 Technical Overview","author":"Ragouzis Nick","year":"2008","unstructured":"Nick Ragouzis, John Hughes, Rob Philpott, Eve Maler, Paul Madsen, and Tom Scavo. 2008. Security Assertion Markup Language (SAML) V2.0 Technical Overview. Committee Draft 02 sstc-saml-tech-overview-2.0-cd-02. OASIS. Retrieved from https:\/\/www.oasis-open.org\/committees\/download.php\/27819\/sstc-saml-tech-overview-2.0-cd-02.pdf"},{"key":"e_1_3_2_125_2","doi-asserted-by":"publisher","DOI":"10.1145\/3664476.3670935"},{"key":"e_1_3_2_126_2","volume-title":"eXtensible Access Control Markup Language (XACML) Version 3.0","author":"Rissanen Erik","year":"2013","unstructured":"Erik Rissanen. 2013. eXtensible Access Control Markup Language (XACML) Version 3.0. OASIS Standard XACML-V3.0. OASIS. Retrieved from http:\/\/docs.oasis-open.org\/xacml\/3.0\/xacml-3.0-core-spec-os-en.pdf"},{"key":"e_1_3_2_127_2","doi-asserted-by":"publisher","DOI":"10.1109\/MPRV.2008.22"},{"key":"e_1_3_2_128_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-79026-8_30"},{"key":"e_1_3_2_129_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2889996"},{"key":"e_1_3_2_130_2","first-page":"1","volume-title":"Proceedings of the 12th Symposium on Usable Privacy and Security (SOUPS 2016)","author":"Ruoti Scott","year":"2016","unstructured":"Scott Ruoti and Kent Seamons. 2016. Standard metrics and scenarios for usable authentication. In Proceedings of the 12th Symposium on Usable Privacy and Security (SOUPS 2016). USENIX Association, Denver, CO, 1\u20132. Retrieved from https:\/\/www.usenix.org\/conference\/soups2016\/workshop-program\/way2016\/presentation\/ruoti_metrics"},{"key":"e_1_3_2_131_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3061589"},{"key":"e_1_3_2_132_2","unstructured":"Nat Sakimura John Bradley Michael B. Jones Breno de Medeiros and Chuck Mortimore. 2014. OpenID Connect Core 1.0 incorporating errata set 1. Retrieved from https:\/\/openid.net\/specs\/openid-connect-core-1_0.html"},{"key":"e_1_3_2_133_2","unstructured":"Mathias Sall\u00e9. 2004. IT Service Management and IT Governance: Review Comparative Analysis and their Impact on Utility Computing. Retrieved from https:\/\/www.hpl.hp.com\/techreports\/2004\/HPL-2004-98.pdf"},{"key":"e_1_3_2_134_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45608-2_3"},{"key":"e_1_3_2_135_2","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2006.103"},{"key":"e_1_3_2_136_2","doi-asserted-by":"publisher","DOI":"10.1016\/S0065-2458(08)60206-5"},{"key":"e_1_3_2_137_2","doi-asserted-by":"publisher","DOI":"10.1109\/35.312842"},{"key":"e_1_3_2_138_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10485-5_7"},{"key":"e_1_3_2_139_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-020-00490-y"},{"key":"e_1_3_2_140_2","doi-asserted-by":"publisher","DOI":"10.1145\/2428955.2429004"},{"key":"e_1_3_2_141_2","doi-asserted-by":"publisher","DOI":"10.1080\/10580530.2020.1738601"},{"key":"e_1_3_2_142_2","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-55v1"},{"key":"e_1_3_2_143_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11219-006-7600-8"},{"key":"e_1_3_2_144_2","doi-asserted-by":"publisher","DOI":"10.1109\/APAQS.2001.990036"},{"key":"e_1_3_2_145_2","first-page":"1","volume-title":"Proceedings of the 13th Symposium on Usable Privacy and Security (SOUPS 2017)","author":"Segreti Sean M.","year":"2017","unstructured":"Sean M. Segreti, William Melicher, Saranga Komanduri, Darya Melicher, Richard Shay, Blase Ur, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, and Michelle L. Mazurek. 2017. Diversify to survive: Making passwords stronger with adaptive policies. In Proceedings of the 13th Symposium on Usable Privacy and Security (SOUPS 2017). USENIX Association, Santa Clara, CA, 1\u201312. Retrieved from https:\/\/www.usenix.org\/conference\/soups2017\/technical-sessions\/presentation\/segreti"},{"key":"e_1_3_2_146_2","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3341492"},{"key":"e_1_3_2_147_2","doi-asserted-by":"publisher","DOI":"10.1145\/3007204"},{"key":"e_1_3_2_148_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICICNIS64247.2024.10823273"},{"key":"e_1_3_2_149_2","doi-asserted-by":"publisher","DOI":"10.1145\/2304656.2304659"},{"key":"e_1_3_2_150_2","doi-asserted-by":"publisher","DOI":"10.1145\/253769.253804"},{"key":"e_1_3_2_151_2","unstructured":"Mark Thomas. 2021. Using ITIL 4 and COBIT 2019 to create an integrated I&T Framework. Retrieved from https:\/\/www.axelos.com\/resource-hub\/white-paper\/using-itil-cobit-2019-create-integrated-environment"},{"key":"e_1_3_2_152_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2018.04.006"},{"key":"e_1_3_2_153_2","unstructured":"United States Congress. 2002. Sarbanes-Oxley Act of 2002. Corporate responsibility. Retrieved from https:\/\/www.congress.gov\/107\/plaws\/publ204"},{"key":"e_1_3_2_154_2","first-page":"179","volume-title":"Quality Metrics for Business Process Models","author":"Vanderfeesten Irene","year":"2007","unstructured":"Irene Vanderfeesten, Jorge Cardoso, Jan Mendling, Hajo A. Reijers, and Wil Aalst, van der. 2007. Quality Metrics for Business Process Models. Future Strategies, Lighthouse Point, Florida, USA, 179\u2013190."},{"key":"e_1_3_2_155_2","doi-asserted-by":"publisher","DOI":"10.1007\/11751595_106"},{"key":"e_1_3_2_156_2","doi-asserted-by":"publisher","DOI":"10.1145\/2639189.2639218"},{"key":"e_1_3_2_157_2","doi-asserted-by":"publisher","DOI":"10.1145\/3168389"},{"key":"e_1_3_2_158_2","doi-asserted-by":"publisher","DOI":"10.1145\/240455.240479"},{"key":"e_1_3_2_159_2","doi-asserted-by":"publisher","DOI":"10.1109\/69.404034"},{"key":"e_1_3_2_160_2","doi-asserted-by":"publisher","DOI":"10.1080\/07421222.1996.11518099"},{"key":"e_1_3_2_161_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2017.04.030"},{"issue":"1","key":"e_1_3_2_162_2","first-page":"166","article-title":"Privacy and freedom","volume":"25","author":"Westin Alan F.","year":"1968","unstructured":"Alan F. Westin. 1968. Privacy and freedom. Washington and Lee Law Review 25, 1 (1968), 166.","journal-title":"Washington and Lee Law Review"},{"key":"e_1_3_2_163_2","volume-title":"Digital Identity: Unmasking Identity Management Architecture (IMA)","author":"Windley Phillip J.","year":"2005","unstructured":"Phillip J. Windley. 2005. Digital Identity: Unmasking Identity Management Architecture (IMA). O\u2019Reilly Media, Inc., Sebastopol, CA."},{"key":"e_1_3_2_164_2","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(05)70282-8"},{"key":"e_1_3_2_165_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363191"},{"key":"e_1_3_2_166_2","doi-asserted-by":"publisher","DOI":"10.1145\/2295136.2295173"},{"key":"e_1_3_2_167_2","volume-title":"Mining Meaningful Role-Based and Attribute-Based Access Control Policies","author":"Xu Zhongyuan","year":"2014","unstructured":"Zhongyuan Xu. 2014. Mining Meaningful Role-Based and Attribute-Based Access Control Policies. Ph. D. Dissertation. State University of New York at Stony Brook."},{"key":"e_1_3_2_168_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCES48766.2020.9137964"},{"key":"e_1_3_2_169_2","doi-asserted-by":"publisher","DOI":"10.18151\/7217537"},{"key":"e_1_3_2_170_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC4512"},{"key":"e_1_3_2_171_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3220030"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3788858","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,12]],"date-time":"2026-02-12T10:24:06Z","timestamp":1770891846000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3788858"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,11]]},"references-count":170,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3788858"],"URL":"https:\/\/doi.org\/10.1145\/3788858","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,11]]},"assertion":[{"value":"2023-08-21","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-01-08","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-02-11","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}