{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:17:25Z","timestamp":1781108245774,"version":"3.54.1"},"reference-count":15,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013,1]]},"abstract":"<jats:p>The task of designing secure software systems is fraught with uncertainty, as data on uncommon attacks is limited, costs are difficult to estimate, and technology and tools are continually changing. Consequently, experts may interpret the security risks posed to a system in different ways, leading to variation in assessment. This paper presents research into measuring the variability in decision making between security professionals, with the ultimate goal of improving the quality of security advice given to software system designers. A set of thirty nine cyber-security experts took part in an exercise in which they independently assessed a realistic system scenario. This study quantifies agreement in the opinions of experts, examines methods of aggregating opinions, and produces an assessment of attacks from ratings of their components. The authors show that when aggregated, a coherent consensus view of security emerges which can be used to inform decisions made during systems design.<\/jats:p>","DOI":"10.4018\/jsse.2013010102","type":"journal-article","created":{"date-parts":[[2013,4,9]],"date-time":"2013-04-09T15:28:15Z","timestamp":1365521295000},"page":"11-30","source":"Crossref","is-referenced-by-count":9,"title":["Towards a More Systematic Approach to Secure Systems Design and Analysis"],"prefix":"10.4018","volume":"4","author":[{"given":"Simon","family":"Miller","sequence":"first","affiliation":[{"name":"Intelligent Modelling and Analysis Research Group, School of Computer Science, University of Nottingham, Nottingham, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Susan","family":"Appleby","sequence":"additional","affiliation":[{"name":"Communications-Electronics Security Group, Cheltenham, Gloucestershire, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonathan M.","family":"Garibaldi","sequence":"additional","affiliation":[{"name":"Intelligent Modelling and Analysis Research Group, School of Computer Science, University of Nottingham, Nottingham, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Uwe","family":"Aickelin","sequence":"additional","affiliation":[{"name":"Intelligent Modelling and Analysis Research Group, School of Computer Science, University of Nottingham, Nottingham, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2013010102-0","unstructured":"CESG. (2009). Extract from HMG IA standard no.1 business impact level tables. Retrieved July 9th, 2012, from http:\/\/www.cesg.gov.uk\/publications\/Documents\/business_impact_tables.pdf"},{"key":"jsse.2013010102-1","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxq059"},{"key":"jsse.2013010102-2","doi-asserted-by":"publisher","DOI":"10.1109\/TFUZZ.2002.806316"},{"issue":"2","key":"jsse.2013010102-3","doi-asserted-by":"crossref","first-page":"205","DOI":"10.1111\/j.2517-6161.1968.tb00722.x","article-title":"A generalization of Bayesian inference.","volume":"30","author":"A.Dempster","year":"1968","journal-title":"Journal of the Royal Statistical Society. Series A (General)"},{"key":"jsse.2013010102-4","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2010.06.005"},{"key":"jsse.2013010102-5","doi-asserted-by":"crossref","unstructured":"Fu, Y., Qin, Y., & Wu, X. (2008) A method of information security risk assessment using fuzzy number operations. In Proceedings of 4th International Conference on Wireless Communications, Networking and Mobile Computing (WiCOM \u201908) (pp. 1\u20134).","DOI":"10.1109\/WiCom.2008.2927"},{"key":"jsse.2013010102-6","doi-asserted-by":"publisher","DOI":"10.1109\/TFUZZ.2006.889755"},{"key":"jsse.2013010102-7","doi-asserted-by":"crossref","unstructured":"Goyette, R., & Karmouch, A. (2011). A dynamic model building process for virtual network security assessment. In Proceedings of the 2011 IEEE Pacific Rim Conference on Communications, Computers and Signal Processing (PacRim) (pp. 482-487).","DOI":"10.1109\/PACRIM.2011.6032941"},{"key":"jsse.2013010102-8","author":"H.Linstone","year":"1975","journal-title":"The Delphi method: Techniques and applications"},{"key":"jsse.2013010102-9","doi-asserted-by":"crossref","unstructured":"Miller, S., Wagner, C., Garibaldi, J. M., & Appleby, S. (2012) Constructing general type-2 fuzzy sets from interval-valued data. In Proceedings of 2012 IEEE International Conference on Fuzzy Systems (FUZZ-IEEE) (In Press).","DOI":"10.1109\/FUZZ-IEEE.2012.6251221"},{"key":"jsse.2013010102-10","doi-asserted-by":"publisher","DOI":"10.1016\/0377-2217(90)90057-I"},{"key":"jsse.2013010102-11","doi-asserted-by":"crossref","unstructured":"Sendi, A., Jabbarifar, M., Shajari, M., & Dagenais, M. (2010). FEMRA: Fuzzy expert model for risk assessment. In Proceedings of the Fifth International Conference on Internet Monitoring and Protection, (pp. 48\u201353).","DOI":"10.1109\/ICIMP.2010.15"},{"issue":"15","key":"jsse.2013010102-12","first-page":"2361","article-title":"Group decision making information security risk assessment based on AHP and information entropy.","volume":"4","author":"Z.Tan","year":"2012","journal-title":"Research Journal of Applied Sciences"},{"key":"jsse.2013010102-13","doi-asserted-by":"crossref","unstructured":"Wu, X., Fu, Y., & Wang, J. (2009). Information systems security risk assessment on improved fuzzy AHP. In Proceedings of the ISECS International Colloquium on Computing, Communication, Control, and Management (CCCM 2009) (Vol. 4, pp. 365\u2013369).","DOI":"10.1109\/CCCM.2009.5270427"},{"key":"jsse.2013010102-14","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.1973.5408575"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=76353","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,8]],"date-time":"2024-05-08T12:07:47Z","timestamp":1715170067000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2013010102"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2013,1]]},"references-count":15,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2013010102","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,1]]}}}