{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T08:19:54Z","timestamp":1758269994086,"version":"3.28.0"},"reference-count":33,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,7]]},"DOI":"10.1109\/qrs.2017.26","type":"proceedings-article","created":{"date-parts":[[2017,8,14]],"date-time":"2017-08-14T16:31:55Z","timestamp":1502728315000},"page":"160-167","source":"Crossref","is-referenced-by-count":13,"title":["Towards Automation in Information Security Management Systems"],"prefix":"10.1109","author":[{"given":"Michael","family":"Brunner","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Sillaber","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruth","family":"Breu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref33","article-title":"RiskFlows - Continuous Risk-driven Workflows and Decision Support in Information Security Management Systems","author":"brunner","year":"2016","journal-title":"CAiSE (Doctoral Consortium)"},{"key":"ref32","first-page":"1","article-title":"AURUM: A Framework for Information Security Risk Management","author":"ekelhart","year":"2009","journal-title":"2009 42nd Hawaii International Conference on System Sciences"},{"article-title":"The Governance Risk Management and Compliance (GRC) Landscape Part 2: Software's Integral Role in GRC Automation","year":"2008","author":"hagerty","key":"ref31"},{"key":"ref30","article-title":"Governance, Risk & Compliance (GRC) Software - An Exploratory Study of Software Vendor and Market Research Perspectives","author":"racz","year":"2011","journal-title":"2011 44th Hawaii International Conference on System Sciences (HICSS) 2011"},{"key":"ref10","article-title":"SP 800&#x2013;30","author":"stoneburner","year":"2002","journal-title":"Risk Management Guide for Information Technology Systems"},{"key":"ref11","first-page":"1","article-title":"State-of-the-Art of Secure, ICT Landscape","year":"2014","journal-title":"NIS Platform"},{"journal-title":"PWC","article-title":"The Global State of Information Security&#x00AE; Survey 2016","year":"2015","key":"ref12"},{"key":"ref13","article-title":"Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation)","volume":"l119 59","year":"2016","journal-title":"Official Journal of the European Union"},{"journal-title":"BCBS","article-title":"Basel II: International Convergence of Capital Measurement and Capital Standards: a Revised Framework","year":"2004","key":"ref14"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/EISIC.2011.39"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.153"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1108\/09685221211267639"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-126r2"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1080\/10658980601051706"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-015-0229-z"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4614-3897-7"},{"key":"ref27","article-title":"A software framework for risk-aware business process management","author":"conforti","year":"2013","journal-title":"Institute for Future Environments School of Information Systems Science & Engineering Faculty"},{"journal-title":"Federal Office for Information Security Germany","article-title":"100&#x2013;2 IT-Grundschutz Methodology","year":"2008","key":"ref3"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/508171.508187"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/RE.2012.6345794"},{"journal-title":"ISACA COBIT 5 A Business Framework for the Governance and Management of Enterprise IT ISA","year":"2012","key":"ref5"},{"journal-title":"Open Web Application Security Project","article-title":"Application Security Verification Standard","year":"2016","key":"ref8"},{"journal-title":"ISO","article-title":"ISO\/IEC 27034 - Application Security Guidline","year":"2011","key":"ref7"},{"journal-title":"The Common Criteria Recognition Agreement Members","article-title":"Common Criteria for Information Technology Security Evaluation","year":"2006","key":"ref2"},{"journal-title":"Guidelines on Security and Privacy in Public Cloud Computing","year":"2011","author":"jansen","key":"ref9"},{"journal-title":"ISO","article-title":"ISO\/IEC 27001: Information technology - Security techniques - Information security management system - Requirements","year":"2013","key":"ref1"},{"journal-title":"ISO","article-title":"ISO\/IEC 27005: Information technology - Security Techniques - Information security risk management","year":"2011","key":"ref20"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-07452-8_13"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2012.2221853"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1049\/cp.2011.0551"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1108\/09685221111115836"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/2024445.2024467"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD.2011.9"}],"event":{"name":"2017 IEEE International Conference on Software Quality, Reliability and Security (QRS)","start":{"date-parts":[[2017,7,25]]},"location":"Prague, Czech Republic","end":{"date-parts":[[2017,7,29]]}},"container-title":["2017 IEEE International Conference on Software Quality, Reliability and Security (QRS)"],"original-title":[],"link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/xplorestaging.ieee.org\/ielx7\/8008606\/8009890\/08009919.pdf?arnumber=8009919","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,9,7]],"date-time":"2017-09-07T00:39:47Z","timestamp":1504744787000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/ieeexplore.ieee.org\/document\/8009919\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,7]]},"references-count":33,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1109\/qrs.2017.26","relation":{},"subject":[],"published":{"date-parts":[[2017,7]]}}}