<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>RiskFlows { Continuous Risk-driven Work ows and Decision Support in Information Security Management Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Michael Brunner</string-name>
          <email>michael.brunner@uibk.ac.at</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Innsbruck, Institute of Computer Science Research Group Quality Engineering 6020 Innsbruck</institution>
          ,
          <country country="AT">Austria</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Information Security Management Systems (ISMS) aim at ensuring proper protection of information values and information processing systems (i.e. assets). Information Security Risk Management (ISRM) techniques are incorporated to deal with threats and vulnerabilities that impose risks to information security properties of these assets. Considering the evolution of information systems as well as more demanding security requirements, enterprises have to e ciently deal with changes to their assets, their risk exposure and the impact of these changes to their ISMS and ISRM activities. Current approaches are not well-suited for enterprises facing information security challenges from continuously evolving systems, diverse requirements regarding information security properties and regular changes to their assets and threat landscape. In our PhD thesis we will develop a continuous risk-driven approach to model and enact work ows in ISMS where security risks and derived controls are managed in a collaborative fashion. In this paper we present the problem statement, research goals, the applied methodology and expected contribution of our PhD thesis.</p>
      </abstract>
      <kwd-group>
        <kwd>Information Security Management Systems</kwd>
        <kwd>Information Security Risk Management</kwd>
        <kwd>Risk Modeling</kwd>
        <kwd>Process Automation</kwd>
        <kwd>Decision Support</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Information Security Management Systems (ISMS) aim at ensuring proper
protection of information values and information systems regarding their con dentiality,
integrity and availability. These information values and information processing
systems are commonly referred to as assets and managing an asset model (or
at least an inventory of all relevant assets) is a fundamental requirement for
ISMS. Information Security Risk Management (ISRM) techniques are used to
systematically identify security risks of these assets, analyzing and evaluating
them and nding proper means to treat risks to information security. Most
standards and best practices in the area of ISMS, ISRM and also Governance,
Risk and Compliance Management (GRC) recognize the need to react to changes
of the assets involved and the overall risk landscape an enterprise faces [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ].
The current practice, that is mandated by industry standards in this eld, is to
follow an audit-driven course of action and to reassess information security risks
annually or when signi cant changes are planned (e.g., the ISO 27k family of
standards [
        <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
        ]). This naturally gives rise to challenges from e ciently dealing
with changes to relevant asset models and related risks, especially in larger
enterprises where multiple stakeholders are involved or even external parties have
to be taken into account [
        <xref ref-type="bibr" rid="ref5 ref6">5, 6</xref>
        ].
      </p>
      <p>
        Enterprises have been catching up on information security during the past ve
years and most of them have established a risk-based cybersecurity framework [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
A major weakness is still their inability to reliably evaluate their actual risk
exposure and to manage security controls from both a business and technology
perspective. Another weakness is the mendable handling of the evolution of
systems within information security management and risk assessment. These
gaps in research and industrial practice have been recently asserted by the
NIS Platform [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. Furthermore, the current trends towards more exible service
supply chains, increasing usage of distributed services and an overall increasing
complexity regarding information system composition call for a more dynamic
and continuous approach to deal with risk in ISMS [
        <xref ref-type="bibr" rid="ref10 ref9">9, 10</xref>
        ].
      </p>
      <p>A continuous approach has the potential to dynamically address such changes,
providing decision support for involved stakeholders, o ering automated ways to
enact collaborative ISMS and ISRM work ows, or automating (parts of) common
risk management tasks. Automation capabilities could range from work ow
enactment as reaction to changes to completely automating risk assessment tasks.
Ultimately, this includes enforcing appropriate security controls without direct
stakeholder participation. Where stakeholder involvement is needed suitable
techniques are to be employed that ensure that work load for individuals is
minimized and collaboration between stakeholders is structured e ciently. We
plan to develop a continuous ISMS approach that addresses the tight coupling
of the three dimensions (1) change handling, (2) work ow automation, and (3)
stakeholder collaboration.</p>
      <p>
        This PhD thesis will follow a design-science research approach [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] to develop
a framework for continuous risk-driven work ows and decision support in ISMS
to address current challenges with regard to changes of the system under
investigation, the operational environment and the actual threat landscape. The
nal goal is to provide a general framework that establishes support for highly
automated work ows to identify risks, analyze them and choose appropriate risk
treatments in accordance with con gurable information security policies.
      </p>
    </sec>
    <sec id="sec-2">
      <title>State of the Art</title>
      <p>
        Many standards and best practices in the area of information security management
(e.g., ISO 27001 [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], Common Criteria for Information Security Evaluation [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], IT
Baseline Protection Catalogues [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], ITIL [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], COBIT [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]) require the de nition
and establishment of risk management processes. Typically ISMS standards do
not o er clear direction towards the risk assessment methodology that should be
applied and merely state requirements regarding documentation artifacts and
the design of the risk management process.
      </p>
      <p>
        The coupling between security requirements, security controls and risk
management generated di erent solutions to model risk and derive security controls
as means of risk mitigation. Risk assessment captures methods and techniques
aiming at identi cation of risks, analyzing their causes and consequences and
estimating their probability and impact [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. On one side, approaches such as
the Failure Mode and E ect Analysis (FMEA), Hazard and Operability Study
(HAZOP) or Preliminary Hazard Analysis (PHA) tend to rely heavily on
stakeholder knowledge. The used models of investigated assets, vulnerabilities and
threats are more simplistic, do not always model interrelations precisely, and
therefore require less e ort upfront. On the opposite side more formal techniques
for risk assessment stem from tree-based approaches (e.g., fault tree analysis,
attack trees) or utilize probabilistic methods (e.g., Markov Chains, Monte Carlo
Simulation) and thus require more detailed models. Techniques such as the
Cyber Security Modeling Language (CySeMoL) [
        <xref ref-type="bibr" rid="ref16 ref17">16, 17</xref>
        ] or ISMS-CORAS [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]
put special attention to model risks in the scope of whole enterprises based
on speci c enterprise architecture models. The downside of these approaches is
that detailed enterprise models are a prerequisite and that the use of prede ned
model elements is enforced, which might not be compatible with already existing
enterprise architecture modeling initiatives.
      </p>
      <p>
        Approaches dealing with changes of systems and threat scenarios
primarily target traceability aspects, e.g., within and between risk models and asset
models and additionally address the detection of model changes. Consequently,
inconsistencies introduced by changes and modularization of security analysis
as counteraction have been investigated for certain areas such as access control
or the domain of safety engineering [
        <xref ref-type="bibr" rid="ref10 ref19">10, 19</xref>
        ]. The utility of this approaches for
ISRM in a collaborative environment with multiple stakeholders being involved
have not yet been demonstrated.
      </p>
      <p>
        Looking into business processes and work ow management Suriadi et al. [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]
give an overview of existing risk-based approaches. Basically, frameworks such as
presented in [21{23] employ a notion of risk to monitor and analyze work ows
and work ow instances, but do not use risk as a work ow controlling entity.
Instead they combine a risk management cycle with process modeling tasks with
the ultimate goal to incorporate risk monitoring into process execution.
      </p>
      <p>
        Collaborative security management has been thoroughly researched in the
past years [
        <xref ref-type="bibr" rid="ref24 ref25">24, 25</xref>
        ]. Although these approaches address issues from and within
collaborative processes to manage information security and also partly cover
aspects from risk assessment, they do not establish means for automation or
risk-based work ows.
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>Research Objective and Questions</title>
      <p>The research objective of this PhD thesis is to develop a solution for continuous
risk-driven ISMS that is (1) capable of systematically handling changes within
asset and risk models, (2) provides suitable automation facilities to reduce costs
and (3) e ciently organizes stakeholder collaboration. We envision a general
framework that establishes support for highly automated work ows to identify
risks, analyze them and choose appropriate risk treatments (thus risk-driven).
The primary goal is to enable enterprises to react to relevant changes of the
threat landscape or their operational environment faster than existing approaches
allow them to. Our solution will consist of a framework and the implementation
of an accompanying software tool.</p>
      <p>To achieve our overarching goal we will provide answers to the following
research questions:
{ RQ1: Which automation techniques are used in ISRM within
enterprises operating an ISMS? We want to shed light into the risk
management techniques employed by enterprises that operate an ISMS and better
understand why and how certain tasks are automated and others are not. This
will help us to better understand the prerequisites (e.g., processes, models,
data sources) for successful automation in ISRM.
{ RQ2: What are work ows to systematically deal with change for
continuous risk-driven ISMS? Since we aim at developing a continuous
approach it is of utter importance to e ciently deal with changes to the
asset and risk model. Considering that a fully automated approach is not
always possible or desired, we will develop a selection of work ows to deal
with change including e ective organization of stakeholder collaboration.
{ RQ3: Which individual ISRM tasks bene t the most from
enhanced automation within a continuous risk-driven ISMS? Our goal
is to develop a continuous risk-driven ISMS and we aim at increasing the
automation of risk management tasks. Currently we see the most promising
tasks being automated risk estimation (de ning probability and impact for
individual risks) and risk treatment (e.g., instantiation of security controls).
However, we also want to research automation possibilities for other ISRM
tasks and how well they fare within a continuous ISMS.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Research Design and Methodology</title>
      <p>
        To answer our research questions and to reach our overarching goal we will
conceptualize a framework and build an accompanying software tool to enable automated
work ows and decision support based on continuous risk management for ISMS {
RiskFlows. We will follow the principles of design science research [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. Where
aspects of Human Computer Interaction (HCI) are involved, we will incorporate
notions of concept-driven interaction design research methodology [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ].
4.1
      </p>
      <sec id="sec-4-1">
        <title>Planned Tasks</title>
        <p>As rst part of our work we will conduct two surveys: (1) a structured literature
review concerning the current state of automated approaches in risk management
which are used by or at least suitable for ISMS and (2) a survey of current
industrial practice regarding automation in risk management of information
security management. The survey regarding current industrial practice is planned
as online questionnaire. Performing these surveys ensures adherence to the
principals of problem relevance and research rigor demanded by design science
research. These surveys will help us answering RQ1 and the results will also
provide a suitable classi cation schema and a referential framework to assess
identi ed approaches. Furthermore, we will conduct expert interviews to derive
key use cases for automation support together with their related activities,
involved stakeholders and develop functional requirements for these use cases.</p>
        <p>
          The results of the conducted surveys will be incorporated into our RiskFlows
framework. The framework will constitute of partaking stakeholders/roles,
process models, required documentation artifacts and an applicable risk analysis
methodology to best support automation and decision support for the envisioned
application context. The framework itself will be tool-agnostic and the prime
design artifact of our work (following the design science principle of providing an
artifact) and provide answers for RQ2 and RQ3. Furthermore, we will de ne a
prioritized set of use cases for our framework, evaluation criteria regarding support
for each individual use case and maturity of their realization in preparation for
the next tasks. As evaluation criteria we will develop a set of Key Performance
Indicators (KPI) [
          <xref ref-type="bibr" rid="ref27">27</xref>
          ]. We plan on extending and verifying the evaluation criteria
by means of expert interviews with professionals from academia and industry.
        </p>
        <p>In order to demonstrate the utility, quality and e ciency of our RiskFlows
framework we will implement an accompanying tool and then examine the
applicability of our approach via a near-life usage scenario. This usage scenario
will be developed in close cooperation with industry partners. The nal stage of
our work will be a evaluation of RiskFlows. We will perform the evaluation based
on previously identi ed use cases and the developed KPIs. The prototype together
with the near-life usage scenario will be provided to experts from academia and
industry for this evaluation. The evaluation results will be used to re ect upon
the devised framework and point out possible future enhancements.
4.2</p>
      </sec>
      <sec id="sec-4-2">
        <title>Proposed Solution RiskFlows</title>
        <p>As prerequisite for RiskFlows we require enterprises to provide an asset model of
the system under investigation that is tightly coupled with the actual realization
of these systems. These asset models will be automatically imported and updated
from (potentially multiple) available data sources such as enterprise architecture
models and con guration management databases. Starting from this asset model,
our approach will automatically steer and enact ISMS-related work ows and
ensure proper and timely cooperation between stakeholders. Our focal point will
be put on processes for risk assessment, including the areas of risk identi cation,
analysis and evaluation.</p>
        <p>RiskFlows will consume/interface the aforementioned asset model of the
system under investigation and a threat model providing the threat landscape
to be examined. Changes to the system under investigation (e.g., integration of
new IT service, addition of infrastructure components, roll-out of new software
version) as well as changes to the threat landscape (e.g., new exploits identi ed,
additional incidents detected) will be continuously monitored. When relevant
changes emerge, RiskFlows will enact prede ned work ows that trigger
corresponding risk-assessment activities (e.g., update risk probability/impact, enforce
risk mitigation strategy) that are either performed fully automatic or relapse to a
semi-automatic solution where stakeholder participation is stipulated. RiskFlows
will ensure proper integration of stakeholders where needed and provide them
with the required dataset to make informed decisions regarding risk evaluation
and risk treatment.</p>
        <sec id="sec-4-2-1">
          <title>Asset Model</title>
        </sec>
        <sec id="sec-4-2-2">
          <title>Information Security Goals and Controls</title>
        </sec>
        <sec id="sec-4-2-3">
          <title>Risk Assessment</title>
          <p>- Risk Identification
based on threat and
vulnerability catalogs
- Risk Estimation and</p>
          <p>Evaluation based on
configurable criteria
- Reassessment of
related assets
2
1
4</p>
          <p>Threat Description
Security Misconfiguration:
No or insufficient Security
Configuration defined and
deployed for Database
Unpatched Vulnerabilities:
Critical patches have not been
applied to Database</p>
        </sec>
        <sec id="sec-4-2-4">
          <title>Risk Model</title>
          <p>Risk Value
I
m
p
a
c
t
I
m
p
a
c
t</p>
          <p>Probability</p>
          <p>Probability</p>
          <p>Figure 1 illustrates a simpli ed RiskFlows example: The starting point is
the addition of a new database to the asset model (1). RiskFlows detects this
change and ensures that the risk model is updated accordingly by conducting an
automatic risk assessment (2). The considered threats and vulnerabilities for the
new asset are derived from prede ned catalogs and instantiated. RiskFlows then
estimates and evaluates these risks in accordance with the con gured criteria for
impact and probability of each risk. Due to assets being connected with each
other this step might require the reassessment of risks from connected assets as
well. Following the risk assessment RiskFlows will instantiate additional security
controls to address newly identi ed risks (3). Finally RiskFlows will re-evaluate
risks when controls have been successfully implemented (4).</p>
          <p>To achieve this, we will provide a tailored risk assessment methodology that
supports automated risk identi cation based on asset and threat models as well
as automated estimation of risk impact and probability. Typically impact will be
derived from the business side whereas probability for certain risks will highly
depend on technical matters. Taking complex multi-layered asset models into
account, our methodology will o er guidance on how to decompose risk impact
from the business layer down to the infrastructure layer and o er means to
condense probabilities from more technical layers upwards to the business layer in
return. As example, the business impact from reduced availability of an IT service
must be decomposed in a way that the fraction of the impact resulting from
required infrastructure components (e.g., servers running parts of the IT service)
can be estimated. On the other hand, the probability of failing infrastructure
components must be condensed upward such that a veridic estimation of the
dependent IT service not meeting the availability constraints can be made. In
order to con gure these aspects we will develop a formal information security
policy language that will be used to de ne the behavior of RiskFlows.</p>
          <p>
            We will place our approach within the normative references of the standards
ISO 27001 [
            <xref ref-type="bibr" rid="ref4">4</xref>
            ], regarding information security management and ISO 27005 [
            <xref ref-type="bibr" rid="ref3">3</xref>
            ]
for information security risk management to ensure compatibility with current
industry standards. RiskFlows will be conceptualized and eventually realized as
extension of ADAMANT [
            <xref ref-type="bibr" rid="ref28">28</xref>
            ] which at its current state provides basic ISMS
functionality regarding the management of security requirements and controls as
well as preliminary work ow support. RiskFlows will enhance ADAMANT by
addition of the risk management features (including automated risk assessment)
and risk-driven work ows.
4.3
          </p>
          <p>Expected Contribution and Current State of the PhD Thesis
With our survey we will be able to gain a better understanding of the prevailing
ISRM approaches used by ISMS practitioners and their suitability for automating
work ows or providing decision support in ISMS. This should prove useful for a
wider audience since the current scienti c exploration of the industrial practice
regarding RM techniques used in information security management is highly
fragmented. With RiskFlows we will provide a novel risk-driven approach to
model and enact work ows in ISMS where information security risks and derived
controls are continuously managed as opposed to the audit-driven course of action
utilized by most enterprises at the moment. We will provide the conceptual
framework as well as a prototypical implementation to interested parties for
further evaluation. Furthermore, we will use the evaluation of RiskFlows to show
that a continuous approach underpinned by automated work ow enactment is
better suited to tackle core ISMS and ISRM tasks.</p>
          <p>At the time of writing we are preparing and conducting initial surveys and
expert interviews providing the basis for our future work on the
conceptualization of the RiskFlows framework. Furthermore, we are implementing required
enhancements for ADAMANT such as support for modeling risks, associated
work ows and import mechanisms for asset models form multiple data sources.
5</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Conclusion</title>
      <p>With our PhD thesis we intend to leverage the fundamentals for a continuous
risk-driven approach to model and enact work ows in ISMS where security risks
and derived controls are managed in a continuous fashion. Our ultimate goal is
to enable enterprises to immediately and adequately react to relevant changes
in threat landscape and the operational environment. Therefore, our approach
emphasizes automation of ISMS work ows, especially the potentially automated
risk evaluation and risk treatment for the system under investigation.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>H.</given-names>
            <surname>Abbas</surname>
          </string-name>
          et al. \
          <article-title>Addressing dynamic issues in information security management"</article-title>
          .
          <source>In: Information Management &amp; Computer Security 19.11</source>
          (
          <year>2013</year>
          ), pp.
          <volume>5</volume>
          {
          <fpage>24</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>D. W.</given-names>
            <surname>Straub</surname>
          </string-name>
          and
          <string-name>
            <given-names>R. J.</given-names>
            <surname>Welke</surname>
          </string-name>
          . \
          <article-title>Coping with systems risk: Security planning models for management decision making"</article-title>
          .
          <source>In: MIS Quarterly 22.44</source>
          (
          <year>1998</year>
          ), pp.
          <volume>441</volume>
          {
          <fpage>469</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3. ISO. ISO/IEC 27005:
          <article-title>Information technology { Security Techniques { Information security risk management</article-title>
          .
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4. ISO. ISO/IEC 27001:
          <article-title>Information technology { Security techniques { Information security management system {</article-title>
          <source>Requirements</source>
          .
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>S.</given-names>
            <surname>Thalmann</surname>
          </string-name>
          et al. \
          <article-title>Challenges in Cross-Organizational Security Management"</article-title>
          .
          <source>In: System Science (HICSS)</source>
          ,
          <year>2012</year>
          45th Hawaii International Conference on (
          <year>2012</year>
          ), pp.
          <volume>5480</volume>
          {
          <fpage>5489</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>R. P.</given-names>
            <surname>Tracy</surname>
          </string-name>
          . \
          <article-title>IT Security Management and Business Process Automation: Challenges, Approaches, and Rewards"</article-title>
          .
          <source>In: Information Systems Security</source>
          <volume>16</volume>
          .22 (
          <year>2007</year>
          ), pp.
          <volume>114</volume>
          {
          <fpage>122</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7. PWC.
          <source>The Global State of Information Security R Survey</source>
          <year>2016</year>
          .
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <given-names>NIS</given-names>
            <surname>Platform</surname>
          </string-name>
          .
          <article-title>State-of-the-</article-title>
          <source>Art of Secue ICT Landscape</source>
          .
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <given-names>D.</given-names>
            <surname>Bachlechner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Thalmann</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Maier</surname>
          </string-name>
          . \
          <article-title>Security and compliance challenges in complex IT outsourcing arrangements: A multi-stakeholder perspective"</article-title>
          .
          <source>In: Computers &amp; Security</source>
          <volume>40</volume>
          (
          <year>2014</year>
          ), pp.
          <volume>38</volume>
          {
          <fpage>59</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10. A.
          <string-name>
            <surname>Borek</surname>
          </string-name>
          et al. \
          <article-title>Managing information risks in asset management - Experiences from an in-depth case study in the utility industry"</article-title>
          .
          <source>In: Asset Management Conference</source>
          <year>2011</year>
          ,
          <article-title>IET and IAM (</article-title>
          <year>2011</year>
          ), pp.
          <volume>1</volume>
          {
          <fpage>6</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>A. R. Hevner</surname>
          </string-name>
          et al. \
          <article-title>Design science in Information Systems research"</article-title>
          .
          <source>In: MIS Quarterly 28.11</source>
          (
          <year>2004</year>
          ), pp.
          <volume>75</volume>
          {
          <fpage>105</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <article-title>The Common Criteria Recognition Agreement Members</article-title>
          .
          <source>Common Criteria for Information Technology Security Evaluation</source>
          .
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <article-title>German Federal O ce for Information Security</article-title>
          . IT Baseline Protection Catalogues.
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>J. O. Long. ITIL R</surname>
          </string-name>
          <year>2011</year>
          at a Glance.
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15. IT Governance Institute.
          <article-title>COBIT 5: A Business Framework for the Governance and Management of Enterprise IT</article-title>
          .
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16. H.
          <string-name>
            <surname>Holm</surname>
          </string-name>
          et al. \
          <article-title>CySeMoL: A tool for cyber security analysis of enterprises"</article-title>
          .
          <source>In: Electricity Distribution (CIRED</source>
          <year>2013</year>
          ), 22nd International Conference and Exhibition on (
          <year>2013</year>
          ), pp.
          <volume>1</volume>
          {
          <fpage>4</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17. T. Sommestad,
          <string-name>
            <given-names>M.</given-names>
            <surname>Ekstedt</surname>
          </string-name>
          , and
          <string-name>
            <given-names>H.</given-names>
            <surname>Holm</surname>
          </string-name>
          . \
          <article-title>The Cyber Security Modeling Language: A Tool for Assessing the Vulnerability of Enterprise System Architectures"</article-title>
          .
          <source>In: Systems Journal, IEEE 7.33</source>
          (
          <year>2013</year>
          ), pp.
          <volume>363</volume>
          {
          <fpage>373</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>K. Beckers</surname>
          </string-name>
          et al. \
          <article-title>ISMS-CORAS: A Structured Method for Establishing an ISO 27001 Compliant Information Security Management System."</article-title>
          <source>In: Engineering Secure Future Internet Services and Systems</source>
          <volume>8431</volume>
          (
          <year>2014</year>
          ), pp.
          <volume>315</volume>
          {
          <fpage>344</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19. L.
          <string-name>
            <surname>Montrieux</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Wermelinger</surname>
            , and
            <given-names>Y.</given-names>
          </string-name>
          <string-name>
            <surname>Yu</surname>
          </string-name>
          . \
          <article-title>Challenges in model-based evolution and merging of access control policies"</article-title>
          .
          <source>In: the 12th international workshop and the 7th annual ERCIM workshop</source>
          (
          <year>2011</year>
          ), pp.
          <volume>116</volume>
          {
          <fpage>120</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20. S. Suriadi et al. \
          <article-title>Current research in risk-aware business process management : overview, comparison, and gap analysis"</article-title>
          . In: School of Electrical Engineering &amp; Computer Science; School of Information Systems; Science &amp; Engineering
          <string-name>
            <surname>Faculty</surname>
          </string-name>
          (
          <year>2014</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <given-names>S.</given-names>
            <surname>Betz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Hickl</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Oberweis</surname>
          </string-name>
          . \
          <article-title>Risk-Aware Business Process Modeling and Simulation Using XML Nets"</article-title>
          .
          <source>In: Commerce and Enterprise Computing (CEC)</source>
          ,
          <source>2011 IEEE 13th Conference on (2011)</source>
          , pp.
          <volume>349</volume>
          {
          <fpage>356</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <given-names>R.</given-names>
            <surname>Conforti</surname>
          </string-name>
          et al. \
          <article-title>A software framework for risk-aware business process management"</article-title>
          . In: Institute for Future Environments; School of Information Systems; Science &amp; Engineering
          <string-name>
            <surname>Faculty</surname>
          </string-name>
          (
          <year>2013</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <given-names>S.</given-names>
            <surname>Tjoa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Jakoubi</surname>
          </string-name>
          , and
          <string-name>
            <surname>G. Quirchmayr.</surname>
          </string-name>
          \
          <article-title>Enhancing Business Impact Analysis and Risk Assessment Applying a Risk-Aware Business Process Modeling and Simulation Methodology"</article-title>
          .
          <source>In: 2008 Third International Conference on Availability, Reliability and Security</source>
          (
          <year>2008</year>
          ), pp.
          <volume>179</volume>
          {
          <fpage>186</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>M. Hawley</surname>
          </string-name>
          et al. \
          <article-title>Collaborative Security Management: Developing Ideas in Security Management for Air Tra c Control"</article-title>
          .
          <source>In: Availability, Reliability and Security (ARES)</source>
          , 2013 Eighth International Conference on (
          <year>2013</year>
          ), pp.
          <volume>802</volume>
          {
          <fpage>806</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <given-names>F.</given-names>
            <surname>Innerhofer-Oberper er</surname>
          </string-name>
          , M. Hafner, and
          <string-name>
            <given-names>R.</given-names>
            <surname>Breu</surname>
          </string-name>
          . \
          <article-title>Living security collaborative security management in a changing world"</article-title>
          .
          <source>In: Tenth IASTED International Conference on Software Engineering SE</source>
          <year>2011</year>
          (
          <year>2011</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26. E. Stolterman and
          <string-name>
            <given-names>M.</given-names>
            <surname>Wiberg</surname>
          </string-name>
          . \
          <string-name>
            <surname>Concept-Driven Interaction</surname>
          </string-name>
          Design Research.
          <article-title>"</article-title>
          <source>In: Human-Computer Interaction 25.22</source>
          (
          <year>2010</year>
          ), pp.
          <volume>95</volume>
          {
          <fpage>118</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <string-name>
            <given-names>D.</given-names>
            <surname>Parmenter</surname>
          </string-name>
          .
          <article-title>Key Performance Indicators(KPI), developing</article-title>
          ,
          <source>implementing and using KPIs</source>
          .
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28.
          <string-name>
            <given-names>M.</given-names>
            <surname>Brunner</surname>
          </string-name>
          and
          <string-name>
            <given-names>R.</given-names>
            <surname>Breu</surname>
          </string-name>
          . \
          <article-title>IT Compliance mit kontextuellen Sicherheitsanforderungen"</article-title>
          .
          <source>In: D.A.CH Security</source>
          <year>2014</year>
          (
          <year>2014</year>
          ), pp.
          <volume>136</volume>
          {
          <fpage>147</fpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>