<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Elicitation of SME Requirements for Cybersecurity Solutions by Studying Adherence to Recommendations</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alireza Shojaifar</string-name>
          <email>a.shojaifar@uu.nl</email>
          <email>alireza.shojaifar@fhnw.ch</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Samuel A. Fricker</string-name>
          <email>samuel.fricker@bth.se</email>
          <email>samuel.fricker@fhnw.ch</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Martin Gwerder</string-name>
          <email>martin.gwerder@fhnw.ch</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Blekinge Institute of Technology, SERL-Sweden</institution>
          ,
          <addr-line>371 79 Karlskrona</addr-line>
          ,
          <country country="SE">Sweden</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>FHNW, IIT and IMVS</institution>
          ,
          <addr-line>5210 Windisch</addr-line>
          ,
          <country country="CH">Switzerland</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Utrecht University, Dept. of Information and Computing Sciences</institution>
          ,
          <addr-line>Utrecht</addr-line>
          ,
          <country country="NL">Netherlands</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2018</year>
      </pub-date>
      <abstract>
        <p>[Context and motivation] Small and medium-sized enterprises (SME) have become the weak spot of our economy for cyber attacks. These companies are large in number and often do not have the controls in place to prevent successful attacks, respectively are not prepared to systematically manage their cybersecurity capabilities. [Question/problem] One of the reasons for why many SME do not adopt cybersecurity is that developers of cybersecurity solutions understand little the SME context and the requirements for successful use of these solutions. [Principal ideas/results] We elicit requirements by studying how cybersecurity experts provide advice to SME. The experts' recommendations offer insights into what important capabilities of the solution are and how these capabilities ought to be used for mitigating cybersecurity threats. The adoption of a recommendation hints at a correct match of the solution, hence successful consideration of requirements. Abandoned recommendations point to a misalignment that can be used as a source to inquire missed requirements. Re-occurrence of adoption or abandonment decisions corroborate the presence of requirements. [Contributions] This poster describes the challenges of SME regarding cybersecurity and introduces our proposed approach to elicit requirements for cybersecurity solutions. The poster describes CYSEC, our tool used to capture cybersecurity advice and help to scale cybersecurity requirements elicitation to a large number of participating SME. We conclude by outlining the planned research to develop and validate CYSEC1.</p>
      </abstract>
      <kwd-group>
        <kwd>Small medium-sized enterprises</kwd>
        <kwd>cybersecurity</kwd>
        <kwd>requirements elicitation</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Small and medium-sized enterprises (SME) are considered as an important part of
economy specially e-driven economies [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ]. Browne et al. explain that based on EU
commission 2005, any company with fewer than 250 employees and with annual
turnover less than € 50 million can be considered as an SME [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Osborn with respect to
EU Commission report states that these SME form 99% of European businesses [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
Regarding cybercriminal point of view, the rate of cyber-attacks against SME is
considerable [
        <xref ref-type="bibr" rid="ref2 ref4">2, 4</xref>
        ]. However, many SME (regarding Kaspersky Labs reports) do not
believe and aware that they are the target of these attacks [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>
        Browne et al. explain that SME are weaker targets than big companies since small
companies have their own specific culture and behave differently regarding
cybersecurity measures [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Kuusisto and Ilvonen explain that most of considered
SME do not have documented information security policy, clearly determined security
responsibilities and security training [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Kurpjuhn states that SME give primacy to
business growth investment rather than security measures, however, the importance and
severity of malicious threats in SME are the same as big companies, although the level of
financial investment and resources for cybersecurity measures in SME are very low [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>
        It should be noted that lack of investment and budget restrictions can be two main
reasons of SME cybersecurity problems which can be originated from lack of security
awareness by SME owners and lack of cost-effective processes [
        <xref ref-type="bibr" rid="ref7 ref8">7, 8</xref>
        ]. SME may also
do not have an internal cyber security policy to reduce the possibility of cyber-attacks
[
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Xian et al. state that SME because of lack of budget, expertise and complexity of
ISRAs (Information‐security risk assessments) are not able to do ISRAs [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. Gundu
and Flowerday assert that some SME incline to concern about external threats and
neglect the security risk of uninformed employees [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. Also, small companies which
may have low levels of risk tolerance can have different approach regarding perceived
threats [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>
        These are some of studied characteristics of SME, in turn, we can conclude that the
cybersecurity approach which intend to safeguard SME against cyber-attacks should
be different with large organisations. Different research vendors have considered and
proposed some approaches, models or framework which address some of SME’s
characteristics [
        <xref ref-type="bibr" rid="ref10 ref2 ref8">10, 8, 2</xref>
        ]. Furthermore, Cholez and Girard concentrate on a method for
SME’s maturity assessment and process improvement in the context of information
security management [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. Mijnhardt et al. propose an assessment tool based on
ISFAM (Information Security Focus Area Maturity) for information security advice
for SME [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>
        However, the preceding framework and models appear to consider some of SME
characteristics, some of influential factors, or match particular SME (in specific
country). ISFAM although covers different security areas in detail, seems complicated to
apply regarding SME’s level of knowledge and expertise in cybersecurity measures.
More generally, many SME do not adopt good cybersecurity practices or abandon
such practices for a variety of reasons, such as lack of information security knowledge
and skill, lack of budget and resources, lack of security and risk awareness, and
employees with multiple roles and access [
        <xref ref-type="bibr" rid="ref10 ref8">8, 10</xref>
        ]. Thus, although there are some attempts
to alleviate the SME’s cybersecurity problems, still a lack of understanding of the
cybersecurity requirements of SME can be seen.
      </p>
    </sec>
    <sec id="sec-2">
      <title>2 Requirements Elicitation by Studying Adherence</title>
      <p>The here presented work aims at finding an effective way to elicit requirements of
SME for cybersecurity solutions. The adoption of a cybersecurity recommendation
hints at a correct match of the solution, hence successful consideration of the SME’s
context and requirements. Abandoned recommendations point to a misalignment that
can be used as a source to inquire missed requirements. Such abandoning may be due
to a variety of reasons that could point to requirements that are not satisfied by the
cybersecurity solutions. Re-occurrence of adoption or abandonment decisions across
many SME corroborate the presence of these requirements.</p>
      <p>
        There are different requirements elicitation automated tools and feedback
collection approaches such as Online ads and in-product surveys, Operational and event
data, and A/B testing [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. However, the point is that these approaches have not been
applied and evaluated in the context of cybersecurity. The new idea of our approach is
to study and mirror the approach of how cybersecurity experts provide advice to SME.
The experts’ recommendations offer insights into what important capabilities of the
solution are and how these capabilities ought to be used for mitigating cybersecurity
threats.
      </p>
      <p>
        The study of adherence is performed by following the dialogue between a
cybersecurity expert and the person in charge of cybersecurity in the SME. Such a dialogue
may be structured according to the established plan-do-check-act (PDCA) model of
process improvement [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] and be based on cybersecurity improvement frameworks
like ISFAM [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. We envision an incremental approach to cybersecurity improvement
that matches the SME context where the customer is the priority and resources scarce.
Inspired by agile development [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], we let the SME adopt cybersecurity capabilities
that the person in charge ranks in a backlog of themes according to the perceived
importance. Upon agreed timing, we let the cybersecurity expert and the SME review the
achievements and reflect on successes and failures of adopting the cybersecurity
controls. Table 1 outlines a cycle of this incremental improvement process. Although this
cycle regarding cybersecurity problem can be the same for big organizations and
SME, it can automate requirements elicitation for many more SME and we can have
many more sources for requirements.
      </p>
      <p>We expect that the study of feedback about adherence will be rich of insights that
can be used to understand the requirements for cybersecurity solutions for SME. In the
trials underlying Table 1, the SME identified controls, such as computer forensics, it
was interested in and was not offered by the cybersecurity expert. Another feedback
was that cybersecurity controls were offered that assumed an organisational structure
that did not match the SME structure. Also, users had complained that too much
unsolicited bulk emails arrive in their inboxes to initiate a change in the mail filters. For
cybersecurity solution developers, these insights will be useful for planning new
features or abandoning features that turn out to be unattractive. Some insights make
explicit the validity of assumptions about the context of cybersecurity solution use,
whether these assumptions were formulated explicitly or existed implicitly in the
minds of the developers. Other insights offer concrete recommendations for how to
adjust a control to make it useful in the SME context.</p>
      <p>To reduce the cost of employing the method and allow scaling to many SME, we
automate the dialogue and advice provision with a software that we call the
Cybersecurity Coach (CYSEC). CYSEC allows cybersecurity experts to define themes and
controls that they believe are helpful for SME. An SME can download and use
CYSEC to determine its cybersecurity capability profile, obtain recommendations for
improvement, and track the improvement success. Upon SME-defined timings,
CYSEC encourages the SME to offer feedback about the selection decisions and the
experience of implementing the selected practices. Consolidation of these
observations and feedbacks across many SME will offer the community of cybersecurity
developers and experts rich insights for evolving the solutions they are offering and
advice they are suggesting.</p>
      <p>CYSEC tool, in general, encompasses four different components: capability
advisor, good practices and tools, adherence monitor, and a bot. Capability advisor
regarding improvement model includes a questionnaire covering different cybersecurity
capabilities (such as patch management, access control, …) referencing to good
practices and SME can see their progress. Good practices and tools, provides SME with
relevant information for training and tools for download. The adherence monitor as a
goal monitor can help cybersecurity experts to evaluate their approaches. And the bot
is an interactive element for Q&amp;A through which each SME can receive feedback and
suitable answers to their questions, and to realize the SME adherence to the advice.
Through observing the SME adherence to the advice and evaluation by the
cybersecurity experts, cybersecurity requirements elicitation for the SME can be done.
However, although CYSEC has not developed yet and we aim to present the mock-up in the
poster, the first three components are based on Duolingo’s components (a successful
tool in language learning). Moreover, we include a new component (advisory
dialogue) for survey in the automated advice of SME to do requirements elicitation in the
cybersecurity context.</p>
      <p>We are developing the adherence monitoring-based requirements elicitation
method with two organisations that are experts in cybersecurity and four SME that are
interested in improving their cybersecurity capabilities. These four SME have guided
us through development process with useful information and through the discussions
we received interesting feedback regarding current frameworks. In about one year, we
open the collaboration to further cybersecurity experts and SME with an open call for
joining our work. The co-development approach allows us to understand the dialogue
between the cybersecurity expert and the SME to the extent that it can be implemented
in the CYSEC tool. The work with the experts allows us to understand important
solutions and controls that are available and how they are used to address cybersecurity
threats. The work with the SME offers us an opportunity to validate the requirements
elicitation approach and mature the CYSEC tool.</p>
    </sec>
    <sec id="sec-3">
      <title>3 Planned Research</title>
      <p>
        Wieringa’s Design Science framework [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] will be applied to conduct the research.
The framework consists of a series of studies and actions that guide the design and
validation of a method and tool like the CYSEC-enabled requirements elicitation
approach. We emphasise the problem investigation, design and validation of the
approach, and evaluation of the impact of the approach. To guide this work, our
research aims to answer the following research questions:
      </p>
      <p>RQ1. What are the hurdles and enablers of SME to adopt cybersecurity solutions?
RQ2. Can the study of adherence to cybersecurity practice be used as a method of
requirements elicitation for improving cybersecurity solutions?</p>
      <p>RQ3. Can requirements elicitation be automated by embedding the dialogue
between the cybersecurity expert and the person in charge of the SME in the CYSEC
tool?</p>
      <p>RQ4. What are the effects of the CYSEC tool-supported approach on cybersecurity
capabilities of SME and solutions that support these SME?</p>
      <p>RQ1 will be answered by collecting experiences of the collaborating SME of using
existing cybersecurity capability improvement methods. RQ2 will be answered by
observing dialogues between cybersecurity experts and persons in charge of the
collaborating SME from the perspective of requirements that can be identified in the
dialogues. The results of RQ2 will be used for designing and implementing the
CYSEC tool. RQ3 will be answered by iteratively letting SME use the CYSEC tool
and evaluating whether the tool is understood and beneficial for the SME and whether
the insights gained with the SME’s end-user feedback helps the improve the
cybersecurity solutions that were recommended to be used by CYSEC. RQ4 will be
answered by inviting a larger number of SME to a beta evaluation phase of the
CYSEC tool.</p>
      <p>The outcome of the research will be an improved understanding of the requirements
of solutions that protect SME against cyber threats. We expect that CYSEC as a tool
not only improve the SME’s adherence, knowledge, and awareness but also help
cybersecurity experts with requirements elicitation for solutions that help SME to
become secure.</p>
    </sec>
    <sec id="sec-4">
      <title>Acknowledgments</title>
      <p>This work was made possible with funding from the European Union’s Horizon
2020 research and innovation programme under grant agreement No 740787
(SMESEC) and the Swiss State Secretariat for Education‚ Research and Innovation
(SERI) under contract number 17.00067. The opinions expressed and arguments
employed herein do not necessarily reflect the official views of these funding bodies.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>C.</given-names>
            <surname>Valli</surname>
          </string-name>
          , I. Martinus,
          <string-name>
            <given-names>M.</given-names>
            <surname>Johnstone</surname>
          </string-name>
          ,
          <article-title>"Small to Medium Enterprise Cyber Security Awareness: an initial survey of Western Australian Business"</article-title>
          ,
          <source>Proceedings of the International Conference on Security and Management (SAM): The Steering Committee of The World Congress in Computer Science Computer Engineering and Applied Computing (WorldComp)</source>
          , pp.
          <fpage>1</fpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Browne</surname>
            <given-names>S</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lang</surname>
            <given-names>M</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Golden</surname>
            <given-names>W. "</given-names>
          </string-name>
          <article-title>Linking Threat Avoidance and Security Adoption: A Theoretical Model For SMEs"</article-title>
          , Bled eConference, p.
          <fpage>32</fpage>
          -
          <lpage>43</lpage>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>E.</given-names>
            <surname>Osborn</surname>
          </string-name>
          .
          <article-title>Business versus Technology: Sources of the Perceived Lack of Cyber Security in SMEs</article-title>
          . CDT in Cyber Security,
          <source>CDT Technical Paper 01/15</source>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>R.</given-names>
            <surname>Lewis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Louvieris</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Abbott</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Clewley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K</given-names>
            <surname>Jones</surname>
          </string-name>
          ,
          <article-title>"Cybersecurity information sharing: a framework for sustainable information security management in uk sme supply chains"</article-title>
          ,
          <source>Proceedings of the European Conference on Information Systems (ECIS)</source>
          <year>2014</year>
          , June 9-11,
          <year>2014</year>
          , ISBN 978-0-9915567-0-0.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Kuusisto</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Ilvonen</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          (
          <year>2003</year>
          ).
          <article-title>Information Security Culture in Small and medium size enterprises</article-title>
          .
          <source>Frontiers of e-business research</source>
          ,
          <volume>431</volume>
          -
          <fpage>439</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>T.</given-names>
            <surname>Kurpjuhn</surname>
          </string-name>
          ,
          <article-title>"The SME security challenge"</article-title>
          ,
          <source>Computer Fraud &amp; Security</source>
          , vol.
          <year>2015</year>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>5</fpage>
          -
          <lpage>7</lpage>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Zec</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Kajtazi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>Examining how IT Professionals in SMEs Take Decisions About Implementing Cyber Security Strategy</article-title>
          .
          <source>In ECIME2015-9th European Conference on IS Management and Evaluation: ECIME</source>
          <year>2015</year>
          (p.
          <fpage>231</fpage>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <given-names>S.</given-names>
            <surname>Dojkovski</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Lichtenstein</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Warren</surname>
          </string-name>
          ,
          <article-title>"Enabling information security culture: influences and challenges for Australian SMEs,"</article-title>
          <source>in ACIS 2010: Proceedings of the 21st Australasian Conference on Information Systems</source>
          , ACIS,
          <year>2010</year>
          , p.
          <fpage>61</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <given-names>Z.</given-names>
            <surname>Ng</surname>
          </string-name>
          ,
          <string-name>
            <surname>A</surname>
          </string-name>
          . Ahmad y, S. Maynard,
          <article-title>"Information Security Management: Factors that Influence Security Investments in SMES"</article-title>
          ,
          <source>Australian Information Security Management</source>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <given-names>T.</given-names>
            <surname>Gundu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. V.</given-names>
            <surname>Flowerday</surname>
          </string-name>
          ,
          <article-title>"Ignorance To Awareness: Towards An Information Security Awareness Process"</article-title>
          , vol.
          <volume>104</volume>
          , pp.
          <fpage>69</fpage>
          -
          <lpage>79</lpage>
          ,
          <year>June 2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Cholez</surname>
            , H. and
            <given-names>F.</given-names>
          </string-name>
          <string-name>
            <surname>Girard</surname>
          </string-name>
          ,
          <article-title>Maturity assessment and process improvement for information security management in small and medium enterprises</article-title>
          .
          <source>Journal of Software: Evolution and Process</source>
          ,
          <year>2014</year>
          .
          <volume>26</volume>
          (
          <issue>5</issue>
          ): p.
          <fpage>496</fpage>
          -
          <lpage>503</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <given-names>F.</given-names>
            <surname>Mijnhardt</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Baars</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Spruit</surname>
          </string-name>
          (
          <year>2016</year>
          ).
          <article-title>"Organizational characteristics influencing SME information security maturity</article-title>
          .
          <source>" Journal of Computer Information Systems</source>
          <volume>56</volume>
          ,
          <fpage>2</fpage>
          .
          <fpage>106</fpage>
          -
          <lpage>115</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>R. J. Wieringa</surname>
          </string-name>
          ,
          <article-title>Design Science Methodology for Information Systems</article-title>
          and Software Engineering:, Springer-Verlag,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.http://library.isical.ac.in:8080/jspui/bitstream/123456789/6553/1/Statistical%20method%
          <article-title>20 from%20the%20viewpoint%20of%20quality%20control</article-title>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <given-names>K.</given-names>
            <surname>Schwaber</surname>
          </string-name>
          and
          <string-name>
            <given-names>M.</given-names>
            <surname>Beedle</surname>
          </string-name>
          ,
          <article-title>Agile Software Development With Scrum</article-title>
          . Upper Saddle River, NJ: Prentice-Hall,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <given-names>A.</given-names>
            <surname>Fabijan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H. H.</given-names>
            <surname>Olsson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Bosch</surname>
          </string-name>
          ,
          <article-title>"Customer feedback and data collection techniques in software R&amp;D: A literature review" in Software Business</article-title>
          , Berlin, Germany:SpringerVerlag, vol.
          <volume>210</volume>
          , pp.
          <fpage>139</fpage>
          -
          <lpage>153</lpage>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>