English
Related papers

Related papers: Security Incident Response Criteria: A Practitione…

200 papers

As cyber threats increasingly exploit human behaviour, technical controls alone cannot ensure organisational cybersecurity (CS). Strengthening cybersecurity culture (CSC) is vital in safety-critical industries, yet empirical research in…

Computers and Society · Computer Science 2025-08-29 Tita Alissa Bach , Linn Pedersen , Maria Kinck Borén† , Lisa Christoffersen Temte†

Software security vulnerabilities can lead to severe consequences, making early detection essential. Although code review serves as a critical defense mechanism against security flaws, relevant feedback remains scarce due to limited…

Software Engineering · Computer Science 2026-01-06 Zixiao Zhao , Yanjie Jiang , Hui Liu , Kui Liu , Lu Zhang

In the process industry, the configuration of Safety Instrumented Systems (SIS) must comply with a defined set of safety requirements, typically documented in the Safety Requirements Specification (SRS). The functional safety standard IEC…

Systems and Control · Electrical Eng. & Systems 2025-03-19 Hamid Jahanian

Security reputation metrics (aka. security metrics) quantify the security levels of organization (e.g., hosting or Internet access providers) relative to comparable entities. They enable benchmarking and are essential tools for decision and…

Cryptography and Security · Computer Science 2023-02-15 Maciej Korczyński , Arman Noroozian

The increasing frequency and sophistication of software supply chain attacks pose severe risks to critical infrastructure sectors, threatening national security, economic stability, and public safety. Despite growing awareness, existing…

Software Engineering · Computer Science 2025-10-31 Liming Dong , Sung Une Lee , Zhenchang Xing , Muhammad Ejaz Ahmed , Stefan Avgoustakis

Smart contracts have been plagued by security incidents, which resulted in substantial financial losses. Given numerous research efforts in addressing the security issues of smart contracts, we wondered how software practitioners build…

Software Engineering · Computer Science 2021-03-30 Zhiyuan Wan , Xin Xia , David Lo , Jiachi Chen , Xiapu Luo , Xiaohu Yang

Research in information security has generally focused on providing a comprehensive interpretation of threats, vulnerabilities, and attacks, in particular to evaluate their danger and prioritize responses accordingly. Most of the current…

Cryptography and Security · Computer Science 2014-11-04 Gustavo Gonzalez-Granadillo , Christophe Ponchel , Gregory Blanc , Hervé Debar

Dependence on information, including for some of the world's largest organisations such as governments and multi-national corporations, has grown rapidly in recent years. However, reports of information security breaches and their…

Computers and Society · Computer Science 2016-06-14 Craig A. Horne , Atif Ahmad , Sean B. Maynard

With the advent of wide security platforms able to express simultaneously all the policies comprising an organization's global security policy, the problem of inconsistencies within security policies become harder and more relevant. We have…

Logic in Computer Science · Computer Science 2007-05-23 Carlos Ribeiro , Andre Zuquete , Paulo Ferreira , Paulo Guedes

In times of Industry 4.0 and cyber-physical systems (CPS) providing security is one of the biggest challenges. A cyber attack launched at a CPS poses a huge threat, since a security incident may affect both the cyber and the physical world.…

Cryptography and Security · Computer Science 2019-05-16 Igor Ivkic , Andreas Mauthe , Markus Tauber

Risk is the best known and perhaps the best studied example within a much broader class of cyber security metrics. However, risk is not the only possible cyber security metric. Other metrics such as resilience can exist and could be…

Cryptography and Security · Computer Science 2015-12-31 Zachary A. Collier , Mahesh Panwar , Alexander A. Ganin , Alex Kott , Igor Linkov

As physical and information security boundaries have become increasingly blurry many organizations are experiencing challenges with how to effectively and efficiently manage security within the corporate. There is no current standard or…

Cryptography and Security · Computer Science 2010-02-10 Syed , M. Rahman , Shannon E. Donahue

Pipeline bursting, production lines shut down, frenzy traffic, trains confrontation, nuclear reactor shut down, disrupted electric supply, interrupted oxygen supply in ICU - these catastrophic events could result because of an erroneous…

Cryptography and Security · Computer Science 2020-01-10 Geeta Yadav , Kolin Paul

Recent trends in the software engineering (i.e., Agile, DevOps) have shortened the development life-cycle limiting resources spent on security analysis of software designs. In this context, architecture models are (often manually) analyzed…

Software Engineering · Computer Science 2019-10-09 Katja Tuma , Christian Sandberg , Urban Thorsson , Mathias Widman , Riccardo Scandariato

The paper examines quantitative assessment of wireless distribution system security, as well as an assessment of risks from attacks and security violations. Furthermore, it describes typical security breach and formal attack models and five…

Cryptography and Security · Computer Science 2019-06-27 Volodymyr Buriachok , Volodymyr Sokolov , Pavlo Skladannyi

Insider threats are one of today's most challenging cybersecurity issues that are not well addressed by commonly employed security solutions. Despite several scientific works published in this domain, we argue that the field can benefit…

Cryptography and Security · Computer Science 2019-04-16 Ivan Homoliak , Flavio Toffalini , Juan Guarnizo , Yuval Elovici , Martín Ochoa

Real-Time systems are essential for promptly responding to external stimuli and completing tasks within predefined time constraints. Ensuring high reliability and robust security in these systems is therefore critical. This requires…

Cryptography and Security · Computer Science 2025-10-07 Eliron Rahimi , Kfir Girstein , Roman Malits , Avi Mendelson

Evaluating the effectiveness of security awareness and training programs is critical for minimizing organizations' human security risk. Based on a literature review and industry interviews, we discuss current practices and devise guidelines…

Cryptography and Security · Computer Science 2021-12-14 Asangi Jayatilaka , Nathan Beu , Irina Baetu , Mansooreh Zahedi , M. Ali Babar , Laura Hartley , Winston Lewinsmith

Industrial Control Systems (ICSs) are widely used in critical infrastructures that face various cyberattacks causing physical damage. With the increasing integration of the ICSs and information technology (IT), ensuring the security of ICSs…

Optimization and Control · Mathematics 2024-12-17 Navid Aftabi , Dan Li , Ph. D. , Thomas Sharkey , Ph. D

Small and medium-sized enterprises (SME) have become the weak spot of our economy for cyber attacks. These companies are large in number and often do not have the controls in place to prevent successful attacks, respectively are not…

Computers and Society · Computer Science 2020-07-17 Alireza Shojaifar , Samuel A. Fricker , Martin Gwerder