{"id":"https://openalex.org/W2545289138","doi":"https://doi.org/10.1093/cybsec/tyw010","title":"A grounded analysis of experts\u2019 decision-making during security assessments","display_name":"A grounded analysis of experts\u2019 decision-making during security assessments","publication_year":2016,"publication_date":"2016-10-05","ids":{"openalex":"https://openalex.org/W2545289138","doi":"https://doi.org/10.1093/cybsec/tyw010","mag":"2545289138"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyw010","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/2/2/147/10833245/tyw010.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2093","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311647","https://openalex.org/P4310311648"],"host_organization_lineage_names":["University of Oxford","Oxford University Press"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"journal-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://academic.oup.com/cybersecurity/article-pdf/2/2/147/10833245/tyw010.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5007316441","display_name":"Hanan Hibshi","orcid":"https://orcid.org/0000-0003-0250-3616"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Hanan Hibshi","raw_affiliation_strings":["Institute for Software Research, Carnegie Mellon University, Pittsburgh, PA 15213, USA"],"affiliations":[{"raw_affiliation_string":"Institute for Software Research, Carnegie Mellon University, Pittsburgh, PA 15213, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5006266551","display_name":"Travis D. Breaux","orcid":"https://orcid.org/0000-0001-7127-8155"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Travis D. Breaux","raw_affiliation_strings":["Institute for Software Research, Carnegie Mellon University, Pittsburgh, PA 15213, USA"],"affiliations":[{"raw_affiliation_string":"Institute for Software Research, Carnegie Mellon University, Pittsburgh, PA 15213, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111581160","display_name":"Maria Riaz","orcid":null},"institutions":[{"id":"https://openalex.org/I137902535","display_name":"North Carolina State University","ror":"https://ror.org/04tj63d06","country_code":"US","type":"education","lineage":["https://openalex.org/I137902535"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Maria Riaz","raw_affiliation_strings":["Department of Computer Science, North Carolina State University, Raleigh, NC 27695, USA"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, North Carolina State University, Raleigh, NC 27695, USA","institution_ids":["https://openalex.org/I137902535"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5028171895","display_name":"Laurie Williams","orcid":"https://orcid.org/0000-0003-3300-6540"},"institutions":[{"id":"https://openalex.org/I137902535","display_name":"North Carolina State University","ror":"https://ror.org/04tj63d06","country_code":"US","type":"education","lineage":["https://openalex.org/I137902535"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Laurie Williams","raw_affiliation_strings":["Department of Computer Science, North Carolina State University, Raleigh, NC 27695, USA"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, North Carolina State University, Raleigh, NC 27695, USA","institution_ids":["https://openalex.org/I137902535"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5007316441"],"corresponding_institution_ids":["https://openalex.org/I74973139"],"apc_list":{"value":1864,"currency":"USD","value_usd":1864,"provenance":"doaj"},"apc_paid":{"value":1864,"currency":"USD","value_usd":1864,"provenance":"doaj"},"fwci":2.87,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.978567,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":86,"max":87},"biblio":{"volume":null,"issue":null,"first_page":"tyw010","last_page":"tyw010"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9896,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9896,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11696","display_name":"Conflict Management and Negotiation","score":0.9225,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11121","display_name":"Public Relations and Crisis Communication","score":0.9095,"subfield":{"id":"https://openalex.org/subfields/3315","display_name":"Communication"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[],"concepts":[{"id":"https://openalex.org/C156325361","wikidata":"https://www.wikidata.org/wiki/Q1152864","display_name":"Grounded theory","level":3,"score":0.57920027},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.5049153},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.18431702},{"id":"https://openalex.org/C190248442","wikidata":"https://www.wikidata.org/wiki/Q839486","display_name":"Qualitative research","level":2,"score":0.116761476},{"id":"https://openalex.org/C36289849","wikidata":"https://www.wikidata.org/wiki/Q34749","display_name":"Social science","level":1,"score":0.06983781}],"mesh":[],"locations_count":1,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyw010","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/2/2/147/10833245/tyw010.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2093","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311647","https://openalex.org/P4310311648"],"host_organization_lineage_names":["University of Oxford","Oxford University Press"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyw010","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/2/2/147/10833245/tyw010.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2093","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311647","https://openalex.org/P4310311648"],"host_organization_lineage_names":["University of Oxford","Oxford University Press"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[{"score":0.79,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, justice, and strong institutions"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":50,"referenced_works":["https://openalex.org/W1492176525","https://openalex.org/W1496437928","https://openalex.org/W1527311855","https://openalex.org/W1528022241","https://openalex.org/W1544152542","https://openalex.org/W1570321471","https://openalex.org/W1602376808","https://openalex.org/W1624143779","https://openalex.org/W1658908529","https://openalex.org/W1662441884","https://openalex.org/W1803273808","https://openalex.org/W1874464064","https://openalex.org/W1898015721","https://openalex.org/W1954228917","https://openalex.org/W1966182711","https://openalex.org/W1982736558","https://openalex.org/W1997501517","https://openalex.org/W2007179372","https://openalex.org/W2036015710","https://openalex.org/W2037789405","https://openalex.org/W2038048606","https://openalex.org/W2039559812","https://openalex.org/W2055095549","https://openalex.org/W2064647596","https://openalex.org/W2067570705","https://openalex.org/W2074409795","https://openalex.org/W2076207454","https://openalex.org/W2082385556","https://openalex.org/W2102836011","https://openalex.org/W2113537253","https://openalex.org/W2126513753","https://openalex.org/W2138362482","https://openalex.org/W2142515939","https://openalex.org/W2146948159","https://openalex.org/W2147733013","https://openalex.org/W2150071393","https://openalex.org/W2282710216","https://openalex.org/W2325370405","https://openalex.org/W2329395632","https://openalex.org/W2411087957","https://openalex.org/W2463421347","https://openalex.org/W2738487222","https://openalex.org/W2911335841","https://openalex.org/W2971035958","https://openalex.org/W3022452870","https://openalex.org/W3150917758","https://openalex.org/W3214833809","https://openalex.org/W4230664025","https://openalex.org/W4238040396","https://openalex.org/W91877992"],"related_works":["https://openalex.org/W4361008414","https://openalex.org/W3040823075","https://openalex.org/W2748952813","https://openalex.org/W2620765995","https://openalex.org/W2109806719","https://openalex.org/W2092147963","https://openalex.org/W2054080977","https://openalex.org/W2015439768","https://openalex.org/W1546533203","https://openalex.org/W1535784397"],"abstract_inverted_index":{"Security":[0],"analysis":[1,103,220,251],"requires":[2],"specialized":[3],"knowledge":[4,63],"to":[5,18,28,44,66,88,108,126,131,135,155,193,205],"align":[6],"threats":[7,184],"and":[8,23,40,64,80,90,98,119,124,167,181,188,210,215,218,233,240,252],"vulnerabilities":[9],"in":[10,35,236],"information":[11],"technology.":[12],"To":[13,70],"identify":[14,67],"mitigations,":[15],"analysts":[16,178],"need":[17],"understand":[19,72],"how":[20,43,177,189,207,216,243],"threats,":[21],"vulnerabilities,":[22,123],"mitigations":[24],"are":[25],"composed":[26],"together":[27],"yield":[29],"security":[30,50,68,96,102,195,208,223,238,250],"requirements.":[31],"Despite":[32],"abundant":[33],"guidance":[34],"the":[36,73,92,228],"form":[37],"of":[38,76,86,95,112,230],"checklists":[39],"controls":[41],"about":[42,149,249],"secure":[45],"systems,":[46],"evidence":[47],"suggests":[48],"that":[49,152,175],"experts":[51,97,209],"do":[52],"not":[53],"apply":[54,127,212],"these":[55,190],"checklists.":[56],"Instead,":[57],"they":[58],"rely":[59],"on":[60,198],"their":[61,133],"prior":[62],"experience":[65],"vulnerabilities.":[69,137],"better":[71],"different":[74],"effects":[75],"checklists,":[77],"design":[78],"analysis,":[79,200],"expertise,":[81],"we":[82,201,241],"conducted":[83],"a":[84,128,147,186],"series":[85],"interviews":[87],"capture":[89],"encode":[91],"decision-making":[93,173,239],"process":[94],"novices":[99,211],"during":[100],"three":[101,110],"exercises.":[104],"Participants":[105],"were":[106,161],"asked":[107],"analyze":[109],"kinds":[111],"artifacts:":[113],"source":[114],"code,":[115],"data":[116],"flow":[117],"diagrams,":[118,121],"network":[120],"for":[122],"then":[125,162],"requirements":[129,224,234],"checklist":[130],"demonstrate":[132],"ability":[134],"mitigate":[136],"We":[138,226],"framed":[139],"our":[140,244],"study":[141],"using":[142,164],"Situation":[143],"Awareness,":[144],"which":[145],"is":[146],"theory":[148,166,204],"human":[150],"perception":[151],"was":[153],"used":[154],"elicit":[156],"interviewee":[157],"responses.":[158],"The":[159],"responses":[160],"analyzed":[163],"coding":[165],"grounded":[168],"analysis.":[169],"Our":[170],"results":[171],"include":[172],"patterns":[174,191],"characterize":[176],"perceive,":[179],"comprehend,":[180],"project":[182],"future":[183],"against":[185],"system,":[187],"relate":[192],"selecting":[194],"mitigations.":[196],"Based":[197],"this":[199],"discovered":[202],"new":[203,247],"measure":[206],"attack":[213],"models":[214],"structured":[217],"unstructured":[219],"enables":[221],"increasing":[222],"coverage.":[225],"highlight":[227],"role":[229],"expertise":[231],"level":[232],"composition":[235],"affecting":[237],"discuss":[242],"method":[245],"produced":[246],"hypotheses":[248],"decision-making.":[253]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2545289138","counts_by_year":[{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":2},{"year":2020,"cited_by_count":2},{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":1},{"year":2016,"cited_by_count":1}],"updated_date":"2025-01-07T06:28:12.892082","created_date":"2016-11-04"}