{"id":"https://openalex.org/W1954228917","doi":"https://doi.org/10.1109/re.2015.7320417","title":"Assessment of risk perception in security requirements composition","display_name":"Assessment of risk perception in security requirements composition","publication_year":2015,"publication_date":"2015-08-01","ids":{"openalex":"https://openalex.org/W1954228917","doi":"https://doi.org/10.1109/re.2015.7320417","mag":"1954228917"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/re.2015.7320417","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5007316441","display_name":"Hanan Hibshi","orcid":"https://orcid.org/0000-0003-0250-3616"},"institutions":[],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hanan Hibshi","raw_affiliation_strings":["Institute for Software Research, Carnegie Mellon Univeristy Pittsburgh, Pennsylvania, USA"],"affiliations":[{"raw_affiliation_string":"Institute for Software Research, Carnegie Mellon Univeristy Pittsburgh, Pennsylvania, USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5006266551","display_name":"Travis D. Breaux","orcid":"https://orcid.org/0000-0001-7127-8155"},"institutions":[{"id":"https://openalex.org/I4210111472","display_name":"King Abdul Aziz University Hospital","ror":"https://ror.org/01vv03303","country_code":"SA","type":"healthcare","lineage":["https://openalex.org/I4210111472"]}],"countries":["SA"],"is_corresponding":false,"raw_author_name":"Travis D. Breaux","raw_affiliation_strings":["College of Computing, King Abdul-Aziz University, Jeddah 21589, Saudi Arabia"],"affiliations":[{"raw_affiliation_string":"College of Computing, King Abdul-Aziz University, Jeddah 21589, Saudi Arabia","institution_ids":["https://openalex.org/I4210111472"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5084783879","display_name":"Stephen B. Broomell","orcid":"https://orcid.org/0000-0001-6983-2591"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Stephen B. Broomell","raw_affiliation_strings":["Department of Social and Decision Science , Carnegie Mellon University , Pittsburgh, Pennsylvania, USA"],"affiliations":[{"raw_affiliation_string":"Department of Social and Decision Science , Carnegie Mellon University , Pittsburgh, Pennsylvania, USA","institution_ids":["https://openalex.org/I74973139"]}]}],"institution_assertions":[],"countries_distinct_count":2,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.655,"has_fulltext":true,"fulltext_origin":"ngrams","cited_by_count":15,"citation_normalized_percentile":{"value":0.883284,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":88,"max":89},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9993,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9993,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.992,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10430","display_name":"Software Engineering Techniques and Practices","score":0.978,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/security-testing","display_name":"Security Testing","score":0.4968157},{"id":"https://openalex.org/keywords/risk-perception","display_name":"Risk Perception","score":0.4907297},{"id":"https://openalex.org/keywords/security-engineering","display_name":"Security engineering","score":0.4435557}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.59783006},{"id":"https://openalex.org/C59488412","wikidata":"https://www.wikidata.org/wiki/Q187147","display_name":"Requirements analysis","level":3,"score":0.5637863},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.5359811},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.5014291},{"id":"https://openalex.org/C195518309","wikidata":"https://www.wikidata.org/wiki/Q13424265","display_name":"Security testing","level":5,"score":0.4968157},{"id":"https://openalex.org/C163355716","wikidata":"https://www.wikidata.org/wiki/Q2154783","display_name":"Risk perception","level":3,"score":0.4907297},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.47164816},{"id":"https://openalex.org/C45384764","wikidata":"https://www.wikidata.org/wiki/Q838667","display_name":"Requirements elicitation","level":4,"score":0.46024626},{"id":"https://openalex.org/C13159133","wikidata":"https://www.wikidata.org/wiki/Q365674","display_name":"Security engineering","level":5,"score":0.4435557},{"id":"https://openalex.org/C173577280","wikidata":"https://www.wikidata.org/wiki/Q530038","display_name":"Requirements management","level":4,"score":0.43955517},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.42933124},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.41593966},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.38965222},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.3241084},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.28409746},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.2546581},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.23250446},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.22161543},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.15440425},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.13873348},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.065413475},{"id":"https://openalex.org/C169760540","wikidata":"https://www.wikidata.org/wiki/Q207011","display_name":"Neuroscience","level":1,"score":0.0},{"id":"https://openalex.org/C78519656","wikidata":"https://www.wikidata.org/wiki/Q101333","display_name":"Mechanical engineering","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/re.2015.7320417","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.73,"display_name":"Peace, justice, and strong institutions"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":23,"referenced_works":["https://openalex.org/W1482707767","https://openalex.org/W1587970460","https://openalex.org/W1730782591","https://openalex.org/W1803273808","https://openalex.org/W1874464064","https://openalex.org/W1972960241","https://openalex.org/W1980201832","https://openalex.org/W1981457167","https://openalex.org/W2054348336","https://openalex.org/W2063585450","https://openalex.org/W2069070239","https://openalex.org/W2087484885","https://openalex.org/W2107031757","https://openalex.org/W2140031625","https://openalex.org/W2162535192","https://openalex.org/W2162777455","https://openalex.org/W2167771807","https://openalex.org/W2172199324","https://openalex.org/W3210030168","https://openalex.org/W4238040396","https://openalex.org/W4300870773","https://openalex.org/W4399638940","https://openalex.org/W620450775"],"related_works":["https://openalex.org/W3173083343","https://openalex.org/W2406589135","https://openalex.org/W2397983840","https://openalex.org/W2113064318","https://openalex.org/W2047723056","https://openalex.org/W2020194669","https://openalex.org/W2013238834","https://openalex.org/W1988225931","https://openalex.org/W1662441884","https://openalex.org/W1190389589"],"abstract_inverted_index":{"Security":[0],"requirements":[1,56,69,107,131,142,158,188],"analysis":[2,125,128],"depends":[3],"on":[4,51,109,116,148],"how":[5,52,65,168],"well-trained":[6],"analysts":[7,58],"perceive":[8],"security":[9,44,55,73,86,106,112,136,149,175,187],"risk,":[10],"understand":[11],"the":[12,41,68,94,103,135,180],"impact":[13,182],"of":[14,24,43,80,105,119,129,157,183],"various":[15],"vulnerabilities,":[16],"and":[17,28,61,115,163,165],"mitigate":[18],"threats.":[19],"When":[20],"systems":[21],"are":[22],"composed":[23],"multiple":[25],"machines,":[26],"configurations,":[27],"software":[29],"components":[30],"that":[31,141],"interact":[32],"with":[33,126,172],"each":[34],"other,":[35],"risk":[36,59],"perception":[37],"must":[38],"account":[39],"for":[40,102],"composition":[42,108,143],"requirements.":[45,121,150],"In":[46,151],"this":[47,124],"paper,":[48],"we":[49,153,166,178],"report":[50],"changes":[53],"to":[54,66,70,100],"affect":[57],"perceptions":[60],"their":[62,117],"decisions":[63],"about":[64],"modify":[67],"reach":[71],"adequate":[72],"levels.":[74],"We":[75,92,122],"conducted":[76],"two":[77],"user":[78],"surveys":[79],"174":[81],"participants":[82,84],"wherein":[83],"assess":[85],"levels":[87],"across":[88],"64":[89],"factorial":[90],"vignettes.":[91],"analyzed":[93],"survey":[95],"results":[96,139],"using":[97],"multi-level":[98],"modeling":[99],"test":[101],"effect":[104],"participants'":[110],"overall":[111,173],"adequacy":[113,146],"ratings":[114,118,147],"individual":[120],"accompanied":[123],"grounded":[127],"elicited":[130],"aimed":[132],"at":[133],"lowering":[134],"risk.":[137,176],"Our":[138],"suggest":[140],"affects":[144],"experts'":[145],"addition,":[152],"identified":[154],"three":[155],"categories":[156,170],"modifications,":[159],"called":[160],"refinements,":[161],"replacements":[162],"reinforcements,":[164],"measured":[167],"these":[169],"compare":[171],"perceived":[174],"Finally,":[177],"discuss":[179],"future":[181],"our":[184],"work":[185],"in":[186],"assessment":[189],"practice.":[190]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W1954228917","counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":2},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":2},{"year":2017,"cited_by_count":1},{"year":2016,"cited_by_count":5}],"updated_date":"2025-01-04T21:31:30.304862","created_date":"2016-06-24"}