<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Sergiy Dotsenko</style></author><author><style face="normal" font="default" size="100%">Oleg Illiashenko</style></author><author><style face="normal" font="default" size="100%">Sergii Kamenskyi</style></author><author><style face="normal" font="default" size="100%">Vyacheslav Kharchenko</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Integrated Model of Knowledge Management for Security of Information Technologies: Standards ISO/IEC 15408 and ISO/IEC 18045</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Information Security</style></keyword><keyword><style  face="normal" font="default" size="100%">information technologies</style></keyword><keyword><style  face="normal" font="default" size="100%">IT security</style></keyword><keyword><style  face="normal" font="default" size="100%">knowledge management</style></keyword><keyword><style  face="normal" font="default" size="100%">security standards</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year></dates><volume><style face="normal" font="default" size="100%">43</style></volume><pages><style face="normal" font="default" size="100%">305-317</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The paper presents analysis of existing knowledge management models and justification for introducing an integrated model of knowledge management for both industry and academia. It is proposed to build such a model using well-known standards of IT security – common criteria and methodology for IT security evaluation. The model of knowledge management is elaborated by analysing the content of the relevant elements of standards and establishing the knowledge content that determines the forms of relations between them. The authors propose the application of an architecture of four-factor models towards the formation of knowledge management models in the organization of the information security management system in accordance with the standards of the series ISO/ IEC 27000.</style></abstract><issue><style face="normal" font="default" size="100%">3</style></issue><section><style face="normal" font="default" size="100%">305</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>47</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Velizar Shalamanov</style></author><author><style face="normal" font="default" size="100%">Georgi Penchev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Methodology for Organizational Design of Cyber Research Networks</style></title><secondary-title><style face="normal" font="default" size="100%">DIGILIENCE 2019</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">cyber security</style></keyword><keyword><style  face="normal" font="default" size="100%">Enterprise Architecture</style></keyword><keyword><style  face="normal" font="default" size="100%">governance</style></keyword><keyword><style  face="normal" font="default" size="100%">IT security</style></keyword><keyword><style  face="normal" font="default" size="100%">management</style></keyword><keyword><style  face="normal" font="default" size="100%">modeling</style></keyword><keyword><style  face="normal" font="default" size="100%">network analysis</style></keyword><keyword><style  face="normal" font="default" size="100%">simulation</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2-4 October</style></date></pub-dates></dates><pub-location><style face="normal" font="default" size="100%">Sofia, Bulgaria</style></pub-location><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;The paper presents possible approaches for building a new network organization in the area of cybersecurity. The study is focused on selection of activities, processes and structures needed for the network governance and management. The study considers links between Enterprise Architecture approach, COBIT framework and network analysis with the task to elaborate a standard and comprehensive framework for analysis of IT related areas of organizational governance and management. Examples of NATO and EU initiatives for network organization design and implementation are explored with specific focus on ECHO project. Accreditation procedure based on participant&amp;rsquo;s self-assessment is presented.&lt;/p&gt;&lt;p&gt;This paper is included in the program of &lt;a href=&quot;https://digilience.org&quot;&gt;DIGILIENCE 2019&lt;/a&gt; and will be published in the post-conference volume.&lt;/p&gt;</style></abstract></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Predrag Tasevski</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">IT and Cyber Security Awareness – Raising Campaigns</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">awareness</style></keyword><keyword><style  face="normal" font="default" size="100%">awareness-raising</style></keyword><keyword><style  face="normal" font="default" size="100%">campaigns</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber security</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber security culture</style></keyword><keyword><style  face="normal" font="default" size="100%">IT security</style></keyword><keyword><style  face="normal" font="default" size="100%">privacy</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2016</style></year></dates><volume><style face="normal" font="default" size="100%">34</style></volume><pages><style face="normal" font="default" size="100%">7-22</style></pages><abstract><style face="normal" font="default" size="100%">Usage of technology in Macedonia has drastically expanded over the last decade. At the same time, it introduces new risks and threats to the country in cyber space. To react against those challenges in the country, there are couple of awareness-raising campaigns, brought by government and non-government actors. However, the existing campaigns are only targeting children, parents and teachers, and institutional level and privacy concerns, while forgetting the end-user. Mainly the approach, in which the awareness campaigns are designed, relies on posters, guides, tips, websites, caravans, etc. For this reason, the article briefly analyses the Macedonian IT and cyber security awareness campaigns, coupled with the background of cyber security path about IT and cyber security awareness-raising. It suggests recommendations and solutions that should be considered in order to raise the awareness level in order to provide safer, more secure and trustworthy cyber space at all levels.
</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>27</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Veselin Monev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Enterprise IT security metrics: Classification, examples and characteristics (in Bulgarian)</style></title><secondary-title><style face="normal" font="default" size="100%">IT4Sec Reports</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">characteristics</style></keyword><keyword><style  face="normal" font="default" size="100%">classification</style></keyword><keyword><style  face="normal" font="default" size="100%">company</style></keyword><keyword><style  face="normal" font="default" size="100%">expected annual lose</style></keyword><keyword><style  face="normal" font="default" size="100%">incident</style></keyword><keyword><style  face="normal" font="default" size="100%">IT security</style></keyword><keyword><style  face="normal" font="default" size="100%">management</style></keyword><keyword><style  face="normal" font="default" size="100%">matrix</style></keyword><keyword><style  face="normal" font="default" size="100%">measure</style></keyword><keyword><style  face="normal" font="default" size="100%">Metric</style></keyword><keyword><style  face="normal" font="default" size="100%">metrics</style></keyword><keyword><style  face="normal" font="default" size="100%">Risk</style></keyword><keyword><style  face="normal" font="default" size="100%">Vulnerabilities</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2014</style></year><pub-dates><date><style  face="normal" font="default" size="100%">March 2014</style></date></pub-dates></dates><number><style face="normal" font="default" size="100%">111</style></number><publisher><style face="normal" font="default" size="100%">Institute of Information and Communication Technologies</style></publisher><pub-location><style face="normal" font="default" size="100%">Sofia</style></pub-location><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The report addresses the key issues associated with measuring IT security for private companies. Several classifications of metrics are discussed focusing on the functions of different levels of security management. For the most part, this work examines the pros and cons of common metrics for measuring IT security and provides guidelines for creating own metrics. ‘Own metrics,’ adapted to the corporate environment, are those which security managers have to create and use for the purpose of effective management.</style></abstract></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Raj Gururajan</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">New Financial Transaction Security Concerns in Mobile Commerce</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">business risk</style></keyword><keyword><style  face="normal" font="default" size="100%">financial transactions</style></keyword><keyword><style  face="normal" font="default" size="100%">IT security</style></keyword><keyword><style  face="normal" font="default" size="100%">mobile commerce</style></keyword><keyword><style  face="normal" font="default" size="100%">security threats</style></keyword><keyword><style  face="normal" font="default" size="100%">technological risk</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2002</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2002</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">8</style></volume><pages><style face="normal" font="default" size="100%">71-86</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Security of transactions in Mobile Commerce is moving away from an IT concern to a Business concern because of potential loss of revenue to businesses due to lack of privacy, integrity or confidentiality, system slowdown or downtime. While most of the various security procedures are limited to corporate IT infrastructure, in mobile commerce issues concerned with transaction security appear to have extended beyond the corporate network to embrace the complete business process. Any lapse in procedures that maintain confidentiality of data or violation of privacy could affect corporate image and hence would impact customer relationships. Any adverse effect on customer relationship would negatively impact business revenue. In addition to existing security problems in a wired commerce environment, the emergence of mobile devices has renewed calls for addressing security threats to financial transactions. These problems are discussed in this paper as key issues in terms of organisation's architectural and procedural approaches to security, reliability and availability of business transactionss.</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record></records></xml>