<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Yavor Todorov</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Maritime Cyber(in)security: A Growing Threat Imperils EU Countries</style></title><secondary-title><style face="normal" font="default" size="100%">Connections: The Quarterly Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">awareness</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity challenges</style></keyword><keyword><style  face="normal" font="default" size="100%">frameworks</style></keyword><keyword><style  face="normal" font="default" size="100%">harmonization</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">Maritime Security</style></keyword><keyword><style  face="normal" font="default" size="100%">norms</style></keyword><keyword><style  face="normal" font="default" size="100%">resilience</style></keyword><keyword><style  face="normal" font="default" size="100%">training</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2021</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2021</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">20</style></volume><pages><style face="normal" font="default" size="100%">73-91</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The massive incorporation of advanced information and communication technologies in ships, ports, traffic, and cargo management increases efficiencies but also creates vulnerabilities. Various malicious actors are willing to exploit access through the cyber domain to gain certain benefits. This article examines cyber risks and threats in the maritime cyber domain and reviews applicable European, US, and international norms, standards, and frameworks aiming to promote cybersecurity. The author outlines six lines of effort focusing on information sharing, awareness raising, certification, and resilience. </style></abstract><issue><style face="normal" font="default" size="100%">3</style></issue><section><style face="normal" font="default" size="100%">73</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Emma Van Goethem</style></author><author><style face="normal" font="default" size="100%">Marleen Easton</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Public-Private Partnerships for Information Sharing in the Security Sector:  What’s in It for Me?</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">benefits</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">public-private partnerships</style></keyword><keyword><style  face="normal" font="default" size="100%">security sector</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2021</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2021</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">48</style></volume><pages><style face="normal" font="default" size="100%">21-35</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p style=&quot;margin-left:19.85pt;&quot;&gt;There is little research on public-private information sharing partnerships within the security sector and the benefits it may bring to both sectors. This contribution uses insights from previous research on the benefits of public-private partnerships from organisational science, information management, innovation economics, and technology studies to examine whether they are also valid within the security sector. In a first phase, this analytical framework is used to screen insights from partners involved in triple-helix collaboration in the field of innovation, technology and security. In a second phase, in-depth interviews are conducted with public and private actors involved in setting up a pilot project where information exchange is central. The research results show that traditional benefits such as increased effectiveness, efficiency, improved relationships, creation of learning opportunities and obtaining a strategic, operational, and/or economic advantage that were found in other contexts are also confirmed in the security sector. In addition, Belgian security actors saw improved decision-making and service delivery, increased personnel safety and a more integrated security chain as potential benefits. Understanding these benefits may facilitate the design of future public-private partnerships in the security sector.&lt;/p&gt;</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue><section><style face="normal" font="default" size="100%">21</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Jyri Rajamäki</style></author><author><style face="normal" font="default" size="100%">Vasilis Katos</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Information Sharing Models for Early Warning Systems of Cybersecurity Intelligence</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">case study</style></keyword><keyword><style  face="normal" font="default" size="100%">Cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">early warning system</style></keyword><keyword><style  face="normal" font="default" size="100%">ECHO</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing models</style></keyword><keyword><style  face="normal" font="default" size="100%">trust models</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2020</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2020</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">46</style></volume><pages><style face="normal" font="default" size="100%">198-214</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">An Early Warning System (EWS) for cybersecurity intelligence will provide the capability to share information to provide up to date information to all constituents involved in the EWS. The development of EWSs will be rooted in a comprehensive review of information sharing and trust models from within the cyber domain as well as models from other domains. This article is the result of a qualitative multiple-case study analysis. It consists of theory development by systematic reviews of academic articles, seven case studies, and cross-case conclusions, from which a set of system requirements and features were established to support a model that promotes information sharing among partners, while also meeting regulatory requirements. Moreover, the final analysis includes the requirements for information sharing within and between partners across organisational boundaries as derived from multi-sector analysis. The study consists of a comprehensive review of information sharing and trust models from within the cyber domain (n &gt; 50), as well as models from other domains, such as healthcare, maritime and critical infrastructure protection.</style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><section><style face="normal" font="default" size="100%">198</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Jyri Rajamäki</style></author><author><style face="normal" font="default" size="100%">Ilkka Tikanmäki</style></author><author><style face="normal" font="default" size="100%">Jari Räsänen</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">CISE as a Tool for Sharing Sensitive Cyber Information in Maritime Domain</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">early warning</style></keyword><keyword><style  face="normal" font="default" size="100%">ECHO project</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">maritime surveillance</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year></dates><volume><style face="normal" font="default" size="100%">43</style></volume><pages><style face="normal" font="default" size="100%">215-235</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The ECHO project aims at organizing and coordinating an approach to strengthen proactive cyber security in the European Union through effective and efficient multi-sector collaboration. One important tool for this aim is the ECHO Early Warning System (E-EWS). The development of the E-EWS will be rooted in a comprehensive review of information sharing and trust models from within the cyber domain, as well as models from other domains. In 2009, the Commission adopted a Communication Towards the integration of maritime surveillance in the EU: “A common information sharing environment for the EU maritime domain (CISE),” setting out guiding principles towards its establishment. The aim of the COM(2010)584 final was to generate a situational awareness of activities at sea and impact overall maritime safety and security. As a outcome of COM(2010)584 final, the EUCISE2020 project has developed a test-bed for maritime information sharing. This case study analyses information sharing models in the maritime domain, the EUCISE2020 test bed and the CISE itself as an alternative for cyber information sharing system. The maritime sector represents a suitable research case because it is already digitized in many aspects. </style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><section><style face="normal" font="default" size="100%">215</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Jussi Simola</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Comparative Research of Cybersecurity Information Sharing Models</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">cooperation</style></keyword><keyword><style  face="normal" font="default" size="100%">Early Warnings</style></keyword><keyword><style  face="normal" font="default" size="100%">ECHO project</style></keyword><keyword><style  face="normal" font="default" size="100%">indicators</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year></dates><volume><style face="normal" font="default" size="100%">43</style></volume><pages><style face="normal" font="default" size="100%">175-195</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;Cyber threats are on the increase. Authorities need to respond to growing challenges by increasing cooperation. Information sharing or information exchange in the EU level and between the countries is a main facility when the objective is to prevent hybrid threats. Intensifying relationships with private sector companies has become very important function and operating model to authorities to provide cyber-safe atmosphere. The main purpose of this study is to find out separating and combining factors concerning cyber information sharing models. The aim is also to find out nation level factors, which affect the utilization of a common Early Warning system by the ECHO stakeholders.&lt;/p&gt;&lt;p&gt;&lt;em&gt;Summary of findings&lt;/em&gt;: unclear allocation of responsibilities in national government departments prevents authorities from fighting together against cyber and physical threats. Cybersecurity responsibilities have been spread too widely. Operational work concerning cyber threat prevention between European public safety authorities should be more standardized, with more centralized management. When the purpose is to protect vital functions of society, public safety organizations in EU member states need proactive features in their information systems. An essential factor in information exchange is the place of registration of organizations or companies. Unclear standardization concerning cyber emergency procedures between authorities and organizations and lack of co-operation between cyber situation centres and cyber emergency response centres prevent common situational awareness.&lt;/p&gt;</style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><section><style face="normal" font="default" size="100%">175</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Jouni Pöyhönen</style></author><author><style face="normal" font="default" size="100%">Viivi Nuojua</style></author><author><style face="normal" font="default" size="100%">Martti Lehto</style></author><author><style face="normal" font="default" size="100%">Jyri Rajamäki</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Cyber Situational Awareness and Information Sharing in Critical Infrastructure Organizations</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Critical Infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">Cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword><keyword><style  face="normal" font="default" size="100%">vital societal functions</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year></dates><volume><style face="normal" font="default" size="100%">43</style></volume><pages><style face="normal" font="default" size="100%">236-256</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Cybersecurity-related capabilities play an ever-growing role in national security, as well as securing the functions vital to society. The national cyber capability includes the resilience of companies running critical infrastructures, their cyber situational awareness (SA) and the sharing of cybersecurity information required for cyber SA. As critical infrastructures become more complex and interdependent, ramifications of incidents multiply. The EU Network and Information Security Directive calls for cybersecurity collaboration between EU member states regarding critical infrastructures and places the most crucial service providers and digital service providers under security-related obligations. Developing better SA requires information sharing between the different interest groups and enhances the preparation for and management of incidents. The arrangement is based on drawing correct situation-specific conclusions and, when needed, on sharing critical knowledge in the cyber networks. The target state is achieved with an efficient process that includes a three-level—strategic, operational and technical/tactical—operating model to support decision-making by utilizing national and international strengths. In the dynamic cyber environment strategic agility and speed are needed to prepare for incidents. </style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><section><style face="normal" font="default" size="100%">236</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Todor Tagarev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">DIGILIENCE - A Platform for Digital Transformation,  Cyber Security and Resilience</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">artificial intelligence</style></keyword><keyword><style  face="normal" font="default" size="100%">cooperation</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber resilience</style></keyword><keyword><style  face="normal" font="default" size="100%">Cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">DIGILIENCE</style></keyword><keyword><style  face="normal" font="default" size="100%">digital transformation</style></keyword><keyword><style  face="normal" font="default" size="100%">emerging technologies</style></keyword><keyword><style  face="normal" font="default" size="100%">human factors</style></keyword><keyword><style  face="normal" font="default" size="100%">hybrid influence</style></keyword><keyword><style  face="normal" font="default" size="100%">industry 4.0</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">intuitionist fuzzy logic</style></keyword><keyword><style  face="normal" font="default" size="100%">social networks</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year></dates><volume><style face="normal" font="default" size="100%">43</style></volume><pages><style face="normal" font="default" size="100%">7-10</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;The ongoing digital transformation requires significant investments and innovation to provide security of cyberspace and variety of critical infrastructures and essential services that increasingly depend on the digital infrastructure, as well as to enhance the resilience of organizations, communities, industries, nations, and alliances in the face of malicious use of cyberspace.&lt;/p&gt;&lt;p&gt;This volume presents 28 of the papers, accepted for presentation at the DIGILIENCE 2019 conference, dealing with cyber information sharing and situational awareness, the benefits and challenges of emerging technologies, such as artificial intelligence, the human factor, education and training for cyber security and resilience, the need to incorporate the cybersecurity efforts into the search for effective and efficient exploitation of information technologies, policies and solutions for security and resilience of Industry 4.0 and critical infrastructures, analysing and countering hybrid influence through social networks and more traditional media. The DIGILIENCE series of conferences will promote the sharing of knowledge and experience and facilitate the spread of good practice in IT governance, cyber security and resilience.&lt;/p&gt;</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Vasil Rizov</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Information Sharing for Cyber Threats</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">cyber security</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber threat</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber threat information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">Information Security</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2018</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2018</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">39</style></volume><pages><style face="normal" font="default" size="100%">43-50</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;An organization that has faced an attack acquires valuable information on cyber threats that may be shared with others. This information can help an organization to identify, assess, monitor, and respond to cyber threats. Organizations that share cyber threat information can improve their own security postures as well as those of other organizations. Information sharing among private and public entities is a powerful mechanism to better understand a constantly changing environment and learn in a holistic way about serious risks, vulnerabilities and threats, as well as solutions. This article provides a review of the benefits and challenges of coordinating and sharing cyber threat information, the strengths and weaknesses of different information sharing models, and the importance of building trust between actors and handling sensitive or classified information. Organizations have to establish information sharing goals and scope of information sharing activities, identify cyber threat information sources, develop rules that control the distribution of threat information, and make effective use of threat information in support of their overall cyber security practices.&lt;/p&gt;</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue><section><style face="normal" font="default" size="100%">43</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Frederic Jordan</style></author><author><style face="normal" font="default" size="100%">Geir Hallingstad</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Towards Multi-National Capability Development in Cyber Defence</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">CERT</style></keyword><keyword><style  face="normal" font="default" size="100%">correlation infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">distributed sensor networks</style></keyword><keyword><style  face="normal" font="default" size="100%">experimentation</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">NATO Computer Incident Response Capability</style></keyword><keyword><style  face="normal" font="default" size="100%">NCIRC</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword><keyword><style  face="normal" font="default" size="100%">validation</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2011</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2011</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">27</style></volume><pages><style face="normal" font="default" size="100%">81-89</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">With NATO and the NATO Nations being heavily dependent on their communication and information systems, ensuring their proper operation is a critical task. Establishing appropriate cyber defence capabilities is a major endeavour and one which a lot of nations are currently putting increased focus on. The multi-national approach to cyber defence capability development presented in this paper is an approach to leverage the common interest nations have in this area to efficiently develop high-quality capabilities through cooperation and coordination. The paper goes on to present initial topics where the approach could be immediately leveraged, including information sharing, situational awareness, and distributed sensor collection and coordination capabilities. The paper concludes that this way forward could significantly improve our cyber defence capabilities and contribute to the overall security of the Alliance</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record></records></xml>