1. The International Organization for Standardization, The International Electrotechnical Commission: ISO/IEC 27005, Information technology – Security techniques – Information security risk management. 3rd edn. ISO/IEC, Switzerland (2018)
2. Santos, J.C.S., Tarrit, K., Mirakhorli, M.: A catalog of security architecture weaknesses. In: Proceedings of 2017 IEEE International Conference on Software Architecture Workshops (ICSAW), pp. 220–223. IEEE (2017)
3. The International Organization for Standardization, The International Electrotechnical Commission: ISO/IEC 27001, Information technology – Security techniques – Information security management systems - Requirements. 2nd edn. ISO/IEC, Switzerland (2013)
4. The International Organization for Standardization, The International Electrotechnical Commission: ISO/IEC 27004, Information technology – Security techniques - Information security management - Monitoring, measurement, analysis and evaluation. 2nd edn. ISO/IEC, Switzerland (2016)
5. National Institute of Standards and Technology: NIST SP 800-55, Performance Measurement Guide for Information Security. 1st rev. NIST, USA (2008)