1. ISO/IEC 27001: Information technology. Security techniques, Information security management systems, requirements, ISO/IEC. 2013.
2. Stoneburner G, Goguen A, Feringa A. Risk management guide for Information Technology systems, NIST800-30. 2002.
3. Nakamura I, Hyodo T, Soga M, Mizuno T, Nishigaki M. A practical approach for security measure selection problem and its availability. Inf Process Soc Jpn J. 2004;45(8):2022–33 (in Japanese).
4. Onibere M, Ahmad A, Maynard S. B. The chief information security officer and the five dimensions of a strategist. In Pacific Asia conference on information systems; 2017. p. 77.
5. Cichonski P, Millar T, Grance T, Scarfone K. Computer security incident handling guide. NIST SP800-61, Rev, vol. 2; 2012.