<?xml version="1.0" encoding="ISO-8859-1"?><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id>1646-9895</journal-id>
<journal-title><![CDATA[RISTI - Revista Ibérica de Sistemas e Tecnologias de Informação]]></journal-title>
<abbrev-journal-title><![CDATA[RISTI]]></abbrev-journal-title>
<issn>1646-9895</issn>
<publisher>
<publisher-name><![CDATA[AISTI - Associação Ibérica de Sistemas e Tecnologias de Informação]]></publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id>S1646-98952024000400066</article-id>
<article-id pub-id-type="doi">10.17013/risti.56.66-81</article-id>
<title-group>
<article-title xml:lang="pt"><![CDATA[3SW: Um Conjunto de Medidas de Segurança para Mitigar Vulnerabilidades em Servidores Web]]></article-title>
<article-title xml:lang="en"><![CDATA[3SW: A Set of Safeguards to Mitigate Vulnerabilities in Web Servers]]></article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Tássio]]></surname>
<given-names><![CDATA[Silva]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Fabiana]]></surname>
<given-names><![CDATA[Mendes]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
<xref ref-type="aff" rid="Aaf"/>
</contrib>
</contrib-group>
<aff id="Af1">
<institution><![CDATA[,Universidade de Brasília Departamento de Engenharia Elétrica Faculdade de Tecnologia]]></institution>
<addr-line><![CDATA[Brasília DF]]></addr-line>
<country>Brazil</country>
</aff>
<aff id="Af2">
<institution><![CDATA[,Aalto University Department of Computer Science ]]></institution>
<addr-line><![CDATA[Espoo ]]></addr-line>
<country>Finland</country>
</aff>
<pub-date pub-type="pub">
<day>00</day>
<month>12</month>
<year>2024</year>
</pub-date>
<pub-date pub-type="epub">
<day>00</day>
<month>12</month>
<year>2024</year>
</pub-date>
<numero>56</numero>
<fpage>66</fpage>
<lpage>81</lpage>
<copyright-statement/>
<copyright-year/>
<self-uri xlink:href="http://scielo.pt/scielo.php?script=sci_arttext&amp;pid=S1646-98952024000400066&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.pt/scielo.php?script=sci_abstract&amp;pid=S1646-98952024000400066&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.pt/scielo.php?script=sci_pdf&amp;pid=S1646-98952024000400066&amp;lng=en&amp;nrm=iso"></self-uri><abstract abstract-type="short" xml:lang="pt"><p><![CDATA[Resumo Por hospedar serviços digitais, servidores web tornam-se alvos prioritários para ações mal-intencionadas. Entretanto, faltam guias amplos que auxiliem sua proteção. Assim, esse trabalho propõe o modelo 3SW que tem como objetivo auxiliar na mitigação de vulnerabilidades em servidores web. Para seu desenvolvimento, foi feita a seleção das medidas de segurança mais relevantes do CIS Controls, considerando nosso escopo (servidores web) e o esforço de implementação. Além disso, o 3SW é comparado com abordagens reconhecidas na cibersegurança para atestar sua utilidade. O 3SW é composto de 93 medidas, que correspondem a 61% das medidas do CIS Controls v8.1. A comparação do 3SW com MITRE ATT&amp;CK mostrou uma cobertura de 86%, com ênfase em auditoria de registros, defesa contra malware e recuperação de dados. Dessa forma, o 3SW oferece uma abordagem que facilita a priorização estratégica e a implementação eficiente de medidas de segurança.]]></p></abstract>
<abstract abstract-type="short" xml:lang="en"><p><![CDATA[Abstract Web servers are often targeted for malicious attacks because they host various applications. Unfortunately, there are not many comprehensive guides available to help implement effective protection measures. This work aims to propose a model called the 3SW model, which is designed to help mitigate vulnerabilities in web servers. To develop this model, we selected the most relevant safeguards from the CIS Controls, focusing specifically on web servers and the effort required for implementation. Additionally, the 3SW model is compared with well-recognized cybersecurity approaches to validate its usefulness. The 3SW consists of 93 safeguards, representing 61% of the CIS Controls v8.1 safeguards. A comparison between the 3SW model and the MITRE ATT&amp;CK framework revealed an 86% coverage, emphasizing log auditing, malware defense, and data recovery. Therefore, we concluded that the 3SW model presents an approach that facilitates strategic prioritization and efficient implementation of protective safeguards for web servers.]]></p></abstract>
<kwd-group>
<kwd lng="pt"><![CDATA[CIS Controls]]></kwd>
<kwd lng="pt"><![CDATA[cibersegurança]]></kwd>
<kwd lng="pt"><![CDATA[segurança da informação]]></kwd>
<kwd lng="pt"><![CDATA[servidor web]]></kwd>
<kwd lng="pt"><![CDATA[medidas de segurança.]]></kwd>
<kwd lng="en"><![CDATA[CIS Controls]]></kwd>
<kwd lng="en"><![CDATA[cybersecurity]]></kwd>
<kwd lng="en"><![CDATA[information security]]></kwd>
<kwd lng="en"><![CDATA[web server]]></kwd>
<kwd lng="en"><![CDATA[safeguards.]]></kwd>
</kwd-group>
</article-meta>
</front><back>
<ref-list>
<ref id="B1">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[AL-Hawamleh]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Cyber resilience framework: Strengthening defenses and enhancing continuity in business security]]></article-title>
<source><![CDATA[International Journal of Computing and Digital Systems]]></source>
<year>2024</year>
<volume>15</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>1315-31</page-range></nlm-citation>
</ref>
<ref id="B2">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Alves]]></surname>
<given-names><![CDATA[R. S.]]></given-names>
</name>
<name>
<surname><![CDATA[Georg]]></surname>
<given-names><![CDATA[M. A. C.]]></given-names>
</name>
<name>
<surname><![CDATA[Nunes]]></surname>
<given-names><![CDATA[R. R.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Judiciário sob ataque hacker: riscos de negócio para segurança cibernética em tribunais brasileiros]]></article-title>
<source><![CDATA[RISTI-Revista Ibérica de Sistemas e Tecnologias de Informação]]></source>
<year>2023</year>
<numero>E56</numero>
<issue>E56</issue>
<page-range>344-57</page-range></nlm-citation>
</ref>
<ref id="B3">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bada]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Nurse]]></surname>
<given-names><![CDATA[J. R.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[The social and psychological impact of cyberattacks]]></article-title>
<source><![CDATA[Emerging cyber threats and cognitive vulnerabilities]]></source>
<year>2020</year>
<page-range>73-92</page-range><publisher-name><![CDATA[Academic Press]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B4">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bardin]]></surname>
<given-names><![CDATA[L.]]></given-names>
</name>
</person-group>
<source><![CDATA[Análise de conteúdo]]></source>
<year>2016</year>
<publisher-loc><![CDATA[São Paulo, Brasil ]]></publisher-loc>
<publisher-name><![CDATA[Edições]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B5">
<nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bashofi]]></surname>
<given-names><![CDATA[I.]]></given-names>
</name>
<name>
<surname><![CDATA[Salman]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Cybersecurity maturity assessment design using NISTCSF, CIS CONTROLS v8 and ISO/IEC 27002]]></article-title>
<source><![CDATA[2022 IEEE International Conference on Cybernetics and Computational Intelligence]]></source>
<year>2022</year>
</nlm-citation>
</ref>
<ref id="B6">
<nlm-citation citation-type="journal">
<collab>BBC</collab>
<article-title xml:lang=""><![CDATA[JBS: Cyber-attack hits world&#8217;s largest meat supplier]]></article-title>
<source><![CDATA[BBC News]]></source>
<year>2021</year>
</nlm-citation>
</ref>
<ref id="B7">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Cebula]]></surname>
<given-names><![CDATA[J. J.]]></given-names>
</name>
<name>
<surname><![CDATA[Young]]></surname>
<given-names><![CDATA[L. R.]]></given-names>
</name>
</person-group>
<source><![CDATA[A taxonomy of operational cyber security risks]]></source>
<year>2010</year>
<publisher-name><![CDATA[Software Engineering Institute, Carnegie Mellon University]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B8">
<nlm-citation citation-type="">
<collab>Center for Internet Security</collab>
<source><![CDATA[CIS Controls V8.1.]]></source>
<year>2024</year>
</nlm-citation>
</ref>
<ref id="B9">
<nlm-citation citation-type="">
<collab>Center for Internet Security</collab>
<source><![CDATA[CIS Community Defense Model 2.0.]]></source>
<year>2024</year>
</nlm-citation>
</ref>
<ref id="B10">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Chen]]></surname>
<given-names><![CDATA[Q.]]></given-names>
</name>
<name>
<surname><![CDATA[Bridges]]></surname>
<given-names><![CDATA[R. A.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Automated behavioral analysis of malware: A case study of wannacry ransomware]]></article-title>
<source><![CDATA[2017 16th IEEE International Conference on machine learning and applications]]></source>
<year>2017</year>
<page-range>454-60</page-range><publisher-name><![CDATA[IEEE]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B11">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Crotty]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Daniel]]></surname>
<given-names><![CDATA[L.]]></given-names>
</name>
</person-group>
<source><![CDATA[Lessons from practice: insights on cybersecurity strategy for business leaders, from SMEs to global enterprises]]></source>
<year>2021</year>
<publisher-loc><![CDATA[Milton Keynes ]]></publisher-loc>
<publisher-name><![CDATA[Open University]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B12">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Cue]]></surname>
<given-names><![CDATA[H. A. A.]]></given-names>
</name>
<name>
<surname><![CDATA[Bourlai]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
<name>
<surname><![CDATA[Lupo]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[A CIS Controls V8. 0 Scoring System using Combined Ranking-Weight Methods]]></article-title>
<source><![CDATA[2024 IEEE International Systems Conference]]></source>
<year>2024</year>
<page-range>1-8</page-range><publisher-name><![CDATA[IEEE]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B13">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Domínguez-Dorado]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Carmona-Murillo]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Cortés-Polo]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Rodríguez-Pérez]]></surname>
<given-names><![CDATA[F. J.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[CyberTOMP: A novel systematic framework to manage asset-focused cybersecurity from tactical and operational levels]]></article-title>
<source><![CDATA[IEEE Access]]></source>
<year>2022</year>
<volume>10</volume>
<page-range>122454-85</page-range></nlm-citation>
</ref>
<ref id="B14">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Fadlil]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
<name>
<surname><![CDATA[Riadi]]></surname>
<given-names><![CDATA[I.]]></given-names>
</name>
<name>
<surname><![CDATA[Mu&#8217;min]]></surname>
<given-names><![CDATA[M. A.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Mitigation from SQL Injection Attacks on Web Server using Open Web Application Security Project Framework]]></article-title>
<source><![CDATA[International Journal of Engineering]]></source>
<year>2024</year>
<volume>37</volume>
<numero>4</numero>
<issue>4</issue>
<page-range>635-45</page-range></nlm-citation>
</ref>
<ref id="B15">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ferdous]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Islam]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
<name>
<surname><![CDATA[Mahboubi]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
<name>
<surname><![CDATA[Islam]]></surname>
<given-names><![CDATA[M. Z.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[A State-of-the-Art Review of Malware Attack Trends and Defense Mechanism]]></article-title>
<source><![CDATA[IEEE Access]]></source>
<year>2023</year>
</nlm-citation>
</ref>
<ref id="B16">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ghanbari]]></surname>
<given-names><![CDATA[H.]]></given-names>
</name>
<name>
<surname><![CDATA[Koskinen]]></surname>
<given-names><![CDATA[K.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[When data breach hits a psychotherapy clinic: The Vastaamo case]]></article-title>
<source><![CDATA[Journal of Information Technology Teaching Cases]]></source>
<year>2024</year>
</nlm-citation>
</ref>
<ref id="B17">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Gil]]></surname>
<given-names><![CDATA[A. C.]]></given-names>
</name>
</person-group>
<source><![CDATA[Como elaborar projetos de pesquisa]]></source>
<year>2023</year>
<edition>7</edition>
<publisher-name><![CDATA[Editora Atlas]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B18">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Gonzalez-Granadillo]]></surname>
<given-names><![CDATA[G.]]></given-names>
</name>
<name>
<surname><![CDATA[Menesidou]]></surname>
<given-names><![CDATA[S. A.]]></given-names>
</name>
<name>
<surname><![CDATA[Papamartzivanos]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Romeu]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
<name>
<surname><![CDATA[Navarro-Llobet]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Okoh]]></surname>
<given-names><![CDATA[C.]]></given-names>
</name>
<name>
<surname><![CDATA[Panaousis]]></surname>
<given-names><![CDATA[E.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Automated cyber and privacy risk management toolkit]]></article-title>
<source><![CDATA[Sensors]]></source>
<year>2021</year>
<volume>21</volume>
<numero>16</numero>
<issue>16</issue>
<page-range>5493</page-range></nlm-citation>
</ref>
<ref id="B19">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Horta]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
<name>
<surname><![CDATA[Holanda]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
<name>
<surname><![CDATA[Marinho]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[A Multi-criteria Approach to Improve the Cyber Security Visibility Through Breach Attack Simulations]]></article-title>
<source><![CDATA[Anais do XXII Simpósio Brasileiro em Segurança da Informação e de Sistemas Computacionais]]></source>
<year>2022</year>
<page-range>330-43</page-range><publisher-name><![CDATA[SBC]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B20">
<nlm-citation citation-type="">
<collab>IBM</collab>
<source><![CDATA[Cost of a Data Breach Report 2024]]></source>
<year>2024</year>
</nlm-citation>
</ref>
<ref id="B21">
<nlm-citation citation-type="">
<collab>International Organization for Standardization</collab>
<source><![CDATA[ISO - ISO/IEC 27000 family - Information security management]]></source>
<year>2024</year>
</nlm-citation>
</ref>
<ref id="B22">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Juma]]></surname>
<given-names><![CDATA[A. H.]]></given-names>
</name>
<name>
<surname><![CDATA[Arman]]></surname>
<given-names><![CDATA[A. A.]]></given-names>
</name>
<name>
<surname><![CDATA[Hidayat]]></surname>
<given-names><![CDATA[F.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Cybersecurity Assessment Framework: A Systematic Review]]></article-title>
<source><![CDATA[2023 10th International Conference on ICT for Smart Society]]></source>
<year>2023</year>
<page-range>1-6</page-range><publisher-name><![CDATA[IEEE]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B23">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kamiya]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Kang]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Kim]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Milidonis]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
<name>
<surname><![CDATA[Stulz]]></surname>
<given-names><![CDATA[R. M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Risk management, firm reputation, and the impact of successful cyberattacks on target firms]]></article-title>
<source><![CDATA[Journal of Financial Economics]]></source>
<year>2020</year>
<volume>139</volume>
<numero>3</numero>
<issue>3</issue>
<page-range>719&#8209;749</page-range></nlm-citation>
</ref>
<ref id="B24">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kern]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Landauer]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Skopik]]></surname>
<given-names><![CDATA[F.]]></given-names>
</name>
<name>
<surname><![CDATA[Weippl]]></surname>
<given-names><![CDATA[E.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[A logging maturity and decision model for the selection of intrusion detection cyber security solutions]]></article-title>
<source><![CDATA[Computers &amp; Security]]></source>
<year>2024</year>
<volume>141</volume>
</nlm-citation>
</ref>
<ref id="B25">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Leszczyna]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Review of cybersecurity assessment methods: Applicability perspective]]></article-title>
<source><![CDATA[Computers &amp; Security]]></source>
<year>2021</year>
<volume>108</volume>
</nlm-citation>
</ref>
<ref id="B26">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Lima]]></surname>
<given-names><![CDATA[E. D.]]></given-names>
</name>
<name>
<surname><![CDATA[Moreira]]></surname>
<given-names><![CDATA[F. R.]]></given-names>
</name>
<name>
<surname><![CDATA[Deus]]></surname>
<given-names><![CDATA[F. E.]]></given-names>
</name>
<name>
<surname><![CDATA[Nze]]></surname>
<given-names><![CDATA[G. D.]]></given-names>
</name>
<name>
<surname><![CDATA[Sousa]]></surname>
<given-names><![CDATA[R. T.]]></given-names>
</name>
<name>
<surname><![CDATA[Nunes]]></surname>
<given-names><![CDATA[R. R.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Avaliação da rotina operacional do operador nacional do sistema elétrico brasileiro (ONS) em relação às ações de gerenciamento de riscos associados à segurança cibernética]]></article-title>
<source><![CDATA[RISTI- Revista Iberica de Sistemas e Tecnologia de Informação]]></source>
<year>2022</year>
<numero>E49</numero>
<issue>E49</issue>
<page-range>301-12</page-range></nlm-citation>
</ref>
<ref id="B27">
<nlm-citation citation-type="">
<collab>MITRE</collab>
<source><![CDATA[MITRE ATT&amp;CK. Mitre Corporation]]></source>
<year>2024</year>
</nlm-citation>
</ref>
<ref id="B28">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Mohammed]]></surname>
<given-names><![CDATA[Z.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Data breach recovery areas: an exploration of organization's recovery strategies for surviving data breaches]]></article-title>
<source><![CDATA[Organizational Cybersecurity Journal: Practice, Process and People]]></source>
<year>2022</year>
<volume>2</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>41-59</page-range></nlm-citation>
</ref>
<ref id="B29">
<nlm-citation citation-type="book">
<collab>NIST</collab>
<source><![CDATA[National Institute of Standards and Technology. Special Publications (SP)]]></source>
<year>2024</year>
<publisher-name><![CDATA[NIST Computer Security Resource Center]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B30">
<nlm-citation citation-type="book">
<collab>NIST</collab>
<source><![CDATA[National Institute of Standards and Technology. Web Server]]></source>
<year>2024</year>
<publisher-name><![CDATA[NIST Computer Security Resource Center]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B31">
<nlm-citation citation-type="">
<collab>NIST</collab>
<source><![CDATA[National Institute of Standards and Technology. Special Publications (SP). Measurement Guide for Information Security: Volume 1 - Identifying and Selecting Measures (NIST SP 800-55v1 ipd)]]></source>
<year>2024</year>
</nlm-citation>
</ref>
<ref id="B32">
<nlm-citation citation-type="">
<collab>OWASP</collab>
<source><![CDATA[About OWASP. OWASP Foundation]]></source>
<year>2024</year>
</nlm-citation>
</ref>
<ref id="B33">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Song]]></surname>
<given-names><![CDATA[L.]]></given-names>
</name>
<name>
<surname><![CDATA[García-Valls]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Improving security of web servers in critical IoT systems through self-monitoring of vulnerabilities]]></article-title>
<source><![CDATA[Sensors]]></source>
<year>2022</year>
<volume>22</volume>
<numero>13</numero>
<issue>13</issue>
<page-range>5004</page-range></nlm-citation>
</ref>
<ref id="B34">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Tsiodra]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Panda]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Chronopoulos]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Panaousis]]></surname>
<given-names><![CDATA[E.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Cyber risk assessment and optimization: A small business case study]]></article-title>
<source><![CDATA[IEEE Access]]></source>
<year>2023</year>
<volume>11</volume>
<page-range>44467-81</page-range></nlm-citation>
</ref>
<ref id="B35">
<nlm-citation citation-type="">
<collab>Verizon</collab>
<source><![CDATA[2023 Data Breach Investigations Report]]></source>
<year>2023</year>
</nlm-citation>
</ref>
</ref-list>
</back>
</article>
