VLDB 2026 Research / reviewers in the wild / expert
Luis Enrique Sánchez Crespo
dblp:348/4392 · also Luis Enrique Sánchez
· DBLP profile ↗
12ranked-venue papers
5as first author
7since 2021 · last 2025
0000-0003-0086-1065ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 5 first-author · 5 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards a sustainable cybersecurity framework for Agriculture 4.0 based on a systematic analysis of proposalsabstractThe world is currently experiencing a profound transformation driven by the convergence of disruptive technologies under the concept of Industry 4.0. These technologies have driven sectors such as agriculture to modernize and automate for greater sustainability, leading to what is now referred to as Agriculture 4.0 However, this transformation entails risks and requires new frameworks that address cybersecurity, sustainability, and knowledge reuse. In this paper, we conduct a systematic review of these new systems with the aim of identifying their main shortcomings and proposing a new framework. The review revealed a significant gap in comprehensively addressing cybersecurity, AI, and sustainability. This highlights the need for deeper exploration of how these elements interact to benefit the agricultural sector. To this end, we propose the development of the QUILLAQUA framework, oriented towards secure, intelligent, and sustainable agriculture, with a focus on fostering effective synergies among these crucial components. This framework integrates advanced technologies in cybersecurity, IoT, and AI to optimise the management of water and nutritional resources in hydroponic systems, ensuring sustainability and data security. This approach aims to enhance technological efficiency in agriculture. It also aims to foster greater awareness to tackle present and future challenges in sustainable agriculture. By doing so, it ensures a successful transition toward more digitized and secure agricultural practices. Diegof Bustamantev, Luis Enrique Sánchez Crespo, David Garcia Rosado, Antonio Santos-Olmo, Eduardo Fernández-Medina |
Comput. Secur. | 2 |
| 2025 | Integrated maritime protection: Innovation for the safeguarding of maritime systems based on MARISMAabstractThe maritime sector is becoming increasingly susceptible to sophisticated cyber-attacks, underscoring the pressing necessity for advanced research and development to establish robust safeguards for maritime assets. Although risk assessment methods for traditional IT systems are now highly developed, they are not directly applicable to risk assessment in maritime environments due to the specific characteristics and particularities of the latter. Therefore, there is an urgent need to define approaches that adequately support risk assessment in maritime environments. To contribute to this important challenge, we propose a novel risk analysis technique, specifically tailored for the maritime sector, based on MARISMA, a security management methodology, and eMARISMA, its cloud-based technological support tool. Our work contributes to the state of the art by defining the MARISMA-SHIPS maritime cybersecurity pattern, which includes a set of reusable and adaptable elements that enable risk management and control in a maritime environment, and is aligned with major international standards such as ENISA and NIST, as well as existing maritime regulations, becoming a key part of our ongoing POSEIDON maritime cybersecurity framework. A case study is presented for a ship developed in the main shipyard in Colombia, which shows how the reusability and adaptability of the proposal allows the proposed MARISMA-SHIPS pattern to be easily adapted to any maritime environment, and which allowed the identification of critical areas of cybersecurity that could be improved. The application of the process in the maritime domain has proven its value in improving the efficiency and security management of maritime assets. Ferney Martínez 0001, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, David Garcia Rosado, Eduardo Fernández-Medina |
Comput. Secur. | 2 |
| 2024 | Towards an integrated risk analysis security framework according to a systematic analysis of existing proposalsabstractAbstract The information society depends increasingly on risk assessment and management systems as means to adequately protect its key information assets. The availability of these systems is now vital for the protection and evolution of companies. However, several factors have led to an increasing need for more accurate risk analysis approaches. These are: the speed at which technologies evolve, their global impact and the growing requirement for companies to collaborate. Risk analysis processes must consequently adapt to these new circumstances and new technological paradigms. The objective of this paper is, therefore, to present the results of an exhaustive analysis of the techniques and methods offered by the scientific community with the aim of identifying their main weaknesses and providing a new risk assessment and management process. This analysis was carried out using the systematic review protocol and found that these proposals do not fully meet these new needs. The paper also presents a summary of MARISMA, the risk analysis and management framework designed by our research group. The basis of our framework is the main existing risk standards and proposals, and it seeks to address the weaknesses found in these proposals. MARISMA is in a process of continuous improvement, as is being applied by customers in several European and American countries. It consists of a risk data management module, a methodology for its systematic application and a tool that automates the process. Antonio Santos-Olmo, Luis Enrique Sánchez Crespo, David Garcia Rosado, Manuel A. Serrano, Carlos Blanco 0001, Haralambos Mouratidis, Eduardo Fernández-Medina |
Frontiers Comput. Sci. | 2 |
| 2024 | Enabling security risk assessment and management for business process modelsabstractBusiness processes (BP) are considered the enterprise’s cornerstone but are increasingly in the spotlight of attacks. Therefore, the design of business processes must consider the security risks and be adequately integrated into the information and operational systems. However, security risk assessment and management are rarely considered at the level of business processes during design time, let alone considering a risk architecture that takes into account the connection and dependencies of risks at these levels of the organisation, business processes, and information systems. In general, most approaches deal with integrating new artefacts for business process models to support risk analysis, but sometimes, the notation can increase complexity, making it difficult to have a risk management tool to support the analysis. After analysing the current risk processes and frameworks, we have realised that they are often neglected when considering organisational and business process levels. In this paper, MARISMA-BP (MARISMA for Business Process) pattern is proposed, a security risk pattern to enable the assessment and management of risks for business process models. This approach is an artefact that has been validated in a real scenario following the design science methodology. Further, MARISMA-BP pattern is supported by eMARISMA, an automated infrastructure that allows the definition and reuse of each risk component, helping us to carry out the risk assessment and management process in an efficient and dynamic way. To demonstrate the applicability of the proposal, MARISMA-BP pattern is applied to a real health-based business process scenario. The findings illustrate the efficacy of MARISMA-BP within eMARISMA for comprehensive risk assessment and management, underscoring its versatility and practical relevance in any business process environment. David Garcia Rosado, Luis Enrique Sánchez Crespo, Angel Jesus Varela-Vaca, Antonio Santos-Olmo, María Teresa Gómez-López, Rafael M. Gasca, Eduardo Fernández-Medina |
J. Inf. Secur. Appl. | 2 |
| 2024 | Minimizing incident response time in real-world scenarios using quantum computingabstractAbstract The Information Security Management Systems (ISMS) are global and risk-driven processes that allow companies to develop their cybersecurity strategy by defining security policies, valuable assets, controls, and technologies for protecting their systems and information from threats and vulnerabilities. Despite the implementation of such management infrastructures, incidents or security breaches happen. Each incident has associated a level of severity and a set of mitigation controls, so in order to restore the ISMS, the appropriate set of controls to mitigate their damage must be selected. The time in which the ISMS is restored is a critical aspect. In this sense, classic solutions are efficient in resolving scenarios with a moderate number of incidents in a reasonable time, but the response time increases exponentially as the number of incidents increases. This makes classical solutions unsuitable for real scenarios in which a large number of incidents are handled and even less appropriate for scenarios in which security management is offered as a service to several companies. This paper proposes a solution to the incident response problem that acts in a minimal amount of time for real scenarios in which a large number of incidents are handled. It applies quantum computing, as a novel approach that is being successfully applied to real problems, which allows us to obtain solutions in a constant time regardless of the number of incidents handled. To validate the applicability and efficiency of our proposal, it has been applied to real cases using our framework (MARISMA). Manuel A. Serrano, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, David Garcia Rosado, Carlos Blanco 0001, Vita Santa Barletta, Danilo Caivano, Eduardo Fernández-Medina |
Softw. Qual. J. | 2 |
| 2023 | Modelling language for cyber security incident handling for critical infrastructuresabstractCyber security incident handling is a consistent methodology with which to ensure overall business continuity. However, specifically handling incidents for critical information infrastructures is challenging owing to the inherent complexity and evolving nature of the threat. Despite the number of contributions made to cyber incident handling, there is little evidence of literature that focuses on modelling activities that will enhance developers’ abilities to model incident handling processes and activities according to different views. Modelling languages of this nature should integrate essential concepts and a descriptive implementation process in order to enable developers to analyse, represent and reason about the crucial incident handling efforts required to support critical information infrastructures. The aim of this paper is, as part of the CyberSANE EU project, to develop a Cyber Incident Handling Modelling Language (CIHML) that focuses explicitly on modelling incident handling in the context of a critical information infrastructure. The work is innovative in its approach because it consolidates concepts from various domains such as security requirements, forensics, threat intelligence, critical infrastructures and cyber incident handling. The approach will allow the phases of the incident handling lifecycle to be modelled from three different views (critical information infrastructures, threat and risk analysis, and incident response). An implementation process is also proposed, which will serve as a comprehensive guide for developers in order to create these modelling views. Finally, CIHML is evaluated using a real-life scenario from the CyberSANE project to demonstrate its applicability. The incident observed had a severe impact on the overall business continuity of the context studied. The results obtained from the study show that CIHML can help critical information infrastructure operators to identify, evaluate, represent and model cyber incidents in critical information systems, in addition to providing the support required to determine the response strategies needed in order to mitigate these cyber-attacks. Haralambos Mouratidis, Shareeful Islam, Antonio Santos-Olmo, Luis Enrique Sánchez Crespo, Umar Mukhtar Ismail |
Comput. Secur. | 4 |
| 2021 | MARISMA-BiDa pattern: Integrated risk analysis for big data
David Garcia Rosado, Julio Moreno, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, Manuel A. Serrano, Eduardo Fernández-Medina |
Comput. Secur. | 3 |
| 2010 | Managing the Asset Risk of SMEsabstractThe information society is becoming increasingly dependent on systems for managing and analyzing the risk to which its main information assets are exposed and having access to these systems has become vital for the evolution of SMEs. However, this type of company requires the systems to be adapted to their special characteristics and to be optimized from the point of view of resources required to set them up and maintain them. This article presents a proposed method for carrying out risk analysis adaptation, which is suitable for SMEs, set within the framework of the methodology for security management in small and medium-sized enterprises (MSM2-SME). This model is being applied directly to real cases, and therefore its application is constantly being improved. Luis Enrique Sánchez Crespo, Eduardo Fernández-Medina, Mario Piattini |
ARES | 1 |
| 2010 | Building ISMS through the Reuse of Knowledge
Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, Eduardo Fernández-Medina, Mario Piattini |
TrustBus | 1 |
| 2008 | Practical Application of a Security Management Maturity Model for SMEs based on Predefined Schemas
Luis Enrique Sánchez Crespo, Daniel Villafranca, Eduardo Fernández-Medina, Mario Piattini |
SECRYPT | 1 |
| 2007 | Developing a Model and a Tool to Manage the Information Security in Small and Medium Enterprises
Luis Enrique Sánchez Crespo, Daniel Villafranca, Eduardo Fernández-Medina, Mario Piattini |
SECRYPT | 1 |
| 2006 | Practical Approach of a Secure Management System based on ISO/IEC 17799abstractFor enterprises to be able to properly use information and communications technologies, it is necessary to have guides, metrics and tools that allow us to always know the level of our security and the points in which we are not covering it. In small and medium-size enterprises, the application of security standards has an additional problem, that is, the fact that they do not have enough resources to perform an appropriate management. In this article we analyze some of the existing maturity models and we compare them to the maturity model we are applying in practice. Finally we introduce a first approach to a scoreboard which is being developed as part of a security management tool for IT systems. This approach is being directly applied to real cases and it is obtaining a constant improvement in its application. Luis Enrique Sánchez Crespo, Daniel Villafranca, Eduardo Fernández-Medina, Mario Piattini |
ARES | 1 |