VLDB 2026 Research / reviewers in the wild / expert
Inger Anne Tøndel
dblp:81/1212
· DBLP profile ↗
31ranked-venue papers
12as first author
5since 2021 · last 2025
0000-0001-7599-0342ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 9 first-author · 1 since 2021Software engineering, systems software and programming languages · 6 · 3 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Organizational factors of software performance testing for systems of systems: A case study using high-reliability organization theory to understand an outageabstractIn systems of systems (SoSs), independent constituent systems operated by different organizations cooperate towards a common goal. This empirical paper is the first to explore what these organizations can learn from high-reliability organization (HRO) theory when collaborating on software performance testing, a part of software performance engineering (SPE). Our case study is based on the Norwegian tax report SoS. Our overall research objective is to understand the organizational factors of SoS software performance testing. To understand these organizational factors , we also analyze the technical factors of SoS software performance. Three months before the opening of the tax return system, we observed meetings where three independent organizations coordinated their performance testing. We also attended conference meetings during, and retrospectives after, the opening. These observations were transcribed and deductively coded for the five HRO principles. Further, we analyzed measurement logs from the organizations participating in the tax return system. The technical root cause of a 90-minute outage in the tax report SoS was a load balancer primary memory shortage caused by too many unserved users. However, the organizational root cause is more interesting: incompatible worldviews reflecting an inadequate holistic SoS management. HRO theory can benefit organizations preparing for workload peaks in mission-critical SoSs. Using the five HRO principles, the constituent organizations can develop a collective mind, bridging incompatible worldviews in SoS software performance testing. Gunnar Brataas, Petter Braskerud, Inger Anne Tøndel, Steinar Kjærnsrød |
J. Syst. Softw. | 3 |
| 2022 | Needs and Challenges Concerning Cyber-risk Assessment in the Cyber-physical Smart GridabstractCyber-risk assessment methods are used by energy companies to manage security risks in smart grids. However, current standards, methods and tools do not adequately provide the support needed in practice and the industry is struggling to adopt and carry out cyber-risk assessments. The contribution of this paper is twofold. First, we interview six companies from the energy sector to better understand their needs and challenges. Based on the interviews, we identify seven success criteria cyber-risk assessment methods for the energy sector need to fulfill to provide adequate support. Second, we present the methods CORAS, VAF, TM-STRIDE, and DA-SAN and evaluate the extent to which they fulfill the identified success criteria. Based on the evaluation, we provide lessons learned in terms of gaps that need to be addressed in general to improve cyber-risk assessment in the context of smart grids. Our results indicate the need for the following improvements: 1) ease of use and comprehensible m ethods, 2) support to determine whether a method is a good match for a given context, 3) adequate preparation to conduct cyber-risk assessment, 4) manage complexity, 5) adequate support for risk estimation, 6) support for trustworthiness and uncertainty handling, and 7) support for maintaining risk assessments. Gencer Erdogan, Inger Anne Tøndel, Shukun Tokas, Michele Garau, Martin Gilje Jaatun |
ICSOFT | 2 |
| 2022 | Influencing the security prioritisation of an agile software development projectabstractSoftware security is a complex topic, and for development projects it can be challenging to assess what security is necessary and cost-effective. Agile Software Development (ASD) values self-management. Thus, teams and their Product Owners are expected to also manage software security prioritisation. In this paper we build on the notion that security experts who want to influence the priority given to security in ASD need to do this through interactions and support for teams rather than prescribing certain activities or priorities. But to do this effectively, there is a need to understand what hinders and supports teams in prioritising security. Based on a longitudinal case study, this article offers insight into the strategy used by one security professional in an SME to influence the priority of security in software development projects in the company. The main result is a model of influences on security prioritisation that can assist in understanding what supports or hinders the prioritisation of security in ASD, thus providing recommendations for security professionals. Two alternative strategies are outlined for software security in ASD – prescribed and emerging – where we hypothesise that an emerging approach can be more relevant for SMEs doing ASD, and that this can impact how such companies should consider software security maturity. Inger Anne Tøndel, Daniela S. Cruzes, Martin Gilje Jaatun, Guttorm Sindre |
Comput. Secur. | 1 |
| 2022 | Continuous software security through security prioritisation meetingsabstractSoftware security needs to be a continuous endeavour in current software development practices. Frequent software updates, paired with an ongoing flow of security breaches, requires software companies to address software security throughout development and post deployment. Prescriptive software security approaches do not match well with agile software development and its emphasis on self-management. Agile approaches are however in favour of meetings as a coordination and problem-solving strategy. This article investigates the role of regular security meetings centred on making security priorities and decisions for achieving continuous software security. Through technical action research and an observational case study, we studied variations of such meetings in three companies. We found that such meetings can reach key stakeholders, make security more visible, and contribute to ongoing security prioritisation. Thus, security meetings are a promising approach, especially for small and medium sized development companies with basic yet immature security competence. Future research should investigate further the role of such meetings and how best to organise them for different contexts and needs. For this we outline implications for research and practice, e.g., related to participants and how to organise the discussions and prioritisations in the meeting. Inger Anne Tøndel, Daniela S. Cruzes |
J. Syst. Softw. | 1 |
| 2021 | Improving smart grid security through 5G enabled IoT and edge computingabstractAbstract This article investigates and analyzes the security aspects of 5G specifications from the perspective of IoT‐based smart grids. As the smart grid requires high‐speed and reliable communication to enable real‐time grid monitoring via Internet of Things (IoT) devices, 5G can be considered a catalyst to transform the current power grid infrastructure into a smart grid. Thus, an understanding of what 5G can bring in terms of cyber security in IoT‐based smart grids is important for design decisions and future risk analysis efforts. In this article, we explore a smart grid use case on automatic voltage control—a use case utilizing 5G as a wireless communication infrastructure with edge support. We identify the benefits 5G brings to several security aspects, and show how 5G security techniques are applicable to the smart grid, thus providing a foundation for future security analysis of 5G enabled smart grid systems. Future research should extend this work to additional smart grid use cases. Ravishankar Borgaonkar, Inger Anne Tøndel, Merkebu Z. Degefa, Martin Gilje Jaatun |
Concurr. Comput. Pract. Exp. | 2 |
| 2020 | Achieving "Good Enough" Software Security: The Role of ObjectivityabstractToday's software development projects need to consider security as one of the qualities the software should possess. However, overspending on security will imply that the software will become more expensive and often also delayed. This paper discusses the role of objectivity in assessing and researching the goal of good enough security. Different understandings of objectivity are introduced, and the paper explores how these can guide the way forward in improving judgements on what level of security is good enough. The paper recommends adopting and improving upon methods that include different perspectives, support the building of interactive expertise, and support confirmability by keeping documentation of the basis on which judgements were made. Inger Anne Tøndel, Daniela S. Cruzes, Martin Gilje Jaatun |
EASE | 1 |
| 2020 | Using Situational and Narrative Analysis for Investigating the Messiness of Software SecurityabstractBackground: Software engineering work and its context often has characteristics of what in social science is termed 'messy'; it has ephemeral and irregular qualities. This puts high demands on researchers doing inquiry and analysis. Aims: This paper aims to show what a combination of situational analysis (SA) and narrative analysis (NA) can bring to qualitative software engineering research, and in particular for situations characterised by mess. Method: SA and NA were applied to a case study on software security. Results: We found that these analysis methods helped us gain new insights and understandings and a broader perspective of the situation we are studying. Additionally, the methods helped collaboration in the analysis. Conclusion: We recommend applying and studying these and similar combinations of analysis approaches further. Inger Anne Tøndel, Daniela S. Cruzes, Martin Gilje Jaatun |
ESEM | 1 |
| 2019 | The Security Intention Meeting Series as a way to increase visibility of software security decisions in agile development projectsabstractTo achieve a level of security that is just right, software development projects need to strike a balance between security and cost. This necessitates making such decisions as to what security activities to perform in development and which security requirements should be given priority. Current evidence indicates that in many agile development projects, software security is dealt with in a more or less "accidental" way based on individuals' security awareness and interest. This approach is unlikely to lead to an optimal security level for the product. This paper suggests Security Intention Recap Meetings as a recurring organisational tool for evaluating current practices regarding the security intentions of a software project, and to make decisions on how to move forward. These meetings involve key decision makers in the project, such as the product owner and the project manager, with the purpose of making security decisions visible and deliberate and to monitor their results Inger Anne Tøndel, Daniela S. Cruzes, Martin Gilje Jaatun, Kalle Rindell |
ARES | 1 |
| 2019 | Collaborative security risk estimation in agile software developmentabstractPurpose Today, agile software development teams in general do not adopt security risk-assessment practices in an ongoing manner to prioritize security work. Protection Poker is a collaborative and lightweight software security risk-estimation technique that is particularly suited for agile teams. Motivated by a desire to understand why security risk assessments have not yet gained widespread adoption in agile development, this study aims to assess to what extent the Protection Poker game would be accepted by agile teams and how it can be successfully integrated into the agile practices. Design/methodology/approach Protection Poker was studied in capstone projects, in teams doing a graduate software security course and in sessions with industry representatives. Data were collected via questionnaires, observations and group interviews. Findings Results show that Protection Poker has the potential to be adopted by agile teams. Key benefits include good discussions on security and the development project, along with increased knowledge and awareness. Challenges include ensuring efficient use of time and gaining impact on the end product. Research limitations/implications Using students allowed easy access to subjects and an ability to collect rich data over time, but at the cost of generalizability to professional settings. Results from interactions with professionals supplement the data from students, showing similarities and differences in their opinions on Protection Poker. Originality/value The paper proposes ways to tackle the main obstacles to the adoption of the Protection Poker technique, as identified in this study. Inger Anne Tøndel, Martin Gilje Jaatun, Daniela S. Cruzes, Laurie A. Williams |
Inf. Comput. Secur. | 1 |
| 2017 | Accountability Requirements for the CloudabstractIn order to be responsible stewards of other people's data, cloud providers must be accountable for their data handling practices. The potential long provider chains in cloud computing introduces additional accountability challenges, and this paper examines requirements which must be fulfilled to achieve an accountability-based approach. Martin Gilje Jaatun, Inger Anne Tøndel, Nils Brede Moe, Daniela S. Cruzes, Karin Bernsmed, Børge Haugset |
CloudCom | 2 |
| 2016 | Zebras and Lions: Better Incident Handling Through Improved Cooperation
Martin Gilje Jaatun, Maria B. Line, Inger Anne Tøndel |
I4CS | 3 |
| 2016 | Playing Protection Poker for Practical Software Security
Martin Gilje Jaatun, Inger Anne Tøndel |
PROFES | 2 |
| 2015 | How Much Cloud Can You Handle?abstractOutsourcing computing and storage to the cloud does not eliminate the need for handling of information security incidents. However, the long provider chains and unclear responsibilities in the cloud make incident response difficult. In this paper we present results from interviews in critical infrastructure organisations that highlight incident handling needs that would apply to cloud customers, and suggest mechanisms that facilitate inter-provider collaboration in handling of incidents in the cloud, improving the accountability of the cloud service providers. Martin Gilje Jaatun, Inger Anne Tøndel |
ARES | 2 |
| 2015 | Assessing Information Security Risks of AMI - What Makes it so Difficult?abstractA rich selection of methods for information security risk assessments exist, but few studies evaluate how such methods are used, their perceived ease-of-use, and whether additional support is needed. Distribution system operators (DSOs) find it difficult to perform information security risk assessments of Advanced Metering Infrastructure (AMI). We have performed a case study in order to identify these difficulties and the reasons for them. Our findings indicate that the risk assessment method in itself is not the main challenge. The difficulties regard competence; more specifically, insight in possible information security threats and vulnerabilities, being able to foresee consequences, and making educated guesses about probability. Improved guidelines can be a valuable aid, but including information security experts as participants in the process is even more important. Inger Anne Tøndel, Maria B. Line, Gorm Johansen |
ICISSP | 1 |
| 2015 | Software Security Maturity in Public Organisations
Martin Gilje Jaatun, Daniela S. Cruzes, Karin Bernsmed, Inger Anne Tøndel, Lillian Røstad |
ISC | 4 |
| 2014 | Information security incident management: Current practice as reported in the literature
Inger Anne Tøndel, Maria B. Line, Martin Gilje Jaatun |
Comput. Secur. | 1 |
| 2012 | Design and Implementation of a CBR-based Privacy AgentabstractThis paper presents Privacy Advisor; a software which uses machine-learning techniques to help the users make online privacy decisions. Privacy Advisor is based on Case Based Reasoning (CBR), which relies on the ability to identify similar situations from the past and use these to provide recommendations in new situations. This paper focuses on the algorithms necessary to calculate the similarity of privacy policies. In addition, we provide results from a focus group study on the perceived similarity of data items and data handling purposes from a privacy point of view. Karin Bernsmed, Inger Anne Tøndel, Åsmund Ahlmann Nyre |
ARES | 2 |
| 2012 | Threat Modeling of AMI
Inger Anne Tøndel, Martin Gilje Jaatun, Maria B. Line |
CRITIS | 1 |
| 2011 | A Risk-Based Evaluation of Group Access Control Approaches in a Healthcare Setting
Maria B. Line, Inger Anne Tøndel, Erlend Andreas Gjære |
ARES | 2 |
| 2011 | Learning Privacy PreferencesabstractThis paper suggests a machine learning approach to preference generation in the context of privacy agents. With this solution, users are relieved from the complex task of specifying their preferences beforehand, disconnected from actual situations. Instead, historical privacy decisions are used as a basis for providing privacy recommendations to users in new situations. The solution also takes into account the reasons why users act as they do, and allows users to benefit from information on the privacy trade-offs made by others. Inger Anne Tøndel, Åsmund Ahlmann Nyre, Karin Bernsmed |
ARES | 1 |
| 2010 | Combining Misuse Cases with Attack Trees and Security Activity ModelsabstractMisuse cases and attack trees have been suggested for security requirements elicitation and threat modeling in software projects. Their use is believed to increase security awareness throughout the software development life cycle. Experiments have identified strengths and weaknesses of both model types. In this paper we present how misuse cases and attack trees can be linked to get a high-level view of the threats towards a system through misuse case diagrams and a more detailed view on each threat through attack trees. Further, we introduce links to security activity descriptions in the form of UML activity graphs. These can be used to describe mitigating security activities for each identified threat. The linking of different models makes most sense when security modeling is supported by tools, and we present the concept of a security repository that is being built to store models and relations such as those presented in this paper. Inger Anne Tøndel, Jostein Jensen, Lillian Røstad |
ARES | 1 |
| 2010 | Experimental Threat Model Reuse with Misuse Case Diagrams
Jostein Jensen, Inger Anne Tøndel, Per Håkon Meland |
ICICS | 2 |
| 2009 | Reusable Security Requirements for Healthcare ApplicationsabstractHealthcare information systems are currently being migrated from paper based journals to fully digitalised information platforms. Protecting patient privacy is thus becoming an increasingly complex task, where several national and international legal requirements must be met. These legal requirements present only high-level goals for privacy protection, leaving the details of security requirements engineering to the developers of electronic healthcare systems. Our objective has been to map legal requirements for sensitive personal information to a set of reusable technical information security requirements. This paper presents examples of such requirements extracted from legislation applicable to the healthcare domain. Jostein Jensen, Inger Anne Tøndel, Martin Gilje Jaatun, Per Håkon Meland, Herbjørn Andresen |
ARES | 2 |
| 2009 | An Architectural Foundation for Security Model Sharing and ReuseabstractWithin the field of software security we have yet to find efficient ways on how to learn from past mistakes and integrate security as a natural part of software development.This situation can be improved by using an online repository, the SHIELDS SVRS, that facilitates fast and easy interchange of security artefacts between security experts, software developers and their assisting tools. Such security artefacts are embedded in or represented as security models containing the needed information to detect, remove and prevent vulnerabilities in software, independent of the applied development process. The purpose of this paper is to explain the main reference architecture description of the repository and the more general tool stereotypes that can communicate with it. Per Håkon Meland, Shanai Ardi, Jostein Jensen, Erkuden Rios, Txus Sanchez, Nahid Shahmehri, Inger Anne Tøndel |
ARES | 7 |
| 2009 | Trusting User Defined Context in MANETs: Experience from the MIDAS ApproachabstractThe MIDAS project has developed a middleware platform for context aware MANET services. A key problem with MANETs is the lack of a central authority and pre-existing trust. Thus it is hard to enable a trusted environment where context can be verified and trusted by peers. This paper describes how the MIDAS middleware can become "secure enough" for typical applications by identifying which existing security mechanisms are most apt to use. Benefits and shortcomings of the suggested solution are analysed and discussed. Vegar Westerlund, Thomas Pronstad, Inger Anne Tøndel, Leendert W. M. Wienhofen |
ARES | 3 |
| 2008 | Covering Your Assets in Software EngineeringabstractMany security requirements elicitation techniques implicitly assume that assets are identified on beforehand, but few actually describe how this should be done. In this paper we suggest one specific method that can be used to identify and prioritize assets in any software engineering project. Martin Gilje Jaatun, Inger Anne Tøndel |
ARES | 2 |
| 2008 | A Study of Information Security Practice in a Critical Infrastructure Application
Martin Gilje Jaatun, Eirik Albrechtsen, Maria B. Line, Stig Ole Johnsen, Irene Wærø, Odd Helge Longva, Inger Anne Tøndel |
ATC | 7 |
| 2008 | A Structured Approach to Incident Response Management in the Oil and Gas Industry
Maria B. Line, Eirik Albrechtsen, Martin Gilje Jaatun, Inger Anne Tøndel, Stig Ole Johnsen, Odd Helge Longva, Irene Wærø |
CRITIS | 4 |
| 2007 | How can the developer benefit from security modeling?abstractSecurity has become a necessary part of nearly every software development project, as the overall risk from malicious users is constantly increasing, due to increased consequences of failure, security threats and exposure to threats. There are few projects today where software security can be ignored. Despite this, security is still rarely taken into account throughout the entire software lifecycle; security is often an afterthought, bolted on late in development, with little thought to what threats and exposures exist. Little thought is given to maintaining security in the face of evolving threats and exposures. Software developers are usually not security experts. However, there are methods and tools available today that can help developers build more secure software. Security modeling, modeling of e.g., threats and vulnerabilities, is one such method that, when integrated in the software development process, can help developers prevent security problems in software. We discuss these issues, and present how modeling tools, vulnerability repositories and development tools can be connected to provide support for secure software development Shanai Ardi, David Byers, Per Håkon Meland, Inger Anne Tøndel, Nahid Shahmehri |
ARES | 4 |
| 2006 | Secure Fast Handover in an Open Broadband Access Network using Kerberos-style TicketsabstractIn an Open Broadband Access Network consisting of multiple Internet Service Providers, delay due to multi-hop processing of authentication credentials is a major obstacle to fast handover between access points, effectively preventing delay-sensitive interactive applications such as Voice over IP. By exploiting existing trust relationships between service providers and access points, it is possible to pre-authenticate a mobile terminal to an access point, creating a Kerberos-style ticket that can be evaluated locally. The terminal can thus perform a handover and be authenticated to the new access point, without incurring communication and processing delays by involving other servers. Martin Gilje Jaatun, Inger Anne Tøndel, Frédéric Paint, Tor Hjalmar Johannessen, John Charles Francis, Claire Duranton |
SEC | 2 |
| 2006 | Improving Availability of Emergency Health Information without Sacrificing Patient Privacy
Inger Anne Tøndel |
SEC | 1 |