EDBT 2026 Demo / reviewers in the wild / expert
Shang Gao 0002
dblp:28/435-2
· DBLP profile ↗
18ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0002-3722-6797ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 7 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Coping with input stage challenges in information security policy development: Information security managers' perspectives in a hybrid work environmentabstractThe purpose of this paper is to investigate how information security managers cope with the challenges in the input stage when developing an information security policy (ISP) in the context of hybrid work in the financial sector. To address this, an empirical study was conducted using semi-structured interviews with eight information security managers in Sweden’s financial sector. The data is analyzed through qualitative thematic analysis. The lens of institutional theory was also applied to interpret the results. According to the results, 18 challenges and their associated solutions for five selected inputs (i.e., risk assessment, industry standards and guidelines, regulations, existing policies and organizational business requirements) within the input stage of the ISP development are identified. For example, one recurring challenge at the input stage of an organization’s risk assessment is the potential intrusion into employees’ privacy when work occurs in their homes. Risks that are easy to identify and evaluate in a controlled office environment often become less visible or more difficult to assess in home-based settings. This creates uncertainty during the input stage because organizations must address these dispersed and varied risks without intruding on employees’ private lives. This study advances the understanding of the input stage’s challenges in the ISP development process in a hybrid work environment. While previous research has primarily examined the ISP’s input stage in traditional office-based contexts, hybrid work introduces additional complexity. According to the results, organizations must balance essential information security requirements with increasing demands for workplace flexibility. They need to ensure that security expectations remain clear and actionable, yet adaptable enough to accommodate employees working remotely. This tension between maintaining operational security and supporting flexibility poses a significant challenge at the input stage related to organizational business requirements when developing effective ISPs for hybrid work. Furthermore, through the lens of institutional theory, the results indicate that some inputs are more strongly affected by isomorphism (i.e., coercive influence), whereas mimetic and normative influences appear less directly associated with specific inputs. Additionally, a primary practical implication is the encapsulated knowledge on the challenges managers may face and the associated solutions in the input phase of ISP development in the context of hybrid work in the financial sector. Managers can adopt and adapt the suggested solutions to further strengthen their work practices in the input stage of the ISP development. Mai Nguyen, Sara Rungård, Shang Gao 0002 |
Comput. Secur. | 3 |
| 2025 | Towards software for tailoring information security policies to organisations' different target groups
Elham Rostami, Fredrik Karlsson 0001, Ella Kolkowska, Shang Gao 0002 |
Comput. Secur. | 4 |
| 2025 | Guest editorial: New frontiers in information security management
Fredrik Karlsson 0001, Shang Gao 0002 |
Inf. Comput. Secur. | 2 |
| 2025 | Trends and challenges in research into the human aspects of ransomware: a systematic mapping studyabstractPurpose The purpose of this paper is to provide an overview of the trends and challenges relating to research into the human aspects of ransomware. Design/methodology/approach A systematic mapping study was carried out to investigate the trends in studies into the human aspects of ransomware, identify challenges encountered by researchers and propose directions for future research. For each of the identified papers from this study, the authors mapped the year of publication, the type of paper, research strategy and data generation method, types of participants included, theories incorporated and lastly, the authors mapped the challenges encountered by the researchers. Findings Fifty-nine papers published between 2006 and 2022 are included in the study. The findings indicate that literature on the human aspects of ransomware was scarce prior to 2016. The most-used participant groups in this area are students and cybersecurity professionals, and most studies rely on a survey strategy using the questionnaire to collect data. In addition, many papers did not use theories for their research, but from those that did, game theory was used most often. Furthermore, the most reported challenge is that being hit with ransomware is a sensitive topic, which results in individuals and organisations being reluctant to share their experiences. Research limitations/implications This mapping study reveals that the body of literature in the area of human aspects of ransomware has increased over the past couple of years. The findings highlight that being transparent about ransomware attacks, when possible, can help others. Moreover, senior management plays an important role in shaping the information security culture of an organisation, whether to have a culture of transparency or of secrecy. Originality/value This study is the first of its kind of systematic mapping studies contributing to the body of knowledge on the human aspects of ransomware. Garret Murray, Malin Falkeling, Shang Gao 0002 |
Inf. Comput. Secur. | 3 |
| 2025 | Agile software development method cargo cult - Devising an analytical toolabstractDespite the widespread adoption of agile software development methods (ASDMs) today, many organizations struggle with effective implementation. One reason for this is that some organizations claim to use an ASDM without fully understanding its core principles, or they adhere to old practices while professing to follow a contemporary software development method. This phenomenon is sometimes referred to by practitioners as “cargo cult” (CC) behavior. However, simply labeling something as CC lacks analytical depth. This paper aims to conceptualize and validate an analytical tool for diagnosing CC and non-CC behavior in software development teams’ use of ASDMs. This study uses a longitudinal ethnographic approach to conceptualize and validate the analytical tool by analyzing four agile practices used by a global industrial manufacturing company. The analytical tool features eight stereotypes—three representing non-CC behaviors and five representing CC behaviors—designed to aid in the analysis of ASDM usage. The tool draws on Social Action Theory and Work Motivation Theory to capture and interpret the CC phenomenon in ASDM use. Using the stereotypes, 36 actions were categorized as CC behavior deviating from documented ASDM practices, and 23 actions as non-CC behavior because they aligned with the documented ASDM and reflected agile goals and values. The tool thus can help both researchers and practitioners gain a deeper understanding of ASDM use in organizations. This study advances understanding of ASDM use by moving beyond the simplistic use of the term “cargo cult”. The developed tool enables structured identification and classification of CC behaviors. The stereotypes provide a way of classifying recurring software development actions against the intended ASDM, allowing the identification of specific types of CC behaviors. The analytical tool enables managers to gain deeper insights into the underlying reasons for deviations, thereby supporting more grounded and effective agile practices within organizations. Tanja Elina Havstorm, Fredrik Karlsson 0001, Shang Gao 0002 |
Inf. Softw. Technol. | 3 |
| 2023 | Policy components - a conceptual model for modularizing and tailoring of information security policiesabstractPurpose This paper aims to propose a conceptual model of policy components for software that supports modularizing and tailoring of information security policies (ISPs). Design/methodology/approach This study used a design science research approach, drawing on design knowledge from the field of situational method engineering. The conceptual model was developed as a unified modeling language class diagram using existing ISPs from public agencies in Sweden. Findings This study’s demonstration as proof of concept indicates that the conceptual model can be used to create free-standing modules that provide guidance about information security in relation to a specific work task and that these modules can be used across multiple tailored ISPs. Thus, the model can be considered as a step toward developing software to tailor ISPs. Research limitations/implications The proposed conceptual model bears several short- and long-term implications for research. In the short term, the model can act as a foundation for developing software to design tailored ISPs. In the long term, having software that enables tailorable ISPs will allow researchers to do new types of studies, such as evaluating the software's effectiveness in the ISP development process. Practical implications Practitioners can use the model to develop software that assist information security managers in designing tailored ISPs. Such a tool can offer the opportunity for information security managers to design more purposeful ISPs. Originality/value The proposed model offers a detailed and well-elaborated starting point for developing software that supports modularizing and tailoring of ISPs. Elham Rostami, Fredrik Karlsson 0001, Shang Gao 0002 |
Inf. Comput. Secur. | 3 |
| 2022 | Awarding bonus points as a motivator for increased engagement in course activities in a theoretical system development courseabstractThis research to practice full paper focuses on gamification in a theoretical university course. Gamification has been applied in many different educational contexts as a means to motivate students to engage with course material. One commonly used gamification element is bonus points. This study aimed to investigate the use of bonus points as a motivator for increased engagement in course activities in a theoretical system development course in higher education. A mixed method approach, based on statistical analysis of course achievement, survey data and student group interviews has been applied to address this aim. According to the results, we found that awarding bonus points in the course seminars had positive effects on students’ learning motivation and engagement, as well as students’ achievements on the final course examination. This study contributes to the current literature of gamification in education by studying the implementation of bonus points in a theoretical course in higher education – two areas where there is currently a lack of studies. Furthermore, practical insights in how to implement a bonus points system in higher education have been highlighted. Jonas Moll, Shang Gao 0002 |
FIE | 2 |
| 2022 | An information classification model for public sector organizations in Sweden: a case study of a Swedish municipalityabstractPurpose The purpose of this study is to create an information classification model that is tailored to suit the specific needs of public sector organizations in Sweden. Design/methodology/approach To address the purpose of this research, a case study in a Swedish municipality was conducted. Data was collected through a mixture of techniques such as literature, document and website review. Empirical data was collected through interviews with 11 employees working within 7 different sections of the municipality. Findings This study resulted in an information classification model that is tailored to the specific needs of Swedish municipalities. In addition, a set of steps for tailoring an information classification model to suit a specific public organization are recommended. The findings also indicate that for a successful information classification it is necessary to educate the employees about the basics of information security and classification and create an understandable and unified information security language. Practical implications This study also highlights that to have a tailored information classification model, it is imperative to understand the value of information and what kind of consequences a violation of established information security principles could have through the perspectives of the employees. Originality/value It is the first of its kind in tailoring an information classification model to the specific needs of a Swedish municipality. The model provided by this study can be used as a tool to facilitate a common ground for classifying information within all Swedish municipalities, thereby contributing the first step toward a Swedish municipal model for information classification. Jan-Halvard Bergquist, Samantha Tinet, Shang Gao 0002 |
Inf. Comput. Secur. | 3 |
| 2021 | Agile Enterprise Architecture by Leveraging Use CasesabstractDespite benefits Enterprise Architecture (EA) has brought, EA has also been challenged due to its complexity, heavy workload demands, and poor user acceptance. Researchers and practitioners proposed to use EA in an agile and "business outcome-driven" way. This means that EA should not primarily be developed and used according to a pre-defined framework. Instead, EA should be developed and used for specific business purposes and by means of concrete deliverables. By doing so, a more effective and efficient way of EA application could be enabled. However, there is no common agreement on what types of business goals can be expected to be achieved by using EA (The What) and how to achieve these goals through EA solutions (The How). To address these issues, we analysed the information provided by leading EA tool vendors available on their websites to get inspiration. The results showed that Use Cases (UCs) are used generally to motivate potential EA users by focusing on specific business issues. Then, EA solutions to address such business requirements or challenges are scoped and derived accordingly. We expect relevant findings could bring inspiration to agile EA engineering, change the EA “heavy-weight” reputation, and improve the application of EA even among its sceptics. Hong Guo 0004, Jingyue Li, Shang Gao 0002, Darja Smite |
ENASE | 3 |
| 2021 | Enhancing employees information security awareness in private and public organisations: A systematic literature reviewabstractPreserving the confidentiality, integrity and availability (CIA) of an organisation's sensitive information systems assets against attacks and threats is a challenge in this digital age. Organisations worldwide make huge investments in information security technological countermeasures. Nonetheless, organisations in many cases fail to protect their information assets as they rely mainly on technical solutions which are not contextually compatible and sufficient. As a matter of fact, a significant number of organisational information security incidents are due to the exploitation of human elements that directly and/or indirectly cause the majority of security incidents. Therefore, employees’ information security awareness (ISA) becomes one of the critical aspects of protection against undesirable information security behaviours. However, to date, there is limited synthesised knowledge about methods for enhancing ISA and integrated insights on factors affecting employees’ ISA levels. This study, therefore, provides a systematic review of the literature on ISA and puts forward a state-of-the-art collection of ISA methods and factors for enhancing employees’ ISA within both private and public sector organisations. The results indicate that various methods and factors are used to enhance employees’ ISA in organisations. Theoretical models and gamification are the methods widely used in both private and public organisations, whereas the constructivist approach and violation detections are some of the methods used only in private organisations. Furthermore, this study offers some insights into the latest trends in ISA content development methods and factors, and fosters good ISA practice by disseminating information and knowledge amongst Information Security professionals to help them build an overarching ISA development programme in their organisations. Khando Khando, Shang Gao 0002, M. Sirajul Islam, Ali Salman |
Comput. Secur. | 2 |
| 2020 | Requirements for computerized tools to design information security policiesabstractInformation security is a hot topic nowadays, and while top-class technology exists to safeguard information assets, organizations cannot rely on technical controls alone. Information security policy (ISP) is one of the most important formal controls when organizations work with implementing information security. However, designing ISPs is a challenging task for information security managers and to ease the burden, computerized tools have been suggested to support this design task. One important prerequisite for developing such tools is the requirements. However, existing research has, to a very limited extent, synthesized existing requirements. Against this backdrop, this study aims to elicit a set of requirements, anchored in existing ISP research, for computerized tools that support ISP design. First, we summarize existing ISP research into 14 requirement themes. Second, we suggest a set of user stories that operationalize these requirement themes from an information security manager's perspective. Third, we suggest another set of user stories that operationalize the same requirement themes from an ISP user's perspective. In total, we suggest 28 user stories that can act as a starting point for both researchers and practitioners when developing computerized tools that provide ISP design support for information security managers. Elham Rostami, Fredrik Karlsson 0001, Shang Gao 0002 |
Comput. Secur. | 3 |
| 2015 | A Workflow for Model Driven Game DevelopmentabstractSoftware development faces challenges from high expectation of software qualities, complexity of software and long development cycle. While Domain Specific Modeling (DSM) is helping developers overcome many of these challenges in many domains, it is not generally applied in the computer game domain. DSM can be hard to apply in the computer game domain because of the complexity of computer game domain knowledge and the peculiarity of traditional computer game development process. Without fully understanding these issues and properly solving them, the strength of DSM approaches will be constrained and game developers will be reluctant to use DSM. In this article, we investigate the development process and explore the feasibility of fitting DSM tasks in traditional computer game development in a compact way to lower cost and improve software quality. We introduce the workflow and illustrate the usage of it by presenting a case study. Further, we discuss the benefits and costs of involving DSM solutions in computer game development. Finally, we present the limitations and future work. Hong Guo 0004, Hallvard Trætteberg, Alf Inge Wang, Shang Gao 0002 |
EDOC | 4 |
| 2015 | Lessons from Practicing an Adapted Model Driven Approach in Game Development
Hong Guo 0004, Hallvard Trætteberg, Alf Inge Wang, Shang Gao 0002, Letizia Jaccheri |
ICEC | 4 |
| 2015 | Understanding business models of mobile ecosystems in China: a case studyabstractThis study aims to have a better understanding of business models of mobile ecosystems in China. On the basis of a literature review on the business model, we propose an analysis framework consisting of four major dimensions of business model concepts to study how a mobile ecosystem works, including value network, value architecture, value proposition, and value finance. Four research questions are presented in this study. To address this, a case study with the WeChat ecosystem is carried out. The key findings from the case study are presented in accordance with identified four dimensions of business model concepts. Shang Gao 0002, John Krogstie |
MEDES | 1 |
| 2015 | An Evaluation of Ontology Based Domain Analysis for Model Driven DevelopmentabstractAlthough Domain Analysis (DA) is important for Model Driven Development (MDD), traditional DA methods are demanding and not practical in many situations. When computer games are developed, game design (problem domain) is usually decided in a gradual way within iterations where software prototypes are constructed and playtest are performed. In such a case, it is not practical to fit a heavyweight DA in the highly iterative process. Researchers indicated that vocabularies were expected to automate game design. Such vocabularies can be reused in another form in DA tasks. In this research, the authors developed an ontology and a DA procedure based on it. To evaluate them, theoretical analysis, case studies, and a user acceptance survey were used. The results indicated that the ontology met the general requirement as a domain vocabulary, and it enhanced the DA process in an expected way. Most of external potential users (46 in total) considered the ontology useful and easy to use. Hong Guo 0004, Shang Gao 0002, John Krogstie, Hallvard Trætteberg, Alf Inge Wang |
Int. J. Semantic Web Inf. Syst. | 2 |
| 2013 | Relating Goal Modeling with BPCM Models in a Combined Framework
Shang Gao 0002 |
ICCSA (3) | 1 |
| 2012 | An exploratory study on lifestyles and the adoption of mobile services in ChinaabstractThis study examines the relationship between the lifestyles of Chinese consumers and the adoption of mobile services. Based on a sample from 313 respondents from the biggest city in central China, the results show that consumers with different lifestyles have different preferences over a number of identified mobile services. It is found that there are some lifestyle factors, such as the investment consciousness and the financial contentment consciousness, having significant negative impact on the adoption of office/learning tools on mobile devices. Furthermore, Chinese consumers are clustered into four lifestyle segments by two dimensions: the quality-awareness fashionable dimension and the economical dimension. The findings demonstrate that the quality-awareness fashionable dimension has stronger impact than the economical dimension toward the adoption of all the five types of mobile services. Shang Gao 0002, Wenying Zheng, Wenyan Zhou |
MoMM | 1 |
| 2012 | The adoption of mobile tourism services: an empirical studyabstractThis study is investigating the adoption of mobile tourism services in Norway. By expanding the Technology Acceptance Model (TAM), a research model, called mobile services acceptance model including seven research hypotheses is presented. The proposed research model and research hypotheses were empirically tested using data collected from a survey of 47 users of a mobile tourism service called extended Mobile Tourist Service Recommender (MTSR) in a city in Norway. The findings indicated that the fitness of the research model is good and strong support was found for the seven research hypotheses. Among all the factors, the personal initiatives and characteristics had the most significant influence on the intention to use MTSR. Shang Gao 0002, Per Christian Røinend, John Krogstie |
MoMM | 1 |