{"id":"W3016717485","doi":"10.1007/s10664-020-09814-x","title":"Using machine learning to assist with the selection of security controls during security assessment","year":2020,"lang":"en","type":"article","venue":"Empirical Software Engineering","topic":"Information and Cyber Security","field":"Computer Science","cited_by":13,"is_retracted":false,"has_abstract":false,"ca_institutions":"University of Ottawa","funders":"","keywords":"Operationalization; Computer science; Security information and event management; Security controls; Computer security model; Computer security; Context (archaeology); Security service; Security testing; Cloud computing security; Security engineering; Security through obscurity; Security domain; Standard of Good Practice; Security convergence; Information security; Risk analysis (engineering); Software security assurance; Control (management); Artificial intelligence; Business; Cloud computing; Network security policy","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.00346741,0.0007287365,0.0005030538,0.001974062,0.0005725651,0.001663951,0.0006921933,0.0008384075,0.003392127],"category_scores_gemma":[0.02062868,0.000253911,0.000261142,0.000589005,0.0003309097,0.001433412,0.0007324985,0.001064289,0.001018098],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0006019461,"about_ca_system_score_gemma":0.001271165,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.003833418,"about_ca_topic_score_gemma":0.006346856,"domain_scores_codex":[0.9981345,0.0009907791,0.0001360485,0.0002626698,0.0003476354,0.0001283413],"domain_scores_gemma":[0.988281,0.007693822,0.001194259,0.0006420561,0.001916577,0.0002722988],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0008597159,0.001139183,0.07121766,0.0001991028,0.0001433605,0.0001951001,0.0008409146,0.113423,0.02524208,0.004393025,0.006040513,0.7763063],"study_design_scores_gemma":[0.00004581562,0.0001715429,0.01353815,0.00005640633,0.00003410714,0.0000688392,0.0002223038,0.9600204,0.01760419,0.006437838,0.001759151,0.00004135592],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.3545561,0.0002786758,0.627292,0.0008791965,0.0001169645,0.0003079044,0.0003208567,0.004934245,0.01131403],"genre_scores_gemma":[0.9005856,0.00004510627,0.09795949,0.00006910272,0.00001321747,0.00005139393,0.0001434514,0.00005793101,0.001074765],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003833418,"threshold_uncertainty_score":0.01833767,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01568697951433107,"score_gpt":0.2603828896955933,"score_spread":0.2446959101812622,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}