| 1997 | An attack detection system for secure computer systems - outline of the solution. | Ioanna Kantzavelou, Sokratis K. Katsikas |
| 1997 | How to trust systems. | Audun Jsang, F. Van Laenen, Svein J. Knapskog, Joos Vandewalle |
| 1997 | A taxonomy and overview of information security experiments. | Erland Jonsson, Lech J. Janczewski |
| 1997 | gGSS-API: a group enhanced generic security service. | Andrew Hutchison |
| 1997 | A comprehensive need-to-know access control system and its application for medical information systems. | Ralph Holbein, Stephanie Teufel, Othmar Morger, Kurt Bauknecht |
| 1997 | A compile-time model for safe information flow in object-oriented databases. | Masha Gendler-Fishman, Ehud Gudes |
| 1997 | Non-intrusive authentication. | Daniel Alberto Galliano, Antonio Lioy, Fabio Maino |
| 1997 | Electronic document exchange in Sweden - the legal aspects. | Per Furberg |
| 1997 | A taxonomy of electronic cash schemes. | Ernest Foo, Colin Boyd, William J. Caelli, Ed Dawson |
| 1997 | A methodology for accrediting a commercial distributed database. | Jan H. P. Eloff, R. Krner |
| 1997 | MVS-SAT: a security administration tool to support SMF protocol data evaluation. | Claudia Eckert, Th. Stoesslein |
| 1997 | Developing secure applications: a systematic approach. | Claudia Eckert, D. Marek |
| 1997 | Deriving Authorizations from Process Analysis in Legacy Information Systems. | Silvana Castano, Maria Grazia Fugini |
| 1997 | Towards a holistic view of security and safety of enterprise information and communication technologies: adapting to a changing paradigm. | Klaus Brunnstein |
| 1997 | Analysis of Java security and hostile applets. | Klaus Brunnstein |
| 1997 | Security requirements and solutions in distributed electronic health records. | Bernd Blobel |
| 1997 | New organizational forms for information security management. | Richard L. Baskerville |
| 1997 | The role of government in creating the IT security infrastructure: builder or bystander? | Mads Bryde Andersen |
| 1996 | IT security and privacy education. | Louise Yngstrm |
| 1996 | An authentication service supporting domain-based access control policies. | Nicholas Yialelis, Morris Sloman |
| 1996 | Security assurance in information systems. | Richard G. Wilsher, Helmut Kurth |
| 1996 | ID-based authentication for mobile conference call. | Shiuh-Jeng Wang, Le-Pond Chin, Jin-Fu Chang, Yuh-Ren Tsai |
| 1996 | Security enforcement in a European medical device vigilance system network. | George Vassilacopoulos, Vassilios Chrissikopoulos, Dimitrios Peppes |
| 1996 | Security model for distributed object framework and its applicability to CORBA. | Vijay Varadharajan, Thomas Hardjono |
| 1996 | Evaluation of the security of distributed IT systems through ITSEC/ITSEM: experiences and findings. | Ian Uttridge, Gualtiero Bazzana, Massimo Giunchi, Gemma Deler, Stphane Geyres, Josef Heiler |