Academic staff

Diamantopoulou Vasiliki

Personal Information
Diamantopoulou Vasiliki

Assistant Professor


vdiamant [at] aegean [dot] gr

+30-2273082273

B12

Personal Website

Full CV

Citations (Google Scholar)

Copyright Notice: This material is presented to ensure timely dissemination of scholarly and technical work. Copyright and all rights therein are retained by authors or by other copyright holders. All persons copying this information are expected to adhere to the terms and constraints invoked by each author's copyright. In most cases, these works may not be reposted or mass reproduced without the explicit permission of the copyright holder.


Journal Publications

[1]
C. Kalloniatis, V. Diamantopoulou, K. Kotis, C. Lyvas, K. Maliatsos, M. Gay, A. G. Kanatas, C. Lambrinoudakis, Towards the design of an assurance framework for increasing security and privacy in connected vehicles, International Journal of Internet of Things and Cyber-Assurance, Vol. 1, No. 3-4, pp. 244-266, 2020, Inderscience Enterprises Ltd.
V. Diamantopoulou, A. Tsohou, M. Karyda, From ISO/IEC27001:2013 and ISO/IEC27002:2013 to GDPR Compliance Controls, Information and Computer Security, Vol. 28, No. 4, 2020, Emerald, https://www.emerald.com/insight/content/...
Abstract:
Purpose – This paper aims to identify the controls provisioned in ISO/IEC 27001:2013 and ISO/IEC 27002:2013 that need to be extended in order to adequately meet, data protection requirements set by the General Data Protection Regulation (GDPR); it also indicates security management actions an organisation needs to perform to fulfil GDPR requirements. Thus, ISO/IEC 27001:2013 compliant organisations, can use this work i) as a basis for extending the already existing security control modules towards data protection; ii) as guidance for reaching compliance with the Regulation. Design/methodology/approach – This study has followed a two-step approach; First synergies between ISO/IEC 27001:2013 modules and GDPR requirements were identified, by analysing all 14 control modules of the ISO/IEC 27001:2013, and proposing the appropriate actions towards the satisfaction of data protection requirements. Second, we identified GDPR requirements not addressed by ISO/IEC 27001:2013. Findings – The findings of this work include i) the identification of the common ground between the security controls that ISO/IEC 27001:2013 includes and the requirements that the GDPR imposes; ii) the actions that need to be performed based on these security controls to adequately meet the data protection requirements that the GDPR imposes; iii) the identification of the remaining actions an ISO/IEC 27001 compliant organisation needs to perform to be able to adhere with the GDPR. Originality/value – This work provides a gap analysis and a further steps identification regarding the additional actions that need to be performed to allow an ISO/IEC 27001:2013 certified organisation to be compliant with the GDPR.
V. Diamantopoulou, A. Androutsopoulou, S. Gritzalis, Y. Charalabidis, Preserving Digital Privacy in e-Participation Environments: Towards GDPR Compliance, Information - Special Issue "Security Requirements Engineering: Designing Secure Socio-Technical Systems", pp. 1–27, 2020, MDPI, https://www.mdpi.com/journal/information...
Abstract:
The application of the General Data Protection Regulation (GDPR) 2016/679/EC, the Regulation for the protection of personal data, is a challenge and must be seen as an opportunity for the redesign of the systems that are being used for the processing of personal data. An unexplored area where systems are being used to collect and process personal data are the e-Participation environment. The latest generations of such environments refer to sociotechnical systems based on the exploitation of the increasing use of Social Media, by using them as valuable tools, able to provide answers and decision support in public policy formulation. This work explores the privacy requirements that GDPR imposes in such environments, contributing to the identification of challenges that e-Participation approaches have to deal with, with regard to privacy protection.
G. Kavalieratos, V. Diamantopoulou, S. K. Katsikas, Shipping 4.0: Security requirements for the Cyber-Enabled Ship, SS on Security and Privacy in Industry 4.0 - IEEE Transactions on Industrial Informatics, Vol. 16, No. 10, pp. 6617 - 6625, 2020, IEEE, (to_appear), https://ieeexplore.ieee.org/xpl/RecentIs..., indexed in SCI-E, IF = 7.377
Abstract:
The Cyber-Enabled Ship (C-ES) is either an autonomous or a remotely controlled vessel which relies on interconnected cyber physical-systems (CPS) for its operations. Such systems are not well protected against cyber attacks. Considering the criticality of the functions that such systems provide, it is important to address their security challenges, thereby ensuring the ship's safe voyage. In this work we leverage the Maritime Architectural Framework reference architecture to analyze and describe the environment of the C-ES. We then apply the Secure Tropos methodology to systematically elicit the security requirements of the three most vulnerable CPSs onboard a C-ES, namely the Automatic Identification System (AIS), the Electronic Chart Display Information System (ECDIS) and the Global Maritime Distress and Safety System (GMDSS). The outcome is a set of cyber security requirements for the C-ES ecosystem in general and these systems in particular.

V. Diamantopoulou, C. Mouratidis, Practical Evaluation of a Reference Architecture for the Management of Privacy Level Agreements, Information and Computer Security, 2019, Emerald, http://www.emeraldgrouppublishing.com/pr...
Abstract:
With the enforcement of the General Data Protection Regulation, any entity seeking compliance to specific privacy- and security-related requirements, the adoption of Privacy by Design and Security by Design principles can be considered as a legal obligation for any such entity processing EU citizens’ personal data. A formal way to support Data Controllers towards their compliance to the new Regulation could be the use of a Privacy Level Agreement (PLA), a mutual agreement of the privacy settings between a Data Controller and a Data Subject, that supports privacy management, by analysing privacy threats, vulnerabilities and Information Systems’ trust relationships. However, the concept of PLA has only been proposed on a theoretical level. In this paper, we propose a novel reference architecture to enable PLA management in practice, and we report on the application and evaluation of PLA management. To this aim, two different domains have been selected acting as real-life case studies, the public administration and the healthcare, where special categories of personal data is processed. The results of this evaluation are rather positive, indicating that the adoption of such an agreement promotes the transparency of an organisation while enhances Data Subjects’ trust.
M. Salnitri, K. Angelopoulos, M. Pavlidis, V. Diamantopoulou, C. Mouratidis, P. Giorgini, Modelling the Interplay of Security, Privacy and Trust in Sociotechnical Systems: A Computer-Aided Design Approach, Journal of Software and Systems Modeling, 2019, Springer, https://link.springer.com/journal/10270, indexed in SCI-E, IF = 1.722
Abstract:
Personal data has become a central asset for multiple enterprise applications and online services offered by private companies, public organisations or a combination of both. The sensitivity of such data and the continuously growing legislation that accompanies their management dictate the development of methods that allow the development of more secure, trustworthy software systems with focus on privacy protection. In this work we propose a method that combines two modelling approaches to cover both early and late requirements specification, giving emphasis on security, privacy and trust. The novelty of our proposal is that it provides the means for software designers and security experts to analyse the system-to-be from multiple aspects, starting from identifying high level goals to the definition of business process composition, and\\r\\nelicitation of mechanisms to fortify the system from external threats. Our approach, which is supported by two CASE tools, demonstrates its application to a real-world case study.
C. Kalloniatis, V. Diamantopoulou, K. Kotis, C. Lyvas, K. Maliatsos, M. Gay, A. G. Kanatas, C. Lambrinoudakis, Towards the design of an assurance framework for increasing security and privacy in Connected Vehicles, International Journal of Internet of Things and Cyber-Assurance, 2019, Inderscience Publishers, (to_appear), https://www.inderscience.com/jhome.php?j...
Abstract:
Intelligent Transport Systems (ITS) play a key role in our daily activities. ITS development over the last decades has been based on the rapid evolution of information and communication technologies (ICT), which include processing capabilities, availability of hardware and communication technologies. Moreover, ITS use ICT to improve sustainability, efficiency, innovation and safety of transportation networks helping towards better management of transportation networks with the use of advanced technologies, which in turn facilitate monitoring and management of information. However, as the development of ITS services increases so does the users' awareness regarding the degree of trust that they demonstrate on adopting this kind of services. The later has brought to light several security and privacy concerns that ITS analysts should consider when designing and implementing various IT related services. This paper moves into this direction by identifying how risk analysis can interact with security and privacy requirements’ engineering world, in order to provide a holistic approach for reasoning about security and privacy in such complex environments like ITS systems. The key contribution of the paper is the conceptual alignment of three well-known methods (EBIOS, Secure Tropos and PriS) as the first step towards the design of a complete assurance framework that will support analysts in designing and consequently implementing secure and trustworthy ITS services.

C. Mouratidis, V. Diamantopoulou, A Security Analysis Method for Industrial Internet of Things, Applied Cryptography, Security, and Trust Computing for Industrial Internet-of-Things, Vol. 14, No. 9, pp. 4093-4100, 2018, IEEE Transactions on Industrial Informatics, https://ieeexplore.ieee.org/abstract/doc..., indexed in SCI-E, IF = 6.764
Abstract:
The Industrial Internet of Things (IIoT) provide an opportunity for industries to build large interconnected systems that utilise various technologies such as personal computers, wireless devices, and sensor devices and bring together the cyber and the physical world. Such systems provide us with huge advantages but they also introduce major security challenges at both the design and runtime stages. The literature argues for the need to introduce security-by-design methods, which enable security analysis and mitigation of security threats. This paper proposes a novel security-by-design method for IIoT environments across two different levels, design/modelling and runtime/simulation. Our method supports analysis of security requirements and identification of attack paths and their integration for the mitigation of potential vulnerabilities. We demonstrate its applicability through a real case study on a critical environment from the maritime sector which demonstrates that our method helps to identify security mechanisms to mitigate attacks on critical assets.
V. Diamantopoulou, C. Mouratidis, Applying the Physics of Notation to the Evaluation of a Security and Privacy Requirements Engineering Methodology, Information and Computer Security, Vol. 26, No. 4, pp. 382-400, 2018, Emerald Publishing Limited, https://www.emeraldinsight.com/eprint/bx...
Abstract:
Security and Privacy Requirements Engineering Methodologies are considered an important part of the development process of systems, especially for the ones that contain and process a large amount of critical information and inevitably need to remain secure and thus, ensuring privacy. These methodologies provide techniques, methods, and norms for tackling security and privacy issues in Information Systems. In this process, the utilisation of effective, clear and understandable modelling languages with sufficient notation is of utmost importance, since the produced models are used not only among IT experts or among security specialists, but also for communication among various stakeholders, in business environments or among novices in an academic environment. This paper evaluates the effectiveness of a Security and Privacy Requirements Engineering Methodology, namely Secure Tropos, on the nine principles of the Theory of Notation. Our qualitative analysis revealed a partial satisfaction of these principles.

V. Diamantopoulou, A. Androutsopoulou, Y. Charalabidis, Towards a Taxonomy of Services Offered by Start-up business Incubators: Insights from the Mediterranean Region, International Journal of Entrepreneurship and Small Business, Vol. 33, No. 4, pp. 494-513, 2017, Inderscience Publishers
Abstract:
Business incubation aims at stimulating entrepreneurship and nurturing ideas to transform them to viable ventures and drive economic growth. Since the emergence of the concept, some decades ago, the incubation process and its underlying services have been evolved, while incubators around the world are continuously increasing. These incubators vary according to their type, operation model and specialisation. The aim of this paper is to define a comprehensive framework that serves as a basis for the categorisation of all services that can be part of the incubation process. The proposed taxonomy, comprised of 8 core service categories, has then been applied on ten University associated incubators from the Mediterranean region, since the various socio-economic conditions encountered there, cause particular interest in the prospect of entrepreneurship. An indicative sample of five European, Middle East and North African countries (i.e. Italy, Greece, Turkey, Israel, Egypt) has been defined, with the Mediterranean Sea uniting them and shaping their unique characteristics. We selected to focus on the University incubators from this area as they bridge the innovation potential of research and academia communities with the real business world and can underpin a sustainable and robust entrepreneurship model. By mapping the sample with the categories of services they offer, we intended to find out how they differentiate from other types of incubators. It was concluded that University incubators fall shorter only in the provision of administrative services in relation to the typical incubators. However, the purpose of this framework is to be further used as a tool both for policy makers’ and support their resource allocation decisions and help the internal stakeholders of incubator activities identify and adopt best practice models.

S. Arvanitis, E. Loukis, V. Diamantopoulou, Are ICT, Workplace Organization and Human Capital Relevant for Innovation? A Comparative Study Based on Swiss and Greek Micro Data, International Journal of the Economics of Business, Vol. 23, No. 3, pp. 319-349, 2016, Taylor & Francis
Abstract:
This paper investigates and compares the relationships for Swiss and Greek firms between indicators for the intensity of use of modern information and communications technologies (ICT), several forms of workplace organization, and human capital, on the one hand, and several measures of innovation performance at firm level, on the other hand. For the Swiss firms, we find that ICT contribute to innovation activities (a) as enablers of process innovation (but not of product innovation) and (b) as means for increasing the efficiency of the R&D process. The organizational variables for “work design” and “employee voice” show significant positive correlations for most innovation indicators. Human capital matters primarily for R&D activities. The findings for the Greek firms indicate positive correlations of ICT with product and process innovation and of new “work design” with product innovation and R&D. No correlation of human capital with innovation could be found. No complementarities for the three factors with respect to innovation performance could be detected in either country.

L. Spiliotopoulou, Y. Charalabidis, E. Loukis, V. Diamantopoulou, A framework for advanced social media exploitation in government for crowdsourcing, Transforming Government: People, Process and Policy, Vol. 8, No. 4, pp. 545-568, 2014, Emerald
Abstract:
Purpose – This paper aims to develop and evaluate, in “real-life” pilot applications, a framework for advanced social media exploitation by government agencies in their policy-making processes to promote public participation and conduct crowdsourcing. Design/methodology/approach – This framework has been developed through cooperation with public sector employees experienced in public policy-making, using both qualitative and quantitative techniques: semi-structured focus group discussions, scenarios development and questionnaire surveys. The evaluation of the framework has been conducted through semi-structured focus group discussions with public sector employees involved in the pilot applications. Findings – A framework has been developed for advanced social media exploitation by government agencies, which is based on the automated posting of policy-related content to multiple social media, and then retrieval and processing of citizens’ interactions with it (e.g. views, likes, comments and retweets), using the application programming interfaces (API) of these social media. Furthermore, a supporting information and communication technologies (ICT) infrastructure and an application process model for it were developed. Its evaluation, based on “real-life” pilot applications, leads to useful insights concerning its capabilities, strengths and weaknesses. Research limitations/implications – The proposed framework has been evaluated in a small number of pilot applications, so further evaluation of it is required, in various types of government agencies and for different kinds of policy consultations. Practical/Implications – The above framework enables government agencies to communicate with wider and more heterogeneous audiences in a short time and at a low cost, increase public participation in their policy-making processes, collect useful knowledge, ideas and opinions from citizens and, finally, design better, more socially rooted, balanced and realistic policies. Originality/value – This research contributes to the development of knowledge concerning advanced practices for effective social media exploitation in government (which is currently limited, despite the considerable relevant knowledge developed in this area for the private sector), by developing and evaluating a framework for advanced and highly automated exploitation of multiple social media by government agencies. Furthermore, an evaluation methodology for such practices has been developed, which is based on sound theoretical foundations.

S. Arvanitis, E. Loukis, V. Diamantopoulou, New Technologies and Traditional Innovation Determinants in the Greek Economy, Journal of Balkan and Near Eastern Studies, Vol. 15, No. 4, pp. 434–458, 2013, Taylor & Francis, Routledge, indexed in SCI-E, IF = 0.616
Abstract:
It is widely recognized that the recent economic crisis in Greece is due not only to excessive government spending and tax evasion, but also to the low competitiveness of its economy. Innovation has become of critical importance for the competitiveness of firms, sectors and countries in the modern economy. This paper presents an empirical study of the ‘new’ innovation determinants based on information and communication technologies (ICT) and also of the ‘traditional’ innovation determinants in the Greek economy. In particular, it investigates the impact of three different ICT (internal information systems (IS), e-sales and e-procurements) and also of six important traditional innovation determinants identified by previous relevant research (four ‘external’ ones—demand expectation, price and non-price competition, market concentration—and two ‘internal’ ones—investment in research and development (R&D) and firm size), on the innovation performance of Greek firms. It is based on firm-level data collected through a survey of 271 Greek firms before the start of the economic crisis, which have been used for the estimation of regression models. It is concluded that in the Greek ‘innovation-averse’ national context (characterized by low level of innovation and uncertainty avoidance culture) none of the examined external (market-related) traditional innovation determinants has an impact on product or process innovation of firms, while on the contrary the internal ones, R&Dexpenditure per employee and size, affect positively both. Furthermore, the examined new technologies seem to be important drivers of innovation: it is concluded that the internal IS have a positive impact on both product and process innovation, the e-sales only on process innovation, but the e-procurement on none. Our results indicate the high potential of ICTas innovation drivers even in such innovation-averse and lower economic development contexts, which, however, vary between different types of ICT.
S. Arvanitis, E. Loukis, V. Diamantopoulou, The Effect of Soft ICT Capital on Innovation Performance of Greek Firms, Journal of Enterprise Information Management, Vol. 26, No. 6, pp. 679-701, 2013, Emerald, indexed in SCI-E, IF = 2.126
Abstract:
Purpose – The purpose of this paper is to investigate the effects of four types of “soft” information and communication technologies (ICT) capital related to ICT knowledge and skills (ICT personnel, ICT training of ICT personnel and users, ICT unit) on the innovation performance of Greek firms. Furthermore, the paper compares these effects with the ones of the hard ICT capital and also of four important “traditional” innovation determinants identified from previous research in this area (demand expectation, price and non-price competition, market concentration). Design/methodology/approach – A quantitative methodology has been adopted for investigating the above effects, based on the estimation of regression models. Using data collected through a survey based on a structured questionnaire from 271 Greek firms, innovation models have been estimated, having as independent variables measures of hard ICT capital, the examined four types of soft ICT capital and also the above traditional innovation determinants. Findings – The paper has been concluded that in the innovation averse Greek national context the examined traditional innovation determinants have very low impact on firms’ innovation performance, however, on the contrary both hard ICT capital, and three out of the four examined types of soft ICT capital (ICT personnel, ICT training of ICT personnel and users) have positive impact on both process and product/services innovation. Furthermore, it has been found that the total effect of these three knowledge and skills related types of soft ICT capital on innovation performance is stronger than the effect of the hard ICT capital. Research limitations/implications – The main limitations of the paper are that it uses simple innovation performance measures (not distinguishing between different types of innovations), and also is based on firm-level data collected from a single country. The paper has interesting implications for future research on the impact of the relation between ICT and innovation, which should not any more neglect the soft ICT capital, but consider various types of both hard and soft ICT capital. Practical implications – The results of the paper can be useful to firms’ chief information officers and chief executive officers and also to consultants and practitioners interested in maximizing the exploitation of the innovation potential of ICT, in order to understand the hard and soft aspects of ICT that have to be developed for this purpose and optimize firms’ ICTrelated investment. Originality/value – The limited previous empirical literature concerning the effect of ICT on innovation focus on the hard ICT capital (mainly on ICT equipment) and neglect the role of the soft ICT capital. The paper contributes to fill this research gap, by examining the effects of three types of ICT capital, and also – for comparison and regression models’ completeness purposes – of hard ICT capital and of four traditional innovation determinants, on firms’ innovation performance.
Contact
  • President: Skoutas Dimitrios
  • Secretariat Head: Karagianni Kalliopi
  • Undergraduate Secretariat: ICS Eng. Department
  • Postgraduate Secretariat: ICS Eng. Department
  • Email: dicsd [at] aegean [dot] gr
  • Phone: 2273082000
  • Address: Κτήριο Λυμπέρη, Παλαμά 2 & Γοργύρας, Τ.Κ. 83200
  • Website: www.icsd.aegean.gr
  • Office Hours: Δευτέρα - Παρασκευή: 8:00 - 16:00
Στατιστικά Σπουδών
Μέσος Όρος Βαθμού Πτυχίου

7.76

Μέσος χρόνος Απόκτησης Πτυχίου

6.5 έτη

Μαθήματα με εργαστήριο

46

Κύκλοι Σπουδών

6

Μαθήματα Υποχρεωτικά

36

Μαθήματα Κύκλου

8

Σύνολο μαθημάτων για πτυχίο

55

Διπλωματική Εργασία

Υποχρεωτική