Kernel Metadata Declaration — on demand
ISO 26324 asks a DOI Registration Agency to produce a Kernel Metadata Declaration for every DOI it issues. Give any DOI: its public record becomes a record in the Smart Scholars DOI Metadata Format 1.0, checked against every rule, and declared as the Kernel XML.
✓ Meets every rule of the format
The record below is complete and every controlled value is a DOI Attribute Value Set 2.3 spelling. The Declaration on the right follows DOIMetadataKernel.xsd element by element.
What the DOI identifies
Contractual Agreement Aspect of Third-party Risk Management in Information Security
10.46243/jst.2025.v10.i07.pp01-09 · JournalArticle — an article in a journal · Digital · Visual · Language
Published 2025-07-18
Part of Journal of Science & Technology · ISSN 2456-5660 · vol. 10 · no. 7 · pp. 1–9
Principal agents
- Ayoub Alfawzan (author → Author)
- Omer Alrwais (author → Author)
- Longman Publishers (publisher → Publisher)
Also in the record, outside the Kernel: the abstract, the licence, 2 links, 7 references. Source: Crossref (member 25296), registered 2025-08-26, last deposited 2026-09-07.
System metadata — ISO 26324:2025, Annex B · DOI Handbook 10.1
Each element by the standard's name and the Handbook's (in grey), read off the record.
| DOI Name DOI name | 10.46243/jst.2025.v10.i07.pp01-09 |
| Referent Type referentType | Creation |
| Referent Sub-Type referentSubType | JournalArticle — an article in a journal |
| Referent Name(s) referentName(s) | Contractual Agreement Aspect of Third-party Risk Management in Information Security (PrincipalTitle) |
| Basic Metadata basicMetadata | author: Ayoub Alfawzan author: Omer Alrwais publisher: Longman Publishers published: 2025-07-18 part of: Journal of Science & Technology · ISSN 2456-5660 · vol. 10 · no. 7 · pp. 1–9 form: Digital · Visual · Language |
| Referent Identifier(s) alternateIdentifier(s) | none besides the DOI |
| Registration Authority registrationAuthorityCode | Crossref — issued by Crossref (member 25296); held here as a copy |
| Created Date issueDate | 2025-08-26 |
| relatedIdentifiers | none needed — the descriptive metadata is in this record |
The record
{
"format": "smartscholars-doi-metadata/1.0",
"doi": "10.46243/jst.2025.v10.i07.pp01-09",
"referent": "Creation",
"type": "JournalArticle",
"structural_type": "Digital",
"modes": [
"Visual"
],
"characters": [
"Language"
],
"titles": [
{
"value": "Contractual Agreement Aspect of Third-party Risk Management in Information Security",
"type": "PrincipalTitle"
}
],
"identifiers": [
{
"type": "DOI",
"value": "10.46243/jst.2025.v10.i07.pp01-09"
}
],
"agents": [
{
"role": "author",
"name": {
"given": "",
"family": "Ayoub Alfawzan"
},
"sequence": "first"
},
{
"role": "author",
"name": {
"given": "",
"family": "Omer Alrwais"
},
"sequence": "additional"
},
{
"role": "publisher",
"name": {
"org": "Longman Publishers"
}
}
],
"dates": {
"published": "2025-07-18",
"date_type": "PublicationDate",
"online": "2025-07-18"
},
"container": {
"type": "Journal",
"titles": [
{
"value": "Journal of Science & Technology",
"type": "PrincipalTitle"
},
{
"value": "J. sci. technol.",
"type": "AbbreviatedTitle"
}
],
"identifiers": [
{
"type": "ISSN",
"value": "2456-5660",
"medium": "electronic"
}
],
"volume": "10",
"issue": "7",
"pages": {
"first": "1",
"last": "9"
}
},
"links": [
{
"url": "https://jst.org.in/index.php/pub/article/view/1332",
"return_type": "text/html",
"primary": true
},
{
"url": "https://jst.org.in/index.php/pub/article/download/1332/1008",
"purpose": "text-mining",
"return_type": "application/pdf"
}
],
"abstract": {
"value": "Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security."
},
"license": {
"url": "https://creativecommons.org/licenses/by/4.0",
"start": "2025-07-18",
"applies_to": "unspecified"
},
"references": [
{
"key": "ref1",
"doi": "10.1109/itsim.2008.4631922",
"unstructured": "Aris, S. R. H. S., Arshad, N. H., & Mohamed, A. (2008). Conceptual framework on risk management in IT outsourcing projects. management, 36(37), 37-38"
},
{
"key": "ref2",
"doi": "10.1080/1097198x.2021.1993725",
"unstructured": "Bhatti, B. M., Mubarak, S., & Nagalingam, S. (2021). Information security risk management in it outsourcing–a quarter-century systematic literature review. Journal of Global Information Technology Management, 24(4), 259-298"
},
{
"key": "ref3",
"unstructured": "Boggavarapu, S. (2021). The Effect of Third-Party Service Providers on Information Security Breaches at Financial Institutions (Doctoral dissertation, University of the Cumberlands)"
},
{
"key": "ref4",
"doi": "10.1365/s43439-021-00029-4",
"unstructured": "Bomhard, D., & Daum, A. (2021). Cybersecurity in outsourcing and cloud computing: a growing challenge for contract drafting, International Cybersecurity Law Review, 2(1), 161-171"
},
{
"key": "ref5",
"unstructured": "Haller, J., & Wallen, C. (2016). Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach, Carnegie Mellon University Software Engineering Institute. Ayoub Alfawzan, Omer Alrwais: Contractual Agreement Aspect of Third-party Risk Management in Information Security"
},
{
"key": "ref6",
"unstructured": "Singh, A. (2009). Improving Information Security Risk Management [Unpublished doctoral dissertation]. University of Minnesota"
},
{
"key": "ref7",
"doi": "10.2139/ssrn.3763399",
"unstructured": "VanHoy, J. (2021). Third Party Risk Management. Available at SSRN 3763399"
}
],
"record": {
"registrant": "Longman Publishers",
"registered": "2025-08-26",
"updated": "2026-09-07",
"issue_number": 1,
"source": "crossref-api",
"source_agency": "Crossref (member 25296)"
}
}The Kernel Metadata Declaration
DOIMetadataKernel.xsd · namespace http://www.doi.org/2010/DOISchema · Attribute Value Sets 2.3 · draft — the agency's DOI name is filled in on accreditation
<?xml version="1.0" encoding="UTF-8"?>
<!-- DRAFT declaration: Smart Scholars is not yet a DOI Registration Agency. registrationAgencyDoiName is a marker (10.0/ is no RA's prefix) and is filled in on accreditation. -->
<kernelMetadata xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.doi.org/2010/DOISchema https://www.doi.org/doi_schemas/DOIMetadataKernel.xsd" xmlns="http://www.doi.org/2010/DOISchema">
<referentDoiName>10.46243/jst.2025.v10.i07.pp01-09</referentDoiName>
<primaryReferentType>Creation</primaryReferentType>
<registrationAgencyDoiName>10.0/smart-scholars-draft</registrationAgencyDoiName>
<issueDate>2026-10-04</issueDate>
<issueNumber>1</issueNumber>
<referentCreation>
<name>
<value>Contractual Agreement Aspect of Third-party Risk Management in Information Security</value>
<type>PrincipalTitle</type>
</name>
<identifier>
<nonUriValue>10.46243/jst.2025.v10.i07.pp01-09</nonUriValue>
<uri returnType="text/html" doesContentNegotiation="true">https://doi.org/10.46243/jst.2025.v10.i07.pp01-09</uri>
<type>DOI</type>
</identifier>
<identifier>
<uri returnType="text/html">https://jst.org.in/index.php/pub/article/view/1332</uri>
<type>URI</type>
</identifier>
<identifier>
<uri>https://jst.org.in/index.php/pub/article/download/1332/1008</uri>
<type>URI</type>
</identifier>
<structuralType>Digital</structuralType>
<mode>Visual</mode>
<character>Language</character>
<type>JournalArticle</type>
<principalAgent>
<name>
<value>Ayoub Alfawzan</value>
<type>PrincipalName</type>
</name>
<role>Author</role>
</principalAgent>
<principalAgent>
<name>
<value>Omer Alrwais</value>
<type>PrincipalName</type>
</name>
<role>Author</role>
</principalAgent>
<principalAgent>
<name>
<value>Longman Publishers</value>
<type>PrincipalName</type>
</name>
<role>Publisher</role>
</principalAgent>
<linkedCreation>
<name>
<value>Journal of Science & Technology</value>
<type>PrincipalTitle</type>
</name>
<name>
<value>J. sci. technol.</value>
<type>AbbreviatedTitle</type>
</name>
<identifier>
<nonUriValue>2456-5660</nonUriValue>
<type>ISSN</type>
</identifier>
<referentCreationRole>Part</referentCreationRole>
<referentCreationSequenceIdentifier>
<value>10</value>
<type>VolumeNumber</type>
</referentCreationSequenceIdentifier>
<referentCreationSequenceIdentifier>
<value>7</value>
<type>IssueNumber</type>
</referentCreationSequenceIdentifier>
<referentCreationSequenceIdentifier>
<value>1-9</value>
<type>PageNumber</type>
</referentCreationSequenceIdentifier>
</linkedCreation>
<creationDate>
<date>2025-07-18</date>
<creationDateType>PublicationDate</creationDateType>
</creationDate>
</referentCreation>
</kernelMetadata>
