<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Towards a quantitative model of cloud computing risks and benefits</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Y. Zelenkov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Financial University under the Government of Russian Federation</institution>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2016</year>
      </pub-date>
      <fpage>31</fpage>
      <lpage>41</lpage>
      <abstract>
        <p>Migrating to the cloud is the main direction of enterprise IT optimization today. Many research papers confirm that cloud computing provides economic benefits, because it enhances flexibility and reduces costs. In other studies, cloud-specific risks are identified and their impact on the customer business is evaluated. However, most often, benefits and risks are considered separately. Model that allows simultaneously evaluate these factors is proposed here. Key factors of tangible and intangible benefits and risks are identified that allows to estimate joint impact of costs and risks on cloud adoption. Simple rules that help to quantify these factors and compute consistent pairwise comparison matrices are also proposed. Usage of proposed method is demonstrated with simple example.</p>
      </abstract>
      <kwd-group>
        <kwd>cloud computing</kwd>
        <kwd>cloud computing risks</kwd>
        <kwd>cloud computing benefits</kwd>
        <kwd>multi criteria decision making</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Migrating to the cloud is the main trend of enterprise IT optimization today. Many research papers
show that cloud computing provides significant tangible and intangible economic benefits, namely
reduced costs and enhanced flexibility of enterprise IT [1]</p>
      <p>An increasing number of companies choose a model of public clouds, physical resources (servers,
data storages…) in that model are owned cloud service provider. Public clouds have given consumers
the potential advantage of reallocating their large capital IT expenditures and upfront planning
overheads into manageable operational spending and planning. For public cloud providers as well, there are
advantages, owing to economies of scale and better utilization of their resources [2,3].</p>
      <p>Literature analysis shows that research papers can be split into two directions. The first examines
the economical benefits of the cloud, the second studies the risks that arise in the migration of
information resources in the cloud. In both directions the models, which help to assess the efficiency of the
clouds, are developed. However, there are very few studies that consider the economical benefits and
risks together.</p>
      <p>Very often a very complex theoretical models that involve the collection of large amounts of data
and complex calculations are proposed. However, in practice it is difficult to collect and measure all
required parameters, so such sophisticated techniques are of limited use. Therefore, practice requires a
fairly simple method that allows to compare different alternatives (public cloud, private cloud, own IT,
etc.) on the basis of simple expert evaluations of potential benefits and risks.</p>
      <p>
        Comparison of few alternatives is the problem of Multi Criteria Decision Making (MCDM).
Solution of any MCDM problem consists from few steps [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. The first step is to define the set of alternatives
and the set of decision criteria that the alternatives need to be evaluated with. Definition of alternatives
in practice usually does not cause the difficulties. Following options usually should be analysed in
particular case of cloud computing: the usage of own IT services, transfer of IT services to the cloud, and
different combination of these scenarios.
      </p>
      <p>Next very critical step is to accurately estimate the pertinent data. Very often these data cannot be
known in terms of absolute values, and it is very difficult to quantify it correctly. Therefore, many
MCDM methods attempt to determine relative importance of alternatives.</p>
      <p>Last step is to compare identified alternatives with help of one of MCDM method.</p>
      <p>Goals of presented research are: (1) to propose a simple set of criteria to assess the feasibility of
cloud computing that can be used in practice, and (2) to propose rules to determine relative importance
of alternatives in terms of each criterion involved in a MCDM problem.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Research literature review</title>
      <p>Many articles contributing to technical aspects have appeared in research literature of cloud
computing. But in a related review, Yang and Tate [5] concluded that the organization of research pertaining
to business aspects of cloud computing is still in a nascent stage, as compared to technical aspects.</p>
      <p>Karunakaran et all [3] collected 155 articles related to business view of cloud, which were published
until 2012, and classified them into a classification framework that is a refinement of that found in
Marston et al. [1]. According to their findings main themes of research are: pricing (32 papers), adoption
(24 papers), economic value (20 papers), and sourcing (17 papers). Both issues what are the subject of
our research (economic benefits and risks) are studied together only in several papers concerned to cloud
service provider selection (the sourcing theme in classification of [3]). Nevertheless, Karunkaran et al.
[3] argue, that the themes cost, quality of service (QoS) and risks appear intertwined and hence future
research should focus on providing holistic solutions.</p>
      <sec id="sec-2-1">
        <title>2.1 Economical benefits of cloud computing</title>
        <p>Most common used methods within economical estimation of cloud computing are: profitability
indicators (such as ROI—Return of Investment), NPV (Net Present Value), TCO (Total Cost of
Ownership) and productivity per employee.</p>
        <p>
          For example, Tak et al. [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ] identify a comprehensive set of factors affecting the costs of a
deployment choice (in-house, cloud, and combination), and use NPV-based cost analysis for adoption
recommendations. Due to the complexity of quantifying associated security risk encountered with deployment
choices, they do not include the risk factor in their current version of analysis.
        </p>
        <p>KhajehHosseini et al. [7] compare TCO reduction for different scenarios of IT services deployment
(purchasing a physical servers, leasing, using the cloud), similar approach is used by Williams [8]</p>
        <p>Mirsa and Mondal [9] developed a general ROI model, which takes into consideration various
intangible impacts of Cloud Computing, apart from the cost. Their model includes some of the key
characteristics of the resources possessed by a company: (1) Size of the IT resources, (2) The utilization
pattern of the resources, (3) Sensitivity of the data they are handling, and (4) Criticality of work done
by the company. Based on this position they developed weighted sum model of economical benefits.</p>
        <p>
          Maresova [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ] adopted general steps of Cost-Benefit Analysis (CBA) for cloud computing
purposes. She proposed a system of criteria, which is divided into three levels: economic, operational and
technical criteria, to specify a cloud computing deployment. These criteria should help to decide which
subjects are related to the impacts of the project, describe the differences between current IT and cloud
computing, and identify and quantify all related costs and benefits. Examples of costs are: expenditure
of time for implementation, support service, User-dependent basic charges, storage capacity, data
transfer and etc. Examples of benefits: reduction in operating costs of IT department, energy saving, etc.
        </p>
        <p>
          There are also studies that evaluate the effectiveness of the clouds with the help of non-economic
criteria. Garg et al. [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] propose a framework that measure the quality and rank cloud services offering
by different providers. They use parameters like service response time, sustainability, suitability,
accuracy, etc. Each individual parameter affects the service selection process, and its impact on overall
ranking depends on its priority in the overall selection process. To address this MCDM problem, they
propose an Analytic Hierarchy Process (AHP) based ranking mechanism to solve the problem of assigning
weights to features considering the interdependence between them, thus providing a much-needed
quantitative basis for the ranking of cloud services.
        </p>
        <p>
          Sundarraj and Venkatraman [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ] integrate an information system success model [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ] with
preference elicitation techniques drawn from MCDM literature. This helps them to combine in one model four
technical qualitative criteria viz. information quality, system quality, service quality and risk mitigation
features with financial quantitative criteria (NPV).
        </p>
        <p>Note, however, that in all cited works threats associated with the possible loss of information or
with unauthorized access to it are not considered.</p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2 Security risks of cloud computing</title>
        <p>A lot of research is devoted to the identification of cloud-specific risks and assessment of their
impact on the business of the customer. Here are some of them.</p>
        <p>
          Takabi et al. [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ] argue that although clouds allow customers to avoid start-up costs, reduce
operating costs, and increase their agility by immediately acquiring services and infrastructural resources
when needed, their unique architectural features also raise various security and privacy concerns. They
note that cloud computing environments are multidomain environments in which each domain can use
different security, privacy, and trust requirements and potentially employ various mechanisms,
interfaces, and semantics. They identified six security and privacy challenges, namely: authentication and
identity management, access control accounting, trust management and policy integration,
secure-service management, privacy and data protection, and organization security management.
        </p>
        <p>
          European Network and Information Security Agency (ENISA) report [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ] discusses assessment of
the security risks and benefits of using cloud computing-providing security guidance for potential and
existing users of cloud computing. It identifies most important classes of cloud-specific risks, between
them:
        </p>
        <p> Lost of governance, when client necessarily cedes control to the Cloud Provider (CP) on a
number of issues which may affect security;</p>
        <p> Lock-in of standards and procedures that can make it difficult for the customer to migrate from
one provider to another or migrate data and services back to an in-house IT environment;
 Isolation failure. This risk category covers the failure of mechanisms separating storage,
memory, routing and even reputation between different tenants;</p>
        <p> Management interface compromise: customer management interfaces of a public cloud provider
are accessible through the Internet and mediate access to larger sets of resources (than traditional hosting
providers) and therefore pose an increased risk, especially when combined with remote access and web
browser vulnerabilities;
 Cloud computing poses several data protection risks for cloud customers and providers;
 Insecure or incomplete data deletion;
 Malicious insider.</p>
        <p>
          Risk level in cited paper [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ] is measured as a sum of qualitative estimations of the business impact
and likelihood of the incident.
        </p>
        <p>
          Subashine et al. [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ] present a survey of the different security risks that pose a threat to the cloud.
They conclude that there are yet many practical problems which have to be solved, and an integrated
security model targeting different levels of security of data for a typical cloud infrastructure is under
research.
        </p>
        <p>
          Hashizume et al. [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ] argue, that cloud computing presents an added level of risk because essential
services are often outsourced to a third party, which makes it harder to maintain data security and
privacy, support data and service availability, and demonstrate compliance. Cloud computing leverages
many technologies (SOA, virtualization, Web 2.0); it also inherits their security issues.
        </p>
        <p>
          In practitioner publications also lot of cloud risks are mentioned, see for example [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ] and [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ], but
hereinafter we will follow Martens and Teuteberg [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ], which formalized three most common IT
security objectives: confidentiality, integrity and availability.
        </p>
      </sec>
      <sec id="sec-2-3">
        <title>2.3 Models of the joint assessment of economic benefit and risk</title>
        <p>Different authors offer a different approach, which allows to consider various aspects of the
problem, but we must admit that none of them is both holistic and simple.</p>
        <p>
          Given security and reliability concerns, Kantarcioglu et al. [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ] explored the optimal decision rule
for moving certain IT function to public clouds. They assumed that value from the cloud computing
adoption are governed by a mixed Brownian/jump process with mean arrival rate of the loss and size of
the loss, which are set as parameters. On base of this model they concluded that entrepreneur will attempt
to shift to cloud computing sooner than later if he anticipates the probability of negative events is high
and the loss is substantial in traditional on-site deployment. But concrete monetization model for the
benefits of both computing paradigms, the cloud computing deployment and the traditional on-site
computing deployment, is not presented in this paper.
        </p>
        <p>
          Saripalli and Pingalli [
          <xref ref-type="bibr" rid="ref22">22</xref>
          ] argue, that cloud adoption decisions tend to involve multiple, conflicting
criteria (attributes) with incommensurable units of measurements, which must be compared among
multiple alternatives using imprecise and incomplete available information. They present a multi-attribute
decision making framework for cloud adoption. It requires the definition of Attributes, Alternatives and
Attribute Weights, to construct a Decision Matrix and arrive at a relative ranking to identify the optimal
alternative. Several important attributes are taken in consideration in this paper, but possible risks did
not include in that attribute list.
        </p>
        <p>
          Martens and Teuteberg [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ] developed a sophisticated formal mathematical decision model that
supports the selection of cloud computing services in a multisourcing scenario. They consider cost as
well as risk factors which are relevant to the decision scope. Coordination costs, IT service costs,
maintenance costs and the costs of taken risks were compared. Risks are modeled by means of the three
common security objectives: integrity, confidentiality and availability. In cited work, each IT service is
considered separately as well as its sourcing options, the relative importance of service is calculated as
number of business processes that depend from it. This model can be viewed as an enough full
presentation of problem, but the number of its parameters is extremely big, so its usage in practice, most likely,
is highly limited.
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Decision making model for selection of cloud services</title>
      <p>
        We can conclude from discussion in previous section that all reviewed models and methods have
some drawbacks. Part of them is based on only qualitative assessments, in quantitative models point
estimations are used very often that leads to the flaw of averages [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ], the risks and benefits are estimated
separately. To close this gap new approach is needed, which can estimate jointly risks and benefits on
one hand, and which is simple enough to be used in practice on other.
      </p>
      <p>As it was stated before, selection of optimal way of IT services development is the MCDM problem.
The most important steps are: the definition of criteria to make an informed choice from the available
alternatives, and quantitative assessment of each alternative under the selected criteria. Usually these
steps cause the greatest difficulties in practice.</p>
      <p>Many researchers state that advantages of cloud computing can be split on two parts: tangible and
intangible economic benefits. Tangible benefits are due to reduction of costs of ownership. Intangible
benefits arise as a result of increasing the speed of changes, improving flexibility and the ability to adapt
new technologies. Since the cloud computing is associated with the risks, they also have to be included
in consideration.</p>
      <p>Thus, the minimum acceptable set of criteria should include:
 Tangible economical benefits or cost saving;
 Intangible benefits or flexibility;
 Risks.</p>
      <p>
        The relative importance of the criteria depends on the requirements and priorities of a particular
company and is determined for each practical case separately. To determine relative performance of
alternatives in terms of each single criterion we will use approach that is based on pairwise comparisons,
which was proposed by Saaty [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. But for the comparative evaluations of alternatives for each criterion
the rules are needed, which form the basis for the comparison. The main problem here is to ensure the
consistency of all judgements.
      </p>
      <p>Let  1,  2, … ,   be n entities (alternatives or criteria) to be compared. To evaluate the relative
weights of the above entities they are compared with each other in terms of a single common
characteristic. Results of comparison are represented in matrix A, each entry of which represents a pairwise
comparison (judgement). Specifically, the entry   denotes the number that estimates the relative
importance of element   when it is compared with element   , and   =   ⁄  , where   denotes the
actual weight of importance of element   . Obviously,    = 1⁄  and   = 1. For consistent case
following condition should be satisfied:
 
=     ,
 ∈ [1,  ],
 ∈ [1,  ],</p>
      <p>∈ [1,  ].
agora.guru.ru/pavt</p>
      <p>
        Fulfillment of this condition is difficult to achieve in practice, because when the set of entities to be
compared contains n elements, the estimation of  ( − 1)⁄2 pairwise comparisons is required. A
measure of closeness to the consistency for the pairwise comparison matrix has been provided by Saaty [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]
in terms of the principal eigenvalue  
and right eigenvector 
= { 1,  2, … ,   } associated with  
has been considered as weighting
vector. Here
      </p>
      <p>
        - consistency index and  - number of entities in matrix. Saaty shows that more   is close
to zero, the more the ratios   ⁄  are close to the preference ratio   . Many techniques of deriving
consistent comparison matrix A are developed [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], but all of them are based on a-posterior quantifying
of qualitative non-consistent data. These approaches are based on subjective judgments and require
enough sophisticated calculations, that sometimes causes difficulties in practice. So practitioners need
a simple method of consistent evaluation of all criteria and alternatives.
      </p>
      <p>To solve formulated problem, according to the above considerations, it is necessary to propose rules
of consistent matrices  ,  ,  and R calculation. Entries   of matrix  represent a relative weights of
criteria, entries   of matrix  represent a relative weights of alternatives under the cost saving criterion,
entries</p>
      <p>of matrix  represent a relative weights of alternatives under the flexibility criterion, and
entries   of matrix  represent a relative weights of alternatives under the risk criterion. Procedures
for assessing all of these parameters should be as simple as possible and based on available data. For
this it is necessary to do two things: firstly, to select those parameters which can be easily quantified,
and secondly, to determine measurement scale for each parameter.</p>
      <sec id="sec-3-1">
        <title>3.1 Evaluation of cost saving criterion</title>
        <p>
          To quantify the cost reductions, the discounted cash flows, which form the total cost of ownership,
are generally considered, and their Net Present Value (NPV) is calculated [
          <xref ref-type="bibr" rid="ref10">8-10</xref>
          ]:
:
= 
 ⁄
        </p>
        <p>,

here 
 - NPV of alternative j;</p>
        <p>– the net cash flow, which is defined as total cost of ownership
for alternative  in time period  ;  – the discount rate;  - the number of time periods.</p>
        <p>The relative cost of ownership of two alternatives   and   in time period  is:
Suppose, that</p>
        <p>
          is the normally distributed random variable with mean   and variance σj, it
value can be presented via  ( ) - inverse cumulative distribution function of standard normal
distribution [
          <xref ref-type="bibr" rid="ref25">25</xref>
          ]:
        </p>
        <p>( ;   ,   ) =   +    ( ), here  is probability. So, relative attractiveness of two
alternatives in any time period can be estimated as:
 
=
  +    ( )
  +    ( )
(1)</p>
        <p>Therefore, relative cost of two different alternatives can be obtained if mean and variance of their
TCO are known. When these data are not available, preliminary estimation of the expected mean can be
used. We can conclude also from the equation (1) that linear scale should be used for comparing the
relative costs of alternatives.
agora.guru.ru/pavt</p>
        <p>Obviously, lower value of TCO corresponds to the more attractive alternative. Therefore, in order
to transform this problem into a problem of maximization, we should consider the cost saving value</p>
        <p>= 1⁄  for comparison of alternatives.</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2 Evaluation of flexibility criterion</title>
        <p>
          As was stated above, this criterion assesses the speed of response to changes in IT services
requirements. In order to form a basis for it, we will use following considerations. In the context of the
contemporary turbulent business environment most important challenge is the need to keep track of coming
changes and update IT services accordingly. Once a business event occurs, the value-add of reacting to
that event decreases over time. Therefore, it would be in a business’s best interest to reduce the time
between business events and decisions made about them [
          <xref ref-type="bibr" rid="ref26 ref27 ref28">26-28</xref>
          ]. Zelenkov [
          <xref ref-type="bibr" rid="ref29">29</xref>
          ] reviewed the process
of IT service change, he postulated that this time gap is made up of three components: change detection,
change analysis and solution development, and solution implementation. General model of change,
which summarizes the results of [
          <xref ref-type="bibr" rid="ref26 ref27 ref28 ref29">26-29</xref>
          ], is presented in Fig. 1.
        </p>
        <sec id="sec-3-2-1">
          <title>Factors that determine the speed of change</title>
          <p>Business
value
m
i
n
o
i
t
c
a
e
t
l
a
e
r
f
o
e
u
l
a
V</p>
        </sec>
        <sec id="sec-3-2-2">
          <title>Business event</title>
          <p>Ability to
detect weak
signals</p>
          <p>Degree of
uniqueness of
business model
Level of details
required for
understanding</p>
          <p>Easiness of
communication
between business</p>
          <p>and IT
Analysis and
modeling tools</p>
          <p>Qualification of</p>
          <p>analytics
IT tools</p>
          <p>Ability of users to
adapt to new rules
Qualification of IT
specialists</p>
          <p>Business and IT
legacy systems
Time</p>
          <p>Change
recognition</p>
          <p>Analysis and</p>
          <p>solution
development
Unmanaged change</p>
          <p>Solution
implementation</p>
          <p>Managed change</p>
          <p>
            If the implementation of the changes is delayed, users are trying to adapt existing applications to
new challenges [
            <xref ref-type="bibr" rid="ref30">30</xref>
            ]. In that case changes are unmanageable, that leads to fragmentation of enterprise
IT system, harmony of its original design is lost [
            <xref ref-type="bibr" rid="ref31">31</xref>
            ] due to the unforeseen scenarios of usage,
incremental improvements, patches, etc. In such situation, the management should be focused on ensuring
compliance of IT with the requirements of the organization [
            <xref ref-type="bibr" rid="ref32">32</xref>
            ] and, therefore, on managed evolution
of enterprise IT system [
            <xref ref-type="bibr" rid="ref33">33</xref>
            ]. The rate of change of enterprise IT services must match the speed of
changes in the requirements of business [
            <xref ref-type="bibr" rid="ref29">29</xref>
            ]. Cloud computing in this case can provide additional value
in the form of intangible benefits which are the result of acceleration of IT services change.
          </p>
          <p>To estimate the losses, associated with a delay of changes, let us consider the following variables:
are:
is:
agora.guru.ru/pavt
diately, at the moment of business event;
  0 - the value that an organization would have received if the change were implemented
imme  - the time spent on the implementation of changes;
  ( ) - the value that an organization receives if the change is realized over time  .
It is followed from Fig. 1 that the desired function must satisfy the following conditions:
 = 0:  ( ) =  0
 → ∞:  ( ) → 0</p>
          <p>For example, power law  ( ) =  0 − satisfy these conditions, where e is the base of of the natural
logarithm (Euler’s number). Hence, loss due to delays in the implementation of the changes over time τ
 ( ) =  0 −  ( ) =  0 −  0 − =  0(1 −  − )
(2)</p>
          <p>It follows from equation (2) that the quick reaction to the changes provide a significant impact to
the organization, but after a while, the potential of IT service change is exhausted. This may mean that
users found alternative way of action under the new conditions, for example, they acquired the IT tools
from third-party, without the consent of the IT department, or developed own applications based on
spreadsheets and etc.</p>
          <p>Equation (2) can be used as a basis for comparison of the intangible benefits of different options of
sourcing IT services. Suppose that the expected values of reaction time of the two alternatives   and
  are   and  l respectively. Therefore, relative performance of alternatives under flexibility criterion


=
 0 − 
 0 −</p>
          <p>=  (  −  )</p>
          <p>So exponential scale should be used for comparing the alternatives and relative performance of
alternative is defined by reduction of reaction time, which it promises. These data can be obtained from
the system of change tracing (for existing IT services), service level agreements (for service in the
cloud), or on the basis of expert assessments.</p>
        </sec>
      </sec>
      <sec id="sec-3-3">
        <title>3.3 Evaluation of risk criterion</title>
        <p>
          To develop a method for evaluating the potential risks of various alternatives, we will use the
seminal model of Gordon and Loeb [
          <xref ref-type="bibr" rid="ref34">34</xref>
          ] with additions made Matsuura [
          <xref ref-type="bibr" rid="ref35">35</xref>
          ].
        </p>
        <p>Let us consider a one-period economic model of a firm contemplating the additional security efforts
to protect a given information set. The information set is characterized by the following three
parameters:
  - the monetary loss conditioned on a breach occurring.</p>
        <p>  - the threat probability, defined as the probability of a threat occurring, since t is a
probability, 0 ≤  ≤ 1. So the potential loss  is defined as  =  .</p>
        <p></p>
        <p>v - the vulnerability, defined as the conditional probability that a threat once realized
would be successful. Since v is a probability, 0 ≤ v ≤ 1.</p>
        <p>Let  &gt; 0 denote the monetary investment in information security to protect the given information
set, measured in the same units used to measure the potential loss  The purpose of the investment z is
to lower the probability that the information set will be breached. Let  ( ,  ) denote the probability that
an information set with vulnerability</p>
        <p>will be breached, conditional on the realization of a threat and
given that the firm has made an information security investment of 
to protect that information. The
expected benefits of an investment in information security, denoted as 
in the firm’s expected loss attributable to the extra security. That is:
, are equal to the reduction

( ) = [ −  ( ,  )] =  [</p>
        <p>−  ( ,  ) ]
agora.guru.ru/pavt</p>
        <p>
          Matsuura [
          <xref ref-type="bibr" rid="ref35">35</xref>
          ] noted that the information security investment z can reduce the threat probability and
that the reduction depends only on the investment z and the current level of threat probability t. So let
 ( ,  ) denote the probability that a threat occurring, given that the firm has made an investment of z.
So in his extended model:

( ) =  [
−  ( ,  ) ( ,  )]
(3)
Equation (3) can be used as a basis for quantitative comparison of risks of various alternatives.
        </p>
        <p>Suppose that the expected values of threat and vulnerability of the two alternatives   and   are
    and     respectively. Therefore, relative performance of alternatives is:


=</p>
        <p>Lower value of     corresponds to the more attractive alternative, therefore, in order to go to the
maximization problem, we should consider the reciprocal values under risk criterion. Linear scale should
be used for comparing the alternatives under risk criterion.</p>
      </sec>
      <sec id="sec-3-4">
        <title>3.4 Evaluation of priorities of criteria</title>
        <p>quirement of normality:</p>
        <p>In case of relative importance of criteria comparison, it is necessary to take in consideration a
re 1 +  2 + ⋯ +   = 1,
where   - the actual weight of importance of criterion  i.</p>
        <p>As formulated above, in case of cloud computing we deal with only  = 3 parameters. Therefore,
following simple procedure can be used in practice. The first step is to assign weights   and   to two
random criteria   and   based on their relative importance. The values of the weights are selected to
satisfy the conditions 0 ≤   +   ≤ 1. The third criterion weight is calculated as   = 1 − (  +   ).
Easy to
check that in this case
condition
of consistency is satisfied, because 

=</p>
        <p>= (  ⁄  )⁄(  ⁄  ). If obtained values   do not satisfy the decision maker for some reasons,
the entire procedure must be performed again, starting with the definition of new values of actual
For example, suppose, that some company considers three options:


</p>
        <p>Use of its own IT infrastructure (alternative  1);
Migration of all IT services to the public cloud (alternative  2);</p>
        <p>Migration of only non-critical IT services to a public cloud (alternative  3).</p>
        <p>Absolute values of alternatives in terms of each criterion were estimated by experts, these values</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Example</title>
      <p>are shown in Table 1.</p>
      <p />
      <p>In accordance with rules proposed in Section 3, the entries of  ,  and R can be calculated as
follows:
(million dollars
per month)
0,5
0,2
0,4
0,20
0,22
agora.guru.ru/pavt</p>
      <p>Matrices S, F and R are presented in Table 2.
 
 
 
 
 
 
 
 
 
 
1
2,5
1,25
7,389
2,718
1
1
0,667
0,909</p>
      <p>Matrix S
Matrix F
Matrix R
 
0,4
1
0,5
0,135
0,368
1,500
1
1
1,364
 
0,8
2
1
0,368
2,718
1
1
1,100
0,733</p>
      <p>Suppose that after discussion company experts decided that actual weight of cost saving importance
is   = 0,3 and actual weight of flexibility is   = 0,15. In accordance with Section 3.4, actual weight
of risk is   = 1 − (  +   ) = 0,55.</p>
      <p>
        Let use weighted production model (WPM) to define relative attractiveness of alternatives. WPM
is one of best known and simplest MCDM method for evaluating number of alternatives in terms of a
number decision criteria. Suppose that a given MCDM problem is defined on m alternatives and n
decision criteria, and all the criteria are benefit criteria, that is, the higher the values are, the better it is.
Let   denotes the relative weight of importance of the criterion   and  
is the relative performance
value of alternative   regarding alternative   when they are evaluated in terms of criterion   . So, to
compare the two alternatives  k and   the following product has to be calculated [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]:

∏ 
 =1
      </p>
      <p>(  ⁄  ) =
  
 ,  = 1,2, … ,  .
all other alternatives.</p>
      <p>If the ratio  (  ⁄  ) is greater than or equal to the value 1, then it indicates that alternative   is
more desirable than alternative   , the best alternative is the one that is better than or at least equal to
superior to all the other alternatives. The ranking of alternatives is as follows:  2 &gt;  3 &gt;  1.</p>
      <p>With given  ,  ,  and R:  ( 1⁄ 2) = 0,703,  ( 1⁄ 3) = 0,848, and  ( 2⁄ 3
) = 1,206.
Therefore, with given criteria priorities and parameters estimations the best alternative is  2, because it is</p>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusion</title>
      <p>The main goal of paper is to propose simple model that can be used in practice. Three criteria (cost
of ownerships saving, intangible benefits that associated with speed of reaction to change and security
risks) that have been proposed here are enough simple and all necessary data can be obtained from
accounting system, contract conditions, statistics and expert opinions. The proposed method helps easy
to get a consistent matrix of pairwise comparisons. All of this leads to the conclusion that the proposed
method can be used in practice.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <surname>Marston</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bandyopadhyay</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          , Zhang, J.,
          <string-name>
            <surname>Ghalsasi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Cloud</surname>
          </string-name>
          <article-title>Computing: The Business Perspective // Decision Support Systems</article-title>
          .
          <year>2011</year>
          . Vol.
          <volume>51</volume>
          , No. 1. P.
          <volume>176</volume>
          -
          <fpage>189</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>Armbrust</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fox</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Griffith</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joseph</surname>
            ,
            <given-names>A. D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Katz</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Konwinski</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <article-title>A View of Cloud Computing // Communications of the ACM</article-title>
          .
          <year>2010</year>
          . Vol.
          <volume>53</volume>
          , No. 4. P.
          <volume>50</volume>
          -
          <fpage>58</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          2015. Vol.
          <volume>38</volume>
          , No. 6. P.
          <volume>582</volume>
          -
          <fpage>604</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Triantaphyllou</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          <article-title>Multi-Criteria Decision Making: A Comparative Study</article-title>
          . Kluwer,
          <year>2000</year>
          . 320 p.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <surname>Yang</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tate</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>A Descriptive Literature Review and Classification of Cloud Computing Research // Communications of the Association for Information Systems</article-title>
          .
          <year>2012</year>
          . Vol.
          <volume>31</volume>
          , No. 1. Paper 2.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Tak</surname>
            ,
            <given-names>B. C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Urgaonkar</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sivasubramaniam</surname>
            ,
            <given-names>A</given-names>
          </string-name>
          . To Move or not to Move:
          <source>The Economics of Cloud Computing // Proceedings of the 3rd USENIX conference on Hot topics in cloud computing</source>
          .
          <year>2011</year>
          . P. 5-
          <fpage>5</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          2012. Vol.
          <volume>42</volume>
          , No. 4. P.
          <volume>447</volume>
          -
          <fpage>465</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <surname>Williams</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          <article-title>The Economics of Cloud Computing</article-title>
          . Cisco Press,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          <string-name>
            <surname>Misra</surname>
            ,
            <given-names>S. C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mondal</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <article-title>Identification of A Company's Suitability for The Adoption of Cloud Computing</article-title>
          and Modelling Its Corresponding Return On Investment // Mathematical and Computer Modelling.
          <year>2011</year>
          . Vol.
          <volume>53</volume>
          , No. 3. P.
          <volume>504</volume>
          -
          <fpage>521</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Marešová</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <article-title>Cost Benefit Analysis Approach for Cloud Computing</article-title>
          . // Advanced Computer and Communication Engineering Technology. Springer,
          <year>2016</year>
          , P.
          <fpage>913</fpage>
          -
          <lpage>923</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Garg</surname>
            ,
            <given-names>S. K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Versteeg</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Buyya</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <article-title>A Framework for</article-title>
          Ranking of Cloud Computing Services // Future Generation Computer Systems.
          <year>2013</year>
          . Vol.
          <volume>29</volume>
          , No. 4. P.
          <volume>1012</volume>
          -
          <fpage>1023</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Sundarraj</surname>
            ,
            <given-names>R. P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Venkatraman</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>On Integrating an IS Success Model and Multicriteria Preference Analysis into a System for Cloud-Computing Investment Decisions // Outlooks and Insights on Group Decision and Negotiation</article-title>
          . Springer,
          <year>2015</year>
          . P.
          <volume>357</volume>
          -
          <fpage>368</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Delone</surname>
            ,
            <given-names>W. H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>McLean</surname>
            ,
            <given-names>E. R.</given-names>
          </string-name>
          <article-title>The Delone</article-title>
          and
          <source>Mclean Model of Information Systems Success: A Ten-Year Update // Journal of management information systems</source>
          .
          <source>2003</source>
          . Vol.
          <volume>19</volume>
          , No. 4. P. 9-
          <fpage>30</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Takabi</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>J. B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ahn</surname>
            ,
            <given-names>G. J.</given-names>
          </string-name>
          <string-name>
            <surname>Security</surname>
          </string-name>
          and Privacy Challenges in Cloud Computing Environments // IEEE Security &amp; Privacy.
          <year>2010</year>
          . No. 6. P.
          <volume>24</volume>
          -
          <fpage>31</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Catteddu</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hogben</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          <article-title>Cloud Computing: Benefits, Risks and Recommendations for Information Security</article-title>
          . ENISA,
          <year>2009</year>
          . URL: www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing
          <string-name>
            <surname>-</surname>
          </string-name>
          risk-assessment/at_download/fullReport (accessed:
          <fpage>07</fpage>
          .
          <fpage>02</fpage>
          .
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Subashini</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kavitha</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          <article-title>A Survey On Security Issues in Service Delivery Models of Cloud Computing //</article-title>
          <source>Journal of Network and Computer Applications</source>
          .
          <year>2011</year>
          . Vol.
          <volume>34</volume>
          , No. 1. P. 1-
          <fpage>11</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Hashizume</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rosado</surname>
            ,
            <given-names>D. G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fernández-Medina</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fernandez</surname>
            ,
            <given-names>E. B.</given-names>
          </string-name>
          <article-title>An Analysis of Security Issues for Cloud Computing //</article-title>
          <source>Journal of Internet Services and Applications</source>
          .
          <year>2013</year>
          . Vol.
          <volume>4</volume>
          , No.1. P. 1-
          <fpage>13</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18. Angeles, S. 8 Reasons to Fear Cloud Computing // Business News Daily,
          <year>2013</year>
          . URL: http://www.businessnewsdaily.com/5215-dangers-cloud-computing.
          <source>html (accessed: 07.02</source>
          .
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Grimes</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <article-title>The 5 Cloud Risks You Have</article-title>
          to Stop Ignoring // InfoWorld,
          <year>2013</year>
          . URL: http://www.infoworld.com/article/2614369/security/the-5
          <article-title>-cloud-risks-you-have-to-stop-ignoring</article-title>
          .
          <source>html (accessed: 07.02</source>
          .
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Martens</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Teuteberg</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          :
          <article-title>Decision-Making in Cloud Computing Environments: A Cost and</article-title>
          Risk Based Approach // Information Systems Frontiers.
          <year>2012</year>
          . Vol.
          <volume>14</volume>
          , No. 4. P.
          <volume>871</volume>
          -
          <fpage>893</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Kantarcioglu</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bensoussan</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hoe</surname>
          </string-name>
          , S.
          <source>Impact of Security Risks On Cloud Computing Adoption // 49th Annual Allerton Conference on Communication, Control, and Computing. IEEE</source>
          ,
          <year>2011</year>
          . P.
          <volume>670</volume>
          -
          <fpage>674</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Saripalli</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pingali</surname>
          </string-name>
          , G.:
          <article-title>MADMAC: Multiple Attribute Decision Methodology for</article-title>
          Adoption of Clouds // 2011 IEEE International Conference on Cloud Computing. IEEE,
          <year>2011</year>
          . P.
          <volume>316</volume>
          -
          <fpage>323</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Savage</surname>
            ,
            <given-names>S. L.</given-names>
          </string-name>
          <article-title>The Flaw of Averages: Why We Underestimate Risk in The Face of Uncertainty</article-title>
          . John Wiley &amp; Sons,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Saaty</surname>
          </string-name>
          , T. L. Axiomatic Foundation of the Analytic Hierarchy Process // Management Sciences.
          <year>1986</year>
          . No. 32. P.
          <volume>841</volume>
          -
          <fpage>855</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <surname>Aivazyan</surname>
            ,
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yenyukov</surname>
            ,
            <given-names>I.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Meshalkin</surname>
          </string-name>
          , L.D. Applied statistics.
          <source>Bases of modeling and initial data processing. Financy i statisitca</source>
          ,
          <year>1983</year>
          . 471 p.
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26.
          <string-name>
            <surname>Bonham</surname>
            ,
            <given-names>S. S.</given-names>
          </string-name>
          <string-name>
            <surname>Actionable Strategies Through Integrated Performance</surname>
            , Process, Project,
            <given-names>And Risk</given-names>
          </string-name>
          <string-name>
            <surname>Management</surname>
          </string-name>
          .
          <source>Artech House</source>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <string-name>
            <surname>Hackathorn</surname>
          </string-name>
          , R.:
          <source>Minimizing Action Distance // Data Administration Newsletter, February</source>
          <volume>1</volume>
          ,
          <year>2004</year>
          . URL: www.tdan.
          <source>com/i025fe04.htm (accessed: 07.02</source>
          .
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28.
          <string-name>
            <surname>Zelenkov</surname>
            <given-names>Y.</given-names>
          </string-name>
          <article-title>Components of Enterprise IT Strategy: Decision-Making Model</article-title>
          and Efficiency Measurement //
          <source>International Journal of Information Systems and Change Management</source>
          .
          <year>2014</year>
          . Vol.
          <volume>7</volume>
          , No. 2,
          <string-name>
            <surname>P.</surname>
          </string-name>
          150-
          <fpage>166</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          29.
          <string-name>
            <surname>Zelenkov</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          <string-name>
            <surname>Business</surname>
          </string-name>
          and IT Alignment in Turbulent Business Environment // Business Information Systems Workshops, LNBIP, vol.
          <volume>228</volume>
          . Springer,
          <year>2015</year>
          . P.
          <volume>101</volume>
          -
          <fpage>112</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          30.
          <string-name>
            <surname>Ciborra</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          <article-title>The Labyrinths of Information: Challenging the Wisdom of System</article-title>
          . Oxford University Press,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          31.
          <string-name>
            <surname>Maurer</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          <string-name>
            <surname>Goodhue</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <article-title>A Theoretical Model of the Enterprise System Agility Life Cycle /</article-title>
          / AMCIS 2010 Proceedings,
          <year>2010</year>
          . Paper 231.
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          32.
          <string-name>
            <surname>Luftman</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kempaiah</surname>
            ,
            <given-names>R. An</given-names>
          </string-name>
          <string-name>
            <surname>Update On</surname>
          </string-name>
          Business-IT Alignment: “A Line” Has Been Drawn // MIS Quarterly Executive.
          <year>2007</year>
          . Vol.
          <volume>6</volume>
          , No. 3. P.
          <volume>165</volume>
          -
          <fpage>177</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          33.
          <string-name>
            <surname>Murer</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bonati</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Furrer</surname>
            ,
            <given-names>F.J.</given-names>
          </string-name>
          <string-name>
            <surname>Managed</surname>
          </string-name>
          <article-title>Evolution: A Strategy for Very Large Information Systems</article-title>
          . Springer,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          34.
          <string-name>
            <surname>Gordon</surname>
            ,
            <given-names>L.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Loeb</surname>
          </string-name>
          , M.P.
          <source>The Economics of Information Security Investment // ACM Transactions on Information and System Security</source>
          ,
          <year>2002</year>
          . Vol.
          <volume>5</volume>
          , No. 4. P.
          <volume>438</volume>
          -
          <fpage>457</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          35.
          <string-name>
            <surname>Matsuura</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          <article-title>Productivity Space of Information Security in an Extension of the Gordon-Loeb's Investment Model</article-title>
          // M.E. Johnson (ed.),
          <source>Managing Information Risk and the Economics of Security</source>
          . Springer,
          <year>2009</year>
          . P.
          <volume>99</volume>
          -
          <fpage>119</fpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>