<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Model-based Requirements for Integrating Cloud Services</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Iyad Zikra</string-name>
          <email>iyad@dsv.su.se</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Computer and Systems Sciences (DSV), Stockholm University</institution>
          ,
          <addr-line>Stockholm</addr-line>
          ,
          <country country="SE">Sweden</country>
        </aff>
      </contrib-group>
      <fpage>65</fpage>
      <lpage>72</lpage>
      <abstract>
        <p>Cloud-based services provide an alternative to the in-house implementation of various types of functionality. Organizations rely on such services to minimize the need for long-term commitments and enhance scalability and ubiquitous access to the services. However, achieving complex tasks that require a combination of services is not well studied, despite the potential added value. This paper investigates the requirements encountered when integrating cloud-based services in the modern organization. The paper proposes a modeldriven solution for capturing the requirements for integrating cloud-based services. The model is to be used within the larger context of the organizational design; modeling components used to describe requirements are related to other views of the organization. A prototype tool and an example business case are presented to illustrate how the requirements model can be elicited and designed. The models are capable of being transformed into an integration solution.</p>
      </abstract>
      <kwd-group>
        <kwd>Iyad Zikra</kwd>
        <kwd />
        <kwd>Cloud Computing</kwd>
        <kwd>Integration</kwd>
        <kwd>Requirements</kwd>
        <kwd>Enterprise Modeling</kwd>
        <kwd>Model-Driven Development</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Cloud services are becoming an increasingly appealing solution for organizations that
want to outsource general functionality. Cloud computing relies on several
technologies, and its definition is still being debated [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Most approaches that tackle cloud
computing target its technical aspects and overlook the relationship/effect that
cloudbased services can have to other parts of the organization. Research that covers
requirements for cloud services generally addresses the design and development of
individual services. Positioning cloud services within the organizational design and
the integration of cloud-based services are two issues that are not well understood.
      </p>
      <p>
        This paper proposes extending the unifying meta-model for enterprise modeling
[
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] to support describing cloud-based enterprise integration requirements. The
proposed approach utilizes the principles of Model Driven Development (MDD) [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] to
facilitate switching service providers at the enterprise-design level in response to
changes in service provisioning needs. The concrete connections to the cloud services
are delegated to the implementation level, described as a platform-specific integration
solution. This is aligned with the vision for creating global cloud marketplaces, where
cloud consumers are able to choose from a selection of comparable cloud-based
commodities [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. The proposed solution relies on incorporating the flexibility of
switching between cloud providers into enterprise models.
      </p>
      <p>The paper is structured as follows. Section 2 is an overview of cloud computing
and services. Section 3 explores the requirements of cloud-based services in the
literature. Section 4 presents the proposed requirements model for integrating cloud
services and demonstrates its use with an example case study. Finally, section 5 includes
concluding remarks and future work.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Cloud Computing</title>
      <p>
        Cloud computing is gaining popularity as an emerging technology that resides at the
intersection of concurrent advancements in diverse fields of technology [
        <xref ref-type="bibr" rid="ref16 ref6">6,16</xref>
        ]. It is
driving a shift in the management attitude towards the use and utilization of existing
technologies to capitalize on the combined added value [
        <xref ref-type="bibr" rid="ref2 ref5">2,5</xref>
        ]. Cloud computing relies
on innovative and assets-free alternatives to traditional outsourcing approaches [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] to
offer the necessary flexibility to meet changing usage patterns and support variable
pricing [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], and to mitigating long-term commitments by cloud consumers and enable
ubiquitous access by service end users [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ].
      </p>
      <p>
        The details of what constitutes ―the cloud‖ are still debated among researchers and
practitioners [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. A widely adopted definition frames cloud computing as:
―a model for enabling convenient, on-demand network access to a shared pool of
configurable computing resources (e.g., networks, servers, storage, applications, and
services) that can be rapidly provisioned and released with minimal management effort or
service provider interaction.‖ [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]
      </p>
      <p>
        This definition highlights the technical perspective of cloud computing. Business
aspects, especially the influence of adopting cloud services on value configurations,
are often neglected [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. Other financial, organizational, resource-related, and
ecological characteristics influence what is viewed as cloud computing [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>
        The flexibility in provisioning and pricing is facilitated through a service-oriented
3-layered architecture [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]: infrastructure layer (Infrastructure as a Service, IaaS),
influenced by developments in grid and cluster computing; platform layer (Platform
as a Service, PaaS): operating systems and software development frameworks; and
software layer, or Software as a Service (SaaS): end-user services are offered through
this layer over the Internet.
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>Requirements for Cloud-based Services</title>
      <p>
        Despite the foreseen advantages, organizations hesitate to fully adopt cloud
computing—a young domain with many unresolved challenges and associated risks and
uncertainties [
        <xref ref-type="bibr" rid="ref2 ref5">2,5</xref>
        ]. Data storage and application platforms are still largely proprietary,
which increases the risks of single failure points, raises the costs of switching cloud
providers, and impedes cloud adoption. Quality assurance and optimization
requirements play a decisive role in choosing from amongst competing providers [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
Furthermore, providing services in the cloud entails security and privacy implications
that are unique to the cloud environment [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. It also introduces additional integrity
and confidentiality requirements for data that is moved between cloud providers [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>
        Variations in legal jurisdiction and the continuously evolving privacy laws
complicate the adoption of cloud services. Service Level Agreements (SLAs) are used as
tools to govern the relationship between cloud provider and cloud consumer
according to organizational policies and applicable rules and regulations [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <p>
        Most literature describing the requirements for cloud services focuses on the
design of individual services. However, efforts are made to facilitate dynamic provider
switching, such as the proposals in [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] and [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
4
      </p>
    </sec>
    <sec id="sec-4">
      <title>Model-based Integration of Cloud Services</title>
      <p>To describe requirements for integrated, complex cloud services, we propose a
modelbased approach that captures the design of the integrated services on a higher level of
abstraction, i.e. the enterprise level. Doing so: a) addresses the business aspects of
cloud services and exposes the value added by the integrated services to the overall
organizational design, b) improves the alignment between the business goals and the
eventual implementation of the integrated services, and c) facilitates the automated
switching between candidate service providers, hence taking a step closer towards
realizing the vision of global cloud marketplaces.</p>
      <p>
        Information systems requirements must describe the underlying motivation for
developing a system in addition to the desired functionality of the system [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
Approaches that support modeling goals in addition to requirements can serve as suitable
means to describe requirements for cloud adoption [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
4.1
      </p>
      <sec id="sec-4-1">
        <title>The Unifying Meta-Model for Enterprise Modeling</title>
        <p>
          Enterprise Modeling (EM) provides means for describing the elements of business,
information, and technology components [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ]. The unifying meta-model for enterprise
modeling offers a platform for capturing enterprise models and eliciting supporting
system design models following MDD principles [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. The meta-model, illustrated in
Fig. 1, is divided into (1) enterprise-level views that represent enterprise knowledge,
and (2) system-level views that describe design details of the supporting information
systems. Composite views are used to offer more elaborate representations of the
organization. The coarse-grained relationships between the views are interpreted as
inter-model relationships (IMRs) that relate model components across different views,
thus enabling the definition of composite views. Traceability across the unifying
meta-model is thereby supported.
The Requirements View (RV) is proposed as a composite view cutting through the
Goal View (GV), Concepts View (CV), Business Process View (BPV), and Systems
View (SV). The components of the RV (Fig. 2) belong to these four views.
        </p>
        <p>The RequirementsTable modeling component is a list of stakeholder-friendly
requirements. A Requirement in the table contains the textual statement of the
requirement (in the traditional sense). It is annotated by a priority value to create an order in
which requirements should be implemented. Each requirement is associated with a
RequirementView, a representational modeling component that groups together the
components comprising a single requirement.</p>
        <p>Concept from the CV represents the entities affected by the requirement. Process
and Role from the BPV represent the functionality expressed by and the
organizational structures affecting the requirement, respectively. The consume and produce
IMRs capture how the concepts are processed. The attributes frequencyOfExecution
and concurrentInstances describe non-functional performance aspects of a
requirement.</p>
        <p>BusinessGoal from the GV and the motivate IMR account for the motivation of a
requirement. The motivate relationships enables motivating the requirement directly
(a requirement being a model component itself) or indirectly through the
requirement’s parts (e.g. concepts, processes, etc.). Problem (either internal, i.e. Weakness,
or external, i.e. Threat) and Constraint capture the limitations affecting a requirement
via the underlying goal of the requirement. Describing the Cause of a problem helps
in designing suitable solutions to mitigate it. Opportunity describes growth potential
in the organization and is used to model future desired requirements. Finally, Key
Performance Indicators (KPIs), which are part of the GV, provide means for
evaluating the fulfilment of a requirement in the implemented solution.</p>
        <p>System from the SV represents the systems affected by the requirement. The type
attribute captures the specific type of the modelled system. System maybe specialized
to reflect possible implementation platforms, including cloud-based services. The type
and specialization of a system affect the selection of the appropriate transformation
rules that are applied to generate the integration solution.
The use of the proposed RV for modeling cloud integration requirements is illustrated
in this section using the example business case of the imaginary organization
Aid&amp;More. The requirements model is developed using a prototype tool that
implements the unifying-meta model for enterprise modeling. The tool supports modeling
enterprise- and system-level models as well as transforming the designed models to a
platform-specific implementation.</p>
        <p>Overview of the Example Business Case. Aid&amp;More is a Non-Governmental
Organization (NGO) active in the humanitarian aid domain. It offers support to people in
distress situations as a result of natural disasters. Each aid project includes several
types of aid and targets a specific distress situation described by: the type of natural
disaster, number of affected people, target geographical location, etc. Types of aid in
a project prescribe the necessary resources to deliver the aid—personnel, vehicles,
warehouses, offices, and aid items. Creating a recognizable and popular brand is
essential for the growth of Aid&amp;More’s work; the organization relies mainly on public
donations to fund its operations. Using information collected from social media, the
NGO aims to understand and analyse its reputation and identify improvement
potential, both in terms of project execution and public relations.</p>
        <p>Aid&amp;More is looking for a solution that automatically retrieves mentions of the
NGO in social media. The solution should then, with the help of online analyses
services, generate summary reports of how Aid&amp;More is perceived. The desired
architecture is illustrated in Fig. 3. The solution has access to project details, managed
using a central Project Management System (called internally as PROM). The system
has a public interface on the Web (i.e. website) to advertise statistics and results from
projects. Google Analytics is employed to monitor and provide feedback on the
impact of the Website. AnalyzeThis is an online service used for analysing data
collected from social networks.</p>
      </sec>
      <sec id="sec-4-2">
        <title>Modeling the Integration Requirements. The business goals of Aid&amp;More are de</title>
        <p>scribed using a goal model (i.e. instance of the GV), a part of which is shown in Fig.
4. Only the goals that motivate the cloud integration requirements are shown.</p>
        <p>A section of the requirements table describing the desired integration solution is
shown in Fig. 5. Each of the requirements has an associated requirement view (i.e.
instance of the RV) that includes the design details of the requirement.</p>
        <p>The requirement view for Requirement A3774OOJ is illustrated in Fig. 6. To fulfill
the requirement (i.e. retrieve Aid&amp;More mentions), the integration solution performs
two activities: ―send search query‖ and ―retrieve search results.‖ The search query is
affected by two factors: the aid project and the specific social media outlet being
queried. The details of the aid project are used to formulate the content of the query. The
interface details of the social media outlet describe the parameters used to establish a
connection for sending the query and retrieving the results.</p>
        <p>The concept ―SocialMediaMention‖ represents occurrences in social networks,
including tags, referrals, shares, likes, re-tweets, etc. The model enables switching the
RESTful services that require (i.e. receive) the search query. The switching is then
reflected in the implementation of the integration solution by applying a different
transformation rule that is suitable for the new service. A new transformation rule
needs to be developed for every new service to be added, but this is done only once
and the transformation rule can be reused in this or other projects.
Existing research concerning requirements for cloud-based service focuses on
individual services and tends to address the more technical aspects of cloud computing.
Business-related aspects are overlooked. We propose in this paper modelling
requirements for integrating cloud services as part of the organizational design. The
unifying meta-model for enterprise modeling is extended with the Requirements View
(RV), a composite view that covers components involved in describing requirements.
The unifying meta-model enables relating requirements to other parts of the
organizational design. The modelled systems can describe cloud-based services and thereby
offer a mechanism for automated service provisioning at the enterprise-design level
and contributing to achieving the envisioned global cloud marketplaces.</p>
        <p>An example business case illustrated the use of the proposed RV with the help of a
prototype tool. The requirements models can be transformed into a platform-specific
integration solution that supports integrating different cloud services. The modularity
of the unifying-meta model allows the RV to be extended with new modeling
components that capture additional details about the requirements.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>AlZain</surname>
            ,
            <given-names>M.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pardede</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Soh</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Thom</surname>
            ,
            <given-names>J.A.</given-names>
          </string-name>
          :
          <article-title>Cloud Computing Security: From Single to Multi-Clouds</article-title>
          .
          <source>In: Proceedings of the 45th Annual Hawaii International Conference on System Sciences (HICSS)</source>
          , pp.
          <fpage>5490</fpage>
          -
          <lpage>5499</lpage>
          . IEEE (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Armbrust</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fox</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Griffith</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joseph</surname>
            ,
            <given-names>A.D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Katz</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Konwinski</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Patterson</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rabkin</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stoica</surname>
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zaharia</surname>
            ,
            <given-names>M.:</given-names>
          </string-name>
          <article-title>A View of Cloud Computing</article-title>
          .
          <source>Communications of the ACM</source>
          <volume>53</volume>
          (
          <issue>4</issue>
          ),
          <fpage>50</fpage>
          -
          <lpage>58</lpage>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Atkinson</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kühne</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <string-name>
            <surname>Model-Driven Development</surname>
          </string-name>
          :
          <article-title>A Metamodeling Foundation</article-title>
          .
          <source>IEEE Software 20(5)</source>
          ,
          <fpage>36</fpage>
          -
          <lpage>41</lpage>
          (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Bubenko</surname>
            ,
            <given-names>J. A.</given-names>
          </string-name>
          , jr.,
          <string-name>
            <surname>Persson</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stirna</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2001</year>
          ).
          <article-title>D3: User guide of the Knowledge Management Approach Using Enterprise Knowledge Patterns. Royal Institute of Technology (KTH)</article-title>
          and Stockholm University: Stockholm, Sweden.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Buyya</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yeo</surname>
            ,
            <given-names>C.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Venugopal</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Broberg</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Brandic</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          :
          <article-title>Cloud Computing and Emerging IT Platforms: Vision, Hype, and Reality for Delivering Computing as the 5th Utility</article-title>
          .
          <source>Future Generation Computer Systems</source>
          <volume>25</volume>
          (
          <issue>6</issue>
          ),
          <fpage>599</fpage>
          -
          <lpage>616</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Creeger</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <source>CTO Roundtable: Cloud Computing. Queue - Distributed Computing</source>
          <volume>7</volume>
          (
          <issue>5</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>17</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Koitz</surname>
            ,
            <given-names>I.T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Glinz</surname>
            ,
            <given-names>M.:</given-names>
          </string-name>
          <article-title>StakeCloud Tool: From Cloud Consumers' Search Queries to New Service Requirements</article-title>
          .
          <source>In: IEEE 23rd International Requirements Engineering Conference (RE)</source>
          , pp.
          <fpage>286</fpage>
          -
          <lpage>287</lpage>
          . IEEE (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Kourtesis</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bratanis</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Friesen</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Verginadis</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Simons</surname>
            ,
            <given-names>A.J.H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rossini</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schwichtenberg</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gouvas</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Brokerage for Quality Assurance and Optimisation of Cloud Services: An Analysis of Key Requirements</article-title>
          . In: Lomuscio,
          <string-name>
            <given-names>A.R.</given-names>
            ,
            <surname>Nepal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            ,
            <surname>Patrizi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            ,
            <surname>Benatallah</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            ,
            <surname>Brandić</surname>
          </string-name>
          , I. (eds.)
          <article-title>ICSOC 2013 Workshops</article-title>
          , LNCS
          <volume>8377</volume>
          , pp.
          <fpage>150</fpage>
          -
          <lpage>162</lpage>
          . Springer (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Leimeister</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Riedl</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Böhm</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Krcmar</surname>
          </string-name>
          , H.:
          <article-title>The Business Perspective of Cloud Computing: Actors, Roles, and Value Networks</article-title>
          .
          <source>In: Proceedings of the 18th European Conference on Informtion Systems (ECIS</source>
          <year>2010</year>
          ), paper 56.
          <string-name>
            <surname>AIS</surname>
          </string-name>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Mell</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Grance</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>The NIST Definition of Cloud Computing</article-title>
          .
          <source>Technical Report, National Institute of Standards and Technology</source>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Ross</surname>
            ,
            <given-names>D. T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schoman</surname>
            ,
            <given-names>K. E.</given-names>
          </string-name>
          :
          <article-title>Structured Analysis for Requirements Definition</article-title>
          .
          <source>IEEE Transactions on Software Engineering</source>
          <volume>3</volume>
          (
          <issue>1</issue>
          ),
          <fpage>6</fpage>
          -
          <lpage>15</lpage>
          (
          <year>1977</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Stieninger</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nedbal</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Characteristics of Cloud Computing in the Business Context: A Systematic Literature Review</article-title>
          .
          <source>Global Journal of Flexible Systems Management</source>
          <volume>15</volume>
          (
          <issue>1</issue>
          ),
          <fpage>59</fpage>
          -
          <lpage>68</lpage>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Takabi</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>J.B.D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gail-Joon</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Security and Privacy Challenges in Cloud Computing Environments</article-title>
          .
          <source>Security &amp; Privacy</source>
          <volume>8</volume>
          (
          <issue>6</issue>
          ),
          <fpage>24</fpage>
          -
          <lpage>31</lpage>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Young</surname>
            ,
            <given-names>J.D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Anton</surname>
            ,
            <given-names>A.I.</given-names>
          </string-name>
          :
          <article-title>A Method for Identifying Software Requirements Based on Policy Commitments</article-title>
          .
          <source>In: 18th IEEE International Requirements Engineering Conference (RE)</source>
          , pp.
          <fpage>47</fpage>
          -
          <lpage>56</lpage>
          . IEEE (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Zardari</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bahsoon</surname>
          </string-name>
          , R.:
          <article-title>Cloud Adoption - A Goal-oriented Requirements Engineering Approach</article-title>
          .
          <source>In: Proceedings of the 2nd International Worshop on Software Engineering for Cloud Computing (SECLOUD'11)</source>
          , pp.
          <fpage>29</fpage>
          -
          <lpage>35</lpage>
          . ACM (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Zhang</surname>
          </string-name>
          , Q., Cheng, L.,
          <string-name>
            <surname>Boutaba</surname>
          </string-name>
          , R.: Cloud Computing:
          <article-title>State-of-the-Art and Research Challenges</article-title>
          .
          <source>Journal of Internet Services and Applications</source>
          <volume>1</volume>
          (
          <issue>1</issue>
          ),
          <fpage>7</fpage>
          -
          <lpage>18</lpage>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Zikra</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stirna</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zdravkovic</surname>
          </string-name>
          , J.:
          <article-title>Bringing Enterprise Modeling Closer to Model-Driven Development</article-title>
          .
          <source>In: PoEM</source>
          <year>2011</year>
          , LNBIP 92, pp.
          <fpage>268</fpage>
          -
          <lpage>282</lpage>
          . Springer (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>