<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Prioritizing Cybersecurity Measures with Decision Support  Methods Using Incomplete Data </article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Hryhorii Hnatiienko</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nikolay Kiktev</string-name>
          <email>nkiktev@ukr.net</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Tatiana Babenko</string-name>
          <email>babenko.tetiana.v@gmail.com</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alona Desiatko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Larysa Myrutenko</string-name>
          <email>myrutenko.lara@gmail.com</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Kyiv National University of Trade and Economics</institution>
          ,
          <addr-line>Kioto str., 19, Kyiv, 02156</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>National University of Life and Environmental Sciences of Ukraine</institution>
          ,
          <addr-line>Heroiv Oborony str., 15, Kyiv, 03041</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Taras Shevchenko National University of Kyiv</institution>
          ,
          <addr-line>Volodymyrs'ka str., 64/13, Kyiv, 01601</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>169</fpage>
      <lpage>180</lpage>
      <abstract>
        <p>   Successful cybersecurity of any organizational system is based on the creation inadequacy and implementation of an integrated multi-level system of measures that cover the main aspects of the organization's functioning: organizational component, personnel management, computer equipment, local networks, software, databases, and other. For continuous and effective protection against threats, all of these aspects of cyber defense must interact in a complex and complementary manner. In such a case, one should also take into account such an attribute of a complex semi-structured system as incompleteness, which is a characteristic feature of such systems, since they contain, if necessary, a subjective component. Incomplete data is a characteristic feature of organizational systems. Despite this, an informed decision must be made. In particular, a common practical task is the ranking of alternatives of different nature. This is carried out by highly competent experts within the areas of responsibility. Naturally, a situation arises when a decision is made based on incomplete data, based on which it is necessary to find a complete resulting ranking of alternatives that best approximates the information received from experts, that is, in a sense, it is closest to the given incomplete expert rankings. To compare different ways of achieving the resulting ranking of alternatives, the formalization of the problem in the classes of single-criterion and multi-criteria models for the metrics of Cook, Hemming, Euclid, and Litvak is considered. The concept of a modified Litvak median and a compromise Litvak median is introduced, which is found using the minimax criterion.</p>
      </abstract>
      <kwd-group>
        <kwd> 1  Organizational system</kwd>
        <kwd>heuristic algorithm</kwd>
        <kwd>information security</kwd>
        <kwd>metric</kwd>
        <kwd>distance</kwd>
        <kwd>median</kwd>
        <kwd>group ordering of objects</kwd>
        <kwd>incomplete expert ranking</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction </title>
      <p> information resources of the organization;
 financial resources that ensure the functioning of the organization;
 technologies used by the organization;
 the brand of the company;
 goodwill - the reputation of the company and other.</p>
      <p>In this regard, the activities of organizations are characterized by a clear delineation of the areas of
responsibility of managers and the competence of the leaders of the organization in different areas of
activity is not a constant value. Therefore, information concerning the organization is usually
incomplete, fuzzy, heterogeneous, and its aggregation requires the development, justification and
proper application of new methods.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Review of research literature </title>
      <p>
        To model practical situations of decision-making in various subject areas, the formalism of
problems of group ordering of objects is often used [
        <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
        ]. Moreover, a feature of the generally
accepted formulations of such problems is the set of objects fixed for all members of the expert group.
Such a rigid binding of the objects set in many cases significantly reduces the quality of the
examination. Sometimes it is possible to specify incomplete rankings in collective ranking problems
[
        <xref ref-type="bibr" rid="ref2 ref5">2, 5</xref>
        ].. But at the same time, classical selection rules are applied to determine the collective decision.
To date, algebraic methods for calculating the median have not been applied to such problems.
      </p>
      <p>
        When planning and implementing measures aimed at improving information security, it should
always be borne in mind that they are multifaceted, and their importance, sequence of
implementation, level of funding, etc., from the point of view of various services of the organization,
may differ significantly. Therefore, it is logical to formalize the development of a sequence for
performing these activities in the class of group choice problems, focused on determining a subset of
equivalent solutions or ordering several selected alternatives [
        <xref ref-type="bibr" rid="ref5 ref6">5, 6</xref>
        ]. Such a flexible approach to the
ordering of objects, in which each expert can offer his own partial ordering of the selected subset of
alternatives, and the search for the complete resulting ranking of objects by algebraic methods is
relevant and promising.
      </p>
      <p>
        The generally accepted methodology used in the creation and study of complex socio-economic
and technical systems is systems analysis. Most of its stages are based on expert assessments and the
use of expert assessments, in particular, when choosing the structure of the system, its optimization
and solving problems of diagnostics, classification, forecasting, and other. It is also known that when
solving many practical problems, the importance of correct obtaining and processing of expert
information is underestimated [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ]. But the adequate use of expert knowledge requires a preliminary
analysis of the features of human decision-making [
        <xref ref-type="bibr" rid="ref2 ref8 ref9">2, 8, 9</xref>
        ] because the study of complex,
multifaceted and contradictory objects involves the use of significant analytical efforts [
        <xref ref-type="bibr" rid="ref10 ref11 ref12">10-12</xref>
        ].
      </p>
      <p>
        According to the selected approaches, the nature of the problems formulation and the form of
feedback when conducting expert assessments, the following main directions are distinguished [
        <xref ref-type="bibr" rid="ref6">6,
1315</xref>
        ]:
 absolute estimates;
 point estimates;
 metric estimates of the relative weight of alternatives, their parameters, criteria or the relative
competence of experts [
        <xref ref-type="bibr" rid="ref16 ref17">16, 17</xref>
        ];
 binary relations reflecting the results of pairwise comparisons of alternatives;
 ranking of alternatives.
      </p>
      <p>
        This article deals with the last two approaches and it will describe the tasks associated with these
areas. Note that the relation is one of the basic concepts of modern mathematics, and the language of
relations is successfully used to describe the relationship between alternatives. A relationship is also
often used to represent complex data structures. In particular, binary relations are the theoretical basis
of decision-making theory, since the properties of binary relations are used to assess the advantages of
alternatives in pairwise comparisons and are adequately interpreted in terms of the expert preference
system. An important way of presenting expert information, which is closely related to binary
relations, is the ranking of alternatives [
        <xref ref-type="bibr" rid="ref13 ref14 ref6">6, 13, 14</xref>
        ]. Often, the sequence of steps in making a decision is
a significant factor, both in protection and in ensuring the functional stability of the system and
eliminating threats. The incomplete ranking was investigated, for example, in works [
        <xref ref-type="bibr" rid="ref2 ref8">2, 8</xref>
        ]. Moreover,
in the monographs [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], the classical methods of the voting theory were applied to the problems of
determining the generalized ranking of alternatives. However, in such cases, it is the use of algebraic
methods for calculating the median that reflects the collective opinion of experts that is promising. In
the article [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ], only the general scheme for constructing the median is considered based on
incomplete rankings of alternatives given by experts.
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. The Purpose of the Study </title>
      <p>The study involves the development of approaches and methods for improving the adequacy of
modeling decision-making situations that arise when creating an integrated system for increasing the
reliability of an organization's cybersecurity. Such a task is a complex combinatorial task. Moreover,
this task is further complicated when, in the process of developing an integrated system of security
measures, divisions are involved in various areas of activity and areas of responsibility, which only
partially overlap. The approach proposed in this work a priori increases the adequacy and
professionalism of the individual opinions of the participants in the examination since experts have
the opportunity to make their judgments within their high on a set of criteria, they are undoubted
specialists, and not within the strict framework of determining priorities on the entire set of security
measures set for all members of the expert group.</p>
      <p>The article aims to develop directions and algorithms for solving the problem of the resulting
ranking based on the incomplete rankings of alternatives specified by experts and an experimental
study of these approaches.</p>
      <p>
        Based on the proposed approaches, it is necessary to develop algorithms for calculating the
resulting ranking of alternatives, consistent with the given incomplete rankings of experts, taking into
account various metrics and various criteria [
        <xref ref-type="bibr" rid="ref19 ref5">5, 19</xref>
        ].
      </p>
      <p>
        To create algorithms for comparing incomplete rankings of alternatives, mathematical models
should be developed that will contain tools that allow determining the distances between incomplete
rankings. Thus, it becomes possible to apply the algebraic approach, which is devoid of many
disadvantages typical for other approaches [
        <xref ref-type="bibr" rid="ref14 ref20 ref21">14, 20, 21</xref>
        ].
      </p>
    </sec>
    <sec id="sec-4">
      <title>4. Models and methods </title>
      <p>
        The main methods used in this work are the methods of decision theory [
        <xref ref-type="bibr" rid="ref14 ref8">8, 14</xref>
        ], expert
technologies [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ], heuristic algorithms [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. The methods of decision theory [
        <xref ref-type="bibr" rid="ref13 ref14">13, 14</xref>
        ] originate from
the theory of operations research. Expert technologies are widely used in various fields of human life
and have been actively developing in recent decades. One of the key concepts of expert technologies
is heuristics [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], which can be axioms, postulates, assumptions, presumptions, paradigms, hypotheses,
additions, sentences, and other. Heuristics are rules of thumb that can help to find a solution and
contribute to the certainty of incorrectly posed problems. With the help of heuristic algorithms,
variants of solutions close to optimal are generated, but they do not guarantee to find the optimal
solution to the problem [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ].
      </p>
    </sec>
    <sec id="sec-5">
      <title>5. Main Material </title>
      <p>
        For many practical situations, it is the sequence of steps taken when making a decision that is an
essential factor in both protection [
        <xref ref-type="bibr" rid="ref23 ref24 ref25">23-25</xref>
        ] and ensuring the reliability of the system's operation and
prompt elimination of threats [
        <xref ref-type="bibr" rid="ref26 ref27 ref28">26-28</xref>
        ].
      </p>
      <p>Let the problem of determining the sequence of implementation of information security measures
of some complex semi-structured system be solved. For this, various departments prepare and
substantiate decisions on the sequence or priority of integrated security measures for a large and
multidisciplinary organization. As a result, representatives of various departments and services
included in the expert group, within their competence and ideas about the importance of activities,
provide individual (partially ordered) proposals on the sequence of measures they propose to improve
the quality of cybersecurity in the form of incomplete rankings Ri ,i  1,..., k.</p>
      <p>Thus, each of the experts establishes a partial order on the subset of Ai , i  I  1,..., k, the set of
objects A, Ai  A, i  I , where he is competent, and within his sphere of influence or
responsibility. The partial orders set by the experts will be denoted as experts will be denoted
Ri  a j1  a j2  ...  a jki , i  I  1,..., k, ki  k, i  I. It is necessary to find some resultant
(aggregated, collective) ordering n of tasks R*  (ai ,..., ai ) , i j  J , j  I , built according to
1 n
logic, characterizing the processes of functioning and ensuring the protection of some organizational
system.</p>
      <p>At the first stage of solving the problem, the subsets of the security measures specified by the
experts are combined into a single set A, which includes all the measures proposed by the experts
ai  A, i  J. The set of all security measures specified by experts in the area of admissible
solutions for determining the resulting ranking of the organization's security measures R* .</p>
      <p>
        To determine the distances between the rankings of objects, the following are used: Cook's metric
of mismatching ranks of objects in individual rankings, the Hamming metric, and sometimes the
Euclidean metric. The most common and reasonable method for finding the resulting ranking [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ] of
objects is to calculate the median of the given rankings. It should be noted that the logic of building a
cyber defense system in an organization can admit and even require that experts assign an advantage
in the form of non-strict rankings [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. In the same class of problems, calculations of a single resulting
ranking should also be performed R* .
      </p>
      <p>
        One of the important requirements for such problems is the requirement of the connectivity of the
graph constructed according to particular expert orders or quasi-orders. To calculate the resulting
ranking with incomplete given individual rankings of experts, two approaches are possible. In the first
approach, to measure the distances between the ranking of security measures given by experts and the
resulting complex improvement of these measures, the Cook metric of the mismatch of the ranks of
objects in the individual ranking is selected [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ]. The second approach involves calculating the
resulting ranking of security measures using the Hamming metric [
        <xref ref-type="bibr" rid="ref30">30</xref>
        ] and using a heuristic
algorithm.
      </p>
      <p>
        Let the problem of determining the importance of the set of alternatives of some complex system
be solved. For this, the preparation and justification of the decision on the sequence of alternatives
arrangement of a large and multidisciplinary organization is carried out. Representatives of various
departments and services included in the expert group, within their competence and understanding of
the importance of alternatives, provide individual proposals on the sequence of implementation of
alternatives that fall within their area of responsibility, or the priority of considering alternatives.
Tastes often do not coincide among the members of the expert group, which is reflected in their
compilation of different subsets of alternatives. This is justified by many factors: the competence of
experts, their interests, priorities, accents, aspects of the considered ideas about the idealization of the
model, and the other [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ]. Therefore, at the previous stage of aggregation, there should be the
implementation of the stage of combining subsets of alternatives, ranked by experts into a single set
of alternatives.
      </p>
    </sec>
    <sec id="sec-6">
      <title>5.1. Problem Statement </title>
      <p>
        In [
        <xref ref-type="bibr" rid="ref19 ref5">5, 19</xref>
        ], the concept of incomplete ranking was introduced: it is a binary relation defined on a
subset of alternatives A' , A'  A , satisfying the properties of completeness, antisymmetry,
transitivity: but only on a subset A' , A'  A , and not on the entire set A . Let the expert group k
specify incomplete rankings of alternatives R iН , i  1,..., k. It is necessary to find some group
(resulting, aggregated, collective, consensus, integrative) ranking n of alternatives R*  (ai ,..., ai ) ,
1 n
i j  I  1,..., n, j  I , built according to logic, characterizing the processes of functioning of some
organizational system. That is R * , the ranking should be built based on individual orderings of tasks
performed by system k elements (experts) RiН  (a1i ,..., ani ), i  J  1,..., k, where ni  the
number of tasks in an individual expert ranking i  J .
      </p>
    </sec>
    <sec id="sec-7">
      <title>5.2. Metrics and Criteria </title>
      <p>
        Distances between rankings of alternatives are determined using metrics [
        <xref ref-type="bibr" rid="ref19 ref5">5, 19</xref>
        ]:
• -Cook metrics of mismatch of ranks (places, positions) of alternatives,
(1) 
d R j , Rl    ril  ril ,  
      </p>
      <p>
        iI
where ril is the rank of the i  th alternative in the ranking of the l  th expert, R l , l  L,
1  ril  n,
• Hamming metrics [
        <xref ref-type="bibr" rid="ref20 ref21">20, 21</xref>
        ];
• Euclidean metrics [
        <xref ref-type="bibr" rid="ref14 ref20">14, 20</xref>
        ];
• A vector of advantages, the elements of which are the number of alternatives that precede each
alternative in the ranking.
      </p>
      <p>The criteria that are most often applied in such cases:
• additive;
• minimax.
5.3. Formalizing the Problem of Determining the Resulting Ranking </p>
      <p>The most common method for finding the resulting ranking of alternatives is to calculate the
median of the given rankings. This group of methods for generalizing expert information is the most
reliable and mathematically justified. The solution to the problem, determined by applying various
metrics and various criteria, is the median of the linear orders specified by experts.</p>
      <p>Let us denote the set of all possible rankings n of alternatives through R , the set of paired
comparison matrices (PCM) that correspond to all possible ranking n of objects – through B , the
set of vectors of advantages reflecting the number of alternatives that precede each alternative in the
ranking (from 0 to n  1 ) – through  P The set of rankings and binary relations given by experts in
their answers, will be denoted by, they are answered, will be denoted by R A ; the set of PCMs and
binary relations between the alternatives corresponding to the ranking - through, and the set of vectors
A
of advantages and corresponding relations – through P .</p>
      <p>For the case under consideration in this work, the cardinality of the sets R A , R B and P A is the
same:</p>
      <p>R A  R B  P A  n ,</p>
      <p>Rl  R A , Bl  R B , P l  P A , l  L .</p>
      <p>
        It
is
clear
that
R A   R , R B   B , P A   P . In general, the cardinality of the set B  P  2nn1/ 2 . But
for the method described in this work, we will consider only their subsets, denoting these subsets in
the same way  R   B   P  n!, since we are not intransitively interested in the elements of
the solution space  B and P .
5.4. Using a Cook metric for Incomplete Rankings of Alternatives 
For the Cook metric (1), using the additive criterion, the following are calculated:
• Cook-Seyford median [
        <xref ref-type="bibr" rid="ref13 ref14">13, 14</xref>
        ]:
(3) 
(4) 
(5) 
when using the minimax criterion, the following is calculated:
• GV-median (compromise) [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]:
• modified GV-median [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]:
      </p>
      <p>R CS  CS  Arg min  d r R, R l  </p>
      <p>RR lL
R МCS   МCS  Arg min  d r R, Rl .  </p>
      <p>RRA lL
R ГВ   ГВ  Arg min max d r R, Rl   </p>
      <p>RR lL
R МГВ   МГВ  Arg min max d r R, R l .  </p>
      <p>
        RR A lL
• modified Cook-Seyford median [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ]:
      </p>
      <p>
        Cook's metric is popular in the problems of ranking alternatives [
        <xref ref-type="bibr" rid="ref13 ref18">13, 18</xref>
        ]. To use it in solving the
set problem of analyzing incomplete rankings, we introduce heuristics and, on their basis, determine
the distance from the rankings set by the experts to the reference ranking.
      </p>
      <p>
        In connection with the peculiarities of calculating generalized ranking with incomplete initial
information, in [
        <xref ref-type="bibr" rid="ref19 ref5">5, 19</xref>
        ] it was proposed to use a number of heuristics. In particular, the components of
the distances for incomplete ranking of objects are described as follows. Heuristic E1. The distance
*(0)
from the incomplete rankings R iН , i  1,..., k, given by the experts to any ranking consists R
of
two components: a certain part of the distance and a probabilistic one. Heuristic E2. An alternative not
specified by an expert generates unknown relationships between all other alternatives and does not
take part in the ranking, that is, this alternative is not represented in an incomplete ranking. Thus,
when setting incomplete rankings for each Expert Advisor, there are several alternatives:
n  the alternatives given by him in the ranking RiН ,i  1,..., k, , which will make up a certain
i
part of the distances;
      </p>
      <p>(n  ni )  i  alternatives unspecified by the expert in the ranking RiН ,i  1,..., k, of the
distances constituting the probabilistic part.</p>
      <p>Heuristic E3. The probabilistic part of the distance from the ranking RiН , i  1,..., k, given by the
expert to any reference ranking is always equal  i , i  1,..., k, for the Cook metric. A certain part of
the distance is calculated by the formula (1).
5.5. Еuclidean Measure of Proximity and Calculation of the Mean 
determined using the Euclidean</p>
      <p>
        According to [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], the resulting ranking can be the average R S   S  Arg min  d 2 R, R l .
RRB lL
It is advisable to use such a resulting ranking [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] if the distance between expert rankings is
 1/ 2
measure of proximity: d Е (B j , Bl )    rt j  rtl 2  ,
 tH 
t  H , j, l  L.
5.6. Using the Hamming Metric for Incomplete Rankings of Alternatives 
      </p>
      <p>
        The probabilistic part from the ranking R iН , i  1,..., k , given by the expert to any other ranking
for the Hamming metric is always equal to  i  ( i  1) / 2, i  1,..., k. To pass from the space of ranks
to the space of pairwise comparisons of alternatives [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], the individual incomplete advantages given
by each expert on subsets of alternatives R lН , l  L , are represented in the form of an incomplete
matrix of pairwise comparisons
l
      </p>
      <p>Where bij , i, j  I , l  L, if and only if, according to the l  th expert, the i  th alternative
prevails in the j  th alternative. Moreover, bilj  blji , i, j  I , l  L. when l  the expert did not
set the preference relation between the alternatives ai
and
a j , then this fact affects
biljН "*", j  I , l  L.</p>
      <p>To determine the distances between incomplete relations (6), the Hamming metric is used
d h (B j , Bl )  0,5  bisj  bis .</p>
      <p>l
iI sI</p>
      <p>Heuristic E4. The mathematical expectation of the indeterminate distances between the alternatives
in the ranking is equal to one. That is, the distance between the PCM elements, at least one of which
is not defined, must be equal to 1 - on the assumption that the equality of its value "-1" or "1" are
equally probable. Since the matrices of relations BН and R Н the form (1) are skew-symmetric.
Without loss of generality, we will use the vectors constructed on their basis ct  bij , xt  rij ,
t  i  1  n  j  i  1  i / 2, 1  i  j  n. Let us denote by N  n  n  1 / 2 the number of
elements of the vectors c, and by H  1,..., N – the set of indices of the elements of these vectors.
Then the distance between the relations B and R will be written in the form
d h (B j , Bl )   ctj  ctl , j, l  L.  </p>
      <p>
        tH
For the Hamming metric (7), when using the additive criterion, the following are calculated:
• Kemeny-Snell median:
• modified median [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ] Kemeny-Snell:
When using the minimax criterion, the following are calculated:
• VG-median (compromise) [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]:
      </p>
      <p>RКС  КС  Arg mBinB lL d h B, Bl  
RМКС  МКС  Arg mBiRnB lL d h B, Bl .  
R ВГ  ВГ  Arg min max d h B, Bl  </p>
      <p>BB lL
   (6) 
(7) 
(8) 
(9) 
(10) 
Modified VG-median:</p>
      <p>RМВГ  МВГ  Arg min max d h B, Bl .   (11) </p>
      <p>BRB lL</p>
      <p>
        Methods for determining medians of the form (2), (4), (8), (10) and their features are considered in
the monograph [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ]. The modified medians (3), (9) were proposed to be applied, in particular, in [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ],
but their use in many practical problems is inappropriate and sometimes unreasonable and
inappropriate. This is because the modified median significantly limits the choice space; therefore,
when applying such criteria, as a rule, we find ineffective solutions: they dominate, in particular, the
median itself of the form (3), (5), (9), (11).
5.7. Using  Distances  Between  Benefit  Vectors  for  Incomplete  Rankings  of 
      </p>
      <p>Alternatives </p>
      <p>
        To apply the algebraic approach on a set of rankings, one can use the distance based on the vectors
of advantages [
        <xref ref-type="bibr" rid="ref29 ref30">29, 30</xref>
        ]  l   1l ,..., nl , where  il  the number of alternatives precedes the i 
alternative in the l  ranking. In the monograph [
        <xref ref-type="bibr" rid="ref32 ref33">32, 33</xref>
        ] B.G. Litvak proposed for the vectors of
We also introduce the concept of a modified Litvak median:
When using the minimax criterion, we introduce the following medians:
• LK-median or Litvak compromise median:
      </p>
      <p>RL  L  Arg mRinR lL d R, Rl  
RML  ML  Arg min  d R, Rl  </p>
      <p>RA lL
• modified LK-median:</p>
      <p>R LK  LK  Arg min max d R, Rl  </p>
      <p>RR lL
RMLK  MLK  Arg min max d R, Rl   </p>
      <p>RA lL</p>
      <p>For incomplete rankings when using the distance (12) between the vectors of advantages, we will
also use heuristics similar to those introduced for medians, based on the application of the Cook
metric (1). Likewise, the distances between the advantage vectors are applied and modified to
determine the Litvack median.
advantages  1 and  2 , formed based on rankings R1 and R2 , to determine the distance by the
formula:
d (R1, R2 )    i1  i2 .  (12) </p>
      <p>iI</p>
      <p>
        For vectors of advantages of the form (12), using the additive criterion, the Litvak median is
calculated [
        <xref ref-type="bibr" rid="ref29 ref30">29, 30</xref>
        ]:
(13) 
(14) 
(15) 
(16) 
(17) 
5.8. Heuristic Algorithm for Determining Medians Using the Heming Metric 
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ], a heuristic algorithm for determining the median R* of a given set of incomplete rankings
RiН , i  I , in the form of the Kemeny-Snell median is given, which is given in [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ].
      </p>
      <p>Step 1. Let us write the upper supra-diagonal triangular parts of the matrices BiН , i  I , in the
form of rows of the new matrix: C  (cij ),i  I , j  J  {1,..., N}, N  n * (n 1) / 2.. Matrix
elements C are defined as follows: сij  blit , j  (l 1) * n  t  l * (l 1) / 2, 1  l  t  n, i  I.</p>
      <p>Step 2. Define a metric priority matrix M  (mlt ),l, t  I , the elements of which are calculated as
follows:
  mlt   cij /  cij ,  1  l  t  n, j  J ,  
iI , iI ,
cij0 cij0
where
x 
is the
absolute
value
of the
number
x,
l   j /n   j / n1,
t  j  l 1* n  l * (l  1) / 2, where x is the integer part of the number x . In this case, the
values of the symmetric elements of the matrix are in the following ratio:
mtl  1/ mlt , mtt  1, t,l  I. It is clear that the elements сij , i  I , j  J , whose values are not
determined by experts, that is сij '*', they do not participate in the formation of values mlt ,
1  l  t  n, j  J , of the form (1).</p>
      <p>Step 3. Construction of the residual matrix P  pij , i  1,..., n, j  1,..., N , based on the analysis
of all possible relationships between the triplets of alternatives.</p>
      <p>p1 j  mlt , j  (l 1) * n  t  l * (l 1) / 2, 1  l  t  n,
mls / mts , l  s, s  t,

pij  mls * mts , l  s, s  t,  

mst / msl , l  s, s  t,
(18) 
s  1,...n, s  l, s  t, i  l 1, l  1,..., n 1, t  l 1,..., n, j  (l 1) * n  t  l * (l  1) / 2.</p>
      <p>Step 4. Replacing one of the matrix elements for each index i  2,..., n, with a matrix element
M  (mlt ), l, t  I , if the elements P  pij , i  2,..., n, j  1,..., N , do not match: mlt  pij , for
j  (l 1) * n  t  l * (l 1) / 2.</p>
      <p>P  pij , i  2,..., n, j  1,..., N.</p>
      <p>Step 5. For each next generated in point 4 matrix, determine the weighting coefficients of each of
n the alternatives by the method of urgent or column sums, which are the standard of the
computational simplicity of determining the "weight".</p>
      <p>Step 6. Placing (or sorting) the elements of the vector elements of the vector obtained in step 5, in
descending order of values (for row sums) or increasing values (for sums in rows). The indices of the
vector ordered in this way will be considered the indices of alternatives in the resulting ranking.</p>
      <p>Step 7. Determination of the sum of the distances from the ranking obtained in clause 6 to the
ranking given by the experts, according to the rules described for incomplete matrices of pairwise
comparisons.</p>
      <p>Step 8. Continuation of the procedures described in steps (points) 4-7 until all modified matrices
M  (mlt ), l, t  I are calculated by replacing the next matrix element in them</p>
      <p>The best matrices obtained in this way, defined in points 4-8, will make up the set of
KemenySnell medians. The VG-median can also be determined using the described algorithm since it
generates variants that are close to optimal solutions.</p>
      <p>The authors carried out a computational experiment using a heuristic algorithm for matrices of
dimensions from 6x6 to 10x10, that is, when several dozen randomly ordered 6-10 alternatives are
given. Experiments using the described method, verified by exact methods, gave the following results:
• with poor consistency of matrices set by experts, the set of effective solutions can be very large
the number of Kemeny-Snell medians for some advantage profiles is up to 15% of the total
number of rankings on a set of alternatives, that is, up to 0.15*n!;
• among the solutions found using the described algorithm when applying the method of urgent
sums, up to 50% of the rankings of alternatives is the Kemeny-Snell median, and when using the
method of line sums - up to 83%;
• application of the described algorithm in some cases allows to find up to 39% of rankings
belonging to the set of Kemeny-Snell medians;
• among the compromise rankings of the form (18) found using the described algorithm, up to
22% is at the same time the GV-median.</p>
      <p>Thus, the described algorithm is a convenient heuristic method for determining the sets of
Kemeny-Snell medians and GV-medians. Although it is impossible to determine the entire set of
effective solutions using this algorithm, some of the medians are guaranteed to be calculated. The
study confirms the relationship between the ordinal and cardinal models for setting expert
preferences, as well as the prospects of using heuristic algorithms in the problems of expert
assessment.</p>
    </sec>
    <sec id="sec-8">
      <title>6. Options for Using the Developed Algorithms </title>
      <p>
        The algorithms for calculating the resulting ranking of the given incomplete expert rankings of
alternatives described in this work can be applied to solve various problems in various subject areas.
In particular, using the described approaches and the algorithms presented, the following problems
can be solved:
• development of a system of complex cybersecurity measures [
        <xref ref-type="bibr" rid="ref28 ref3 ref4">3, 4, 28</xref>
        ];
• development and implementation of procedures for rapid response to external threats to the
organizational system;
• search for the ranking of the most popular cryptocurrencies on trading floors and determine the
integral ordering of the popularity of the cryptocurrency;
• selection of textbooks for the formation of a list of literature and determination of the sequence
of presentation of the academic discipline;
• determination of the sequence of preparation of collections of books in libraries for the
harmonious formation of personality;
• construction of a sequence of lecture courses in the tasks of developing curricula of educational
programs.
      </p>
    </sec>
    <sec id="sec-9">
      <title>7. Further Research </title>
      <p>
        In many tasks, events that should be sequenced using incomplete expert rankings must run in
parallel, or even occur simultaneously. Therefore, it is logical to formalize the problem posed in the
class of computing the collective quasi-order [
        <xref ref-type="bibr" rid="ref14 ref20">14, 20</xref>
        ].
      </p>
      <p>
        It is also promising to develop parallel algorithms using artificial intelligence methods, the use of
which in the described approaches can contribute to obtaining a synergistic effect when:
• formalization and further optimization of business processes [
        <xref ref-type="bibr" rid="ref36">36</xref>
        ];
• solving problems of information recovery to the preferences of experts based on the definition
of group ranking.
• application of the formalisms of the problem of determining collective ranking to a wide class
of classical combinatorial problems in the descriptions of the corresponding statements for
adaptation and interpretation of the statement.
      </p>
    </sec>
    <sec id="sec-10">
      <title>8. Conclusions </title>
      <p>
        A model of an integrated approach to the construction of a cybersecurity system for some complex
weakly structured organizational system is considered. An approach to finding the resulting ranking
of the priority of cybersecurity measures as a solution to the problem of multi-criteria optimization is
also described. This approach makes it possible to determine the resulting ordering of a set of
activities in the form of a median of incomplete rankings given by experts. The proposed approach
allows you to combine information security measures of different composition and priorities,
proposed by experts from the relevant departments of the organization; find a compromise solution
for a diverse group of experts; use the described technique to solve data augmentation problems; build
an integrated cybersecurity system for an organization [
        <xref ref-type="bibr" rid="ref34 ref35">34, 35</xref>
        ] or improve a previously created
system of measures [
        <xref ref-type="bibr" rid="ref17 ref37">17, 37</xref>
        ].
      </p>
      <p>Thus, in this work, approaches to determining the resulting ranking of alternatives based on
incomplete expert rankings were investigated and the following main results were obtained:
• the formulation of tasks for determining the group ranking of alternatives based on incomplete
expert rankings is proposed;
• introduced the concept of Litvak's compromise median;
• approaches to the aggregation of expert data are considered, taking into account the peculiarities
of incomplete information received from experts;
• algorithms have been developed for solving problems of calculating large-scale collective
ranking;
• computational experiments were carried out to study the described algorithms and features of
the ranking problems;
• it has been found that the modified medians of a given set of expert rankings are always
naturally and reasonably dominated by the medians calculated in the full space of all possible
rankings of alternatives.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Voloshin</surname>
            ,
            <given-names>A.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gnatienko</surname>
            ,
            <given-names>G.N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Drobot</surname>
            ,
            <given-names>E.V.</given-names>
          </string-name>
          <article-title>A Method of Indirect Determination of Intervals of Weight Coefficients of Parameters for Metricized Relations Between Objects</article-title>
          .
          <source>Journal of Automation and Information Sciences</source>
          ,
          <year>2003</year>
          ,
          <volume>35</volume>
          (
          <issue>1</issue>
          -
          <fpage>4</fpage>
          ). DOI:
          <volume>10</volume>
          .1615/JAutomatInfScien.v35.
          <year>i3</year>
          .
          <fpage>30</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>A.</given-names>
            <surname>Dodonov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Lande</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Tsyganok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Andriichuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kadenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Graivoronskaya</surname>
          </string-name>
          , Information Operations Recognition.
          <article-title>From Nonlinear Analysis to Decision-Making</article-title>
          , LAP Lambert Academic Publishing,
          <year>2019</year>
          , 292 p.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>Hrechko</given-names>
            <surname>Viktoriia; Hrygorii Hnatienko; Tetiana Babenko</surname>
          </string-name>
          .
          <article-title>An intelligent model to assess information systems security level</article-title>
          .
          <source>2021 Fifth World Conference on Smart Trends in Systems Security and Sustainability (WorldS4)</source>
          , London, United Kingdom,
          <fpage>29</fpage>
          -
          <issue>30</issue>
          <year>July 2021</year>
          , pp.
          <fpage>128</fpage>
          -
          <lpage>133</lpage>
          . DOI:
          <volume>10</volume>
          .1109/WorldS451998.
          <year>2021</year>
          .
          <volume>9514019</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Babenko</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hnatiienko</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vialkova</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          <article-title>Modeling of the integrated quality assessment system of the information security management system</article-title>
          .
          <source>CEUR Workshop Proceedings</source>
          ,
          <year>2021</year>
          ,
          <volume>2845</volume>
          , pp.
          <fpage>75</fpage>
          -
          <lpage>84</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Hnatiienko</surname>
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tmienova</surname>
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kruglov</surname>
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2021</year>
          )
          <article-title>Methods for Determining the Group Ranking of Alternatives for Incomplete Expert Rankings</article-title>
          . In: Shkarlet S.,
          <string-name>
            <surname>Morozov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Palagin</surname>
            <given-names>A</given-names>
          </string-name>
          . (eds) Mathematical Modeling and
          <article-title>Simulation of Systems (MODS'</article-title>
          <year>2020</year>
          ).
          <source>MODS 2020. Advances in Intelligent Systems and Computing</source>
          , vol
          <volume>1265</volume>
          . Springer, Cham. DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>030</fpage>
          -58124-4_
          <fpage>21</fpage>
          . Pp.
          <volume>217</volume>
          -
          <fpage>226</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Hnatiienko</surname>
            <given-names>H. Choice</given-names>
          </string-name>
          <article-title>Manipulation in Multicriteria Optimization Problems / Selected Papers of the XIX International Scientific and Practical Conference "Information Technologies and Security"</article-title>
          (ITS
          <year>2019</year>
          ), pp.
          <fpage>234</fpage>
          -
          <lpage>245</lpage>
          (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Hnatiienko</surname>
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Snytyuk</surname>
            <given-names>V.</given-names>
          </string-name>
          <article-title>A posteriori determination of expert competence under uncertainty / Selected Papers of the XIX International Scientific and Practical Conference "Information Technologies and Security"</article-title>
          (ITS
          <year>2019</year>
          ), pp.
          <fpage>82</fpage>
          -
          <lpage>99</lpage>
          (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Makarov</surname>
            ,
            <given-names>I.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vinogradskaya</surname>
            ,
            <given-names>T.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rubchinsky</surname>
          </string-name>
          , А.А.
          <article-title>Theory of choice and decision making, Nauka</article-title>
          , Moscow,
          <year>1982</year>
          , 328 p.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Bozóki</given-names>
            <surname>Sándor</surname>
          </string-name>
          &amp;
          <article-title>Tsyganok Vitaliy. The (logarithmic) least squares optimality of the arithmetic (geometric) mean of weight vectors calculated from all spanning trees for incomplete additive (multiplicative) pairwise comparison matrices</article-title>
          .
          <source>International Journal of General Systems</source>
          .
          <year>2019</year>
          . vol.
          <volume>48</volume>
          , No.4. P.
          <volume>362</volume>
          -
          <fpage>381</fpage>
          . DOI:
          <volume>10</volume>
          .1080/03081079.
          <year>2019</year>
          .1585432
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Hudry</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          <article-title>NP-hardness results on the aggregation of linear orders into median orders</article-title>
          .
          <source>Annals of Operations Research</source>
          . 
          <year>2008</year>
          .  Vol.
          <volume>163</volume>
          , No.
          <volume>1</volume>
          .  Pp.
          <fpage>63</fpage>
          -
          <lpage>88</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Kadenko</surname>
            <given-names>S.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsyganok</surname>
            <given-names>V.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Andriichuk</surname>
            <given-names>O.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Karabchuk</surname>
            <given-names>A.V.</given-names>
          </string-name>
          <article-title>An analysis of decisionmaking support tools in the context of strategic planning problem solution</article-title>
          .
          <source>Data Recording, Storage &amp; Processing</source>
          .
          <year>2020</year>
          . Vol.
          <volume>22</volume>
          .
          <string-name>
            <surname>Nо</surname>
          </string-name>
          . 2. P.
          <volume>77</volume>
          -
          <fpage>91</fpage>
          . [in Ukrainian] DOI: 10.35681/
          <fpage>1560</fpage>
          -
          <lpage>9189</lpage>
          .
          <year>2020</year>
          .
          <volume>22</volume>
          .2.
          <fpage>211281</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>List</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          <article-title>Judgement aggregation: a survey</article-title>
          . C. List,
          <string-name>
            <given-names>C.</given-names>
            <surname>Puppe</surname>
          </string-name>
          . In:
          <article-title>Oxford handbook of rational and social choice</article-title>
          .  Oxford: Oxford University Press. 
          <year>2009</year>
          .  Pp.
          <fpage>457</fpage>
          -
          <lpage>482</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Cook</surname>
            ,
            <given-names>W.D.</given-names>
          </string-name>
          <article-title>Distance-based and adhoc consensus models in ordinal preference ranking</article-title>
          .
          <source>European Journal of Operational Research</source>
          . 
          <year>2006</year>
          .  No.
          <fpage>172</fpage>
          .  Pp.
          <fpage>369</fpage>
          -
          <lpage>385</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Voloshin</surname>
            <given-names>O.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mashchenko</surname>
            <given-names>S.O.</given-names>
          </string-name>
          <string-name>
            <surname>Decision Theory</surname>
            :
            <given-names>A</given-names>
          </string-name>
          <string-name>
            <surname>Textbook</surname>
          </string-name>
          . - Kyiv: Kyiv University Publishing and Printing Center,
          <year>2006</year>
          . - 304 p.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>A.</given-names>
            <surname>Alnur</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Meila</surname>
          </string-name>
          .
          <article-title>Experiments with Kemeny Ranking: What Works When? Mathematical Social Sciences</article-title>
          . 
          <year>2012</year>
          .  Vol.
          <volume>64</volume>
          , No.
          <volume>1</volume>
          .  Pp.
          <fpage>28</fpage>
          -
          <lpage>40</lpage>
          . DOI:
          <volume>10</volume>
          .1016/j.mathsocsci.
          <year>2011</year>
          .
          <volume>08</volume>
          .008
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Saaty</surname>
            ,
            <given-names>T.L</given-names>
          </string-name>
          .
          <article-title>Decision making with the analytic hierarchy process</article-title>
          ,
          <source>International Journal of Services Sciences</source>
          <volume>1</volume>
          (
          <issue>1</issue>
          ) (
          <year>2008</year>
          ):
          <fpage>83</fpage>
          -
          <lpage>98</lpage>
          . DOI:
          <volume>10</volume>
          .1504/IJSSCI.
          <year>2008</year>
          .
          <volume>017590</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>M.</given-names>
            <surname>Rakushev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Kravchenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Permiakov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Lavrinchuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Bychenkov</surname>
          </string-name>
          ,
          <string-name>
            <surname>Krainov</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          <article-title>Modeling of solving stabilized differential equations by differential-Taylor transformations</article-title>
          ,
          <source>IEEE 2nd International Conference on Advanced Trends in Information Theory</source>
          , ATIT`
          <year>2020</year>
          , Proceedings, pp.
          <fpage>216</fpage>
          -
          <lpage>221</lpage>
          . DOI:
          <volume>10</volume>
          .1109/ATIT50783.
          <year>2020</year>
          .9349265
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Hnatiienko</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kudin</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Onyshchenko</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Snytyuk</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Kruhlov</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <article-title>Greenhouse Gas Emission Determination Based on the Pseudo-Base Matrix Method for Environmental Pollution Quotas Between Countries Allocation Problem</article-title>
          .
          <source>2020 IEEE 2nd International Conference on System Analysis &amp; Intelligent Computing (SAIC)</source>
          , Kyiv, Ukraine,
          <year>2020</year>
          , pp.
          <fpage>150</fpage>
          -
          <lpage>157</lpage>
          , DOI: 10.1109/SAIC51296.
          <year>2020</year>
          .
          <volume>9239125</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Saaty</surname>
            ,
            <given-names>T. L.</given-names>
          </string-name>
          (
          <year>2016</year>
          ).
          <article-title>Pairwise Comparisons and their Contribution to Understanding Consciousness</article-title>
          .
          <source>International Journal of the Analytic Hierarchy Process</source>
          ,
          <volume>8</volume>
          (
          <issue>1</issue>
          ).
          <source>DOI: 10.13033/ijahp.v8i1.381</source>
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Voloshin</surname>
            ,
            <given-names>O.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mashchenko</surname>
          </string-name>
          . S.O.
          <article-title>Models and methods of decision making: textbook. way for students. higher textbook zakl</article-title>
          .,
          <string-name>
            <surname>K.</surname>
          </string-name>
          :
          <article-title>Publishing and Printing Center "Kyiv University"</article-title>
          ,
          <year>2010</year>
          , 336 p.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Saaty</surname>
            ,
            <given-names>T.L.</given-names>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>Aligning the Measurement of Tangibles With Intangibles And Not the Converse</article-title>
          .
          <source>International Journal of the Analytic Hierarchy Process</source>
          ,
          <volume>3</volume>
          (
          <issue>1</issue>
          ).
          <source>DOI: 10.13033/ijahp.v3i1.91</source>
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Mulesa</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Snytyuk</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Myronyuk</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          (
          <year>2019</year>
          ).
          <article-title>Optimal alternative selection models in a multi-stage decision-making process</article-title>
          .
          <source>EUREKA: Physics and Engineering</source>
          , (
          <volume>6</volume>
          ),
          <fpage>43</fpage>
          -
          <lpage>50</lpage>
          . DOI:
          <volume>10</volume>
          .21303/
          <fpage>2461</fpage>
          -
          <lpage>4262</lpage>
          .
          <year>2019</year>
          .001005
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Kravchenko</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vialkova</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          <article-title>The problem of providing functional stability properties of information security systems</article-title>
          . Modern Problems of Radio Engineering, Telecommunications and Computer Science,
          <source>Proceedings of the 13th International Conference on TCSET 2016</source>
          , pp.
          <fpage>526</fpage>
          -
          <lpage>530</lpage>
          . DOI:
          <volume>10</volume>
          .1109/TCSET.
          <year>2016</year>
          .7452105
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Andrew</surname>
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Tanenbaum</surname>
          </string-name>
          , Maarten Van Steen.
          <source>Distributed Systems: Principles and Paradigms</source>
          ,
          <source>Prentice Hall of India; 2nd edition (January</source>
          <volume>1</volume>
          ,
          <year>2007</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <surname>White</surname>
            ,
            <given-names>G.B.</given-names>
          </string-name>
          :
          <article-title>The community cyber security maturity model</article-title>
          .
          <source>In: IEEE International Conference on Technologies for Homeland Security</source>
          , pp.
          <fpage>173</fpage>
          -
          <lpage>178</lpage>
          . IEEE Press, Wakefield (
          <year>2011</year>
          ). DOI:
          <volume>10</volume>
          .1109/HICSS.
          <year>2007</year>
          .522
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <article-title>Department of Energy: Cybersecurity Capability Maturity Model (C2M2): Version 1.1</article-title>
          .
          <string-name>
            <surname>Technical</surname>
            <given-names>report</given-names>
          </string-name>
          , Department of Homeland Security (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>Angel</given-names>
            <surname>Marcelo</surname>
          </string-name>
          Rea-Guaman, Tomás San Feliu, Jose A.
          <string-name>
            <surname>Calvo-Manzano</surname>
          </string-name>
          , and
          <string-name>
            <surname>Isaac Daniel</surname>
          </string-name>
          Sanchez-Garcia.
          <source>Comparative Study of Cybersecurity Capability Maturity Models / International Conference on Software Process Improvement</source>
          and
          <string-name>
            <given-names>Capability</given-names>
            <surname>Determination</surname>
          </string-name>
          . -
          <year>September 2017</year>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -67383-
          <issue>7</issue>
          _
          <fpage>8</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <surname>Palko</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hnatienko</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Babenko</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bigdan</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <article-title>Determining key risks for modern distributed information systems</article-title>
          .
          <source>CEUR Workshop Proceedings</source>
          ,
          <year>2021</year>
          ,
          <volume>3018</volume>
          , pp.
          <fpage>81</fpage>
          -
          <lpage>100</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>S.</given-names>
            <surname>Amodio</surname>
          </string-name>
          ,
          <string-name>
            <surname>A. D'Ambrosio</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Siciliano</surname>
          </string-name>
          .
          <article-title>Accurate algorithms for identifying the median ranking when dealing with weak and partial rankings under the Kemeny axiomatic approach</article-title>
          .
          <source>European Journal of Operational Research</source>
          ,
          <year>2015</year>
          , No.
          <volume>249</volume>
          .pp.
          <fpage>667</fpage>
          -
          <lpage>676</lpage>
          . DOI:
          <volume>10</volume>
          .1016/j.ejor.
          <year>2015</year>
          .
          <volume>08</volume>
          .048
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <surname>Hudry</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          <article-title>Complexity of computing median linear orders and variants</article-title>
          .
          <source>Electronic Notes in Discrete Mathematics</source>
          ,
          <year>2013</year>
          , Vol.
          <volume>42</volume>
          .  Pp.
          <fpage>57</fpage>
          -
          <lpage>64</lpage>
          . DOI:
          <volume>10</volume>
          .1016/j.endm.
          <year>2013</year>
          .
          <volume>05</volume>
          .146
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <surname>Orlov</surname>
            ,
            <given-names>A.I.</given-names>
          </string-name>
          <article-title>Methods of making managerial decisions: textbook - M .:</article-title>
          <string-name>
            <surname>KNORUS</surname>
          </string-name>
          ,
          <year>2018</year>
          . - 286 p.
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>A.</given-names>
            <surname>Boltenkov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. I.</given-names>
            <surname>Kuvaeva</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. V.</given-names>
            <surname>Poznyak</surname>
          </string-name>
          .
          <article-title>Analysis of median methods of consensus aggregation of rank preferences</article-title>
          .
          <source>Computer Science and Mathematical Methods in Models</source>
          ,
          <year>2017</year>
          , vol.
          <volume>7</volume>
          , No. 4. - pp.
          <fpage>307</fpage>
          -
          <lpage>317</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <given-names>H.</given-names>
            <surname>Bury</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Wagner</surname>
          </string-name>
          .
          <article-title>Zastosowanie mediany Litvaka do wyznaczania oceny grupowej w przypadku występowania obiektów równoważnych</article-title>
          .
          <source>Studia i Materiały Polskiego Stowarzyszenia Zarządzania Wiedzą</source>
          ,
          <year>2007</year>
          , Vol.
          <volume>10</volume>
          .  Pp.
          <fpage>19</fpage>
          -
          <lpage>34</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          <source>[34] ISO. ISO/IEC 27001:2013 Information technology - Security techniques - Information security management systems - Requirements</source>
          ;
          <year>2013</year>
          . URL: https://www.iso.org/standard/54534.html
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [35]
          <article-title>ISO</article-title>
          . ISO/IEC 27002:
          <year>2013</year>
          <article-title>Information technology - Security techniques - code of practice for information security controls; 2013</article-title>
          . URL: https://www.iso.org/standard/54533.html
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [36]
          <string-name>
            <surname>Kraevsky</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kostenko</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kalivoshko</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kiktev</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lyutyy</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          <article-title>Financial Infrastructure of Telecommunication Space: Accounting Information Attributive of Syntalytical Submission</article-title>
          . IEEE International Scientific-Practical Conference Problems of Infocommunications,
          <source>Science and Technology (PIC S&amp;T)</source>
          ,
          <volume>8</volume>
          -
          <fpage>11</fpage>
          Oct.
          <year>2019</year>
          , Kyiv, Ukraine,
          <year>2019</year>
          . - pp.
          <fpage>873</fpage>
          -
          <lpage>876</lpage>
          . DOI:
          <volume>10</volume>
          .1109/PICST47496.
          <year>2019</year>
          .
          <volume>9061494</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          [37]
          <string-name>
            <surname>Stouffer</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stouffer</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zimmerman</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tang</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lubell</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cichonski</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>McCarthy</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <article-title>Cybersecurity framework manufacturing profile / US Department of Commerce, National Institute of Standards and Technology (</article-title>
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>