Abstract
This paper aims to verify impacts of information security investment based on Japanese firm level data. First, the empirical analysis shows impacts of some security measures including information security policy on computer virus attack. Second, the author introduces the concept of intangible assets into information security investment and verifies the complementarity between tangible and intangible assets. The result suggests that the complementarity might work in information security investment.