資訊科技的快速發展與網路的普及,造成企業組織所面臨的資訊安全挑戰更加日趨嚴峻。資訊安全對於企業組織的營運而言,不僅只是一個充滿不確定性的風險威脅,同時也是個無法迴避的關鍵課題,而許多新形態的數位犯罪與隱私權保護議題,更是需要有明確務實的資安策略以作為回應。 而本研究的主要目的,是希望藉由探討國內外有關資安與策略規劃之相關的文獻,與研究者本身多年的資安實務經驗,嘗試在本研究中提出,符合資安領域應用之企業資安策略規劃模式,並以個案A公司為實例,來驗證本研究所提出的資安策略規劃建構流程之適宜性與可行性。 在本研究中,將透過個案研究的方式,探討個案A公司在面對眾多複雜的資安議題挑戰中,如何依循參考在本研究流程架構中所提出的資安策略規劃建構流程,以進行企業資安策略的規劃與發展,這其中同時整合了本研究所提出之企業組織中的三個重要支柱,包含人員(People)、流程制度(Process)與科技技術(Technology)。並以本研究所進一步提出的「現況風險分析」模式(TW-PPT),找出對該公司最重要的關鍵資安問題與確切需求。同時在其企業資源與能力有限的條件下,運用本研究所提出的「因應策略規劃」模式(O-PPT),規劃發展出適宜可行的企業資安策略及行動方案。 今日資訊安全威脅的危害程度,已凌駕在科技應用的發展之上,企業組織必須要有方法得以規劃適宜的資安策略以應對之,才能確保日常營運的正常與發展。但是到目前為止,卻少有人進行這方面的真正探討或研究,尤其是關於資安策略規劃的文獻與實證研究的方法更是付之闕如。因此本研究的探討與結果,將可做為學術界後續者研究與實務界進行資安策略規劃時的參考。
The rapid development of information technology and the popularity of the Internet have made the information security become a company or enterprise’s more and more serious challenges. The Information security is not only a risk that threat full of uncertainty for the operation of enterprise organizations, but also a key concern which cannot be avoided or ignored. Many new forms or new types of digital crime and privacy protection issues gradually emerged which require a clear and pragmatic security strategy in response. The main purpose of this study is to explore domestic and foreign related information security strategic and planning literatures, with the researcher's many years of information security implementation and practice experience to try to propose an “Information Security Strategy Planning” model in the application field. And use the case A company as an example to verify the suitability and feasibility when establish information security strategy planning model and processes flow. Through the case study, where discussed how the A Company is facing the challenges of many complex security issues, and how to follow the reference to the information security strategy planning establish process proposed in this research process framework. The planning and development of the security strategy, which integrates three important elements of the organization proposed by the researcher, which including “People”, “Process” and “Technology”. Based on the “current risk analysis” model (TW-PPT), which is further proposed by the researcher, where identify the most important key security issues and exact needs for the company. At the same time, under the condition that its enterprise resources and capabilities are limited, the “Development Strategy Planning” model (O-PPT) proposed by the researcher is used to plan and develop suitable and feasible enterprise security strategies and action plans. The degree of harm of information security threats today is above the development of technology applications. Organizations must have the means to plan appropriate information security strategies to cope with them in order to ensure the normal operation and development of daily operations. But so far, only few people have actually conducted any real discussion or research in this area, especially the literature and empirical research methods of the strategic planning of the information security. Therefore, the research and results of this study will serve as a reference for the academic and follow-up research and practice community in the strategic planning of security.