在當前地緣政治和國際緊張局勢日益加劇的背景下,全球資訊安全風險逐步上升,對資訊安全的需求愈加迫切。在此情況下,美國於2019年發布了網絡安全成熟度模型認證(CMMC),旨在強化國防供應鏈的網路安全,並將此標準納入供應商評估過程中。該政策不僅影響美國企業,也對赴美設廠的全球企業產生深遠影響。面對日益緊張的國際形勢,台灣政府計畫引進CMMC認證,以加強國防供應鏈的資訊安全。當前,ISO 27001作為台灣廣泛採用的資訊安全管理主要標準,為許多企業提供了一套完整的資訊安全框架。因此,如何在ISO 27001標準架構下提前準備導入CMMC,已成為台灣企業需要重視的問題。 本研究透過文獻整理,匹配CMMC與ISO 27001相關的控制措施及CMMC官方文件建議的檢查項目,並輔以專家訪談蒐集專家對此匹配結果的意見,以了解目前台灣業界對於CMMC標準導入的看法。根據訪談結果與相關文獻統整後,研擬一份自評表。初步研擬自評表後,進行第二次專家訪談,驗證自評表是否能夠作為提高台灣企業合規CMMC認證準備度的工具,並收集專家對自評表後續修正的建議,作為未來CMMC自評表建構的參考依據。研究結果提供了實務評估中兩項標準之對應參照及重點檢查項目評估的自評表,並為後續研究CMMC自評表的製作及CMMC評估流程的步驟提供建議。
In the context of heightened geopolitical and international tensions, global information security risks are increasing, necessitating urgent enhancements in security measures. In 2019, the United States introduced the Cybersecurity Maturity Model Certification (CMMC) to bolster network security within the defense supply chain and integrated this standard into the supplier evaluation process, significantly impacting both American and global businesses operating in the U.S. As international tensions continue to escalate, the Taiwanese government plans to adopt the CMMC certification to strengthen its defense supply chain's information security. Currently, ISO 27001 serves as the primary standard for information security management in Taiwan, providing a comprehensive security framework for numerous businesses. Thus, effectively integrating CMMC within the ISO 27001 framework is a crucial issue for Taiwanese enterprises. This study aims to align CMMC with ISO 27001 by reviewing literature on related control measures and selecting check items recommended in official CMMC documentation, complemented by expert interviews to validate and suggest improvements for this alignment. The interviews and literature review help understand the Taiwanese industry's perspective on adopting the CMMC standard. A self-assessment checklist is drafted based on the interview outcomes and literature synthesis to ensure closer alignment with CMMC standards. A second round of expert interviews will assess whether this checklist can serve as a tool to enhance Taiwanese enterprises' readiness for CMMC certification and propose necessary modifications. The results offer a practical assessment tool comparing both standards and provide a self-assessment checklist for evaluating key check items, aiding in the development and implementation of future CMMC self-assessments.