近年來網際網路的發達,導入資訊技術以提昇組織效率與競爭力已經是全球的趨勢。而在近年來全球資訊安全事件不斷發生,資訊犯罪手法不斷翻新,為保護組織內部相關資訊資產之安全,並保持組織持續運作,如何導入適當的資訊安全管理機制已經是許多企業的共同需求。國際標準組織(ISO)因應這類需求而制訂了ISO/IEC 27001資訊安全管理系統(Information Security Management System,ISMS),以此標準來管理組織內部資訊的運用、資訊設備的安全以及資訊使用者的控管,以達成資訊資產的「機密性」、「完整性」及「可用性」。 前述這三種基本特性鼎足而立,不可偏廢。然而這三者之間具有潛在的互斥關係。當機密性被強調的時候,就可能會降低資訊的可用性及完整性,因此本研究主要在探討企業導入資訊安全控制措施是否會對現行專案績效產生影響,並探討讓 ISMS 有效運作的成功關鍵因素,以及推動過程中最容易遭遇的問題與困難。 本研究採用質性研究的訪談法,依據ISO/IEC 27001資訊安全管理系統所要求的管制措施,訪問三家已經通過ISO27001認證的公司。然後採用內容分析法來分析訪談逐字稿,運用三角檢定法來確保本研究的信度及效度,並產生結論命題。 本研究結果發現(1)對於軟體專案績效最有負面影響的主要管制措施為「變更控制程序」、「作業系統變更後的應用系統技術審查」;(2) 讓ISMS有效運作的關鍵成功因素,主要為高階主管的全力支持與承諾、全體員工的參與及共識;(3) 導入ISMS最常遭遇的問題與困難,主要為推動小組成員對於導入標準的熟悉度不夠。 最後,本研究針對前述發現所隱含的管理意涵進行討論,本研究成果將可提供企業在實施資訊安全管制措施時的重要參考借鏡。
As the internet develops in recent years, integrating information technology to elevate organizational performance and competitiveness has become a global trend. However, as the information security has been constantly under attack and the information crime has frequently taken a new form, how to establish an appropriate information security management system in order to protect the organizational information properties and maintain the processes of organizations for business continuity has become the need of many corporations. In responding to this need, the international standard of ISO/IEC 27001 Information Security Management System (ISMS) has been developed and published by the International Organization for Standardization (ISO). Based on ISO/IEC 27001, a corporation could manage the use of organizational information properties, the security of information equipment and the access control of users, which then ensures the confidentiality, integrity, and availability of information property. Those three characteristics mentioned above are equally important and none of them is negligible. Nonetheless, there is a potential conflicting relationship among those three characteristics. While confidentiality is increased, then availability and integrity might decrease. Thus this study aims to investigate the influence of ISMS controls on software project performance, to examine the critical successful factors for ISMS implementation, and to explore the common problems and difficulties in the ISMS implementation processes. This study adopts a qualitative research method — interviewing. Three companies, which have achieve ISO 27001 certification, have been investigated according to the ISMS controls of ISO/ISE 27001 in this study. Content Analysis is adopted to analyze transcripts, triangulation is adopted to ensure the reliability and validity of this study and leading to the conclusions. The findings show that: (1) among the ISMS controls, “change control process” and “technical review of applications after operating system changes” have the most distinctive negative influence on the software project performance; (2) the major critical successful factors of ISMS implementation are the full support and commitment from top management, and the participation and consensus of all the staff; (3) the most common problems and difficulties of ISMS implementation are lack of familiarity with ISMS standards among promote group members. Finally, implications of the findings listed above are discussed. The findings of this study would provide an important reference for corporations in their future practices of ISMS implementation.