透過您的圖書館登入
IP:3.19.30.232
  • 期刊
  • OpenAccess

企業導入雲端服務專案之風險評估

Risk Assessment of Cloud Services Project for Enterprises

摘要


雲端運算給資訊科技產業帶來商機,但亦帶來重大的挑戰。客戶願意採用雲端服務的前題是須確保客戶資訊安全。近期發生的網路進階持續性滲透攻擊(advancedpersistent threat,APT)已導致客戶對導入雲端服務產生心理障礙。針對導入雲端服務所面臨的潛在風險問題,本研究提出一套風險評估方法,參考雲端安全聯盟(cloudsecurity alliance,CSA)與歐洲網路與資訊安全局(European network and informationsecurity agency,ENISA)所提出的雲端服務之資訊安全架構,已決定導入雲端服務之風險項目,利用模糊層級分析法(fuzzy analytic hierarchy process,FAHP)合理評估與分析雲端服務之風險項目優先順序。所研提的方法與案例分析,有助於企業了解轉移應用程式至雲端服務的風險項目及控管優先順序,以利決定資安資源分配及降低系統導入後之潛在衝擊。

並列摘要


Cloud computing presents the IT industry not only with exciting opportunities, but also with significant challenges since consumers are reluctant to adopt cloud computing solutions in the absence of firm guarantees regarding the security of their information. Network attacks such as APT attacks present a serious obstacle to consumer acceptance of cloud service project nowadays. Accordingly, the present study proposes a project risk assessment scheme and constructs a risk evaluation matrix based on the security framework followed by both Cloud Security Alliance (CSA) and European Network and Information Security Agency (ENISA). In addition, the risk priorities of attributes are rationally evaluated by fuzzy analytic hierarchy process (FAHP) method in the risk assessment process. Overall, the results confirm that the proposed method provides an effective means of recognizing the risk attributes and their risk priorities, deciding the allocation of risk budget, and reducing the impact of potential risk for enterprises.

參考文獻


Wright, M.,Filatotchev, I.,Hoskisson, R. E.,Pen, M. W.(2005).Strategy research in emerging economies: Challenging the conventional wisdom.Journal of Management Studies.42(1),1-33.
國際商業機器股份有限公司(2010),IBM觀點:安全與雲端運算,國際商業機器股份有限公司網站,Retrieved February 17, 2012, 取自: https://www14.software.ibm.com/webapp/iwm/web/signup.do?source=swg-TW_DP_SW&S_PKG=wp_securitycloudcomputing
王平、林文暉、郭溥村、王子夏、盧永翔(2010)。雲端運算服務之資安風險與挑戰。資訊安全通訊。16(4),45-65。
彭秀琴、張念慈(2010),雲端運算下資訊安全之探討,經建會管制考核處,Retrieved February 17, 2012,取自:http://www.cepd.gov.tw/dn.aspx?uid=9857。
黃富祿、張力允、李仁鐘、周碩聰(2010)。組織導入雲端運算之資安管理評估。資訊安全通訊。16(4),66-83。

被引用紀錄


周宗麟(2015)。企業營業秘密外洩資安事件之防範機制 —以N公司EIM導入個案為例〔碩士論文,國立臺灣大學〕。華藝線上圖書館。https://doi.org/10.6342/NTU.2015.00521
黃亷鈞(2013)。以Fuzzy AHP建立國軍資訊安全管理系統風險評估準則〔碩士論文,國立中正大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201613570176

延伸閱讀