透過您的圖書館登入
IP:18.191.157.186
  • 期刊

中小企業資訊安全診斷之個案研究

The Diagnostic Service of Information Security of SMEs-Case Study of Taiwan Retailers

摘要


本研究是以個案研究方式比較兩個行業別相近的中小企業規模零售業,參考ISO27001所發行之標準的11個管理領域、39個控制目標、133個控制要點,以模糊德爾菲之專家問卷的統計分析結果排除業務和法令規章無關之控制項目制訂一份以60個控制措施評量的資安檢核表,調查、分析與評估目前企業現有問題與資訊安全管理機制,以讓業主了解如何提升其資訊安全等級,研究過程中該企業提出目前急迫改善的控制項進行資訊安全診斷服務,並比較診斷前後實施改善的成果,提出該企業未來制度面與人員資訊安全能力提升的建議與未來資訊安全系統功能架構改善建議,最後,針對個案的兩個零售業公司的資訊安全觀念及落實推動上,分析其資訊安全各控制措施達成率。

並列摘要


This research takes the method of case study to compare two SME retailers which are similar industries. According to the standards which is contained 11 administrative domains, 39 control objects, and 133 control points bulletined by ISO 27001, an information security checklist is made by 60 control measure assessments that the unrelated controlled items of businesses, laws and regulations are excluded. This checklist is to investigate, analyze and evaluate the enterprises' present problems and information security incident management to let the proprietors to realize how to promote the information security level. During the research process, the research proposes the solutions to improve the controls to process the diagnostic service of information security; and then to compare the results of before and after implementation to propose the suggestions for the future institution of business, the enhancement of information security personnel and the improved structure of future information security system. Finally, for the case, two retail companies, the research will be directed to the concept and implementation of information security and then to analyze the achievement rate of each control measure of information security.

被引用紀錄


李維祚(2017)。以適應性結構化理論觀點探討組織導入ISMS之關鍵成功因素與互補性資產〔碩士論文,淡江大學〕。華藝線上圖書館。https://doi.org/10.6846/TKU.2017.00561

延伸閱讀