透過您的圖書館登入
IP:18.116.13.113
  • 期刊

遵循個人資料保護法下之人力資源系統再造

摘要


個人資料保護法已於民國99年5月26日經總統公布,法務部於民國100年10月27日公布個資法施行細則,全台灣各政府單位及各產業都必須遵循此保護法的規範,企業為避免遭受龐大的罰款與名譽受損,因此必須更加注重資訊安全的重要性;而在企業資訊系統中擁有最多個人資料的系統應屬人力資源系統(Human Resource System, HRS),經查目前市佔率較高的人力資源系統都還存有一些洩漏個人資訊的弱點存在,例如:資料庫欄位未加密、存取筆數未設限和顯示畫面未對敏感性欄位隱藏等。有鑑於此,本文參考現行國內法規以及探討企業內部資訊安全控制,藉由專家學者的協助調查人力資源系統應該做哪些必要調整,透過個案公司之人力資源系統之配合修正,以驗證相關之修改能符合個人資料保護法之要求,降低此法對企業所帶來的相對衝擊,期望能找出低成本的因應方案,正視個人資料保護法帶來的好處,最終能將資料外洩犯罪率降到最低。

並列摘要


Passed by the legislature on October 27, 2010, Taiwan's new Privacy Protection Act will take effect in 2012. By then, all government departments and private sectors around the nation will be subject to the regulation of this protection act. In order to avoid penalties and loss of reputation for violation of the act, all enterprises must pay additional attention to information security. Among the current corporate information systems, human resource systems contain most personal information of a company. A review of dominant human resource systems in the market shows that most of these systems still have some weaknesses that may easily result in personal information leakage, including non-encryption of database columns, no limitation on maximum data access, visibility of sensitive columns, and so on. Therefore, this thesis investigates domestic laws governing information security and internal information security controls commonly used by enterprises. With assistance of experts and scholars, this thesis explores the necessary adjustments of human resource systems for compliance with the Privacy Protection Act. The human resource systems of a case company is used as an example to validate whether these adjustments can make it compliant with the Privacy Protection Act and reduce the relative impacts on the company. Holding a positive view of the benefits of the Privacy Protection Act, this study attempts to find a cost-effective response plan, which can ultimately minimize the crime rate of information leakage.

延伸閱讀