透過您的圖書館登入
IP:3.144.167.151
  • 期刊

ISMS驗證合規初論:根基於管理系統驗證機構資通安全管理法驗證方案特定要求

A Preliminary Discussion on ISMS Certification Compliance: Based on the Specific Requirements of the Cybersecurity Management Law under the Management System Certification Bodies

摘要


隨著政府機關對資通安全的重視,我國整體資安防護體系之建立與資安防護能力之提升已見初步成效;2022年5月1日,全國認證基金會(Taiwan Accreditation Foundation, TAF)已實施於2022年4月頒佈的《管理系統驗證機構資通安全管理法驗證方案特定要求》(備考:ISO/IEC 27002: 2022(E)第5. 1節(ISO/IEC 27001:2022(E)第A. 1節)已規範之),開展我國資訊安全管理系統(Information Security Management Systems, ISMS)實作及其驗證的新頁。根基於此,本文期以前述ISMS驗證之緣由及國家資通訊安全發展方案(110年至113年)」中「建立資通系統弱點之主動發掘、通報及修補機制」與「完善政府網際服務網防禦深廣度」之工作項目中的資安弱點通報機制(Vulnerability Alert and Notification System, VANS)及零信任網路(Zero Trust Network, 簡稱ZTN)之實作,探討ISMS驗證合規的實然與應然。

並列摘要


With the government's emphasis on cybersecurity, the establishment and capabilities of national overall information security protection system have achieved initial results. The Taiwan Accreditation Foundation (TAF) has implemented the "specific requirements for the management system verification bodies on verification schemes of Cybersecurity Management Act" issued on April 2022 (for reference, see: Section 5. 1 of ISO/IEC 27002: 2022 (E) (this is specified in ISO/IEC 27001: 2022(E) Section A. 1) on May 1, 2022. The act has opened a new page on the implementation and verification of national Information Security Management Systems (ISMS). Regarding this topic, we discuss the necessity and reality of ISMS certification compliance in this paper. Besides illustrating the above narrative of verification of ISMS in our country, we also deliberate the implementations of Vulnerability Alert and Notification System (VANS) and Zero Trust Network (ZTN) in the work of " establishing an active discovery, notification, and repair mechanism for information system vulnerabilities" and " improving the defense depth and breadth of the government Internet service network" in the National Communication Information Security Development Plan.

參考文獻


Souppaya, Murugiah, John Morello, Karen Scarfone (2017). Application Container Security Guide. NIST Special Publication 800-190, doi: 10. 6028/NIST.SP. 800-190.
Sultan, S., I. Ahmad and T. Dimitriou (2019). Container Security: Issues, Challenges, and the Road Ahead. In IEEE Access, vol. 7, pp. 52976- 52996, 2019, doi: 10. 1109/ACCESS.2019.2911732
中國信息通信研究院雲計算與大數據研究所 (2021)。《數位化時代零信任安全藍皮報告 (2021 年 )》。
中華民國資訊軟體協會 (2012)。「行政院完備我國資訊安全管理法規之分析 」委託研究計畫,期中報告 (初稿 ),101/ 08/ 17。
仉桂美、劉德勳與包宗和 (2021)。109教調 0004(監察院調查報告),110/06/04。

延伸閱讀