透過您的圖書館登入
IP:3.145.94.251
  • 期刊

組織導入資訊安全管理制度之效益探討

Effectiveness Appraisal of Implementing an Information Security Management System in Organizations

摘要


本研究藉由訪談及問卷蒐集資料,以敍述統計、變異數及迴歸分析,探討導入Information Security Management System(ISMS)對組織的影響。研究發現,導入ISMS遭遇困難程度較高者為:增加額外的工作量、人力不足,以及資安成員缺乏足夠的權力。導入ISMS獲取效益程度較高者為:提升組織對維護資訊安全之聲譽、提升政府部門整體服務價值、建立標準化及文件化之資安作業流程,以及提升組織成員的資安標準認知及資安職能。導入ISMS的成功關鍵因素程度較高者為:高階主管的支持與承諾、具有資安職能之專案人員、資訊安全團隊的積極推動,以及持續的資安宣導和訓練。導入ISMS是一項管理制度的建立,組織應掌握成功關鍵因素並降低遭遇的阻力,以獲取最大效益;導入後,仍應秉持PDCA(Plan, Do, Check, Act)的精神,持續對ISMS改善與精進,使組織的資訊安全更臻完備。

關鍵字

ISO 27001 ISMS 資訊安全 PDCA

並列摘要


By using descriptive statistics, ANOVA and regression analysis approach, we examined the organizational impact when implementing ISMS. The top three types of difficulties for implementing ISMS are increased workload, Shortage of manpower and Lack of proper authority for information security team. The top four benefits for implementing ISMS are found to be: Gain reputation for enhancing information security, Raise value of governmental services, Establish standardized and documented information security processes, and Raise information security awareness and capabilities of organization staff. The top four critical success factors for implementing ISMS are shown as: Top management support and commitment, Project team members with information security capabilities, Proactive push by information security team, and On-going information security advocacy and training. Embarking on ISMS is one key step in enterprise management; therefore, enterprises should control the critical successful factors and minimize the possible difficulties in order to realize more benefits. To attain more complete information security, carrying out PDCA (Plan, Do, Check, Act) and improving ISMS will be the main factors.

參考文獻


王保進(2010)。導入品質保證內涵與重視學生學習成效之大學校務評鑑。評鑑雙月刊。24,54-58。
行政院科技顧問組(2010)。2010資通安全政策白皮書。臺北:行政院。
李東宜(2010)。2010年政府機構資通安全執行概況調查。政府機關資訊通報。271,15-20。
徐正(2006)。組織導入BS7799後之資訊安全管理成效研究(碩士論文)。淡江大學資訊管理學系碩士班。
莊煥銘、韓富州()。

被引用紀錄


王偉全(2013)。以本體論為基礎之資訊安全文件管理系統的開發與建置-以某國軍單位為個案實證分析對象〔碩士論文,國立屏東科技大學〕。華藝線上圖書館。https://doi.org/10.6346/NPUST.2013.00087
翁加偉(2014)。個資法施行後對組織之衝擊與因應-以S大學為例〔碩士論文,國立中央大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0031-0412201511590247

延伸閱讀