透過您的圖書館登入
IP:3.147.73.35
  • 學位論文

ISO 27001認證對於企業績效之影響

The Impact of ISO 27001 Certification on Firm Performance

指導教授 : 許瑋元
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


近來,資訊安全成為了家喻戶曉的重要議題。由於企業及組織對於資訊科技的使用及依賴日益增加,以及資訊安全事件對於組織帶來的負面衝擊愈加嚴重,資訊安全已經成為管理階層最為重要的考量議題之一。另一方面,由於個人對於資訊安全的意識逐漸提昇,企業必須有效提昇其資訊安全的品質以增進消費者信心。然而,隨著資訊科技在組織中的角色轉變,資訊安全已經由單純的技術議題,轉變為企業層級的管理議題。一套建立良好資訊安全管理的有效辦法,是目前企業至為需要的。ISO 27001資訊安全標準提供了一套建立資訊安全管理系統的規範及指引。ISO 27001資訊安全認證更進一步展示了企業在資訊安全方面的規範遵循以及優越性。然而ISO 27001資訊安全認證的成本極高,我們想要了解究竟此認證是否可以作為一個競爭優勢,帶給企業正向的財務方面績效。我們採用了事件研究法,針對美國以及部分歐洲國家的公司進行研究分析。我們發現無論是以財務績效衡量,或者是以股票市場績效衡量,ISO 27001並未對認證公司帶來任何的正面衝擊。我們將這個結果歸因於ISO 27001的本質,即良好的資訊安全管理可能會被視為公司的責任與義務,而非競爭優勢。另一方面,我們發現大部分的樣本公司,其認證都只涵蓋了部分營業單位或廠房設施,而非整體公司的認證。這可能會被視為不盡完善的資訊安全管理規劃。

並列摘要


In the recent years, information security has become a household name and gained enormous public attention. The extensive use and dependence on information technology (IT) of businesses and organizations, along with worsening impact that IT incidents brings has made information security one of the top concerns of the management. Moreover, individual awareness of information security would require corporations to invest and highlight their efforts in securing their handling of information to gain customer confidence. However, the extensive use of IT has made information security a complicated management issue at corporate level. The guidance of an information security management would be urgently in need. ISO 27001 standard provides guidance to a sound information security management system (ISMS). The certification of ISO 27001 further shows compliance and excellence in it. As the costs incurred during the implementation and accreditation are considerable, we would like to discover whether the certification benefits financially by acting as a competitive advantage. We took the event study methodology with samples from United States and selected European countries to investigate the impact after certification. In the results, we have found no evidence that ISO 27001 certification brings positive impact in terms of financial and stock market performance. We attribute the results to the nature of ISO 27001 that a good information security management would bee seen as an obligation, or “meeting the requirements”, instead of a competitive advantage. We also took the scope of the certification as an explanation, where most of the certification only covers part of the organization, instead of a full-scope. This would be seen as a compromised commitment in information security.

並列關鍵字

Information security ISO 27001 ISMS event study

參考文獻


AM Lima, M., Resende, M., & Hasenclever, L. (2000). Quality certification and performance of Brazilian firms: an empirical study. International Journal of Production Economics, 66(2), 143–147.
Ashenden, D. (2008). Information Security management: A human challenge? Information Security Technical Report, 13(4), 195–201.
Barber, B. M., & Lyon, J. D. (1996). Detecting abnormal operating performance: The empirical power and specification of test statistics. Journal of Financial Economics, 41(3), 359–399.
Barber, B. M., & Lyon, J. D. (1997). Detecting long-run abnormal stock returns: The empirical power and specification of test statistics. Journal of Financial Economics, 43(3), 341–372.
Boehmer, W. (2009). Cost-benefit trade-off analysis of an ISMS based on ISO 27001. Availability, Reliability and Security, 2009. ARES’09. International Conference on (pp. 392–399).

延伸閱讀