透過您的圖書館登入
IP:13.58.197.26
  • 學位論文

專案成員的認知對於IT專案實施之影響: 以資安軟體公司執行JSOX為例之個案研究

Interpreting the IT Project Implementation Process:A Case Study on Information Security Software Corporation’s JSOX Implementation

指導教授 : 許瑋元

摘要


在早期,當一家公司嘗試著去實施一個大型的資訊系統相關的專案,多數專案的實施關鍵在於新技術的成熟度與公司對於此種技術的專業導入能力。是以能夠找到有技術與經驗的開發人員,一般說來,就已經成功了一半。但是近年來,由於網際網路的發達,網路程式的多功能化與越來越少新的程式技術會影響到公司專案執行並造成問題。技術障礙的因素越來越不是問題,取而代之的是企業運作流程的日新月異。為了融入變化趨大的市場與企業環境,如何溝通訂出一個最有效率的系統流程,變成了專案成功的關鍵因素。 此篇論文針對一家在世界同業的佔有率領先公司之一的資訊安全軟體與服務公司,由於這家公司在近年內因為日本政府的法令改變,必須實施公司資訊相關的專案以符合日本證管會的要求,此法令被通稱為JSOX以呼應美國沙賓法案(SOX)的法令。由於個案所述的公司的競爭優勢在於公司的專業技術能力與對於新科技的快速導入能力,所以當JSOX實施的需求發生之初,所需規劃的制式流程與層層管控的核可制度,多少被認為違背了公司長久以來的主要優勢與公司文化。 無論如何,法令勢必得遵守,公司於是成立一個專案小組負責這一個法令相關的資訊專案,期待盡可能的通過法規的查核。然而,在過去連續兩年的專案實施成果卻是成功的,連續兩年通過了外部稽核單位的考核。為了瞭解這個專案小組成功的原因,依此發現一些有用與有效的結論,可以提供其他相似專案實施的建議,以個案研究的方式,有邏輯的找出有價值與有趣的特點來解釋其成功的緣由。 在此研究實施的過程當中,我們將探討JSOX的由來與其歷史因素、相關的機構認證的需求、組織行為與個人行為的連結要素、科技框架理論與方法與質性研究與訪談的工具介紹。透過訪談以得到此研究所想要得到的資料與其架構。最後,根據分析與個人的工作經驗,提供有價值的發現、分析與建議。

並列摘要


For a corporation to implement an IT project, in general, had been treated as a “technology” deployment. During the recent years, due to the technology has become more standardized and less additional new technology needed, the business process has become more and more impor-tant to introduce a successful project. This thesis is base on a business case of a leading security software corporation to deliver an IT JSOX compliance project which is newly announced by Japan government to enforce the pub-lic companies which are listed in Japan stock exchange market. According to the nature of this company are a technology leading corporation which might need to closely chase the fast pace technology in the world in order to sustain its leading position. Once the company needs to adopt the JSOX requirements, it introduces the necessities of standard processes and tight approval processes which somehow violate the core culture of this company. However, this is a legal requirements to comply; therefore, there is a specific project team has been formed and successfully passed auditing for 2 successive years. In order to understand how the project team has been successful to give an analysis to generate the valuable key factors for other similar corporation which might have similar type of projects to implement for refer-ences, this research using the technological frame theory model to identify the indicators by giv-ing interviewing with several key members of this project team and try to find out something in-teresting and valuable findings and suggestions. Along with the research, we shall look into how and why the JSOX compliance been formed; key compliance framework in the IT industry that are also perform the similar approach-ing; the key factors and relationship of the organization behavior and personal behavior; also the theory of technological frame’s methodology. Base on the reference theories and frameworks; try to build up the linkage between the case itself with and gathering the finding in between. Also, base on the theories described, through the semi-constructed interviewing methodology to give individual interviewing with several key members of the JSOX project team of the company to come out the basis of this research. Finally, base on the findings have been generated from this research, also my past experience on the implementation of IT projects, summarize the key factors of the success of the im-plementation of the project described and also give the additional suggestions for further imple-mentation, hope to give a full set of reference items for a company who might have the same sit-uation and needs to deploy the compliance-like IT projects. Hopefully, from the planning till full implementation life cycle, the result can help this kind of enterprise to have a better provision to the potential situation they will need to face to.

並列關鍵字

SOX JSOX Compliance Information Security Corporate Governance Frame Theory CMMI ISO27001 COBIT COSO Enron MCI WorldCom

參考文獻


4. 質性研究訪談模式 - 質性研究方法 P122~P136:訪談模式與實施步驟分析 (林金定、嚴嘉楓、陳美花)
5. 台灣大學資訊管理研究所,碩士論文,校園組織成員對於資訊安全管理之認知研究,林建宇,P23~P26,科技框架(Technological Frame)的意義
8. 簡報: 訪談研究 ,陳繁興,國立彰化師範大學技術及職業教育學院
17. COSO Enterprise Risk Management – Understanding the New ERM Framework, Robert R. Moeller
28. Organization Behavior Theories - Organization Behavior,13th Edition,Robbins/Judge,Pearson Education

延伸閱讀