透過您的圖書館登入
IP:3.21.93.44
  • 學位論文

電子商務型企業資訊風險與內控管理機制之研究

Research on Information Risk and Internal Control Management Mechanism of E-commerce Enterprises

指導教授 : 郭瑞祥
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


近年來,隨著資訊科技環境不斷的變化,加上網路應用的普及與快速發展下,經濟、社會都起了結構性的轉變。在電子商務、社群商務或線上、線下消費行為上,都有了顯著的改變,雖然這為企業創造了許多新的商業機會與商業模式,但同時也為企業帶來了比以往更快速、更不可預測、更充滿不確定性的風險與威脅。就現今的企業經營發展而言,企業組織面臨的資訊風險與資訊安全挑戰已日漸嚴峻,添加了更多不確定性與複雜性的變數、帶來了更多的危機。尤其在資訊安全、隱私保護與數位犯罪形態上等議題,已嚴然成為當今企業組織首要面對的關鍵課題。而企業組織對營運的資訊風險偵知與管理,更需一個明確且務實的資訊風控策略與安管機制來回應,尤其對從事虛實整合的企業,更是尤為重要。 本研究目的為發展企業資訊的內控、稽核與風險管理機制,以保障企業經營與資訊風險於可控範圍內。企業因資訊環境的進步,複雜度不斷提昇,資訊系統的風險控制與稽核需求也與日俱增,對數據資料的準確性和資訊風險的控制,直、間接影響企業財務報表資訊的準確性與可靠性,更被企業視為之首要。因此,企業的管理者需隨時注意環繞在企業外部或潛藏在組織內部之風險,建立完整的資訊危機、偵防、預警、稽核、管控的機制與制度以應對之。此研究希望藉由探討有關資訊風險、內控管理與策略規劃等文獻,配合實務,提出符合企業資訊內控與資訊安全領域應用之策略規劃與模式,結合個案實例,以驗證本研究所提出的資訊內控、策略規劃與建構流程之可行性與適宜性。 本研究除採用文獻探討方式外,另彙整專家意見,強調專家審計觀點,配合資訊技術審計和風險控制模型,依資訊風險類型區分為內、外部資訊風險,建立資訊風險壓力構面,分析資訊風險結果,發展資訊內控、資訊安全稽核的流程與方法,以規劃出適用企業資訊內控與資訊安全性原則的可執行方案。並透過個案研究方式,探討個案公司在面對複雜的資訊內控、安全等議題時,如何依循研究流程架構中提出的資訊內控及資訊安全性原則規劃建構流程,找出最佳資訊風險管理的內部優先措施,以進行企業內資訊內控與資訊安全性原則的規劃與實施,以驗證資訊風險控制與管理之適用性,幫助企業進行實際應用建構之結構來確保資訊風險管理的有效性。 隨著資訊風險與資訊安全威脅的與日俱增,企業組織必須有可遵循的方法論,才能快速適宜的規劃出資訊內控與資訊安全性原則以應對。本研究的具體貢獻在針對電子商務、社群商務、線上消費或數位交易為主體的環境下,以資訊系統內部控制規範為基礎,歸納與分析過去文獻,以構建出資訊系統內部控制、資訊安全架構與資訊風險評估機制,透過個案實證機制的實用性,讓企業能夠精準地進行資訊系統的內部控制,同時評估內控機制的績效,以驗證所產出的稽核機制被運用在企業內部控制稽核上的可行性。研究成果可為學術界強化研究知識,或為後續研究者或實務界在互聯網或以數位交易為主體的環境下,實施企業風險管理,內部控制稽核與進行資訊安全性原則規劃時參考。

並列摘要


In recent years, information technology has been continuously changing. With the popularity and rapid development of mobile applications, the economy and society have undergone structural changes. The significant changes in e-commerce, community commerce, or online/offline consumer behaviors, which create new business opportunities and business models for many companies, but also brought more unpredictable risks or threats of uncertainty to the company. In terms of business development, information technology risks and information security challenges have become more and more serious, adding even more uncertainty, complexity, and crises to the company. Especially on information security and privacy protection issues such as digital fraud or crime have become the key issues that businesses headache today. Therefore, the business urgently needs detection of information risk, a strategy of information control, and information security management mechanism to deal with it, especially for enterprises engaged in online/offline integration. The purpose of this research is to develop an internal control, audit, and risk management mechanisms for corporate, to ensure that the operations and information risks are within control. Due to the information technology fast-growing, the complexity, risk control, and the need for auditing of information systems are increasing. The data accuracy and the information risks control, directly or indirectly, affect the accuracy and reliability of financial statements, and this considered as the top priority of the enterprise. Therefore, the business management level needs to pay attention to the risks where surrounding enterprise externally or internally to establish a complete mechanism for information system control, such as crisis detection, prevention, warning, audit, and control to deal with it. The hope for this research is to study relevant articles in information security, risk management, and strategic planning to cooperate with practice to propose strategic planning and models that are consistent with the application of corporate information internal control and information security fields. And also combine with a case study to verify the research proposal feasibility and suitability. In addition to literature, research summarizes expertise opinion and information system auditing perspectives to cooperates with information technology audits and risk control models. Distinguish internal and external information risk to establish an information risk pressure factor. Analyze information risk results, to develop a process or method of information internal control and information security audit to plan a suitable solution for enterprise information, internal control, and information security strategy. Through the case study, to discussing the information internal control and security issues, and how to follow the strategic plan and the process to measure priority and implementation to the company to verify the applicability and effectiveness of information risk control and security management. With the increase of information security risk and threat, organizations must have a methodology to follow and an appropriate plan for information internal control and information security strategies to respond. The contribution of this research is to summarize and analyze the past literature based on information system internal control and targeted at e-commerce or community commerce or digitized transactions environment. Through the information security architecture and information risk assessment mechanism, the case study allows the company to carry out internal control of the information system accurately, and to evaluate the performance of the control mechanism and also verify the result in the audit. The research results can be used for academic research to strengthen research knowledge or for follow-up researchers or practical in risk management, internal control audit, or information security strategy planning under the Internet or digital transaction as the core environment enterprise.

參考文獻


一、中文部份
[1] 方至民 (2015) ,策略管理 建立企業永續競爭力,前程文化事業出版,2015/06/09。
[2] 司徒達賢,策略管理,遠流出版,1996/01/29。
[3] 李坤清、蔡旭升、沈正玔、柯志偉 (2012) 。MIS 面對 IFRS 導入之因應對策。
[4] 邱義城,策略聖經,商周出版,1997/09/01。

延伸閱讀