透過您的圖書館登入
IP:18.225.209.95
  • 學位論文

組織導入BS7799後之資訊安全管理成效研究

The Study of the Effectiveness of Information Security Management after Organizations Implement BS 7799

指導教授 : 黃明達

摘要


在台灣,2006年5月已經有84家組織導入BS7799資訊安全管理系統。近年來,相關的研究都是以探討單一行業、個別領域與個案公司方面為主,目前較缺乏探討各不同行業別、不同領域的組織導入BS7799後,其成效分析之實證研究。因此,本研究探討的就是當ISMS(Information Security Management System)導入組織一段時間後,資訊安全管理上的成效議題,即BS7799導入組織後在資訊安全管理上的成效。 本研究是透過2005年12月底中華民國台灣地區在ISMS國際機構業已註冊,通過BS7799認證的組織共計66家來進行問卷調查。研究BS7799導入後,其不同組織行業別、導入部門範圍別間,資訊安全管理上實施的成效。最後歸納出的結果顯示:1.導入後,74%的組織資訊安全事件有減少;2.各組織的資訊安全控制領域皆有改善,當中以「資訊安全政策」、「營運持續管理」與「實體與環境安全」改善成效較高,「資訊安全政策」領域內的控制措施A5.1.2改善成效最佳;3.「資訊安全事件管理」與「資訊系統取得開發及維護」是改善成效比較偏低的領域,可作爾後組織導入BS7799時的參考。

並列摘要


Eighty four organizations in Taiwan have implementted BS 7799 information security management system in May, 2006. The relative researches in the recent years mostly discuss the topic of one industry field, specific doman or case study. It is lack to investigate in the effectiveness of imple- menting information security management system (ISMS) among the orga- nizations in different fields. This paper focuses on the effectiveness after BS 7799 is implemented into organizations. Based on the survey of the sixty six organizations in Taiwan which have registered in the ISMS international user group, this paper brings us to look into the better and worse domans and controls while implementing BS 7799. The discovery of this paper is as follows: in general, after organizations implement BS 7799, the information security events of seventy four percent- ages in these organizations have decreased. It shows most organiza- tions have improved the environment of information security. Furthermore, the organizations gain improvement in most control objectives, and are remark- ablely secured in “Security policy, business continuity management ,and physical and environmental security.” Implementing A5.1.2 control makes outstanding effecttiveness. Neverthrless, the other outcome shows the lower implementational effectiveness in “information security incident management” and “information systems acquisition, development and maintenance.”

並列關鍵字

BS7799 ISMS

參考文獻


【2】孫淑景,內控處理準則電腦資訊循環之個案研究-BS7799為例,中原大學會計系碩士學位論文,民國九十二年六月,頁1-81。
【14】劉有禮,以BS7799資訊安全管理規範建構組織資訊安全風險管理模式之研究,元智大學工業工程與管理系碩士學位論文,民國九十年,頁1-38。
【18】Chau, Jacqui. “Skimming the Technical and Legal Aspects of BS7799 Can Give a False Sense of Security,” Computer Fraud & Security , Sep. 2005, pp.8.
【22】Peltier, Thomas R. “Risk Analysis and Risk Management,” Information Systems Security, Sep. 2004, pp. 44.
【23】Stephenson, Peter. “Forensic Analysis of Risks in Enterprise Systems.” Law, Investment, and Ethics, Sep. 2004, pp.11.

被引用紀錄


黃慶裕(2011)。探討導入ISMS對組織之影響〔碩士論文,元智大學〕。華藝線上圖書館。https://doi.org/10.6838/YZU.2011.00104

延伸閱讀