透過您的圖書館登入
IP:3.144.205.223
  • 學位論文

以BS 10012為基礎評估組織導入個人資訊管理制度之研究

A Study of Introducing Organizational Personal Information Management System Based on BS 10012

指導教授 : 黃明達

摘要


台灣刑事警察局2009年165反詐騙專線統計指出,網路購物個人資料(或簡稱個資)外洩詐騙事件排名第一,佔全部詐騙數35%,顯示個資外洩情形嚴重。在個人資料保護法三讀通過後,組織一旦違法使用個資,將面臨高價求償金、刑責等問題,組織可能需開始著手規劃並實施針對個人資料的相關保護工作,降低個資法帶來的衝擊。 本研究以問卷調查方式,分析各組織個人資料保護現況。發現商譽受損是最多組織擔憂若不慎洩漏個資時的衝擊,但中小企業與非營利事業對於須自行舉證組織並無故意或過失洩漏個資的困擾更甚於商譽受損。本研究以BS 10012為基礎之「規劃」、「實行與運作」、「監督與審查」、「改善」等四構面,評估組織的個人資訊管理制度(Personal Information Management System, PIMS)狀況,提供十種組織可優先加強構面之建議,如資訊服務業、金融業等組織在「規劃」構面、政府部門等在「實行與運作」構面、非營利組織等在「監督與審查」構面與電信業等在「改善」構面,建議強化個人資訊管理制度上的不足,使組織降低個資法將帶來的衝擊。

並列摘要


In 2009, the Criminal Investigation Bureau 165 anti-fraud hotline statistics indicated that internet shopping frauds due to leakage of personal information were ranked first, accounting for 35% of frauds. This indicates that personal information leakage is a serious problem. After third reading of the Personal Information Protection Act passed, if an organization uses personal information illegally, it will face high claims payments, criminal liability and other issues. To reduce the impact from the Personal Information Protection Act, organizations may need to begin to plan and implement relevant measures for the protection of personal information. This study used the a questionnaire survey to analyze the status of personal information protection in organizations. Goodwill impairment is found in most organizations which are concerned about the impact of accidental personal information leakage. However small and medium-sized enterprises and non-profit organizations are concerned about being required to prove that they have no intention or negligence related to personal information leakage problems than organization goodwill impairment. We assess an organizational personal information management system based on the four phases of BS 10012, “Plan", "Do", "Check", "Act”. Through this analysis, we provide priority strengthen phase advices for 10 organizations, For instance, the “information services industry” and “financial services industry” are in the "plan" phase, “government departments” are in the "Do" phase, “non-profit organizations” are in the "Check" phase, and the “telecommunications industry” is in the "Act" phase. Strengthening personal information management system will enable organizations to reduce the impact of the Personal Information Protection Act.

參考文獻


[7] 翁清坤,〈論個人資料保護標準之全球化〉,東吳法律學報,第二十二期,頁1-60,2010年7月。
[11] 蒲樹盛,〈創新科技環境下的資訊管理重點雲端資訊安全、個資隱私保護、營運持續服務〉,中華民國品質學會月刊,第46卷,第7期,頁22-25,2010年7月。
[6] 李振瑋、江耀國,〈英國資料保護法中資料所有人權力之研究─兼論我國個資法之相關規範及案例〉,中原財經法學報,第二十四期,頁29-84,2010年6月。
[14] BS 10012, Data Protection - Specification for a Personal Information Management System, British Standards Institution, 2009.
[15] BSI Group, Data Dilemma: One in Five Businesses Admit Breaching the Data Protection Act. http://www.bsigroup.com/About-BSI/ News-Room/BSI-News-Content/Disciplines/Information-Management/BS-10012-publication/, accessed 2011/1/14.

被引用紀錄


杜恩君(2015)。BS 10012導入經驗之研究─以淡江大學為例〔碩士論文,淡江大學〕。華藝線上圖書館。https://doi.org/10.6846/TKU.2015.00859
陳俊谷(2015)。個人資料檔案風險評鑑威脅與弱點項目之研究〔碩士論文,淡江大學〕。華藝線上圖書館。https://doi.org/10.6846/TKU.2015.00634
林淑儀(2014)。臺灣推動個人資料保護與管理制度(TPIPAS)之研究〔碩士論文,淡江大學〕。華藝線上圖書館。https://doi.org/10.6846/TKU.2014.00899
張天宇(2012)。以PMBOK®方法論探討BS 10012個資管理制度專案規劃〔碩士論文,國立交通大學〕。華藝線上圖書館。https://doi.org/10.6842/NCTU.2012.00391
鄭伊雯(2012)。植基於ISO 27001建立符合BS 10012之個人資訊管理自我評鑑模式〔碩士論文,中原大學〕。華藝線上圖書館。https://doi.org/10.6840/cycu201200358

延伸閱讀