透過您的圖書館登入
IP:3.134.78.106
  • 學位論文

金融服務業導入資訊安全管理機制影響之研究

The Influence of Applying Information System Security for the Financial

指導教授 : 吳忠敏
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


金融服務業高度倚賴資訊科技達成其營運需求, 引發對於資訊安全管理議題之重視,本研究針對金融服務業間導入與未導入資訊安全管理機制對資訊安全衝擊影響之差異比較。 本研究採問卷調查方式,並輔以企業深度訪談進行,歸納出之結果如下。 1. 金融服務業導入資訊安全管理機制關鍵因素以資訊安全政策、網路安全管理、使用者存取管理、作業系統存取控制、應用系統之存取控制最具成效。 2. 發生資訊安全事件前五項為主:病毒、濫用內部網路/電子郵件、電力中斷、濫用即時通訊軟體、未經授權取存;導入資訊安全管理機制之單位發生機率及影響衝擊程度皆較未導入較低。 3. 已導入企業於資訊安全異常事件之因應及對資訊安全之幫助皆較未導入企業為佳。

並列摘要


Financial service industry highly relies the information technology to achieve its business demand, initiates value of regarding the information security management subject, this research inducts in view of the financial service industry with has not inducted the information security management to compare to difference of the information security management impact influence This research picks the questionnaire survey way, and auxiliary carries on by enterprise depth interview, induces the result to be as follows: 1. Financial service industry inducts the information security management machine-made key aspect by the information security policy, the network safety control, the user access control, Operation system control application system control 2. Has the information security event first five items primarily: The virus, abuses internal network/email, electric power severance, abuses the immediate communication software, without authorization access; Inducts unit of the information safety control mechanism to have the probability and the influence impact degree comparatively has not all inducted lowly。 3. The organization who has implement ISMS, when fact to information security event is better then do not implement’s organization.

參考文獻


16. 孫淑景,內控處理準則電腦資訊循環之個案研究-BS7799 為例,中原大學會計系碩士學位論文,P1-81、2003。
30. Austin, Robert D. and Darby ,Christopher A.R. 81:6 “The Myth of Secure Computing” Harvard Business Review , P120-p126,2003。
31. BS 7799 ISO/IEC 17799-1:2005,Information Technology -Code of practice for information security management,2005。
32. BS 7799 ISO/IEC 27001-2:2005,Information security management systems -Specification with guidance for use,2005。
33. Chau, Jacqui.,Skimming the Technical and Legal Aspects of BS7799 CanGive a False Sense of Security, Computer Fraud & Security, p8. ,2005。

被引用紀錄


陳盈成(2012)。外商銀行業資訊安全管理之研究-以A銀行為例〔碩士論文,淡江大學〕。華藝線上圖書館。https://doi.org/10.6846/TKU.2012.00303

延伸閱讀