透過您的圖書館登入
IP:3.133.86.172
  • 學位論文

以貝氏模式建構之資訊安全風險因子評估指標

Construction of Bayesian Risk Factors Assessment Index on Information Security

指導教授 : 詹前隆
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


本研究之目的在於運用貝氏模氏建構之資訊安全風險因子評估指標,結合資安專家觀點與企業關注議題,找出企業推動資訊安全工作之關鍵指標,協助進行資訊安全風險評估,讓企業更能深入了解企業資訊安全狀況,進而做好資訊安全相關決策。採用專家訪談(expert interview)與德爾菲專家問卷(Delphi Method)將資訊安全風險因子分成五大類,二十九項風險指標,運用貝氏理論(Bayesian Theory)建構評估指標與模式,計算資訊安全分數,發現前五大關鍵指標為高階主管支持與配合、阻擋與偵測蠕蟲病毒間碟程式的攻擊、已知駭客的攻擊手法進行防護措施、資安設備(資安軟體)符合需求、落實系統使用權限控管與密碼金鑰之管理。最後以相關性分析驗證了此評估模式之效度。

並列摘要


The goal of this research lies in application of construction of Bayesian Risk Factors Assessment Index on Information Security. Here, to integrate the viewpoints of the peaceful experts and the subjects that enterprises mainly pay attention to, and find out the key indicator that enterprises wish to promote their trouble-free service, then assist to help evaluate the security risk appraisal to enable the enterprises deeply realize the safe condition about their information, and complete themselves the information safe related decision-making. Adopt the expert interview and Delphi Method to divide the information security risk factors into 5 broad headings and 29 risk indicators. Based on Bayesian Theory, construct the appraisal targets and the patterns, and calculate the scores of the information security. There are first five important key indicators appeared, the higher level manager support and coordinate, the impediment and the detection between worm virus and the small dish program's attack, the known hacker's attack technique to carry on the protective measure, the information security equipment (information security software) to meet the demand, and fulfill the well-control management of the system using right and the gold key-password. Finally, the relevant analysis has confirmed validity of this appraisal pattern.

參考文獻


12.樊國楨、黃健銘、"醫療產業資訊安全管理系統初探"、資訊安全通訊
13.樊國楨、"資訊安全管理系統標準系列及其教育訓練的回顧與前瞻"、資訊安全通訊、第14卷3期、pp.25-44,2008/07。•
14.蔣雅禎,「貝氏統計模式架構之門診病患選科決策輔助」,元智大學,碩士論文,民國94年
15.江鴻屏,「運用貝氏模式建構慢性下背痛風險評估系統」,元智大學,碩士論文,民國93年
16.金秋華,「運用貝氏理論評估腦瘤病患症狀之診斷率」,元智大學,碩士論文,民國94年

被引用紀錄


呂志鴻(2011)。企業資訊安全投資之決策變數探討〔碩士論文,元智大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0009-2801201414585161

延伸閱讀