透過您的圖書館登入
IP:3.14.253.221
  • 學位論文

探討導入ISMS對組織之影響

A Study of the Effectiveness of Implementing the ISMS on Organization

指導教授 : 黃依賢

摘要


ISO 27001為現今國際最多組織所採用的資訊安全管理標準,亦是導入資訊安全管理系統(Information Security Management Systme,ISMS)的最佳參考規範。目前,我國已有413家機關通過ISMS驗證,全球排名第5。在個人資料保護法通過之後,企業面臨强化資訊安全議題;而且,醫療院所通過ISMS驗證後,得以申請定額之電子病歷補助款,這都將促使導入ISMS之組織大幅成長。本研究藉由訪談及問卷蒐集資料,以敍述統計、變異數及迴歸分析方式,探討導入ISMS對組織的影響。研究對象包含12個政府機關、7家民間企業及5所學術單位、人物專訪10位,有效問卷總計239份。研究發現,導入ISMS遭遇困難程度較高者為「導入ISMS會增加額外的工作量」、「導入ISMS之人力不足」以及「資安成員缺乏足夠的權力」。導入ISMS獲取效益程度較高者為「提升組織對維護資訊安全之聲譽」、「提升政府部門整體服務價值」、「建立標準化及文件化之資安作業流程」以及「提升組織成員的資安標準認知及資安職能」。導入ISMS的成功關鍵因素程度較高者為「高階主管的支持與承諾」、「具有資安職能之專案人員」、「資訊安全團隊的積極推動」以及「持續的資安宣導和訓練」。導入ISMS是一項管理制度的建立,組織應掌握成功的關鍵因素並降低遭遇的阻力,以獲取最大效益;導入後,仍應秉持PDCA的精神,持續對ISMS改善與精進,使組織的資訊安全更臻完備。

關鍵字

ISO 27001 ISMS PDCA 資訊安全

並列摘要


ISO 27001 is an information security management standard that is mostly adopted by international enterprises, and is considered the specification to be applied to ISMS. Currently, there are 413 agencies in Taiwan have gained the ISMS certification which is ranking No. 5 globally. As the Personal Data Protection Act was passed, enterprises are required to strengthen their own information security; hospitals and clinics also need to get the ISMS certification in order to apply for fixed subsidy when implementing the electronic medical records. Those factors will generate a substantial growth of organizations to implement the ISMS. This study collected data through interviews and questionnaires. By using descriptive statistics, ANOVA and regression analysis approach are to examine the organization impact when implementing the ISMS, which including 12 government agencies, 7 enterprises and 5 academic institutions. In this study, 10 interviews and 239 valid questionnaires were collected as well. We found that the top three difficulties for implementing ISMS are "Increased workload", "Shortage of manpower" and "Lack of proper authorities for information security team". The top four benefits for implementing ISMS are "Gain reputation for enhancing information security", "Raise value of governmental services", "Establish standardized and documented information security processes" and "Raise information security awareness and capabilities of organization staffs". The top four critical success factors for implementing ISMS are "Top management support and commitment", "Project team member with information security capabilities","Proactively push by information security team", and "Ongoing information security advocacy and training".The enterpreise is able to establish the management system with the use of ISMS. Therefore, the enterprises should control the critical successful factors and minimize the possible difficulties in order to make more benefits. To attain a more complete information security, carrying on PDCA and improving ISMS will be the main factors.

並列關鍵字

ISO 27001 ISMS PDCA Information Security

參考文獻


5.王保進 (2010a). 對學生學習成效機制自我評鑑之作業方向. 評鑑 27期: 7-13.
6.王保進 (2010b). 導入品質保證內涵與重視學生學習成效之大學校務評鑑.評鑑 24期: 54-58.
9.行政院 (2010). 個人資料保護法. 行政院.
15.李茂基 (2009). 政府推動資安之策略與省思.
16.林金定, 嚴嘉楓, et al. (2005). "質性研究方法:訪談模式與實施步驟分析." 身心障礙研究 Vol.3: No.2.

延伸閱讀