透過您的圖書館登入
IP:216.73.216.100
  • 學位論文

軍事機構取得ISO 27001認證之階段性關鍵成功因素研究-以C單位為例

The Phased Key Success Factors on the Military Body Obtains ISO 27001

指導教授 : 許通安
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


摘 要 近年來國防洩密情事頻傳,資訊安全事件不斷發生,分析事件單位面對安全威脅無法防禦的主要原因是防禦方式只有單點運作,缺乏全面的整體防線,部份有心人士運用日新月異的網路科技、進行各種滲透、破壞及竊密行為,已到了所謂無孔不入的地步,網路安全已儼然是網路世代的高科技攻防戰,國軍肩負國防安全的第一線,資通安全相對重要,如何有效建置資訊安全管理系統是目前軍事機構單位不容忽視,且必須面臨的課題。ISO 27001為目前國際公認最完整之資訊安全管理標準。本研究以通過ISO 27001認證之軍事機構個案單位為研究對象,以深度訪談為主、其他相關資訊安全文件及取得ISO 27001認證學術文獻資料為輔,探討軍事機構取得ISO 27001認證之階段性關鍵成功因素。 本研究結果發現: 一、策劃、組織與教育訓練階段: 其比較重要之關鍵成功因素為<高階主管支持與承諾>、<企業安全政策、目標、活動的明確化>、<專案領導者>、<合適的資訊安全輔導顧問>等四項。 二、文件製作及系統評估階段: 其比較重要之關鍵成功因素為<高階主管支持與承諾>、<合適的資訊安全輔導顧問>、<資訊化程度>等三項。 三、試行、內部稽核與缺失改善階段: 其比較重要之關鍵成功因素為<高階主管支持與承諾>、<員工對資訊安全、風險評估、風險管理認同感及了解與接受度>、<不斷稽核與矯正>、<輔以員工適當的資訊安全教育訓練>等四項。 四、驗證與頒證階段: 其比較重要之關鍵成功因素為<高階主管支持與承諾>、<需能配合顧問公司的建議>、<合適的資訊安全輔導顧問>、<不斷稽核與矯正>等四項。 五、持續改善階段: 其比較重要之關鍵成功因素為<高階主管支持與承諾>、<企業安全政策、目標、活動的明確化>、<合適的資訊安全輔導顧問>等三項。 受限於能力及時間,本研究只針對該個案單位進行研究,希望此項研究結果能提供其他軍事機構做為取得ISO 27001認證參考依據,有效且順利的建置符合國際標準的資訊安全環境,事先防範資安事故的發生,確保國防資訊安全,國家機密才能真正滴水不漏,使敵人無可乘之機。 關鍵字:ISO 27001、關鍵成功因素

並列摘要


ABSTRACT In recent years, the blabbing secret of national defense occurred frequently, the accident of information security found constantly. The principal cause why department, which made the fault, unable to prevent from those threat is that the protection was executed singly. Where locks a whole plan to protect. Someone who use the fast changing technology, Internet, to penetrate department, to damage information, and to steal secret. Those actions has been all-pervasive doing. Security of internet has become a battle of high-tech of internet generation. Military is the front of national security. So that security of information and communication was more important. In military, it cannot be ignored or evaded that how to set up an effective system, which was use to manage information and communication. ISO 27001 is the most complete information security management standards that was recognized by internationally. In this research, department of military, which is adopted certification of ISO 27001, was object of study. This thesis takes depth interview as major; documents of information security and literatures of ISO 27001 certification as subordinate for studying the key factors which influence the military department to adopt certification from ISO 27001. In this study, we found the key factors for adopting certification in five stages: Planning, educating, and training The key factors are high-order executive support and not promise, enterprise safe policies, goals, activities make clear, special project leader, and last advisor suitable information safety . Pondering of system and producing of documents The key factors are high-order executive support and not promise, suitable information safety last advisor, and degree not information-based. Trying, inner checking, and faults amending The key factors are high-order executive support and not promise, the staff are safe to information, and can't understand it assess risk, risk management acceptance and it accept it degree, audit and correct constantly, and complement by staff proper information safety education and training. Verifying and certification awarding The key factors are high-order executive support and not promise, is it can cooperate with suggestion of consultant firm to need, coach a advisor by suitable information safety, and are audit and correct constantly. Verifying constantly The key factors are high-order executive support and not promise, it is safe in enterprise policy, goal, activity make clear, and last advisor suitable information safety. It is for the reasons of limited time and inadequate resource that the object of study was chosen only one. The results of this research are able to be referred for the military agencies who want to obtain the certification of ISO 27001. The results also help to setup a safe information of environment which satisfied international standard. The final aim of this research is to guard against the accident of security information, to assure the safety of national defense information, and to destroy the opportunity of enemy attack. Keyword:ISO 27001, Key Succeed

並列關鍵字

Key Succeed ISO 27001

參考文獻


6. 虞金燕,我國資訊安全市場發展現況與趨勢(上),2001
9. 王凱,資訊安全市場發展現況與趨勢,2004
4. 羅慧真,政府研究機構資通安全系統架構之研究-以某政府研究機構為例,2008
21. 李仁暉,台灣金融業導入資訊安全管理系統關鍵成功因素研究-以A金控為例,2007
28. Ansoff, H. I., “Strategic Management,” Wiley, 1979

被引用紀錄


陳俊瑋(2016)。資訊安全規範影響因素評估〔碩士論文,中原大學〕。華藝線上圖書館。https://doi.org/10.6840/cycu201600681
黃慶裕(2011)。探討導入ISMS對組織之影響〔碩士論文,元智大學〕。華藝線上圖書館。https://doi.org/10.6838/YZU.2011.00104

延伸閱讀