透過您的圖書館登入
IP:3.142.199.138
  • 學位論文

國立大學資訊安全管理之研究

A Study on the Information Security Management in National University

指導教授 : 游進年
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


資訊安全的認知源自知識與實務相互間的驗證,而大學是充滿自主性與學術性的組織,最珍貴的資產是知識及研發的人才,其組織型態及文化有別於其他公務機關或是企業,因此在資訊安全管理的目標、內涵及管理機制都有不同的需求與考量,亦值得深入探究。 本研究旨在探討國立大學資訊安全管理的現況、有利策略、以及相關人員對資訊安全管理的看法及其差異性。研究方法採用調查研究,蒐集資料並進行分析討論,問卷內容係參照經濟部所公布的資訊安全管理之作業要點CNS 17800編製而成,利用上網方式填答問卷,以26所國立大學資訊部門人員作為研究對象。 根據文獻探討及問卷分析討論,歸納出以下結論: 一、資訊安全管理業務運作現況是偏重於技術面,依問卷分析發現主要原因為使用者欠缺資訊安全管理認知,其次為欠缺一套資訊安全管理制度。 二、資訊部門人員背景以編制內及軟體開發的人員為主,與其他的政府機關不同。 三、與管理階層有關措施的可行性得分偏低,顯示管理階層實質參與實施資訊安全管理作業的意願偏低。 四、影響人員看法差異的因素,由業務性質分析發現因專業及實務經驗的不同,網路管理、主機管理與軟體開發人員在安全措施的看法上有明顯差異性;由教育程度分析發現「博士」群組認為資訊的可用性最重要,有別於其他群組認為機密性為最重要,且在安全措施的必要性看法上有差異;由管理階層分析發現「組長」與「主任」的看法未達共識。 依據上述結論,本研究提出以下建議: 一、建議教育部透過相關會議宣導資訊安全管理,並規畫提昇學校人員資訊安全認知的培訓。 二、建議國立大學籌組「資訊安全管理委員會」,並結合人事制度提高人員對資訊安全的重視,開拓資訊安全的管理面。 三、建議未來研究者採用質性研究方法,進而探討大學的體制面、教育面、技術面的問題。

並列摘要


Information security cognition requires mutual confirmation from factual knowledge and practical field experience. Colleges and universities are aggregations of independent academic bodies. The most precious properties of colleges and universities are the researchers and the intellectual properties as a direct result of their research. Therefore, the aim of information security in colleges and universities is different from other civil services or private organizations. The overall goals and management procedures need to be reconsidered. The purpose of this research is to study the current information security strategies and practices in national universities, as well as exploring the viewpoints of personnel involved in ensuring university information security. The research method is questionnaire-survey based. The questions in the survey are modified from the CNS 17800 information security management guideline of the Ministry of Economic Affairs. The questionnaire is distributed to and collected from computing center personnel of 26 national universities through web pages. From literatures and analysis of the collected questionnaires, conclusions are as follows: 1.The current information security practice stresses the technical aspect because the managers lack for understanding of information security and procedural guidelines to the management. 2.The staffs in computer centers of the national universities are from the internal organization. Their main responsibility is to develop software and they usually do not contact with information security management, which differs from those in the government agencies. 3. Based on the analysis, the scores related to higher level management is quite low. This indicates that higher level decision makers have less interest in participating in information security promotion. 4. Personnel with different background have different cognition on information security. First, the network administrator, the system administrators and software developers differ in their viewpoints on information security. Second, those persons with a Ph.D. degree thought that information accessibility is the most important issue while others listed information secrecy as the most important factor. The two groups also differ in their viewpoints in the necessity of information security. Third, the study also found that computer center directors and the division head also differ on many issues. According to above findings, Our study offers the following suggestions: 1. To Ministry of Education(MOE), we suggest they should promote information security at MOE meetings. We hope MOE to plan many programs for “Information Security management” and make on-the-job training to personnel. 2. To the universities, we suggest they should establish “Information Security Subcommittee” for enforcing & controlling various regulations, and urge the university administrators to oversee seriously and implement related strategies accompanied with a personnel reward system. 3. For the future duties, we suggest it should conduct qualitative study. Deeply research the aspects of principle system, education, and technology in the information security.

參考文獻


董崇明(2004)。科技中立的迷思。2004著作權法說明會。經濟部智慧財產局。未出版。
簡文慶(2000)。企業機密資訊文件管理機制之探討─ 以摩托羅拉公司為例。中原大學企業管理研究所碩士論文。全國博碩士論文摘要,89CYCU5121024。
侯皇熙(2004)。植基於BS7799探討政府部門的資訊安全管理─ 以海關資訊部門為例。國立成功大學工程科學系碩士論文。全國博碩士論文摘要,92NCKU5028044。
劉永禮(2001)。以BS7799資訊安全管理規範建構組織資訊安全風險管理模式之研究。元智大學工業工程與管理學系碩士論文,未出版,桃園。
Colleen, S.& David, M (2004). The spread of the witty worm. IEEE Security & Privacy. 2(4), 46-50.

被引用紀錄


黃建岡(2014)。驗證策略對國內生產毛額與對企業風險及品質成本的影響-兼論驗證工作的本質〔博士論文,朝陽科技大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0078-2611201410190722

延伸閱讀