透過您的圖書館登入
IP:3.142.173.227
  • 學位論文

個案公司量販事業部導入ISO 27001之關鍵成功因素

The Discount Division Of The Case Company To Import The ISO 27001 Key Success Factors

指導教授 : 王平

摘要


本研究期望對個案公司綜合試行單位(量販部門)導入ISO 27001之經驗,透過專家訪談及運用層級分析法決定建立資安風險管理制度(Information Security Management System,ISMS)之各風險屬性因素,找出重要因素以期許能對個案企業之其他部門導入作業,提供經驗及建議方向。首先,針對導入ISO 27001之試行單位進行問卷調查,歸納出導入ISO 27001之關鍵因素與評估架構,再經由層級分析法(Analytic Hierarchy Process,AHP)分析各風險因素的相對權重,藉由風險因素之排序探討導入ISO 27001重視度。期望透過本研究之分析結果,作為個案公司其他部門導入資安風險管理制度之決策參考,以提升導入資訊安全管理成效。最後研究歸納出前五大重要風險屬性,分別為「證據之收集」、「用戶密碼管理」、「報告資訊安全性事件」、「組織決策者實際支持」與「網路控管」相關作業,可作為其他部門執行資安風險管理之參考。

並列摘要


This study hope that the case company integrated pilot units (hypermarkets, department) into the experience of ISO 27001, through expert interviews and the use of level analysis to determine the establishment of information security risk management systems (Information Security Management System, ISMS) all risk property factor to identifyimportant factor to the expectations of other departments of the case enterprises import operations, experience and suggestions direction. First of all, for import the ISO 27001 of the pilot unit to conduct the questionnaire survey, summed up the import ISO 27001 of the key factors and assessment framework, and then through the hierarchy analysis method (Analytic Hierarchy Process, AHP) analysis of each risk factor relative the right weight, By the risk factors of sort of exploring the great importance to the degree of ISO 27001. Expectations through the analysis of results of this study, as other departments of the case company to import the information security risk management system of decision-making reference to enhance the import of the effectiveness of information security management. The final study summed up the top five important risk attributes, as "evidence collection", "user password management, report information security incidents, organizational decision-makers practical support and network control operations, as other departments, the implementation of information security risk management reference.

並列關鍵字

ISO 27001 Critical Success Factors

參考文獻


[9] 王平、羅濟群、趙國銘、王子夏,「I雲端運算服務之風險分析,
[1] Tiversa,On Presidential Security Leak, The WPXI NEWS
[10] British Standards Institution, BS 7799-1 Information Security
Management-Part 1:Code of Practice for Information Security
[11] British Standards Institution, BS 7799-2 Information Security

被引用紀錄


陳俊瑋(2016)。資訊安全規範影響因素評估〔碩士論文,中原大學〕。華藝線上圖書館。https://doi.org/10.6840/cycu201600681

延伸閱讀