透過您的圖書館登入
IP:3.149.251.155
  • 學位論文

以ISO27001/BS7799為基礎之校園資訊安全管理研究

The Research of Information Security Management in Campus based on ISO27001/BS7799

指導教授 : 吳昌憲
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


本研究植基於「ISO27001/BS7799資訊安全管理規範」、「教育體系資通安全管理規範」,挑選適當控制項內容,以問卷方式調查國內大專院校的資通安全狀況。其間接促成教育部在「教育體系資通安全管理規範」的要求,讓受訪之學校以本研究問卷進行自審,並將結果作比較討論,期望能提供學校、教育部在推動教育體系資通安全之參考。 此外,在本研究中討論資訊安全的需求及原因,並從風險管理的角度,建立一套資訊安全風險評估的模式。從問卷調查的分析結果顯示,除了可以提供資訊安全事項的優先處理順序與相關對策外,更可彰顯出組織資訊安全風險問題之所在,從而有效加以管理及規範與建立完善的資訊安全。

並列摘要


Based on "ISO27001/BS7799 information security management standards" and "The norms of Information and Communication Security Management in Educational Systems", this study was conducted by selecting appropriate control items and emailing questionnaires to survey the current status of implementing information and communication security management in domestic universities and colleges. This indirectly facilitates the request of "The norms of Information and Communication Security Management in Educational Systems" by Ministry of Education, and prompts surveyed universities and colleges to review themselves with the questionnaires of this study. Hopefully the review discussion will provide schools and Ministry of Education a helpful reference for building a security management system. Furthermore, the demand and reason of information security were discussed in this study. From the viewpoint of risk management, a model of risk assessment for information security was established. According to the analysis result of questionnaires, it produced a set of priorities concerning information security as well as suggestions for proper responses. It also helped identify potential problems of information security within organization. Thus, the model put forward by this study is able to raise information security consciousness among organization members and contribute to better information security.

參考文獻


[4]劉聰德、蔡舜智、謝沛宏、劉瑄儀、陳彥豪、許乃文、王靜音,「剖析我國資通安全現況及挑戰」,收錄於國家科技政策關鍵議題研究,國家實驗研究院,2006。
[5]侯皇熙,「植基於 BS7799 探討政府部門的資訊安全管理─以海關資訊部門為例」,國立成功大學工程科學系,碩士論文,2004。
[14]侯皇熙,「植基於 BS7799 探討政府部門的資訊安全管理─以海關資訊部門為例」,國立成功大學工程科學系,碩士論文,2004。
[16]杜偉欽,民95, “結合HIPAA與ISO27001為基礎探討醫療院所資訊安全管理之研究”,國立成功大學工程科學研究所碩士論文。
[26]Caelli,W.,D.Longley and M.Shain(1989),Information Security for Managers,Stockton Press,New York.

延伸閱讀