摘 要 在資訊科技普及的今日,我國不遺餘力的推廣資訊對生活方面的應用。但隨著網路環境的普及,資安事件之層出不窮;致使政府開始逐漸重視資訊安全之各項領域。所以行政院研究發展考核委員會,開始積極推動國家資通安全會報組織的成立,並協助政府機關民間企業導入資訊安全相關政策及輔導措施。 由於企業員工對資訊安全防護認知的不足與輕忽,造成了企業資訊安全的一大漏洞,公司即使投資了各種網路防護等軟硬體及加上良好的保全系統保護機房的安全,結果仍可能不堪一擊。因為社交工程利用人性容易相信而上當的弱點,避開了不容易破解的網路防火牆,應用了簡單的溝通和欺騙技巧,便突破了企業耗資千萬的安全防護,所花費的成本竟然只有幾封e-mail郵件,或者利用一、兩通電話就有可能造成企業的莫大損失。 本研究希望透過企業內部電子郵件社交工程的演練、資安教育訓練及資安宣導,讓企業員工了解由於個人之因素可能導致企業遭受資安事件的危害,並且進一步建立員工之資訊安全基本認知。經由以上3點架構希望能夠使員工在資訊安全認知上有更深一層的了解,並且培養員工正確的使用習慣,以便改善企業資訊環境的體質。 就以上之敘述在此規劃二大主題方向進行研究探討: 一、企業內部員工在電子郵件社交工程演練後,探討員工在演練前後之差異性以及在點擊郵件篩選之認知上是否有明顯之提升,進而降低機密文件及個人資料外洩等資安事件之發生。 二、透過資安教育訓練與宣導,探討是否能夠提升員工之資訊安全認知。當了解資訊安全對企業之重要性後,進而避免個人及企業遭受到資安的危害。 結合以上二大主題透過企業內部社交工程演練及單位內部問卷調查實證,探討企業內部員工對電子郵件社交工程演練及資訊安全認知上的了解程度。
ABSTRACT Because most of the employees are careless with information security, that will cause the security vulnerability in an enterprise. Although the company constructs the system with hardware/software for network protection, however, that is still indefensible. Moreover, the hacker may use social engineering (communication and cheat skills) to pass-through the firewall. The attack just costs several telephone-call fees but brings huge damage to an enterprise. Employees usually do not care about business about information security. They believe that such the issues should be handled by department of information, and this concept will cause unexpected damage. Consequently, the company (TS) (research objective of this study) helps employees to construct the essential of information security by importing the training courses of social engineering based on internal e-mail system, related practice and propagation are included. Therefore, this study comprises two topic listed below: 1.After performing the practice of social engineering, does the company (TS) successfully improve the employees’ cognition of such issues (ex. clicking e-mails)? 2.After importing training and propagation of information security, do employees actually understand the importance of information security? If yes, that can keep the enterprise away from the damage. Finally, we can verify and confirm whether the employees have learned about the importance of social engineering and information security or not by analyzing of questionnaires.