透過您的圖書館登入
IP:18.218.127.141
  • 學位論文

探討銀行業ISO/IEC 27001: 2005 資訊安全管理現況-以T 銀行為例

A Study on the ISO 27001: 2005 in Banking: Current Status of Information Security Mangement - A Case Study of T Bank

指導教授 : 周惠文
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


在高度競爭的環境下,銀行依賴資訊系統程度也日益增加。然而隨著資訊安全事件不斷發生,遵循一套良好規範的資訊安全管理系統 (Information Security Management System, ISMS),將是落實資訊安全的重要環節。本研究以個案銀行作為研究對象,透過以ISO 27001 為基礎的問卷,調查133 項控制措施中對銀行最為關鍵的項目。此外,本研究亦調查員工在組織導入ISMS 後,對於其資訊安全幫助程度及行政效率影響程度的認知。 研究結果發現,對銀行而言共有10 項關鍵措施,分別為「人力資源管理」構面的1 項;「安全政策」、「資訊安全的組織」與「實體與環境安全」構面各有2項以及「通訊與作業管理」構面的3 項。因此銀行在導入ISMS 時,可針對相關的控制措施特別著墨並投入較多的資源。 另外,研究發現組織導入ISMS 後不僅對於資訊安全有所助益,對於行政效率也沒有產生負面的影響。有鑑於此,建議尚未導入ISMS 的銀行,可以審慎評估導入的可行性,以增強組織的資訊安全。除此之外,受訪者對於「ISMS 對組織資訊安全的幫助程度」可能會因為不同科別與職等的特性,導致態度上有所差異。所以組織亦可在導入ISMS 時,考量不同群體的特質,提出對應的措施。

並列摘要


In a highly competeive enronment, banks rely more and more on infromation security system. However, with the incresing information secutiry incidents, it would be very important for banks to follow a well-defined information security management system (ISMS). This research takes a bank as the case study. The researcher wants to find out those important controls among those 133 ones based on the questionaries of ISO 27001. Besides, this study also wants to find out if it helps or promotes staff''s understanding towards administration effect after implementing ISMS. This study finds out there are ten key controls for bank. There are one control that comes form human resources security, six from security policy, orgination of imformation security, physical and environmental security, and three form communications and operations management. As a result, when implementing ISMS, banks should put more importance and human resource on those related meausres. What''s more this study also finds that implementing ISMS not only helps the imformation security but also does no negative effect to the administration effiency. As a reuslt, the researcher suggests banks which do not implement ISMS could take the possibilty of implementing ISMS into serious consideration to reinforce the information security of the orgination. Besides, the attitude of interviewers towards "the level that ISMS helps imformation security of banks" differs from different departments and job. Therefore, when an orgination could take this into consideration when implementing ISMS and find out its solution.

參考文獻


11. 黃彥男、高天助、林劍秋 (2011),世界經濟論壇「網路整備度」評比分析與展望. 研考雙月刊,35(4),143-148。
4. 杜偉欽 (2006),「結合HIPAA與ISO27001為基礎探討醫療院所資訊安全管理之研究」,國立成功大學工程科學研究所碩士論文。
7. 林麗英 (2010),「資訊安全管理系統績效評估之研究-以檔案管理局為例」,朝陽科技大學資訊管理研究所碩士論文。
9. 侯皇熙 (2004),「植基於BS7799探討政府部門的資訊安全管理 ─ 以海關資訊部門為例」,國立成功大學工程科學系專班碩士論文。
1. Boehmer, W. (2008). Appraisal of the Effectiveness and Efficiency of an Information Security Management System Based on ISO 27001. The Second International Conference on Emerging Security Information, Systems and Technologies (224-231). IEEE.

被引用紀錄


李沛倫(2016)。資訊安全稽核作業評量輔助系統之研究〔碩士論文,淡江大學〕。華藝線上圖書館。https://doi.org/10.6846/TKU.2016.00872
林宇溱(2015)。資訊安全政策導入ISO 27001之關鍵成功因素探討〔碩士論文,中原大學〕。華藝線上圖書館。https://doi.org/10.6840/cycu201500619
翁加偉(2014)。個資法施行後對組織之衝擊與因應-以S大學為例〔碩士論文,國立中央大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0031-0412201511590247
陳維揚(2016)。以ISO27001探討醫院資訊安全系統〔碩士論文,國立中正大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201614042653
謝勝文(2016)。瞭解遵守資訊政策意圖:處罰、社會影響、價值認知及安全風氣〔碩士論文,國立中正大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201614063666

延伸閱讀