透過您的圖書館登入
IP:18.119.111.9
  • 學位論文

中小企業實施資訊安全管理措施之資訊系統效益研究

The Information System Benefits of Information Security Management Implementation for Small and Medium-Sized Enterprises

指導教授 : 張碩毅
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


新科技及技術不斷推陳出新,自帶設備(BYOD) 、雲端硬碟及雲端科技服務應用等也越來越多元。網際網路及資訊科技的進步雖然讓我們能快速、方便的取得所需及傳遞資料,但也因為這樣的便利性,在沒有做好安全的認知及防範時,容易讓我們曝露在新的資訊安全風險中。由於資安事件造成的不僅是組織財務面的損失,並且會影響組織之品牌形象,甚至影響到組織的永續經營。所以如何保護資訊資產安全,避免不當的使用或破壞、竊取,是組織不得不重視的議題。 資訊安全管控措施雖然可以讓企業避免無法估計的損失,但是,凡事有管理的動作,就代表著無法隨心所欲並且失去便利性,所以一旦中小企業為了安全考量,開始進行資訊安全的管控措施,往往會發現在整個資訊系統使用存取上,程序會變的繁瑣,因此造成一般使用者使用上變的比以前還要麻煩而抱怨連連。雖然安全性提升了,但是便利性卻大幅下降,而不便利就造成處理速度變慢,進而影響系統服務績效或個人績效的問題。 實施資訊安全管理措施,雖然可以讓企業避免因為資料外洩而造成的商業損失,但對企業內部整個資訊系統效益的影響究竟為何?因此,本研究以「ISO 27001 、CNS27001之資訊安全管理措施」結合「D&M 資訊系統成功模型」及「科技接受模型(TAM)」理論觀點,以「資訊安全管理措施」、「系統特性」、「人員認知」等三個構面形成本研究之研究模型,來探討中小企業實施資訊安全管理措施之「資訊系統效益」。 本研究以國內已實施資訊安全管理措施的中小企業為對象,經由問卷發放的方式進行資料收集以進行模式的驗證。問卷總共發放497份,實際有效問卷為102份,有效問卷回收率為20.5%。研究結果發現: 1、資訊安全管理措施對系統特性構面(資訊品質、系統品質、服務品質)及人員認知(認知有用性、認知易用性)構面皆有顯著影響。 2、人員認知(認知有用性、認知易用性)對資訊系統效益有顯著影響。 3、系統特性構面(資訊品質、系統品質、服務品質)對資訊系統效益並無顯著影響,而且在資訊品質、系統品質對資訊系統效益影響的路徑為負值,顯示其與資訊系統效益可能為反向影響。

並列摘要


Bring Your Own Device (BYOD), cloud drive and cloud services applications are becoming increasingly diverse in new technology innovation. Due to advances in network and information technology , that we can quickly and easily obtain the required information, but also because of this convenience of no safety cognition and defenses, is easy for us exposed to new information security risk. Because information security incident caused not only the loss of the organization's financial side, and will affect the brand image of the organization, even affecting the sustainable operation of the organization. So how to protect the security of information assets, avoid improper use or damage or theft, is the organization has to pay attention to issues. Although information security management can allow enterprises to avoid incalculable loss, but everything has management of action, always lose convenience. When implementing the information security management on the small and medium-sized enterprises, often found on the entire system access becomes cumbersome, thus causing more trouble and users complaining. While security has improved, but convenience has dropped significantly, convenience has resulted in slower processing speed, which affects system performance or individual performance problems. Implementation of information security management, although can allow enterprises to avoid business losses, but what influence on the entire enterprise information system? Therefore, this study based on "ISO 27001, CNS27001 information security management " and "D & M Information System Success Model" and "The Technology Acceptance Model (TAM)" theoretical to three dimensions of "information security management" and "system characteristics " and "staff awareness ", to discussion in the "Information System Benefits" of the implementation of information security management for small and medium-sized enterprise. This research has been targeted at small and medium-sized enterprise in implementing information security management. Data collection via questionnaires way to verify mode. A total of 497 questionnaires distributed, 102 valid questionnaires were real, effective response rate was 20.5%. The results showed that: 1. Information security management on system characteristics dimensions (information quality, system quality, service quality) and staff awareness (perceived usefulness, perceived ease of use) dimensions are significant affect. 2. Staff awareness (perceived usefulness, perceived ease of use) have a significant affect on information systems benift. 3. System characteristics dimensions (information quality, system quality, service quality) has no significant affect on information systems benift, but also in the path of information quality and system quality to information systems benift is negative, showing its benefit may be a reverse effect.

參考文獻


2、方仁威(2004) 「資訊安全管理系統驗證作業之研究」,交通大學資訊管理研究所博士論文。
8、林靖文(2011) ,「運用科技準備度與科技接受模型探討公共圖書館使用者使用數位服務科技之意願-以國立臺中圖書館為例」,臺灣大學文學院圖書資訊學系碩士論文。
22、蘇豐裕、王嘉男、林谷鴻(2008) ,「 ERP系統使用者滿意度之研究-以F公司為例」,工程科技與教育學刊第五卷第三期。
19、潘思佑(2006) ,「 企業資訊系統服務品質與使用者滿意度之研究」,成功大學企業管理研究所碩士論文。
1、Bailey, J. E., & Pearson, S. W. (1983). Development of a Tool for Measuring and Analyzing Computer User Satisfaction. Management Science, 29(5), 530-545

延伸閱讀