透過您的圖書館登入
IP:18.191.240.243
  • 學位論文

以本體論為基礎之資訊安全文件管理系統的開發與建置-以某國軍單位為個案實證分析對象

Development and Implementation of An Information Security Management System Based on Ontology – A Case Study of a Military Unit in Taiwan

指導教授 : 黃明祥

摘要


資訊安全對於國軍部隊而言,不僅僅是機密資料的保護,更是關係著國家社稷的安危。根據統計,在多起資訊安全事件當中,屬於人為因素的比率高達85%,問題的核心在於國軍單位要如何做好資訊安全的管控,如何有效製訂國軍資訊安全政策,提供國軍資訊安全管理的一般性指導原則。因此,國軍資安政策律定各層級單位所應編製的原則,依照CNS 27001國家標準制定而成的ISMS資安管理制度建立相關資安管理制度,推行「資安政策」、「管理辦法」、「作業程序」與「紀錄表單」等架構規範文件的製作及管理作為,製定單位官兵所應遵循的規範與原則。 有鑑於資安文件管理的複雜處理程序,本研究擬以本體論作為系統開發基礎。本體論源自於哲學領域,在資訊整合、資訊科學、知識工程、與企業整合等領域扮演著一個重要的角色。文件管理系統是一套針對某種文件或是某些文件所建立的電子化資料庫以及提供操作的前端介面,透過電子化技術,將難以保存且難以傳輸的書面資料轉化成電子資料庫,研究人員要瀏覽資訊時,文件管理系統會協助從後端儲存處取出資訊,也可追蹤檔案新增的變化,使現有文件做最大程度的運用。 綜合上述所云,本研究開發一套以本體論為基礎之資訊安全文件管理系統應用於國軍某一電腦中心,透過本體論在知識領域儲存與萃取的優點,幫助電腦中心人員將相關資訊安全政策、防護技能、經驗及知識擷取,提供一個快速方便且不限時間地點的資料獲取管道,人員可隨時隨地上傳、審核、查詢、下載及分享知識文件等資訊安全相關政策、技術及紀錄表格。本研究依據本體論制定的資安文件類別有以下11大類:資訊安全政策訂定與評估、資訊安全組織、資訊資產分類與管制、人員資源管理與教育訓練、實體環境安全、通訊與作業安全管理、存取控制安全、系統開發與維護之安全、資訊安全事件之反應及處理、業務永續運作管理及相關法規與施行單位政策之符合性,作為資訊安全相關作業文件的分類依據,加強資訊作業人員專業技術交流,進一步提升資訊安全政策落實的效率和執行的精確度。 本研究根據電腦中心對於資訊安全文件管理系統的應用成效之發放重要性評估問卷給資訊相關人員共17人,統計分析如下:在系統品質方面:(1)資訊品質以系統所產出內容使用的正確性為最重要;(2)服務品質以文件品質之信任程度為最重要;(3)系統品質以文件管理系統的作業效率及安全性為最重要。在各項資訊作業效益方面,以本體論為基礎的資訊安全文件管理系統可以使作業人員容易掌握各項資安事件,提升作業品質與工作效率。同時,在資訊及知識應用方面,該系統依據ISO 27001的控制要項來管理知識文件的分類為可提供資訊作業人員完整的資訊安全政策資訊及作業程序等,上述研究成果可以作為資訊安全防護作業之用途。

並列摘要


Information security is considered as an important task of protecting the confidential data and protection of a nation's security for a military unit. According to the results of a survey on information security, occurrences of negligence of human behavior is over 85% among the events of information security. Therefore, how to develop an information policy and providing general guiding principles for information security control is the major issues of information security management for a military unit. In this research, an information security policy and execution principles is developed for a military unit. Furthermore, an information security document management system (ISDMS) including four major sections such as information security policy, managerial methods, operating procedures, and record sheets according to the regulations of CNS 27001 is developed. It is hoped to be carried out by the soldiers and employees of a military unit as the operation specifications and execution principles of delivering the document of information security system management. For the purposes of coping with the complex information security documents, this research develops an ISDMS based on the concept of ontology. Fundamentally, ontology originates from the field of philosophy and it is widely applied to the applications such as information system integration, information science, knowledge engineering, and business integration. Thus, ontology serves as a powerful tool to develop a structure of management system for information security documents. An ontology-based information security document management system is a good medium of storing digital information security documents and provides users to access information security documents. Bases on the needs of information security document management for a military unit, this research proposes a research model and develops an ISDMS. It aims to facilitate the employees of the computer center in accessing the information security document effectively with the function such as uploading, downloading and reviewing the information security immediately. An ISDMS based on ontology contains main categories including information security policy, information security organization, information asset classification and control, human resource management and educational training, physical environment security, communication and operating security management, access control security, security of system development and maintenance, reaction and process to information security events, professional work continuously operation management, conformation to relevant provisions of information security and information security policy of implementation units. The categories mentioned above can be used to classify the information security documents that is aimed to increase the technical exchanges among information professionals in order to improve the efficiency and effectiveness of implementations of information security policy. To examine the application performance of an ISDMS, a questionnaire is delivered to seventeen information professionals. Major findings of data analysis are summarized as follows. First, on the aspect of system quality, the correctness of contents of outputs of an information system is ranked as the first priority on information quality, the degree of truthfulness of document's quality is ranked as the first priority on service quality, and operation efficiency and security of document management system is ranked as the first priority on system application quality. Second, on the aspect of operation benefits, an ontology-based ISDMS can provide information professionals useful information about information security events. Third, an ISDMS based on the controlling items of ISO 27001 international standard can provide information professionals information about comprehensive information security policy and standard operating procedures. The findings of this research contribute to the application of preventing the occurrences of the events of information security.

參考文獻


10.李國豪、孫振東、李志仁。電腦中心共構服務之管理模型研究:以政府機關為例,華岡工程學報第28期,中國文化大學工學院,2011。
12.林志維,教材之數位化-以國軍數位化教材之發展應用為例,生活科技教育月刊43卷第4期,2010。
13.林明武、夏鈞浩,從「ISO17799」的導入論國軍資訊資產控管-以後備司令部為例,國防雜誌第26卷第4期,2011,第66-75頁。
18.晁瑞明、譚言家、黃淑苹,應用知識庫於會計師事務所-分散式知識管理之使用者行為研究,會計與公司治理第5卷第2期,2008,第29-54頁。
28.黃暉庭、蔡宗宏,整合自我效能、信任、組織支持與動機因素探索醫療知識庫系統之使用意圖-以台灣某教學醫院為例,電子商務研究Electronic Commerce Studies.,2008,第377-409頁。

延伸閱讀