透過您的圖書館登入
IP:3.142.98.108
  • 學位論文

企業導入ISO 27001 之關鍵成功因素對績效之影響

THE IMPACT OF CRITICAL SUCCESS FACTORS FOR ISO 27001 CERTIFICATION ON PERFORMANCE

指導教授 : 李賢哲
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


近年來網際網路的發達致使人們對於電腦的依賴性逐漸增加,而企業面臨到全球化競爭下電子及資訊技術的進步,進而制定e化策略以及所需要的安全政策來因應資安威脅。 本研究將焦點置於國內通過ISO 27001認證之企業,將問卷發放給企業最常見的三個部門-業務、財務、資訊,來判斷其導入ISO 27001四個構面的關鍵成功因素是否對於其績效有影響。而企業整體績效並不僅限於帳面上的績效,另外也有無形的績效,因此將績效分為四個構面-客戶、財務、內部流程、學習與成長等四構面,進行關鍵成功因素對於平衡計分卡四構面的影響。 研究結果發現通過ISO 27001認證企業中,四個關鍵成功因素構面之重要性依序為管理構面,技術構面,人員構面與外在環境構面;至於BSC績效構面之重要性依序為內部流程構面,客戶構面,財務構面與學習與成長構面。而關鍵因素構面對於企業的整體績效都有顯著正向影響,代表著ISO 27001的導入對於提升企業績效是有幫助的。另外,詳細而言,關鍵因素構面皆對顧客構面有正向影響,管理、人員關鍵因素購面對財務構面有正向影響,而管理、技術及人員關鍵因構面對內部流程構面有正向影響。最後,關鍵因素構面皆對學習與成長構面有正向影響。

並列摘要


In recent years, the internet has led to an increase in computer-dependent; enterprises are facing the competition from the globalization of electronic and information technology; in other words, the development of e-strategy and security policy needed to be conducted for reducing the security threats. So, the adoption of ISO 27001 is a hot topic in recent days. Therefore, this study focuses on identifying the critical success factors for implementing ISMS for enterprises and examining the impact of the critical success factors on performance. In this study, we collect a total of 70 enterprises with adoption of ISO 27001 certification as valid samples to do statistical research. The results show that the adoption of ISO 27001 has a significant positive impact on performance, and the management dimension has the most influence of these four dimensions. But, external environment is relatively the smaller one. Also, enterprises with the implementation of ISO 27001 all have a positive impact on the BSC four perspectives of performance; it implies that the implementation of ISO 27001 has benefits on performance of the enterprise. Specifically, dimensions of critical factors all have positive impact on customers perspective. Secondly, management, technology dimensions have positive impact on financial perspective. Thirdly, management, technology and staff dimensions have positive impact on internal process perspective. Eventually, dimensions of critical factors all have positive impact on innovation and learning perspective.

參考文獻


Hsu, C. “The Study of the Effectiveness of Information Security Management after Organizations Implement BS 7799.” Unpublished MBA Thesis, Tamkang University, 2005.
Aakers, D. A. Strategic Market Management, USA: John Wiley & Sons Inc, 1984.
Badenhost, K. P. and Jan H. P. Elloff. “Framework of A Methodology for the Life Cycle of Computer Security in an Organization.” Computer & Security 8, No. 5 (1989): 217.
Babbie, E. R. The Pactice of Social Research, Boston: Wadsworth Pub Co., 1998.
Basie V. S. and V. S. Rossouw. “Information Security to…Business Security?” Computers & Security 20, (2005): 215-218.

延伸閱讀