透過您的圖書館登入
IP:3.140.185.170
  • 期刊

建構醫院資訊安全風險管理架構與風險衡量之研究

Developing a Risk Measurement Framework for Hospital Information Security Management

摘要


本研究目的為建構醫院資訊安全風險管理架構,藉以提供醫院組織人員對資訊安全認知的警覺輔助並達成風險有效衡量。研究模式建構係以ISO17799資訊安全標準為實務規劃,並結合修正期望效用理論與Riskit模式為理論基礎;進一步為驗證模式的可行性,本研究以中部某醫學中心推動資訊安全風險計畫為對象進行實地調查。結果顯示,本研究所得與先前學者的探討趨於一致,意即印證人類在面臨風險環境下其決策態度與行為並非是一致的,並且對於風險衡量方面的基數方法咸認為比Riskit模式所使用序數排列更為精確與可靠;本研究所發展的修正模式可以藉由免參數兩階段的偏好選擇,確實且全面地反映出利害關係人的風險態度與決策行為。綜觀醫院資訊安全風險管理的經驗顯示,若能深入調查個別利害關係人對於風險認知的態度,就可以掌握不同階段潛在的風險因素,再利用免參數方法據以衡量潛在的風險事件,即使有非預期危害事件發生亦可以將風險損失加以轉移與控制,進而達成風險管理的目標。由於本研究架構所探討利害關係人的決策態度與行為特性具有一般性的應用價值,可以提供其他資訊安全風險管理領域應用之參考。

並列摘要


The purpose of this study was to develop a hospital information security risk framework, improve sensitivity toward organizational risk, and improve decision making. This study adopted the ISO17799, which has ten controls items, for risk management. To ensure that the proposed framework was feasible, we conducted a field study to investigate the risk to identification, analyses, measurement and control, respectively. We found that the analysis was in agreement with previous studies and that there was a great diversity in human decision behavior and uncertainty in risky environments. Thus, the proposed framework was able to elicit the real risk attitude of each stakeholder more accurately than the Riskit model. A review of risk experience was able to show clearly the potential incident through its investigation into the risk cognition of stakeholders more in detail. Furthermore, using this study, we were not only able to identify potential risk incident utilizing a non-parameter method, but also were also able to access risk and control losses. We concluded that the proposed framework can reduce information security risk about by considering stakeholders' decision positions and behavior attribute and providing decision makers the effective support need for quality decision making. Finally, the implications of the research findings can be used to investigate similar at risk decision making issues.

延伸閱讀