透過您的圖書館登入
IP:3.145.119.199
  • 學位論文

從資訊人員觀點探討企業導入資訊安全管理系統之影響—以金融業為例

A Study of the Viewpoint on Information Professional for Business Implementing the Information Security - Based on Financial Industry of Taiwan

指導教授 : 蕭瑞祥

摘要


資訊安全無疑的是現今金融業內最重視的一環,且隨著資訊科技進步、個人電腦技術的精進及駭客手法分享的迅速,企業對於資安問題的防堵與解決疲於奔命,資訊安全不再是一個企業對外展現其附加價值的標籤,而是成為企業內的基本配備。金融業因為資訊安全問題所導致的損失,已經嚴重打擊到內部的營收,所以金融業逐年加重其於資訊安全的支出比例,但資安問題仍是層出不窮。資安問題從過去外部的攻擊事件逐漸轉為內部人員的不當行為竊取,而金融危機引發的經濟衰退,導致過去一年開始,許多公司大幅裁員,不僅資訊人力緊縮,離職員工在離開公司時會隨身帶走屬於公司的機密資料,而這其中的許多人將會在新公司使用這些資料,此舉將對企業的競爭力及營運造成很大的影響。因此企業加強對資安的需求,加上科技快速的演進,資訊人員的工作量不斷增加,精神壓力倍增,在兩項因素互相影響循環之下,將會降低企業執行資安工作的效能。 本研究將以ISO27001為基礎,探討金融業在導入資訊安全管理系統後,資訊人員所屬組織性質、職務性質、個人性質對資安政策導入之必要性、工作量增減程度、實際提升資訊安全之看法及影響。本研究透過問卷的形式來蒐集資料,藉由金融專業人士協助二階段的問卷設計及前測作業,並經由敘述性統計、變異數分析 (One-way ANOVA)、平均數分析等統計方法進行分析,研究結果顯示企業導入資訊安全後,資訊人員之所屬「公司產業」、「公司規模」、「學歷」在資安『導入之必要程度』有顯著差異;資訊人員之所屬「公司產業」、「公司是否取得ISO27001」、「工作性質」、「性別」在資安導入後『工作量增減程度』有顯著差異;資訊人員之所屬「公司規模」、「學歷」在『資訊安全提升程度』有顯著差異,且在所有資安條項中,除了「資產管理」以外,資訊人員皆認同資安『導入之必要程度』高於『資訊安全提升程度』,更高於『工作量增減程度』。 期望未來在企業導入的資安政策中,能運用本研究建議分析資訊人員認同其導入必要且實際改善資訊安全的條項,以提供企業思考其資安預算及人力之配置,及找出增加其工作量之原因,改善作業流程,尋求配套措施,以減輕其工作負擔,落實資安政策,收事半功倍之效。

關鍵字

資訊安全 ISO27001 資訊人員

並列摘要


Information security is no doubt the most important part of current financial industry. Enterprises are always busy in solving the information security problems with the progress of information technology, the improvement of computer technology, and the quickness of spreading hack skills. Information security is no longer a label that enterprises show their added values, but the basic equipments within the enterprises. The income of the financial industry is impacted by the losses caused by information security problems. Therefore the financial industry increases its proportion of information security expenditures year by year, but more and more information security issues still exist. These information security issues change from the external attacking events to the internal employee thefts. The economic recession caused by financial crisis makes enterprises laying off employees started from last year. It also makes the lacking of information manpower, and even more worse, the leaving employees carry the employer's confidential information away. Some of the leaving employees then use the stealing data in the new companies. This surely causes huge impacts to the capabilities of enterprises' competition and operation. So enterprises strength the need of information security. Along with the progress of information technology, the Information Professionals' workloads and mental pressure increase by times. In the interactions between these two factors, the efficiency of information security jobs is reducing. This research, based on the ISO27001 standard, discusses the viewpoints and influences of the financial industry about the organizations types, position types, and personal characteristics of Information Professionals to the necessity of information security policies, the extent of increasing workloads, and the level of improving the information security after implementing the information security management systems. The data was collected in the method of questionnaire proposed by this research with aided of 2-phase designing and fore testing by the financial professionals, and was analyzed in the method of statistics such as descriptive statistics, One-way ANOVA, and average analysis. The results of this research show that after implementing the information security policies there exists significant differences in the issues of Information Professionals: the "The Company's Industry", "The Company's Size", and "The Educational Background" issues exist significant differences in the "Whether the Company Needs to Implement Information Security Policies Or Not" factor; the "The Company's Industry", "If the Company Gets a ISO27001 Standard", "The Job Type", and "The Gender" issues exist significant differences in the "The Extent of Increasing Workloads" factor; the "The Company's Size", and "The Educational Background" issues exist significant differences in the "The Extent of Improvements of Information Security" factor. In addition, Information Professionals commonly agree with that the "Whether the Company Needs to Implement Information Security Policies Or Not" issue is more important than the "The Extent of Improvements of Information Security" one and much more important than the "The Extent of Increasing Workloads" one among all information security items except for the "The Assets Management" issue. This research expects that the enterprises will consider the results and analysis of this research about the items agreed by the Information Professionals which need to implement and surely can improve the security while implementing the information security policies. Enterprises using the results of this research to figure out their appropriate settings of information security budgets and human resources and to find out the reasons of increasing workloads can improve their operating process and seek the accompanying measures to lighten the burden on related jobs. So that enterprises can implement the policies on information security properly and gain more benefits and rewards.

參考文獻


22.邱漢松(2008)「台灣資訊工作人員的樂觀程度研究-以某大型金控公司資訊部為例」,中央大學資訊管理研究所碩士論文。
11.杜偉欽(2006)「結合HIPAA與ISO27001為基礎探討醫療院所資訊安全管理之研究」,成大工程科學研究所碩士論文。
23.鍾明憲(2008)「資訊人員對資訊安全系統導入意向之研究」,元智大學資訊管理學系碩士班論文。
24.吳明隆(2007)「SPSS統計應用學習實務(問卷分析與應用統計)」,知城圖書,經緯國際股份有限公司。
1.Bartol,K.M.,“Turnover Among DP Personnel: A Causal Analysis,”Communication of The ACM, Vol.26,No.10,1983, pp.807-811. Hills, CA: Sage, 155.

被引用紀錄


陳盈成(2012)。外商銀行業資訊安全管理之研究-以A銀行為例〔碩士論文,淡江大學〕。華藝線上圖書館。https://doi.org/10.6846/TKU.2012.00303
王偉全(2013)。以本體論為基礎之資訊安全文件管理系統的開發與建置-以某國軍單位為個案實證分析對象〔碩士論文,國立屏東科技大學〕。華藝線上圖書館。https://doi.org/10.6346/NPUST.2013.00087
涂國慶(2011)。應用商業智慧於網路安全之研究〔碩士論文,大同大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0081-3001201315111712

延伸閱讀