透過您的圖書館登入
IP:3.145.47.253
  • 學位論文

導入BS7799標準對建立資訊安全文化影響之經驗研究-以Y公司為例

An Empirical Investigation of the Relationships between Culture of Security and Information Security Standard (BS7799)

指導教授 : 曾德宜
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


本研究探討台灣著名Y公司導入「資訊安全管理制度」(BS7799)後對於組織之資訊安全文化的影響程度,以及兩者之間的關聯性。本研究採取BS7799的管控領域為自變項,以及OECD所提出資訊安全文化概念為依變項,向該公司123位成員發送問卷進行調查,以因素分析、逐步多元迴歸分析等統計方法進行分析。研究結果發現,導入BS7799標準對於資訊安全文化的發展有顯著影響,其中以「安全政策」對於資訊安全文化整體發展的影響最重要;導入BS7799資訊安全管理制度對於資訊安全認知與責任的建立、反應與應變能力的強化、安全設計與執行上與存取控管的落實以及資訊倫理的內化等方面,皆有明顯的成效。

並列摘要


This paper tends to study the influence of information security management system (BS7799) on information security culture of an organization and the correlation between them in a famous Taiwan company named ‘Y’. The research chose management sections of BS7799 as independent variables and the conception of information security culture defined by OECD as dependent variable. Questionnaires were sent to 123 employees in Y company and the collected data were analyzed with statistical methods such as factor analysis and stepwise multiple regression analysis. The result shows that the introduction of BS7799 system has significant influence on the development of information security culture. Particularly, security policies have the most important influence on the development of information security culture as a whole. The introduction of information security management system (BS7799) also has significant influence on establishment of awareness and responsibility of information security, strengthening the capability of response and solving an emergency, security design and application, management of access control, endogenesis of ethics of information, etc.

參考文獻


1. Baggett, W. O., (2003), “Creating a Culture of Security”, The Internal Auditor (60), pp.37-39.
4. Jacqui Chau. (2005),“Skimming the technical and legal aspects of BS7799 can give a false sense of security”,Computer Fraud & Security Volume.
5. Fumy, Walter.( 2004), “IT security standardisation,Network Security”, Dec2004 , pp.6-11.
7. OECD.(2002),OECD Guidelines for the Security of Information Systems and Networks: Towards a Culture of Security,OECD.
10. Saint-Germain, R.(2005), “Information Security Management Best Practice Based on ISO/IEC 17799.”,Information Management Journal, (July/Aug, 2005).

被引用紀錄


徐弘昌(2009)。以ISO 27001為基礎評估電信業資訊安全管理 - 以第一類電信業者為例〔碩士論文,國立交通大學〕。華藝線上圖書館。https://doi.org/10.6842/NCTU.2009.00229
黃建岡(2014)。驗證策略對國內生產毛額與對企業風險及品質成本的影響-兼論驗證工作的本質〔博士論文,朝陽科技大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0078-2611201410190722

延伸閱讀