透過您的圖書館登入
IP:3.21.104.109
  • 會議論文

位置服務系統之資訊安全政策風險評估研究

A Study of the Risk Assessment of Information Security Policies on Location-Based Service

摘要


位置服務(Location-Based Service, LBS)是行動生活化的應用加值服務,透過行動定位技術依據使用者所在的環境、位置及需求,來取得使用者手機或具有行動定位裝置的位置資訊並結合位置相關資訊服務,提供使用者所需即時資訊服務。為了確保個人資訊於傳輸時作業安全和資訊保護,與避免機密或隱私的個人資訊外洩,或是個人資訊遭受非法竄改與偽造以及外力入侵竊取個人資訊等,存在著眾多位置服務風險與弱點的安全性問題。 因此位置服務產業需要一個完整的資訊安全評量標準。本研究針對位置服務系統之內部與外部環境並依據其服務的機密性、完整性、可用性及隱私性等多方面進行審慎評估,以HIPAA資訊安全規範與電腦處理個人資料保護法為架構基礎,透過文獻探討與專家問卷建構出位置服務系統資訊安全政策之風險評估模式,經由研究結果發現位置服務系統資訊安全政策的風險管理指標構面內容共區分成六個構面分別為:「主要服務功能面」、「技術服務支援面」、「技術安全機制面」、「系統安全維護面」、「作業環境安全面」、「組織安全政策面」等構面,每個層面皆包含四至六個項目之評量準則,共計三十二項準則。並利用AHP層級分析法來衡量出位置服務之業者、管理階層、一般使用者在針對各個風險評估上的指標之權重值,以了解各個評估指標對風險評估之影響,而產生出來的結果讓位置服務業者更能制定與評估目前的位置服務系統的資訊安全政策。 本研究所提出一個提供位置服務業者來評估制定資訊安全政策的風險評估量表。並藉由位置服務系統資訊安全之探討,找出所要考量影響個人資訊隱私安全的關鍵因素,以提供位置服務業者制定嚴謹的資訊安全政策或是導入運用之評量準則與現行運用的安全規範之參考,有助於位置服務業者對於個人資訊隱私安全的重視與保障,以防止商業利益行為、安全防護漏洞及作業流程的缺失來降低個人資訊隱私外洩,並期望建置出更安全的個人資訊隱私安全服務與環境之目標,防範資訊安全危機的發生。

並列摘要


Location-Based Service is the value-added application of life-mobilization, which acquires users’ circumstances, location and needs on mobile phones or handsets through mobility position technology. However, there are a lot of problems which involve the security issue such as privacy protection, external inspection in confidential or personal data, and illegal distortion of personal data. Obviously, it is critical for information transmission and prevention its risk as well as weakness of security. Therefore, for LBS, a complete solution in information security evaluation standard is keenly necessary. Through this research, we made cautious evaluation about the realm of LBS's confidentiality, completeness, availability, and privacy for internal also external environment within the structure of the Health Insurance Portability and Accountability Act, and the Computer-Processed Personal Data Protection Law. By the method of document research and questionnaire, we constructed the risk assessment of information security policy on Location-Based Service. We concluded that six dimensions of the assessment which includes major service function, technical service support, technical security system, systematic security maintenance, operational environment safety, and organizational security policy, each dimension involves four to six items of the appraisal, the total items is 32. We also made use of Analytic Hierarchy Process to measure the risk weighting of each indicator for LBS providers as well as its management and users, to comprehend the influence from each indicator on the assessment method. The results can be the reference of LBS information security policy. Our research submitted a risk-assessment method of information security for LBS providers. Meanwhile, we found out several key factors that affect personal information security through this research. It helps for LBS providers to make rigorous information security or apply this assessment method to be the reference of security guidelines. This assessment method is beneficial to help LBS providers emphasize and ensure information security to prevent illegal Commercial activity via security vulnerability, LBS providers will reduce the possibilities of Data leakage also. Finally, by the research we hope to assist LBS providers to build better personal information environment and to prevent information security risks.

被引用紀錄


董毓國(2009)。實施資訊安全政策對銀行之影響〔碩士論文,淡江大學〕。華藝線上圖書館。https://doi.org/10.6846/TKU.2009.00572
謝亞庭(2016)。行動支付風險管理稽核機制之研究〔碩士論文,國立中正大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201614052885

延伸閱讀