Summary: | 碩士 === 華梵大學 === 資訊管理學系碩士班 === 96 === As the development and application of Internet, popularity of computer, and information science, information technology is to be a paramount part of enterprise organization operation, and information system also plays an important function in the enterprise activity of organization.
Thus, the progress of Internet and information technology that results in danger and influence to information security management in enterprise organization. if only to apply ISO27001 standard control measure to set up information security management system(ISMS), information security event still keeps happening, and information security management system and its management operating environment seemingly does not to meet risk control to information security after establishing information security management system of enterprise organization.
Based on above mentioned, this content is to set up and to improve a case study of information security management system. By using ISO20000 and BS25999 related to standard to explore and discuss information security management system, in order to enhance the information security management and its implementation.
|