The Research of the Information Security Governance of Value Delivery
碩士 === 中國文化大學 === 資訊安全產業研發碩士專班 === 98 === Control Objectives for Information and Related Technology(COBIT)published by IT Governance Institute(ITGI)have focus on five main areas,they are Strategic alignment、Risk management、Resource management、Performance measurement and Value delivery。 This thesis i...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2010
|
Online Access: | http://ndltd.ncl.edu.tw/handle/24554623459213727816 |
id |
ndltd-TW-098PCCU1650006 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-098PCCU16500062017-02-23T04:27:14Z http://ndltd.ncl.edu.tw/handle/24554623459213727816 The Research of the Information Security Governance of Value Delivery 資訊安全治理之價值交付的研究 Yen- Ju Chen 陳彥如 碩士 中國文化大學 資訊安全產業研發碩士專班 98 Control Objectives for Information and Related Technology(COBIT)published by IT Governance Institute(ITGI)have focus on five main areas,they are Strategic alignment、Risk management、Resource management、Performance measurement and Value delivery。 This thesis is mainly focus on the Value delivery,and using Information Security Governance(ISG)Implementation Model to study the Value delivery。After analysis of three sample model of the Information Security Governance,I hereby to proposal two suggestions as below: (1)Add Context establishment implementation model addition to The Process/Metrics、Organization/R&R、Security Architecture and Investment Management implementation models that announced in the ISO/IEC 3rd WD 27014 plus,and to integrated with the ISO/IEC 3rd WD 27014 and ISMS(ISO/IEC 27001) Implementation Framework。 (2)When implementing the ISMS,suggest to add High risk evaluation model addition to the Evaluate、Direct and Monitor models in the ISO/IEC 38500。And use the Context establishment implementation model and High risk evaluation model as the Areas of information security governance。Base on the above suggestions,this thesis’s object is to integrate both the Information Security Governance and ISMS and to establish a framework and modeling for the ISMS。 Kwo-Jean Farn 樊國楨 2010 學位論文 ; thesis 85 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 中國文化大學 === 資訊安全產業研發碩士專班 === 98 === Control Objectives for Information and Related Technology(COBIT)published by IT Governance Institute(ITGI)have focus on five main areas,they are Strategic alignment、Risk management、Resource management、Performance measurement and Value delivery。
This thesis is mainly focus on the Value delivery,and using Information Security Governance(ISG)Implementation Model to study the Value delivery。After analysis of three sample model of the Information Security Governance,I hereby to proposal two suggestions as below:
(1)Add Context establishment implementation model addition to The Process/Metrics、Organization/R&R、Security Architecture and Investment Management implementation models that announced in the ISO/IEC 3rd WD 27014 plus,and to integrated with the ISO/IEC 3rd WD 27014 and ISMS(ISO/IEC 27001) Implementation Framework。
(2)When implementing the ISMS,suggest to add High risk evaluation model addition to the Evaluate、Direct and Monitor models in the ISO/IEC 38500。And use the Context establishment implementation model and High risk evaluation model as the Areas of information security governance。Base on the above suggestions,this thesis’s object is to integrate both the Information Security Governance and ISMS and to establish a framework and modeling for the ISMS。
|
author2 |
Kwo-Jean Farn |
author_facet |
Kwo-Jean Farn Yen- Ju Chen 陳彥如 |
author |
Yen- Ju Chen 陳彥如 |
spellingShingle |
Yen- Ju Chen 陳彥如 The Research of the Information Security Governance of Value Delivery |
author_sort |
Yen- Ju Chen |
title |
The Research of the Information Security Governance of Value Delivery |
title_short |
The Research of the Information Security Governance of Value Delivery |
title_full |
The Research of the Information Security Governance of Value Delivery |
title_fullStr |
The Research of the Information Security Governance of Value Delivery |
title_full_unstemmed |
The Research of the Information Security Governance of Value Delivery |
title_sort |
research of the information security governance of value delivery |
publishDate |
2010 |
url |
http://ndltd.ncl.edu.tw/handle/24554623459213727816 |
work_keys_str_mv |
AT yenjuchen theresearchoftheinformationsecuritygovernanceofvaluedelivery AT chényànrú theresearchoftheinformationsecuritygovernanceofvaluedelivery AT yenjuchen zīxùnānquánzhìlǐzhījiàzhíjiāofùdeyánjiū AT chényànrú zīxùnānquánzhìlǐzhījiàzhíjiāofùdeyánjiū AT yenjuchen researchoftheinformationsecuritygovernanceofvaluedelivery AT chényànrú researchoftheinformationsecuritygovernanceofvaluedelivery |
_version_ |
1718416085123858432 |