A Study on Execution of Information Security Management System Self-Assessment Mechanism

碩士 === 國防大學管理學院 === 資訊管理學系 === 101 === Abstract ISO/IEC 27001 is an information security management system (ISMS) standard published by the International Organization for Standardization (ISO) in 2005. Based on this standard, Taiwan’s Bureau of S...

Full description

Bibliographic Details
Main Authors: Tu, Shen-Wen, 涂昇文
Other Authors: Wu, Tsung-Li
Format: Others
Language:zh-TW
Published: 2013
Online Access:http://ndltd.ncl.edu.tw/handle/18588219195958169523
id ndltd-TW-101NDMC1654033
record_format oai_dc
spelling ndltd-TW-101NDMC16540332016-02-21T04:19:51Z http://ndltd.ncl.edu.tw/handle/18588219195958169523 A Study on Execution of Information Security Management System Self-Assessment Mechanism 資訊安全管理系統執行力自我檢測機制之研究 Tu, Shen-Wen 涂昇文 碩士 國防大學管理學院 資訊管理學系 101 Abstract ISO/IEC 27001 is an information security management system (ISMS) standard published by the International Organization for Standardization (ISO) in 2005. Based on this standard, Taiwan’s Bureau of Standards, Ministry of Economic Affairs has in 2007 laid down and announced the CNS 27001 national standards. Nonetheless, ISO/IEC 27001 is just implementation guidance and strategies to maintain an organization’s security. Once an organization obtained the certificate after going through all kinds of paper works and procedures, it doesn’t necessarily mean that the accredited organization will be protected from attacks forever. In order to achieve solid security within an organization, continuous and persistent execution of ISMS is a must. However, the seemingly simple “execution” is in fact “a black hole of business management” (quotes from Dr. Tang, Ming-Je), i.e., execution is not as easy as it sounds. This paper devised a self-assessment mechanism on ISMS execution, and the corresponding software tool was created as well. By following the principle of Plan-Do-Check-Act(PDCA) while tracking the execution of ISO27001’s 11 areas and 133 controls, this tool provides an easy way for an organization being able to improve its ISMS performance effectively. Keywords:Execution、ISMS、ISO/CNS 27001 Wu, Tsung-Li Ting-Jung Yu 吳宗禮 余丁榮 2013 學位論文 ; thesis 115 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國防大學管理學院 === 資訊管理學系 === 101 === Abstract ISO/IEC 27001 is an information security management system (ISMS) standard published by the International Organization for Standardization (ISO) in 2005. Based on this standard, Taiwan’s Bureau of Standards, Ministry of Economic Affairs has in 2007 laid down and announced the CNS 27001 national standards. Nonetheless, ISO/IEC 27001 is just implementation guidance and strategies to maintain an organization’s security. Once an organization obtained the certificate after going through all kinds of paper works and procedures, it doesn’t necessarily mean that the accredited organization will be protected from attacks forever. In order to achieve solid security within an organization, continuous and persistent execution of ISMS is a must. However, the seemingly simple “execution” is in fact “a black hole of business management” (quotes from Dr. Tang, Ming-Je), i.e., execution is not as easy as it sounds. This paper devised a self-assessment mechanism on ISMS execution, and the corresponding software tool was created as well. By following the principle of Plan-Do-Check-Act(PDCA) while tracking the execution of ISO27001’s 11 areas and 133 controls, this tool provides an easy way for an organization being able to improve its ISMS performance effectively. Keywords:Execution、ISMS、ISO/CNS 27001
author2 Wu, Tsung-Li
author_facet Wu, Tsung-Li
Tu, Shen-Wen
涂昇文
author Tu, Shen-Wen
涂昇文
spellingShingle Tu, Shen-Wen
涂昇文
A Study on Execution of Information Security Management System Self-Assessment Mechanism
author_sort Tu, Shen-Wen
title A Study on Execution of Information Security Management System Self-Assessment Mechanism
title_short A Study on Execution of Information Security Management System Self-Assessment Mechanism
title_full A Study on Execution of Information Security Management System Self-Assessment Mechanism
title_fullStr A Study on Execution of Information Security Management System Self-Assessment Mechanism
title_full_unstemmed A Study on Execution of Information Security Management System Self-Assessment Mechanism
title_sort study on execution of information security management system self-assessment mechanism
publishDate 2013
url http://ndltd.ncl.edu.tw/handle/18588219195958169523
work_keys_str_mv AT tushenwen astudyonexecutionofinformationsecuritymanagementsystemselfassessmentmechanism
AT túshēngwén astudyonexecutionofinformationsecuritymanagementsystemselfassessmentmechanism
AT tushenwen zīxùnānquánguǎnlǐxìtǒngzhíxínglìzìwǒjiǎncèjīzhìzhīyánjiū
AT túshēngwén zīxùnānquánguǎnlǐxìtǒngzhíxínglìzìwǒjiǎncèjīzhìzhīyánjiū
AT tushenwen studyonexecutionofinformationsecuritymanagementsystemselfassessmentmechanism
AT túshēngwén studyonexecutionofinformationsecuritymanagementsystemselfassessmentmechanism
_version_ 1718192169360031744