A Study on Execution of Information Security Management System Self-Assessment Mechanism
碩士 === 國防大學管理學院 === 資訊管理學系 === 101 === Abstract ISO/IEC 27001 is an information security management system (ISMS) standard published by the International Organization for Standardization (ISO) in 2005. Based on this standard, Taiwan’s Bureau of S...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2013
|
Online Access: | http://ndltd.ncl.edu.tw/handle/18588219195958169523 |
id |
ndltd-TW-101NDMC1654033 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-101NDMC16540332016-02-21T04:19:51Z http://ndltd.ncl.edu.tw/handle/18588219195958169523 A Study on Execution of Information Security Management System Self-Assessment Mechanism 資訊安全管理系統執行力自我檢測機制之研究 Tu, Shen-Wen 涂昇文 碩士 國防大學管理學院 資訊管理學系 101 Abstract ISO/IEC 27001 is an information security management system (ISMS) standard published by the International Organization for Standardization (ISO) in 2005. Based on this standard, Taiwan’s Bureau of Standards, Ministry of Economic Affairs has in 2007 laid down and announced the CNS 27001 national standards. Nonetheless, ISO/IEC 27001 is just implementation guidance and strategies to maintain an organization’s security. Once an organization obtained the certificate after going through all kinds of paper works and procedures, it doesn’t necessarily mean that the accredited organization will be protected from attacks forever. In order to achieve solid security within an organization, continuous and persistent execution of ISMS is a must. However, the seemingly simple “execution” is in fact “a black hole of business management” (quotes from Dr. Tang, Ming-Je), i.e., execution is not as easy as it sounds. This paper devised a self-assessment mechanism on ISMS execution, and the corresponding software tool was created as well. By following the principle of Plan-Do-Check-Act(PDCA) while tracking the execution of ISO27001’s 11 areas and 133 controls, this tool provides an easy way for an organization being able to improve its ISMS performance effectively. Keywords:Execution、ISMS、ISO/CNS 27001 Wu, Tsung-Li Ting-Jung Yu 吳宗禮 余丁榮 2013 學位論文 ; thesis 115 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國防大學管理學院 === 資訊管理學系 === 101 === Abstract
ISO/IEC 27001 is an information security management system (ISMS) standard published by the International Organization for Standardization (ISO) in 2005. Based on this standard, Taiwan’s Bureau of Standards, Ministry of Economic Affairs has in 2007 laid down and announced the CNS 27001 national standards.
Nonetheless, ISO/IEC 27001 is just implementation guidance and strategies to maintain an organization’s security. Once an organization obtained the certificate after going through all kinds of paper works and procedures, it doesn’t necessarily mean that the accredited organization will be protected from attacks forever. In order to achieve solid security within an organization, continuous and persistent execution of ISMS is a must. However, the seemingly simple “execution” is in fact “a black hole of business management” (quotes from Dr. Tang, Ming-Je), i.e., execution is not as easy as it sounds.
This paper devised a self-assessment mechanism on ISMS execution, and the corresponding software tool was created as well. By following the principle of Plan-Do-Check-Act(PDCA) while tracking the execution of ISO27001’s 11 areas and 133 controls, this tool provides an easy way for an organization being able to improve its ISMS performance effectively.
Keywords:Execution、ISMS、ISO/CNS 27001
|
author2 |
Wu, Tsung-Li |
author_facet |
Wu, Tsung-Li Tu, Shen-Wen 涂昇文 |
author |
Tu, Shen-Wen 涂昇文 |
spellingShingle |
Tu, Shen-Wen 涂昇文 A Study on Execution of Information Security Management System Self-Assessment Mechanism |
author_sort |
Tu, Shen-Wen |
title |
A Study on Execution of Information Security Management System Self-Assessment Mechanism |
title_short |
A Study on Execution of Information Security Management System Self-Assessment Mechanism |
title_full |
A Study on Execution of Information Security Management System Self-Assessment Mechanism |
title_fullStr |
A Study on Execution of Information Security Management System Self-Assessment Mechanism |
title_full_unstemmed |
A Study on Execution of Information Security Management System Self-Assessment Mechanism |
title_sort |
study on execution of information security management system self-assessment mechanism |
publishDate |
2013 |
url |
http://ndltd.ncl.edu.tw/handle/18588219195958169523 |
work_keys_str_mv |
AT tushenwen astudyonexecutionofinformationsecuritymanagementsystemselfassessmentmechanism AT túshēngwén astudyonexecutionofinformationsecuritymanagementsystemselfassessmentmechanism AT tushenwen zīxùnānquánguǎnlǐxìtǒngzhíxínglìzìwǒjiǎncèjīzhìzhīyánjiū AT túshēngwén zīxùnānquánguǎnlǐxìtǒngzhíxínglìzìwǒjiǎncèjīzhìzhīyánjiū AT tushenwen studyonexecutionofinformationsecuritymanagementsystemselfassessmentmechanism AT túshēngwén studyonexecutionofinformationsecuritymanagementsystemselfassessmentmechanism |
_version_ |
1718192169360031744 |